PRIVACY AND PERSONAL DATA PROTECTION POLICY
This Privacy Policy governs the manner in which the companies operating under the Green Life Resorts trademark collect, process, store, and protect the personal data of visitors to the website www.greenliferesorts.bg and hotel guests.
Our activity fully complies with Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR), the Personal Data Protection Act (PDPA), the Tourism Act, and the Consumer Protection Act.
1. DATA ON PERSONAL DATA CONTROLLERS
The website www.greenliferesorts.bg provides information and booking capabilities for five hotel complexes. Depending on the hotel you choose, the controller of your personal data is the respective commercial company. The registered seat and management address are identical for all companies: 7A General Gurko Str., 4th floor, office 10-11, Burgas 8000.
The commercial companies have the following details:
"Sozopol Resorts" EOOD
Operates: Green Life Apartments Sozopol and Green Life Sozopol Antares
UIC: BG204894165
Email: sales.sozopol@greenliferesorts.bg | Phone: +359 878 484 404
"Pamporovo Resorts" EOOD
Operates: Green Life Family Apartments Pamporovo and Antares City Sozopol
UIC: BG204893800
Email: sales.pamporovo@greenliferesorts.bg | Phone: +359 879 893 303
antares@greenliferesorts.bg | Phone: +359 877 721 878
"Bansko Resorts" EOOD
Operates: Green Life Bansko
UIC: BG204893782
Email: sales.bansko@greenliferesorts.bg | Phone: +359 888 050 706
Joint Controllership: In cases of shared website usage, a centralized booking system, and joint marketing campaigns, the three specified companies act as joint controllers within the meaning of Art. 26 of the GDPR. Data subjects may exercise their rights with respect to each company through the common point of contact specified in Section 9.
2. CATEGORIES OF PERSONAL DATA WE PROCESS
Depending on how you interact with our website and hotels, we collect the following categories of data:
* Identification data: First name, middle name, last name, PIN (EGN) / PNF (LNCH) (for Bulgarian citizens) or date of birth (for foreign citizens), citizenship, identity document number and validity.
* Contact data: Phone number, email address, postal address.
* Booking and stay data: Arrival and departure dates, selected room category, special requirements/preferences, information about accompanying persons (incl. children).
* Financial and payment data: Credit/debit card details, bank account, payment history, billing details.
* Technical and analytical data: IP address, geographical location, browser type and operating system, website visit history, cookies.
* Marketing data: Preferences for receiving newsletters, promotional offers, and participation in satisfaction surveys.
* Video data: Closed-circuit television (CCTV) recordings in common areas of the hotel complexes (reception, lobby, restaurants, outdoor areas).
3. PURPOSES AND LEGAL BASES FOR PROCESSING
We process your personal data lawfully, subject to at least one of the legal bases provided in the GDPR, for the following specific purposes:
* Processing bookings and providing hotel services: Identification, contact, and stay data are processed to fulfill a booking made by you, register at reception, and provide requested tourist services. Legal basis: Performance of a contract or pre-contractual steps at your request (Art. 6, Para. 1, Item "b" of the GDPR).
* Guest registration pursuant to the Tourism Act: We are required by law to collect your identification data and identity document details upon check-in and submit them to the Unified Tourism Information System (ESTI). Legal basis: Compliance with a legal obligation applicable to the Controllers (Art. 6, Para. 1, Item "c" of the GDPR).
* Payment administration and accounting documentation: Financial data, payment card details, and billing data are processed for service payments, invoice issuance, and accounting maintenance. Legal basis: Compliance with a legal obligation under the Accountancy Act and the Tax and Insurance Procedure Code (Art. 6, Para. 1, Item "c" of the GDPR).
* Ensuring safety and security (Video Surveillance): To protect the life, health, and property of our guests, staff, and visitors, video surveillance is conducted in common areas of the hotels. Legal basis: Legitimate interest of the Controllers in ensuring physical security (Art. 6, Para. 1, Item "f" of the GDPR).
