GOBEAUTY PERSONAL DATA PROTECTION POLICY
POLICY FOR PERSONAL DATA PROTECTION
of the company GO BEAUTY
in accordance with the requirements of Regulation (EU) 2016/679 (GDPR)
As a personal data administrator GO BEAUTY strictly implements the legal and regulatory provisions on the personal data collection and processing. Therefore, we consider our duty to exercise due diligence in the processing of your personal data and to take all possible measures to protect them from any unlawful actions. Protecting the rights and freedoms of citizens is of paramount importance for GO BEAUTY and we treat with due respect the interests of all citizens.
With this Policy we inform you about the processing procedures of your personal data, the data protection rights that you have and we also provide you with all information under Art. 13 and Art. 14 of Regulation (EC) 2016/679 of the EP and the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free motion of such data (General Data Protection Regulation – GDPR).
This Policy is published on the website as well as on the app sign-up screens. When you sign up, you must accept the Terms of Service and the Policy, and then you cannot access them through the application itself, and you can view it through the website.
contact GO BEAUTY:
At the company registered address and address of management: Sofia, ul. Rikkardo Vakkarini 10V
– by phone: +359 888 057152
– by e-mail: firstname.lastname@example.org
Contact Data Protection Officer: Mrs. Gabriela Palaveeva
– by phone:+359 888 603 022
– by e-mail: email@example.com
All personal data processing shall be performed in accordance with the data protection principles set out in Article 5 of Regulation (EC) 2016/679. GO BEAUTY’s policies and procedures aim to ensure compliance with these principles.
Personal data shall be processed legally, in good faith and transparently.
Legally – to identify a legitimate basis before processing the personal data.These are so-called “processing grounds”, such as “consent”.The consent of the person is one of the grounds for processing the personal data. Such may also be the performance of a contract or the legitimate interest of the company GO BEAUTY, in which cases there is no need the consent to be given.
In good faith – in order for the processing to be in good faith, the data controller must provide certain information to the data subjects, necessary in each certain case and for each specific purpose in a comprehensible, concise and accessible way for the data subject.This applies irrespective of whether personal data is obtained directly from data subjects or from other sources.
Transparent – Regulation (EU) 2016/679 sets requirements as what information should be made available to data subjects covered by the “transparency” principle set out in Articles 12, 13 and 14 of the GDPR.Under the GDPR provisions cited, the information must be communicated to the data subject in an intelligible form using a clear and comprehensible language,ie confidentiality declarations to be signed by the data subjects must be detailed and specific, understandable and accessible.
Personal data – means any information relating to an identifiable physical person or the information with an individual, who can be identified (“data subject”), an identifiable physical natural person is a person who can be identified, directly or indirectly , in particular by an identifier such as name, identification number, location data, online identifier or one or more physical, physiological, genetic, mental, intellectual, economic, cultural or social identities of that individual person.
Processing of personal data – means any operation or set of operations performed with personal data or a set of personal data by automatic or other means such as collecting, recording, organising, structuring, storing, adapting or modifying, retrieving, consulting, using, disclosing through transmission, distribution or other means by which data becomes available, arranged or combined, restricted, deleted or destroyed.
Ordinary Personal Information -for all individuals, depending on the purpose of the processing – personal information (for example: name, address, date and place of birth, nationality, email address, telephone number);identity verification data; identity card details.
Special category (sensitive) personal data- for the purposes of medical expertise and human resources.
Purpose-of personal data processing in GO BEAUTY:
The information that may contain your personal data shall be processed for the following purposes:
-Beauty and relax procedures
-Alerts, complaints and other requests;
-Exercise of the rights within the meaning of Regulation (EU) 2016/679 before GO BEAUTY personal data administrator.
Upon registration of the client:
– e-mail / e-mail address:
– Phone number
– Profile photo (optional)
– Date of birth
– Gender/ Sex
When creating a query/ When creating a visit request or doctor review:
– All customer details data from the registration
– Address to visit
– Additional address guidelines (optional)
– Exact coordinates for the visit
– District for the visit (we have it as a separate address field and is used for internal purposes only)
– Patient data – whether the patient is a child or an adult
– Phone – may be different from the phone of the registered user if the order was filled for a third person or for a child
– Gender/ sex – may be different from the pointed by the registered user if the order is for a third person or for a child
– Age – may be different from the pointed by the registered user if the order is for a third person or for a child
– List of desired services
– Date and time of visit
– Symptoms or Additional Notes – Free Text (Optional)
– Additional photos for support of the examination.The user should keep in mind that it is not advisable to take pictures of the face or intimate parts of the body as the photos will be seen by the specialist. In the event of violation of this recommendation, the responsibility remains for the user taking the photos .
– Customer rating for the visit
– If the request was declined by the customer, the reason for suspension of the application (optional)
In pursuance of its subject matter and in connection with its operational activities GO BEAUTY processes personal data of individuals for the execution of the contracts it concludes in sense of the Obligations and Contracts Act, Public Procurement Act, Commercial Law, etc.
Insofar as personal data of individual individuals are processed in connection with the execution of these contracts, the information shall be processed in a minimum volume sufficient for the exact fulfilment of the obligations under the respective contract. Access to this information shall be provided to third parties only when this is specified in a special act.
