| Document: | Privacy Policy |
| Version: | 01 |
| Date: | 1 April 2024 |
This Privacy Policy is adopted pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the General Data Protection Regulation – GDPR).
:property_legal_name is committed to protecting the personal data of its guests, employees, partners, and any other individuals whose data it processes. This policy sets out how the organisation collects, uses, stores, and protects personal data.
This policy applies to the processing of personal data carried out in the context of the activities of :property_legal_name, regardless of whether the processing takes place within or outside the European Union, provided it relates to the offering of goods or services to data subjects in the EU or the monitoring of their behaviour within the EU.
:property_legal_name declares that it shall:
:property_legal_name, as the data controller, is responsible for and must be able to demonstrate compliance with the data protection principles. The controller implements appropriate technical and organisational measures to ensure and be able to demonstrate that processing is performed in accordance with the GDPR.
Where processing is carried out on behalf of the controller, the controller engages only processors providing sufficient guarantees to implement appropriate technical and organisational measures so that processing meets the requirements of the GDPR and ensures the protection of the rights of the data subject.
Where required by applicable law, the organisation designates a Data Protection Officer. The DPO is involved, in a timely manner, in all issues relating to the protection of personal data, reports directly to management, and operates independently in the performance of their tasks.
Under the GDPR, data subjects have the following rights:
Where processing is based on consent, the controller must be able to demonstrate that the data subject has given consent. Consent must be freely given, specific, informed, and unambiguous. The data subject has the right to withdraw consent at any time, and withdrawal must be as easy as giving consent.
Processing shall be lawful only if and to the extent that at least one of the following applies: the data subject has given consent; processing is necessary for the performance of a contract; processing is necessary for compliance with a legal obligation; processing is necessary to protect the vital interests of the data subject or another person; processing is necessary for the performance of a task carried out in the public interest; or processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party.
The organisation ensures that personal data collected is adequate, relevant, and limited to what is necessary for the purpose for which it is processed. Unnecessary data is not collected or retained.
The organisation takes reasonable steps to ensure that personal data is accurate and, where necessary, kept up to date. Inaccurate data is erased or rectified without undue delay.
Personal data is retained only for as long as is necessary to fulfil the purpose for which it was collected. The organisation establishes retention periods for different categories of data and implements procedures for the secure deletion or anonymisation of data that is no longer required.
The organisation implements appropriate technical and organisational measures to ensure the security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage.
Where personal data is transferred to a third country or international organisation, appropriate safeguards are in place in accordance with the GDPR, including but not limited to adequacy decisions, standard contractual clauses, or binding corporate rules.
In the event of a personal data breach, the controller shall notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to the rights and freedoms of natural persons, the data subjects concerned shall also be notified without undue delay.
Where a type of processing, in particular using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons, the organisation carries out an assessment of the impact of the envisaged processing operations on the protection of personal data prior to the processing.
All employees who process personal data receive appropriate training on data protection principles and procedures. Training is provided at induction and at regular intervals thereafter to ensure continued compliance with this policy and the GDPR.
Мурите Парк Хотел
powered by HotPilot
To talk with the assistant, your browser needs microphone access for this page — right now it's turned off.
Tap the icon on the left of the address bar (a camera, lock, or sliders icon), set the microphone to “Allow”, then reload this page.
Красива градина, вкусна храна, топла минерална вода, далеч от градския шум...добро място за почивка
Всичко беше наред. Обслужващият персонал в ресторанта беше малко груб на моменти. Тавана в банята на стаята беше изключително мръсен и прогнил. Стената в стаята под телевизора също.
We use cookies to run this site, remember your choices, and measure and improve it. Essential cookies are always on. Cookie Policy