Политика за защита на личните данни

"TWO SISTERS" Ltd, IDN 200836079, with registered office and address of management: Sofia, 19-21 "Dimitar Manov" street /hereinafter referred to as the "Company"/ is the administrator of personal data within the meaning of the Law on Protection of personal data and processes the same in accordance with this law and REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016 (General Data Protection Regulation), briefly referred to as the "Regulation". This Privacy Policy aims to inform you what personal data the company collects, how and for what purpose it is used, the conditions under which it is provided to third parties and for what purpose. The personal data protection policy can be changed and updated in order to bring it into line with possible changes in Bulgarian and applicable European legislation, as well as with possible changes in the company's activities. The main activity of the company is related to providing accommodation in the "The Red Doors House" guest house.

Personal data that the Company collects: 
The Company collects personal data that is necessary for the performance of its activities. Personal data is collected personally from the data subjects (employees, clients - natural persons and representative of a legal entity - client). The Company does not collect special categories of personal data ("sensitive data"). 
I. Personal data we collect from employees are: Ordinary personal data: three names, social security number, number and date of issue of an identity card, address, telephone number and data from a diploma of completed education;
The customer data that is collected is: 
  1. Ordinary personal data: three names, social security number and address, and for foreigners - personal number and address; phone number and e-mail - if the customer has provided one. 
  2. Data collected when payment is made to "TWO SISTERS" Ltd in the manner indicated in the general terms and conditions of the website;
Purpose of personal data processing 
Personal data is processed for the following purposes: 
  1. To identify a customer for: electronic contact form and phone call; 
  2. For reservations; 
  3. To provide accommodation for tourists, including for the needs of communication with customers, to ensure the fulfillment of contracts; 
  4. To carry out communication with representatives of counterparties of the Company-legal entities; 
  5. For concluding labor and civil contracts and complying with the requirements of labor legislation; 
  6. For accounting needs, including for the needs of payment of remuneration; 
  7. For statistical purposes; 
  8. To issue invoices; 
  9. To carry out tax-insurance control by the relevant competent authorities; 
  10. For guest reviews;
Data storage: 
The data is stored for a different period of time depending on the requirements of the current legislation: 
  1. Employee data is stored for the terms according to labor legislation: 50 years + 1 year from the date of conclusion of the contract; 
  2. Other accounting documentation containing personal data: 10 years +1. years from the date of drawing up the document; 
  3. Tourist customer data, other than the previous data: 5 years from the date of the last accommodation, unless the data subject requests "to be forgotten" before the expiration of this period; 
  4. Data of representatives of counterparties of the Company-legal entities: until the expiry of the term of the relevant contract and fulfillment of the obligations under it, unless the data subject requests "to be forgotten" before the expiry of this term.
Provision of personal data to third parties: 
  1. Personal data are provided to the NRA and others. legally established recipients when the legislation requires it and in compliance with the legal requirements; 
  2. In case of non-fulfillment of obligations, personal data are provided to a lawyer or law firm; 
  3. On Booking.com, with address Herengracht 597, 1017 CE Amsterdam, The Netherlands (www.booking.com) (hereinafter referred to as Booking.com), for online bookings.
The company provides personal data in the presence of a legal basis for providing the data or in the presence of express consent from the data subject to: 
  1. Personal data processors who, based on a contract with "Two Sisters" Ltd. - process your personal data or have direct/indirect access to your personal data 
  2. Company providing accounting services; 
  3. Competent authorities, which by virtue of a normative act have the authority to demand from "Two Sisters" Ltd. the provision of information, including personal data, such as - a Bulgarian court or a court of another country, various supervisory/regulatory bodies - Commission for the Protection of users, the Commission for the Regulation of Communications, bodies with powers to protect national security and public order (the bodies of the Ministry of Internal Affairs - in the event of non-fulfillment of established obligations by tourists or in other legally defined cases); 
  4. Third parties - service providers, subcontractors and other related organizations solely for the purpose of performing tasks and providing services to you on our behalf.
The Company in any case takes such technical and organizational security measures against unauthorized and illegal processing, accidental loss, destruction or damage of personal data as may be required, taking into account the state of technical development, common practice and legal requirements.
Rights of the subjects of personal data: 
  1. You have the right to find out what the Company's personal data protection policy is through this document. 
  2. You have the right to receive confirmation as to whether and what your personal data is being processed, you have the right to access this personal data, as well as to receive a copy of the information on paper or electronic media (depending on technical capabilities). 
  3. You have the right to request that the Company correct your inaccurate personal data without undue delay, and to request that your personal data be updated in the event of a change. Considering the purposes of the processing, you have the right to have your incomplete personal data completed, including by adding a declaration. 
  4. You have the right to request the deletion of personal data if the legal basis for their processing has ceased or the data is not necessary for the Company to establish, exercise or defend against legal and other claims. 
  5. When there is no legal basis for the processing of personal data, you have the right to request the restriction of the processing of your personal data, as well as the right to object to the processing. You can withdraw your consent to the processing of traffic data for market research purposes at any time. 
  6. You have the right to request the transfer of your personal data to another Administrator.
Use of cookies 
Like many other websites, ours uses cookies. "Cookies" are small individual packets of information sent by an organization to your computer to recognize you when you visit. They collect statistics about your browsing activities. This allows us to track user traffic patterns as well as develop statistical analyzes of service usage, such as time spent on the website and pages most frequently visited. Cookies do not identify you as an individual, and aggregate statistics do not include personal information. Cookies help us improve the website and provide a better personalized service. By agreeing to use this site and its services, you consent to the use of cookies, including Google Analytics cookies. If you would prefer not to receive cookies while browsing the Website or via HTML formatted emails, you may decline them. For this purpose, you can set your internet browser to warn you before accepting a cookie or to refuse cookies when it alerts you to their presence. You can usually find these settings in your browser's 'Options' or 'Preferences' menu. To be aware of these settings, as well as for more detailed information, you can use the 'Help' button from the menus of your browser.

Links to Other Sites: Our website may contain links to other websites operated by other organizations. This privacy policy applies only to our site, so we encourage you to read the privacy statements of other websites you visit. We are not responsible for the security policy of other websites, even if you use links from our site to reach them. In addition, if you have reached our website through a third-party site, we cannot be responsible for the privacy policy and practices of the owners and administrators of that third-party site, and we recommend that you check its Privacy Policy.

You can exercise the rights specified in this policy by sending your request (as well as the reason for it) to e-mail: info@thereddoorshouse.com, and the Company will ensure the exercise of your rights related to the protection of personal data, within the terms and according to the terms of the Personal Data Protection Act and in accordance with the Regulation. Any person whose personal data is processed according to this policy has the right to appeal to a supervisory authority /CLP or the competent Court/ in connection with the processing of his personal data. The Personal Data Protection Commission exercises legal control over the processing of personal data and we provide full access to the personal data registers we keep under the legal conditions for this. If you wish to make any complaint about the way your data is processed, you can contact us at e-mail: info@thereddoorshouse.com. If you are not satisfied with our answer or do not think that we are processing your data in a lawful manner, you can contact the competent body for the protection of personal data - Commission for the Protection of Personal Data, as follows: Address: Sofia 1592, bul. "Prof. Tsvetan Lazarov" No. 2, phone: 02/915 35 18, 02/915 35 15, 02/915 35 19, fax: 02/915 35 25, E-mail: kzld@cpdp.bg, Web site: www.cpdp.bg This Privacy Policy was adopted in May 2018. and is updated and/or supplemented periodically when changes occur in the legislation of the Republic of Bulgaria or the EU.