Principles We Follow When Processing Your Personal Data Bellow please read the general principles that guide us when we process your personal data:
Transparency: When Vaya Beach Resort collects and processes your personal data, we provide you with all information about how and from what sources we collect your data, for what purpose we collect it, for how long we store it, to whom we would potentially transfer it, who are the potential recipients of your data, what are your rights as a data subject
Proportionality: We collect only the minimum necessary personal data, just as we need to operate effectively.
Accuracy and timeliness: We process only up-to-date data that is true. We take all measures to ensure that the personal data we store is accurate and up-to-date with reference to the services we are providing.
Time Limitation: We store your personal data only for the period necessary for the effective conduct of our obligation to you and in accordance with the provisions of the law.
Observance of the rights of data subjects : We guarantee the observance of your access, rights, correction, deletion of your personal data that we process.
Confidentiality and Security: We have provided all necessary administrative, technical and organizational measures to protect your personal data against unwanted, accidental or illegal loss or unauthorized use, disclosure or access.
When and what kind of data is stored and processed for what reason?
Use of the Website Whenever you navigate our Website, data about you is collected and processed. We collect the following data
Information related to the browser or device you use to access our website
Country you are browsing from
Browsing habits, including sites visited
Marital status, and
Other demographics and statistical information
The data is collected through the session cookies (with regard to cookies see also below) we use on our Website. It is anonymised before we use it to build anonymous utilisation profiles, for marketing purposes and to optimise our Website and the services we provide. This data shall not be used in order to identify the visitor of this Website personally.
Interacting with us Every time you interact with us (e.g. booking a villa through our Website, by phone or through a third party provider, posting a comment on our blog, signing up for our newsletter) we may collect and process the Personal Data you provide to us.
a. Booking a villa When you book a villa, we collect Personal Data, which might include all or a combination of:
Your selected dates
Number of villas in the reservation
Number of people in the reservation (adults and children)
Age of children
The rate/special offer selected
Any add-on packages selected
Your full name
Your address, including city and country
Your e-mail address, and
Your credit card details
Villa, Bed type and/or other preferences
We use this Personal Data to handle your reservation in the most professional way and to establish and fulfil our contractual obligation with you. This includes verifying your identity, taking guarantee and/or payment information, and sending stay-related and/or marketing communication. We take the protection of your Personal Data very seriously and therefore have kept the mandatory required fields to a minimum.
b. Newsletter and special offers If you personally agree to provide your contact information to us (e.g. when booking a service with us or when signing up for our newsletter via our Website), we may use this Personal Data to send you our newsletters and details of other special offers which may be of interest to you, based on previous interactions with us (e.g. bookings).
If you sign up for our newsletter via our Website, you are required to provide your email address only and your interest in staying in touch. Any additional information is voluntary and will be used solely for a personalisation of the newsletter. You can revoke your consent and sign out of receiving the newsletter at any time by clicking on the unsubscribe link included in every newsletter. For any further objections, kindly address the contact stated at the end of this policy.
We also might include web beacons in HTML-formatted e-mail newsletters in order to count how many newsletters (or particular articles, links, etc.) are being accessed, and on our website to count users who have visited these pages.
c. “Contact Us” functionality You can get in contact with us via our Website by using the “Contact Us” functionality, or by telephone. To contact us you are required to provide the following information:
Your full name
Your zip code
Your telephone number and your e-mail address,
Your enquiry, and
Recaptcha, to confirm you are an actual person, and not a robot
Villa, Bed type and/or other preferences
Any additional information (e.g. home address) is provided voluntarily. We will use your information to reply to your enquiry.
d. Marketing Data Data related to our customer surveys in order to improve the quality of services provided. Participation in our surveys is always voluntary. We may invite you to participate in our competitions, raffles, events, information about which you can share with your contacts on social networks for evaluation by voting, shared offers or other promotions.
e. Video information For your security, we use a surveillance system - video cameras located at different points in the building of the resort.
Transfer of Personal Data to a third party Our partners could belong to on of the following groups:
payment service providers - Your personal data will be provided to the payment service provider you have chosen to make payment to us.
the accounting service providers that process our accounting operations
state bodies and local self-government bodies
In order to fulfill the requirements of the Civil Registration Act Art. 99, Vaya Beach Resort provides your identification data, as well as the data for your stay to the local self-government bodies, and upon request to the Ministry of Interior.
To meet the requirements of the national legislation , Vaya Beach Resort provides information to the National Revenue Agency.
Social Media On our Website we use the following social media plug-ins: Facebook, LinkedIn, Instagram.
The plug-ins can be identified by the social media buttons marked with the logo of the provider of the respective social media networks. We have implemented these plug-ins using the so-called 2-click solution. This means that when you navigate on our Website, Personal Data will initially not be collected by the providers of these social media plug-ins. Only if you click on one of the plug-ins will your Personal Data be transmitted: By activating the plug-in, data is automatically transmitted to the respective plug-in provider and stored by them (in the case of US providers your Personal Data will be stored in the USA). We neither have influence on the collected data and data processing operations conducted by the providers, nor are we aware of the full extent of data collection, the purposes or the retention periods.
