PRIVACY POLICY
PRIVACY POLICY
“Stefan Kazakov-90 – Katya Kazakova “ET, UIC 160085981, with registered office and management address: 23, Vasil Aprilov Blvd.
hereinafter referred to as “Cityscape Studios”, is a personal data controller and processes the personal data provided in accordance with the Personal Data Protection Act and REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC GDPR, hereinafter referred to as “GDPR”.
We, as the Data Controller, respect the privacy of users. This security policy aims to inform you about the process of collection, processing, storage, use and redirection of personal data. We therefore ask you to familiarize yourself with its contents by reading it carefully. If you have any questions, you can ask them via the Contact Form on the website.
I. DEFINITIONS
For the purposes of this Policy and in accordance with the definitions given in Article 4 of the GDPR, the following terms shall have the following meanings:
- “Personal Data” means any information relating to an identified natural person or an identifiable natural person (“Data Subject”);
- “data subject” – means an identifiable natural person, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
- ‘Data controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its determination may be laid down in Union or Member State law;
- ‘Processing of personal data’ means any operation or set of operations which is performed upon personal data or a set of personal data by automatic or other means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
In order to secure and improve the services we provide and for the purposes of administering the resources to them, we store, use and process personal data as described in this Privacy Policy in compliance with applicable legal requirements.
II. TYPES OF PERSONAL DATA PROCESSED
The types of personal data that the Controller collects and processes vary according to the purposes for which they are collected and the grounds for their processing:
- The following types of data are collected and processed in order to make, request and confirm a reservation:
a/ When booking, via website:
- Name and surname of the contact person;
- e-mail address and telephone number of the contact person;
- bank card for the reservation guarantee;
b/ When booking by phone:
- contact telephone number and e-mail address for confirmation of reservation
- Name and surname of the contact person;
- For the purpose of accommodating guests in the Studios, the controller processes and stores the following data:
- UCN / PNF;
- Name of the person (for Bulgarian citizens – in Cyrillic, for foreigners – in Latin, in accordance with the national document);
- Date of birth;
- Gender;
- Nationality;
- Identity card number/valid national identity document/;
- Country issuing the national document.
The data collected for the purpose of registration at the hotel are collected on the basis of Art. 116, para. 2 of the Tourism Act and are necessary for keeping a register of the tourists accommodated. The data shall be stored for a period of 5 /five/ calendar years.
- To ensure safety in the premises of the BUILDING and for the prevention of unlawful acts in the BUILDING, the following data is processed and stored – video images of individuals visiting the “Cityscape” Studio”. Video surveillance is only carried out in the common areas of the building. The video surveillance data helps to investigate illegal acts and acts against public order. This data is stored on DVR or NVR devices with data access restricted to persons only authorized to access and process personal data. Video images of individuals are stored for a period of up to one month from the date of capture, after which they are automatically destroyed, unless storage for a longer period is necessary to fulfil a legal obligation of Cityscape Studios.
III. GROUNDS FOR PROCESSING
Cityscape Studios processes your personal data on the basis of Article 6(1) and (b). “a” b. “b” b. “c” and b “f” of the GDPR, namely:
Article 6(1)(b). “a” of the GDPR – the data subject has consented to the processing of his/her personal data to receive commercial communications for marketing purposes.
Article 6(1)(b). “a” of the GDPR – the processing is necessary for compliance with a legal obligation to which the Controller is subject;
Article 6, paragraph 1, b. “b” of the GDPR – the processing is necessary for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject before entering a contract;
Article 6(1)(b). “f” of the GDPR – the processing is necessary for the purposes of the legitimate interests of the HOTEL, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data especially where the data subject is a child.
IV. PROCESSING PRINCIPLES
When processing personal data, we comply with the following principles:
- lawfulness in the collection, processing and storage of your data – we comply with the provisions of the applicable Bulgarian and European legislation;
- fairness and transparency – the data we collect, process and comply with this Privacy Policy, which is available to every user;
- relevance of processing to the purposes and minimization of data – the types of data we collect are minimized according to the purposes for which they are processed. The purposes for which your data is processed are those for which we are legally obliged, have a contractual relationship or have obtained your consent to collect it;
- storage limitation – we process and store the received data for a period in accordance with the purposes for which it is needed and in accordance with your consent.
- user consent for data processing – in order to use your data for marketing purposes to improve the services we provide to you, we must obtain your explicit consent to do so.
Please note that when you send a request for pricing conditions, for a reservation, for clarification on an already made reservation, you give your consent to Cityscape Studios to store and process the personal data provided by you for the purpose of the request.
