Information about the data controller:

The address of our website: https://mdbeautyskin.com.

MD LAB Ltd., is a company registered in the Commercial Register of the Registry Agency with UIC 207353898, registered office and registered address. registered office and registered address. +359 88 960 1345; e-mail: info@mdbeautyskin.com.

We process your personal data on the following grounds:

Explicit consent from you – the purpose is stated on a case-by-case basis;

In the following paragraphs you will find information about the processing of your personal data depending on the basis on which we process it.

1. COLLECTION AND PROCESSING OF PERSONAL DATA

Personal data is information that serves to identify you, i.e. name, telephone number, e-mail or postal address. mdbeautyskin.com does not collect personal data from you unless you provide it in special cases, such as when you order products or sign up to receive promotional communications. By submitting your personal data, you agree to receive e-mail communications about current commercial offers, promotions, news and the organisation of events and campaigns for marketing purposes.

1.1 AFTER YOUR CONSENT

We process your personal data on this basis only after your explicit, unambiguous and voluntary consent. We do not foresee any adverse consequences for you if you refuse the processing of personal data.

Consent is a separate basis for processing your personal data and the purpose of the processing is set out in it, and is not covered by the purposes listed in this policy. If you give us your consent and until you withdraw or terminate any contractual relationship with us, we will make product/service offers that are suitable for you.

On this basis, we only process the data for which you have given us your explicit consent. The specific details are determined on a case-by-case basis. Typically, data include:

Email

Phone

Address

Names

Consents granted may be withdrawn at any time. Withdrawal of consent shall have no effect on the performance of the contractual obligations. If you withdraw your consent to the processing of personal data for any or all of the ways described above, we will not use your personal data and information for the purposes set out above.

2. USE AND STORAGE OF PERSONAL DATA

mdbeautyskin.com uses your personal data solely for the purpose of the technical management of the site, to provide you with access to special information or for general communication with you.

mdbeautyskin.com will not sell your personal data to third parties, nor will it trade it anywhere else. The employees of mdbeautyskin.com are required to protect the confidentiality of your data and to respect a confidentiality agreement.

2.1 PROCESSING OF ANONYMISED PERSONAL DATA

We process your data for static purposes, that is, for analyses in which the results are only aggregated and the data are therefore anonymous. It is impossible to identify a specific person from this information.

2.2 AUTOMATICALLY RECORDED INFORMATION

When you access the mdbeautyskin.com website, some general non-personal data (Internet browser used, number of visits, average time spent on the site, pages viewed) is automatically recorded (not as part of registration).

This information is used to assess how attractive our website is and to improve its content and functionality. Your data is no longer processed or transmitted to third parties.

2.3 COOKIES

“Cookies are small files that are temporarily stored on your hard drive and allow our website to recognize your computer the next time you visit the mdbeautyskin.com website. mdbeautyskin.com uses cookies solely to collect information about the use of our website.

2.4 SECURITY

mdbeautyskin.com attaches great importance to ensuring the security of your personal data. Your data is conscientiously protected from loss, destruction, alteration/falsification, manipulation and unauthorized access or disclosure.

2.5 MINORS

mdbeautyskin.com advises all parents and guardians to educate their children about safety and responsibility when providing personal information on the Internet. Minors must not transmit personal data to the mdbeautyskin.com website without the permission of their parents or guardians. mdbeautyskin.com will never collect personal information if it knows it is of a minor, nor will it use it in any way or disclose it to third parties without permission.

2.6 LINKS TO OTHER WEBSITES

This privacy statement applies to the website, mdbeautyskin.com. Sub-pages on this site may contain links to other providers that do not enforce the privacy statement. When you leave the mdbeautyskin.com website, please look for and read the privacy statement of each site that collects personally identifiable information.

3.HOW WE PROTECT YOUR PERSONAL DATA

To ensure adequate protection of the company’s and its customers’ data, we apply all necessary organizational and technical measures provided for in the Personal Data Protection Act.

In order to maximize the security of the processing, transmission and storage of your data, we may use additional security mechanisms such as encryption, pseudonymization, etc.

4. CONSUMER RIGHTS

Each User of the Site enjoys all the rights for the protection of personal data under Bulgarian and European Union law. Each User is entitled to:

  • Awareness (in relation to the processing of his personal data by the controller);
  • Access to your own personal data;
  • Correction (if data is inaccurate);
  • Erasure of personal data (right to be forgotten);
  • Restriction of processing by the controller or processor;
  • Portability of personal data between controllers;
  • Objection to processing of personal data;
  • The data subject shall also have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her;
  • The right to a judicial or administrative remedy if the data subject’s rights have been violated.

