CastelloWhy CastelloManufacturingProjectsStandardsThe Team
Contact us
BG
EN
Contact Us

Privacy Policy

Castello Precast Ltd is an engineering and construction company with UIC 175231972, registered at the address city of Sofia, Vitosha district, 11 „Panorama Sofia“ Str., entrance A, floor 7, apt. 702. The Company acts as a controller of personal data within the meaning of Art. 4(7) of Regulation (EU) 2016/679 (GDPR) and the Personal Data Protection Act (PDPA). This policy is a notice under Art. 13 of the GDPR, addressed to every natural person whose data is processed when visiting the website or when sending an enquiry through the contact form.

The processing of personal data is carried out in compliance with the principles established in Art. 5 of the GDPR: lawfulness, fairness and transparency; purpose limitation; minimisation; accuracy; storage limitation; integrity and confidentiality; accountability. The rights of data subjects are governed in Section VIII of this policy.

For questions relating to the processing of personal data, you may contact the Company at email office@castelloprecast.eu.  If you find that the processing of your data infringes your rights, you have the right to file a complaint with the Commission for Personal Data Protection (CPDP), whose details are specified in Art. 3.

The policy enters into force from the date specified in Section XI. It is subject to periodic updating and each version is identified by a number and a date of entry into force.

SECTION I. CONTROLLER AND SUPERVISORY AUTHORITIES

Art. 1. The controller of personal data is:

Castello Precast Ltd UIC: 175231972, Registered seat and management address: city of Sofia, Vitosha district, 11 „Panorama Sofia“ Str., entrance A, floor 7, apt. 702, Email: office@castelloprecast.eu, Website: castelloprecast.eu

Art. 2. The Company has not appointed a data protection officer (DPO). The core activity of the Company does not constitute large-scale systematic processing of personal data and does not include the processing of special categories of data or data on convictions within the meaning of Art. 37(1)(b) and (c) of the GDPR. Requests for the exercise of data subject rights are sent to email office@castelloprecast.eu. 

Art. 3. The competent supervisory authority within the meaning of the GDPR is the Commission for Personal Data Protection (CPDP) Address: 2 „Prof. Tsvetan Lazarov“ Blvd., city of Sofia 1592 Email: kzld@cpdp.bg Website: www.cpdp.bg

SECTION III. PRINCIPLES AND LEGAL GROUNDS

Art. 5. Principles of personal data processing

Art. 5.1. Lawfulness presupposes a valid legal ground for each specific processing activity, determined before its commencement. Without such a ground, processing is prohibited. Fairness requires that the data be used in a manner consistent with the context in which the subject provided it, without hidden purposes or additional use. Transparency is the third pillar.

The Company ensures transparency through this Policy, published permanently on the website. Contextual notices are displayed immediately before sending the contact form and upon loading the consent management system. Subjects receive full information under Art. 13 of the Regulation before their data is processed.

Art. 5.2. The data is collected for specific, explicitly stated and legitimate purposes and is not processed for purposes incompatible with them. The specific purposes for each category of data are determined in Section IV of this Policy. In the case of a new purpose, the Company checks compatibility under Art. 6(4) of the Regulation before any new processing. The procedure is described in Art. 8 of this Policy. In the case of incompatibility, a new independent ground or express consent is required.

Art. 5.3. The Company collects only the data objectively necessary to achieve the specific purpose. The fields of the contact form are limited to the minimum without which a response to the enquiry is impossible. The analytical tools are configured with IP truncation, in so far as the provider's interface permits it, and are not loaded before consent is obtained.

Art. 5.4. Data found to be inaccurate is corrected promptly after the discrepancy is established or after the Company is notified by the affected subject. The data received through the contact form is stored in the form received, since the subject is responsible for its accuracy when providing it. The procedure for submitting a request for correction is governed in Art. 22.2 of this Policy.

Art. 5.5. The storage period of each category of personal data is limited to the period necessary to achieve the purpose for which it was collected. The specific periods are specified in Section V of this Policy. Data whose period has expired is deleted or irreversibly anonymised, unless there is a ground for extension, expressly specified in Section V.

