DATA PROTECTION POLICY at "BEACH RESORT" EOOD
We, „Beach Resort” EOOD, recognize the importance of protecting the personal data of our customers and partners, and we strive to maintain good policies and practices that ensure the maximum possible protection of your personal data, processed during and/or in connection with the provision of basic and/or additional tourist services for accommodation and meals, as well as other services provided on-site at the hotel managed by us -“Casa di Fiore SPA & Medical.”
This Privacy Policy is based on the requirements of the Personal Data Protection Act and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
This Privacy Policy is applied by the hotel and its official website.
All amendments and additions to the Privacy Policy will be implemented after the publication of its updated version, accessible through our website: casadifiore.com
The Privacy Policy is applicable to your personal data if you are an individual or a representative of a legal entity that uses or wishes to use the services provided at the hotel - "Casa di Fiore SPA & Medical" managed by the company "Beach Resort" EOOD, including those offered online through a specialized platform on our website, as well as through social networks.
1. Definitions: The GDPR lists a total of 26 definitions, and it is not appropriate to reproduce them here. However, the key definitions relevant to this policy are as follows:
“Personal data” means: any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
“Processing” means: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
“Processor” means: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
"Data subject's consent" means: any freely given, specific, informed and unambiguous indication of the data subject's wishes, by which he or she, by a statement or by a clear affirmative action, signifies agreement to personal data relating to him or her being processed;
2. Principles Related to the Processing of Personal Data: There are a number of fundamental principles on which the GDPR is based. They are as follows:
Personal data shall be:
• processed lawfully, fairly, and in a transparent manner in relation to the data subject (“lawfulness, fairness, and transparency”);
• collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89, paragraph (1), not be considered to be incompatible with the initial purposes (‘purpose limitation’);
• adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed (“data minimization”);
• accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);
• kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89, paragraph (1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’);
• processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).
3. Who processes and is responsible for your personal data: "Beach Resort" EOOD ("we") is a commercial company registered in the Commercial Register and the Register of Non-Profit Legal Entities with the Registry Agency with UIC BG206060846, which collects, processes and stores your personal data under the terms of this Policy and the applicable legislation of the European Union and the Republic of Bulgaria.
"Beach Resort" EOOD is a personal data controller within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and the Personal Data Protection Act.
For any questions regarding the processing of your personal data, please contact us at our registered office: Silistra, 41 Dobrudzha Str. or at the following contact details:
• website: casadifiore.com
• email: hotel@casadifiore.com
4. What data, for what purposes and on what legal basis do we process: 4.1. Depending on the specific purposes and grounds, ”Beach Resort” EOOD processes the data specified below independently or in combination with each other, namely:
A) Data provided by you, necessary for identification and execution of reservations made by you and confirmed, such as:
• full name, telephone number and/or e-mail address to contact you, or a contact person specified by you, date and time of check-in and check-out, children and their ages;
• data collected when making a payment to us – credit or debit card number, bank account and other information collected and processed in connection with making a payment via bank transfer, direct debit or via a POS terminal of "Beach Resort" EOOD;
• data from your profile for access to our online booking platform – username, history of reservations made and payments;
• data regarding the services you have used and the information obtained through them regarding your preferred services offered by us;
• health status-related data in connection with the rehabilitation services we offer;
• other data you provide to us in connection with services you have already used.
B) Data provided by you and stored by ”Beach Resort” EOOD in the process of providing on-site accommodation services at the "Casa di Fiore SPA & Medical" hotel, which data are collected, processed and stored in accordance with the current regulatory requirements regarding keeping a register of accommodated tourists by entities engaged in hotel business, namely:
• the person’s name; unique civil identification number (EGN) /for Bulgarian citizens/ or personal identification number (LNC) /for foreign citizens with a residence permit in Bulgaria/, or date of birth /in all other cases/;
• gender;
• nationality;
• ID card number /valid national identity document, country that issued the national document,
C) Other:
• Digital data—video recordings. This refers to data collected through the video surveillance systems used by “Beach Resort” EOOD in all publicly accessible areas of the “Casa di Fiore SPA & Medical” hotel (foyer, reception desk, restaurant, lobby bar, SPA center, fitness center, hallways, stairwells, entrances, parking lot, kids’ club), for the purposes of security, surveillance, monitoring, and protection of public order;
• Health status in connection with the provision of balneological services.