* Direct marketing and newsletter distribution: Sending promotional offers, special packages, and email newsletters is conducted based on your explicit consent (Art. 6, Para. 1, Item "a" of the GDPR). For existing clients, sending similar offers may also be based on our legitimate interest in developing our commercial activity (Art. 6, Para. 1, Item "f" of the GDPR), while always providing an easy option to opt out.
* Traffic analysis and website improvement: The use of cookies and the collection of technical data regarding your behavior on the site are carried out to improve the functionality and security of our platforms. Legal basis: Prior consent (Art. 6, Para. 1, Item "a" of the GDPR).
4. CATEGORIES OF EXTERNAL DATA RECIPIENTS
Your personal data is not sold to third parties. Data may be disclosed solely to:
* State and municipal authorities: Ministry of Interior, Ministry of Tourism (via the ESTI system), National Revenue Agency (NRA), Commission for Consumer Protection, and other supervisory bodies.
* Data Processors (Service Providers):
* IT companies maintaining the website and booking engine software.
* Hosting providers and email system providers.
* Banking institutions and licensed payment operators (for transaction processing).
* Licensed security companies (for video surveillance).
* Accounting and law firms.
All processors are bound by strict confidentiality and data protection agreements.
5. INTERNATIONAL DATA TRANSFERS
As a rule, your data is stored on servers located within the European Union (EU) and the European Economic Area (EEA).
If a transfer to third countries outside the EU becomes necessary (e.g., when using analytical services such as Google Analytics or email marketing platforms), the transfer takes place only if one of the following conditions is met:
* An adequacy decision by the European Commission;
* Standard Contractual Clauses (SCCs) approved by the EC;
* Your explicit consent.
6. DATA RETENTION PERIODS
We store your data only for as long as necessary to fulfill the purposes for which it was collected:
* Address cards and guest registers: 5 years (pursuant to the Tourism Act).
* Accounting documents and invoices: 10 years (pursuant to the Accountancy Act).
* Inquiries and unfulfilled bookings: Up to 12 months from processing the inquiry.
* Direct marketing data: Until withdrawal of consent or exercise of the right to object.
* CCTV footage: Up to 30 days from recording (except in cases of a detected offense, where it is retained until investigations conclude).
7. SECURITY MEASURES
To protect your personal data, we implement appropriate technical and organizational measures, including:
* Encryption of the connection to the website via SSL/TLS certificates.
* Restricted access to personal data, limited strictly to employees who require it to perform their official duties.
* Password security policies, firewalls, and antivirus systems.
* Physical security at locations where hard copy documents are stored.
8. YOUR RIGHTS AND SUPERVISORY AUTHORITIES
As a data subject, you have the following rights:
* Right of access: To request confirmation as to whether we process your data and a copy of it.
* Right to rectification: To request correction of inaccurate or completion of incomplete data.
* Right to erasure ("Right to be forgotten"): Where statutory grounds exist (e.g., purpose no longer applies, consent withdrawn).
* Right to restriction of processing: When contesting the accuracy of the data or the lawfulness of processing.
* Right to data portability: To receive your data in a structured, machine-readable format.
* Right to object: At any time against processing based on legitimate interest or for direct marketing purposes.
* Right to withdraw consent: At any time, without affecting the lawfulness of processing prior to withdrawal.
How to exercise your rights:
You may submit a written application or email to our general privacy contact point (see Section 9). The application should include your name, contact details, and a description of the request.
Right to lodge a complaint and competent supervisory authorities regarding personal data protection:
If you believe that the processing of your data violates personal data protection legislation, you have the right to lodge a complaint with:
Commission for Personal Data Protection (CPDP)
Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592
Phone: +359 2 915 35 18
Email: kzld@cpdp.bg | Website: www.cpdp.bg
9. PRIVACY CONTACTS
For questions related to this policy or to exercise your rights, you can contact us via the common contact point for the Green Life Resorts brand:
Correspondence address: 7A General Gurko Str., 4th floor, office 10-11, Burgas 8000
Data protection email: office@greenliferesorts.bg
10. CHANGES TO THE PRIVACY POLICY
We reserve the right to update this Policy periodically. All changes will be published on this page indicating the date of the last update.
