PERSONAL DATA PROTECTION POLICY
I. GENERAL PROVISIONS
Art.1.(1) For the purpose of conducting its activities, in accordance with the General Terms published on the website https://entrepreneursnightout.org (the “Website”), hereinafter referred to as the “Terms”, Divine IG Ltd., UIC: 204438425, with its registered office and address in Sofia, Poduyane district, postal code 1836, Levski residential area, zone B, builidng 2, floor 9, apartment 57 (“Divine IG”/”We”/”The Company”), processes data of individuals (“Data Subjects”/”You”/”Your”), in accordance with this Policy.
(2) In processing personal data, Divine IG complies with all applicable legal acts on personal data protection, including the Personal Data Protection Act and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
II. DEFINITIONS
Art.2. In this Policy, the following definitions of terms, derived from Art. 4 of the Regulation, are used:
1. “Regulation” – General Data Protection Regulation 2016/679 of 27 April 2016, replacing Directive 95/46/EC on data protection. It has direct effect and implies changes in the legislation of the member states in the field of personal data protection. Its aim is to protect the “rights and freedoms” of natural persons and to ensure that personal data is not processed without their knowledge, and where possible, that it is processed with their consent.
2. “Personal data” – can be any information that can be linked to an identified or identifiable natural person, directly or indirectly, through the use of one or more specific features or identifiers related to that natural person. From the perspective of the nature of the information, the concept of “personal data” includes any kind of statement about a person. It includes “objective” information and “subjective” information, opinions or assessments. Regarding the form or medium on which this information is contained, the concept of “personal data” includes information in any form, whether alphabetical, digital, graphic, photographic or acoustic. For example, it includes information stored on paper as well as information stored in computer memory.
3. “Special (sensitive) categories of personal data” are a special category of personal data due to the specific nature of the information they reveal about the natural person. In particular, this information reveals racial or ethnic origin, religious and philosophical beliefs, political views, membership in trade union (or professional) organizations, data on the health status of the natural person, biometric data for the sole purpose of identifying a natural person.
4. “Data controller” is Divine IG, which determines the purposes and means of processing personal data.
5. “Data processor” – can be any natural or legal person, public authority or structure, which processes personal data on behalf of and by explicit written assignment of Divine IG. The data processor is always a person external to the structure of the Company and is not in an employment relationship with the Company. The employees of the Company are not data processors. The Company may also act as a Data Processor, in which case it processes the relevant personal data in execution of a written contract with a controller, its documented instructions, and the legal obligations of the Company.
6. “Processing of personal data” means any operation or set of operations performed on personal data, such as collection, recording, organisation, structuring, storage, alteration, use, disclosure by transmission and provision of access, arrangement, erasure or destruction. In practice, any activity involving the use of personal data in any form may constitute processing of personal data.
7. “Data subject” – any living natural person who is the subject of personal data held by the Controller.
III. PRINCIPLES OF PERSONAL DATA PROCESSING
• Lawfulness, fairness and transparency;
• Purpose limitation;
• Data minimisation;
• Accuracy and timeliness;
• Limited storage;
• Integrity and confidentiality.
IV. CATEGORIES OF DATA SUBJECTS
Art.3. In connection with its activities, the Company processes information regarding the following Data Subjects:
1. Website visitors;
2. Registered users and subscribers to paid plans;
3. Individuals participating in the Company’s events and initiatives;
4. Individuals communicating with the Company via the contact form, email, phone, or social networks;
V. PROCESSED PERSONAL DATA
Art.4. The Company processes the following categories of personal data, depending on the specific activity and purpose of processing:
1. Contact and identification data:
o Full name;
o Email address;
o Phone number;
o City and country (if provided);
o Professional information (e.g., position, organisation – where applicable);
2. Data related to event participation and subscriptions:
o Selected subscription plan and activity related to it;
o Registration date and renewal date;
o Event participation history;
o Used discounts or partner offers (if applicable);
3. Communication data:
o Content of messages, inquiries, alerts, or feedback;
o Date, time, and communication channel (e.g., email, contact form, phone);
o Responses provided by the Company;
4. Data automatically collected when using the Website:
o IP address;
o Type of browser and operating system;
o Date and time of access;
o Information on user behaviour (e.g., pages visited, buttons clicked, time spent on the site);
o Data from log files, including logs from security systems;
5. Data related to payments:
o Last 4 digits of the card (if applicable);
o Information from online payment platforms (e.g., PayPal, Stripe), limited to what is necessary to confirm a payment;
6. Data collected through cookies and similar technologies:
o Data detailed in the Cookie Policy, including for sessions, preferences, analytics, and advertising (upon consent);
7. Data processed under legal requirement:
o Data necessary for issuing invoices, accounting documents, and other legally required documents;
8. Security and abuse prevention data:
o Data from security monitoring systems and fraud prevention;
o Data from system logs and security modules (e.g., WAF logs);
VI. PURPOSES AND METHODS OF PROCESSING
Art.5. Divine IG collects, uses, and processes the information described above for the following purposes:
(1) To protect and enforce the legitimate interests of Divine IG. These are purposes related to the legitimate interests of Divine IG and/or third parties such as other users, companies, etc. These purposes include:
For these purposes, it may be necessary to process part or all of the categories mentioned above.
