Privacy Policy

Please read this document carefully. It contains the Policy for the protection of personal data of clients of Via Serdika OOD ("Policy/s") and aims to explain the practices related to the processing of personal data in the context of the services provided and the activities performed.

This Policy has been prepared in accordance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the Regulation).

POLIC FOR THE PROTECTION OF PERSONAL DATA OF CLIENTS OF Via Serdika OOD

GENERAL PROVISIONS

Art. 1. In connection with the provision of its services and the performance of its activities, Via Serdika OOD ("HOTEL Via Serdika SOFIA") processes as an administrator the personal data of its clients - individuals, as well as the personal data of other individuals specified below ("Data Subjects"/ "You"), in accordance with the rules and principles provided for in this Policy.

Art. 2. "Via Serdika" OOD is a company with UIC 207662706, with its registered office and management address at 53 Konstantin Stoilov Str., 1202 Sofia, Bulgaria, tel.: ++359 88 888 7775, e-mail address: [email protected]

 VAT number: BG207662706.

DATA SUBJECTS

Art. 3. (1) In connection with the services provided, HOTEL Via Serdika SOFIA processes information regarding the following Data Subjects:

(a) individuals visiting the website https://hotelviaserdika.com/ (the Website);

(b) individuals making reservations on their own behalf or on behalf of another individual or legal entity through the Website;

(c) individuals using the services provided by HOTEL Via Serdika SOFIA, including, but not limited to, hotel accommodation services, restaurant services and related services, provision of premises for organizing conference and other events, etc. sub., as well as individuals representing or otherwise acting on behalf of legal entities that use these services;

(d) individuals who have sent, on their own behalf or on behalf of another person they represent, inquiries (including, but not limited to, by e-mail, by fax, by call, using the Instant Messaging functionality of the Website, etc.), requests, signals, complaints or other correspondence to HOTEL Via Serdika SOFIA;

(e) individuals whose information is contained in inquiries (including by call or using the Instant Messaging functionality of the Website), requests, signals, complaints or other correspondence to HOTEL Via Serdika SOFIA.

(2) The services of HOTEL Via Serdika SOFIA can only be requested by legally capable persons who have reached the age of 18.  

CATEGORIES OF PERSONAL DATA

Art. 4. The information (categories of personal data) that HOTEL Via Serdika SOFIA processes regarding Data Subjects in accordance with this Policy may include:

1. In connection with the provision of hotel accommodation services:

(a) Identification data: guest names; date of birth; gender; nationality; national identification number (such as EGN for Bulgarian citizens) and/or identity document number; date of issue of identity document; validity of identity documents; country that issued the identity document; signature.

(b) Contact details: telephone; e-mail address; address.

(c) Information related to hotel accommodation: room number; floor; dates of stay (arrival date and departure date); length of stay (number of nights spent); use of a tourist package; preference for room type (smoking/non-smoking); VIP status of a guest;

(e) Additional information related to hotel accommodation upon explicit request by the user of the services: special requirements and preferences, incl. for type of press, for food and beverages; special requirements related to food products, beverages and other substances with which the guest is prevented from coming into contact/touch (regardless of the reason).

2. Data related tous with payments and issuing invoices: information on the method of payment (in cash, by bank transfer, by credit card, etc.); information on payments due and made; information on payment terms and overdue/unpaid debts; bank information (bank, IBAN, bank account holder); currency of the payment made; number, validity and holder of a credit/debit card; CVC code; data contained in a payment authorization form (slip); name of a legal entity; address of a legal entity; VAT number and/or other identification, tax or registration number (Personal Identification Number for individuals); authorization forms (signed).

3. In connection with the provision of restaurant services:

(a) Identification data: names.

(b) Contact details: telephone; e-mail address; address.

(c) Data related to payments and invoicing: number, validity and holder of a credit/debit card; CVC code; name of legal entity; address of legal entity; VAT number and/or other tax or registration number (for ET and for individuals); authorization forms (signed).

(d) Information related to preferences (if explicitly requested by the user): preferences for food and beverages; preferred method of payment; special requirements related to food products, beverages and other substances with which the guest is prevented from coming into contact/touch (regardless of the reason).

