Privacy policy
This Privacy policy explains how Еurobau estate Ltd whose principal place of business is St.George Hotel, 64 Kniaz Boris I str., Sofia , collects, handles, stores and processes personal data.
TABLE OF CONTENTS
- What information about you do we collect and why?
- What do we do with your information?
- Lawful grounds for processing personal information
- Who might we share your information with?
- How secure is your information?
- How long do we keep hold of your information?
- How can I access, verify or change the information you hold about me?
WHAT INFORMATION ABOUT YOU DO WE COLLECT AND WHY?
We may collect and process personal data relating to you, your friends and family members or any other individual where you have provided their information to us. Before providing us with any information you are responsible for ensuring that such individuals are aware of this policy and the provisions of this are clearly communicated to them:
- Contact information (such as name, email address, mailing address, and phone number);
- Payment information (including payment card numbers, billing address, and bank account information);
- Passport information;
- Travel itinerary;
- Details about birthdays, special events and friends and family where we are hosting an event for you;
- Demographic data (such as age, gender, country, and preferred language);
- Special categories of data (such as food allergies, health information we collect from your use of the Spa or if you have any health conditions);
- Information related to your reservation, stay, or visit to our property (including the date of arrival and departure, and goods and services purchased);
- Information necessary to fulfil your special requests and/or specific accommodations;
- Loyalty program member information, online account details, profile or password details;
- Copies of your correspondence if you contact us;
- Your interests and preferences;
- Information collected through the use of closed circuit television systems, card key and other security systems; and
- Information related to your use and interaction with our website (see section Cookies and online tracking below).
WHAT DO WE DO WITH YOUR INFORMATION?
Еurobau estate Ltd collects your information to operate effectively and provide you with the best experiences with our services. Еurobau estate Ltd may collect, use, and disclose the information it collects for a variety of reasons, including for the following purposes:
- Fulfilment of reservation and other purchases: we may process information relating to transactions that you enter into with us and/or through our website (“transaction data”). The transaction data may be processed for the purpose of completing your room reservation, supplying the purchased goods and services, customizing our services to your preferences, seeking your feedback on your stay at our properties, and keeping proper records of those transactions.
- Membership Programs: to administer and operate membership programs, including the Friends of St.George Hotel program. The data may be processed for the purposes of recording stay and transactional data, earning and redeeming rewards, points, or credits in connection with the programs.
- Response to inquiries: we may process information contained in or relating to any communication that you send to us (“correspondence data”). The correspondence data may include the communication content and metadata associated with the communication. The correspondence data may be processed for the purposes of communicating with you and record-keeping.
- Internal business purposes: for our internal business purposes, such as data analysis, audits, developing new products, enhancing the website, improving our services, identifying usage trends and visiting patterns, determining the effectiveness of our promotions, and meeting contractual obligations.
- Administrative and other communications: to send you important information regarding our website, changes to our terms, conditions, and policies, or other administrative information (e.g., information about your travel reservations, such as reservation confirmations).
- Marketing and promotions: to communicate news and promotions relating to Еurobau estate Ltd products and services and other products and services we think may be of interest to you, and to operate sweepstakes, contests, or other marketing or promotional activities.
- Safety and security: to maintain your safety and security as well as that of other guests and personnel, while you visit our managed hotels and residences.
- Our legal duties: to comply with legal and regulatory requirements or demands in accordance with applicable law, a court order, subpoena, or other legal process.
- Additional uses: We may also use your data in other ways as described to you when you provide such information to us.
LAWFUL GROUNDS FOR PROCESSING PERSONAL INFORMATION
The legal basis for processing your personal information is made up of one or more of the following reasons:
- Consent to the processing of such information for a specific reason;
- The processing is necessary to perform the agreement or to take steps to enter into an agreement;
- The processing is necessary for compliance with a legal obligation we have; or
- The processing is necessary for the purposes of a legitimate interest pursued by us, which might be:
- to provide our services;
- to improve our website;
- to keep our website safe and secure;
- to prevent fraud;
- to protect our business interests;
- to ensure that complaints are investigated;
- to evaluate, develop or improve our services; or
- to keep you informed about relevant services.
In relation to any processing of special categories of personal data, we will generally rely on obtaining specific consent from you at the time unless there is otherwise a legal requirement for us to process such information. Where you have consented to our processing of such special categories of personal data you may withdraw such consent at any time, by contacting us at office@stgeorge-bg.com , however please be aware if you withdraw such consent we may be unable to provide you with our services.
HOW SECURE IS YOUR INFORMATION?
We implement appropriate administrative, organisational and technical safeguards and security measures to protect personal information within our control from unauthorized access, acquisition, disclosure, destruction or alteration, accidental loss, misuse or damage. We regularly review and monitor such safeguards and security measures.
HOW LONG DO WE KEEP HOLD OF YOUR INFORMATION?
To the extent permissible by applicable law, we will retain your personal information for such period as necessary to satisfy or to fulfil the following:
- The purposes for which that personal information was provided;
- An identifiable and ongoing business need, including record keeping;
- A specific legal or regulatory requirement; and/or
- A requirement to retain records that may be relevant to any notified regulatory investigations or active legal proceedings.
Where there is no sufficient justification to retain such personal information, such personal information will be safely and securely deleted, disposed of, anonymised and/or blocked.
WHAT ARE MY RIGHTS IN RELATION TO PERSONAL INFORMATION?
At any time, you have the right:
- To request access to or a copy of any personal data which we hold about you;
- To rectification of your personal data, if you consider that it is inaccurate;
- To ask us to delete your personal data, if you consider that we do not have the right to hold it;
- To withdraw consent to our processing of your personal data (to the extent such processing is based on previously obtained consent);
- To ask us to stop or start sending you marketing messages as described below in the marketing section;
- To restrict processing of your personal data;
- To data portability (moving some of your personal data elsewhere) in certain circumstances;
- To object to your personal data being processed in certain circumstances; and
Any request for access to or a copy of your personal data must be in writing and we will endeavour to respond within a reasonable period and in any event within one month in compliance with data protection legislation. We will comply with our legal obligations as regards your rights as a data subject.
We aim to ensure that the information we hold about you is accurate at all times. To assist us in ensuring that your information is up to date, do let us know if any of your personal details change.