PERSONAL DATA PROTECTION POLICY
“BIRS” OOD, entered in the Commercial Register at the Registry Agency, with UIC: 020951471, with registered seat and head office, city of Varna, Resort Golden Sands, Marina Grand Beach Hotel, web site: www.marinagrandbeach.bg, is a Personal Data Controller (PDC) to the Commission for Personal Data Protection (CPDP) and processes the provided data and personal information pursuant to the Personal Data Protection Act and the General Data Protection Regulation (EU) 2016/679.
This Personal Data Protection Policy applies to Marina Residence Boutique Hotel and its official website https://marinaresidence.bg
We, as Personal Data Controller and as professionals, with long years of experience in the field of tourism, we respect the privacy of the personality of the users. This security policy aims to inform you about the process of collecting, processing, storing, using and redirecting personal data. Therefore, please examine its contents and read it carefully. If you have any questions, you can pose them on the following e-mail address: email@example.com
For the purposes of this policy and in accordance with Regulation (EU) 2016/679:
Personal data is any information related to a natural person, who is identified or can be identified, directly or indirectly, by an identification number or by one or more specific indications. The data may relate to facts (for example, name, e-mail address, location or date of birth) or an opinion about the actions or behaviour of the Data Subject.
A personal data controller is a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the personal data processing; when the purposes and means of such processing are determined by the law of the Union or a Member State, the controller or the specific criteria for its designation may be laid down in the Law of the Union or a Member State;
Personal data processing is any action or set of actions that may be carried out with respect to personal data by automatic or other means, such as collection, recording, organisation, storage, adaptation or alteration, restoring, consultation, use, disclosure by transmission, dissemination, provision, updating or combination, blocking, erasure or destruction.
Personal data processing
In order to provide and improve the services we provide and for the purposes of administering the resources to them, we store, use and process personal data by complying with applicable legal requirements.
TYPES OF PERSONAL DATA THAT IS PROCESSED
The types of personal data that the Controller collects and processes are different, according to the purposes for which they are collected and the reasons for their processing:
The types of data collected according to their objectives are as follows: 1. For the realization of booking and confirmation of a reservation, “BIRC” OOD collects and processes the following types of data:
a) When booking through a website:
– Name and surname of the contact person;
– e-mail address and telephone of the contact person;
b) When booking by phone:
– telephone for feedback and e-mail address for confirmation of the reservation
– Name and surname of the contact person;
This data is stored until the reservation is made. After that, the data is destroyed and its subsequent processing is not possible.
2. For the purpose of accommodating guests at Marina Residence Boutique Hotel, the controller processes and stores the following data:
– Personal Identification Number/ Personal Number of Foreigner:
– Name of the person (for Bulgarian citizens – in Cyrillic, for foreigners – in Latin, according to the national document);
– Date of birth;
– ID card number/ valid national identity document;
– Country, issuing the national document.
The data collected for the purposes of registration at the hotel is collected on the basis of art. 116, para. 2 of the Tourism Act and is necessary for keeping a register for the accommodated tourists. The data shall be kept for a period of 5 (five) calendar years.
3. For the purpose of realization of corporate or personal events the following data is processed and stored at Marina Residence Boutique Hotel:
– Name and family name of the person organizing the event. For corporate events, a contact person designated by the legal person organising the event;
– e-mail address and telephone of the contact person;
This data is kept for up to 3 (three) calendar years after the event has been implemented.
PRINCIPLES OF PROCESSING
When processing personal data, we adhere to the following principles:
– legality – when collecting, processing and storing your data, we comply with the provisions of the applicable Bulgarian and European legislation;
– relevance of processing with the purposes and reducing data to the minimum – the types of data we collect are reduced to a minimum, according to the purposes for which they are processed. The purposes for which your data is processed are those, for which we are legally committed, for which we have a contractual relationship or for their collection, we have obtained your consent;
– limitation of storage – we process and store the data obtained, for a period of time, according to the purposes for which it is needed and according to your consent.
– user consent to data processing – in order to use your data for marketing purposes, in order to improve the services we provide you, we must obtain your explicit consent to do so.
PERSONAL DATA PROTECTION
Personal data privacy
We use electronic methods for processing personal data in order to ensure accurate and rapid provision of services and assistance to users.
The process of processing your personal data provided to BIRC OOD is carried out in accordance with the applicable legislation in the field of personal data protection, and BIRC OOD respects your personal privacy.
PERSONAL DATA SECURITY
“BIRS” OOD implements technical and organizational security measures in order to protect the personal data you have provided, from accidental or unlawful destruction, accidental loss, unauthorized access, alteration or dissemination, and other unlawful forms of processing on the part of the unauthorised for that persons. The security measures we apply are subject to constant improvement and adaptation to the most modern technologies.