(2) To fulfil contractual obligations to you.
Your personal data may be processed for registration, access to subscription services, participation in events, payment processing, support provision, and other actions arising from your relationship with the Company. This also includes membership administration and communication regarding subscriptions.
(3) Purposes for which you have given your explicit consent. Your data may be processed based on your explicit consent, with processing in this case being specific and to the extent and scope provided in the respective consent.
(4) To fulfil the legal obligations of Divine IG, which include fulfilling statutory obligations to retain or provide information upon receipt of a relevant order from competent state or judicial authorities, ensuring the exercise of control powers by competent state authorities, fulfilling Divine IG’s legal obligations to notify you of various circumstances related to your rights, the services provided, or the protection of your data, etc. For these purposes, it may be necessary to process part or all of the categories mentioned above.
(5) To respond to your inquiries and address your complaints. To resolve submitted complaints, signals, disputes, inquiries, requests, or other issues communicated to us, received through communication from the Website, calls to Divine IG, or sent by regular or electronic mail, we store and process this information, as well as the result of this processing.
(6) For statistical purposes such as analysing the performance of applications on the Website and understanding how visitors use them.
(7) The use of cookies is necessary for the functioning of the Website. You can find a detailed description of the cookies used and their purpose in the Cookie Policy, published on the Website.
(8) Logs related to security, technical support, development, etc., may be used on the Website for the following purposes:
– To ensure reliable operation and identify technical issues;
– To ensure security and detect malicious actions;
– To develop and improve the Website;
– To measure the traffic and usability of the Website;
– Logs required by law.
Server logs, logs from security devices (Web Application Firewalls), and other devices falling into this category. They are stored for a period of up to 1 (one) year. Logs may contain the following information: date and time, URL, browser and device information.
Art.6. The services of Divine IG and the functionalities provided on the Website are not intended for the storage and processing of special categories of personal data within the meaning of Art. 9 and Art. 10 of the Regulation.
Art.7. Divine IG does not collect or process personal data of children under 16 or less, except with parental consent in accordance with applicable local legislation. If we learn that personal data of a child has been inadvertently collected, we will promptly delete the data in question.
VII. RETENTION PERIOD
Art.8. The retention periods for personal data are determined according to the specific purposes of processing, as described in Section VI, and in accordance with legal requirements. Data is retained only for the period necessary to achieve the respective purpose, after which it is deleted or anonymised in a secure manner.
Art.9. Under certain circumstances, Divine IG has the right to anonymise your personal data for research, statistical, or other purposes, in which case the Company may use this information for an unlimited period without further notice to you.
Art.10. When processing is based on consent (e.g., for marketing), data is retained until the consent is withdrawn by the data subject, unless there is another basis for continuing the processing.
Art.11. In cases where we process your personal data based on your consent, including but not limited to marketing purposes, it is processed and stored until we receive a request from you for it to be deleted.
Art.12. In the event of a legal dispute or proceeding requiring the retention of data and/or a request from a competent state authority, it is possible to retain data for longer than the specified periods until the final resolution of the dispute or proceeding at all instances. The specified periods may be changed if a different requirement for retaining information is established according to applicable legislation.
VIII. THIRD PARTIES
Art.13. Your personal data may be provided to third parties in the following cases:
1. when it is provided for by law;
2. if it is duly requested by a competent state or judicial authority;
3. when we have received your explicit consent for this;
4. when it is necessary for the protection of the rights and legitimate interests of Divine IG and/or other users.
Art.14. The company may provide or share personal data with third parties acting as data processors within the meaning of Art. 28 of the GDPR, and/or as independent controllers, when necessary, in compliance with all legal requirements and with appropriate contractual arrangements in place. Such third parties include, but are not limited to:
1. Other companies within the Divine IG network, when necessary for administrative purposes and to provide professional services to our clients (for example, when we provide services involving consultations from other companies within our network in different territories).
