Effective as of 01.08.2024
Why should you read this Privacy Policy?
Merkato is committed to the principles of personal data protection laid down in European and UK law and recognizes the importance of safeguarding personal information. We are constantly improving our data processing activities and our privacy notices in order to provide you with as much transparency over the way we handle your data as we can. This Privacy Policy describes how we collect, use, process, and disclose your information, including personal information, in conjunction with your access to our Website and utilization of our contact forms.
If you have concerns about how we use your personal information, you can contact us at
merkato@merkato.com
About us
When this policy mentions “we,” “us,” or “our,” it refers to Merkato Services EOOD, company number 206438370, with registered seat and address at 51 Blvd. James Bourchier, floor 15, Sofia, Bulgaria (hereinafter referred to as ‘Merkato’), which is responsible for your information under this Privacy Policy and acts as a Data Controller within the meaning of Regulation 2016/679 (the ‘GDPR’). Merkato is a strategic business partner of the myPOS group of companies.
The present Privacy Policy grants rights which only natural persons may benefit from. Whenever we use “you”, “your” or similar, the persons which we refer to are the natural persons, which may be the representatives, the beneficial owners, the authorized persons or other similar and in case the you act as a sole trader or similar.
How do we process your personal information?
- What information do we process about you?
You are informed that we collect personal data you have provided when you fill in and submit our contact forms in order to obtain an offer for the services offered by our partners or to be recruited as a reseller.
- Information that we process.
We may ask for and collect from you the following personal information when you contact us via the contact forms on our Website:
Type of Personal Data |
Purpose of Processing |
Legal grounds under GDPR |
What third-party processors can we use for this? |
Names (First Name, Surname, Last Name) |
|
|
|
Marketing |
Our legitimate interests |
Marketing services providers. |
|
|
|
Cross-sales marketing |
Your consent |
In case there is a third-party processor, you will be provided with information about them in the consent form. |
Drawing up offers for myPOS services |
At your request in order to take steps prior to entering into a contract |
Our myPOS partners |
Recruiting of resellers/distributors |
At your request in order to take steps prior to entering into a contract |
Our myPOS partners
Our auditors; legal or other similar counsels; regulators |
Due diligence |
Compliance with legal obligations |
Our auditors; legal or other similar counsels; compliance outsourcing providers; regulators |
Risk and compliance analysis and action |
Compliance with legal obligations |
Blacklist and/or sanction list database providers; compliance and risk outsourcing providers; legal or other similar counsels; regulators |
Email |
Marketing |
Our legitimate interests |
Marketing services providers. |
|
|
|
Cross-sales marketing |
Your consent |
In case there is a third-party processor, you will be provided with information about them in the consent form. |
Drawing up offers for myPOS services |
At your request in order to take steps prior to entering into a contract |
Our myPOS partners |
Recruiting of resellers/distributors |
At your request in order to take steps prior to entering into a contract |
Our myPOS partners
Our auditors; legal or other similar counsels; regulators |
Due diligence |
Compliance with legal obligations |
Our auditors; legal or other similar counsels; compliance outsourcing providers; regulators |
Risk and compliance analysis and action |
Compliance with legal obligations |
Blacklist and/or sanction list database providers; compliance and risk outsourcing providers; legal or other similar counsels; regulators |
Phone number |
Marketing |
Our legitimate interests |
Marketing services providers. |
|
|
|
Cross-sales marketing |
Your consent |
In case there is a third-party processor, you will be provided with information about them in the consent form. |
Drawing up offers for myPOS services |
At your request in order to take steps prior to entering into a contract |
Our myPOS partners |
Recruiting of resellers/distributors |
At your request in order to take steps prior to entering into a contract |
Our myPOS partners
Our auditors; legal or other similar counsels; regulators |
Risk and compliance analysis and action |
Compliance with legal obligations. |
Blacklist and/or sanction list database providers; compliance and risk outsourcing providers; legal or other similar counsels; regulators; |
Due diligence |
Compliance with legal obligations |
Our auditors; legal or other similar counsels; compliance outsourcing providers; regulators |
Turnover |
Drawing up offers for myPOS services |
Pre-contractual |
Our myPOS partners; |
Data, collected in relation to interactions with our Website |
Facilitating use of our Website |
Our contract with you or in order to take steps prior to entering into a contract; |
None |
Personalize, Measure, and Improve our Advertising and Marketing |
Our legitimate interests |
Marketing services providers |
Operate, protect, improve, and optimize your experience, such as by performing analytics and conducting research |
Our legitimate interests |
Marketing services providers |
Data, collected in relation to interactions with our Social media channels |
Personalize, Measure, and Improve our Advertising and Marketing; Review and use of public comments and opinions made on social networking sites (e.g. Facebook and Twitter) to better understand prospective customers and partners and to improve our website and business strategies |
Our legitimate interests |
Marketing services providers; marketing consultants; SEO and other similar software or consultancy providers; other similar providers |
Data, provided in relation to participations in games, quizzes and completion of questionnaire or a contest entry form for promotional campaigns |
Provide you with the option to participate in the respective event |
Performance of our obligations under the general terms and conditions of the relevant campaign |
Marketing services providers; our myPOS partners |
Personalize, Measure, and Improve our Advertising and Marketing |
Our legitimate interest |
Marketing services providers; our myPOS partners |
Cookies and other tracking technologies |
The use of cookies and other tracking technologies is described in our Cookie Policy |
- Specific data processing cases
In any case, we may share any of your information for specific reasons, outlined below:
- With members of the myPOS corporate family: We may share your Personal Data with members of the myPOS Group of companies or within our extended family of companies that are related by common ownership or control, so that we may provide the Services you have requested or authorized or to manage the risk, or to help detect and prevent potentially illegal and fraudulent acts and other violations of our policies and agreements.