Our activity fully complies with Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR), the Personal Data Protection Act (PDPA), the Tourism Act, and the Consumer Protection Act.
1. DATA ON PERSONAL DATA CONTROLLERS
The website www.greenliferesorts.bg provides information and booking capabilities for five hotel complexes. Depending on the hotel you choose, the controller of your personal data is the respective commercial company. The registered seat and management address are identical for all companies: 7A General Gurko Str., 4th floor, office 10-11, Burgas 8000.
The commercial companies have the following details:
"Sozopol Resorts" EOOD
Operates: Green Life Apartments Sozopol and Green Life Sozopol Antares
UIC: BG204894165
Email: sales.sozopol@greenliferesorts.bg | Phone: +359 878 484 404
"Pamporovo Resorts" EOOD
Operates: Green Life Family Apartments Pamporovo and Antares City Sozopol
UIC: BG204893800
Email: sales.pamporovo@greenliferesorts.bg | Phone: +359 879 893 303
antares@greenliferesorts.bg | Phone: +359 877 721 878
"Bansko Resorts" EOOD
Operates: Green Life Bansko
UIC: BG204893782
Email: sales.bansko@greenliferesorts.bg | Phone: +359 888 050 706
Joint Controllership: In cases of shared website usage, a centralized booking system, and joint marketing campaigns, the three specified companies act as joint controllers within the meaning of Art. 26 of the GDPR. Data subjects may exercise their rights with respect to each company through the common point of contact specified in Section 9.
2. CATEGORIES OF PERSONAL DATA WE PROCESS
Depending on how you interact with our website and hotels, we collect the following categories of data:
* Identification data: First name, middle name, last name, PIN (EGN) / PNF (LNCH) (for Bulgarian citizens) or date of birth (for foreign citizens), citizenship, identity document number and validity.
* Contact data: Phone number, email address, postal address.
* Booking and stay data: Arrival and departure dates, selected room category, special requirements/preferences, information about accompanying persons (incl. children).
* Financial and payment data: Credit/debit card details, bank account, payment history, billing details.
* Technical and analytical data: IP address, geographical location, browser type and operating system, website visit history, cookies.
* Marketing data: Preferences for receiving newsletters, promotional offers, and participation in satisfaction surveys.
* Video data: Closed-circuit television (CCTV) recordings in common areas of the hotel complexes (reception, lobby, restaurants, outdoor areas).
3. PURPOSES AND LEGAL BASES FOR PROCESSING
We process your personal data lawfully, subject to at least one of the legal bases provided in the GDPR, for the following specific purposes:
* Processing bookings and providing hotel services: Identification, contact, and stay data are processed to fulfill a booking made by you, register at reception, and provide requested tourist services. Legal basis: Performance of a contract or pre-contractual steps at your request (Art. 6, Para. 1, Item "b" of the GDPR).
* Guest registration pursuant to the Tourism Act: We are required by law to collect your identification data and identity document details upon check-in and submit them to the Unified Tourism Information System (ESTI). Legal basis: Compliance with a legal obligation applicable to the Controllers (Art. 6, Para. 1, Item "c" of the GDPR).
* Payment administration and accounting documentation: Financial data, payment card details, and billing data are processed for service payments, invoice issuance, and accounting maintenance. Legal basis: Compliance with a legal obligation under the Accountancy Act and the Tax and Insurance Procedure Code (Art. 6, Para. 1, Item "c" of the GDPR).
* Ensuring safety and security (Video Surveillance): To protect the life, health, and property of our guests, staff, and visitors, video surveillance is conducted in common areas of the hotels. Legal basis: Legitimate interest of the Controllers in ensuring physical security (Art. 6, Para. 1, Item "f" of the GDPR).
