PRIVACY POLICY

We at WHISP LTD. ("Company", "we", "us", or "our") are committed to protecting your personal information and your right to privacy. This Privacy Policy will explain how our organization uses the personal data we collect from you when you visit and use our website https://www.whisphealth.com (the "Website") and the services presented on it. If you have any questions or concerns about our policy, or our practices with regards to your personal information, please contact us. You can find our contact details below in this Privacy Policy.

Topics:

About this Privacy policy

Terms of Use

Who is responsible for data collection on this Website?

What data do we collect?

How do we collect your data?

How will we use your data?

What entitles us to collect and use your data?

How do we store your data?

Marketing

What are your data protection rights?

Сookies

External hosting

Analysis tools

Newsletter

Payment services

Login with your Facebook/ Google account

Data transfer to third parties

Data transfer to third countries

How do we protect your data?

Competent supervisory authority

Objection to advertising emails

Changes of our Privacy Policy

Privacy policies of other websites

About this Privacy Policy

When you visit the Website and use our services, you trust us with your personal information. We take your privacy very seriously. In this Privacy Policy, we seek to explain to you in the clearest way possible what information we collect, how we use it and what rights you have in this regard. We hope you take some time to read through it carefully, as it is important and it will help you make informed decisions about sharing your personal information with us. If there are any terms in this Privacy Policy that you do not agree with, please discontinue use of our Websites and our services.

This Privacy Policy applies to all information collected through our Website, and/or any related services, sales, marketing or events (we refer to them collectively in this privacy policy as the "Services").

Terms of Use

Who is responsible for data collection on the Website?

The data processing on this Website is carried out by its operator:

WHISP LTD.

UIC: 206250888

Business address: 54 Knyaz Al. Dondukov, ent. B, 1000 Sofia, Bulgaria

Managing director: Greta Stefanova

Email: [email protected]

Phone: +359 (0) 899 129 823

The Website's operator is the controller of your personal data in terms of data protection law.

What data do we collect?

We collect only data you have voluntarily provided to us depending on the purpose for the data processing as follows:

  • Login credentials for the purposes of customer care and data protection;
  • Contact information (name, email address, phone number, etc.) for registration with the Website, providing ordered Services and staying in touch with you;
  • Personal information (including date and place of birth, places and periods of residence) depending on the type and scope of the Services you order on the Website;
  • Payment details according to the provided payment method;
  • Information from your registered profiles on social media and networks, when you access them via the links provided on the Website or register with the Website with your respective profile;
  • Data collected by the Website's cookies and third party services and tools as described below in this Privacy Policy for the purposes of ensuring the proper functioning of the Website, analyzing user behavior, for identifying consumer preferences, developing new services, and more accurately target the Services offered by us to certain user groups.

How do we collect your data?

You directly provide us most of the data we collect. We collect data and process data when you:

  • Register with the Website and/ or place an order for any of our Services;
  • Voluntarily complete a contact form, a customer survey, provide feedback on any of our messages, contact us via email or phone or subscribe for our newsletter;
  • Authorize a payment via the built-in functionality on the Website;
  • Use or view our Website via your browser's cookies.This is mainly technical data (e.g. internet browser, operating system or time of the page was viewed) that is collected automatically by our IT systems as soon as you enter our Website. You can learn more about how we use cookies in the respective section below;
  • Аcces social media accounts and profiles via provided links and plugins implemented on the Website.

How will we use your data

We collect your data so we can:

  • Process your order and provide the Services ordered;
  • Manage your account;
  • Respond to your inquiries and requests;
  • Email you with special offers on other Services we think you might like;
  • Send you a newsletter you have voluntarily subscribed to;
  • Enable your access to our profiles and channels in social media;
  • Keep statistics on the usability of our Services;.
  • Ensure that the Website is functioning properly and error-free;
  • Improve the Website experience and personalize the Services;
  • Provide customer support;
  • Fulfil our administrative obligations.

