Personal data protection in SuperHosting.BG

We are fully compliant with GDPR.

General information

The European Union’s General Data Protection Regulation ("GDPR"), coming into effect in 25 May 2018, lays out a new set of rules for how the personal data of people living within the EU should be handled. It sets out the protection of personal data as a guaranteed right for all citizens across EU.

As a personal data processor when offering hosting services, SuperHosting.BG is compliant with all the requirements of the regulation and meets the high standards "Data privacy by design and by default". Only the required legal minimum of personal data is gathered, processed and kept secure with the appropriate technical and organisational measures.


Information about the Controller
  1. Name SuperHosting.BG Ltd.
  2. UIC/BULSTAT :131449987
  3. Seat and registered address: Iztok Residential area, 36 G. M. Dimitrov Blvd., Izgrev area, 1797 Sofia
  4. Correspondence address: Iztok Residential area, 36 Dr G. M. Dimitrov Blvd., Izgrev area, 1797 Sofia
  5. Telephone: +359 2 8108 999.
  6. Email:
Information about the Data Protection Officer
  1. Name: 'Vladimirov Kiskinov' Attorneys-at-Law
  2. UIC/BULSTAT : 176645870
  3. Seat and registered address: 6 Nayden Gerov St., Floor 4, Office 7, Sofia
  4. Correspondence address: 6 Nayden Gerov St., Floor 4, Office 7, Sofia
  5. Telephone: 02 988 18 28
  6. Email:
Information about the Supervisory Authority
  1. Name: Commission for Personal Data Protection
  2. Seat and registered address: 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia
  3. Correspondence address: 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia
  4. Telephone: 02 915 3 518
  5. Email: kzld@government.bg, kzld@cpdp.bg
  6. Website: www.cpdp.bg
Grounds for collecting, processing and storing your personal data

Art. 1. (1) SuperHosting.BG shall collect and process your personal data in relation to the provision of hosting services, registration of domains, usage of virtual or dedicated servers and the conclusion of contracts with the Company on the grounds of Art. 6, Para. 1, Regulation (EU) 2016/679 (GDPR), and in particular on the following grounds:

    • explicit consent provided by you as a customer;
    • fulfillment of the obligations of SuperHosting.BG under contract with you;
    • compliance with a legal obligation applicable to SuperHosting.BG;
    • for the purposes of the legitimate interest of SuperHosting.BG.
    • SuperHosting.BG shall be a controller regarding your data as the User of our services. With regard to the personal data you process using our services, SuperHosting.BG shall act as a processor.
Purposes and principles for collecting, processing and storing your personal data

Art. 2. (1) SuperHosting.BG shall collect and process the personal data you provide to us in connection with the use of our hosting services and for the conclusion of a contract with the Company as well as for subscribing to our events, including for the following purposes:

  • creating a profile for full functionality in providing our services;
  • individualization of a party to this contract;
  • registration of a participant in an event organized by SuperHosting.BG;
  • accounting purposes;
  • statistical purposes;
  • information security;
  • securing the implementation of this contract for the provision of the respective service;
  • sending information e-mails, announcements about changes in services, and recommendations to improve the use of the platform, new and upgraded subscription plans etc.;
  • improving and personalizing the service by suitable offers, ads, promotional campaigns, events and other products and services that might be of interest to you;
  • provision of technical support via ticketing system or call center;
  • creating an online store via the Shopiko platform;
  • subscribing to receive notifications about latest blogposts published in SuperHosting.BG corporate blog;
  • leaving replies under our blogposts published in SuperHosting.BG corporate blog.

(2) SuperHosting.BG shall comply with the following principles when processing your personal data:

  • lawfulness, fairness and transparency;
  • limitation of the purposes for processing;
  • relevance with processing purposes and minimization of data collection;
  • accuracy and age of the data;
  • limitation of storage for the achievement of the purposes;
  • integrity and confidentiality of processing, and ensuring an adequate level of security for the personal data.

(3) When processing and storing personal data, SuperHost.BG may process and store personal data to protect the following legitimate interests of theirs:

  • fulfilling their obligations to the National Revenue Agency, the Ministry of Interior and other governmental or municipal authorities.
What kind of personal data shall SuperHosting.BG collect, process and store?

