Privacy policy
Privacy and Personal Data Protection Policy
Last updated: 7 September 2026
This Privacy Policy explains how the personal data of visitors to the Bansko Spa & Holidays website is collected, used, stored and protected. It also applies to individuals who submit enquiries, request offers or make reservations.
1. Personal Data Controller
The personal data controller is:
Turserviz LTD, UIC 103711877, with registered office and management address at Varna, PVZ Trakata 1611, operator of Bansko Spa & Holidays.
Hotel address: 29 Yavor Street, Bansko, Bulgaria
Reservations email: office@banskospa.net
Email for personal data enquiries: office@banskospa.net
Telephone: +359 877 000 780
2. Who This Policy Applies To
This policy applies to:
- visitors to the website;
- individuals submitting enquiries through the website’s contact forms;
- hotel guests and potential guests;
- individuals requesting accommodation offers;
- representatives of companies and organisations submitting enquiries about events, conferences, team-building programmes and organised groups;
- individuals subscribing to receive news and special offers;
- individuals communicating with us by telephone, email or through our social media profiles.
3. Personal Data We Collect
Depending on how you use the website and our services, we may process the following information:
Contact details
- first and last name;
- telephone number;
- email address;
- company or organisation;
- job title, where relevant to a corporate enquiry.
Reservation and stay details
- preferred arrival and departure dates;
- number of adults and children;
- children’s ages, where required to determine the applicable conditions and price;
- selected room type;
- accommodation, meal and additional service preferences;
- special requirements voluntarily provided by you;
- payment confirmation information, without storing full payment card details when the payment is processed by an external provider.
Corporate event and group details
- company or organisation name;
- contact person;
- number of participants and guests;
- preferred dates;
- required number of rooms;
- type of event;
- requirements regarding venues, equipment, catering and entertainment;
- preferred budget and additional organisational requirements.
Information submitted through contact forms
- the content of your message;
- any information you voluntarily provide;
- date and time of the enquiry;
- technical information required to prevent abuse and spam.
Technical information
When you visit the website, the following information may be processed automatically:
- IP address;
- browser type and version;
- operating system and device type;
- pages visited;
- date and time of the visit;
- referring page or website;
- technical logs and error information;
- identifiers stored through cookies, where you have provided the required consent.
4. Purposes of Processing
Personal data may be processed for the following purposes:
- responding to enquiries;
- preparing and sending personalised offers;
- creating, confirming and managing reservations;
- providing the requested hotel services;
- organising conferences, team-building programmes, corporate events and group accommodation;
- communicating with guests before, during and after their stay;
- processing payments and refunds;
- issuing accounting and tax documents;
- complying with legal obligations;
- protecting the legitimate interests, property and security of the hotel and its guests;
- preventing fraud, abuse and technical attacks;
- maintaining and improving the website;
- measuring website traffic and performance;
- sending marketing communications and special offers where valid consent has been provided.
5. Legal Bases for Processing
We process personal data on one or more of the following legal bases:
Performance of a contract or steps taken before entering into a contract
This legal basis applies when you:
- request information about prices or availability;
- request a personalised offer;
- make or manage a reservation;
- request a hotel or additional service;
- communicate with us regarding an upcoming or completed stay.
Compliance with a legal obligation
Certain information is processed and retained where necessary to comply with applicable accounting, tax, tourism or other legal requirements.
Legitimate interests
We may process personal data for:
- protecting our information systems and website;
- preventing fraud and abuse;
- establishing, exercising or defending legal claims;
- improving our services and guest communications;
- maintaining necessary business correspondence.
When relying on legitimate interests, we assess whether those interests are overridden by your rights and interests.
Consent
Consent may be used for:
- sending marketing communications;
- using analytical and advertising cookies;
- processing information that is not necessary for providing the requested service.
You may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
6. Recipients of Personal Data
Where necessary, personal data may be disclosed to:
- employees and authorised representatives of the hotel;
- providers of hotel management and reservation systems;
- hosting, technical support and email service providers;
- payment service providers and banks;
- accounting and legal advisers;
- suppliers involved in organising requested events or additional services;
- online booking platforms where a reservation is made through them;
- analytics and advertising service providers where the required consent has been provided;
- state and municipal authorities where disclosure is required by law.
