Privacy policy
Grand Lodge of Ancient Free and Accepted Masons in Bulgaria – an association registered in the territory of the Republic of Bulgaria, with headquarters and address of management: Sofia, Vitosha District, 5 "Sredorek" St., email: office@glafam.bg
In connection with its activities – uniting and coordinating the activities of all Regular Lodges of Ancient Free and Accepted Masons in Bulgaria, preparing and implementing projects in accordance with Article 7; participating in national and international initiatives, publishing activities, and charity – the Grand Lodge of Ancient Free and Accepted Masons in Bulgaria ("the Association") processes data, some of which are personal data, according to the Personal Data Protection Act and Regulation (EU) 2016/679, thus it has the quality of administrator of personal data. This policy aims to inform users of www.glafam.bg about how their personal data is processed, their rights, the methods for protecting personal data used by the administrator, to whom the Association has the right to provide the collected personal data, as well as the methods for exercising the rights of data subjects.
2. Introduction:
GDPR is the General Data Protection Regulation (Regulation 2016/679 of the European Parliament and Council). The regulation significantly increases the rights of European citizens and consequently imposes more obligations on organizations that collect and process personal data. It came into effect on May 25, 2018, and will apply in all EU member states. Personal data is collected for specific, explicitly stated, and legitimate purposes and is not processed further in a manner incompatible with those purposes. Processing is carried out lawfully, fairly, and transparently concerning the data subject.
3. Objectives and scope of the policy:
With this Privacy Policy, the Grand Lodge of Ancient Free and Accepted Masons in Bulgaria acknowledges the confidentiality and inviolability of personal data. In accordance with the legislation and good practices, the Association implements the required technical and organizational measures to protect the personal data of individuals.
This Privacy Policy aims to inform individuals about the purposes of processing personal data, the recipients or categories of recipients to whom the data may be disclosed, the mandatory or voluntary nature of providing the data and the consequences of refusal to provide them, information about the right of access and correction of the collected data.
4. Glossary of terms:
“Personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person;
“Genetic data” means personal data related to the inherited or acquired genetic characteristics of a natural person, which provide unique information about the distinguishing features or health of that person and which are obtained, in particular, from the analysis of a biological sample from that person;
“Biometric data” means personal data resulting from specific technical processing, which relates to the physical, physiological, or behavioral characteristics of a natural person and which allow or confirm the unique identification of that natural person, such as facial images or fingerprint data;
“Consent of the data subject” means any freely given, specific, informed, and unambiguous indication of the wishes of the data subject, by means of a statement or a clear affirmative action, which signifies the data subject's agreement to the processing of personal data relating to them;
“Processing” means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
“Administrator” means a natural or legal person, public authority, agency, or other body that alone or jointly with others determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union law or the law of a member state, the administrator or specific criteria for its designation may be provided for in Union law or the law of a member state;
“Data processor” means a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the administrator;
“Representative” means a natural or legal person established in the Union, designated by the administrator or data processor in writing in accordance with Article 27, representing the administrator or data processor regarding their respective obligations under Regulation (EU) 2016/679;
“Recipient” means a natural or legal person, public authority, agency, or other body to whom personal data are disclosed, whether a third party or not. However, public authorities that may receive personal data in the context of a specific inquiry in accordance with Union or member state law are not regarded as “recipients”; the processing of such data by the mentioned public authorities shall be in accordance with the applicable rules on data protection in line with the purposes of the processing;
“Supervisory authority” means an independent public authority established by a member state and responsible for monitoring the application of Regulation (EU) 2016/679.
“Personal data breach” means a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.
“Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal qualities related to a natural person and, in particular, to analyze or predict aspects concerning the performance of that natural person's professional duties, their economic situation, health, personal preferences, interests, reliability, behavior, location, or movements;
5. Basic principles related to the processing of personal data that we adhere to:
- Lawful, fair, and transparent processing of personal data;
- Processing of personal data for specific purposes;
- Data minimization;
- Accuracy and maintenance of up-to-date information;
- Storage limitation;
- Integrity and confidentiality;
- Accountability.
6. Purpose of processing:
The Grand Lodge of Ancient Free and Accepted Masons in Bulgaria processes personal data for the implementation of activities – uniting and coordinating the activities of all Regular Lodges of Ancient Free and Accepted Masons in Bulgaria, preparing and implementing projects according to Article 7; participating in national and international initiatives, publishing activities, and charity. Personal data is collected for specific, legally defined purposes and must be processed lawfully and fairly. Data is not processed further in a manner incompatible with these purposes. Further processing of personal data for archiving purposes in the public interest, for scientific or historical research, or for statistical purposes is not considered incompatible with the initial purposes.