Information on the purpose and scope of data collection and its processing by the plug-in provider can be found in the respective data protection policies of these providers, where you will also find further information on your rights and options for privacy protection.
We use the following categories of cookies on our Website:
Category 1: Strictly Necessary Cookies These cookies collect information on how people use our website. For example, we use Google Analytics cookies to help us understand how users arrive at our site, browse or use our site and highlight areas where we can improve areas such as navigation, booking experience and marketing campaigns. The data stored by these cookies never shows personal details from which your individual identity can be established.
Category 2: Performance Cookies These cookies collect information on how people use our website. For example, we use Google Analytics cookies to help us understand how users arrive at our site, browse or use our site and highlight areas where we can improve areas such as navigation, booking experience and marketing campaigns. The data stored by these cookies never shows personal details from which your individual identity can be established.
Category 3: Functionality Cookies These cookies remember choices you make such as the country you visit our Website from, language and search parameters such as number of guests, resort, time of stay. These can then be used to provide you with an experience more appropriate to your selections and to make the visits more tailored and pleasant.
Current versions of web browsers offer enhanced user controls regarding the placement and duration of both first and third-party cookies. Search for "cookies" under your web browser's “Help” menu for more information on cookie management features available to you. You can enable or disable cookies by modifying the settings in your browser. You can also find out how to do this, and find more information on cookies at www.allaboutcookies.org. However, if you choose to disable cookies in your browser, you may be unable to complete certain activities on our websites or to correctly access certain parts of it.
Our Website uses Google Analytics, which is a web analytics service provided by the third party provider Google, Inc. (“Google”). Google Analytics is used for the purpose of evaluating your use of our Website, compiling reports on Website activity and other services relating to Website activity and internet usage.
Security measures for compliance with data protection
We strive to maintain the appropriate standards of security and we have put in place sufficient technical and organisational measures for the protection of your Personal Data in accordance with the current state of the art technologies, especially to protect the data against loss, falsification or access by unauthorised third persons. For the transfer of particularly sensible Personal Data via the internet, such as for example credit card details, we exclusively use encrypted transmission routes and we comply with the Payment Card Industry Data Security Standards (PCI DSS) which is a set of policies and procedures intended to optimise the security of credit, debit and cash card transactions and protect cardholders against misuse of their personal information.
In respect of the collection and use of your personal data, you may:
withdraw your consent at any time for example by unsubscribing from the newsletter under “data protection”,
ask us whether we process Personal Data about you, for which purposes, the categories of Personal Data concerned, to which categories of recipients the information has been disclosed, where possible, the envisaged period for which the personal data will be stored (or, if not possible, the criteria used to determine that period),
inquire with us about the appropriate safeguards relating to the transfer to a third party, ask us for a copy of the Personal Data undergoing processing and ask to receive your Personal Data in a structured, commonly used and machine-readable format and to transmit those data to another controller without any hindrance from us.
have inaccurate data rectified,
object against the further processing and request erasure of your Personal Data,
request that the processing of your personal data is restricted by Vaya Beach Resort ,
request not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
If you have any further questions on your personal data which has been stored with us or would like to exercise your rights please refer to our Data Protection Manager via email: firstname.lastname@example.org.
Retention and deletion of Personal Data
We will retain your personal data only for a limited period of time needed to fulfil the purposes of processing mentioned above. After that time your personal data will be erased. If we process your personal data based on your consent we will retain your personal data for a limited period of time needed to fulfil the purposes of processing it accordance to the Bulgarian legislation. We will keep your information for the duration of the contractual relationship you have with us, and, to the extent permitted, after the end of that relationship for as long as necessary to perform the purposes set out in this notice. The criteria to determine the storage period are statutory and contractual requirements, the nature of our relationship with you, the nature of the data concerned and the technical requirements. Laws may require us to hold certain information for specific periods.
Where we process personal data for marketing purposes or with your consent, we process the data until you ask us to stop and for a short period after this (to allow us to implement your requests). We also keep a record of the fact that you have asked us not to send you direct marketing or to process your data so that we can respect your request in future. In other cases, we may retain data for an appropriate period after any relationship with you ends, to protect ourselves from legal claims, or to administer our business.
Who is the contact person for questions and/or problems relating to the data protection?
Please contact our Data Protection person in charge at email@example.com
We are happy to welcome you back with refined experience and exceptional services! Let us take care for your peace of mind these Easter Holidays. Enjoy family traditions and friends in safe and secluded environment. For your private proposal, please check our Exclusive offers or do not hesitate to contact us.
Stay safe and keep dreaming...our journey together will continue!