Политика за поверителност
The protection of personal data is of great importance to KER TOKI POWER AD, EIK 206117083, and we want the process of processing your personal data to be completely open and transparent to you. That is why we have a Policy that defines how your personal data will be processed and protected.
The privacy policy explains how KER TOKI POWER AD collects and processes your personal data. Personal data means any information or set of information that identifies or could be used to identify the user. This includes information such as first and last name, home address, email address, ID card number, IP address, cookie ID number. This policy explains how we process your personal data, what your rights are, and how the law protects you and your data.
This Privacy Policy applies to your personal data when you visit our web-based site: https://toki.bg/ (the "Site") or use our services available on the Site, and does not apply to other websites/online stores and/or services that we do not own or control.
THE LEGAL FRAMEWORK FOR THE PROTECTION OF PERSONAL DATA
Respecting the confidentiality and protecting your personal data is an important issue for us, which we take into account in all our business relationships. We respect the confidentiality of your personal data and always act in accordance with the provisions of the Personal Data Protection Act and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
April 2016. Over time, there may be other changes that we will need to make to this Privacy Policy, in which case we will notify you each time we make a change to our Privacy Policy. We may need to ask you to accept the changes or give your consent again to the use of your personal data.
Who are we?
The company providing services to you in its capacity as Data Controller is KER TOKI POWER AD, which you can contact at the following address: Sofia, 41 Hristofor Kolumb Blvd., 6th floor ("We"). The purpose of this Privacy Policy is to inform you about the processing of your personal data by us, the processing activities we carry out, the rights you have in relation to your personal data, and the methods of exercising those rights.
You can contact the Data Protection Officer at KER TOKI POWER AD at the following address: Sofia, 41 Hristofor Kolumb Blvd., 6th floor, or by phone: 02/9071620, and email: gdpr@toki.bg. The Data Protection Officer is responsible for providing information about the processing of personal data, including the rights of data subjects, and for ensuring compliance with the provisions of the Personal Data Protection Act and other applicable legislation.
We respect your right to privacy and work continuously to keep the data we process to a minimum and as secure as possible. However, in order for you to use our services, we need to process certain personal data.
DESCRIPTION OF PERSONAL DATA PROCESSED BY US
I. CUSTOMER PERSONAL DATA
Categories of data subjects:
natural persons and/or legal representatives of commercial companies who:
● wish to conclude or have concluded an Individual Contract for the supply of electricity and participation in a standard balancing group, or
● wish to conclude or have concluded a Combined Services Agreement under general terms and conditions.
Categories of personal data we may process: full name; personal identification number; permanent address; correspondence address; email address; telephone number; IP address.
Purposes and legal grounds for processing personal data
We process personal data for the following purposes:
а) Conclusion of a Contract with a Client;
б) Use of the services provided through the Site;
в) Analysis and forecasting of customer consumption;
г) Providing, improving, and maintaining our services—this includes analyzing data, identifying usage trends, and performing calculations and statistical analysis. This data is primarily quantitative, without personalized information;
д) Establishing contact with the Customer and exchanging information.
The legal basis for the processing is the fulfillment of pre-contractual and contractual obligations of KER TOKI POWER AD in connection with the conclusion and/or performance of a contract and consent from the data subject.
Storage period:
а) 5 years after termination of the contract/agreement, and in the case of procedures related to possible disputes that have been initiated but not completed within the 5-year period – until their completion;
б) 10 years for related accounting records and financial statements.
Recipients of personal data
We may share your personal data with the following third parties:
а) ERP;
б) Customs Agency;
в) FSES;
г) NAP;
д) NSI;
е) Accountants and lawyers;
ж) IT service providers;
з) to government and/or law enforcement authorities, if required by applicable law.
II. PERSONAL DATA OF ELECTRICITY PRODUCERS
Categories of data subjects:
individuals and/or legal representatives of commercial companies who:
● wish to conclude or have concluded a Contract for the purchase and sale of electricity, or ● wish to conclude or have concluded a Contract for participation in a balancing group.
Categories of personal data we may process:
full name; personal identification number; permanent address; correspondence address; email address; phone number; bank account; IP address.
PURPOSES AND LEGAL GROUNDS FOR PROCESSING PERSONAL DATA
We process personal data for the following purposes:
a) Conclusion of a Contract with an Electricity Producer;
b) Use of the services provided through the Administrator's websites;
c) Analysis and forecasting of electricity production;
d) Establishing contact with the Electricity Producer and exchanging information.
The legal basis for processing is the fulfillment of pre-contractual and contractual obligations of KER TOKI POWER AD in connection with the conclusion and/or performance of a contract and consent from the data subject.
STORAGE PERIOD:
a) 5 years after the termination of the contract/agreement, and in the case of procedures related to potential disputes that have been initiated but not completed within the 5-year period – until their completion;
b) 10 years for related accounting records and financial statements.
