Privacy Policy
1. Collection and Use of Personal Data
GRAFFITI ORDERS ("we" or "us") collects and uses personal data only when you have given your consent or when necessary to provide the services we offer. The collected data may include:
- Name and contact information (phone, email)
- Messages and inquiries sent through the contact form
- Technical data (IP address, browser, device information)
- Data related to orders and services
2. Purpose of Processing
Your personal data is processed exclusively for the following purposes:
- Responding to inquiries and delivering services
- Communication regarding orders and projects
- Support and improvement of services
- Maintaining necessary records and documentation
- Compliance with legal obligations
3. Legal Basis for Processing
Processing of personal data is based on:
- Your consent (when you provide data voluntarily)
- Necessity for contract performance (for orders and services)
- Legal obligation (for tax and accounting purposes)
- Legitimate interest (for improving services and communication)
4. Data Sharing
We do not sell, trade, or share your personal data with third parties except in the following cases:
- To service providers that help us operate our services (e.g., email service providers)
- When required by law or to protect our rights
- With your explicit consent
All third parties with whom we share data are required to maintain strict data protection measures.
5. Data Retention
Your personal data is retained only for as long as necessary to fulfill the purposes for which it was collected or as required by law. Typically this includes:
- Contact and inquiry data – 3 years after last communication
- Order and payment data – 10 years (for accounting and tax purposes)
6. Your Rights
Under the General Data Protection Regulation (GDPR) and Bulgarian law, you have the following rights:
- To access your personal data
- To request correction of inaccurate or incomplete data
- To request erasure of your data ("right to be forgotten")
- To restrict processing of your data
- To object to processing
- To object to automated decision-making
- To withdraw your consent at any time
To exercise these rights, please contact us using the details in Section 12. We will respond to your requests within one month.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, loss, or disclosure. These measures include:
- Encryption of sensitive data
- Limited access to personal data only to necessary employees
- Regular system and software updates
- Data protection policies within the organization
8. Cookies and Tracking
Our website may use cookies and similar technologies to enhance your user experience and analyze traffic. You can manage cookie settings through your browser preferences.
9. Third Parties
We may use third-party services (e.g., Google Analytics) to analyze website usage. These services have their own privacy policies and may collect anonymized data. We always strive to use reputable and responsible providers.
10. Changes to This Policy
We reserve the right to update or modify this Privacy Policy at any time. By continuing to use the website after changes are posted, you are considered to have accepted the new policy. We will notify users of significant changes by posting the updated policy on this page.
11. Contact Regarding Data Protection
If you have questions or concerns about the processing of your personal data, please contact our Data Protection Officer:
- Email: [email protected]
- Phone: +359 88 963 7333
- Address: [Your address if applicable]
You also have the right to lodge a complaint with the Commission for Personal Data Protection if you believe your rights have been violated.
12. Effective Date
This Privacy Policy is effective as of January 1, 2025 and applies to all users of the website.