PERSONAL DATA PROCESSING DECLARATION
pursuant to Article 13 of Regulation (EU) 2016/679 (GDPR) – effective from 26.08.2026.
This Declaration is a translation of the Bulgarian original. In the event of any discrepancy between the language versions, the Bulgarian version shall prevail.
Who processes your data
SARNITE – SINEVA BEACH JSC, UIC 202745490, VAT No BG202745490, with registered office and address at Sofia, Dragalevtsi district, 28 Zahari Zograf Street, Bulgaria, represented by Lyudmila Aleksandrovna Terzieva, operating Hotel Sineva Beach, Saint Vlas 8256 (the “Company”, the “Merchant”), in its capacity as personal data controller.
Contact for data protection matters: sineva_beach@abv.bg, tel. +359 877 446 206.
We hereby declare the following
- The Company has the right to collect and process personal data of its clients, guests and visitors to the website www.sinevabeach.com in its capacity as personal data controller, in strict compliance with Regulation (EU) 2016/679 (GDPR), the Bulgarian Personal Data Protection Act and applicable Bulgarian legislation.
- We process the following categories of data: names, e-mail address, telephone, country and address; reservation data (dates, room type, number and ages of guests, special requirements); invoicing data; identity document data on check-in (in accordance with the Tourism Act); payment data (amount, currency, reservation number, date, time and status of the transaction, the last 4 digits of the card); technical data (IP address, cookie data) and the content of correspondence with us.
- We process the data for the following purposes: conclusion and performance of the reservation and accommodation contract; acceptance and processing of payments; issuing accounting and tax documents; compliance with legal obligations (including maintaining the register of accommodated tourists and submitting data to ESTI); responding to enquiries and handling complaints and disputed payments; website security and fraud prevention; sending marketing communications – only with your express consent.
- Legal bases: performance of a contract (Art. 6(1)(b)); compliance with a legal obligation (Art. 6(1)(c)); the legitimate interests of the Company (Art. 6(1)(f)); your express consent (Art. 6(1)(a)) – for marketing and for non-essential cookies.
- We do not collect, process or store bank card data. The full card number, expiry date, CVV2/CVC2 security code and PIN are entered by you solely within the secure environment of the servicing bank during a 3-D Secure payment and never reach the Company at any point.
- The Company complies with the security requirements of the International Card Organisations Mastercard International and Visa International, including the applicable requirements of the PCI DSS standard and the rules of the Visa Secure and Mastercard Identity Check programmes, as well as with the “General Terms and Conditions for servicing payments with electronic payment instruments accepted over the Internet through the use of the Virtual POS terminal device service” of the servicing bank – Allianz Bank Bulgaria JSC.
- We apply appropriate technical and organisational measures to protect the data: encrypted SSL/TLS (HTTPS) connection, control and restriction of access to employees for whom it is necessary in the performance of their duties, confidentiality obligations for staff, regular backups and updates, firewalls and antivirus protection, and internal procedures for responding to security incidents.
- Data are disclosed only to: the servicing bank and the payment service provider (for the processing of payments and of any disputes); the provider of the reservation system (Quendoo); the hosting and technical support provider; the accounting service provider; and the competent state authorities where provided for by law. We do not sell or provide your data to third parties for their own commercial purposes.
- Retention periods: reservation and payment data – up to 5 years; accounting and tax documents – 10 years under the Accountancy Act; data in the register of accommodated tourists – for the statutory periods; data processed on the basis of consent – until that consent is withdrawn.
- Your rights: access to your data; rectification; erasure (“right to be forgotten”); restriction of processing; data portability; objection to processing; withdrawal of consent at any time; the right to lodge a complaint with the Commission for Personal Data Protection (1592 Sofia, 2 Prof. Tsvetan Lazarov Blvd, kzld@cpdp.bg, www.cpdp.bg) or with the courts. Requests are to be sent to sineva_beach@abv.bg; we respond within one month.
- Deletion of a user account: if you have created an account on the website, you have the right to request its deletion at any time by e-mail to sineva_beach@abv.bg or through the deletion function within the account itself. The account is deleted within 30 days, with the exception of data we are required by law to retain.
- We do not carry out automated decision-making or profiling producing legal effects for you or similarly significantly affecting you.
- Providing the reservation data is a necessary condition for the conclusion and performance of the contract. If you refuse to provide it, we cannot accept and fulfil your reservation. Providing data for marketing purposes is voluntary.
By ticking the consent box when making a reservation, you declare that you have read this Declaration, the Privacy Policy and the General Terms and Conditions of the Merchant and that you accept them.
SARNITE – SINEVA BEACH JSC
UIC 202745490 | VAT No BG202745490
Sofia, Dragalevtsi district, 28 Zahari Zograf Street, Bulgaria
Represented by: Lyudmila Aleksandrovna Terzieva
Date: 26.08.2026
