Terms and conditions
Information about us
"SUNNY HILLS - ELENA SPA" Ltd. (hereinafter referred to as the "Hotel" and / or "Administrator") is a company entered in the Commercial Register and a register of the NGO, registered with the Registry Agency under UIC 204373874, address: Elena 17, Stara Planina Str., Spa Complex Elena, Tel: +359 878 911 211
Our Data Protection Officer's contacts are:
- Data Protection Officer: Kristina Koleva
- Tel: 0878 911 211
- Email: Elena_hotel@bg
The hotel, as a personal data controller, collects and processes certain information about individuals.
This information may refer to employees, managers, clients and hotel guests, suppliers, contractors, business contacts and other individuals with whom the Administrator has a connection or wants to establish business contact.
What is meant by "personal data" and "processing of personal data"?
"Personal data" means any information by which an individual may be identified directly or indirectly by one or more characteristics characteristic of the person - such as: name, identification number / personal identification number, contact details - location / postal address, telephone number, email, online identifier / IP address, etc. These signs may be part of the physical, physiological, genetic, mental, mental, economic, cultural or social identity of the individual.
"Processing of personal data" is the set of actions performed with personal data or a set of personal data such as collecting, recording, organizing, structuring, storing, adapting or modifying, retrieving, consulting, using, disclosing by transmission, dissemination or otherwise, by which data becomes available, arranged or combined, limited, deleted or destroyed.
Our attitude to your personal data
The security of the data you entrust to us is very important to us. We therefore protect your data by applying any appropriate technical and organizational means that are adequate to the potential risks to the rights and freedoms of individuals in order to prevent unauthorized access, unauthorized or malicious use, loss or premature deletion of information.
What information do we collect and why?
We may collect personal information about you when you use our Site or choose our services. In most cases, we require your personal data for the purpose of signing a contract, complying with a statutory obligation or protecting our legitimate interest. In some cases, we process data based on your consent.
Depending on the services you use, we may collect and process the following information for you:
- Name of person, single citizen number (for registration in the hotel and invoice, on request), date of birth and gender;
- Contact details - contact address, phone number and e-mail address (email);
Principles we guide and respect:
We strictly abide by the basic principles introduced as mandatory in the processing of personal data;
Personal data are processed lawfully, in good faith and transparently;
Personal data are collected for specific, explicit, and legitimate purposes and not further processed in a manner inconsistent with these purposes;
Personal data are appropriate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
Personal data are accurate and, if necessary, kept up-to-date;
Personal data shall be kept in a form that permits the identification of the persons concerned for no longer than is necessary for the purposes for which the personal data are processed;
Personal data shall be processed in such a way as to ensure an adequate level of security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, misappropriation or damage, by applying appropriate technical and organizational measures;
We process the personal data we collect most often for the following purposes:
When signing and executing a contract - to register a guest at the hotel, prepare accounting documents as an account or invoice for the services provided to you; for the purpose of notifications related to our services;
In carrying out a legal obligation - for the purpose of obligations provided by the Law on Tourism, the Accountancy Act and the Tax and Social Insurance Procedure Code and other related normative acts, in relation to the keeping of proper and lawful accounting; with obligations to provide information to all state commissions and regulators, as well as a court; when executing online booking (distance selling) and selling outside our hotel facility;
With your consent, direct marketing for our products and services.
What are your rights:
When collecting and processing your personal data you are entitled to:
Information about your personal data processed and access to personal data collected for you;
Correction / replenishment if the data are inaccurate / incomplete - on your own initiative or on the initiative of the hotel;
Deletion of personal data, if there are legal grounds for doing so;
Restrict the processing of your personal data by the hotel, provided there are legal grounds for doing so;
Data portability between individual administrators - this entitles you to receive your hotel data and transfer it to another administrator in a format appropriate for use;
An objection to the processing of your personal data, provided there are legal grounds for doing so;
Entitlement to judicial or administrative redress if your rights have been violated.
You can protect your rights by emailing us: firstname.lastname@example.org или пощата/куриер на адрес: гр. Елена, ул. „Стара планина“ № 17, СПА Комплекс Елена;
Your personal data are stored with us in accordance with the purpose for which they were collected and within the statutory deadlines.
