Privacy Policy
This Privacy Policy describes how Crystal Pro Ltd. ("Crystal Pro Jewellery", "we", "us") collects, uses, and discloses your personal information when you visit crystalpro.bg, use our services, or make a purchase from us.
Updates to this Policy
We may periodically update this policy to reflect changes in our practices or legal requirements. The new version is published on the website with a "last updated date" noted.
What information we collect
Information you provide voluntarily:
- Full name, email address, phone number, shipping address
- Order and payment data
- Account login data
- Correspondence with us
Automatically collected information:
- IP address, browser and device type
- Cookies and website behavior
Information from third parties:
- Platforms such as Shopify, payment providers, marketing partners
Purpose and legal basis of processing
We process your personal data based on:
- Your consent — Art. 6, para. 1, letter "a" of the GDPR
- Performance of a contract — Art. 6, para. 1, letter "b"
- Legal obligation — Art. 6, para. 1, letter "c"
- Legitimate interest — Art. 6, para. 1, letter "f"
Purposes include order processing and delivery, customer account maintenance, marketing communication (only with expressed consent), website analysis and improvement, fulfilling legal obligations, and protection against fraud and abuse.
Data retention period
- Up to 5 years — for accounting and tax control purposes
- Up to 1 year — for marketing, or until consent is withdrawn
- For the term of the contractual relationship and up to 6 months thereafter — if necessary to protect our interests
Cookies
We use cookies to improve user experience, for analysis and advertising. You can manage or block cookies through your browser settings.
More information: shopify.com/legal/cookies
Disclosure of Information
We may share information with:
- E-commerce platforms, logistics (Speedy), and payment providers
- Law enforcement authorities when legally required
Data Transfer outside the EU/EEA
Some information may be processed in the USA and other countries through services such as Shopify, Meta, and Google. These transfers are carried out under the Standard Contractual Clauses approved by the European Commission.
Automated Decisions
We do not carry out automated decision-making or profiling within the meaning of Art. 22 of the GDPR.
Children's Personal Data
Our services are not intended for individuals under 16 years of age. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided such data, please contact us immediately.
Security
We implement technical and organizational measures to protect personal data from unauthorized access, loss, alteration, or destruction. Data is stored only as long as necessary for the described purposes and in accordance with the law.
Your Rights
You have the right to:
- Access your personal data
- Correction of inaccurate data
- Erasure ("right to be forgotten")
- Restriction or objection to processing
- Data portability
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
We respond to your requests within 1 month. If necessary, the period may be extended by up to 2 months, of which you will be notified in advance.
Exercise your rights at: crystalpro.office@gmail.com
Complaints
If you believe that we are processing your data unlawfully, you can lodge a complaint with:
Commission for Personal Data Protection — cpdp.bg
Controller and Contact
Crystal Pro Ltd. UIC: BG201292171 📍 Chataldzha Str. 20, entrance A, office 1, Varna 9002, Bulgaria 📧 crystalpro.office@gmail.com 📞 089 551 87 45