4. In cases where the Data Subject represents another person (e.g. a company): information about which person and in what capacity (including place of work, position), as well as information about the requested services/orders placed in this capacity. Accordingly, in cases where the services are requested by a person other than the Data Subject for the benefit of the Data Subject - in what capacity the Data Subject will use the services, by whom they were requested, by whom the payment will be made, etc. (e.g. in the case of accommodations organized by an employer or business partner of the Data Subject, etc.).

cases where the Data Subject represents another person (e.g. a company): information about which person and in what capacity (incl. place of work, position), as well as information about the requested services/orders made in this capacity. Accordingly, in cases where the services are requested by a person other than the Data Subject for the benefit of the Data Subject - in what capacity the Data Subject will use the services, by whom they were requested, by whom the payment will be made, and the like. (e.g. accommodation organized by an employer or business partner of the Data Subject and the like).

5. In connection with the issuance of customer discount cards:

(a) Identification data: names.

(b) information about the discount that can be used with the relevant customer card.

6. In connection with the services and functionalities of the Website:

(a) Data processed in connection with making a hotel accommodation reservation: names; e-mail address; telephone; country; number, validity and holder of a credit/debit card; CVC code; number of rooms; number of guests, including number of adults and number of children; corporate code/access code; event and/or group accommodation participant code; reservation number; special offers and preferences of the guest (if explicitly stated in the reservation form); package details (e.g. Honeymoon package, special occasion package, weekend package Explore Sofia, etc.).

(b) Data processed in connection with making purchases in the e-shop of the Website, accessible at https://hotelviaserdika.com/ registration data (names; e-mail address; telephone; fax; name of legal entity; address; town; postal code; region; country; password); order history; data on purchased vouchers (number; requested personal message); history of payments made; number, validity and holder of a credit/debit card; CVC code; bank account details; order number;

(c) Unstructured content from conversations with and inquiries to a booking agent via the Instant Messaging functionality of the Website.

(d) Information from account login logs, server logs and logs of security devices (Web Application Firewalls) and other devices falling into this category: date and time, IP address, URL, browser and device information.

(e) Cookies: The Website requires the use of cookies. A detailed description of the cookies used, their purpose and informationThe data processed through them can be found in the Cookie Policy of HOTEL Via Serdika SOFIA, available at: https://hotelviaserdika.com/

In connection with complaints, applications, requests, requests and signals submitted by customers (incl. in free text): unstructured information contained in the relevant complaints, applications, requests, requests and signals.

VIDEO SURVEILLANCE AND SECURITY

Art. 5. (1) In accordance with the requirements of the applicable legislation, HOTEL Via Serdika SOFIA applies security measures, which include the following technical and organizational means for access control and for ensuring physical security against encroachments on buildings and facilities and for protecting the life and health of citizens: physical security, security alarm systems and a video surveillance system, performing 24-hour video surveillance and consisting of recording and storage devices.

(2) Video surveillance and video recording may be carried out in publicly accessible areas and premises in the buildings of HOTEL Via Serdika SOFIA and in those for which a special access regime is provided. Video surveillance is not carried out in guest rooms, sanitary and hygienic premises, recreation rooms, etc. under. The data from the video surveillance activities are stored in a monitoring room with limited access and 24-hour security.

(3) Through information boards placed in a prominent place, the Data Subjects and other visitors who may be filmed are notified of the use of technical means of surveillance and control and of any other relevant information in connection with the surveillance carried out.

DIRECT MARKETING

Art. 6. (1) With the explicit consent of the Data Subject, HOTEL Via Serdika SOFIA, or other companies affiliated with or partners of GRAND HOTEL SOFIA may process the following personal data: names; telephone; address; e-mail address; information about the type and volume of used and preferred services provided by HOTEL Via Serdika SOFIA and other data explicitly mentioned in the relevant consent, for the purposes of direct marketing such as offering other goods and services, including offering goods and/or services offered by other persons, conducting surveys, polls with a view to improving the quality of the services provided, etc. according to the scope of the specifically given consent.

(2) When personal data are processed for the purposes of direct marketing, the Data Subject has the right at any time to object to this processing of personal data. In these cases, the processing of personal data for these purposes shall be terminated.

(3) The Data Subject has the right at any time to withdraw the consent given by him to the processing of his personal data for the purposes of direct marketing. In these cases, the processing of personal data based on the given consent shall cease.

(4) Profiling for the purposes of direct marketing may only be carried out with the explicit consent of the Data Subject, subject to at least the following additional safeguards for their rights and interests: right to human intervention by the controller; right to express their point of view and right to contest decisions based on profiling. At present, HOTEL Via Serdika SOFIA does not carry out such personal data processing activities.