In this case, your data will be deleted in accordance with current regulations and this privacy policy.
Personal data received in connection with an enquiry shall be processed and stored for a period of up to 6 /six/ months from the processing of the enquiry, after which it shall be destroyed, except in cases where the Controller has the right to store the data on a legal or contractual basis for a longer period.
V. DATA PROTECTION MEASURES
We use electronic methods to process personal data to ensure accurate and prompt service delivery and to assist users.
Your personal data is processed in compliance with applicable data protection regulations, and Cityscape Studios respects your privacy.
The data that is collected for the purpose of accommodation in “Cityscape Studio” is accessible to the third parties defined in the Tourism Act – Ministry of Tourism, Municipalities, Ministry of Interior, National Revenue Agency and National Statistical Institute.
VI. STORAGE OF PERSONAL DATA
The data we collect from you is stored within the European Economic Area (“EEA”) in compliance with national and European law, in particular the GDPR.
VII. RIGHTS OF DATA SUBJECTS
Users of services provided by Cityscape Studio have the following rights as personal data subjects:
- Right of access and right to rectification: in accordance with current legislation, you have the right and access to the data you have provided for processing. With a written request via the Contact Form on the website, you can obtain information about the type of personal data you have provided and the purpose of its processing. By gaining access to your data, you can request that it be corrected in the event that you find errors or inconsistencies.
- Right to object to processing based on legitimate interest: Users have the right to object to the processing of their data.
- Consumers have the right to complain to the competent supervisory authority. Under the current legislation, the competent supervisory authority in the Republic of Bulgaria is the Commission for Personal Data Protection.
- Right to data portability: Where your personal data is processed in an automated manner on the basis of your consent or on the basis of a contract, you have the right to receive your data in a structured, commonly used and machine-readable format.
- Right to erasure/right to be forgotten: You have the right to erasure of all personal data processed by Cityscape Studios and its processors at any time, except where the processing is necessary for at least one of the following purposes, namely:
- (a) to exercise the right to freedom of expression and the right to information;
- (b) for compliance with a legal obligation requiring processing provided for in Union law or the law of the Member State to which it applies;
- (c) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes pursuant to Article 89(1) of the GDPR, in so far as the right to erasure is likely to render impossible or seriously impede the achievement of the purposes of that processing; or
- (d) the establishment, exercise or defense of legal claims.
- Right to restriction: you have the right to ask Cityscape Studios to restrict the processing of your personal data in the following circumstances:
- (a) the accuracy of the personal data is contested by the data subject, for a period that allows the Controller to verify the accuracy of the personal data;
- (b) the processing is unlawful but the data subject does not wish the personal data to be erased but requests instead that its use be restricted;
- c) the Controller no longer needs the personal data for the purposes of the processing, but the data subject requires them for the establishment, exercise or defense of legal claims;
- (d) the data subject has objected to processing pursuant to Article 21(1) of the GDPR and is awaiting verification whether the legitimate grounds of the controller override the interests of the data subject.
- The right to be informed of an infringement under Article 34 of the GDPR:
Where a personal data breach is likely to pose a high risk to your rights and freedoms, Cityscape Studios will, without undue delay, inform you of the personal data breach with a notice describing the nature of the personal data breach and specifying at least:
- the name and contact details of a person in the Cityscape Studios team from whom more information can be obtained;
- the possible consequences of the personal data breach;
- a description of the measures taken or proposed by the controller to address the personal data breach, including, where appropriate, measures to mitigate any adverse effects.
The above information will not be sent personally to any user in the event of a security breach.
VIII. CHANGES TO THE PRIVACY POLICY
Cityscape Studios’ privacy policy may be updated unilaterally to enhance, offer new services, modify the way we serve and communicate with our customers, or in response to regulatory changes.
When we make changes to this Privacy Policy, we will bring the changes to your attention by posting them on our website, giving you a reasonable period of time to familiarize yourself with them, after which they will apply to the processing of your personal data without further notice.
If you declare within this period that you reject the changes, you will be deemed to have withdrawn your consent to the processing of your personal data and the processing of your personal data will be discontinued in the future, where the basis for the collection and processing of your personal data is your consent. This may also involve terminating your registrations for our games, services, e-newsletters, etc. for the purposes of which you originally provided us with your personal data.
IX. Contact with the team
If you have any questions regarding our privacy measures and policies, please send a message via the Contact Form on the website.
The exercise of the above rights does not deprive you of the right to complain. You may submit a complaint to the supervisory authority in Bulgaria, the Personal Data Protection Commission. More information can be found at: www.cpdp.bg