Privacy Policy
1. Who processes your data
The controller of the personal data processed in connection with the website and services of Hotel Saint George is:
ET “Polikom-Slavey Dimov”
UIC: [UIC]
Address: [address]
E-mail: [e-mail]
Phone: [phone]
Hereinafter referred to as “the Hotel” or “the Controller”.
2. What personal data we may process
Depending on the way you use our website and services, we may process:
- names;
- telephone number;
- e-mail address;
- address and billing details, where necessary;
- reservation information — dates, number of guests, room type and preferences;
- data necessary in connection with accommodation and the fulfilment of legal obligations;
- the content of messages sent through contact or reservation forms;
- technical data related to the use of the website, where applicable;
- data regarding given or withdrawn cookie preferences.
We do not collect or store full bank card details when payment is made through an external payment service provider.
3. For what purposes we process the data
Personal data may be used for:
- processing and confirming reservations;
- providing hotel accommodation and related services;
- communication in connection with a reservation or enquiry;
- making and recording payments;
- issuing accounting documents;
- fulfilling obligations arising from applicable legislation;
- processing complaints and requests;
- ensuring the security and normal operation of the website;
- statistical and analytical purposes, where the necessary consent has been given;
- marketing communication, where there is a valid legal basis.
GDPR requires personal data to be collected for specific purposes, limited to what is necessary and not stored for longer than needed.
4. Legal grounds
Depending on the specific processing, the legal ground may be:
Performance of a contract or taking steps before entering into a contract — for example, in the case of an enquiry or reservation.
Legal obligation — when we are required to process or store certain information by law.
Legitimate interest — for example, to protect systems, prevent misuse or protect legal interests, where the interests and rights of the data subject do not override them.
Consent — for example, for certain analytical, marketing or other optional technologies.
5. Reservation and payment services
For online reservations, Hotel Saint George may use an external reservation system, including Quendoo.
When such a service is used, part of the data provided by you may be processed by the respective provider for the purposes of making and managing the reservation.
When payment is made through a bank or payment provider, the data necessary for processing the transaction is processed by the respective provider in accordance with its own rules and privacy policy.
6. Recipients of personal data
Where necessary, personal data may be provided to:
- reservation system providers;
- payment service providers and banks;
- accounting and other professional service providers;
- hosting, technical support and information system providers;
- competent state or municipal authorities, where required by law.
Providers who process personal data on our behalf must act in accordance with the applicable data protection rules.
7. Transfer of data outside the EEA
Some external services used on the website may involve data processing outside the European Economic Area.
Where applicable, such transfer is carried out on the basis of appropriate grounds and safeguards in accordance with GDPR.
The specific external services that use cookies or other technologies are described in the Cookie Policy.
8. How long we store the data
Personal data is stored only for the period necessary for the purposes for which it was collected, as well as for the periods required by applicable accounting, tax, tourism or other legislation.
Enquiries and correspondence that do not lead to a reservation may be deleted after they are no longer needed, unless there is a legal basis for longer storage.
9. Your rights
Under the conditions of GDPR, you have the right to:
- information about the processing;
- access to your personal data;
- correction of inaccurate or incomplete data;
- deletion, where the legal requirements are met;
- restriction of processing;
- data portability, where applicable;
- object to certain types of processing;
- withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal.
These rights are among the fundamental rights of natural persons under GDPR.
To exercise your rights, you can contact us at [privacy e-mail].
10. Complaint to a supervisory authority
If you believe that your personal data is being processed in breach of the applicable rules, you have the right to file a complaint with:
Commission for Personal Data Protection (CPDP)
Sofia 1592
2 Prof. Tsvetan Lazarov Blvd.
Current information about filing complaints is published by the CPDP.
11. Security
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, destruction or other unlawful processing.
12. Changes to this policy
This Policy may be updated in the event of changes to legal requirements, the services used or the way we process personal data.
The current version is published on the website of Hotel Saint George.