Privacy Policy (GDPR)

Privacy Policy (GDPR)

Last updated: [insert date]
Data Controller: Aparthotel Olympus Plaza, address: Primorska Str. 6A 9649, email: [email protected], tel.: +359 897 83 52 49
Website: https://www.olympusplaza-aparthotel.com/

1. Data we collect

  • Identification and contact details: name, email, phone, country, preferred communication language.

  • Reservation data: stay dates, number of guests, accommodation preferences, booking reference.

  • Payments: last 4 digits of card/token (processed via payment provider). We do not store full card details – these are handled by certified providers (HotelRunner/payment processor).

  • Technical data: IP address, device/browser type, cookies and similar technologies.

  • Communication: emails, contact form messages, reviews.

2. Purposes and legal bases

  • Contract performance – managing reservations, invoicing, pre-/post-stay communication.

  • Legal obligations – accounting, reporting to competent authorities (e.g., tourist registers).

  • Legitimate interest – service improvement, fraud prevention, protecting rights (minimal impact, balanced with data subjects’ rights).

  • Consent – newsletters, marketing emails, analytics & advertising cookies. Consent may be withdrawn at any time.

3. Retention periods

  • Reservation/invoice data: as required by law (typically 5–10 years).

  • Marketing consent: until withdrawn + up to 24 months log.

  • Technical logs/cookies: depending on category (see “Cookie Policy”).

4. Data sharing

  • Service providers: HotelRunner (PMS/Channel Manager/booking engine), payment processors, IT/hosting support, email provider.

  • Online platforms (if used): Booking.com, Expedia, Airbnb etc. – only as required for reservations.

  • All processors are bound by contracts (Art. 28 GDPR). For transfers outside the EU – standard contractual clauses or equivalent safeguards.

5. Your rights

Access, rectification, erasure, restriction, objection, portability, withdrawal of consent, complaint to the Bulgarian DPA (www.cpdp.bg).
Contact for rights: [email protected]. If a Data Protection Officer (DPO) is appointed, contact: [email protected]+359897835249.

6. Security

We apply technical and organizational measures (access control, encryption in transit, logging, backups).

7. Contact

For privacy questions: [email protected]+359897835249, Primorska Str. 6A 9649.