Art. 5.6. The Company applies technical and organisational measures to protect the data from unauthorised access, alteration, disclosure or destruction. The measures are proportionate to the risk to the rights and freedoms of the subjects. Their specific description is contained in Section IX.

By virtue of the principle of accountability under Art. 5(2) of the Regulation, the Company maintains a record of processing activities under Art. 30 of the Regulation. The record is updated upon each change in the processing. In the case of an inspection by the CPDP, the Company is in a position to demonstrate compliance with each of the principles established in Art. 5 of the Regulation.

Art. 6. Legal grounds

Art. 6.1. Enquiries received through the contact form are processed on the ground of Art. 6(1)(b) of the Regulation. The applicable ground is the performance of pre-contractual measures at the request of the subject. The condition is that the initiative comes from the subject themselves, and that the data provided is objectively necessary to respond to the specific enquiry. The legal ground is autonomous and does not require a separate act of consent. The subject gives rise to the ground by the act of sending the enquiry.

If the correspondence does not develop into contractual relations, the data is not deleted immediately. It is stored for the period under Section V of this Policy. The ground is the legitimate interest of the Company to defend itself against possible legal claims arising from the pre-contractual contact.

Art. 6.2. On the ground of a legal obligation under Art. 6(1)(c) of the Regulation, the Company processes personal data when a specific normative act obliges it to provide or process it, regardless of the will of the subject. In the context of the data collected through the website, the following are applicable:

  1. An order of a court for the provision of data within the framework of instituted civil, administrative or criminal proceedings;
  2. A request by the CPDP for access to personal data or processing documentation in the course of an inspection or investigation under Art. 58 of the Regulation in conjunction with Art. 57 of the PDPA;
  3. An order of the prosecution office or of the bodies of the Ministry of the Interior in the cases expressly provided for in the Criminal Procedure Code.

A request for erasure does not suspend an obligation arising from the said acts. Upon receipt of such a request, the Company specifies the particular normative act excluding erasure and the period for which the obligation is in force.

Art. 6.3. For the processing of technical log data, the Company applies the legitimate interest under Art. 6(1)(f) of the Regulation. The purpose is to ensure the security and stability of the website. The ground does not extend to analytical, behavioural or advertising activities. The detailed legitimate interest balancing assessment is set out in Art. 7 of this Policy.

Art. 6.4. The analytical and advertising tools (Google Analytics 4, Meta Pixel, Google Ads) are loaded and activated solely after the express consent of the subject, given through the consent management platform (CMP). The consent is specific by tool and by functional category, given freely and without being tied to access to the content of the website. Refusal of consent does not restrict navigation and does not give rise to consequences for the subject.

Visiting the website, scrolling and reading this Policy do not constitute a form of consent. The procedure for withdrawal is described in Art. 22.7 of this Policy.

Art. 7. Legitimate interest balancing assessment

Art. 7.1. The legitimate interest consists in the protection of the website from unauthorised access, automated attacks and malicious HTTP requests. This protection requires the recording of minimal technical identifiers: IP address of the request, type and version of browser, HTTP method and URI path, status code of the response, date and time. Without them, a response to a security incident is impossible.

Art. 7.2. In assessing the balance, the Company takes into account the following circumstances. The processed data does not reveal the content of communications, health status, financial situation or convictions. It is not linked to identified persons and does not serve to build an individual profile. Storage is limited to 90 days, after which the records are deleted automatically. Subjects reasonably expect that visiting a website generates server records, since this practice is inherent in the HTTP protocol.

Art. 7.3. Subjects may object to the processing on the ground of Art. 21 of the Regulation at any time, by sending a request to office@castelloprecast.eu. Upon receipt of such a request, the Company suspends the specific processing, unless there are compelling legal grounds for its continuation or the data is necessary for the establishment, exercise or defence of legal claims. The response is sent within the period under Art. 12(3) of the Regulation.

Art. 8. Purpose limitation and processing for a new purpose

Art. 8.1. When the Company considers processing already collected data for a new purpose, it checks the compatibility with the original purpose, taking into account:

  1. The existence of a meaningful link between the new and the original purpose and the context in which the data was collected;
  2. The nature of the data and whether special categories under Art. 9 of the Regulation are among it;
  3. The likely consequences for the subjects and the risk to their rights and freedoms in the new processing;
  4. The existence of technical and organisational safeguards, such as pseudonymisation or encryption.

