One of the main concerns of National Guarantee Fund EAD is the security of personal data of individuals - our customers and partners, and we have taken the necessary measures to bring the activities of all our offices / branches and employees in line with best practices. and legal requirements for the protection of information and its confidentiality.
When we collect personal data of our customers, we follow the principle of minimizing the processed data, legality, transparency and security. The Fund (hereinafter referred to as the "Company") seeks to process only personal data that are essential and relevant to achieving the objectives of its business.
This privacy policy applies both to information collected through the Company's website and to the personal data that it processes in the course of its core business and in defense of its legitimate interest as a Lender.
The company processes those personal data that are necessary and related to its activities, while acting as an administrator or co-administrator of personal data. As part of the Group of Bulgarian Development Bank ЕAD, the Company shares data with the bank for the purposes of legal risk and security assessment.
Regardless of the reason you share your personal information with us, we recommend that you do not disclose sensitive personal information: such as information about racial or ethnic origin, religion, trade union membership, sexual orientation, health status, etc., unless is a necessary condition for you to be provided with a service by the Company.
More information about the personal data we process and the categories of recipients in connection with the individual programs can be found here.
Based on your prior consent and if you wish, we may disseminate information about your project funded by the BDB Group, details of your name, location and photo (for example, by publishing on the BDB Group website). We use this personal data to encourage more citizens, small and medium-sized enterprises to develop their business with the help of the BDB Group.
Our website uses cookies and social plugins to function better and more efficiently. When they visit the site, they collect a limited set of personal information automatically.
When you visit our offices and in order to protect your and our security, we use physical security measures such as CCTV surveillance and access control by registering visitors at the reception.
The personal data we process are the names of the visitors, the date and time of access to the building, as well as a video image. We store this data in a secure location, allowing only a limited number of people to access it and only when necessary.
In certain cases, the Company will process personal data of individuals who are not customers of the Bank, for example:
The personal data we collect in the selection process are used solely to identify the candidates with the closest profile to the requirements for the specific position. After the completion of the selection, the provided information is kept for 3 months and is destroyed.
The personal data that we process for the purposes of selection are name, previous professional experience, information on education and acquired qualifications, as well as other information that is relevant in the specific case and is related to the job application.
The Company stores your personal data only for the minimum necessary period to achieve the objectives set out in this Policy, as well as when by law or international agreement it is obliged or has the right to store them for a longer period.
The retention period is determined taking into account several factors, including the duration of the provision of services (for example, in case of deferral and renegotiation of the loan), if necessary in order to establish, exercise or protect our legal claims (for example for collection of overdue receivables) , or whether we have a legal obligation to store the data (for example, accounting documents for a period of 5 years or 10 years).
We are obliged to store personal data related to programs implemented with international financing and support for up to ten years after the conclusion of our contract with the partner international bank.
Data related to video surveillance and access control in the offices of the BDB Group are stored for a short period of time - usually 30 days, unless a longer processing period is required to protect our legal claims - for example for the purposes of additional incident investigation.
In connection with the applicable legal requirements, we are obliged to transfer your personal data to registers such as: CRC, CROZ and TRYULNC, as well as to state bodies and institutions such as BNB, NSSI, NRA, SANS, judicial system, prosecutor's office and others.
Your personal data is subject to automatic exchange in connection with compliance with the data exchange requirements under the Tax and Social Security Procedure Code (TSPC) and the Agreement between the Government of the Republic of Bulgaria and the Government of the United States of America to improve tax compliance internationally. connection to an initiative also known as FATCA.
With regard to the programs and products of the BDB Group, which are provided jointly and in cooperation with local and international partners of the Group (a list of international partners is available here), personal data of clients are exchanged, as far as necessary for the respective service, the conclusion of a loan or collateral agreement, control over the fulfillment of the contractual obligations, accountability to the Bank's partners and protection of their interests.
You can find a list of commercial banks and non-bank credit institutions - partners of the Company on the territory of the Republic of Bulgaria here.
When concluding transactions by telephone, we use telephone exchange services from the mobile operator MTel / A1.
When we defend our rights and legitimate interests and if we use the services of external consultants, lawyers, translators, auditors, etc., we disclose to them the amount of personal data that is necessary to assist us.
The Company will not share or distribute your data for marketing or other purposes to third parties.
In other cases and to the extent necessary, personal data is provided only to our trusted partners - technical providers of marketing services and web design services, IT support, courier service providers, for whom we have made sure that they meet the highest standards. for security of information and its confidentiality.
Providing data to our partners is necessary so that we can deliver the services you have requested, as well as to improve the functioning of our website.
The company processes your personal data only in accordance with the above objectives and deadlines.
When we collect personal data, we do so in a minimal amount and only for predetermined and clearly defined purposes and retention periods. We provide access to the data only to a limited number of persons who have been previously trained and instructed on how to work with the data.
In connection with the entry into force of new European rules for personal data protection, the Company undertook a detailed analysis and audit of all our processes related to personal data processing. As part of this analysis, we check our partners, revise our procedures and rules, train our employees, and use experienced information security consultants to ensure compliance with the highest standards of confidentiality and security of your information.
As a data subject, you have the right to receive confirmation and / or detailed information, incl. a copy of the personal data processed for you (right of access).
In addition, you may object to the collection and further processing of your personal data, as well as request that they be corrected (updated) or deleted (when we do not have a valid legal basis to continue processing them).
It is important to know that you can withdraw your consent to the processing of personal data at any time. You can do this by communicating your intention to the designated Data Protection Officer, whose contacts are listed below.
If you believe that your data protection rights have been violated, you have the right to file a complaint to the Commission for Personal Data Protection: Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd., tel. 02 / 91-53-518, e- e-mail: kzld@cpdp.bg and / or other supervisory / regulatory body, when you believe that there is a violation in connection with the processing of your personal data by the Company.
To ask questions about your rights or if you want to exercise any of them, please contact the Data Protection Officer.
We will review each of your requests without undue delay within 30 days of receiving the request. If we are unable to do so for reasons beyond our control, we will notify you in a timely manner, stating the reasons for the delay.
Any changes to this policy will be announced on the Company's website and in each of our offices. In the event of a significant change in the information, we will additionally notify you by sending an email or SMS message. Users of our online banking services will also be notified when logging in to their account.