1. Introduction
This Privacy Policy is adopted pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the General Data Protection Regulation – GDPR).
:property_legal_name is committed to protecting the personal data of its guests, employees, partners, and any other individuals whose data it processes. This policy sets out how the organisation collects, uses, stores, and protects personal data.
2. Material and Territorial Scope
This policy applies to the processing of personal data carried out in the context of the activities of :property_legal_name, regardless of whether the processing takes place within or outside the European Union, provided it relates to the offering of goods or services to data subjects in the EU or the monitoring of their behaviour within the EU.
3. Definitions
- Personal data – Any information relating to an identified or identifiable natural person (data subject). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
- Sensitive data (special categories) – Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification purposes, data concerning health, or data concerning a person’s sex life or sexual orientation.
- Processing – Any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
- Controller – The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Data subject – An identified or identifiable natural person whose personal data is processed.
- Consent – Any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
- Child – Under the GDPR, specific protections apply to children. In Bulgaria, the age limit for consent to information society services is 14 years.
- Profiling – Any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.
- Personal data breach – A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
- Main establishment – The place of the controller’s central administration in the EU, or the place where decisions on the purposes and means of processing are taken, if different from the central administration.
- Recipient – A natural or legal person, public authority, agency, or another body to which personal data is disclosed.
- Third party – A natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
4. Policy Declaration
:property_legal_name declares that it shall:
- Process personal data lawfully, fairly, and in a transparent manner in relation to the data subject.
- Collect personal data only for specified, explicit, and legitimate purposes and not further process it in a manner incompatible with those purposes.
- Ensure that personal data is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
- Take every reasonable step to ensure that inaccurate personal data is erased or rectified without delay.
- Keep personal data in a form permitting identification of data subjects for no longer than is necessary for the purposes for which the data is processed.
- Process personal data in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical and organisational measures.
5. Obligations and Responsibilities
5.1 Data Controller
:property_legal_name, as the data controller, is responsible for and must be able to demonstrate compliance with the data protection principles. The controller implements appropriate technical and organisational measures to ensure and be able to demonstrate that processing is performed in accordance with the GDPR.
5.2 Data Processor
Where processing is carried out on behalf of the controller, the controller engages only processors providing sufficient guarantees to implement appropriate technical and organisational measures so that processing meets the requirements of the GDPR and ensures the protection of the rights of the data subject.
5.3 Data Protection Officer (DPO)
Where required by applicable law, the organisation designates a Data Protection Officer. The DPO is involved, in a timely manner, in all issues relating to the protection of personal data, reports directly to management, and operates independently in the performance of their tasks.
6. Data Protection Principles
- Lawfulness, fairness, and transparency – Personal data is processed lawfully, fairly, and in a transparent manner.
- Purpose limitation – Data is collected for specified, explicit, and legitimate purposes and is not further processed in a manner incompatible with those purposes.
- Data minimisation – Data collected is adequate, relevant, and limited to what is necessary.
- Accuracy – Personal data is accurate and, where necessary, kept up to date.
- Storage limitation – Data is kept in an identifiable form for no longer than is necessary.
- Integrity and confidentiality – Data is processed with appropriate security measures in place.
- Accountability – The controller is responsible for and must be able to demonstrate compliance with all of the above principles.
7. Rights of the Data Subject
Under the GDPR, data subjects have the following rights:
- Right to information – The right to be informed about the collection and use of their personal data.
- Right of access – The right to obtain confirmation as to whether personal data concerning them is being processed, and, where that is the case, access to the personal data.
- Right to rectification – The right to obtain rectification of inaccurate personal data without undue delay.
- Right to erasure (right to be forgotten) – The right to obtain the erasure of personal data under certain circumstances.
- Right to restriction of processing – The right to obtain restriction of processing in certain cases.
- Right to data portability – The right to receive personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
- Right to object – The right to object to processing based on legitimate interests or for direct marketing purposes.
- Rights related to automated decision-making and profiling – The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects the data subject.
8. Consent
Where processing is based on consent, the controller must be able to demonstrate that the data subject has given consent. Consent must be freely given, specific, informed, and unambiguous. The data subject has the right to withdraw consent at any time, and withdrawal must be as easy as giving consent.
9. Lawful Basis for Processing
Processing shall be lawful only if and to the extent that at least one of the following applies: the data subject has given consent; processing is necessary for the performance of a contract; processing is necessary for compliance with a legal obligation; processing is necessary to protect the vital interests of the data subject or another person; processing is necessary for the performance of a task carried out in the public interest; or processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party.
10. Data Minimisation
The organisation ensures that personal data collected is adequate, relevant, and limited to what is necessary for the purpose for which it is processed. Unnecessary data is not collected or retained.
11. Accuracy
The organisation takes reasonable steps to ensure that personal data is accurate and, where necessary, kept up to date. Inaccurate data is erased or rectified without undue delay.
12. Storage Limitation
Personal data is retained only for as long as is necessary to fulfil the purpose for which it was collected. The organisation establishes retention periods for different categories of data and implements procedures for the secure deletion or anonymisation of data that is no longer required.
13. Integrity and Confidentiality
The organisation implements appropriate technical and organisational measures to ensure the security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage.
14. Transfer of Personal Data
Where personal data is transferred to a third country or international organisation, appropriate safeguards are in place in accordance with the GDPR, including but not limited to adequacy decisions, standard contractual clauses, or binding corporate rules.
15. Data Breach Notification
In the event of a personal data breach, the controller shall notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to the rights and freedoms of natural persons, the data subjects concerned shall also be notified without undue delay.
16. Data Protection Impact Assessment (DPIA)
Where a type of processing, in particular using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons, the organisation carries out an assessment of the impact of the envisaged processing operations on the protection of personal data prior to the processing.
17. Training
All employees who process personal data receive appropriate training on data protection principles and procedures. Training is provided at induction and at regular intervals thereafter to ensure continued compliance with this policy and the GDPR.