PURPOSES OF PROCESSING PERSONAL DATA

Art. 7. HOTEL Via Serdika SOFIA collects, stores and processes the information described in Art. 4, 5 and 6 above, for the purposes provided for in this Policy and in the general terms and conditions (contract) for the use of the relevant services it provides. Depending on the legal basis for the processing, these purposes may be:

(a) purposes related to compliance with legal obligations of HOTEL Via Serdika SOFIA;

(b) purposes related to and/or necessary for the performance of contracts concluded with HOTEL Via Serdika SOFIA or to take steps at the request of the Data Subject prior to entering into a contract;

(c) purposes of the legitimate interest of HOTEL Via Serdika SOFIA or of third parties;

(d) purposes for which the Data Subject has consented to the processing of his/her data.

Art. 8. The purposes for processing personal data by HOTEL Via Serdika SOFIA related to compliance with legal obligations include:

1. wateris a register of accommodated tourists and submission of information from it to the competent authorities in accordance with the statutory procedure;

2. address registration of foreigners in accordance with the requirements of the applicable legislation;

3. withholding and payment of tourist tax;

4. activities related to the development and introduction of measures to counter terrorism;

5. handling of signals, complaints, requests for the exercise of rights and the like, as well as of claims and commercial guarantees (if applicable), including the preparation of responses thereto;

6. accounting, invoicing and reporting of payments received and made in accordance with the current tax and accounting legislation;

7. other activities to fulfill legal obligations (tax, accounting, regulatory, licensing, etc.) of HOTEL Via Serdika SOFIA, related to providing information to competent state and judicial authorities and providing assistance in inspections by competent authorities.

Art. 9. The purposes of processing personal data by HOTEL Via Serdika SOFIA, related to and/or necessary for the performance of contracts or to take steps at the request of the Data Subject prior to concluding a contract with HOTEL Via Serdika SOFIA, include:

1. accepting, administering and processing reservations and cancelled reservations;

2. serving customers, including providing online services via the Website;

3. providing the possibility of registering an account and administering and maintaining registered accounts in the online store accessible via the Website;

4. administering, fulfilling and delivering purchases made via the Website;

5. implementing of communication related to the services provided;

6. administration and receipt of payments for the services provided, incl. remotely;

7. providing a guarantee for reservations made and for the payment of hotel accommodation and additional requested services;

8. financial and accounting activities and administration, processing and collection of payments due for the services provided;

9. reimbursement of incorrectly transferred amounts;

10. ensuring an individual approach to the provision of services, consistent with the preferences stated by the users.

Art. 10. The purposes of processing personal data related to the implementation of the legitimate interests of HOTEL Via Serdika SOFIA or third parties include:

1.  Legitimate interest – (1.1.) exercising and protecting the legitimate rights and interests of HOTEL Via Serdika SOFIA; and (1.2.) assisting in exercising and protecting the legitimate rights and interests of clients; of other persons related to HOTEL Via Serdika SOFIA; of employees of HOTEL Via Serdika SOFIA; of persons processing personal data on behalf of HOTEL Via Serdika SOFIA; and of business partners of HOTEL Via Serdika SOFIA:

(a) establishing, exercising or defending legal claims of the above-mentioned persons under items (1.1) and (1.2), incl. and by court order, including filing complaints, signals, etc. to the competent state and judicial authorities;

(b) video surveillance and access control for the purpose of protecting the property of HOTEL Via Serdika SOFIA, proving compliance with applicable requirements, ensuring physical security against encroachments on buildings and sites and protecting the life and health of citizens;

(b) taking actions to suspend the provision of services in the event of refusal to pay, violation of the rules and policies established by HOTEL Via Serdika SOFIA, etc.;

(c) administering and servicing received complaints, signals, requests, etc. sub.;

(d) collection of receivables due to HOTEL Via Serdika SOFIA, including by compulsory order and/or by assignment to third parties, as well as transfer of receivables to third parties (assignments) in accordance with the procedure established by law;

(e) issuing notarial invitations.

2.  Legitimate interest – analysis, planning and improvement of the quality of the services provided by HOTEL Youa Serdika SOFIA:

(a) maintaining a copy of the data from the internal information system, in connection with the current status of the hotel (occupancy, liabilities, etc.) in the event of a failure of the information systems;

(b) receiving, processing and preparing responses to submitted applications, requests, etc. sub., unrelated to complaints and grievances from the Services used;

(c) survey of customer and service user satisfaction;

(d) control, analysis and optimization of business processes to improve the quality of services.

3.  Legitimate interest – ensuring the normal functioning and use of the Website:

(a) maintenance and administration of the Website;

(b) detection and resolution of technical problems with the functionalities of the Website;

(c) taking measures against malicious actions against the security and normal functioning of the Website.