• IP address when visiting our website/online booking platform,
• Information related to a complaint filed regarding a travel service provided by us and used by you;
• Information regarding the type and content of your reservation, as well as any other information related to it, including e-mails, letters, requests, applications, complaints, grievances, and other feedback we receive from you;
4.2. Purposes and legal grounds for processing personal data: The main ground for processing and keeping personal data is the performance of a contract to which the data subject is a party or to take steps at the request of the data subject prior to entering into such a contract. At the same time, the processing of certain personal data is necessary for compliance with the company's legal obligations under the Labor Code, the Tourism Act, the Civil Registration Act, the Accountancy Act and other applicable laws and regulations, as well as for the protection of the legitimate interests of the controller or a third party, such as:
A) We process and store the minimum amount of personal data necessary and required by law for the purposes of providing tourist accommodation and catering services, as well as for all other services provided on-site at the “Casa di Fiore SPA & Medical Hotel,” such as:
• Customer identification when: making, modifying, or canceling a reservation, as well as when providing tourist services for accommodation and catering, as well as all other services provided on-site at the hotel. Customer identification is carried out through all commercial and communication channels - at the hotel front desk by providing an ID document, by telephone, on our online platform via an electronic contact form, by e-mail, etc.;
• Updating your personal data or information regarding services at the “Casa di Fiore SPA & Medical” hotel in response to your request to correct or modify data or services;
• Handling and responding to customer complaints/ inquiries/appeals;
• Adjusting amounts due for already made reservations for accommodation and catering if there is a reason for this;
B) In fulfillment of its legal obligations, “Beach Resort” EOOD processes your data for the following purposes:
• Providing information to the Ministry of Interior, the competent municipality where the hotel is located, the Consumer Protection Commission, and the Personal Data Protection Commission, in connection with the fulfillment of our obligations as a hotel operator arising from the applicable laws and regulations in this area;
• Processing your data contained in invoices issued in your name for other purposes compatible with the original purpose for which they were collected
• Conducting tax and social security audits by the relevant competent government authorities;
• Providing information to the court and third parties in the context of legal proceedings, for the purpose of protecting our legitimate interests, including the collection of receivables from customers through legal action;
C) "Beach Resort" also processes your data for the purposes of our following legitimate interests:
• For the purposes of direct marketing - sending offers containing information about our current offers, promotions and discounts for accommodation at the "Casa di Fiore SPA & Medical" hotel and/or changes in the terms and conditions of offers you have already used;
• To include your name, photographs, video and other data in advertising brochures, website and other publications of "Beach Resort" EOOD as a result of your participation in group events and activities organized by us at the hotel (dancing, sports activities and other entertainment).
• To protect, exercise or preserve the legal rights, privacy, safety or property of the controller, users of the controller’s services, and members of the public;
5. Categories of third parties that have access to and process your personal data: In connection with the conduct of our business and the fulfillment of our contractual obligations with our clients, we provide your data to the following groups of “recipients,” namely:
• to the data subject - whenever they exercise this right;
• to the users/customers to whom the data relates;
• to business partners – for the purposes of fulfilling the reservations you have made: travel agents and representatives in Bulgaria and abroad, transport companies and airlines, providers of the relevant basic and additional tourist services, and other subcontractors with whom we have concluded contracts;
• payment service providers for online credit card payments;
• insurance companies when reporting an insured event involving a guest staying at our hotel;
• IT companies that maintain information systems, our company website, software and platforms for managing our clients' reservations, etc.;
• public authorities (Ministry of Interior, Municipality, National Revenue Agency, National insurance institute, Consumer Protection Commission, Personal Data Protection Commission, judicial and other supervisory authorities);
• Other personal data controllers to whom "Beach Resort" EOOD provides your personal data on a legal basis and/or on the basis of a bilaterally signed contract.
We may be required – by law, in the event of litigation and/or upon request by public and governmental authorities in or outside your country of residence, as well as for the purposes of national security, law enforcement or other issues of public importance – to disclose your personal data where such disclosure is necessary or appropriate.
