PRIVACY AND PERSONAL DATA PROTECTION POLICY
Effective from 26.08.2026.
This Policy describes how SARNITE – SINEVA BEACH JSC collects, uses, stores and protects your personal data when you use the website www.sinevabeach.com, when making reservations and payments, and during your stay at Hotel Sineva Beach, in accordance with Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act (PDPA).
This Policy is a translation of the Bulgarian original. In the event of any discrepancy between the language versions, the Bulgarian version shall prevail.
1. Who processes your data (Controller)
| Controller | SARNITE – SINEVA BEACH JSC |
|---|---|
| Company ID (UIC) | 202745490 |
| VAT number | BG202745490 |
| Registered office and address | Sofia, Dragalevtsi district, 28 Zahari Zograf Street, Bulgaria |
| Represented by | Lyudmila Aleksandrovna Terzieva |
| Site | Hotel Sineva Beach, Saint Vlas 8256, Burgas region |
| Telephone | +359 877 446 206 |
| E-mail for data protection enquiries | sineva_beach@abv.bg |
2. What personal data we collect
| Category | Specific data |
|---|---|
| Reservation data | first and last name, e-mail address, telephone, country, address (for invoicing), number and ages of guests, names of accompanying persons, dates of stay, room type, board arrangement, special requirements and notes |
| Payment data | selected payment method, amount paid and currency, reservation number, date and time of the transaction, transaction status, the last 4 digits of the card and the unique transaction identifier received from the servicing bank. We do not collect or store the full card number, expiry date, CVV2/CVC2 or PIN. |
| Invoicing data | name/company name, address, UIC/VAT number, representative, bank details |
| Check-in data | data from an identity document (full name, nationality, date of birth, sex, type, number and issuer of the document), which are entered in the register of accommodated tourists in accordance with the Bulgarian Tourism Act |
| Account data (if you create one) | e-mail address, encrypted password, first and last name, telephone, reservation history |
| Technical data | IP address, browser type and version, operating system, pages visited, date and time of the visit, referral source, cookie data |
| Correspondence | the content of enquiries, complaints, reviews and other communication with us |
| Video surveillance | video recordings from the common areas of the hotel, where such surveillance is carried out – with signage on site |
We do not knowingly collect data of persons under 18 years of age without the consent of a parent or guardian. Data relating to children accompanying guests are provided by their parents/guardians.
3. For what purposes and on what legal basis
| Purpose | Legal basis (GDPR) | Retention period |
|---|---|---|
| Conclusion and performance of the reservation and accommodation contract | Art. 6(1)(b) – performance of a contract | up to 5 years from the end of the stay |
| Processing payments and defending against disputed transactions | Art. 6(1)(b) and (c); Art. 6(1)(f) – legitimate interest | up to 5 years from the transaction |
| Issuing and retaining accounting and tax documents | Art. 6(1)(c) – legal obligation (Accountancy Act, Tax and Social Insurance Procedure Code, VAT Act) | 10 years |
| Maintaining the register of accommodated tourists and submitting data to the Unified Tourism Information System (ESTI), as well as providing data to the competent authorities | Art. 6(1)(c) – legal obligation (Tourism Act) | in accordance with the statutory periods |
| Responding to enquiries and handling complaints | Art. 6(1)(b) and (f) | up to 3 years from closure of the case |
| Maintaining a user account | Art. 6(1)(b) | until deletion of the account at your request |
| Sending news and offers (marketing) | Art. 6(1)(a) – your express consent | until consent is withdrawn |
| Website security, prevention of fraud and abuse | Art. 6(1)(f) – legitimate interest | up to 12 months |
| Analysis of traffic and improvement of the website (analytics and marketing cookies) | Art. 6(1)(a) – consent via the cookie banner | in accordance with the lifetime of the relevant cookie |
| Establishment, exercise or defence of legal claims | Art. 6(1)(f) | until expiry of the applicable limitation period |
Providing the reservation data is a necessary condition for concluding the contract. If you do not provide it, we cannot accept and fulfil your reservation. Providing data for marketing purposes is voluntary and your refusal does not affect your reservation.