Art. 8.2. If the check establishes incompatibility, the Company does not proceed with processing for the new purpose without an independent legal ground or express consent. Subjects are notified of the new purpose, the legal ground and the storage period before the start of the processing. The processing does not begin before the notification has been carried out.

Art. 9. Special categories of personal data

Art. 9.1. The Company does not process special categories of personal data under Art. 9(1) of the Regulation. The contact form does not contain fields for health data, biometric data, racial or ethnic origin, political views, religious beliefs, genetic data or data concerning sex life. None of the integrated technical tools is configured to extract or store data from these categories.

Art. 9.2. If a subject includes information from a special category in the free text field of the contact form, the Company does not process it for purposes related to its sensitive nature. Where this information is inseparable from the enquiry and is necessary for its response, it is processed under enhanced access measures, restricted to the persons directly engaged with the specific enquiry; if it is provided unintentionally and is not necessary, it is deleted without undue delay.

Art. 9.3. In the event of a possible introduction in the future of processing requiring special categories of data, the Company determines the ground under Art. 9(2) of the Regulation, carries out an impact assessment under Art. 35 of the Regulation where necessary and notifies the subjects before the start of the processing.

Art. 10. Restrictions on data processing

Art. 10.1. The website is corporate in nature and is intended for business communication with commercial partners, designers, construction consultants and potential clients carrying out economic activity. The Company's Services are not directed at natural persons under 18 years of age within the meaning of Art. 18 of the PDPA. The functionalities of the website are not adapted for interaction with children and no marketing or informational messages of any kind are addressed to them.

Art. 10.2. The Company does not collect personal data of persons under 18 years of age. If it becomes known in any way that such a person has provided data through the website, it is deleted immediately, without the need for a request from the subject or their legal representative.

SECTION IV. CATEGORIES OF DATA AND PURPOSES

Art. 11. The Company processes personal data in a volume limited to the categories described in the table below. Each category is bound to a specific purpose and a single legal ground.

Data category
Specific data
Purpose
Legal ground
Contact form data
First and last name, email address, telephone number, content of the enquiry
Receiving, reviewing and responding to business enquiries; establishing pre-contractual correspondence
Art. 6(1)(b) GDPR
Analytical data (GA4)
Truncated IP address, type and version of browser, operating system, visited URLs, session duration; cookies _ga, _gid, _ga_XXXXXXXX
Measuring reach and analysing user behaviour
Art. 6(1)(a) GDPR (Consent)
Advertising data (Meta Pixel)
Browser identifier, user behaviour on the website; cookies _fbp, _fbc
Displaying personalised advertisements and measuring the effectiveness of campaigns on Meta (Facebook and Instagram)
Art. 6(1)(a) GDPR (Consent)
Advertising data (Google Ads)
Data on conversions and interactions with advertisements; cookie _gcl_au
Measuring conversions from Google Ads campaigns and optimising advertising allocation
Art. 6(1)(a) GDPR (Consent)
Technical log data
IP address, HTTP method, URI path, status code, date and time of the request, type and version of browser
Ensuring the security and stability of the website; identifying and blocking malicious traffic
Art. 6(1)(f) GDPR (Legitimate interest)

Art. 12. Mandatory and optional fields

Art. 12.1. The provision of data through the contact form is entirely voluntary. The fields “First and last name”, “Email address” and “Telephone number” are functionally mandatory: without them, the Company cannot identify the sender and send a response. The subject is free not to send the enquiry if they do not wish to provide this data.

Art. 12.2. The field “Content of the enquiry” is optional in a technical sense, but practically necessary in order for you to receive a response. The subject determines the volume of information they include in it.

Art. 13. The tools in rows 2, 3, 4 and 5 of the table are not loaded by default upon visiting the website. They are loaded solely after obtaining express consent through the consent management system. Refusal of consent does not block access to the content of the website and does not give rise to technical restrictions for the subject. Upon withdrawn consent, the tools are deactivated upon the next loading of the page.

Art. 14. Purposes and prohibition of incompatible processing

Art. 14.1. The data collected through the contact form is used solely for correspondence on the specific enquiry and for subsequent communication arising from it. It is not provided to third parties for advertising purposes and is not used for automated profiling.

