Personal Data Policy
PERSONAL DATA PROTECTION POLICY
This security policy aims to inform you about the process of collection, processing, storage, use and redirection of personal data. Therefore, please familiarize yourself with its contents by reading it carefully.
The HOTEL is the data controller to the CPDP and processes the data and personal information provided in accordance with the Data Protection Act and the General Data Protection Regulation (EU) 2016/679.
This Personal Data Protection Policy is implemented by the HOTEL and its official website.
We, as a professional with many years of experience in the tourism industry and as a data controller, respect the privacy of users.
In case you have any questions, you can ask them via the Contact Form on the website.
DEFINITIONS
For the purposes of this policy and in accordance with Regulation (EU) 2016/679:
– Personal Data is any information relating to an individual who is identified or identifiable, directly or indirectly, by reference to an identification number or to one or more specific attributes. The data may relate to facts (for example – name, e-mail address, location or date of birth) or to an opinion about the Data Subject’s actions or behaviour.
A controller is a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its determination may be laid down in Union or Member State law;
Processing of personal data means any operation or set of operations which may be performed upon personal data, whether or not by automatic means, such as collection, recording, organisation, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, disclosure, updating or combination, blocking, erasure or destruction.
Processing of personal data
In order to secure and improve the services we provide and for the purposes of administering the resources to them, we store, use and process personal data in compliance with applicable legal requirements.
TYPES OF PERSONAL DATA PROCESSED
The types of personal data that the controller collects and processes vary according to the purposes for which they are collected and the grounds for processing them:
The types of data collected according to their purposes are as follows:
1. The HOTEL collects and processes the following types of data in order to realize the reservation request and confirmation:
а/ When making a reservation, via the website:
– Name and surname of the contact person;
– e-mail address and telephone number of the contact person;
б/ When booking by telephone:
– telephone number and e-mail address for confirmation of the reservation
– Name and surname of the contact person;
These data are stored until the reservation is realised. After that, the data is destroyed and its further processing is impossible.
2. For the purpose of the accommodation of guests in the HOTEL, the controller processes and stores the following data:
– Unique Citizenship Number / Personal Number of a Foreigner;
– Name of the person (for Bulgarian citizens – in Cyrillic, for foreigners – in Latin, according to the national document);
– Date of birth;
– Gender;
– Nationality;
– Identity card number/valid national identity document;
– Country issuing the national document. The data collected for hotel registration purposes are collected on the basis of Art. 116(2) of the Tourism Act and are required for the purpose of keeping a register of the tourists accommodated. The data shall be stored for a period of 5 /five/ calendar years.
PROCESSING PRINCIPLES
When processing personal data, we comply with the following principles:
– lawfulness – when collecting, processing and storing your data, we comply with the provisions of the applicable Bulgarian and European legislation;
– fairness and transparency – we process the data we collect and in accordance with this privacy policy, which is accessible to any user;
– relevance of processing to the purposes and minimisation of data – the types of data we collect are minimised according to the purposes for which they are processed. The purposes for which your data is processed are those for which we are legally obliged, have a contractual relationship or have obtained your consent to collect it;
– storage limitation – we process and store the data we receive for a period of time in accordance with the purposes for which it is needed and in accordance with your consent.
– Users’ consent to data processing – in order to use your data for marketing purposes to improve the services we provide to you, we must obtain your explicit consent to do so.
Please note that when you send an enquiry to the HOTEL (for price conditions, for a reservation, for clarification on a reservation already made, for an event and/or other questions related to the services provided by the hotel) you give your consent for the HOTEL to store and process the personal data provided by you for the purposes of the enquiry made.
In this case, your data will be deleted in accordance with current legislation and this privacy policy.
PERSONAL DATA PROTECTION
Personal data privacy.
We use electronic methods to process personal data in order to ensure accurate and prompt provision of services and assistance to users.
The process of processing your personal data provided to the HOTEL is carried out in accordance with the applicable data protection legislation, and the HOTEL respects your privacy. The HOTEL shall ensure that the persons authorised by it to process the personal data are committed to confidentiality or are obliged by law to respect confidentiality.
PERSONAL DATA SECURITY
The HOTEL implements technical and organisational security measures to protect the personal data you have provided from accidental or unlawful destruction, accidental loss, unauthorised access, alteration or dissemination, and from other unlawful forms of processing by unauthorised persons. The security measures that we apply are subject to continuous improvement and adaptation to the latest technology.
Personal data collected may be provided to the HOTEL partners who act as data processors on behalf of the HOTEL and are committed to complying with all applicable data protection regulations. We comply with the condition that the relevant information may only be used within the limits set by the legal basis on which it is collected or by your personal consent in respect of processing carried out on behalf of the HOTEL, and that such information is to be treated as confidential.
The HOTEL may disclose and provide personal information in accordance with applicable law if ordered or required to do so by a court or administrative authority or if the provision of the personal information is related to the performance of a legal obligation of the HOTEL.
The data collected for the purpose of accommodation in the HOTEL is accessible to the third parties defined in the Tourism Act – Ministry of Tourism, Municipalities, Ministry of Interior, National Revenue Agency and National Statistical Institute.
RIGHTS OF USERS REGARDING THEIR DATA
- In accordance with current legislation, you have the right to ownership and access to the data you have provided for processing. With a written request via the Contact Form on the website, you can obtain information about the type of personal data you have provided and the purpose of its processing, as well as request that we remove any records of your personal information without the possibility of further processing. By accessing your data, you can request that it be corrected in the event that you find errors or inconsistencies.
2. Users have the right to object to the processing of their data. The objection shall be addressed to the HOTEL in accordance with paragraph 1 of this section. The HOTEL undertakes to examine your objection and inform you of the result of the internal check within 30 calendar days of receipt.
3. Users have the right to lodge complaints with the competent supervisory authority. According to the current legislation, the competent supervisory authority in the Republic of Bulgaria is the Commission for Personal Data Protection.
4. Users have the right to obtain their data stored by the HOTEL when provided in a structured, widely used and machine-readable format. Users shall also have the right to transfer such data to another data controller without hindrance from the HOTEL, in the cases and in respect of data provided by consent, in the case of data provided under a contract to which the user is a party or data provided upon the user taking steps and requesting a contract.
CHANGES TO PERSONAL DATA PROTECTION RULES
The HOTEL’s privacy policy may be unilaterally changed by the HOTEL in order to improve it, offer new services, change the way we serve and communicate with our customers, and in relation to legislative changes.
When changes are made to this privacy policy, the HOTEL shall bring the changes to your attention by posting them on our website, giving you a reasonable period of time to familiarise yourself with them, after which they shall apply to the processing of your personal data without further notice. If, within this period, you declare that you reject the changes, you will be deemed to have withdrawn your consent to the processing of your personal data and the HOTEL will cease processing them in the future. This may also involve terminating your registrations for our games, services, e-newsletters, etc. for the purposes of which you originally provided us with your personal data.
Contacting the HOTEL team
If you have any questions regarding our privacy measures and policies, please send a message via the Contact Form on the Site.
