Privacy Policy

Mandatory Information on Personal Data Protection Rights

Details of the company processing your data

Name: DZZD BELLISSIMA
UIC/BULSTAT: 176835776
Seat and registered office Veliko Tarnovo, 29 Osvobozhdenie Street
Mailing address: Veliko Tarnovo, 29 Osvobozhdenie Street
Phone: +359 888 412 053
E-mail: info@dream-reformer.com
Website: www.dream-reformer.com

Details of the competent data protection supervisory authority

Name: Commission for Personal Data Protection
Seat and registered office Sofia 1952, 2 Prof. Tsvetan Lazarov Blvd
Mailing address: Sofia 1952, 2 Prof. Tsvetan Lazarov Blvd
Phone: 02 915 3 518
Website: www.cpdp.bg

DZZD BELLISSIMA (hereinafter referred to as the Controller or the Company) operates in accordance with the Personal Data Protection Act and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. This information is intended to inform you about all aspects of the processing of your personal data by the Company and the rights you have in connection with this processing.

Grounds for collecting, processing and storing your personal data

Clarification: In the context of this privacy policy, the term ‘contract’ refers to any interaction between users and the administrator of the website that results in the provision of services, commercial transactions or other types of interactions, including but not limited to purchases, service registrations, inquiries via contact forms, inquiries by phone, subscriptions and other similar actions.

Article 1. The Controller collects and processes your personal data in connection with the use of the website ww.dream-reformer.com and the conclusion of contracts with the Company and provision of services pursuant to Article 6 (1) of Regulation (EU) 2016/679 (GDPR), and in particular on the following basis:

• Explicit consent received by you as a client;
• Fulfilment of the Controller’s obligations related to the provision of services or information;
• Compliance with a legal obligation applicable to the Controller;
• For the purpose of the legitimate interests of the Controller or of a third party;

Purposes and principles for collection, processing and storage of your personal data

Article 2. (1) We collect and process the personal data that you provide to us in connection with the use of the website, the provision of services and the conclusion of a contract with the Company, including for the following purposes:

• conclusion and performance of a contract remotely;
• identification of a party to the contract;
• accounting purposes;
• statistical purposes;
• protection of information security;
• ensuring the performance of the contract for the provision of the relevant services;
• sending a newsletter, if expressly desired by you;

(2) When processing your personal data, we comply with the following principles:

• lawfulness, fairness, and transparency;
• limitation of processing purposes;
• compatibility with the purposes of the processing and minimisation of the data collected;
• accuracy and timeliness of data;
• storage limitation in order to achieve the purposes;
• integrity and confidentiality of the processing and ensuring an appropriate level of security of personal data.

(3) When processing and storing personal data, the Controller may process and store personal data for the purpose of protecting the following legitimate interests of the Controller:

• to fulfil its obligations to the National Revenue Agency, the Ministry of Interior and other state and municipal authorities.

What types of personal data are collected, processed and stored by our Company

Article 3. (1) The Company carries out the following operations with the personal data provided by you for the following purposes:

• Conclusion and performance of a service contract with a client or partner – the purpose of this operation is to conclude, perform and administer a contract with a business partner or a client. Given the limited scope of personal data collected and the fact that some of the data are collected from publicly available sources, impact assessment for this operation is not required.

• Sending newsletters – the purpose of this operation is to administer the process of sending newsletters to clients who have stated that they want to receive them. Given the limited scope of personal data collected, impact assessment for this operation is not required.

• Exercising the right of refusal or filing a complaint – the purpose of this operation is to administer the process of exercising the client’s right of refusal or submitting a complaint. Given the limited scope of personal data collected, impact assessment for this operation is not required.

(2) The Controller processes the following categories of personal data and information for the purposes and on the grounds specified below:

Your identifying data (e.g., e-mail, name, etc.)

Purpose for collecting the data 1) to contact users and send information to users; 2) for the purposes of the services requested by users and 3) to send a newsletter.

Grounds for processing your personal data – By placing an order or requesting a service without registration, or by entering into a written contract with the Controller, a contractual relationship is established, which serves as a basis for processing your personal data – Article 6(1)(b) of GDPR. Your data used for sending newsletters are processed on the basis of your explicit consent – Article 6(1)(a) of GDPR.

• Contact details for deliveries (name, phone number, address, etc.)