Art. 14.2. If the Company establishes a new purpose for already collected data, it applies the compatibility test described in Art. 8 of this Policy. Processing for a new purpose does not begin before the subject has been notified and, where necessary, before they have given express consent.

SECTION V. STORAGE PERIODS

Art. 15. Each category of personal data is stored for a period bound to the specific purpose or to a normative requirement. The data is not retained after the expiry of the applicable period without an express ground, specified below.

Data category
Storage period
Ground
Contact form data (names, email, telephone, content)
Until completion of the correspondence; after completion it is stored for 3 years
Art. 17(3)(e) GDPR; Art. 110 and 111 of the Obligations and Contracts Act
Technical log data
90 days
Art. 5(1)(e) GDPR and legitimate interest under Art. 7
Records of given consent (CMP)
Until withdrawal, but no more than 2 years from the giving
Art. 5(2) in conjunction with Art. 7(1) GDPR

Art. 16. In the event of instituted judicial, arbitration or administrative proceedings in which the data is relevant, the applicable period from the table is extended until the entry into force of the final act. The extension is documented internally with an indication of the type of proceedings and the date of their institution.

Art. 17. Erasure and anonymisation

Art. 17.1. After the expiry of the period, the data is deleted or irreversibly anonymised. Erasure is permanent destruction, excluding any possibility of recovering the data. Anonymisation is permissible only when it is irreversible and the result objectively excludes the establishment of the identity of the subject. The partial concealment of an identifier, for example the display only of the last four digits of a payment instrument, is not anonymisation and is not treated as such.

Art. 17.2. The backup copies of the system are verified periodically for their integrity and recoverability. The erasure of data also covers the backup copies within their life cycle.

Art. 18. Records of given consent

Art. 18.1. The records documenting given consent (CMP logs) are stored separately from the operational data. The ground is the obligation of accountability under Art. 5(2) in conjunction with the obligation of demonstrability of consent under Art. 7(1) of the Regulation.

Art. 18.2. Upon withdrawal of consent, the CMP logs are not deleted automatically together with the operational data. They are retained for the period necessary to demonstrate the lawfulness of the processing carried out before the withdrawal. The maximum period is 3 years from the date of giving the consent, after which they are deleted at the next regular clearing cycle.

Art. 19. The subject may shorten the actual period of the cookies through the browser settings or by manual deletion at device level. Such an action does not affect the lawfulness of the processing carried out before the deletion.

SECTION VI. RECIPIENTS OF PERSONAL DATA

Art. 20. The Company discloses personal data only to the recipients expressly specified in this section, and only in the volume necessary for the specific purpose. The provision of data outside these cases is permissible solely in the case of a legal obligation under Art. 6.2 of this Policy.

Art. 21. Processors of personal data

The following providers process personal data on behalf of and on the instruction of the Company on the basis of a concluded data processing agreement (DPA) under Art. 28 of the Regulation:

Art. 21.1. Webflow, Inc. (USA) provides the hosting of the website and the technical receipt of the data received through the contact form. The data is stored in Webflow's infrastructure until the moment when the Company transfers or deletes it. The transfer to the USA is governed in accordance with Section VII.

Art. 21.2. Google LLC (USA) provides the Google Analytics 4 and Google Ads services. In its capacity as a processor, Google receives analytical and advertising data solely after consent given by the subject. The transfer to the USA is governed in accordance with Section VII.

Art. 22. Meta Platforms Ireland Limited and Meta Platforms, Inc.

Art. 22.1. Meta Pixel is provided by Meta Platforms Ireland Limited (Ireland), acting as a processor with respect to the data collected in fulfilment of the advertising purposes of the Company. The tool is activated only after express consent under Art. 6.4 of this Policy.

Art. 22.2. With respect to the processing that Meta Platforms Ireland Limited and Meta Platforms, Inc. (USA) carry out for their own purposes, including improving the advertising platform, developing products and internal analytics, the Company acts as an independent controller. It does not determine the purposes and means of Meta's processing for its own purposes and is not liable for it. For the processing carried out by Meta for its own purposes, subjects may turn directly to Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Art. 23. Public authorities

Art. 23.1. The CPDP, the bodies of the prosecution office, the courts and the Ministry of the Interior receive personal data only when a normative act or an authoritative act of a competent authority obliges the Company to provide it. These authorities are not considered third parties within the meaning of Art. 4(10) of the Regulation, since they act in fulfilment of a legal obligation. They remain recipients within the meaning of Art. 4(9) of the Regulation.

