DRAFT FOR REVIEW — 28 September 2026. Company registration number: 206283984. Before launch, confirm that the described processing, providers and retention criteria match actual operations.
1. Controller
“NPS DENT” Ltd. (ЕНПИЕС ДЕНТ ЕООД). Company registration number (ЕИК): 206283984. Address: Тракия, Пловдив България. Contact: nps-dent@nps-dent.com, +359 886 998 394. Main website: https://nps-dent.com.
2. Data and purposes
Depending on the functions used, data includes name, telephone, email, delivery address, business/invoice details, requests/orders, correspondence and technical information. Purposes include receiving and confirming requests, contact, delivery, accounting, complaints, statutory duties and security. The website does not collect bank card details. We collect only data necessary for the purpose. A Bulgarian personal identification number (ЕГН) is not collected without a specific legal basis. Personal data is not sold. A separate consent checkbox is not required for processing necessary to handle a request or perform a contract.
3. Legal bases
Receiving and confirming a request relies on steps taken at your request before a contract and, if concluded, performance of the contract (GDPR Article 6(1)(b)). Accounting and other mandatory records rely on legal obligations (6(1)(c)). Security, abuse prevention and legal claims may rely on legitimate interests (6(1)(f)), subject to balancing your rights and interests. Consent, where required for optional cookies or marketing, is requested separately (6(1)(a)).
4. Recipients
Authorised people handling your request have access. Necessary data may be shared with hosting and technical support, email, accounting and delivery providers, and competent authorities where legally required. Providers act according to their applicable roles and confidentiality duties. Do not include sensitive data or patient information in request notes.
5. International transfers
If a service involves transfers outside the EEA, an applicable GDPR mechanism is required, such as an adequacy decision or appropriate safeguards. Ask the controller for recipient and safeguard details. Actual providers and processing locations must be verified before final publication; this draft does not certify the absence of such transfers.
6. Retention
Request and correspondence data is retained while necessary to handle the request and follow-up questions. Completed sales, invoices and accounting records are kept for applicable statutory periods. Necessary complaint or dispute records may be retained until resolution and expiry of applicable claim periods. Technical logs are retained according to justified security needs. Data is deleted or anonymised when no retention basis remains. The actual deletion schedule must be confirmed and implemented before launch.
7. Your rights
Subject to legal conditions, you have rights of access, correction, erasure, restriction, portability and objection. You may object to direct marketing at any time. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. Erasure does not override mandatory legal retention.
8. Exercising rights
Send your request to nps-dent@nps-dent.com with sufficient detail to identify the relevant record. If there is reasonable doubt about identity, necessary additional verification may be requested. The normal response period is one month. Complexity or multiple requests may allow two additional months, with notice during the first month. Requests are normally free, subject to statutory exceptions for manifestly unfounded or excessive requests.
9. Supervisory authority
You may complain to the competent supervisory authority. In Bulgaria: Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, https://cpdp.bg, email kzld@cpdp.bg. Follow the authority’s current filing and signature requirements.
10. Required fields and automation
Required fields are needed to receive and process the request; without them the form cannot be submitted. Notes are optional unless model details are necessary. A person confirms the request. Automated emails and calculated totals do not automatically accept a sale. If profiling or other significant automated processing is introduced, the policy must be updated in advance.
11. Cookies, security and changes
Optional cookie choices are separate from accepting the terms and can be changed in Cookie settings. See the cookie policy for current categories. Access is limited according to need and appropriate technical and organisational safeguards are used. Do not send card or patient details. Material changes require an updated policy and fresh consent where necessary. Draft revised: 28 September 2026.