Menu

Privacy Policy

The hotel, as a personal data controller, collects and processes certain information about individuals.

This information may relate to employees, managers, customers and guests of the hotel, suppliers, contractors, business contacts and other individuals with whom the Administrator has a relationship or wishes to establish business contact.

This personal data protection policy governs how personal data is collected, processed and stored to meet the standards of the Administrator’s organization and comply with legal requirements.

This personal data protection policy is issued on the basis of the Personal Data Protection Act and the by-laws implementing it, as amended, (“Bulgarian Legislation”), and the General Data Protection Regulation (EU) 2016/679 (“GDPR”).

What is meant by “personal data” and “processing of personal data”?

“Personal data” is any information by which an individual can be identified directly or indirectly by one or more characteristics characteristic of the individual – such as: name, identification number/Personal Identification Number, contact details – location/postal address, telephone number, electronic address (email), online identifier/IP address, images from video recordings, etc. These characteristics may be part of the physical, physiological, genetic, mental, intellectual, economic, cultural or social identity of the individual.

“Processing of personal data” is the set of operations performed on personal data or on sets of personal data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Our attitude towards your personal data

The hotel attaches great importance to the protection of personal data and collects and processes personal data only in compliance with the requirements of local and European legislation. The purpose of this “Personal Data Protection Policy” is to inform you how we process your data and what personal data we would collect about you, for what purpose, for what period and, respectively, what your rights are.

The security of the data you have entrusted to us is very important to us. That is why we protect your data by implementing all appropriate technical and organizational measures that are adequate to the possible risks to the rights and freedoms of natural persons, in order to prevent unauthorized access, unauthorized or malicious use, loss or premature deletion of information.

What information do we collect and why?

We may collect personal data about you when you use our Site or select our services. In most cases, we require your personal data for the purpose of entering into a contract, to comply with a legal obligation, or to protect our legitimate interest. In certain cases, we process data based on your consent.

Depending on the services you use, we may collect and process the following information about you:

  • Names of the person, unique civil number (for the purposes of registration at the Hotel and issuing an invoice, upon request);
  • Contact details – contact address, telephone number and electronic address (email).

Principles that guide us and that we adhere to

We strictly adhere to the basic principles introduced as mandatory when processing personal data:

  • Personal data is processed lawfully, fairly and transparently;
  • Personal data are collected for specific, explicit and legitimate purposes and are not further processed in a manner incompatible with those purposes;
  • The personal data are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
  • Personal data is accurate and, where necessary, kept up to date;
  • Personal data are stored in a form which permits identification of the persons concerned for no longer than is necessary for the purposes for which the personal data are processed;
  • Personal data are processed in a manner that ensures an appropriate level of security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, by implementing appropriate technical and organizational measures.

We process the personal data we collect most often for the following purposes:

  • When concluding and performing a contract – for registering the guest at the Hotel, preparing accounting documents such as a bill or invoice for the services provided to you; for the purpose of notifications related to our services;
  • In fulfillment of a legal obligation – for the purpose of obligations provided for in the Tourism Act, the Accountancy Act and the Tax and Insurance Procedure Code and other related regulatory acts, in connection with the maintenance of proper and lawful accounting; in obligations to provide information to all state commissions and regulatory bodies, as well as a court; in fulfillment of obligations in connection with online reservations (distance sales) and sales outside our hotel facility;
  • With your consent – for direct marketing of our products and services.

What are your rights?

When collecting and processing your personal data, you have the right to:

  • Information about your personal data being processed and access to the personal data collected about you;
  • Correction/completion if the data is inaccurate/incomplete – on your initiative or on the initiative of the Hotel;
  • Deletion of personal data, if there are legal grounds for this;
  • Restriction of the processing of your personal data by the Hotel, if there are legal grounds for this;
  • Portability of personal data between individual administrators – this right allows you to receive your data from the Hotel and transfer it to another administrator in a format suitable for use;
  • Objection to the processing of your personal data, if there are legal grounds for this;
  • The right to judicial or administrative protection in the event that your rights have been violated;
  • You can protect your rights by writing to us at e-mail: reservation@martinez.bg or at the address: Sozopol, Hotel Martinez
  • Your personal data is stored with us in accordance with the purpose for which it was collected and within the statutory time limits.

When may we disclose your personal data?

We implement a set of measures to protect your personal data from loss, theft and misuse, as well as from unauthorized access, disclosure, alteration or destruction. We do not provide your personal data to third parties before we have ensured that all technical and organizational measures have been taken to protect this data, and we strive to exercise strict control to fulfill this purpose.

Some of the recipients of personal data may be: courier companies, external consultants and specialists, collection companies and law firms, banks, security companies, sales agents and representatives, etc.

It is possible, under circumstances provided by law, that your personal data may be disclosed. For example, with your explicit consent or with permission from the Personal Data Protection Commission, your personal data may be provided to third parties. The provision of personal data in some cases is mandatory in order to comply with our legal requirements, such as: Regulatory authorities, incl. state commissions, institutions and agencies, NRA, NSSI, courts, prosecutor’s offices, and others to whom we are obliged to provide personal data under the current legislation. It is possible, when necessary or appropriate, that your personal data may be provided for national security purposes or in the event of problems of public importance.

Security

The hotel takes measures to protect your personal information from accidental loss and unauthorized access, use, alteration or disclosure. Policies and procedures are in place designed to protect information from loss, misuse and unauthorized disclosure. In addition, we take additional information security measures, including access controls, strict physical protection and reliable information collection, storage and processing practices.

On the other hand, we implement technical measures such as encryption, pseudonymization and anonymization of the collected personal data.

When do we delete your personal data?

We store all information we have collected about you and destroy it within the statutory deadlines, or if there are none, within the deadlines set by us after the final settlement of all our financial relations. We do not keep your data indefinitely.

Transfer between countries

The transfer, storage and processing of personal data is secured with modern technical means. The hotel will not transfer your data outside the EEA without complying with legal possibilities, and will implement appropriate safeguards to maintain the confidentiality of your information.

Destruction

After the storage period has expired, the data is destroyed as quickly as possible by destroying paper media by shredding, and on technical media – by deleting and erasing the relevant files from the Company’s computers and systems.

Changes to this “Privacy Policy”

This Privacy Policy may change from time to time. Such changes will be effective immediately upon posting. Regularly reviewing this page ensures that you are always aware of what information we collect, how and for what purposes the Hotel uses it, and under what circumstances (if any) we will share it with other parties.