Art. 23.2. The Company does not provide data proactively and does not expand the volume of the data provided beyond what is expressly requested. Upon receipt of a request from a public authority, it is documented internally with an indication of the legal ground and the date of provision.

Art. 24. The Company does not sell personal data to third parties. The data is not provided to partners, advertising networks or aggregators for their own independent marketing purposes outside the cases expressly described in this section.

SECTION VII. INTERNATIONAL TRANSFERS OF PERSONAL DATA

Art. 25. Four of the providers described in Section VI are established in the United States of America: Webflow, Inc., Google LLC, Microsoft Corporation and Meta Platforms, Inc. The transmission of data to them constitutes a transfer to a third country within the meaning of Chapter V of the Regulation and is permissible only where there is an appropriate mechanism guaranteeing protection of the data equivalent to the EEA standard.

Art. 26. The EU-US Data Privacy Framework

Art. 26.1. By a decision of the European Commission of 10 July 2023, the USA is recognised as a third country with an adequate level of protection for organisations certified under the EU-US Data Privacy Framework (DPF). Certification obliges the organisation to comply with a set of data protection principles applicable directly to the processing of personal data from the EU, and subjects it to the supervision of the Federal Trade Commission of the USA.

Art. 26.2. Webflow, Inc., Google LLC and Microsoft Corporation are certified participants in the DPF. The current certification status of each of them can be verified in the public register at dataprivacyframework.gov.

Art. 26.3. Certification under the DPF is the primary mechanism for transfer to these three providers. It does not exclude the applicability of the standard contractual clauses described in Art. 27 as a fallback instrument in the event of a possible change in the legal status of the DPF.

Art. 27. Standard contractual clauses

Art. 27.1. The standard contractual clauses (SCC), adopted by Decision 2021/914 of the European Commission, are incorporated in the terms of use of Webflow, Inc., Google LLC and Microsoft Corporation. The clauses are not concluded as separate instruments between the Company and each provider, but apply automatically upon acceptance of the provider's terms of use. In the event of a possible invalidity of the DPF, they become the applicable mechanism for transfer without the need for additional action on the part of the Company.

Art. 27.2. Subjects have the right to obtain information about the specific mechanism applied in the transfer to each provider, in accordance with Art. 31 of this Policy.

Art. 28. Meta Platforms, Inc.

Art. 28.1. Meta Platforms, Inc. (USA) is a certified participant in the DPF. The transfer of data processed by Meta Platforms Ireland Limited and forwarded to Meta Platforms, Inc. is carried out under this certification. In parallel with it, Meta Platforms Ireland Limited has incorporated the SCC (Decision 2021/914) in the terms of use of the advertising platform, thereby providing a fallback mechanism.

Art. 28.2. In view of the history of regulatory proceedings against Meta Platforms in the EU, the Company activates Meta Pixel solely after express consent from the subject. The data transmitted through the pixel is limited to the minimum necessary to measure the effectiveness of advertising campaigns and does not include direct identifiers such as names or email addresses.

Art. 28.3. For the processing that Meta carries out for its own purposes after receiving the data, the liability lies entirely with Meta Platforms Ireland Limited as an independent controller. Subjects may exercise their rights with respect to this processing directly before Meta at the address: 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Art. 29. The Company has established that the described providers apply additional technical measures in fulfilment of the obligations arising from the decision of the CJEU in Case C-311/18 (Schrems II). These measures include encryption in transit and storage, restriction of the access of their own staff to user data to the cases strictly necessary for the maintenance of the service, and contractual mechanisms obliging the provider to notify the Company upon receipt of a request for access from a public authority of the USA. The Company has assessed that, under the operation of the DPF, the SCC and these additional measures, the risk of non-compliance with the requirements of the Regulation is limited to an acceptable level.