Purpose for collecting the data To fulfill the Controller’s obligations under a service contract and to deliver the related materials/goods, if applicable.

Grounds for processing your personal data – By accepting the general terms and conditions or by entering into a written contract with the Controller, a contractual relationship is established, which serves as a basis for processing your personal data – Article 6(1)(b) of GDPR.

• Additional data provided by you – If you want to, you may provide additional data, such as first name, last name, phone number, etc.

Purpose for collecting the data To supplement user information for the performance of services.

Grounds for data processing: You have given your explicit consent to the processing of your personal data for one or more specific purposes – Article 6 (1)(a) of GDPR. Providing these data is not mandatory.

(3) The Controller does not collect or process personal data, which relate to the following:

• revealing racial or ethnic origin;
• revealing political, religious or philosophical beliefs, or membership in trade unions;
• genetic and biometric data, health data or data on sexual life or sexual orientation.

(4) Personal data are collected by the Controller from data subjects.

(5) The Company will not perform automated decision-making based on the data.

Article 4. (1) The Company will carry out the following operations with the personal data you provide as legal representatives or authorised representatives of legal entities - business partners, for the following purposes:

• Conclusion and performance of a service contract: For the conclusion and execution of a commercial transaction with a business entity, we process only the full name of the legal representative or the person authorised by the company.

Conclusion of impact assessment: Considering the small number of data subjects whose data are processed and the limited scope of personal data collected, impact assessment for this operation is not required.

(2) Personal data are collected by the Controller from data subjects and from the Commercial Register at the Registry Agency.

(3) The Company will not perform automated decision-making based on the data.

Article 5. The Controller can use the so-called “cookies” for the purpose of providing full functionality of the website, improving user experience, for statistical purposes, for easier access, etc., which you consent to by using our website. You can control and/or delete the cookies at any time through your browser settings. Cookies do not constitute personal data and are not used to identify visitors and users of the website.

Personal data retention period

Article 6. (1) The Controller will store your personal data for a period no longer than necessary to fulfill contractual obligations or as required by law. Upon expiration of this period, the Controller will take the necessary measures to delete and destroy all your data without undue delay or to anonymise your data (i.e. to render them in a form that does not reveal your identity).

(2) The Controller will process your personal data, which you have provided when placing inquiries, orders, or requested services without registration on the website until their completion, unless you have given your explicit consent at the time of the inquiry, order, or requested service for your data to be processed for the purpose of improving the services, provision of customised content, personalised offers, promotions, as well as for statistical purposes.

(3) The Controller will store your personal data provided in connection with inquiries, orders or requested services made without registration on the website, for a period of 5 years, for the purpose of protecting the Controller’s legal interests in case of judicial or administrative disputes with users of the website.

(4) The Controller will inform you, if the data retention period needs to be extended in order to fulfil a regulatory obligation or in view of the legitimate interests of the Controller or otherwise.

(5) The Controller will store personal data, which the Controller is required to keep in accordance with the applicable legislation for the required period, which may exceed the duration necessary for fulfilling an order or requested service.

Article 7. The Controller will store the personal data of legal representatives of its business partners for the duration of the contract, to comply with the legitimate interests and legal obligations of the Controller, and this retention period may exceed the duration of the concluded contract.

Transfer of your personal data for processing

Article 8. (1) The Controller may, at its own discretion, transfer part or all of your personal data to data processors for processing purposes to which you have agreed, subject to the requirements of the Regulation (EU) 2016/679 (GDPR).

(2) The Controller will notify you in case of intention to transfer part or all of your personal data to third countries or international organisations.

Your rights regarding collection, processing and storage of your personal data

Withdrawal of consent for the processing of your personal data

Article 9. (1) If you do not want personal data provided by you to be processed for marketing purposes and for receiving newsletters, you may withdraw your consent for processing at any time, by completing the withdrawal form in Appendix 1 or by sending us a free-form request by e-mail.

(2) Once we receive your request, we will send to the email address provided by you for receiving newsletters and promotional messages, a letter with detailed instructions for verifying your identity as a newsletter recipient and data subject for whom the withdrawal of consent is being requested.

(3) Withdrawal of consent does not affect the lawfulness of the processing of personal data by the Controller prior to the withdrawal.

Right of access

Article 10. (1) You have the right to request and receive confirmation from the Controller whether personal data concerning you are being processed by sending a free-form request via email.

