1. Purpose and Scope
1.1. Customer Umbrella LTD, a company established under the laws of Bulgaria (identification number 206426432; registered office address: 9000, Varna, Bulgaria, Tzanko Tzerkovski 7), hereinafter referred to as the “Company”, strives to comply with applicable laws and regulations related to Personal Data protection in countries where the Company operates. This Policy sets forth the basic principles by which the Company processes your personal data, and indicates the responsibilities while processing personal data.
1.2. The Company does not knowingly attempt to solicit or receive information from children under 16 years of age.
2. Company’s website
2.1. The Company controls and manages– www.customerumbrella.com (hereinafter the “Website”) which may collect particular data for its business purposes.
3. Definitions of legal bases for the processing
3.1. Consent – your clear agreement to the processing of your personal data for a specific purpose.
3.2. Contract – the reason why the processing is necessary based on a contract you have with the Company, or because the Company has asked you to take specific steps before entering into that contract.
3.3.Legitimate Interests – the reason why the processing your data is necessary which is based on the legitimate interests or the legitimate interests of a third party, provided those interests are not outweighed by your rights and interests. These legitimate interests are:
3.3.1. Gaining insights from your behavior on the Website;
3.3.2. Delivering, developing and improving the Website;
3.3.3. Enabling the Company to enhance, customize or modify the Website and services;
3.3.4. Determining whether marketing campaigns are effective;
3.3.5. Enhancing data security.
4. Consent rule
4.1. If you have given consent to the processing of your data you can freely withdraw such consent at any time by emailing the Company to [email protected]
4.2. If you do withdraw your consent, and if the Company does not have another legal basis for the processing of your data, then the Company will stop the processing of your personal data.
4.3. If the Company has another legal basis for the processing of your data, then the Company may continue to do so subject to your legal interests and rights.
5. Company’s responsibilities
5.1. If you are a registered user or a visitor to the Website the Company acts as the ‘data controller’ of personal data. This means that the Company determines how and why your data are processed.
6. Your responsibilities
6.3. Treat your personal data confidential and secure.
7. Collected data
7.1. The Company collects data when you interact with its Website, especially when:
7.1.1. You browse any page of the Website;
7.1.2. The Company calls you;
7.1.3. You use the Website and receive services;
7.1.4. You receive emails from the Company;
7.1.5. You chat with the Company for customer support;
7.1.6. You connect integrations;
7.1.7. You opt-in to marketing emails.
7.1.8. The Company collects the following categories of data:
– contact details such as you’re your first name, last name, address, telephone number, email address;– data that identifies you such as your IP address, login information, browser type and version, time zone setting, browser plug-in types, geolocation information about where you might be, operating system and version;– data on how you use the website such as your URL clickstreams (the path you take through the website), goods/services viewed, page response times, download errors, how long you stay on webpages, what you do on those pages, how often, and other actions.
7.2. The Company collects the following categories of data:
7.2.1. The recipients of the collected data are the highest management level of the Company, its employees and contractors, and other third-party service providers mentioned below.
8. Purposes and legal basis for the processing
The Company processes the data for:
8.1.1. Providing Services:
Details: the Company needs to provide services accessible via the Website. Legal basis: Consent; Contract; Legitimate Interests.
8.1.2. Keeping the Website running:
Details: managing your requests (like orders), login and authentication, remembering your settings, processing payments, hosting and back-end infrastructure. Legal basis: Contract; legitimate Interests.
8.1.3. Improving the Website
Details: testing features, interacting with feedback platforms and questionnaires, managing landing pages, heat mapping the Website, traffic optimization and data analysis and research, including profiling and the use of machine learning and other techniques over your data and in some cases using third parties to do this. Legal basis: Contract; legitimate Interests.
8.1.4. Customer support
Details: notifying you of any changes to the service, solving issues, any bug fixing. Legal basis: Contract; Legitimate Interests.
8.1.5. Marketing purposes (with your consent only)
Details: sending you emails and messages about new functions, goods and services, and content. Legal basis: Consent.
8.1.6. Prevent fraud
Details: evercookies .Legal basis: Legitimate Interests.