Art. 30. Change in the legal status of the DPF

Art. 30.1. If the Decision of the European Commission of 10 July 2023 is declared invalid or temporarily suspended, the Company immediately switches to the SCC as an independent mechanism for transfer for all affected providers. The switch does not require new notification of the subjects, since the SCC are incorporated in advance in the contractual relations with each provider.

Art. 30.2. In the case of a substantial change in the legal framework for transfers, affecting the protection of the data of the subjects, this Policy is updated within 30 days of the entry into force of the change. Subjects are notified in accordance with Art. 33 of this Policy.

Art. 31. Upon request, the Company provides the subject with the specific contractual safeguard applied in the transfer to the respective provider, including a copy of the applicable SCC, within the period under Art. 12(3) of the Regulation.

SECTION VIII. RIGHTS OF THE DATA SUBJECT

Art. 32. Data subjects exercise the rights under this section by means of a written request, sent to office@castelloprecast.eu.  The Company responds within one month of its receipt under Art. 12(3) of the Regulation. In the case of factual complexity or a large number of simultaneous requests, the period is extended by up to two months. The subject is notified of the extension within the first month with an indication of the reasons. The exercise of the rights is free of charge.

Art. 33. Right of access (Art. 15 of the Regulation)

Art. 33.1. The subject may request confirmation of whether the Company processes personal data relating to them and, in the case of an affirmative answer, obtain a copy of it. Together with the copy, the Company provides information about the purposes of the processing, the categories of affected data, the recipients to whom the data has been disclosed or is to be disclosed, the applicable storage period and the available rights under this section. Upon request, the Company also specifies whether the data is subject to automated decision-making.

Art. 33.2. Where the request is submitted by electronic means, the copy is provided in a widely used electronic format. For each subsequent copy beyond the first, the Company may charge an administrative fee corresponding to the costs of fulfilment, of which the subject is notified in advance and in writing.

Art. 34. Right to rectification (Art. 16 of the Regulation)

The subject may request the prompt rectification of inaccurate data relating to them. Incomplete data is completed by the provision of additional information by the subject. The Company notifies each recipient to whom the data has been disclosed of the rectification carried out in accordance with Art. 19 of the Regulation, unless notification is objectively impossible or requires disproportionate effort. Upon request, the Company informs the subject of these recipients.

Art. 35. Right to erasure (Art. 17 of the Regulation)

Art. 35.1. The subject may request erasure of the data when one of the following grounds is present:

  1. The data is no longer necessary for the purpose for which it was collected or processed;
  2. The subject withdraws the consent on the basis of which it is processed, and there is no other independent legal ground;
  3. The subject has successfully lodged an objection under Art. 38 of this Policy and there are no overriding legal grounds for the continuation of the processing;
  4. The data has been processed unlawfully.

Art. 35.2. The right to erasure does not apply when the processing is necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims under Art. 17(3) of the Regulation. In the case of a refusal, the Company specifies the particular exception and the period for which the retention of the data is imperative. The subject is notified in writing within the general period under Art. 32 of this Policy.

Art. 36. Right to restriction of processing (Art. 18 of the Regulation)

Art. 36.1. Upon an imposed restriction, the data continues to be stored, but is not processed for any purpose beyond its storage, except with the express consent of the subject or for the establishment, exercise or defence of legal claims. The restriction is a temporary measure, applied until the resolution of the specific circumstance that necessitated the request.

Art. 36.2. The subject may request restriction when they contest the accuracy of the data and expect the Company to verify it, when the processing is unlawful and they prefer restriction over erasure, or when they have lodged an objection under Art. 38 and await the result of the Company's assessment.

Art. 36.3. Before lifting the restriction, the Company notifies the subject. They have the right to express an opinion before the processing is resumed.

Art. 37. Right to portability (Art. 20 of the Regulation)

The subject may obtain the data provided by them in a structured, widely used and machine-readable format (CSV or JSON), when the processing is based on consent or on a contract and is carried out by automated means. The right is applicable to the contact form data and to the records of given consent. The subject may request that the data be transferred directly to another controller, where this is technically feasible.