We process personal data of individuals who have expressed a desire to use the services of specialists with whom GO BEAUTY has contractual relations. In the course of the service activities management, the processing of all data for the identification of the individuals, for health status and for social status, all contact data, as well as all other data depending on the type and the volume of the requested service has been performed.
The collected data shall be used only for the purpose of contractors and specialists and shall be provided to third parties only in cases when required by law. In such cases, the data may be provided to the NSSI, the NRA, the courts in the Republic of Bulgaria, the National Audit Office, the General Directorate of the Labor Inspectorate and other public authorities, in view of their powers and competencies. The information shall not be stored outside the EU and the European Economic Area. GO BEAUTY shall provide the appropriate technical and organisational measures to protect your personal data.
Alerts and other claims
Alerts and other claims in connection with the exercise of the rights and obligations of GO BEAUTY shall be submitted under the terms and conditions of the current legislation.
In the processing of the information contained in the alerts and other complaints deposited to GO BEAUTY shall be treated those personal data that are relevant to the case. Data that has become known to GO BEAUTY in this regard shall be made available to third parties only if this is provided by law.
Exercise of the rights within the meaning of Regulation (EC) 2016/679 to GO BEAUTY
You have the right to exercise your rights under Art.15-22 of Regulation (EC) 2016/679 to GO BEAUTY for the personal data that GO BEAUTY handles about you. When claiming rights claims within the meaning of Regulation (EC) 2016/679 to GO BEAUTY you will be asked to identify yourself – by providing an identity document, by providing electronic signature, by sending a confirmation message to a mail or a SMS, or by other methods and means of identification. All personal data processed in connection with the processing of individual claims will only be used for the purpose of exercising those rights. In this regard, the personal data may be provided to third parties only when this is required by law.
Your rights in relation to the processing of your personal data:
Right to information relating to your own personal data
You have the right to request:
– information on whether data processing related to you is being processed, information on the purpose of such processing, the categories of data and the recipients or categories of recipients to whom the data collected shall be disclosed;;
– a message in comprehensible form that contains your personal data being processed, as well as any available information about their source;
Right to Data Correction
In the event that we have and process incomplete or inaccurate (erroneous / wrong data), you are entitled at any time to request:
- to delete, to correct or to block your personal data, the processing of which does not meet the requirements of the law;
– to notify third parties to whom personal information has been disclosed of any erasure, correction or blocking, except where this is impracticable or involves excessive effort.
Right to delete data (right “to be forgotten”)
At any time you have the right to ask the administrator without undue delay to delete your personal data if :
– the data are no longer needed for the purposes for which they were collected or were otherwise processed;
– in the case of the unlawful processing of your personal data;
– – in the case of withdrawal of your explicit consent to the processing of personal data and when there is no other legal basis for their processing;
– In the event of exercising the right of deletion in order to track the development of the service and to protect the rights of the user, GO BEAUTY reserves the right for a period of 3 to 6 months to keep the application data containing your age, gender and approximate location, and your pictures and symptoms.
In the event of a user profile being deleted, all identifying data will be deleted at the same time, and only age, gender, approximate location of each request submitted and the list of ordered services will be left in storage..
Accordingly, if the user wants his account to be deleted, he / she needs to send an email, and then AT HOME through the CMS will be able to delete his / her profile. For this purpose, the “Delete by GDPR” button is created in the CMS in the client’s account at the bottom.
Right to Restrict Processing
You may request a limitation of the processing customisable data if:
– the processing of the data has not any legal basis, but instead of deleting it, you want its limited processing; or
– we no longer need these data (for the intended purpose), but you need them for the establishment, exercise or protection of any legal claims; or
– you submitted an objection for data processing as you expect a check whether the grounds of the administrator are legal.
Right of data portability
– You may ask us to provide your personal data that you have entrusted to our care in an organised, orderly, structured, generally accepted electronic format if we process the data under the contract and based on the declaration of consent that may be withdrawn or as a contractual obligation and processing shall be done automatically.
Right of objection (right of complaint)
You may at any time:
– refuse the processing of your personal data if there is a legitimate reason for doing so; - where the denial of processing is justified, the personal data of the individual concerned should no longer be processed.
Right of complaint: If you believe that we are violating the applicable legal framework, please contact us to clarify the matter.You have the right to file a complaint before GO BEAUTY, before the Commission for Personal Data Protection. You can also complain to a regulatory body within the EU.
Links to other websites
This data protection policy is not the same as the policies referenced on the GO BEAUTY website to other websites. We encourage you to read the data protection policies of the other websites you visit to understand their procedures for collecting, using, and disclosing personal information.
The security of personal data is important to us. GO BEAUTY maintains appropriate administrative, technical and physical safeguards to protect personal data against accidental or unlawful destruction, accidental loss, alteration, unauthorised disclosure or access, use and any other unlawful forms of processing of personal data of the individuals.
Updates to this policy to protect personal data
GO BEAUTY reserves the right to modify this policy, in case of necessity or in case of legal changes, but this will not reduce the level of protection of the personal data of the individuals.