The personal data collected can be provided to partners of “BIRS” OOD, who act as processors of personal data on behalf of “BIRS” OOD and are committed to comply with all applicable norms of personal data protection. We comply to the condition that the relevant information may be used only within the limits set by the legal basis due to which it is collected or by your personal consent to the processing, carried out on behalf of “BIRS ” OOD, and that this information should be treated as confidential.
“BIRS” OOD may disclose and provide personal information according to the applicable law if a court or administrative authority orders or requests it or if the provision of personal data is related to the fulfilment of a legal obligation of “BIRS” OOD. The data collected for the purpose of accommodation at Marina Residence Boutique Hotel is accessible to the third parties defined in the Tourism Act – Ministry of Tourism, Varna Municipality and the Minister of Interior, the National Revenue Agency and the National Statistics Institute.
CONSUMER RIGHTS CONCERNING THEIR DATA
1. In accordance with current regulations, you are entitled to ownership and access to the data you have provided for processing. By written application to the e-mail address: firstname.lastname@example.org, you can obtain information about the type of personal data provided and the purpose of its processing, as well as to request that we remove any records of your personal information without the possibility of further processing. Receiving access to your data, you may request that its correction in case you find any errors or inconsistencies.
The written statement may be made in person (or by a person authorized by a notary certified power of attorney) at the specified contact address or electronically, from the e-mail address you have provided to us, as data for processing.
Contact address and exercise of the rights described above: BIRS OOD, Address: city of Varna, Bulgaria, resort Golden Sands, Hotel Marina Grand Beach, e-mail: email@example.com
2. Users have the right to object to the processing of their data. The objection is addressed to “BIRS” OOD, in accordance with item 1 of this section. “BIRS” OOD is committed to examining your objection and within 30 calendar days of its receipt to inform you of the result of the internal verification carried out.
3. Users are entitled to complain to the competent supervisory authority. Under the current legal framework, a competent supervisory authority in the Republic of Bulgaria is the Commission for Personal Data Protection.
4. Users are entitled to receive their data, which “BIRS” OOD stores, when they are provided in a structured, widely used and machine-readable format. Users are also entitled to transfer this data to another data controller without obstruction by “BIRS” OOD, in cases and in relation to the data provided by consent, in the case of data, provided under a contract to which the user is a party or data provided when the user takes steps and request the conclusion of a contract.
CHANGES TO THE RULES FOR PERSONAL DATA PROTECTION
The rules of BIRS OOD for personal data protection can be changed unilaterally by BIRS OOD with a view to their improvement, offering new services, changes in the way of servicing and communication with our customers, as well as in connection with legislative changes.
When making changes to these rules for personal data protection, BIRS OOD brings to your attention the changes made, by posting them on our website www.marinaresidence.bg, providing you reasonable time to get acquainted with them, after the expiration of which they begin to apply to the processing of your personal data without further notice. If within this period you declare that you reject the changes, you will be deemed to have withdrawn your consent to the processing of your personal data and BIRS OOD will cease to process them in the future. This may also be related to the termination of your registrations for our games, services, e-newsletters, etc., for the purposes of which you initially provided us with your personal data.
To contact the team of “BIRS” OOD if you have questions regarding our measures and rules regarding personal data protection, please send a message to the following address with the topic “BIRS” OOD – Personal Data Protection: firstname.lastname@example.org
NOTIFICATION OF CONFIDENTIAL TREATMENT OF PERSONAL DATA
“Birs” OOD, entered in the Commercial Register at the Registered Agency with UIC 020951471 is a Personal Data Controller (PDC) within the meaning of Regulation (EU) 2016/679 and other applicable acts of the European Union and of the Republic of Bulgaria.
As such, it is particularly responsible for the right to privacy of individuals and ensures, to the fullest extent possible, the protection of their personal data in the processing process in relation to its activities.
This communication is intended, in accordance with the requirements for awareness under art. 13 and art. 14 of the GDPR (General Data Protection Regulation) to inform you about the activities of the PDC for processing of personal data, the purposes for which the data is processed, the measures and the safeguards for the protection of the processed data, your rights and the way to exercise them.
For all matters relating to the processing of your personal data, you may contact the Data Protection Officer of Birs OOD at the e-mail: email@example.com. In your communication, you should indicate the data needed for your individualization and a contact for feedback.
You can also contact us at our management address: Varna, Bulgaria, resort Golden Sands, Hotel Marina Grand Beach.
What personal data do we collect, for what purposes and on what legal basis do we process them?
As Personal Data Controller (PDC) “Birs” OOD collects personal data for specific purposes, precisely defined by law and processes them lawfully and in good faith.
In carrying out its activities, the PDC processes personal data of individuals for the following purposes:
- For the purposes of its lawful (legitimate) interest;
- For fulfilment of contractual obligations or for taking steps at the request of the customer before concluding a contract;
- For compliance with a legal obligation that applies to the company;
- In case of explicit consent from you as a customer;
The reasons that entitle us to process your data are set in detail in the Tourism Act, the Civil Registration Act (the obligatory hotel registration in the establishment where you will be staying), the Electronic Document Act and the electronic certification services (in case of payment via POS terminals) and other relevant normative acts.