Art. 3. (1) SuperHosting.BG shall perform the following operations with personal data and for the following purposes:

  • Registration of a user on the website and implementation of a contract for the provision of hosting services, registration of a domain, virtual or dedicated server, etc. The purpose of this operation shall be to create an account that is associated with the service and to allow you to manage the content of the service through the administrative panel, according to the plan chosen by you. Conclusion of the Impact assessment: Based on the Impact Assessment referred to above, the Data Protection Officer considers that the 'Conclusion of Hosting Service Contract' operation is eligible and provides sufficient guarantees to protect the rights and legitimate interests of the data subjects in accordance with the requirements of the GDPR.
  • Registration of a user for the purposes of registering a domain in or outside the .bg area. Conclusion of the Impact assessment: Based on the Impact Assessment referred to above, the Data Protection Officer considers that the 'Domain registration' operation is eligible and provides sufficient guarantees to protect the rights and legitimate interests of the data subjects in accordance with the requirements of the GDPR.
  • Conclusion and implementation of a commercial transaction with a customer or a partner. The purpose of this operation shall be to conclude and implement a contract with a business partner or customer and the administration thereof.
  • Sending information and notification e-mails. The purpose of this operation shall be to administer the process of sending notification messages to customers about service improvements, system requirements and service expiration, as stated in service contract.
  • User registration in the Shopiko platform and signing a contract for the provision of a service for the creation of online stores through it. The purpose of this operation shall be to register and create an online store.
  • Subscription for receiving notifications about new blogposts from SuperHosting.BG corporate blog – the purpose of this operation is sending articles and posts published in our blog in case you have given your consent for it.
  • Moderating replies under blogposts in SuperHosting.BG corporate blog – the purpose of this operation is giving the users the opportunity to leave a reply to the blogpost or article and share their opinion on a certain subject described in the material.

(2) SuperHosting.BG shall process the following categories of personal data and information for the following purposes, and for the following reasons:

  • Data: Your personalizing data (name and surname, e-mail, country, phone)
    • Purpose for which data is collected: 1) To register the User. 2) To establish contact with the User and to send information to them, including, when the User has asked, to send newsletters or advertising messages. 3) To create an online store via the Shopiko platform.
    • Grounds for processing your personal data. By accepting the terms and conditions, registering on the website and purchasing a service, a contractual relationship shall be established between SuperHosting.BG and you, on which basis we shall process your personal data - Art. 6, Para. 1, Item (b) of the GDPR.
  • Additional data provided by you. If you want to update your profile, you can fill in the contact details and the administration contact email.
    • Purpose for which data is collected: Updating the information in the User's account.
    • Grounds for data processing: By accepting the terms and conditions, registering on the website and purchasing a service, a contractual relationship shall be established between SuperHosting.BG and you, on which basis we shall process your personal data - Art. 6, Para. 1, Item (b) of the GDPR.
  • Other data that SuperHosting.BG shall process. When logging in to our website or your account, SuperHosting.BG shall collect data about the IP address you use.
    • Purpose for which data is collected: Improving security of the service and interface localization, statistical and marketing research.
    • Grounds for data processing: The data processing is necessary for the implementation of the contract by which the data subject is a party - Art. 6, Para. 1, Item (b) of the GDPR. Before the creation of the User's profile, the IP address shall be collected on the basis of the legitimate interests of the Controller - Art. 6, Para. 1, Item (e) of the GDPR.
  • Your invoice data. If you would like an invoice to be issued to you as a natural person, you should provide us with your personal ID number.
    • Purpose for which data is collected: Issuing an invoice for payments under a contract for the provision of services for the use of the platform for the creation of online stores.
    • Grounds for processing your personal data. By accepting the terms and conditions, registering on the website or signing a written contract, a contractual relationship shall be established between SuperHosting.BG and you, on which basis we shall process your personal data - Art. 6, Para. 1, Item (b) of the GDPR.
  • Personal data for SuperHosting.BG blog users: - Your name, e-mail address, website.
    • Purpose for which data is collected: 1) To subscribe the User to receive notifications about blogposts published in SuperHosting.BG blog. 2) To leave replies under blogposts in SuperHosting.BG blog.
    • Grounds for processing your personal data. You give your consent on which basis we shall process your personal data - Art. 6, Para. 1, Item (b) of the GDPR.

(3) SuperHosting.BG shall not collect or process personal data that relates to the following:

  • reveal racial or ethnic origin;
  • reveal political, religious or philosophical beliefs, or trade union membership;
  • genetic and biometric data, health data, or data on sexual life or sexual orientation.

(4) Personal data shall be collected by SuperHosting.BG from the persons to whom it relates.

(5) The Company shall not perform automated decision making with data.

(6) The company shall not process personal data of persons under 14 years old unless consent is given by the holder of parental responsibility over the child.


Personal data storage period

Art. 4. (1) SuperHosting.BG shall store your personal data for no longer than the duration of existence of your website profile. Upon expiry of this period, SuperHosting.BG shall take reasonable care to erase and destroy all your data without undue delay.

(2) SuperHosting.BG shall notify you in case the storage period needs to be extended in order to achieve the purposes, the implementation of the contract, in view of the legitimate interests of SuperHosting.BG or otherwise.

