Privacy Policy

PERSONAL DATA PROTECTION AND CONFIDENTIALITY POLICY

The policy reflects the requirements of Regulation 2016/679, the Personal Data Protection Act and the subordinate legislation implementing it in relation to the receipt, processing, storage and destruction of personal data of natural persons.

Information about us

Oasis Tour AD (Oasis Tour and/or the Administrator) is a company registered in the Commercial Register of the Registry Agency with UIC 102729737, with registered office and address of management: Burgas, ul. Yanko Komitov No. 16a, Tel: 0899001100; e-mail: office@oasis-delsol.com

Contact information at Oasis Tour AD regarding the protection of our customers’ personal data

Oasis Tour AD

Burgas, ul. Yanko Komitov No. 16a

office@oasis-delsol.com

Data Protection Officer: Veselin Chavdarov – Hotel Manager

Oasis Tour AD processes your personal data in order to provide you with better, higher quality and more diverse hotel services. We protect your data by applying all appropriate technical and organizational measures at our disposal to prevent unauthorized access, unauthorized or malicious use, loss, or premature deletion of information.

We collect and process personal data only in compliance with local and European legislation. We are aware that the processing of your data is related to a specific purpose and cannot be carried out without restriction.

This “Privacy and Data Protection Policy” is intended to explain how and why we process your personal data.

How and why we use your personal data

Your personal data is processed for the following purposes:

  • to establish the identity of the customer upon request, preliminary reservation, and/or accommodation at Oasis del Sol, Lozenech.
  • preparing and sending a bill/invoice for the hotel services provided
  • collecting the amounts due for the services you have used;

We process your identification data and other personal data in order to comply with obligations laid down in a legislative act, such as:

  • providing information to the Personal Data Protection Commission in connection with obligations under the personal data protection legislation – the Personal Data Protection Act, Regulation (EU) 2016/679 of April 27, 2016, etc.;
  • obligations provided for in the Accounting Act and the Tax and Social Security Procedure Code and other related regulations in connection with the keeping of accurate and lawful accounting records;
  • provision of information to the court and third parties in the course of court proceedings, in accordance with the requirements of the procedural and substantive legal acts applicable to the proceedings;

Categories of personal data we process:

identification data:

  • full name, personal identification number or foreigner’s personal identification number, permanent address; passport details

other data:

o personal contact details – contact address, telephone number and contact information (email, telephone number), age group; nationality

o credit or debit card information, bank account number or other bank and payment information in connection with payments made to Oasis Tour AD and by Oasis Tour AD in case of cancellation of a reservation;

  • For children under the age of 16, the processing of personal data is lawful to the extent that consent has been given by the parent or guardian responsible for the child.

When we process your basic personal data and other data described for the purposes of providing hotel services and their payment, responding to your requests for services, and fulfilling our regulatory obligations, this processing is mandatory. If you do not provide us with identification data, we will not be able to provide you with our hotel services.

How we protect your personal data

To ensure adequate protection of the data of Oasis Tour AD and its guests, we implement all necessary measures provided for in Regulation (EU) 2016/679 of April 27, 2016, and Bulgarian legislation.

We make every effort to ensure that the personal data collected from you is protected against loss and/or unauthorized access. This protection applies to information stored on electronic and paper media. Access to your personal information is restricted to selected employees or representatives. In addition, we use generally accepted information security techniques, such as firewalls, access control procedures, etc., to protect personal information against loss and/or unauthorized access.

Storage and protection of personal information:

We store the personal information provided to us for as long as necessary to fulfill the purpose for which the personal data was collected and processed, in accordance with Regulation (EU) 2016/679 of April 27, 2016, and Bulgarian legislation. Once the purpose for which the personal data was collected has been achieved, it will be destroyed.

Cookie Policy

Use of cookies

Cookies are small text files created by the websites you visit. A cookie will help the website recognize your device the next time you visit it and thus save your preferences and actions for a certain period of time. The use of so-called “cookies” serves solely for the convenience and ease of users when working online. Cookies do not contain information that can identify a person (such as name, surname, email address, telephone number), but a combination of a computer and a website. Cookies do not contain information that can identify a person (such as name, surname, email address, telephone number), but rather a combination of computer and web browser. The best example of information stored in a cookie is whether you have clicked “OK” on this website’s cookie policy so that you are not asked again.

How are cookies used?

We use cookies primarily to facilitate the usability of the website, improve its performance, and store information about user behavior. No personal data is stored during this process, i.e., Oasis Tour AD cannot identify you as an individual through the cookies on its website, which is why the Personal Data Protection Act does not apply to the collection of this information. The information collected from cookies is usually used in aggregate form to analyze user behavior on the Website, which allows us to improve the functionality of the site, user paths, and the content used.

How can I manage the use of cookies?

Depending on the browser you are using, you have the option to allow or refuse the storage of cookies from all sources or to set a notification that will ask for your permission to accept or refuse each new cookie.
Most browsers are set to accept cookies by default. Cookies can be deleted by the user at any time. Accepting or rejecting these cookies can be activated or deactivated by you via your browser settings. You can find the necessary settings in the relevant section of your Internet browser menu. Details can be found in the “Help” menu of your Internet browser. You can control

and/or delete cookies whenever you wish – for more information, see aboutcookies.org.

All cookies used on our website are automatically deleted/erased after a certain period of time. This period varies up to 365 days depending on the purpose of the specific cookie.

Categories of recipients to whom personal data may be disclosed:

– to individuals to whom the data relates;

– to persons for the protection of the life and health of the individual to whom the data relates;

– to persons if provided for in a normative act

-persons performing a task in the public interest;

-persons under contract;

-persons processing personal data

We do not disclose your personal data to third parties, foreign countries, or international organizations.

You have the following rights when it comes to your personal data being processed:

Right to information:

You have the right to ask for:

  • info on whether data about you is being processed, info on why it’s being processed, what types of data are being processed, and who the data is being shared with;
  • a communication in an intelligible form containing your personal data that is being processed, as well as any available information about its source;

Right to rectification:

If we process incomplete or incorrect data, you have the right, at any time, to request that we:

  • delete, rectify, or block your personal data whose processing does not comply with the requirements of the law;

Right to object:

You have the right at any time to:

  • object to the processing of your personal data if there is a legal basis for doing so; where the objection is justified, the personal data of the individual concerned may no longer be processed;

Right to restriction of processing:

You may request restriction of the processing of personal data if:

  • you dispute the accuracy of the data for the period in which we need to verify its accuracy; or
  • the processing of the data is without legal basis, but instead of deleting it, you request its restricted processing; or
  • we no longer need this data (for the specified purpose), but you need it for the establishment, exercise, or defense of legal claims; or
  • you have objected to the processing of the data, pending verification of whether the controller’s grounds are legitimate.

Right to data portability:

You may request that we provide the personal data you have entrusted to our care in an organized, structured, commonly used electronic format.

Right to complain:

If you believe that we are violating applicable regulations, please contact us to clarify the issue. You can protect your rights by filing a complaint with the CPDP www.cpdp.bg Sofia, Prof. Tsvetan Lazarov Blvd. 2, email kzld@cpdp.bg or with the court.

Withdrawal of consent:

You have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Policy updates and changes

In order to implement the most up-to-date security measures and to comply with applicable law, we will regularly update this Privacy Policy. We encourage you to regularly review the current version of this Privacy Policy and Privacy Statement to stay informed about how we protect the personal data we collect.