4. To whom we disclose the data (recipients)
Your data may be disclosed to the following categories of recipients, only to the extent necessary and subject to confidentiality safeguards:
| Recipient | Purpose / capacity |
|---|---|
| Allianz Bank Bulgaria JSC and the payment service provider operating the virtual POS terminal | processing of bank card payments, refunds and the examination of disputed transactions – independent controller |
| Quendoo – provider of the reservation system and channel manager | receiving and managing online reservations – data processor |
| Hosting and technical maintenance provider | technical maintenance of the website – data processor |
| Accounting services | accounting and tax services – data processor |
| Hotel management software (PMS) | management of accommodation and invoicing – data processor |
| Tour operators and online booking platforms (where the reservation was made through them) | fulfilment of the reservation – independent controllers |
| State authorities – Ministry of Tourism (ESTI), Ministry of the Interior, National Revenue Agency, National Statistical Institute, municipal administration, courts | compliance with legal obligations |
| E-mail and communication service providers | sending confirmations and correspondence |
We do not sell or rent your personal data to third parties.
5. Transfers of data outside the EU
As a rule, data are processed within the European Union/EEA. Where any of the service providers used (for example analytics, mapping or communication services) processes data outside the EU/EEA, the transfer takes place only on the basis of a European Commission adequacy decision or under standard contractual clauses adopted by the Commission, with appropriate supplementary safeguards.
6. How we protect your data
- Encrypted SSL/TLS (HTTPS) connection across the entire website and the reservation form.
- Card payments take place entirely within the secure environment of the servicing bank, with 3-D Secure authentication. The hotel has no access to your card details.
- Compliance with the security requirements of the ICO Mastercard and Visa and with the applicable requirements of the PCI DSS standard.
- Access to data limited to employees who need it in order to perform their duties, bound by confidentiality obligations.
- Regular backups, software updates, firewalls and antivirus protection.
- Internal data protection rules and incident response procedures. In the event of a security breach giving rise to a high risk to your rights, we will notify you and report to the CPDP in accordance with Articles 33 and 34 GDPR.
7. Your rights
As a data subject you have the following rights:
- Right of access (Art. 15) – to obtain information on whether we process your data and a copy of it.
- Right to rectification (Art. 16) – to request correction of inaccurate or incomplete data.
- Right to erasure / “right to be forgotten” (Art. 17) – insofar as no legal retention obligation applies.
- Right to restriction of processing (Art. 18).
- Right to data portability (Art. 20) – to receive your data in a structured, machine-readable format.
- Right to object (Art. 21) – to processing based on legitimate interest, including for direct marketing.
- Right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
- Right not to be subject to automated decision-making – we do not carry out automated profiling producing legal effects for you.
- Right to lodge a complaint with the Commission for Personal Data Protection or with the courts.
How to exercise your rights
Send a written request to sineva_beach@abv.bg or to the hotel’s address, stating your name, contact details and your specific request. We respond within one month of receipt of the request; for complex or numerous requests this period may be extended by a further two months, of which you will be informed. The service is free of charge; for manifestly unfounded or excessive requests a reasonable fee may be charged.
Supervisory authority
Commission for Personal Data Protection (CPDP)
1592 Sofia, 2 Prof. Tsvetan Lazarov Blvd, Bulgaria
tel.: +359 2 915 3518; e-mail: kzld@cpdp.bg; www.cpdp.bg
8. Cookies
The website uses cookies. Detailed information is available in the Cookie Information.
9. Changes to this Policy
We reserve the right to update this Policy. The current version is published at this address with its date of entry into force. In the event of material changes we will notify you by appropriate means.
SARNITE – SINEVA BEACH JSC – last updated 26.08.2026.