What entitles us to collect and use your data?

Data that we collect to process your orders, provide you requested Services and manage your account are processed on the basis of a legally binding agreement that you enter into with us by using our Website and the Services presented on it. You can find out more about this agreement in our Terms of Use.

If you send us inquiries using the contact form on the Website or contact us by phone or email, your details from the inquiry form and the contact details you provide, will be stored by us for the purpose of processing your request and in case of follow-up questions. Data processing is carried out on the basis of your agreement with us, If your request is related to the performance of a contract with us or is necessary to carry out pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the inquiries and requests you make or on your consent, if this was required.

Data that we collect via cookies are primarily processed on the basis of our legitimate interest to enable the proper functioning of our Website. As far as cookies are applied for other purposes than ensuring our Website's functionality, you will be explicitly asked to grant your consent for using respective cookies and processing the information we get through them.

Data that we collect and share via third-party services and tools are processed either on the basis of our legitimate interest to make our Website more attractive for users or on your explicit prior consent. The different cases are specified below in this Privacy Policy.

Data that we collect to send you newsletters and interesting offers are processed on the basis of your explicit prior consent. You can learn more about your options regarding data processing for these purposes in the respective sections below.

In addition, we may process and store your personal data to protect our legitimate interests in fulfilling our administrative and/ or contractual obligations resulting out of applicable laws and regulations (such as accounting, statististics, taxation, responding to requests from public authorities etc.).

As far as data is processed on the basis of your consent, you can always revoke such consent by simply notifying us at [email protected] or via the link provided for this purpose on the respective web page or in the respective email. Please be noted that the legality of the data processing carried out before the revocation remains unaffected.

How do we store your data?

We securely store your data. For further information, please check the "How do we protect your data?" section below.

Unless a specific storage period is stated in this Privacy Policy, we will keep your provided email, personal information and login credentials until the purpose for the data processing no longer applies.

Data collected via cookies or third-party services and/ or tools as described in this Privacy Policy are stored for the period specified in the respective section below.

If you make a legitimate request for deletion of your data, delete your registered account or revoke your consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g. tax or commercial retention periods or statutory limitation periods); in the latter case, the deletion takes place after these reasons no longer apply.

Marketing

We would like to send you information about new features on the Website or our Services that we think you might like. If you have agreed to receive marketing messages, you may object at any time to the processing of personal data for the purpose of such direct marketing and always opt out at a later date. You have the right at any time to stop us from contacting you for marketing purposes. If you object your personal data will no longer be used for marketing purposes.

If you no longer wish to be contacted for marketing purposes, please contact us at [email protected]

What are your data protection rights?

We would like to make sure you are fully aware of all of your data protection rights. You are entitled to the following:

  • The right to access – you have the right to receive information about the origin, recipient and purpose of your stored personal data free of charge at any time. For any further copies of your personal data we may charge you a small fee.
  • The right to rectification – you have the right to request that Our Company correct any information you believe is inaccurate. You also have the right to request Our Company to complete the information you believe is incomplete.
  • The right to erasure – you have the right to request that Our Company erases your personal data, under certain conditions.
  • The right to restrict processing – you have the right to request that Our Company restricts the processing of your personal data, under certain conditions.
  • The right to object to processing – you have the right to object to Our Company's processing of your personal data, under certain conditions.
  • The right to data portability – you have the right to request that Our Company transfer the data that we have collected to another organization, or directly to you, under certain conditions.
  • The right to lodge a complaint - you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your residence, your place of work or the place of the alleged violation of data protection laws and regulations. This right exists without prejudice to other administrative or judicial remedies. You can find the contact information of the supervisory competent for our data processing activities in the respective section in this Privacy Policy below.

If you would like to exercise any of these rights, please contact us at our email: [email protected]. If you make a request, we have one month to respond to you.