4.  Legitimate interest – carrying out hotel and restaurant activities and providing quality hotel and restaurant services:

(a) administration and management of the services provided by HOTEL Via Serdika SOFIA;

(b) management and quality control of the services provided;

(c) receiving feedback on the services provided.

Art. 11. The purposes for processing personal data on the basis of consent given by the Data Subject include:

1. Sending marketing and advertising messages for services, special offers, packages, events and the like;

2. Surveys and receiving feedback on the quality of services;

3. Sending newsletters;

4. Other purposes for which consent has been specifically provided by the Data Subject.

PROVISION OF PERSONAL DATA AND CONSEQUENCES OF REFUSAL TO PROVIDE THEM TO HOTEL Via Serdika SOFIA

Art. 12. (1) HOTEL Via Serdika SOFIA clearly indicates, where applicable and in an appropriate manner, whether the indication/provision of the relevant data and/or documents is mandatory or constitutes a requirement necessary for the conclusion or performance of a contract, as well as the consequences of refusal to provide it.

(2) If additional clarifications are needed, each Data Subject may request such at the facilities of HOTEL Via Serdika SOFIA or send an inquiry to the contacts specified in Art. 23 of this Policy.

(3)  Refusal to provide data and documents specified as mandatory may constitute an insurmountable obstacle to the provision of a service by HOTEL Via Serdika SOFIA, to the satisfaction and execution of the submitted requests, applications, requests, signals, etc. sub., which releases HOTEL Via Serdika SOFIA from liability for non-performance.

(4) Refusal to provide data and documents or the provision of incorrect data may result in the inability to provide the relevant services or in the suspension of access to services provided by HOTEL Via Serdika SOFIA.

(5)  Data subjects should not provide HOTEL Via Serdika SOFIA with any special categories of data within the meaning of Art. 9 and Art. 10 of the Regulation (namely: personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data, data concerning health or data concerning the sex life or sexual orientation of a natural person; and personal data relating to convictions and offences).

OTHER SOURCES OF PERSONAL DATA

Art. 13. (1) In some cases, personal data processed by HOTEL Via Serdika SOFIA are not collected or received directly from the Data Subject to whom they relate, but from third parties such as:

1. Persons representing, working for or otherwise cooperating with the Data Subject;

2. Event organizers – regarding information about event participants;

3. Commercial partners (e.g. booking sites such as com; travel agents, other persons providing intermediary services in making reservations)and or when requesting other services and the like) of HOTEL Via Serdika SOFIA;

4. Competent state and judicial authorities.

(2) The persons under para. 1, items 1-3 undertake to inform the Data Subjects whose data they provide to and to guarantee that they provide the data on the basis of a valid legal basis.

PROCESSING OF INFORMATION BY THIRD PARTIES – PERSONAL DATA PROCESSORS

Art. 14. (1) For the purposes specified in this Policy, HOTEL Via Serdika SOFIA may delegate personal data processing activities to third parties - personal data processors, in accordance with and within the framework of the requirements of the Regulation and other applicable rules for the protection of personal data.

(2) When personal data are disclosed to and processed by personal data processors, this will only be done to the extent and in the volume necessary for the performance of the tasks assigned to them by HOTEL Via Serdika SOFIA.

(3) The personal data processors act on behalf of HOTEL Via Serdika SOFIA and are obliged to process personal data only and only in strict compliance with the instructions of HOTEL Via Serdika SOFIA, and will not have the right to use or process the information in any other way for purposes other than the purposes specified in this Policy.

CATEGORIES OF RECIPIENTS OF PERSONAL DATA

Art. 15. HOTEL Via Serdika SOFIA does not disclose personal data about the Data Subject to third parties, except in cases where:

1. this is necessary for the fulfillment of a legal obligation of HOTEL Via Serdika SOFIA:

(a) competent state, municipal or judicial authorities;

(b) auditors;

2. this is explicitly provided for in the Policy and/or in the general terms and conditions (contract) for the use of the relevant services that HOTEL Via Serdika SOFIA provides:

(a) processors of personal data on behalf of HOTEL Via Serdika SOFIA;

(b) debt collection companies.