(2) You have the right to access the data concerning you as well as the information relating to the collection, processing and storage of your personal data.

(3) Once we receive your request, we will send a letter to the e-mail address you used on the website, containing detailed instructions for verifying your identity as the data subject requesting access.

(4) After completing the verification process under section 3 above, the Controller will provide upon request a copy of the processed personal data concerning you, in electronic or another appropriate form.

(5) Access to the data is provided free of charge, but the Controller reserves the right to charge an administrative fee in case of repetitive or excessive requests.

Right of rectification or completion

Article 11. (1) You can rectify or complete any inaccurate or incomplete personal data concerning you at any time by sending a request via email.

(2) You can correct or complete any inaccurate or incomplete personal data concerning you by submitting a request to the Controller by e-mail, using the form in Appendix 4 or by sending a free-form request.

Right to erasure (‘right to be forgotten’)

Article 12. (1) You have the right to request from the Controller the erasure of part or all of the personal data concerning you and the Controller has the obligation to erase such personal data without undue delay where one of the following grounds applies:

• the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
• you withdraw the consent on which the processing is based and there is no other legal ground for processing of the data;
• you object to the processing of your personal data, including for the purposes of direct marketing, and there are no overriding legitimate grounds for processing of the data;
• the personal data have been unlawfully processed;
• the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the Controller is subject;
• the personal data have been collected in relation to the offer of information society services.

(2) The Controller is not obliged to erase personal data, if the data are stored and processed:

• for exercising the right of freedom of expression and information;
• for compliance with a legal obligation which requires processing by Union or Member State law to which the Controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
• for reasons of public interest in the area of public health;
• for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes;
• for the establishment, exercise or defence of legal claims.

(3) To exercise your right to be forgotten, you need to send a request via e-mail for erasure of your personal data processed by the Controller, by filling in the form in Appendix 2 or by submitting a free-form request, then the Controller will send a letter to the e-mail address you used on the website, containing detailed instructions for verifying your identity as the data subject requesting data erasure.

(4) Once we have verified the identity of the person who made the request and the person to whom the data relate, in accordance with the instructions sent to you, we will erase all data concerning you that we process, in accordance with section 3.

(5) If you have made a request or requested services that are being processed, the soonest you can exercise your ‘right to be forgotten’ is after the request or service has been successfully completed.

Right to restriction

Чл. 13. (1) You have the right to request that the Controller restricts the processing of your personal data by sending us a free-form request via email, when:

• the accuracy of the personal data is contested by you, for a period enabling the Controller to verify the accuracy of personal data;
• the processing is unlawful and you oppose the erasure of personal data and request the restriction of their use instead;
• the Controller no longer needs the personal data for processing purposes, but you require the personal data for the establishment, exercise or defence of your legal claims;
• you have objected to processing pending the verification whether the legitimate grounds of the Controller override your interests.

(2) Once we receive your request, we will send you a letter to the e-mail address, which you used to interact with the website, containing detailed instructions for verifying your identity as a website user and as a data subject requesting restriction of processing.

(3) After performing the verification in accordance with section 2, the Company will stop processing your data, but will not remove posts that you might have published on the website, if any.

Right to data portability

Article 14. (1) If you have given consent for the processing of your personal data or if the processing is necessary for the performance of the contract with the Controller, you can:

• request from the Controller to provide you with your personal data in a readable format so you can transmit them to another controller;
• request from the Controller to transmit your personal data directly to another controller specified by you, where technically feasible.

(2) You can exercise the right to data portability by sending us a completed form as per Appendix 3 or a free-form request by e-mail, then the Controller will send you a letter to the e-mail address, which you used to interact with the website, containing detailed instructions for verifying your identity as a website user and as a data subject requesting data portability.

(3) After performing the verification in accordance with section 2, the Company will send you in XML format the data it processes concerning you to the e-mail address you provided.

Right to obtain information

Article 15. You can request from the Controller to inform you about all recipients to whom your personal data, subject to a request for rectification, erasure, or restriction of processing, have been disclosed. The Controller may refuse to provide this information where and insofar as the provision of such information proves impossible or would involve a disproportionate effort.

Right to object

Article 16. You can object at any time to processing of personal data concerning you by the Controller, including if those data are processed for profiling or direct marketing purposes.

