This Policy sets out the principles and rules applied by “OPTIMUM PLAN” Ltd. when processing personal data in accordance with Regulation (EU) 2016/679 (GDPR), the Personal Data Protection Act and the applicable European and Bulgarian legislation. The purpose of the Policy is to ensure lawful, fair, transparent and secure processing of personal data.
This Policy governs the internal rules and organisational principles for the processing and protection of personal data by “OPTIMUM PLAN” Ltd.
The Policy aims to ensure compliance with applicable legislation, limit risks to the rights and freedoms of natural persons and establish clear responsibilities when handling personal data.
The personal data controller is “OPTIMUM PLAN” Ltd., UIC 207907479.
Registered office and management address: 9006 Varna, Primorski District, Sts. Constantine and Helena residential complex, 67th Street No. 4, entrance B, floor 2, apartment 26.
E-mail: office.optimumplan@gmail.com
Telephone: 0897 924 007
“OPTIMUM PLAN” Ltd. processes personal data in compliance with the principles of lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
Personal data are processed only for specific, explicitly stated and legitimate purposes and are not further processed in a manner incompatible with those purposes.
The Company may process personal data relating to clients and prospective clients; suppliers and counterparties; representatives and employees of legal entities; job applicants; employees and persons engaged under civil law contracts; visitors to the website; and other persons entering into contractual, pre-contractual or legally regulated relationships with the Company.
Depending on the specific activity, the following may be processed: identification data; contact details; contractual and commercial data; payment and accounting data; professional data; correspondence; and technical data, including IP address, logs and cookie data.
Special categories of personal data are processed only where this is necessary, lawful and supported by an appropriate legal basis and additional safeguards.
Personal data may be processed for the provision of services; communication and customer service; preparation of offers; conclusion, performance and termination of contracts; accounting and tax reporting; compliance with legal obligations; protection of legitimate interests and legal claims; recruitment; and maintenance and improvement of the website and information systems.
Processing is carried out on one or more of the grounds set out in Article 6 of the GDPR: consent; taking steps prior to entering into a contract or performance of a contract; compliance with a legal obligation; protection of vital interests; performance of a task carried out in the public interest, where applicable; or the legitimate interests of the Company or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.
Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.
Personal data are retained only for the period necessary to achieve the purposes for which they were collected or for the period required by applicable law.
After the applicable periods expire, the data are securely erased, destroyed or anonymised, unless another valid legal basis exists for their continued retention.
Where necessary, personal data may be disclosed to accounting and legal advisers; banks and payment institutions; IT and hosting providers; courier and postal operators; insurers; state and municipal authorities; courts; and other competent institutions.
Where an external provider processes personal data on behalf of the Company, the relationship shall be governed by a contract or other legal act in accordance with Article 28 of the GDPR.
The Company implements appropriate technical and organisational measures taking into account the nature, scope, context and purposes of the processing, as well as the likelihood and severity of the risk to the rights and freedoms of natural persons.
The measures may include access controls; individual user accounts and secure passwords; backups; antivirus protection; encryption where necessary; physical protection of documents and devices; access restrictions based on job functions; periodic review of access rights; and staff training and awareness.
Employees and other persons who have access to personal data must process them only within the scope of their assigned functions and in compliance with confidentiality obligations.
Access to personal data is granted on a “need-to-know” basis and is terminated when the relevant employment or contractual need ceases to exist.
Where a security breach is suspected or established, immediate action shall be taken to limit the consequences, identify the causes, document the incident and prevent recurrence.
Where the statutory conditions are met, the competent supervisory authority shall be notified without undue delay and, where applicable, no later than 72 hours after the Company becomes aware of the breach. Affected data subjects shall be notified where there is a high risk to their rights and freedoms.
Every data subject has the right to information; access; rectification; erasure; restriction of processing; data portability; objection; withdrawal of consent; the right not to be subject to a decision based solely on automated processing where the conditions under the GDPR are met; the right to lodge a complaint with the Commission for Personal Data Protection; and the right to judicial remedy.
Requests relating to the exercise of rights under the GDPR may be sent to office.optimumplan@gmail.com or to the Company’s address.
The Company may request additional information to verify the identity of the applicant. Requests shall be considered within the time limits and subject to the conditions laid down in the GDPR.
As a rule, the Company does not transfer personal data outside the European Economic Area.
Where such a transfer is necessary, it shall be carried out only on the basis of an adequacy decision, appropriate safeguards, an applicable derogation or another valid basis under Chapter V of the GDPR.
The Company maintains the documentation required for its processing activities where this is required by law and periodically reviews the effectiveness of the measures implemented.
Where there are changes in the activities, technologies, risks or regulatory requirements, this Policy and the related procedures shall be updated.
This Policy may be amended in the event of changes to legislation, the Company’s activities, the technologies used or the manner in which personal data are processed.
The current version shall be approved by the Company’s manager and shall apply from the date indicated at the end of the document.
This Policy shall apply together with the General Terms and Conditions, the Privacy Policy, the Cookie Policy and the Company’s other internal rules.
Any matters not expressly regulated herein shall be governed by Regulation (EU) 2016/679, the Personal Data Protection Act and the applicable Bulgarian legislation.
CONTACT DETAILS
“OPTIMUM PLAN” Ltd.
UIC: 207907479
9006 Varna, Primorski District, Sts. Constantine and Helena residential complex, 67th Street No. 4, entrance B, floor 2, apartment 26
E-mail: office.optimumplan@gmail.com
Telephone: 0897 924 007
Website: https://www.optimum-plan.com
Last updated: 28 July 2026