3. this is necessary for the provision of the services of HOTEL Via Serdika SOFIA:

(a) banks and payment service providers;

(b) postal and courier service providers;

(c) commercial partners of HOTEL Via Serdika SOFIA such as: reservation sites; travel agencies and other providers of tourist or other auxiliary services such as rental cars, taxi and other transport services and the like

4. The data subject has given his/her explicit consent - the persons provided for in the relevant consent (e.g. related to HOTEL Via Serdika SOFIA, business partners of HOTEL Via Serdika SOFIA and the like);

5. this is necessary to protect the rights or legitimate interests of HOTEL Via Serdika SOFIA, third parties or the Data Subject:

(a) state, municipal and judicial authorities;

(b) private and state bailiffs;

(c) lawyers;

(d) notaries.

6. in other cases provided for by law.

Art. 16. (1) HOTEL Via Serdika SOFIA processes and stores information about the Data Subject until the relevant purposes for which it was collected and processed are achieved.

(2) HOTEL Via Serdika SOFIA, in accordance with its internal rules and procedures and the applicable legislation, processes and stores information about the Data Subject within the following periods:

Data types

Storage period

Data for the register of accommodated tourists within the meaning of Art. 116 of the Tourism Act, which include identification data of the accommodated persons and data related to hotel accommodation

 

Accordingly,ments in the Tourism Act and the by-laws, procedure and deadline

Information related to requested and used hotel accommodation, event and restaurant services, incl. for cancelled hotel accommodation reservations (insofar as they are related to refunds of prepaid amounts and/or withholding of amounts due)

From the date of the relevant reservation/request up to 5 /five/ years from the provision of the service/completion of the contract/cancellation of the reservation.

In cases where the services are requested and used on the basis of a contract with continuous performance, the period begins to run from the final performance and/or termination of the contract.

Financial and accounting documents; invoices; authorization forms; other information related to tax and social security control.

Up to 10 /ten/ years, starting from the beginning of the year following the one in which payment of the obligation for the relevant year is due.

Unstructured communication, correspondence, complaints, signals and

5 years

In cases where the correspondence concerns a contract with continuous execution, the period begins to run from the final execution and/or termination of the contract.

Data related to the registration of a profile in the Website's e-shop

For the entire period of registration and up to 5 years after its termination.

Data related to reservations for restaurant services made by phone

Up to 1 year

System logs. Logs related to security, technical support, etc. (may contain information such as: date and time, IP address, URL, browser version and device information)

1 year

Log of actions on requests for account registration or for purchasing goods with or without a registered account on the Website (information is stored such as: action/content of the request, date and time, IP address, etc.)

For the entire period of maintaining account registration on the Website and up to 5 /five/ years after its termination (if any)

Up to 5 /five/ years from the execution of the requested purchase (if made without a registered account).

Video data

2 months

Data contained in feedback cards

The information from the feedback cards is entered in an anonymized form (only the feedback; the received reviews and recommendations) without any information about the person who gave this feedback in the internal systems of HOTEL Via Serdika SOFIA, after which the cards are destroyed immediately.  

Up to 30 days from their completion.

Data processed based on the explicit consent of the Data Subject

From the moment of granting consent until its withdrawal by the Data Subject.

 

The personal data specified in this Policy may be processed for a longer period than those specified above, if this is necessary to achieve the goals set forth therein or to protect the rights and/or legitimate interests (including in court) of HOTEL Via Serdika SOFIA or if the current legislation provides for the processing of data for a longer period.

RIGHTS OF DATA SUBJECTS IN RELATION TO THEIR PERSONAL DATA

Art. 17. (1) In connection with the processing of personal data relating to him, each Data Subject has the following rights:

1. Right to information – to receive information regarding the processing of his personal data by HOTEL Via Serdika SOFIA;

2. Right to access:

(a) to receive confirmation whether personal data relating to him are being processed;

(b) to obtain access to the processed personal data and to detailed information regarding the processing and his rights.

3. Right to rectification – to request the correction or completion of his personal data if they are inaccurate or incomplete;

4. Right to erasure – to request the erasure of his personal data if there are grounds for doing so. that provided for in the Regulation;

5. Right to restriction of processing of personal data – to require HOTEL Via Serdika SOFIA to restrict the processing of his/her personal data within the framework of the Regulation, if the grounds for this are present, provided for therein;

6. Notification of third parties – right to require HOTEL Via Serdika SOFIA to notify third parties to whom his/her personal data have been disclosed of any correction, deletion or restriction of the processing of his/her personal data, unless this is impossible or requires disproportionate efforts from HOTEL Via Serdika SOFIA;

7. Right to data portability – to receive the personal data concerning him/her and which he/she has provided to HOTEL Via Serdika SOFIA, in a structured, widely used and suitable for machine-readable format, and to transfer these data to another controller without hindrance from HOTEL Via Serdika SOFIA.