Art. 38. Right to object (Art. 21 of the Regulation)

Art. 38.1. The subject may object to the processing based on legitimate interest under Art. 6(1)(f) of the Regulation, at any time and without the need to state specific reasons. Upon receipt of an objection, the Company suspends the processing immediately, unless it demonstrates the existence of compelling legal grounds overriding the interests, rights and freedoms of the subject, or the processing is necessary for the establishment, exercise or defence of legal claims. The assessment is specific to each objection received.

Art. 38.2. In the present context, the Company does not carry out direct marketing on the basis of contact form data. Upon the introduction of such an activity in the future, subjects will be notified expressly before its commencement and will have an unconditional right to object without stating grounds.

Art. 39. Automated decision-making and profiling (Art. 22 of the Regulation)

The Company does not take decisions based solely on automated processing, including profiling, which produces legal consequences for the subject or affects them in a significant manner. In the event of a possible introduction of such an activity, subjects are notified in advance and are provided with the right to human intervention, the right to express an opinion and the right to contest the decision.

Art. 40. Right to withdraw consent (Art. 7(3) of the Regulation)

Art. 40.1. Given consent may be withdrawn at any time by changing the settings in the consent management system (CMP) of the website or by sending a request to office@castelloprecast.eu. The mechanism for withdrawal is identical in complexity to the mechanism for giving consent. Withdrawal does not give rise to adverse consequences for the subject.

Art. 40.2. Withdrawal does not affect the lawfulness of the processing carried out before it. After receiving the withdrawal, the Company deactivates the respective tools upon the next loading of the page and deletes the already collected data, in so far as there is no other legal ground for its storage.

Art. 41. Right to lodge a complaint with a supervisory authority

The subject has the right to lodge a complaint with the Commission for Personal Data Protection, 2 „Prof. Tsvetan Lazarov“ Blvd., city of Sofia 1592, kzld@cpdp.bg,  www.cpdp.bg. The right to complain to the CPDP is independent of the right to an effective judicial remedy under Art. 79 of the Regulation. The two means of protection may be used simultaneously.

SECTION IX. SECURITY MEASURES

Art. 42. The Company applies technical and organisational measures to protect personal data from unauthorised access, alteration, disclosure, loss or destruction, in accordance with Art. 32 of the Regulation. The measures are determined after an assessment of the risks to the rights and freedoms of the subjects, taking into account the nature of the processed data, its volume, the context and the purposes of the processing. The Company reviews the adequacy of the measures upon each substantial change in the processing or upon an established incident.

Art. 43. Technical measures

Art. 43.1. The communication between the user's browser and the website is carried out via the TLS protocol version 1.2 or higher. Protocols SSL 3.0, TLS 1.0 and TLS 1.1 are excluded from the server configuration. The data received through the contact form is transmitted in encrypted form from the moment of its sending until its receipt in Webflow's infrastructure.

Art. 43.2. Access to the data stored in the administrative panel of the website and in the related systems is restricted to the persons for whose work function it is directly necessary. Access is carried out with individual credentials. The sharing of credentials between different persons is prohibited.

Art. 43.3. The Company applies a policy of periodic data archiving. The archive copies are stored separately from the operational environment and are verified periodically for their integrity and recoverability. The backup copies are protected with access controls corresponding to those for the operational data.

Art. 43.4. The infrastructure of the website is protected with mechanisms for monitoring network activity. The technical log data described in Section IV serves for the early identification of anomalies in the traffic. Upon an established anomaly, the Company takes immediate measures to limit the risk.

Art. 44. Organisational measures

Art. 44.1. Access to personal data is granted only to persons bound by an express obligation of confidentiality by virtue of an employment contract or an additional agreement. The obligation is indefinite and does not lapse with the termination of the employment relationship. The Company maintains a current internal document determining which persons have access to which categories of data.

Art. 44.2. The Company maintains internal documentation of the processing activities, including the record under Art. 30 of the Regulation, this Policy and the records of given consent. The documentation is updated upon each change in the tools, the purposes or the volume of the processed data.

Art. 45. Personal data security breaches

Art. 45.1. Upon the establishment of a security breach affecting personal data, the Company notifies the CPDP within 72 hours of becoming aware of it, provided that the breach is likely to give rise to a risk to the rights and freedoms of natural persons. The notification contains a description of the breach, the categories and approximate number of affected subjects and data, the likely consequences and the measures taken or planned to limit the damage. If the full information is not available within the 72-hour period, the notification is sent in stages.