We may also disclose information about you if we determine that such disclosure is justified and necessary to enforce our company terms and conditions, or to protect our operations, legitimate interests and rights, as well as the legitimate interests and rights of other users. Furthermore, in the event of a reorganization, merger, or sale, we may transfer any and all collected data to the relevant third-party successor.
6. How long are your personal data stored? Security: The duration of storage of your personal data depends on the purposes of the processing for which they were collected:
• Personal data processed for the purpose of providing and performing tourist services for accommodation and meals at the "Casa di Fiore SPA & Medical" hotel are stored for a period of up to 3 (three) years, starting from the date of your departure from the hotel, as well as until the final settlement of all financial relations between the parties, in compliance with the legally established deadlines, where applicable;
• Personal data processed for the purpose of issuing accounting/financial documents to facilitate tax and social security control - including, but not limited to invoices, debit and credit notes, are stored for at least 3 (three) years, unless the applicable legislation provides for a longer
• Picture (Video recording) – up to 30 days from the creation of the recording.
Personal data may be retained for longer periods to protect the legitimate interests of ”Beach Resort” EOOD, as well as until the expiration of the relevant statute of limitations for the purpose of protection against potential customer claims related to the performance /termination of the provided tourist services for accommodation and meals in our hotels, as well as for a longer period in the event of an already arisen legal dispute - the documents are stored until its final resolution with an effective court/arbitration decision.
As a Data Controller, “Beach Resort” EOOD exercises due diligence and implements the appropriate administrative, technical, and physical measures required by law, as well as those related to personnel (training, awareness, etc./ to protect the information in its possession, including the protection of its customers’ personal data from loss, theft, and unauthorized use, disclosure, modification, and any other unlawful forms of processing. We have physical, electronic, and procedural safeguards that comply with our legal obligations regarding the protection of personal data, and we maintain these in accordance with the latest technological advancements.
We are responsible for the protection of the client's personal data that has become known to us in connection with the performance of our activities as an employer and hotel operator, when providing the tourist services we offer, as specified in the General Terms and Conditions and in this Policy, except in cases of force majeure, accidental event or malicious actions of third parties, as well as in cases where the customer has made this information available to third parties on their own.
7. Video surveillance: The common areas of the ”Casa di Fiore SPA & Medical” hotel are subject to 24-hour video surveillance, which is carried out using stationary security cameras located in the appropriate places.
Video surveillance is conducted for the purpose of protecting, exercising, or preserving the legal rights, privacy, safety or property of the controller, its employees, and/or contractors, as well as to ensure the safety, privacy and security of hotel guests and members of the public.
Video surveillance is organized and monitored by the controller's employees, specially trained in data protection.
The recordings are stored on video servers for a period of 30 days, except in cases of a reported violation of the rights of the controller, tourists, or third parties, in which case the period of storage of the recordings may be extended according to specific needs.
You have the right to request access to the recordings if you allege a violation of rights pertaining to you or to a person over whom you exercise supervision; your request will be reviewed within the timeframes specified in Section 8 of this policy. The Company may refuse to consider requests that are unreasonably repetitive, require disproportionate technical effort, or jeopardize the privacy of other users.
8. What are your rights regarding the processing of your personal data by “Beach Resort” EOOD, and what actions should you take to exercise them: • right of access to data concerning him/her - the customer has the right at any time to request from us confirmation as to whether personal data concerning him/her is being processed, information on the purposes of such processing, the categories of data and the recipients or categories of recipients to whom the data are disclosed;
• the right to correct and update their personal data when it is inaccurate or incomplete in light of the purposes of its processing;
• right to erasure (the right to "be forgotten"), when his/her data is processed unlawfully or on an obsolete basis (the original purpose for which they were collected and processed has been fulfilled, the storage period has expired (including the statute of limitations), consent for processing has been withdrawn, you have objected to their processing, etc.), there is no other basis for their processing or national or European legislation requires this;
• the right to restrict processing – in the event of a legal dispute between ”Beach Resort” and the individual until its resolution and/or for the establishment, exercise or defense of legal claims; when the processing is unlawful, but the data subject does not want the personal data to be deleted, but instead requests a restriction on their use; in the event of your objection to the processing of your personal data for the period of verification of its validity;
• right to data portability - the data subject has the right to request that we transfer his/her personal data in a machine-readable format to another controller explicitly designated by him/her without hindrance;
• obligation to notify in case of correction or deleting personal data, or restricting of processing - the customer has the right to require that we notify third parties to whom his personal data has been disclosed of any deletion, correction or blocking of this data, except in cases where this is impossible or involves excessive efforts for "Beach Resort" EOOD
• right to be notified of a personal data breach—in cases where the data breach is likely to result in a high risk to the rights and freedoms of natural persons. We are not obliged to notify you if: we have implemented appropriate technical and organizational measures to protect the data affected by the security breach, as well as we have subsequently taken measures to ensure that the breach will not result in a high risk to your rights, and if the notification would require a disproportionate effort.
