Privacy policy

PRIVACY POLICY OF PERSONAL DATA COLLECTION AND PROTECTION BY TWIGGY SHOP

We consider ensuring the right to personal data protection as a fundamental commitment of Twiggy Shop. Therefore, we will use and apply all necessary means and efforts to process your data in full compliance with Regulation (EU) 2016/679 ("General Data Protection Regulation" or "GDPR") and any other applicable legislation.

As transparency is one of the fundamental principles of this legal framework, we have prepared this document to inform you about how we collect, use, transmit, and protect your personal data when you interact with us concerning products and services, including through our website.

We reserve the right to periodically update and modify this Privacy Policy to reflect any changes in the way we process your personal data or changes in your legal requirements. In case of such changes, we will publish the updated version of the Privacy Policy on our website, so we kindly ask you to periodically check its content.

Who we are and how to contact us? Twiggy Shop is the trade name of Twiggy Shop Ltd. with headquarters at: 15 St. Naum Street, Ruse, registered in the Commercial Register with UIC BG203138688 (referred to below as Twiggy Shop or we). For data protection legislation purposes, we are the data controller when processing your personal data.

As your opinions are always important to us, and we are always ready to provide you with additional information you may need regarding the processing of your data, we encourage you to contact the Data Protection Officer via email at data.protection@twiggyshop.eu or by regular mail or courier to the address: 15 St. Naum Street, Ruse, with the text "Attention: Data Protection Officer of Twiggy Shop."

What categories of personal data do we process? In general, we collect your personal data directly from you, allowing you to decide what type of information to provide us. For example, the information we receive from you includes:

  • When creating a profile on Twiggy Shop, you send us your email address, first name, last name, etc.
  • You can add additional information to your personal page (My Account) on the Twiggy Shop platform, such as a photo, gender, nickname, mobile phone number, home phone number, date of birth, education, delivery address, additional email address, dates on bank cards, etc.
  • When placing an order, you provide us with information such as the desired product, your name, delivery address, billing information, payment method, phone number, dates on bank cards, etc.

Additionally, we may collect and subsequently process certain information about your browsing behavior on our website or using the mobile application to personalize your online experience and make suggestions tailored to your profile. We encourage you to learn more about this by reading the processing section below.

On our website and in the mobile application, we may store and collect information through cookies and similar technologies in accordance with the Cookie Policy.

We do not collect or otherwise process sensitive data included in special categories of personal data in the General Data Protection Regulation. Furthermore, we do not wish to collect or process data of minors under the age of 16.

Purposes and Legal Basis of Processing

We will use your personal data for the following purposes:

  1. Providing Services by Twiggy Shop for Your Benefit:

    • Creating and managing a profile on the Twiggy Shop platform.
    • Processing orders, including acceptance, validation, dispatch, and invoicing.
    • Resolving issues related to order cancellations or any other order-related problems, purchased goods, or services.
    • Handling returns of products in accordance with legal provisions.
    • Refunding the value of products according to legal provisions.
    • Providing assistance, including responding to your inquiries regarding your orders or Twiggy Shop's products and services, or marketplace sellers on the Twiggy Shop online platform.

    The processing of your data for these purposes is generally necessary for the conclusion and performance of a contract between Twiggy Shop and you. Additionally, processing in compliance with applicable legislation, including tax and accounting laws, is required for these purposes.

  2. Improving Our Services:

    • Collecting information about your buyer behavior to enhance your online shopping experience.
    • Encouraging you to complete satisfaction surveys after completing a purchase.
    • Conducting market research and studies directly or with the help of partners.

    These activities are based on our legitimate interests in conducting business while always ensuring that your fundamental rights and freedoms are not adversely affected.

  3. Marketing:

    • Keeping you informed about the best offers for products/services you are interested in.
    • Sending various types of messages through electronic communication channels (email/SMS/mobile push/web push, etc.) containing general and thematic information, information about similar products or products complementing your purchases, information about offers and promotions, information about products added to "My Profile/Shopping Cart" sections, or if you have shown interest in purchasing them, and other business communications such as market research and consumer opinion surveys.

    In most cases, we require your prior consent to send you marketing messages. You can change your decision and withdraw your consent at any time by adjusting settings in your customer profile under the "My Personal Data" section, using the "Unsubscribe" link in the messages you receive from us, or by contacting Twiggy Shop using the contact details provided above.

    In certain situations, we may base our marketing activities on our legitimate interest in promoting and developing our business. Regardless, you can, at any time using the means described above, terminate the processing of your personal data for marketing purposes, and we will respond to your request.

  4. Protection of Our Legitimate Interests:

    • Using or disclosing information to protect our rights and business.
    • Implementing measures to protect the website and platform users against cyberattacks.
    • Implementing measures to prevent and detect fraud attempts, including sharing information with competent public authorities.
    • Managing various other risks.

    The primary reason for these types of processing is our legitimate interests related to the protection of our business activities, ensuring that all measures we take maintain a balance between our interests and your fundamental rights and freedoms. Moreover, in some cases, processing by us is based on legal provisions, such as the obligation to protect goods and values stipulated by applicable legislation.

Duration of Personal Data Retention:

As a general rule, we retain your personal data for as long as you have an account with Twiggy Shop. You can always request us to delete specific information or close your account, and we will respond to such requests by retaining certain information even after the account is closed, whenever applicable legislation or legitimate interests require it.

To Whom We Disclose Your Personal Data?

