Mandatory Information on Personal Data Protection Rights

General Information



As of May 25, 2018, the new General Data Protection Regulation (EU) 2016/679, also known as GDPR, adopted by the European Union, enters into force. The Regulation aims to ensure the protection of the personal data of individuals from all EU Member States and to harmonize regulations regarding its processing.



As a personal data controller providing intermediary services in the purchase, sale, rental, and leasing of real estate, Unique Estates complies with all requirements of the new regulation, collecting only the necessary data required to provide the service and storing it responsibly and lawfully.



Information about the Personal Data Controller:



Company Name: "Unique Estates" Ltd.

UIC: 175085752

Registered Office Address: Sofia 1142, Sredets District, 17 Patriarch Evtimiy Blvd.

Business Address: Sofia 1142, Sredets District, 17 Patriarch Evtimiy Blvd.

Correspondence Address: Sofia 1142, Sredets District, 17 Patriarch Evtimiy Blvd.

Email: office@ues.bg

Phone: 088/260 0600, 02/819 2020

Personal Data Administrator Certificate No: 256538

Information about the Data Protection Officer:



Officer: Legal Advisor Milen Marinov

Correspondence Address: Sofia 1000, 17 Patriarch Evtimiy Blvd.

Phone: 088/481 0989

Email: legal@ues.bg



Information about the Competent Supervisory Authority:



Name: Commission for Personal Data Protection

Registered Office Address: Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd.

Correspondence Address: Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd.

Phone: 02/915 3518

Email: kzld@government.bg, kzld@cpdp.bg

Website: www.cpdp.bg



“Unique Estates” Ltd. conducts its activities in accordance with the Personal Data Protection Act and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

Legal Grounds for Collecting, Processing, and Storing Your Personal Data:



Art. 1. (1) Unique Estates collects and processes your personal data in connection with the provision of intermediary services for the purchase, sale, rental, and leasing of real estate, for which contracts are concluded with the company on the basis of Article 6, Paragraph 1 of Regulation (EU) 2016/679, specifically on the following grounds:



• Explicit consent received from you as a client;

• Fulfillment of Unique Estates' obligations under a contract with you;

• Compliance with a legal obligation applicable to Unique Estates;

*Example: under the Measures Against Money Laundering Act (MAMLA), under which the company is an obligated entity;

• For the purposes of Unique Estates’ legitimate interests.



(2) Unique Estates is a data controller in relation to your personal data as a user of our services. For personal data that you process while using our services, Unique Estates acts as a data processor.

Purposes and Principles of Collecting, Processing, and Storing Your Personal Data:



Art. 2. (1) Unique Estates collects and processes the personal data you provide in connection with the use of our services, for concluding a contract with the company, as well as for registering to participate in our events, including for the following purposes:



• Creating a customer profile and ensuring full functionality in the provision of our services;

• Identification of the contracting party;

• Event registration organized by Unique Estates;

• Accounting purposes;

• Statistical purposes;

• Ensuring the execution of the service provision contract;

• Sending informational messages, invitations, notices of service changes, newsletters about properties whose features match criteria defined by the client, etc.;

• Improving and personalizing the service by offering suitable offers, events, and other products and services that may be of interest to you.



(2) Unique Estates complies with the following principles when processing your personal data:



• Lawfulness, fairness, and transparency;

• Purpose limitation;

• Data minimization;

• Accuracy and data up-to-date status;

• Storage limitation for achieving the purposes;

• Integrity and confidentiality of processing and ensuring an appropriate level of personal data security.



(3) When processing and storing personal data, Unique Estates may do so to protect the following legitimate interests:



• Fulfillment of its obligations to the National Revenue Agency, Ministry of Interior, Cybercrime Unit, and other national and municipal authorities.

What Types of Personal Data Does Unique Estates Collect, Process, and Store?



Art. 3. (1) Unique Estates performs the following operations with personal data for the following purposes:



• Registering a customer profile to provide intermediary services related to real estate. The purpose of this operation is to create a profile linked to the service used, which includes information about the client’s property searches and offers. Impact assessment conclusion: Based on the impact assessment, the Data Protection Officer considers that the operation “Concluding an intermediary service contract” is permissible and provides sufficient guarantees for the protection of the rights and legitimate interests of data subjects in accordance with GDPR.