The user may request deletion if one of the following conditions applies:

  • The personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
  • The user withdraws their consent on which the data processing is based and there is no other legal basis for the processing;
  • The data user objects to the processing and there are no legitimate grounds for the processing that override;
  • Personal data have been unlawfully processed;
  • The personal data must be erased in order to comply with a legal obligation under Union or Member State law to which the controller is subject;
  • The personal data was collected in connection with the provision of information society services to children and consent was given by the person with parental responsibility for the child.

The user has the right to restrict the processing of his/her personal data by the controller when:

  • Challenge the accuracy of the personal data. In this case, the restriction of processing shall be for a period which allows the controller to verify the accuracy of the personal data;
  • The processing is unlawful, but the User does not wish the personal data to be deleted, but requests instead that their use be restricted;
  • The controller no longer needs the personal data for the purposes of the processing, but the User requires them for the establishment, exercise or defence of legal claims;
  • Object to processing pending verification whether the legitimate grounds of the controller override the interests of the User.

4.1 RIGHT TO PORTABILITY

The data subject shall have the right to obtain the personal data concerning him or her which he or she has provided to a controller in a structured, commonly used and machine-readable format and shall have the right to transfer those data to another controller without hindrance from the controller to whom the personal data have been provided, where the processing is based on consent or a contractual obligation and the processing is carried out by automated means.

When exercising his or her right to data portability, the data subject shall also have the right to obtain a direct transfer of personal data from one controller to another, where technically feasible.

4.2 RIGHT TO OBJECT

Users have the right to object to the controller to the processing of their personal data. The controller shall be obliged to terminate the processing unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.

If you object to the processing of personal data for direct marketing purposes, the processing shall be terminated immediately.

4.3 COMPLAINT TO THE SUPERVISORY AUTHORITY

Each User has the right to lodge a complaint against unlawful processing of his/her personal data with the Personal Data Protection Commission or the competent court.

5. NOTIFICATION OF CHANGES

Any changes to our privacy policy will be disclosed in the privacy statement, on the home page and other places we deem appropriate.

6. PROCESSING OF PERSONAL DATA FOR THE PURPOSE OF SHOPPING THROUGH THE ONLINE STORE

You can shop online on our website. You can use this service with or without registration. The data provided in both cases will be used solely for the purpose of carrying out the contract.

Additionally, you have the option to subscribe to our newsletter, and not agreeing to this in no way prevents you from becoming a customer of our online store.

Before registering, please read the details of who we are and the purposes for which your personal data is processed.

In processing personal data, MD LAB Ltd. complies with the legal and regulatory framework applicable in Bulgaria in relation to the protection of personal data, including but not limited to Regulation (EU) 2016/679 (“Regulation”).

7. CONCLUSION OF A CONTRACT:

By pressing the “Register” or “Buy” button , you make an electronic statement, which enters into a contract with MD LAB Ltd. under these Terms and you agree to abide by them. Before clicking the “Order” button, you have the opportunity to review and edit the information you provide.

You acknowledge that electronic statements to MD LAB Ltd. and electronic statements from MD LAB Ltd. to you are deemed to be signed with an ordinary electronic signature in accordance with Article 3(10) of Regulation (EU) No 910/2014, with the force of a handwritten signature.

By giving your consent to register and complete an order, you agree to MD LAB Ltd, UIC: 207353898, Blvd. Vitosha № 139, entrance B, floor 6, app.15, to use the personal data provided by you – e-mail, first name, last name, address (country, city/village, postal code), telephone. In case you request an invoice, you must give your explicit consent to MD LAB Ltd. to use the data necessary for its issuance.

In addition, MD LAB Ltd. stores information about the registration and consent to the Terms (date, time and IP address), and maintains a log of the fact of sending the statement (without its content) for a period of 1 /one/ year. The log contains the date of the statement, the sender’s name and email address, and the recipient’s identification.

When processing your personal data, you will not be subject to a decision based solely on automated processing, including profiling.

MD LAB Ltd. protects the User’s personal data in accordance with the Personal Data Protection Act.

To protect the User’s personal data, MD LAB Ltd. will send the personal data once to the e-mail address entered by the User during the order.

The User may store data on the User’s end communication device, unless the latter expresses its disagreement to this.

The User agrees that MD LAB Ltd. has the right to send the User at any time electronic newsletters, offers for product purchases, promotions, etc. via electronic messages.

MD LAB Ltd. has the right to collect, store and process data about the User’s actions during the use of mdbeautyskin.com.

MD LAB Ltd. has the right to ask the User to identify himself at any time and to verify the data entered by the User in the online order form at mdbeautyskin.com.

7.1 NOTIFICATION OF CHANGES

Any changes to our privacy policy will be disclosed in the privacy statement, on the home page and in such other places as we deem appropriate.