9. Your rights
You may choose not to provide the Company with personal data. If you choose to do so, you can continue to visit the Website and browse its pages, but the Company will not be able to provide its services and process transactions without personal data.
You may turn off cookies in your browser via settings. You can block cookies on your browser refusing cookies. You may delete cookies. If you turn off cookies, you can continue to use the Website and browse its pages, but the Website and certain services will not work properly.
You may ask us to refrain from using your data for marketing. You can opt-out from marketing by emailing us at [email protected]
You can exercise the following rights by sending us an email at [email protected]
9.1.1. You have the right to access information about you, especially:
the categories of data; the purposes of data processing; third parties to whom the data disclosed; how long the data will be retained and the criteria used to determine that period; other rights regarding the use of your data.
9.1.2. You have the right to make the Company correct any inaccurate personal data about you.
9.1.3. You can object to the Company using your personal data for profiling you or making automated decisions about you. The Company may use your data to determine whether we should let you know information that might be relevant to you (for example, tailoring emails to you based on your behavior).
9.1.4. You have the right to the data portability of your data to another service or Website. The Company will give you a copy of your data in a readable format so that you can provide it to another service. If you ask us and it is technically possible, we will directly transfer the data to the other service for you.
9.1.5. You have the right to be “forgotten”. You may ask erasing any personal data about you, if it is no longer necessary for the Company to store the data for purposes of your use of the Website.
9.1.6. You have the right to lodge a complaint regarding the use of your data by the Company. You can address any complaint to your national regulator (see the list at http://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm
In the context of the right to access information, the Company shall provide you with the information within one month of your request unless there is a justified requirement to provide such information faster.
We have security and organizational measures and procedures to secure the data collected and stored. We have security policies and data processing agreements with all our employees and contractors who are obliged to follow and maintain appropriate technical and organizational measures. We have internal Information Security Policy.
Connections to the Website are encrypted using 256-bit SSL with integrity assured by the SHA2 ECDSA algorithm.
We use servers that comply with strict international data security standards, including ISO 27001.
We use servers that are certified under PCI DSS Level 1, ISO/IEC 27001:2013, SOC 1 type II.
You acknowledge that no perfect security infrastructure exists, no data transmission is guaranteed to be 100% secure, and there may be some security risks.
You are responsible for your login information and password. You shall keep them confidential.
In case if your privacy has been breached, please contact the Company immediately on [email protected]
11. Location of the processing of personal data
The Company is international and can have foreign branches and departments. The Company’s Research and Development department is based in Varna at secure premises. The employees and contractors of the Company’s Research and Development department are bound by the respective agreements, Company’s internal policies and Information Security Policy.
Our servers for storing the data are located in Germany.
12. Retention period
The Company will delete your personal data from the databases pursuant to your demand to delete your data.
13. Transfer of your personal data
Cookies are pieces of data that a Website transfers to a user’s hard drive for record-keeping purposes.
The Company uses the following types of cookies:
Strictly needed cookies. These cookies are necessary for the Website to work correctly. They will allow you to move our Website and use its capabilities. These files do not identify you as a person. If you do not agree to use this type of file this may affect the proper work of the Website or its components.Cookies related to performance, efficiency, and analytics. These files help us understand how you interact with our Website by providing information about the areas visited and the amount of time spent on the Website, as well as showing problems in the operation of the Internet resource, for example, error messages. This will help us to improve the work of the Website. Cookies related to analytics. These files help us to measure the effectiveness of advertising campaigns and optimize the content of Websites for those who are interested in our advertising. This type of cookies shall not be used for Your identification. All information that is collected and analyzed is anonymous. Advertising cookies. These cookies record information about Your online activities, including visits to our Website, as well as information about the links and advertising that you have chosen to view. The Company uses such files to collect data about your activity on the Internet and determine your interests, which allows the Company to provide advertising that suits your interests and on which you have given your consent.
You have several options how to manage cookies on your device. All browsers allow you to block or delete cookies from your device. You may consult the privacy features in your browser to understand what you should do if you need to manage cookies.
15. Address of the Data Controller
Customer Umbrella LTD
Registered address: 9000, Varna, Bulgaria, Tzanko Tzerkovski 7