PRIVACY POLICY

This Privacy Policy applies to HOTEL IZVORA 2 and its official website www.izvora2.com, owned by STOEV RESORTS EOOD.
This security policy is intended to inform you about the process of collection, processing, storage, use and redirection of personal data. Therefore, please familiarize yourself with its contents by reading it carefully. If you have any questions, you may ask them via the Contact Form on the website.

Definitions
For the purposes of this policy and in accordance with Regulation (EU) 2016/679:
Personal data is any information relating to an individual who is identified or identifiable, directly or indirectly, by reference to an identification number or to one or more specific attributes. Data may relate to facts (for example – name, e-mail address, location or date of birth) or to an opinion about the Data Subject’s actions or behaviour.
A controller is a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of that processing are determined by Union or Member State law, the controller or the specific criteria for its determination may be laid down in Union or Member State law;
Processing of personal data means any operation or set of operations which may be performed upon personal data, whether or not by automatic means, such as collection, recording, organisation, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, disclosure, updating or combination, blocking, erasure or destruction.
In order to secure and improve the services we provide and for the purposes of administering the resources to them, we store, use and process personal data in compliance with applicable legal requirements.

TYPES OF PERSONAL DATA PROCESSED
The types of personal data that the controller collects and processes vary according to the purposes for which they are collected and the grounds for their processing:
The types of data collected according to their purposes are as follows:
1. In order to fulfil the reservation request and confirmation, the HOTEL collects and processes the following types of data:
a/ When booking, via website:
– Name and surname of the contact person;
– e-mail address and telephone number of the contact person;
b/ When booking by phone:
– feedback phone number and e-mail address for booking confirmation
– Name and surname of the contact person;
This data is stored until the reservation is realized. After that, the data is destroyed, and further processing is not possible.
2. For the purpose of accommodation of guests in the HOTEL, the administrator processes and stores the following data:
– EGN/UCN;
– Name of the person (for Bulgarian citizens – in Cyrillic, for foreigners – in Latin, according to the national document);
– Date of birth;
– Sex;
– Citizenship;
– ID card number/valid national identity document;
State issuing the national document.
The data collected for the purpose of registration at the hotel are collected on the basis of Art. 116, para. 2 of the Tourism Act and are necessary for keeping a register of the tourists accommodated. The data shall be stored for a period of 5 /five/ calendar years.
3. For the purpose of corporate or personal events at the HOTEL, the following data is processed and stored:
– Two names of the person organizing the event. For corporate events, a contact person designated by the legal entity organizing the event;
– e-mail address and telephone number of the contact person
This data is stored for up to 3 /three/ calendar years after the event.

PROCESSING PRINCIPLES
When processing personal data, we comply with the following principles:
– lawfulness – when collecting, processing and storing your data, we comply with the provisions of the applicable Bulgarian and European legislation;
– fairness and transparency – the data we collect, process and comply with this privacy policy, which is available to any user;
– relevance of processing to the purposes and data minimization – the types of data we collect are minimized in accordance with the purposes for which they are processed. Your data is processed for the purposes for which we are legally required, have a contractual relationship, or have obtained your consent to collect it.
– storage limitation – we process and store the received data for a period of time consistent with the purposes for which it is required and with your consent.
– user consent for data processing – in order to use your data for marketing purposes to improve the services we provide to you, we must obtain your explicit consent to do so.
Please note that when you send an enquiry to the HOTEL (for price conditions, for a reservation, for clarification on an already made reservation, for an event and/or other questions related to the services provided by the hotel) you give your consent to the HOTEL to store and process the personal data provided by you for the purpose of the enquiry.
In this case, your data will be deleted in accordance with current regulations and this privacy policy.

DATA PROTECTION
Privacy of personal data
We use electronic methods to process personal data in order to provide accurate and prompt service and assistance to users.
The process of processing your personal data provided to the HOTEL is carried out in accordance with the applicable data protection legislation, and the HOTEL respects your privacy. HOTEL shall ensure that persons authorised by it to process personal data are committed to confidentiality or are obliged by law to respect confidentiality.

PERSONAL DATA SECURITY
HOTEL applies technical and organizational security measures to protect the personal data you have provided from accidental or unlawful destruction, accidental loss, unauthorized access, alteration or dissemination, as well as from other unlawful forms of processing by unauthorized persons. The security measures that we apply are subject to continuous improvement and adaptation to the latest technology.
The personal data collected may be provided to HOTEL partners who act as data processors on behalf of HOTEL and are committed to complying with all applicable data protection regulations. We comply with the condition that the relevant information be used only within the limits set by the legal basis on which it is collected or by your personal consent in respect of processing performed on behalf of the HOTEL, and that such information be treated as confidential.
HOTEL may disclose and provide personal information in accordance with applicable law if a court or administrative authority orders or requires it, or if the provision of the personal data is related to HOTEL’s performance of a legal obligation. The data collected for the purpose of accommodation in the HOTEL is accessible to the third parties defined in the Tourism Act – the Ministry of Tourism, Municipalities, the Ministry of Interior, the National Revenue Agency, and the National Statistical Institute.

USERS’ RIGHTS CONCERNING THEIR DATA
1. In accordance with current legislation, you have the right of ownership and access to the data you have provided for processing. With a written request via the Contact Form on the website, you can obtain information about the type of personal data you have provided and the purpose of its processing, as well as request that we remove any records of your personal information without the possibility of further processing. By accessing your data, you can request that it be corrected in the event that you find errors or inconsistencies.
2. Users have the right to object to the processing of their data. The objection shall be addressed to the HOTEL, in accordance with paragraph 1 of this section. The HOTEL undertakes to examine your objection and inform you of the result of the internal check within 30 calendar days of its receipt.
3. Users have the right to file a complaint with the appropriate regulatory authority. The Commission for Personal Data Protection is the competent supervisory authority in the Republic of Bulgaria, according to current legislation.
4. Users have the right to obtain their data stored by the HOTEL if it is provided in a structured, widely used, and machine-readable format. Users also have the right to transfer such data to another data controller without interference from the HOTEL in the case of data provided by consent, data provided under a contract to which the user is a party, or data provided when the user takes steps and requests to enter into a contract.

CHANGES TO DATA PROTECTION RULES
HOTEL’s privacy policy may be changed unilaterally by HOTEL in order to improve it, to offer new services, to change our service and communication methods with our customers, and in response to legislative changes.
When making changes to these rules for the protection of personal data, the HOTEL shall bring to your attention the changes made by publishing them on our website, providing you with a reasonable period of time to familiarize yourself with them, after which they shall apply to the processing of your personal data, without further notice. If, within this period, you declare that you reject the changes, you will be deemed to have withdrawn your consent to the processing of your personal data and the HOTEL will cease processing them in the future. This may also involve terminating your registrations for our games, services, e-newsletters, etc. for the purposes of which you originally provided us with your personal data.
Contact with the HOTEL team
If you have any questions regarding our privacy measures and policies, please send a message via the Contact Form on the website or contact us by email at hotel_izvora2@yahoo.com.

BY BOOKING VIA THE WEBSITE, YOU GET:

10% discount;

Free parking;

Early check-in.

BEST PRICE