The right to data portability applies when the following two conditions are met:

(a) the processing is based on consent or a contractual obligation; and

(b) the processing is carried out by automated means.

If technically feasible, the data subject shall have the right to obtain the direct transfer of personal data from HOTEL Via Serdika SOFIA to another controller. The right to data portability may be exercised in a manner that does not adversely affect the rights and freedoms of others.  

8. Rights in automated individual decision-making, including profiling – not to be subject to an automated decision based solely on automated processing (i.e. processing without human intervention), including profiling within the meaning of the Regulation, which produces legal effects concerning the Data Subject or similarly affects him/her insignificant extent, unless there are grounds for this provided for in the Regulation and suitable safeguards are provided for the protection of the rights and freedoms and legitimate interests of the Data Subject. Such safeguards are at least the right to human intervention by HOTEL Via Serdika SOFIA, the right of the Data Subject to express his point of view and contest the decision.

If such a decision, including profiling, is taken against the Data Subject, for each specific case the Data Subject has the right and will receive from HOTEL Via Serdika SOFIA separately significant information about the logic involved, the significance and the envisaged consequences of such processing for him, as well as about the manner of exercising the rights under this point.

9. Right to withdraw consent to processing – where the processing of personal data is based solely on the consent given by the Data Subject, the Data Subject may withdraw his consent at any time. Such withdrawal shall not affect the lawfulness of the processing based on the consent given up to the moment of its withdrawal;

RIGHT TO OBJECT

Art. 18. The data subject shall have the right to object, at any time and on grounds relating to his or her particular situation, to processing of personal data concerning him or her, including profiling within the meaning of the Regulation, which is based on public interest, exercise of official authority or the legitimate interests of HOTEL Via Serdika SOFIA or of a third party. In such cases, HOTEL Via Serdika SOFIA shall cease processing of the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.

Art. 19. (1) The data subject may exercise his/her rights related to the protection of personal data by personally submitting a relevant written request to HOTEL Via Serdika SOFIA - submitted personally by the Subject to the address specified in Art. 23 of this Policy or by means of a notarized request sent by mail.

(2) The request under Para. 1 may also be exercised electronically, and for this purpose the same must be signed by the Data Subject with a qualified electronic signature within the meaning of the Electronic Document and Electronic Certification Services Act and  Art. 3, item 12 of Regulation (EU) No. 910/2014 of the European Parliament and of the Council of 23 July 2014. on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC, and to be sent to GRAND HOTEL SOFIA at the e-mail address specified in Art. 23 of this Policy.

(3) The data subject may exercise the rights related to his personal data personally or through a person expressly authorized by him (with a notarized power of attorney).

(4) Some of the rights may also be exercised through the functionalities available on the Website.

RIGHT TO COMPLAINT TO A SUPERVISORY AUTHORITY

Art. 20. Each data subject has the right to lodge a complaint with a supervisory authority for personal data protection, in particular in the Member State (EU/EEA) of his/her habitual residence, place of work or place of the alleged infringement, if he/she considers that the processing of his/her personal data infringes the provisions of the Regulation or other applicable requirements for the protection of personal data.

SUPERVISORY AUTHORITY IN THE REPUBLIC OF BULGARIA

Art. 21. The supervisory authority in the Republic of Bulgaria is:

Personal Data Protection Commission
Address: Sofia 1592, bul. „Prof. Tsvetan Lazarov” № 2
Website: https://www.cpdp.bg/.

LIMITATIONS OF RIGHTS

Art. 22The scope of the rights of the Data Subjects and the obligations of HOTEL Via Serdika SOFIA in relation to these rights may be limited by a legislative measure of EU or Member State law, which applies to HOTEL Via Serdika SOFIA.

CLARIFICATIONS AND ADDITIONAL INFORMATION

Art. 23The data subject may receive explanations regarding the content and grounds for data processing, the manner of exercising the rights under this Policy, as well as any additional information regarding their rights in the processing of personal data by HOTEL Via Serdika SOFIA at:

Address: 53 Konstantin Stoilov St., 1202 Sofia, Bulgaria
Email address: [email protected]
Phone:+359 88 888 7775

This Personal Data Protection Policy has been drawn up by Via Serdika OOD in its capacity as a personal data administrator in order to fulfill its obligations to provide information to data subjects under Art. 13 and Art. 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

This Personal Data Protection Policy is in force from  31.01.2025.