2. Third parties and/or organisations that provide us with applications and/or functionalities, IT services, or services related to data processing.
3. Third parties that assist us in providing and managing our internal IT systems. For example, information technology providers, cloud service providers, identity management, website hosting and management, data analysis, data backup, security, and storage services. The servers that power and facilitate this cloud infrastructure are located in secure data centres around the world, and personal data may be stored in any of them;
4. Third parties/organisations that help us in providing services or information in other ways;
5. Auditors and other professional advisers;
6. Law enforcement authorities, other governmental and regulatory agencies, or other third parties as required by and in accordance with applicable law;
Art.15. With regard to personal data regulated by EU legislation, please note that cross-border transfers may involve countries outside the European Economic Area (EEA) and countries that do not have laws providing specific protection for personal data. We have taken steps to ensure that all personal data has the necessary protection and that all transfers of personal data outside the EEA are conducted lawfully. When we transfer personal data outside the EEA to a country not determined by the European Commission to provide an adequate level of personal data protection, the transfers will be conducted in accordance with an agreement following the EU requirements for transferring personal data outside the EEA – such as the European Commission’s approved standard contractual clauses. You can read more about these clauses here.
IX. DATA SUBJECT RIGHTS
Art.16. In accordance with Regulation (EU) 2016/679 (GDPR), every data subject has the following rights:
– Right to be informed.
This Policy aims to inform you in detail about the processing of your personal data in connection with the Services provided.
– Right of access.
You have the right to obtain confirmation as to whether your personal data is being processed, access to it, and information regarding its processing and your rights in relation to it. You can exercise such access at any time.
– Right to rectification.
You have the right to rectify your personal data if it is incomplete or inaccurate.
You have the opportunity to correct your data at any time by making a request to us.
– Right to erasure (“right to be forgotten”).
You have the right to request the deletion of data, except in cases where there is a substantial reason and/or legal obligation for its processing.
The data is deleted after the specified period expires. In the meantime, it can only be provided in due course to competent state authorities exercising their control powers or to a competent court in the event of a legal proceeding in which they are involved. In the event of a legal dispute or proceeding requiring the retention of data and/or a request from a competent state authority, it is possible to retain data for longer than the specified periods until the final resolution of the dispute or proceeding at all instances.
– Right to restriction of processing.
The regulation provides the possibility to restrict the processing of your personal data if there are grounds for this, as provided in it.
– Right to notify third parties.
If applicable, you have the right to request from the Controller of your personal data to notify third parties, when he has provided your data, regarding the rectification, erasure, or restriction of the processing of your personal data.
It is important to note that Divine IG is not an intermediary in the relationships between you and other parties.
– Right to data portability.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to use this data for another controller at your discretion.
– Right not to be subject to automated decision-making.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless there are grounds provided in the applicable data protection legislation for this and appropriate safeguards are in place to protect your rights, freedoms, and legitimate interests.
The website does not use technologies that fall into this category.
– Right to withdraw consent.
You have the right, at any time, to withdraw your consent for the processing of personal data that is based on your given consent. Such withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
For services such as email subscription for announcements, which are based on your desire (consent), there is an option to terminate the subscription at any time (withdrawal of consent).
– Right to object.
You have the right to object to the processing of your personal data based on public interest, official authority, or legitimate interest.
In the event of such an objection, we will consider your request and, if justified, we will comply with it. If we believe there are compelling legal grounds for the processing or that it is necessary for the establishment, exercise, or defence of legal claims, we will inform you of this.
– Right to lodge a complaint.
You have the right to lodge a complaint with a supervisory or judicial authority if you believe that the processing of personal data relating to you violates applicable data protection legislation. The supervisory authority in the Republic of Bulgaria is the Commission for Personal Data Protection, with address: Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd. Website: https://www.cpdp.bg
You can exercise your rights by written request to the email: info@entrepreneursnightout.org or via the postal address of the Company, indicated at the beginning of this Policy.
X. ACCURACY OF INFORMATION.
Art.17. Divine IG is not responsible for the accuracy of the data provided by you, does not conduct checks in this regard, and does not guarantee the actual identity of the individuals who have provided the data. In all cases of doubt on your part, of established fraud and/or abuse, please notify us immediately. You undertake, when providing any information on the website, not to violate the rights of other persons in connection with the protection of their personal data or other rights.
XI. OTHER
This personal data protection policy is prepared in two identical copies, in Bulgarian and English, and in case of discrepancy between the Bulgarian and English text, the Bulgarian text shall prevail.
This Policy comes into effect from 02 April, 2025.