When can we disclose your personal information:
We apply a set of measures to protect your personal data from loss, theft and misuse, as well as from unauthorized access, disclosure, alteration or destruction. The hotel uses third parties to support certain contract activities or when performing a legal obligation. We do not provide your personal data to third parties before making sure that all technical and organizational measures are taken to protect these data by striving to exercise strict control to meet this goal.
Some of the recipients of personal data can be: courier companies, external consultants and specialists, collectors and law firms, banks, security firms, sales agents and representatives, etc.
It is possible that under your law, your personal data will be disclosed. For example, with your explicit consent or if authorized by the Privacy Commission, your personal data may be shared with third parties. The provision of personal data in some cases is mandatory in order to comply with our legal requirements, such as: Regulatory bodies, incl. state commissions, institutions and agencies, NRA, NSSI, courts, prosecutor's office, etc., to which we are obliged to provide personal data under current legislation. It is possible, when necessary or appropriate, to provide your personal data for national security purposes or for issues of public concern.
Cookies and tracking
We use "cookies" to make your visit to our site more enjoyable and to enable the use of certain functionalities on different pages. These are small text files that are saved on the end device from which you visit our site. Some cookies - "session cookies" are deleted by closing your browser. Other cookies remain on your final device and allow us or affiliate companies to recognize your browser on a subsequent visit ("permanent cookies"). You can set your browser so that you are informed about the setting of "cookies" and decide individually to accept or turn off the adoption of "cookies" on specific cases or in general. You can find additional information in the help section of your internet browser. Disclaimer of cookies may limit the functionality of our website. We distinguish between system cookies and promotional cookies. Systemic cookies are necessary for the proper functioning of our website. Rejecting these cookies will change your browsing experience on our website and certain services on our website will not be usable. Promotional "cookies" are saved loading the site and help us analyze aggregate data about our visitors - for example, how come to our site, how long they spend on it, the first time you visit us, how viewing content on our site, and to conclude on the success of our marketing campaigns.
Links to social media
Our website also contains links to Facebook and Instagram. In this case, the transfer of data to the mentioned social media operators only takes place when the corresponding button on the icon illustrating the link is pressed. Clicking on such a button opens the page of the relevant social network. There you can post information about our services according to the rules of the social media operator. You can use our official contact profiles across the various social networks as well as other official public company accounts. These are ours: Facebook page https://www.facebook.com/Elena.hotel.complex/;
Instagram page https://www.instagram.com/spacomplex_elena/. Personal data you send via a personal message will only be processed for the purpose of responding to your inquiry. We are not responsible for the information and personal data that you voluntarily share in our official accounts without being expressly requested by you.
The hotel takes steps to protect your personal data from accidental loss and unauthorized access, use, modification or disclosure. There are policies and procedures designed to protect information from loss, misuse and unlawful disclosure. We also take additional information security measures, including access control, strict physical protection and reliable practices for collecting, storing and processing information.
On the other hand, we apply technical measures such as encryption, pseudonymisation and anonymisation of collected personal data.
When do we delete your personal information?
We retain all the information we have collected for you and destroy it within the statutory deadlines and, if there are none, within the time limits set by us after the final settlement of all our financial relations. We do not keep your data indefinitely.
The accounting and commercial information as well as all other information and documents relevant for taxation and mandatory insurance contributions are kept by the hotel within the following deadlines:
- salary payroll - 50 years;
- accounting records and financial reports - 10 years;
- documents for tax and social control - 5 years after expiry of the prescription period for repayment of the public obligation with which they are connected;
- all other media - 5 years, provided that no shorter term is provided for by law;
After the expiry of the storage period, the media (paper or technical) which are not subject to submission to the National Archives Fund may be destroyed.
After the storage period has expired, the data is destroyed as quickly as possible by the destruction of the hard disk by means of shredding and by the technical means by deleting and deleting the relevant files from the computers and systems of the Company.
This privacy procedure can be changed over time. Such changes will take effect immediately after their disclosure. Regular review of this page ensures that you will always be aware of what information we collect, how and for what purposes the Hotel uses it and in all circumstances (if any) we will share it with other parties.