• the right to object to the processing of your personal data – at any time and on grounds relating to the person's particular situation, provided that there are no compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or legal proceedings.
• When personal data are processed for direct marketing purposes, the User has the right at any time to object to the processing of personal data concerning him or her for this type of marketing, which also includes profiling to the extent that it is related to direct marketing. No later than the time of the first contact with the Userhe or she is explicitly informed of the existence of the right to object described above, which shall be provided to him or her by means of a notice in a clear manner and separately from any other information.
• Right to judicial and administrative remedies - the right to lodge a complaint with a supervisory authority, the right to an effective judicial remedy against a supervisory authority, the right to an effective judicial remedy against a controller or processor of personal data; the right to compensation for damages suffered.
Procedure for exercising rights: You can exercise all your rights regarding the protection of your personal data using the forms attached to this Policy, which you can download from here. Of course, these forms are not mandatory and you may submit your requests in any form that contains a statement to that effect and identifies you as the data owner.
"Beach Resort" EOOD shall consider and decide on the Customer's request in accordance with the requirements of the applicable legislation as soon as possible and in any case within 1 /one/ month from the receipt of the requests. If necessary, this period may be extended by an additional 2 (two) months, given the complexity and number of requests. "Beach Resort" EOOD shall inform the User of any such extension within one month from the receipt of the request, indicating the reasons for the delay.
Information about the supervisory authority:
COMMISSION FOR PERSONAL DATA PROTECTION (CPDP),
Sofia 1592, 2 ”Prof. Tsvetan Lazarov” Blvd.,
tel.: 02/91-53-518, fax: 02/91-53-525,
e-mail: kzld@cpdp.bg
www.cpdp.bg
9. Can you refuse to provide personal data to “Beach Resort” EOOD, and what are the consequences of doing so? In order to process your reservation and provide you with the accommodation services you have requested at the “Casa di Fiore SPA & Medical” hotel, we need certain data which are legally defined by the legislation in force in the Republic of Bulgaria.
Failure to provide the personal data specified in item 4 will prevent “Beach Resort” EOOD from accepting your reservation and, accordingly, from providing you with the requested services on-site at the “Casa di Fiore SPA & Medical” hotel.
10. Our Cookie Policy: "Beach Resort" EOOD uses so-called "cookies" on its website: casadifiore.com, which are important for its correct operation. By visiting our website, you accept the use of cookies.
Types of cookies we use:
• Essential cookies – these cookies are necessary for the website to function properly. For example, these cookies allow us to display information on our site, such as photos, videos, and more, and they help the search function works properly so you don’t have to enter the same information on different pages. These cookies are temporary and are deleted when you close your browser.
• Analytical cookies – thanks to these cookies we monitor the traffic on our site and can analyze how easily our users navigate it (Google Analytics cookies). These cookies do not give us any information about your personal data. They show us which pages of our site have been viewed, whether our site was visited via a mobile or desktop device and other anonymous data.
You can adjust the settings for the cookies you receive from our site in the browser you use. Please note that if you restrict some types of cookies, our site may not work properly and you may not be able to use its full functionality.
11. Changes to the Privacy Policy: “Beach Resort” EOOD reserves the right, when circumstances so require, to unilaterally update, amend, and supplement this Privacy Policy at any time in the future. Any additions or changes to this Policy will be published on the Company’s website: casadifiore.com and/or will be provided upon the customer’s request.
12. Appendix: • Data subject request form;
This policy was adopted on 04.01.2022.