- With myPOS distributors: We may share information related to you or your company with myPOS distributors, which help us to provide you with the best myPOS The distributors may process some of your personal information in order to process myPOS terminal orders and other similar activities.
- Aggregated We may also share aggregated information (information about users that we combine together so that it no longer identifies or references an individual user) and other anonymized information for regulatory compliance, industry and market analysis, demographic profiling, marketing and advertising, and other business purposes.
- With our legal counsels for the purposes of protecting our legal rights. We may share any information which is necessary to protect our legal rights to legal counsels or similar
- We may monitor or record telephone calls, emails, web chat or other communications with you for regulatory, security, customer services or training purposes. When visiting our offices, CCTV, access control systems and/or other monitoring systems may be in operation.
- Business If we are involved in any merger, acquisition, reorganization, sale of assets, transfer of portfolio, bankruptcy, or insolvency event, then we may sell, transfer or share some or all of our assets, including your information in connection with such transaction or in contemplation of such transaction (e.g., due diligence). In this event, we will notify you before your personal information is transferred to a different legal person and/or becomes subject to a different privacy policy.
- Processing based on statutory or contractual requirement, or a requirement necessary to enter into a contract
Whenever any of the above-described data is being processed based on “Our contract with you or at your request in order to take steps prior to entering into a contract”, this data is required for us to continue to provide you with the particular services and if you do not provide it to we may have to discontinue these services.
Decisions based solely on automated processing
Sometimes, our systems may take decisions based solely on automated processing. This does not mean that we will always use automated decision making for these processing activities. In case you believe that you have been unfairly treated by our automated decision-making systems you may ask that a person reviews the decision at all times by contacting us as described in the “How do I complain?” section
Information collected about you from third parties
- Information from public sources and screening
We may ask certain entities for information about you when you wish to become a reseller/distributor.
Such entities are generally fraud prevention agencies. These providers rely on publicly available information about you or your business.
We may also collect information about you from public sources for Anti Money Laundering reasons or market research. This includes:
a) official public records, like your national Company register;
b) information published by the press or on social
Information from data
We may receive certain information in order to evaluate your business from third-party providers generally known as data aggregators. This information may include the following:
- General business details, including, where available, documents such as Articles of Association and other similar company details;
- Details about your business activity
- Other relevant information that may be required for us to evaluate your business or that you may have consented to share through the third-party provider.
Data aggregators collect information for businesses from publicly available sources, or in some cases – this information is shared based on your consent or other type of legal ground, which the data aggregator to legally share certain information about you with us.
Data Retention and Erasure
We generally retain your personal information for as long as is necessary for us to comply with our regulatory obligations. If you no longer want us to use your information, you can request that we erase your personal information, providing there is no reason which prevent us by law to delete such information.
We may retain some of your personal information as necessary for our legitimate business interests.
We may retain and use your personal information to the extent necessary to comply with our legal obligations. For example, we may keep some of your information for legal and auditing obligations.
Because we maintain our records in a manner protecting from accidental or malicious loss and destruction, residual copies of your personal information may not be removed from our backup systems for a limited period of time.
We reserve the right to retain your identification data for an indefinite duration if you have been placed on our company’s internal blacklist due to suspected malicious, fraudulent, or analogous behavior. This retention is predicated on our legitimate interest in preventing such individuals from accessing our services in the future.
Your rights
You may exercise any of the rights described in this section before us by sending an email to
merkato@merkato.com
Please note that we may ask you to verify your identity before taking further action on your request. Please note that upon receipt of your e-mail we shall try our best to provide you with the requested information and resolve your request in reasonable time, subject to all obligations which we or the related companies have under the applicable laws.
- Managing Your Information
You have the right to obtain the following:
- confirmation of whether and where we are processing your personal data; information about the purposes of the processing;
- information about the categories of data being processed;
- information about the categories of recipients with whom the data may be shared;
- information about the period for which the data will be stored (or the criteria used to determine that period);
- information about the existence of the rights to erasure, to rectification, to restriction of processing and to object to processing;
- information about the existence of the right to complain to any Regulator;
- where the data was not collected from you, information as to the source of the data; and
- information about the existence of, and an explanation of the logic involved in, any automated processing. Additionally, you may request a copy of the personal data being processed.