Cookies

Cookies are text files placed on your computer to collect standard Internet log information and visitor behavior information. When you visit our Website, we may collect information from you automatically through third-party cookies or similar technology and local storage.

We also may use cookies for marketing purposes and to provide features (such as social media tools). Information collected via cookies may be shared with our social media, advertising or analytics partners as described below in this Privacy Policy.

Third-party providers

We work with third-party providers like Facebook and Google, who also set cookies for analytics and marketing purposes. This list may not be exhaustive, but we commit to keeping it updated based on information from these providers. Please see the following resources for more detailed information about the cookies set by Facebook and Google

External hosting

Our Website is hosted by DigitalOcean – The developer cloud DigitalOcean, LLC, ATTN: Legal, 101 Avenue of the Americas, 10th Floor, New York, NY 10013 USA. as an external service provider. The personal data collected via our Website are stored on DigitalOcean – The developer cloud's servers. Such data can be i.a. IP addresses, contact requests, meta and communication data, order data, contact details, website accesses and other data generated via the Website.

DigitalOcean – The developer cloud is used for the purpose of fulfilling the contract with our potential and existing customers and in the interest of a safe, fast and efficient provision of our Services by a professional provider. In order to ensure data protection compliant processing, we have concluded a data processing agreement with Legal - Terms of Service Agreement

DigitalOcean – The developer cloud will only process your data insofar as this is necessary to fulfill its service obligations towards us and will follow our instructions with regard to such data processing.

Analysis tools

This Website uses "Google Analytics" and “Facebook Analytics” to statistically evaluate users behavior. The providers are respectively Google, LLC, 1600 Amphitheatre Parkway, Mountain View, California, USA and Facebook Inc. 1 Hacker Way, Menlo Park, California, USA

Google and Facebook Analytics use tools and technologies (incl. cookies) that allow the recognition of the Website visitors. Google Analytics collects information (such as log files, origin of the Website visitors, activities of the visitors on the Website) that might be stored on servers in the USA. You can learn more about the data transfer to the USA from the "Data transfer to third countries" section below.

We use Google Analytics on the basis of our legitimate interest in the anonymized analysis of user behavior in order to optimize both our Website and its advertising. If a corresponding consent has been requested (e.g. consent to the storage of cookies), processing takes place exclusively on the basis of such consent; the consent can be revoked at any time.

Newsletter

We may offer a newsletter service on the blog hyperlinked to our Website. If you would like to receive newsletters from us, we will only store your e-mail address after we have verified (via additional link that we will send you before you subscribe for our newsletter service) that you are the owner of the e-mail address and that you agree to receive the newsletter. Further data is not collected or is only collected on a voluntary basis. We use this data exclusively for sending the requested information.

The data we have collected on the occasion of your newsletter subscription will be stored by us or our newsletter service provider until you unsubscribe from the newsletter and will be deleted from the newsletter distribution list after you unsubscribe from the newsletter. This does not affect data that we have saved for other purposes. However, after you have unsubscribed from our newsletter, your email address may be stored in a blacklist by us or our newsletter service provider in order to prevent future mailings. The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both your interest and our legitimate interest in compliance with the legal requirements when sending newsletters. Storage in the blacklist is not limited in time. You can object to the storage provided that your interests outweigh our legitimate interests.

The processing of the data entered in the newsletter registration form takes place exclusively on the basis of your consent. You can revoke your consent to the storage of the data, the e-mail address and their use for sending the newsletter at any time, for example via the "unsubscribe" link in the newsletter. The legality of the data processing operations already carried out remains unaffected by the revocation.

Payment services

When you commence a payment for services ordered on our Website, your payment details will be automatically transmitted to our payment services provider. We use the platform stripe.com (“Stripe”). We do not save any credit card or personal data in connection with the payment processing, these data are entered directly at Stripe.

