Personal Data Policy

Processing of personal data

Color M Ltd. is a personal data controller pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) and the Personal Data Protection Act. When processing personal data, Color M Ltd. complies with the principles set out in the General Data Protection Regulation: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.

1. PURPOSES OF PROCESSING

Color M Ltd. processes personal data for the following purposes, which reflect the grounds for their processing:

• in compliance with the requirements of the Tourism Act, Article 116;

• provision of services: reservations, hotel accommodation;

• performance of concluded contracts;

• identifying customers using the services of Hotel Palitra Varna, 11 Konstantin Doganov Street;

• human resources management;

• video surveillance;

• exercising rights under Regulation (EU) 2016/679 before the BNB as a personal data controller;

• processing complaints, signals, and other requests.

2. RIGHTS OF DATA SUBJECTS

Persons whose personal data is processed by Color M Ltd. have the following rights:

A/ Right of access – at the request of the data subject,

Color M Ltd. shall provide information regarding:

* the personal data it collects and processes;

* the purposes for which they are processed;

* the recipients or categories of recipients to whom the personal data are disclosed, if any;

* the sources from which the data were obtained, except where they were collected directly from the data subject.

B/ Right to rectification – upon request of the data subject, Color M Ltd. shall rectify inaccurate personal data relating to him/her.

C/ Right to erasure (or “right to be forgotten”) – at the request of the data subject, when there is no legal basis for their processing, Color M Ltd. shall erase the data if any of the following grounds apply:

* the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;

* the data subject withdraws the consent on which the processing is based;

* the data subject objects to the processing and there are no overriding legitimate grounds for the processing;

* the personal data has been processed unlawfully;

* the personal data must be erased to comply with a legal obligation.

D/ Right to restriction of processing – at the request of the data subject, Color M Ltd. shall restrict the processing of personal data in the cases expressly provided for in the General Data Protection Regulation.

E/ Right to data portability – the data subject has the right to request and receive the personal data concerning him or her, which he or she has provided to Hotel Palitra, in a commonly used, structured, and machine-readable format, and has the right to transmit/transfer this data to another controller. This right applies when the basis for the processing of personal data is consent or a contractual obligation and the processing of personal data is carried out by automated means, i.e. it is technically possible to do so.

E/ Right to object – the data subject has the right to object at any time and on grounds related to the specific situation, provided that there are no compelling legal grounds for the processing that take precedence over the interests, rights, and freedoms of the natural person. Color M Ltd. shall consider the objection and provide its opinion in writing within 30 days, unless an extension is necessary, in which case the data subject will be notified in a timely manner.

G/ Right to withdraw consent – in cases where processing is based on consent, the data subject has the right to withdraw it by sending a request by email to palitra@abv.bg or in person at Hotel Palitra Varna, 11 Konstantin Doganov Street.

G/ Right to lodge a complaint – the data subject has the right to lodge a complaint with the supervisory authority – the Personal Data Protection Commission, at the following address: 1592 Sofia, Prof. Tsvetan Lazarov Blvd. No. 2, email: kzld@cpdp.bg, in relation to the processing of their personal data.

Note: The exercise of some of the rights described may not be a reason for refusing to provide personal data to the competent authorities for the prevention, investigation, and detection of crimes. The rights of data subjects shall be exercised by them in compliance with the provisions and requirements of the General Data Protection Regulation.

3. TYPES OF PERSONAL DATA PROCESSED

Color M Ltd. processes personal data that may be obtained directly from the data subject or from a third party. Color M Ltd. may process different types of data, depending on the purpose of the processing, such as:

• data through which the data subject can be identified (e.g., full name, personal identification number);

• contact details to get in touch with the data subjects (e.g., phone number, email address, postal address);

• personal data provided by administrators in cases provided for by law;

• video surveillance recordings – video surveillance is carried out in and around the premises of Hotel Palitra Varna on the basis of the Private Security Activity Act.

4. PERSONS PROCESSING PERSONAL DATA AT “Color M” Ltd. Access to personal data is only granted to persons whose job duties or specific tasks require such access, in compliance with the “need to know” principle and after familiarization with the regulations in the field of personal data protection.

5. PERSONS PROCESSING PERSONAL DATA PROVIDED BY “Color M” LTD.

Color M Ltd. has a legal obligation to provide personal data to data controllers. Personal data processors are natural or legal persons, public authorities, agencies, or other structures that process personal data on behalf of the controller.

6. GROUNDS FOR PROCESSING

The personal data collected by Color M Ltd. in its capacity as a personal data controller is processed on the following grounds, as follows:

• consent of the data subject for one or more specific purposes;

in connection with the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

• for compliance with a legal obligation;

• for the purposes of the legitimate interests pursued by the controller or by a third party.

7. RETENTION PERIOD OF PERSONAL DATA Personal data processed by Color M Ltd. is stored in accordance with the periods specified by law or in internal acts.

8. TECHNICAL AND ORGANIZATIONAL PROTECTION MEASURES

Color M Ltd. applies the necessary technical and organizational measures and protection measures in accordance with the regulatory requirements.

9. PERSON RESPONSIBLE FOR PERSONAL DATA PROTECTION

n connection with the processing of personal data, the data subject may contact Color M Ltd. through the personal data protection officer – Plamen Doichev, Manager, at the email address адрес:palitra@abv.bg, in writing at the office in the building of Hotel Palitra Varna or at the postal address: Varna, Vasil Levski Blvd., bl. 9, entrance A.