In carrying out our activities, the company processes personal data of natural persons for the execution of the contracts it concludes. In connection with their implementation, the data controller collects and processes personal data of individuals, limited to what is necessary for the proper execution of the obligations under the relevant contract. Access to this information shall be made available to third parties only where specified in a specific law.
In order to fulfil its obligations under a contract, the company sometimes processes also data of children under the age of 18, provided by their legal representatives – a party to the contract with us. Children’s data at the hotel accommodation is necessary to the extent required by the regulatory requirements.
When we process personal data based on the subject’s consent, the data is only processed if the persons have expressed their consent to the processing freely, specifically, informed and unambiguously.
On our sites we provide video surveillance in order to protect, exercise or maintain the legal rights, privacy, safety or ownership of the controller, its employees and/or contractors, as well as to ensure the safety, privacy and security of the hotel guests and members of the public. Video surveillance recordings shall be kept for a period of one month. Only certain employees within the framework of their duties have access to the data. The purpose of collecting personal data is to identify individuals for access control purposes.
“Birc” OOD processes your data only for the purposes for which it was collected and does not use them for other purposes. These purposes are entirely related to the use of tourist services offered by the company.
As a PDC “Birs” OOD stores your personal data on paper and technical media and implements the necessary technical and organizational measures to ensure an appropriate level of security, including protection against unauthorized access, accidental loss, destruction or damage.
According to the purposes, different types of personal data are collected:
- For filing or confirming a reservation, “Birc” OOD collects the following types of data:
- When booking, through the website – name and surname of the contact person; Contact person’s e-mail address;
- When booking by phone – telephone for feedback and e-mail address for confirmation of the reservation; Name and surname of the contact person.
This data is stored until the reservation is made. After that the data is destroyed and its subsequent processing is not possible.
- We process and store the following data upon check-in for guests:
- Personal Identification Number/ Personal Number of Foreigner;
- Name of the person (figures are written according to the national document); Дата на раждане;
- Date of birth;
- ID Card number/ valid national identity document;
- Country issuing the national document.
On the basis of art. 116, para. 2 of the Tourism Act, the data in the register of accommodated tourists shall be kept for a period of five calendar years.
- The following data is processed and stored for realization of corporate or personal events by the PDC:
- First name and surname of the person – organizer of the event. In case of corporate events – a contact person designated by the legal entity organising the event;
- E-mail address and telephone number to contact the person.
This data shall be kept for a period of up to two calendar years after the event has been implemented.
- For direct marketing purposes, including analysing and profiling target audiences to track customer satisfaction, we process the following data:
- E-mail address;
- IP address;
- Place of living;
- Behaviour of the users of the site of “Birc” OOD
The explicit consent of the data subject is required for the processing and storage of such data. The data that is processed for direct marketing purposes shall be kept for a period of two years or until the consent has been withdrawn.
The purpose of collecting this data is to provide you with personal suggestions and services tailored to your needs and expectations.
Transfer of personal data to a non-EU country or an international organisation?
The company does not provide personal data to third parties outside the EU or to an international organisation without obtaining your consent first.
How long do we store your personal data?
As a PDC “Birc” OOD stores your personal data for a period no longer than the requirements of the applicable legislation for the respective stipulated period.
What are your rights?
As a PDC, we have taken measures to protect your personal data in accordance with the requirements of regulation 2016/679, which are aimed at securing the rights of the subjects whose personal data is processed, namely:
– Right of access;
– Right to correct inaccurate or incomplete data;
– Right to deletion (right to be forgotten), if the conditions of art. 17 of REGULATION 2016/679 are applicable
– Right to restriction of processing;
– Right to data portability, if the conditions for portability under art. 20 of REGULATION 2016/679 are present;
– Right to object if the conditions of art. 21 of REGULATION 2016/679 apply.
– The right of the data subject not to be the subject of a decision based solely on automated processing, involving profiling.
How can you apply your rights?
You can exercise the above rights by submitting a written application (either in person or through a expressly authorized person by means of a notary certified power of attorney) to the data controller (“Birc” OOD), in which you should specify your request. The request should be signed and sent to the address of the PDC. The application can be submitted electronically in accordance with the Law on Electronic Document and Electronic Signature.
You have a right to appeal to the supervisory authority.
You have the right to complain to the supervisory authority and the competent authority is the Personal Data Protection Commission, with address: 1592 Sofia, Bulgaria No.2 Prof. Tsvetan Lazarov Blvd. (www.cpdp.bg).
If you wish to file a complaint regarding the processing of your personal data by the PDC (recipients, including non-EU and international organisations), you can do so on the company’s contact details or directly to the Data Protection Officer.