Your rights in the event of a personal data breach

Article 17. (1) If the Controller finds a personal data breach that is likely to result in a high risk to your rights and freedoms, you will be notified by the Controller without undue delay about the personal data breach and the measures taken or to be taken.

(2) The Controller is not obliged to notify you, if:

• the Controller has implemented appropriate technical and organisational protection measures in respect of the personal data affected by the personal data breach;
• the Controller has taken subsequent measures which ensure that the breach will no longer result in a high risk to your rights;
• the notification would require disproportionate effort.

Recipients to whom your personal data have been disclosed

Article 18. (1) For the purposes of processing your personal data and ensuring full functionality of the service and in view of your interests, the Controller may provide the data to the following Data Processors:

Data Processor and purpose of the processing of personal data

Google LLC (Google Analytics)
Purpose: We use Google Analytics to collect statistical data about website traffic and user behaviour in order to improve user experience.
Privacy Policy: For more information about how your data is processed, please read: Google Privacy Policy.

Google LLC (Google Search Console)
Purpose: We use Google Maps to display maps and provide location-based services, such as to show addresses and routes.
Privacy Policy: For more information about how your data is processed, please read: Google Privacy Policy.

Google LLC (reCAPTCHA)
Purpose: Protection against automated requests and spam through confirmation tests (CAPTCHA), including collection of data related to interaction with these tests, such as IP address and other browser-related information.
Privacy Policy: For more information about how your data is processed, please read: Google Privacy Policy.

LatePoint LLC (LatePoint Plugin for booking)
Purpose: We use LatePoint to provide booking/appointment functionality – collecting data such as name, email, payment information, IP address, and other details necessary for scheduling appointments, managing agents, services, and locations. The data may also be used for statistics, hosting, support, and analytics to ensure the proper functioning of the service.
Privacy Policy: For details regarding the processing of your data through LatePoint and the entities to whom it may be disclosed as data processors, please read: LatePoint Privacy Policy

Meta Platforms Ireland Ltd. (Facebook Pixel)
Purpose: We use Facebook Pixel to track user activity after interactions with our ads on Facebook. This allows us to measure the effectiveness of advertising campaigns and optimize the content and ads we show to users. The data collected through Facebook Pixel may include information about page visits, device type, IP address, browser, and on-site actions.
Privacy Policy: For more information about how your data is processed, please read: Meta Privacy Policy

Wordfence, Inc. (Wordfence Security)
Purpose: Providing protection against hacking attacks and monitoring website security, including collection of IP address, other browser-related information and active security measures.
Privacy Policy: For more information about how your data is processed, please read: Wordfence Privacy Policy.

Complianz
Purpose: Generating cookie policies and managing consent for the use of cookies in compliance with GDPR, CCPA and other laws.
Privacy Policy: For more information about how your data is processed, please read: Complianz Privacy Policy.

Vimeo, Inc. (Vimeo Video Embed)
Purpose: Embedding videos from Vimeo to provide multimedia content to users. This may include the collection of data such as IP addresses, browser information, and other data related to video viewing.
Privacy Policy: For more information about how your data is processed, please read: Vimeo Privacy Policy.

For more detailed and comprehensive information regarding the processing of your personal data, including the use of cookies and interactions with all third parties, please refer to our COOKIE POLICY. It provides detailed information about all technologies we use to collect and process personal data, including information about cookies and other similar methods.

(2) Data Processors comply with all requirements regarding the lawfulness and security of processing and storage of your personal data.

Article 19. The Controller will not transmit your data to third countries.

Article 20. In the event of a breach of your rights pursuant to the above legislation or the applicable personal data protection legislation, you have the right to file a complaint with the Commission for Personal Data Protection, as follows:

Name: Commission for Personal Data Protection
Seat and registered office Sofia 1952, 2 Prof. Tsvetan Lazarov Blvd
Mailing address: Sofia 1952, 2 Prof. Tsvetan Lazarov Blvd
Phone: 02 915 3 518
Website: www.cpdp.bg

Article 21. You can exercise all your rights regarding the protection of your personal data using the forms attached to this information. Of course, these forms are optional and you can submit your requests in any form, which contains a statement to that effect and identifies you as the data subject.

Article 22. If the consent relates to data transfer, the Controller will describe the possible risks associated with the data transfer to third countries in the absence of an adequacy decision and appropriate safeguards.

Appendix 1

Withdrawal of for Data Processing Consent Form

Your name: ……………………. Your e-mail used on the website: …………………….
Contact information (e-mail)*: …………………….