RECIPIENTS OF PERSONAL DATA
We may share your personal data with the following third parties:
а) ERP;
b) Customs Agency;
c) FSES
d) NAP;
e) NSI;
f) Accountants and lawyers;
g) IT service providers
з) to government and/or law enforcement authorities, if required by applicable law.
III. PERSONAL DATA RECEIVED FROM OUR SITE'S CONTACT FORMS
When we receive an inquiry from an individual through one of our contact forms available on the Site or by receiving an email at our email addresses, we will use the contact details provided by the individual (name and email address) to get in touch and provide the information and/or assistance they need.
The personal data received through our contact forms will be stored for up to 1 (one) year after the correspondence is completed.
METHOD OF COLLECTING PERSONAL DATA
We process and use only personal data that is provided voluntarily and personally by you. This means you are responsible for not providing data of third parties in violation of their data protection rights, as we do not have the practical ability to control whether you provide us with third-party data with their knowledge and consent, given in accordance with legal requirements.
DATA PROTECTION
At KER TOKI POWER AD, we have implemented the necessary information security measures to prevent accidental loss, unauthorized use or access to your personal data, alteration, or disclosure. Additionally, we limit access to your personal data to those employees, external service providers, and other third parties who have a legitimate right to access it. They are subject to a confidentiality obligation.
Given the nature of the Internet, we draw attention to the fact that there may be security gaps when transmitting data over the Internet (for example, via email) and that complete protection of data from access by third parties is not possible.
INFORMATION WE SHARE
We do not share information containing personal data with legal entities, organizations, and individuals unless one of the following circumstances applies:
1. With your consent – we will share information containing personal data with legal entities, organizations, and individuals when we have your consent to do so;
2. For performing certain services – with third parties processing personal data – as described above;
3. Legal requirements – we will share information containing personal data with other legal entities, organizations, or individuals if we have reason to believe that access, use, retention, or disclosure of the information is reasonably necessary and/or mandatory for:
● the purposes of applicable law, regulation, in the course of legal proceedings or a final court decision;
● collection of due amounts;
● investigating potential violations;
● detecting, preventing, or otherwise addressing fraud, technical issues, or security problems;
● protection against harm to our rights, property, or safety, our users or the public, as required or permitted by law.
MINORS
We allow our Site and services to be used only by individuals over the age of 18. If we receive information that we have collected personal data from someone under the age of 18, we will immediately delete it unless we are required by law to retain it. Please contact us if you believe we have mistakenly or inadvertently collected information from someone under the age of 18.
YOUR RIGHTS
The General Data Protection Regulation guarantees a certain set of rights that you can exercise in relation to the personal data we process about you. Specifically, you have:
● Right to receive a copy of the information we hold.
● You can request a copy of the personal data we hold about you by sending us an email at: gdpr@toki.bg.
○ We will try to respond to all legitimate requests within one month. Sometimes it may take us longer than a month, in which case we will notify you.
● Right to tell us if the information we hold is incorrect
○ You have the right to question any information we hold about you that you believe is incorrect or incomplete.
○ Please contact us by email at gdpr@toki.bg if you wish to do this, and we will take reasonable steps to verify the accuracy of the information and, if necessary, correct it.
●Tell us that you want us to stop using your personal data. You have the right to: ○ object to the use of your personal data;
○ or request the deletion of your personal data;
○ or request a restriction of processing;
○ or ask us to stop using them if there is no need to do so (known as the 'right to be forgotten').
○ There may be legal grounds for which we need to retain or use your data, which we will share with you when you exercise any of the above rights.
● Withdrawal of consent
○ You can withdraw your consent for us to use your personal data at any time. Please contact us at the email gdpr@toki.bg if you wish to withdraw your consent. If you withdraw your consent, we may not be able to provide you with certain products or services.
CONTACTS
For questions related to this Privacy Policy, please contact: KER TOKI POWER AD
Address: Sofia, 41 Hristofor Kolumb Blvd., 6th floor
Email: gdpr@toki.bg
FILING A COMPLAINT
Please, if you are not satisfied with the way we have used your personal data, let us know by sending us an email at: gdpr@toki.bg
You have the right to complain to the Bulgarian Commission for Personal Data Protection, located at: Bulgaria, 1592, Sofia, Prof. Tsvetan Lazarov Blvd. No. 2; Phone: +359 2 91 53 518; Fax: +359 2 91 53 525; email address: kzld@cpdp.bg, website: https://www.cpdp.bg/.
By browsing and using the features of our Site, you expressly agree that your personal data will be collected and processed by us, while also guaranteeing their accuracy and authenticity. You also declare that you have been informed about the type of personal data we collect and process, the purposes for which they will be used, as well as your right to access, correct, or delete the collected personal data.