The Association does not collect personal data for marketing and advertising purposes. The data collected by the Grand Lodge of Ancient Free and Accepted Masons in Bulgaria is solely with the explicit, freely, clearly, and informed consent of the user, which they have indicated when reading this Privacy Policy.
Outside the aforementioned purposes and in relation to the principles outlined in Article 5 of Regulation (EU) 2016/679, the Grand Lodge of Ancient Free and Accepted Masons in Bulgaria does not collect and does not process any other personal data of its employees, partners, and clients. The Association does not process personal data for the purpose of automated decision-making, including “profiling.” The organization collects data directly from the data subject.
7. The Association processes personal data only when:
- It has obtained clear, freely, informed, and unambiguous consent from the data subjects, who have been informed about how their personal data will be used in this policy;
- There is a contractual obligation to fulfill a contract where one party is a natural person (when the Association processes data of its employees);
- When processing is necessary for the performance of a task carried out in the public interest (under EU or national legislation).
8. What data is collected and processed:
Important: The Grand Lodge of Ancient Free and Accepted Masons in Bulgaria does not collect or process sensitive personal data of its clients and users of the website www.glafam.bg.
The data collected and processed includes:
Name and surname of the user – for the purpose of identifying the user in case of inquiries;
Email address – for quick and easy correspondence;
Phone – for contact when necessary;
Other data, permissible under the Regulation, if necessary for fulfilling the Association's obligations or related to a specific service.
The provider of personal data has the right not to share all the requested personal data. In cases where this personal data is necessary for the execution of a specific service, a particular specialized function, or an effective response to an inquiry (excluding direct marketing) – the Grand Lodge of Ancient Free and Accepted Masons in Bulgaria will not be able to fulfill the request due to the lack of data, for which the user is explicitly notified through the personal data policy.
9. Recipients of personal data to whom the Association has the right to disclose data:
The Association provides personal data to the competent state authorities and institutions when required by the country's legislation and in accordance with the rules defined therein (for example: National Revenue Agency, National Social Security Institute, Employment Agency, judicial and investigative authorities, health institutions, etc.). It also provides personal data to individuals from accounting firms, banking institutions, HR agencies, and mobile operators for legally established purposes or those specified in a contract concluded with the parties.
The personal data of users of www.glafam.bg is not provided to third parties, outside the legal requirements. The organization does not provide personal data to parties outside the European Union.
10. Rights of individuals – data subjects:
The measures taken to protect personal data in accordance with the requirements of Regulation (EU) 2016/679 are aimed at ensuring the protection of the rights of the subjects of personal data, namely:- Right of access;
- Right to correct inaccurate or incomplete data;
- Right to erasure (the right "to be forgotten"), if the conditions of Art. 17 of Regulation (EU) 2016/679 are met;
- Right to restriction of processing;
- Right to data portability, if the conditions for portability under Art. 20 of Regulation (EU) 2016/679 are met;
- Right to object if the conditions of Art. 21 of Regulation (EU) 2016/679 are met;
- Right to appeal to the Personal Data Protection Commission or the District Court
- Right for the data subject not to be subject to a decision based solely on automated processing, including profiling;
11. Security of personal data:
Data storage period:As a personal data controller, the Grand Lodge of Ancient Free and Accepted Masons in Bulgaria processes data for a period as provided for in the current legislation and in accordance with the principle of storage limitation.
The remaining data is stored for different periods, depending on the type of data determining the legal obligation for processing, including its storage.The storage criteria are:- in the case of a query from the website form, the data is kept for 12 months, or until necessary, in order to clarify all aspects of the query itself and to give the user a satisfying answer.
- the personal data of the workers/employees of the Grand Lodge of Ancient Free and Accepted Masons in Bulgaria is stored and processed for a longer period because of the requirements of the Accounting Act;
12. Personal data breach:
In the event of a personal data breach, the Grand Lodge of Ancient Free and Accepted Masons in Bulgaria will notify the supervisory authority within 72 hours after becoming aware of the breach unless it is unlikely to result in a risk to the rights and freedoms of individuals. If the personal data breach is likely to result in a high risk to the rights and freedoms of individuals, the Grand Lodge of Ancient Free and Accepted Masons in Bulgaria will also notify the affected individuals without undue delay.
13. Changes to the Privacy Policy:
The Grand Lodge of Ancient Free and Accepted Masons in Bulgaria has the right to make changes to this Privacy Policy at any time. The updated version of the Privacy Policy will be published on the official website of the organization, and the date of the last update will be indicated. The users of www.glafam.bg are obliged to check the policy regularly to stay informed about the current version.
THE GRAND LODGE OF