Stripe is operated by Stripe Payments Europe, Limited, an Irish company located at The One Building, Lower Grand Canal St, Dublin 2, Ireland, registration number 513174, e-mail address for clients: [email protected] or https://stripe.com/en-gb-bg/contact, acting as a payment processing agent.

Login with your Facebook/ Google account

We may offer an option to register with the Website with your Facebook or Google account. Additional registration with the Website will not be necessary.

To log in, you will be redirected to the Facebook/ Google page, where you can log in with your user credentials. This will link your Facebook/ Google profile and our Website. Through the link we will automatically receive information about your email address, name, language preferences etc., depending on your privacy settings. We will only use your name and email address for the registration with our Website.

If you choose one of these options, please review the respective privacy policies of Facebook (https://www.facebook.com/about/privacy) and Google (https://policies.google.com/privacy) and adjust your privacy settings as preferred. If you disagree with transfer of your data from your Facebook or Google profile to us, please discontinue the registration process and use the direct registration option on our Website.

Data transfer to third parties

To enable access to our Website and provide the services presented thereon we use third-party services, platforms and infrastructure. For this reason we may transmit all or part of your personal data to our service providers. Such data transfer is executed for the purpose of fulfilling the contract with our potential and existing customers and based on our legitimate interest of providing user oriented, accessible and data-secure Services.

In order to ensure data protection compliant processing by external service providers, we have concluded data processing agreements with them. Our service providers will only process your data insofar as this is necessary to fulfill their service obligations towards us and will follow our instructions with regard to such data processing.

Data transfer to third countries

Our Website includes tools from companies based in the USA. When these tools are active, your personal data can be passed on to the US servers of the respective companies. We would like to point out that the USA is not a safe third country within the meaning of EU data protection law. The transfer of your data to the USA gives rise to the risk that your data may be read and evaluated by the US public authorities and that profiles can be created about you without your knowledge.

Where legally and technically possible, we will only use such tools of such third party service providers that provide appropriate safeguards (such as standard data protection clauses or approved certification mechanisms) in terms of EU data protection law. In all other cases the transmission of your data to the USA will only be admissible where you have given your consent to the use of the respective tool or service. This consent is granted when you consent to the use of the respective tools and services for analysis and advertising via our consent form when you start using the Website, as explained in the "Cookies" section above.

How do we protect your data?

We regularly review and apply all technical and organisational means that serve to protect and ensure confidentiality, integrity and availability of all types of data you trust us with.

To protect the transmission of confidential content, such as orders or inquiries that you send to us, this Website uses a SSL encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http: //" to "https: //" and by the lock symbol in your browser line. If the SSL encryption is activated, the data that you transmit to us cannot be read by third parties.

The data you provide us with for the purposes of provision the Services you have ordered on the Website are encrypted by design and stored in our systems in a way preventing any unauthorized access and malicious actions towards such data.

Competent supervisory authority

Competent supervisory authority for the data processing activities carried out by us in connection with operation of the Website is the Commission for Personal Data Protection:

2, Prof. Tsvetan Lazarov blvd.

1592 Sofia, Bulgaria

Tel. +359 2 915 3523

Fax +359 2 915 3525

e-mail: [email protected]

Website: http://www.cpdp.bg/

Objection to advertising emails

We hereby object to the use of our contact data provided as part of our transparency obligations for sending unsolicited advertising and information material. We expressly reserve the right to take legal action in the event of unsolicited sending of advertising information, such as spam e-mails.

Changes to our Privacy Policy

We keep our Privacy Policy under regular review and will place any updates on this web page. This Privacy Policy was last updated on 04.11.2020.

Privacy policies of other websites

Our Website contains links to other websites, including social media and networks. Our Privacy Policy applies only to our Website, so if you follow a link to another website, you should be concerned that our Privacy Policy no longer applies and read the privacy policy of the respective website.

We value your privacy and use cookies and other technologies on our website to improve your experience and process your data. By clicking "Accept" you agree with our Cookie policy