To
Name: …………………….
UIC/BULSTAT: …………………….
Seat and registered office …………………….
Mailing address: …………………….
Phone: …………………….
E-mail: …………………….
Website: …………………….

I hereby withdraw my consent to the processing of the personal data provided by me for the purpose of receiving newsletters, promotional messages or other marketing materials, and I acknowledge that I am aware of the terms and conditions for withdrawal of consent in accordance with the Mandatory Information on Personal Data Protection Rights available on the website.

In the event of a breach of your rights pursuant to the above legislation or the applicable personal data protection legislation, you have the right to file a complaint with the Commission for Personal Data Protection, as follows:

Name: Commission for Personal Data Protection
Seat and registered office Sofia 1952, 2 Prof. Tsvetan Lazarov Blvd
Mailing address: Sofia 1952, 2 Prof. Tsvetan Lazarov Blvd
Phone: 02 915 3 518
Website: www.cpdp.bg

Appendix 2

Right to Be Forgotten Request – Erasure of My Personal Data

Your name: ……………………. Your e-mail address used for registration or interaction with the website: …………………….
Contact information (e-mail)*: …………………….

To
Name: …………………….
UIC/BULSTAT: …………………….
Seat and registered office …………………….
Mailing address: …………………….
Phone: …………………….
E-mail: …………………….
Website: …………………….

I request all personal data you collect, process and store concerning me, which have been provided by me or third parties, to be erased from your databases based on the provided identification.
I declare that I am aware that some or all of my personal data may continue to be processed and stored by the Controller for the purpose of fulfilling the Controller's legal obligations.

In the event of a breach of your rights pursuant to the above legislation or the applicable personal data protection legislation, you have the right to file a complaint with the Commission for Personal Data Protection, as follows:

Name: Commission for Personal Data Protection
Seat and registered office Sofia 1952, 2 Prof. Tsvetan Lazarov Blvd
Mailing address: Sofia 1952, 2 Prof. Tsvetan Lazarov Blvd
Phone: 02 915 3 518
Website: www.cpdp.bg

Appendix 3

Personal Data Portability Request

Your name: …………………….

Your e-mail address used for registration or interaction with the website: …………………….
Contact information (e-mail)*: …………………….

To
Name: …………………….
UIC/BULSTAT: …………………….
Seat and registered office …………………….
Mailing address: …………………….
Phone: …………………….
E-mail: …………………….
Website: …………………….

I request all personal data you collect, process and store in your database to be sent in XML format to:
e-mail: …………………….
Controller – Data Recipient: …………………….

Name: …………………….
Identification Number (UIC, BULSTAT, Reg. No. with the Commission for Personal Data Protection): …………………….
E-mail: …………………….

In the event of a breach of your rights pursuant to the above legislation or the applicable personal data protection legislation, you have the right to file a complaint with the Commission for Personal Data Protection, as follows:

Name: Commission for Personal Data Protection
Seat and registered office Sofia 1952, 2 Prof. Tsvetan Lazarov Blvd
Mailing address: Sofia 1952, 2 Prof. Tsvetan Lazarov Blvd
Phone: 02 915 3 518
Website: www.cpdp.bg

Appendix 4

Data Rectification Request

Your name: ……………………. Your e-mail address used for registration or interaction with the website: …………………….
Contact information (e-mail)*: …………………….

To
Name: …………………….
UIC/BULSTAT: …………………….
Seat and registered office …………………….
Mailing address: …………………….
Phone: …………………….
E-mail: …………………….
Website: …………………….

I request the following personal data you collect, process and store concerning me, which have been provided by me or third parties, to be rectified as follows:

Data to be rectified:
…………………………………………..
Please rectify the data as follows:
…………………………………………..

In the event of a breach of your rights pursuant to the above legislation or the applicable personal data protection legislation, you have the right to file a complaint with the Commission for Personal Data Protection, as follows:

Name: Commission for Personal Data Protection
Seat and registered office Sofia 1952, 2 Prof. Tsvetan Lazarov Blvd
Mailing address: Sofia 1952, 2 Prof. Tsvetan Lazarov Blvd
Phone: 02 915 3 518
Website: www.cpdp.bg


To find out more about cookies and how we process your personal data through them, as well as how you can manage your consent, please refer to our COOKIE POLICY.