Art. 45.2. Where the breach is likely to give rise to a high risk to the rights and freedoms of the affected subjects, the Company notifies them personally without undue delay. The notification is sent to the email address provided at the contact and contains a clear description of the nature of the breach, the contact details of the responsible person, the likely consequences and the protective measures taken. The notification of the subjects lapses only in the exhaustively listed cases under Art. 34(3) of the Regulation, including when the technical measures have rendered the data unintelligible to unauthorised persons.

Art. 45.3. Every security breach, whether or not it gives rise to a notification obligation, is documented internally with a description of the facts, the consequences and the actions taken. The documentation is stored for the purposes of accountability under Art. 5(2) of the Regulation.

Art. 46. The Company cannot guarantee protection against attacks directed at the user's equipment or browser. The liability of the Company is limited to the measures applied in its own infrastructure and in the infrastructure of the providers with which a DPA has been concluded. Subjects are encouraged to keep their browser and operating system up to date and not to provide credentials for access to the website to third parties.

SECTION X. COOKIES AND TRACKING TECHNOLOGIES

Art. 47. Categories of cookies

Art. 47.1. The website uses three categories of cookies. The strictly necessary cookies ensure the basic technical functions of the website, including session security and navigation. They are loaded upon each visit, regardless of the subject's choice in the consent management system, and cannot be deactivated without disrupting the functioning of the site. The legal ground is the legitimate interest of the Company under Art. 6(1)(f) of the Regulation.

Art. 47.2. The analytical cookies are loaded only after express consent. Google Analytics 4 places the cookies _ga, _gid and _ga_XXXXXXXX, with which it measures the reach and behaviour of visitors.

Art. 47.3. The marketing cookies are loaded only after express consent and solely for the purposes of the advertising campaigns. Meta Pixel places the cookies _fbp and _fbc to measure the effectiveness of advertisements on Meta. Google Ads places the cookie _gcl_au to track advertising conversions. The tools are not activated in the case of refusal of consent and are not loaded even partially before confirmation from the CMP.

Art. 48. Consent management

Art. 48.1. The Company applies a consent management system (CMP) which, upon the first visit to the website, presents the subject with a clear choice by categories of cookies. The consent is specific by tool. The choice is stored in documented form for the period under Section V and may be changed at any time through access to the settings of the CMP. Withdrawal is technically as easy as the giving of consent.

Art. 49. In the case of withdrawn or not given consent for a particular category, the respective tools remain inactive. Subjects may additionally manage the cookies at browser level through the built-in settings of the browser used, which does not affect the lawfulness of the processing carried out before the deletion.

SECTION XI. FINAL PROVISIONS

Art. 50. Updating of the Policy

Art. 50.1. The Company updates this Policy upon a change in the tools applied, in the purposes or volume of the processing, in the applicable regulatory framework or upon an instruction from the CPDP. Each version is identified by a sequential number and a date of entry into force. The previous versions are archived and accessible on request for a period of 3 years.

Art. 50.2. In the case of a substantial change affecting the manner in which the data of the subjects is processed, the Company publishes a notice on the website no less than 30 days before the entry into force of the change. Where the change affects processing based on consent, new consent is collected before its activation. The continued use of the website after the entry into force of the updated Policy is not considered consent to it.

Art. 51. Severability of the provisions

If an individual provision of this Policy is declared invalid or unenforceable by a competent authority or court, the remaining provisions retain their effect in full. The invalid provision is replaced by one that achieves the purpose of the original to the maximum extent permitted by the applicable law. The replacement is carried out with minimal editing of the remaining content.

Art. 52. Contextual notices and entry into force

Art. 52.1. The Company provides a contextual notice immediately before the sending of the contact form, containing a reference to this Policy and identification of the controller. The notice is visible without additional action on the part of the subject and is not hidden in general terms or footnotes.

Art. 52.2. This Policy is in force and was published on 08.06.2026. It repeals all previous documents of the same kind issued by the Company.

CastelloManufacturingStandardsWhy CastelloProjectsThe Team
© 2026 Castello. All rights reserved.
General Terms of UsePrivacy Policy
Design and development: Creative Corner Studio