* Direct marketing and newsletter distribution: Sending promotional offers, special packages, and email newsletters is conducted based on your explicit consent (Art. 6, Para. 1, Item "a" of the GDPR). For existing clients, sending similar offers may also be based on our legitimate interest in developing our commercial activity (Art. 6, Para. 1, Item "f" of the GDPR), while always providing an easy option to opt out.
* Traffic analysis and website improvement: The use of cookies and the collection of technical data regarding your behavior on the site are carried out to improve the functionality and security of our platforms. Legal basis: Prior consent (Art. 6, Para. 1, Item "a" of the GDPR).
4. CATEGORIES OF EXTERNAL DATA RECIPIENTS
Your personal data is not sold to third parties. Data may be disclosed solely to:
* State and municipal authorities: Ministry of Interior, Ministry of Tourism (via the ESTI system), National Revenue Agency (NRA), Commission for Consumer Protection, and other supervisory bodies.
* Data Processors (Service Providers):
* IT companies maintaining the website and booking engine software.
* Hosting providers and email system providers.
* Banking institutions and licensed payment operators (for transaction processing).
* Licensed security companies (for video surveillance).
* Accounting and law firms.
All processors are bound by strict confidentiality and data protection agreements.
5. INTERNATIONAL DATA TRANSFERS
As a rule, your data is stored on servers located within the European Union (EU) and the European Economic Area (EEA).
If a transfer to third countries outside the EU becomes necessary (e.g., when using analytical services such as Google Analytics or email marketing platforms), the transfer takes place only if one of the following conditions is met:
* An adequacy decision by the European Commission;
* Standard Contractual Clauses (SCCs) approved by the EC;
* Your explicit consent.
6. DATA RETENTION PERIODS
We store your data only for as long as necessary to fulfill the purposes for which it was collected:
* Address cards and guest registers: 5 years (pursuant to the Tourism Act).
* Accounting documents and invoices: 10 years (pursuant to the Accountancy Act).
* Inquiries and unfulfilled bookings: Up to 12 months from processing the inquiry.
* Direct marketing data: Until withdrawal of consent or exercise of the right to object.
* CCTV footage: Up to 30 days from recording (except in cases of a detected offense, where it is retained until investigations conclude).
7. SECURITY MEASURES
To protect your personal data, we implement appropriate technical and organizational measures, including:
* Encryption of the connection to the website via SSL/TLS certificates.
* Restricted access to personal data, limited strictly to employees who require it to perform their official duties.
* Password security policies, firewalls, and antivirus systems.
* Physical security at locations where hard copy documents are stored.
8. YOUR RIGHTS AND SUPERVISORY AUTHORITIES
As a data subject, you have the following rights:
* Right of access: To request confirmation as to whether we process your data and a copy of it.
* Right to rectification: To request correction of inaccurate or completion of incomplete data.
* Right to erasure ("Right to be forgotten"): Where statutory grounds exist (e.g., purpose no longer applies, consent withdrawn).
* Right to restriction of processing: When contesting the accuracy of the data or the lawfulness of processing.
* Right to data portability: To receive your data in a structured, machine-readable format.
* Right to object: At any time against processing based on legitimate interest or for direct marketing purposes.
* Right to withdraw consent: At any time, without affecting the lawfulness of processing prior to withdrawal.
How to exercise your rights:
You may submit a written application or email to our general privacy contact point (see Section 9). The application should include your name, contact details, and a description of the request.
Right to lodge a complaint and competent supervisory authorities regarding personal data protection:
If you believe that the processing of your data violates personal data protection legislation, you have the right to lodge a complaint with:
Commission for Personal Data Protection (CPDP)
Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592
Phone: +359 2 915 35 18
Email: kzld@cpdp.bg | Website: www.cpdp.bg
9. PRIVACY CONTACTS
For questions related to this policy or to exercise your rights, you can contact us via the common contact point for the Green Life Resorts brand:
Correspondence address: 7A General Gurko Str., 4th floor, office 10-11, Burgas 8000
Data protection email: office@greenliferesorts.bg
10. CHANGES TO THE PRIVACY POLICY
We reserve the right to update this Policy periodically. All changes will be published on this page indicating the date of the last update.