(3) (4) SuperHosting.BG shall store your personal data processed on given consent grounds until you explicitly withdraw your consent. The latter shall not apply to already published replies as to keeping the reasonable continuity of the blogpost replies.

(4) SuperHosting.BG shall keep the personal data that they are required to keep under the applicable legislation for the required term, which may exceed the duration of your registration.


Transfer of your personal data for processing

Art. 5. (1) SuperHosting.BG may, at their sole discretion, transmit all or part of your personal data to personal data processors for the fulfillment of the processing purposes, subject to the requirements of Regulation (EU) 2016/679.

(2) SuperHosting.BG shall notify you in case of intent to transmit all or part of your personal data to third countries or international organizations.


Your rights when collecting, processing or storing your personal data

Withdrawal of consent to process your personal data

Art. 6. (1) If you do not wish all or any of your personal data to continue to be processed by SuperHosting.BG for a particular or for any processing purpose, you may, at any time, withdraw your consent to processing by filling in the form in your profile or a request in free text.

(2) SuperHosting.BG may require you to prove your identity and your identity with the data subject.

(3) Your account shall become inactive if you withdraw your consent for the processing of personal data which is required for creating and maintaining your registration for the use of the services.


Right of access

Art. 7. (1) You shall have the right to request and obtain from SuperHosting.BG confirmation as to whether or not personal data about you is being processed.

(2) You shall have the right to access the data relating to it as well as the information relating to the collection, processing and storage of your personal data.

(3) SuperHosting.BG shall provide you, upon request, with a copy of the processed personal data about you, in electronic or other appropriate form.

(4) Providing access to the data shall be free of charge, but SuperHosting.BG shall reserve the right to impose an administrative fee in the event of recurrence or disproportionate claims.


Right to rectification or filling in

Art. 8. You can rectify or fill in the inaccurate or incomplete personal data about you directly through your website profile or by sending a request to SuperHosting.BG.


Right to erasure ('right to be forgotten')

Art. 9.(1) You shall have the right to request from SuperHosting.BG the erasure of the personal data about you, and SuperHosting.BG shall have the obligation to erase it without undue delay where one of the following grounds applies:

  • the personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed;
  • you withdraw your consent on which the data processing is based and where there is no other legal ground for the processing;
  • you object to the processing of the data about you, including for the purposes of the direct marketing, and there are no overriding legitimate grounds;
  • the personal data has been unlawfully processed;
  • the personal data has to be erased for compliance with a legal obligation in the EU or Member State law to which SuperHosting.BG is subject;
  • the personal data has been collected in relation to the offer of information society services.

(2) SuperHosting.BG shall not be obliged to erase the personal data, if they store and process the data:

  • for exercising the right of freedom of expression and information;
  • for compliance with a legal obligation which requires processing by the EU or Member State law to which the Controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
  • for reasons of public interest in the area of public health;
  • for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes;
  • for the establishment, exercise or defense of legal claims.

(3) In order to exercise your right to be 'forgotten', you should submit a request through the option in your profile or a written request sent to SuperHosting.BG as well as to authenticate your identity and identity with the person to whom the data provided to SuperHosting.BG relates, by presenting your ID card on the spot for identification purposes and, if necessary, entering your login data for the account of the person to whom the data relates before an employee of SuperHosting.BG.

(4) SuperHosting.BG shall not erase the data that they have a legal obligation to store, including for protection against claims brought against them or proof of their rights.


Right to restriction

Art. 10. You shall have the right to request from SuperHosting.BG restriction of processing of data about you where one of the following applies:

  • you contest the accuracy of the personal data, for a period enabling SuperHosting.BG to verify the accuracy of the personal data;
  • the processing is unlawful, but you oppose the erasure of the personal data and only request the restriction of their use instead;
  • SuperHosting.BG no longer needs the personal data for the purposes of the processing, but you require them for the establishment, exercise or defense of your legal claims;
  • you have objected to processing, pending the verification whether the legitimate grounds of SuperHosting.BG override those of yours.
Right to data portability

Art. 11. (1) You may, at any time, download, directly through your profile or by email request, the data about you that are stored and processed in connection with the use of SuperHosting.BG services.

(2) You can request SuperHosting.BG to transmit your personal data directly to another controller, chosen by you, where technically feasible.


Right to receive information

Art. 12. You may request from SuperHosting.BG to inform you of all recipients to whom personal data has been disclosed for which rectification, erasure or limitation of the processing has been requested. SuperHosting.BG may refuse to provide this information if this would not be possible or would require disproportionate effort.


Right to object

Art. 13. You shall have the right to object, on grounds relating to your particular situation, at any time, to processing of personal data about you, by SuperHost.BG including profiling or direct marketing.