Depending on the case, we may transmit or grant access to some of your personal data to the following categories of recipients:

  • Companies within the group of companies to which Twiggy Shop belongs.
  • Courier service providers.
  • Payment/banking service providers.
  • Marketing/telemarketing service providers.
  • Service providers related to market research.
  • IT service providers.
  • Other companies with which we may develop joint programs for selling our goods and services in the market.

If required by law or necessary to protect our legitimate interests, we may disclose certain personal data to public authorities. We ensure that access to your data by private third-party entities is carried out in accordance with legal provisions in the field of data protection and information privacy, based on contracts concluded with them.

Countries to Which We Transmit Your Personal Data:

Currently, we store and process your personal data in Bulgaria. However, it is possible that some of your personal data may be transferred to entities located within or outside the European Union, including countries for which the European Commission has not recognized an adequate level of personal data protection.

We will always take steps to ensure that any international transfer of personal data is carefully managed to protect your rights and interests. Data transfers to service providers and other third parties will always be protected by contractual obligations and, where appropriate, other safeguards such as standard contractual clauses issued by the European Commission or certification schemes, such as the Privacy Shield for data transfers from the EU to the United States.

You can contact us at any time using the contact details provided above to find out which countries we transmit your data to and what protective measures we apply in connection with these data transfers.

How Do We Protect the Security of Your Personal Data?

We are committed to ensuring the security of personal data by applying appropriate technical and organizational measures in compliance with industry standards. We store your data on secure servers, using the latest encryption algorithms and ensuring backup storage.

We use the PayMill payment processing service to handle payments. All payment information is encrypted using SSL technology.

Despite the measures we take to protect your personal data, we are aware that transmitting information over the internet or other public networks is not entirely secure, with a risk that data may be viewed and used by unauthorized third parties. We cannot assume responsibility for these vulnerabilities in systems beyond our control.

Your Rights:

The General Data Protection Regulation recognizes several rights regarding your personal data. You can request access to your data, correction of errors in our files, and/or object to the processing of your personal data. You also have the right to file a complaint with the relevant supervisory authority or the court. Depending on the case, you may also have the right to request the deletion of your personal data, the right to restrict the processing of your data, and the right to data portability.

More information about each of these rights can be obtained by reviewing the table below. To exercise your rights, you can contact us using the contact details provided above. Please note the following if you wish to exercise these rights:

Identity: We take the privacy of all records containing personal data seriously. For this reason, please send us your requests regarding these records using the email address provided in your Twiggy Shop account. Otherwise, we reserve the right to verify your identity by requesting additional information for confirmation.

Fees: We will not impose a fee for exercising any rights regarding your personal data, except when your request for access to information is unfounded, repetitive, or excessive, in which case we will charge a reasonable amount. We will inform you of any applicable fees before considering your request.

Response Time: We plan to respond to all valid requests within one month, unless the request is particularly complex or if you have made multiple requests, in which case we will respond within a maximum of two months. We will notify you if we need more than one month. We may ask you to tell us exactly what you want to receive or what concerns you. This will help us act more quickly and shorten the response time to your request.

Rights of Third Parties: We will not be required to respond to a request if it adversely affects the rights and freedoms of other data subjects.

Complaints: You have the right to file a complaint with the local supervisory authority regarding the processing of your personal data. In Bulgaria, the contact details for the data protection supervisory authority are as follows:

National Supervisory Authority for Personal Data Processing Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2 Correspondence address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2 Phone: 02 915 3 518 Email: kzld@government.bg, kzld@cpdp.bg Website: www.cpdp.bg

Without prejudice to your right to contact the supervisory authority at any time, please contact us first, and we promise to make every effort to resolve your issues amicably

Automated Decision Making:

You can request not to be subject to a decision based solely on automated processing, but only when that decision:

  • has legal consequences for you; or
  • similarly affects you to a significant extent.

This right does not apply if the decision made after automated decision-making:

  • is necessary for us to enter into or perform a contract with you;
  • is authorized by law, and there are adequate safeguards for your rights and freedoms; or
  • is based on your explicit consent.

Right to Object:

You can object at any time, for reasons related to your specific situation, to the processing of your personal data based on our legitimate interests if you believe that your fundamental rights and freedoms outweigh those interests.

Additionally, you can object at any time to the processing of your data for direct marketing purposes (including profiling) without stating any reasons, in which case the processing will be terminated at the earliest opportunity.

Restriction of Data Processing:

You can ask us to restrict the processing of your personal data, but only if:

  • their accuracy is contested (see the data correction section) to allow us to verify their accuracy; or
  • the processing is unlawful, but you do not want the data to be deleted; or
  • they are no longer needed for the purposes for which they were collected, but we still need to establish, exercise, or defend a legal claim; or
  • you have already exercised the right to object, and it is being verified whether our legitimate grounds still prevail.

We may continue to use your personal data as a result of a request for restriction:

  • if we have your consent; or
  • to establish, exercise, or defend a legal claim; or
  • to protect the rights of Twiggy Shop or another natural or legal person.

Data Deletion:

You can request the deletion of personal data by using the link provided below:

  • Edit Personal Data

Correction: You can request the correction of personal data by using the link provided below:

  • Edit Personal Data

Access: You can review your personal data by using the link provided below:

  • My Personal Data

We remind you that you can contact the Data Protection Officer of Twiggy Shop at any time by sending your request to the following:

You can also use one of the forms below to obtain the requested information:

  • My Personal Data
  • Request for Personal Data
  • Edit Personal Data