- Rectification of Inaccurate or Incomplete Information.
You have the right to ask us to correct inaccurate or incomplete personal information concerning you (which you cannot rectify yourself).
- Data Access and Portability.
You have the right to:
- receive a copy of your personal data in a structured, commonly used, machine-readable format that supports re-use;
- transfer your personal data from one controller to another;
- store your personal data for further personal use on a private device; and
- have your personal data transmitted directly between controllers without hindrance.
In some jurisdictions, applicable law may entitle you to request copies of your personal information held by us.
- Withdrawing Consent and Restriction of Processing.
Where you have provided your consent to the processing of your personal information by us you may withdraw your consent at any time by sending a communication to us specifying which consent you are withdrawing. Please note that the withdrawal of your consent does not affect the lawfulness of any processing activities based on such consent before its withdrawal. Additionally, in some jurisdictions, applicable law may give you the right to limit the ways in which we use your personal information, in particular where (i) you contest the accuracy of your personal information;
(ii) the processing is unlawful and you oppose the erasure of your personal information; (iii) we no longer need your personal information for the purposes of the processing, but you require the information for the establishment, exercise or defence of legal claims; or (iv) you have objected to the processing and pending the verification whether our legitimate grounds override your own.
In some jurisdictions, applicable law may entitle you to require us not to process your personal information for certain specific purposes (including profiling for marketing purposes) where such processing is based on legitimate interest. If you object to such processing we will no longer process your personal information for these purposes unless we can demonstrate compelling legitimate grounds for such processing or such processing is required for the establishment, exercise or defence of legal claims.
You can ask us to stop sending you marketing messages at any time by contacting us at
merkato@merkato.com
Please bear in mind that irrespective of your opt-out, related to marketing messages, you will still continue to receive specific messages, which we are required to send you under the applicable legislation.
You should in first place try to resolve the matter by sending an e-mail
to: merkato@merkato.com
Merkato Services EOOD
51 Blvd. James Bourchier, floor 15, Sofia, Bulgaria
If you are not satisfied with how we have handled tour complaint, you have the right to file a complaint with the lead supervisory authority, the Commission for Protection of Personal Data, Bulgaria:
Address: Sofia 1592, 2 Prof. Tsvetan Lazarov blvd.
e-mail:
kzld@cpdp.bg
Operating globally
To facilitate our global operations we may be required to transfer, store, and process your information within our family of companies or with service providers based in Europe, India, Asia Pacific and North and South America. Laws in these countries may differ from the laws applicable to your Country of Residence. For example, information collected within the EEA may be transferred, stored, and processed outside of the EEA for the purposes described in this Privacy Policy. Where we transfer store and process your personal information outside of the EEA we have ensured that appropriate safeguards are in place to ensure an adequate level of data protection.
International transfers
Where we disclose any of your collected personal information outside EEA, we shall comply with any relevant adequacy decision, where possible.
- Other Means to Ensure an Adequate Level of Data Protection.
In case personal information is shared with corporate affiliates or third-party service providers outside the EEA in absence of an adequacy decision, we have – prior to sharing your information with such corporate affiliate or third-party service provider – established the necessary means to ensure an adequate level of data protection and a valid legal ground under the applicable data transfer rules. We will provide further information on the means to ensure an adequate level of data protection on request.
Protection of personal data transferred from or to the United Kingdom of Great Britain and Northern Ireland:
Where we transfer any of your collected personal data from or to UK we shall comply with the Decision on the adequate protection of personal data by the United Kingdom – General Data Protection Regulation, dated 28 June 2021.
Security
We take the responsibility to ensure that your personal information is secure, kept in an encrypted from on servers, collocated in Special data centers in Class A jurisdictions in Europe.
To prevent unauthorized access or disclosure of information we maintain physical, electronic and procedural safeguards that comply with applicable regulations to guard non-public personal information.
Can Children Use Our Services?
We do not knowingly collect information, including Personal Data, from children or other individuals who are not legally able to conclude contracts. If we obtain actual knowledge that we have collected Personal Data from an individual under the age of 18, we will promptly delete it, unless we are legally obligated to retain such data. Contact us if you believe that we have mistakenly or unintentionally collected information from an individual under the age of 18.
Changes to this privacy policy
We reserve the right to modify this Privacy Policy at any time in accordance with this provision. If we make changes to this Privacy Policy, we will post the revised Privacy Policy on our Website. If you disagree with the revised Privacy Policy, you can stop visiting and utilizing our Website. Your continued access to or use of the Website will be subject to the revised Privacy Policy.
Contact us
If you have any questions or complaints about this Privacy Policy or our information handling practices, you may email us to the e-mails stated above in
pt. 8.6 (How do I Complain).