Политика Конфиденциальности (GDPR)
Privacy policy
The HOTEL is a controller of personal data at the CPDP and processes the provided data and personal information in accordance with the Personal Data Protection Act and the General Regulation on Personal Data Protection (EU) 2016/679.
This Privacy Policy applies to the HOTEL and its official website.
We, as a data controller and as a professional with many years of experience in the field of tourism, respect the privacy of consumers. This security policy aims to inform you about the process of collection, processing, storage, use and redirection of personal data. Therefore, please familiarize yourself with its contents by reading it carefully. In case you have questions, you can ask them through the Contact form on the site.
DEFINITIONS
For the purposes of this policy and in accordance with Regulation (EU) 2016/679:
Personal data is any information relating to a natural person who is identified or can be identified directly or indirectly by an identification number or by one or more specific features. The data may refer to facts (for example - name, e-mail address, location or date of birth) or to an opinion about the actions or behavior of the Data Subject.
Personal data controller is a natural or legal person, public body, agency or other structure, which alone or together with others determines the purposes and means for the processing of personal data; where the purposes and means of such processing are determined by Union law or the law of a Member State, the controller or the specific criteria for its determination may be laid down in Union law or in the law of a Member State;
Processing of personal data is any action or set of actions that can be performed on personal data by automatic or other means, such as collection, recording, organizing, storing, adapting or modifying, recovering, consulting, using, disclosing by transmission , distribute, make available, update or combine, block, delete or destroy.
Processing of personal data
In order to provide and improve the services we provide and for the needs of administering the resources to them, we store, use and process personal data in compliance with the applicable legal requirements.
TYPES OF PERSONAL DATA TO BE PROCESSED
The types of personal data that the controller collects and processes are different, according to the purposes for which they are collected and the reasons for their processing:
The types of data collected according to their purposes are the following:
- In order to make a request and confirm a reservation, the HOTEL collects and processes the following types of data: а/ When booking, through the website: – Name and surname of the contact person; – e-mail address and telephone number of the contact person; б/ When booking by phone: – telephone for feedback and e-mail address for booking confirmation – Name and surname of the contact person; This data is stored until the reservation is made. The data is then destroyed and further processing is impossible. 2. For the purposes of accommodating guests in the HOTEL, the administrator processes and stores the following data: – PIN / LNC; – Name of the person (for Bulgarian citizens - in Cyrillic, for foreigners - in Latin, according to the national document); – Date of birth; – Gender; – Citizenship; – Identity card number / valid national identity document; – State that issued the national document. The data that are collected for the purposes of registration at the hotel are collected on the basis of Art. 116, para 2 of the Tourism Act and are necessary for keeping a register for the accommodated tourists. The data is stored for a period of 5 / five / calendar years. 3. For the purposes of the realization of corporate or personal events in the HOTEL the following data are processed and stored: – Two names of the person organizing the event. In case of corporate events, contact person designated by the legal entity, organizer of the event; – e-mail address and telephone number of the contact person These data are stored for up to 3 / three / calendar years after the event.
- In accordance with current regulations, you have the right of ownership and access to the data you have provided for processing. With a written application through the Contact form on the site, you can receive information about the type of personal data provided and the purpose of their processing, as well as request that we remove any records of your personal information, without the possibility of further processing. When accessing your data, you can request that it be corrected in case you find errors or inconsistencies.
- Users have the right to object to the processing of their data. The objection is addressed to the HOTEL, by the order of item 1 of the present section. The HOTEL undertakes to consider your objection and within 30 calendar days of its receipt to inform you of the result of the internal inspection.
- Consumers shall have the right to complain to the competent supervisory authority. According to the current legislation, the competent supervisory authority in the Republic of Bulgaria is the Commission for Personal Data Protection.
- Users have the right to receive their data, which the HOTEL stores when they are provided in a structured, widely used and machine-readable format. Users have the right to transfer this data to another controller of personal data without interference by the HOTEL, in cases and in respect of data provided by consent, in cases of data provided under a contract to which the user is a party or data provided by taking steps by the consumer and requesting a contract.