• Concluding and performing a business transaction with a client or partner – the purpose of this operation is to conclude and fulfill a contract and its administration;

• Sending informational messages – the purpose of this activity is to manage the process of sending updates to clients regarding changes in services, deadlines, terms, obligations, or non-performance under the intermediary contract;

• Sending newsletters – the purpose of this operation is to manage the process of sending newsletters to clients who have subscribed.



(2) Unique Estates processes the following categories of personal data for the following purposes and on the following legal bases:



A/ Data: Your identifying data (full name, personal number or place and date of birth for foreign nationals, data and/or copy of ID document, mailing address, email, and phone number)



B/ Purpose for collecting the data:

1) Client registration;

2) Communication with the client and sending information, including newsletters and marketing communications, upon request.



(3) Unique Estates does not collect or process personal data that:

• reveal racial or ethnic origin;

• reveal political, religious, or philosophical beliefs, or trade union membership;

• are genetic and biometric data, health-related data, or data about sexual orientation or sex life.



(4) Personal data are collected by Unique Estates directly from the individuals to whom they relate.



(5) The company does not perform automated decision-making with personal data.

Retention Period of Your Personal Data:



Art. 4. (1) Unique Estates retains your personal data for no longer than the duration of your contractual relationship with the company. After this period, Unique Estates takes the necessary steps to delete and destroy all your data without undue delay.



(2) Unique Estates will notify you if the data retention period needs to be extended to achieve the purposes, perform the contract, or due to the company's legitimate interests or other legal grounds.



(3) Unique Estates stores personal data that must be retained under applicable legislation for the statutory period, which may exceed the duration of your registration.



Transfer of Your Personal Data for Processing:



Art. 5. (1) Unique Estates may, at its discretion, transfer some or all of your personal data to processors in order to fulfill the purposes of processing, in compliance with Regulation (EU) 2016/679.



(2) Unique Estates will inform you in the event of an intention to transfer some or all of your personal data to third countries or international organizations.

Your Rights Regarding the Collection, Processing, and Storage of Your Personal Data:



Withdrawal of Consent for Processing Personal Data



Art. 6. (1) If you do not wish some or all of your personal data to continue being processed by Unique Estates for specific or all processing purposes, you may withdraw your consent at any time by submitting a “Notice of Withdrawal of Rights in accordance with Regulation (EU) 2016/679 of 27.04.2016, Section 1, Article 12, Paragraph 4.”



(2) Unique Estates may request verification of your identity and confirmation that you are the data subject.



Right of Access



Art. 7. (1) You have the right to request and receive confirmation from Unique Estates as to whether personal data concerning you is being processed.



(2) You have the right to access your data, as well as information about the collection, processing, and storage of that data.



(3) Upon request, Unique Estates provides a copy of the processed personal data concerning you in electronic or other suitable format, based on a “Request for Confirmation and Access to Processed Personal Data in accordance with Regulation (EU) 2016/679 of 27.04.2016, Section 2, Article 15.”



(4) Access is free of charge, but Unique Estates reserves the right to charge an administrative fee in cases of repetition or excessive requests.

Right to Rectification or Completion



Art. 8. You can rectify or complete inaccurate or incomplete personal data related to you by completing and submitting a “Request for Rectification of Processed Personal Data, in accordance with Regulation (EU) 2016/679 of April 27, 2016, Section 2, Article 16.”



Right to Erasure (‘Right to be Forgotten’)



Art. 9. (1) You have the right to request that Unique Estates delete personal data related to you, and Unique Estates is obligated to delete such data without undue delay when one of the following grounds applies:

• The personal data is no longer necessary for the purposes for which it was collected or otherwise processed;

• You withdraw your consent on which the processing is based, and there is no other legal ground for the processing;

• You object to the processing of the personal data, including for direct marketing purposes, and there are no overriding legitimate grounds for the processing;

• The personal data has been unlawfully processed;

• The personal data must be erased to comply with a legal obligation under EU or Member State law applicable to Unique Estates;



(2) Unique Estates is not obligated to delete personal data if it processes the data:

• For exercising the right to freedom of expression and information;

• For compliance with a legal obligation requiring processing under EU or Member State law, or for performing a task carried out in the public interest or in the exercise of official authority;

• For reasons of public interest in the area of public health;

• For archiving purposes in the public interest, scientific or historical research, or statistical purposes;

• For the establishment, exercise, or defense of legal claims.



