PRIVACY AND PERSONAL DATA PROTECTION POLICY OF "VPI AESTHETIC TECHNOLOGIES" LTD
I. General Provisions
This Policy aims to inform visitors and partners of the website https://vpiaesthetics.com/ about the way "VPI Aesthetic Technologies" Ltd ("the Company", "we") collects, uses, stores and protects their personal data.
The Company processes personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable national legislation.
Definitions:
"Personal data" means any information relating to an identified or identifiable natural person.
"Data controller" means a natural or legal person which determines the purposes and means of processing personal data.
"Data processor" means a person which processes personal data on behalf of the controller.
"Processing" means any operation performed on personal data, including collection, storage, use, disclosure and erasure.
"Consent" means a freely given, specific, informed and unambiguous indication of the data subject's agreement to processing.
The Company processes personal data only on the legal bases provided by the GDPR, including:
- —consent of the data subject (which may be withdrawn at any time);
- —necessity for the performance of a contract;
- —compliance with a legal obligation;
- —protection of the legitimate interests of the controller.
II. Data Controller Information
"VPI Aesthetic Technologies" Ltd, UIC 208787513
Address: Sofia, 110 Simeonovsko Shose Blvd., Block 8, Apt. 4
Email: shop@vpiaesthetics.com
Website: https://vpiaesthetics.com/
III. Data Protection Contact
Contact person: attorney N. Nesheva
Email: Nikoleta.nesheva@nnconsult.bg
Supervisory Authority:
Commission for Personal Data Protection (CPDP)
Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd.
Tel: 02 / 91 53 518 | Email: kzld@cpdp.bg
Website: www.cpdp.bg
IV. What Personal Data We Process
When using the website and contacting us, the following data may be processed:
- —Name and surname
- —Email address and/or phone number (via contact forms)
- —Representative data of an establishment or partner
- —Technical data – IP address, logs, cookies (used solely for website functionality)
V. Purposes and Legal Bases
Processing is carried out only when necessary for:
- —Responding to inquiries and communication – Art. 6(1)(b) GDPR
- —Performance of a contract or pre-contractual steps – Art. 6(1)(b)
- —Compliance with legal obligations – Art. 6(1)(c)
- —Marketing communications – with explicit consent – Art. 6(1)(a)
- —Legitimate interests (site improvement, abuse prevention) – Art. 6(1)(f)
VI. Recipients of Personal Data
The Company does not share personal data with third parties, except:
- —trusted hosting, accounting and IT service providers under confidentiality agreements
- —state authorities when required by law
VII. Retention Period
- —Inquiry data: up to 12 months after correspondence ends
- —Contract-based data: up to 5 years after contract expiry
- —Consent-based data: until consent is withdrawn
After expiry, data is deleted or anonymised.
VIII. Your Rights as a Data Subject
As a data subject, you have the right to:
- —Access your personal data processed by the Controller
- —Request rectification, erasure or restriction of personal data
- —Be notified before data is first disclosed to third parties
- —Object to processing of personal data
- —Erasure ("right to be forgotten") under Art. 17 GDPR
- —Withdraw consent for processing at any time
- —Lodge a complaint with the CPDP at kzld@cpdp.bg if you believe your rights have been violated
Rights are exercised by written request to shop@vpiaesthetics.com.
IX. Data Security
"VPI Aesthetic Technologies" Ltd applies organisational and technical measures for the protection of personal data — encrypted communication (HTTPS), restricted database access, access controls, and regulated archiving and destruction procedures.
X. Policy Updates
This Policy may be updated upon changes in legislation or processing practices. The updated version will be published at https://vpiaesthetics.com/
Last updated: 8 May 2026.