Your rights upon personal data security breach

Art. 14. (1) If SuperHosting.BG become aware of a breach in your personal data that is likely to result in a risk to your rights and freedoms, we shall, without undue delay, notify you about this breach and about the measures that have been undertaken or are to be undertaken.

(2) SuperHosting.BG shall not be obliged to notify you if:

  • they have implemented appropriate technical and organizational protection measures, and those measures were applied to the personal data affected by the personal data breach;
  • they have taken subsequent measures which ensure that the high risk to your rights and freedoms is no longer likely to materialize;
  • the notification would involve disproportionate effort.
Persons provided with your personal data

Art. 15. For domain registration in or outside of the .bg area, and upon request submitted by you, SuperHosting.BG shall transmit the necessary information to the respective domain registrar who shall process your data as a controller for the purpose of registering the requested domain.

Art. 16. The Controller shall not transfer your data to third countries.

Other provisions

Art. 17. In case of violation of your rights under the above or applicable data protection laws, you shall have the right to file a complaint with the Commission for Personal Data Protection as follows:

  1. Name: Commission for Personal Data Protection
  2. Seat and registered address: 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia
  3. Correspondence address: 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia
  4. Telephone: 02 915 3 518
  5. Email: kzld@government.bg, kzld@cpdp.bg
  6. Website: www.cpdp.bg

Art. 18. You may exercise all of your rights to protect your personal data through the forms enclosed with this information. Of course, these forms shall not be mandatory and you can make your claims in any form that contains a statement about it and identifies you as the data holder.

Art. 19. If the consent relates to transfer, the Controller shall describe the possible risks in the transfer of data to third countries in the absence of a decision for adequate protection and appropriate remedies.

Art. 20(1). When assigning SuperHosting.BG to process personal data to a third party for the purposes of using the service, SuperHosting.BG shall act in their capacity of a personal data processor.

(2). In the cases under Para. 1, SuperHosting.BG shall act only on your instruction as the User of the service and only as long as they may have control over the personal data you are processing. SuperHosting.BG shall have no control over the content and data that you as a service user choose to be uploaded to the service (including whether or not this data includes personal data). In this case, SuperHosting.BG shall have no role in the decision-making process whether the User uses the data processing service, for what purposes and whether it is protected. Accordingly, the responsibility of SuperHosting.BG in this case shall be limited to 1) complying with the instructions of the User of the service, pursuant to the contract and the general terms and conditions, and 2) providing information about the service and functionalities through their interface.

The current Privacy policy is last revised on March 21, 2019

 
SuperHosting.BG uses cookies which allow the website to function properly. By continuing to use and navigate our website, you agree with our use of cookies.

There are several types of cookies:

  • Essential cookies:

    Some cookies are essential in order to enable you to move around our websites and use their features, such as choosing your language or prices according to different VAT values in different countries. These types of cookies also turn on cache options, activate test services as Shopiko trial plan, etc.

  • Analytical cookies:

    We also use cookies to track visits on our website and personalize your experience from information we infer from your behavior (Google Analytics cookies). These cookies do not contain personal data. They show us information which pages of our website are visited, the type of browser via desktop/mobile access and other anonymous data. For IP addresses we also use _anonymizelp. We keep data in Google Analytics for no more that 50 months.

  • Functional cookies:

    Without these cookies, we cannot enable important features on our website such as uploaded videos, chat sessions, preferred language, etc.

  • Targeting cookies:

    These cookies contain information how you use our website that we may share with data providers solely in hashed, non-human readable form. They do not contain personal data. These cookies help us displaying you only information which is relevant. These are the dynamic cookies of Facebook, Google, Adform, Adwise, etc. In addition, most advertising networks offer you a way to opt out of targeted advertising. To find out more information, please visit http://www.aboutads.info/choices/ or https://youronlinechoices.eu/.

You can personalize the use of cookies in your browser settings.

Note that by disabling certain categories of cookies, you may be prevented from accessing some features of our website or certain content or functionality may not be available.
 

What security measures have been taken in SuperHosting.BG infrastructures to keep your personal data safe?

Long before GDPR compliance steps were made, a whole new security system was developed and implemented on our infrastructure - SH Protect. It is a multilevel working system monitoring and protecting the websites and personal data of our customers from a considerable number of malicious action attempts. The system is updated every day so that customer information is being secured in the most effective way.
It was 3 years ago when a whole system against DDoS attacks was implemented. It detects around 95% of the common DDoS attacks and is being continuously updated with newly registered attacks.
Our team keeps working on blocking malicious actions towards data stored in our infrastructure as well as improving the quality of the secure systems.
You can find more information how we keep your website and mail data safe in our blog: https://blog.superhosting.bg/en/security-challenge-accepted.html