(3) To exercise your right to erasure, you must submit a “Request for Deletion of Processed Personal Data, in accordance with Regulation (EU) 2016/679 of April 27, 2016, Section 2, Article 17.”



(4) Unique Estates does not delete data it is legally obligated to retain, including for legal defense or to prove its own rights.

Right to Restriction of Processing



Art. 10. You have the right to request that Unique Estates restrict the processing of your data by submitting a “Request for Restriction of Processing of Personal Data, in accordance with Regulation (EU) 2016/679 of April 27, 2016, Section 2, Article 18,” when:

• You contest the accuracy of the personal data, for a period enabling Unique Estates to verify the accuracy;

• The processing is unlawful but you oppose the erasure of the personal data and request restriction instead;

• Unique Estates no longer needs the personal data for the purposes of the processing, but you require it for the establishment, exercise, or defense of legal claims;

• You have objected to processing pending verification of whether Unique Estates’ legitimate grounds override yours.



Right to Data Portability



Art. 11. (1) You may at any time download the data stored and processed about you in relation to your use of Unique Estates services by submitting a “Request for Transfer of Processed Personal Data, in accordance with Regulation (EU) 2016/679 of April 27, 2016, Section 2, Article 20.”



(2) You may also request that Unique Estates directly transfer your personal data to another controller you specify, where technically feasible.



Right to Receive Information



Art. 12. You may request that Unique Estates inform you of all recipients to whom personal data, subject to rectification, erasure, or restriction of processing, has been disclosed by submitting a “Request for Notification upon Rectification, Erasure, or Restriction of Processing of Personal Data, in accordance with Regulation (EU) 2016/679 of April 27, 2016, Section 2, Article 19.” Unique Estates may refuse to provide this information if it proves impossible or requires disproportionate effort.

Right to Object



Art. 13. You may object at any time to the processing of your personal data by Unique Estates, including if it is processed for profiling or direct marketing purposes, by submitting an “Objection to the Processing of Personal Data, in accordance with Regulation (EU) 2016/679 of April 27, 2016, Section 2, Article 21.”



Your Rights in Case of a Personal Data Breach



Art. 14. (1) If Unique Estates becomes aware of a personal data breach that may pose a high risk to your rights and freedoms, we will notify you without undue delay about the breach, as well as the measures taken or to be taken, via a “Personal Data Breach Notification, in accordance with Regulation (EU) 2016/679 of April 27, 2016, Section 2, Article 33, Paragraph 1.”



(2) Unique Estates is not obliged to notify you if:

– It has implemented appropriate technical and organizational protection measures regarding the data affected by the breach;

– It has subsequently taken actions to ensure that the breach will not pose a high risk to your rights;

– Notification would involve disproportionate effort.

Entities to Whom Your Personal Data Is Disclosed



Art. 15. For the purpose of company accounting, in accordance with the legal requirements in the Republic of Bulgaria, and upon request by the NRA, Cybercrime Directorate, and other competent authorities, as well as for statistical or other purposes not contrary to the Regulation.



Art. 16. The controller does not transfer your data to third countries.



Other Provisions



Art. 17. If your rights under this document or applicable personal data protection legislation are violated, you have the right to file a complaint with the Commission for Personal Data Protection. Contact details are listed above.



Art. 18. You may exercise all your rights regarding the protection of your personal data by using the forms attached to this document. Of course, using the forms is not mandatory — you may submit a request in any form that includes a statement of intent and identifies you as the data subject.



Art. 19. If the consent relates to data transfer, the controller shall describe the possible risks of transferring the data to third countries in the absence of an adequacy decision and appropriate safeguards.



Art. 20. When you instruct Unique Estates to process personal data of a third party for the purposes of using the service, Unique Estates acts as a personal data processor.

What Security Measures Has Unique Estates Taken Regarding the Personal Data Stored on Our Infrastructure?



The security of all types of information, including personal data stored on our infrastructure, is a top priority for us as a company. Security is something we cannot afford to compromise on.



In addition to making every effort to fully comply with the new data protection regulation, three years ago we implemented a completely new security system developed specifically for us to protect our entire infrastructure.



Also, three years ago we implemented a full-scale DDoS protection system. This DDoS protection system detects 95% of known types of DDoS attacks and is continuously updated to reflect newly identified threats. With these measures, we are able to block potential malicious attempts targeting the information stored on our servers.



Last updated: September 24, 2021

Information under the ZZLPSPOOIN | Unique Estates