We only disclose information necessary for the relevant purpose and require our service providers to apply appropriate data protection measures.
7. Transfers Outside the European Economic Area
Some providers of analytics, advertising, cloud or communication services may process personal data outside the European Economic Area.
Where such a transfer takes place, we use the applicable legal safeguards, including an adequacy decision, Standard Contractual Clauses or other appropriate safeguards under data protection legislation.
8. Data Retention Periods
We retain personal data only for as long as necessary for the relevant purpose:
- enquiries that do not result in a reservation – for up to 12 months after the communication has ended;
- reservation and stay information – for the duration of the contractual relationship and afterwards in accordance with applicable statutory retention and limitation periods;
- accounting and tax documents – for the periods required by applicable legislation;
- corporate enquiries that do not result in a contract – for up to 12 months after the last communication;
- marketing data – until consent is withdrawn or the relevant marketing activity is discontinued;
- technical logs – for the period required to maintain the security and proper operation of the website;
- information required for legal claims – until the relevant proceedings are finally concluded or the applicable limitation period expires.
After the relevant retention period expires, the information is deleted, anonymised or archived where required by law.
9. Cookies
The website may use:
- strictly necessary cookies;
- functional cookies;
- analytical cookies;
- advertising cookies.
Strictly necessary cookies are used for the proper operation and security of the website.
Analytical and advertising cookies are used only after consent has been obtained, where such consent is required. You can change your preferences through the website’s cookie settings.
Detailed information about the cookies used, their providers, purposes and duration is available in the separate Cookie Policy.
10. Marketing Communications
We may send you news, special offers and promotions only where we have an applicable legal basis.
You may stop receiving marketing communications at any time by:
- using the unsubscribe link in the message;
- contacting us using the details provided in this policy.
Opting out of marketing communications does not affect service-related communications required to manage a reservation or provide a requested service.
11. Children’s Data
The website and our services are not intended for independent use by children.
Information about children may be processed where it has been provided by a parent, guardian or another person making the reservation and is required to determine the applicable accommodation conditions or provide the requested services.
We do not knowingly use children’s personal data for direct marketing.
12. Data Security
We apply appropriate technical and organisational measures to protect personal data against:
- unauthorised access;
- unlawful use;
- loss or destruction;
- accidental alteration;
- unauthorised disclosure.
Access to personal data is limited to individuals who require it to perform their professional duties.
Despite the measures taken, no information transmission or storage system can guarantee absolute security.
13. Your Rights
Subject to the conditions of applicable legislation, you have the right to:
- receive information about whether we process your personal data;
- request access to your personal data;
- request the correction of inaccurate or incomplete information;
- request the deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive personal data provided by you in a structured, commonly used and machine-readable format, where applicable;
- request the transfer of your data to another controller, where applicable;
- withdraw consent;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where this right applies;
- submit a complaint to the competent supervisory authority.
These rights are not absolute and may be restricted in circumstances provided by law.
14. How to Exercise Your Rights
You can submit a request:
By email: office@banskospa.net
Please provide sufficient information to allow us to identify the person and personal data concerned by the request.
Where necessary to protect personal data, we may request additional information to verify your identity. We will not request more information than is necessary for this purpose.
We will respond within the time limits established by applicable legislation.
15. Complaints to the Supervisory Authority
If you believe that your personal data is being processed unlawfully, you have the right to submit a complaint to:
Commission for Personal Data Protection
Address: 2 Prof. Tsvetan Lazarov Boulevard, Sofia 1592, Bulgaria
Email: kzld@cpdp.bg
Website: https://cpdp.bg/
You may also seek protection through the competent courts.
16. External Websites and Services
The website may contain links to:
- an online reservation system;
- payment service providers;
- social media platforms;
- travel and accommodation platforms;
- map services and other external services.
These services may apply their own privacy policies. We are not responsible for how independent third parties process personal data through their own websites and systems.
We recommend reviewing their privacy policies before using their services.
17. Changes to This Policy
We may update this policy when changes are made to the website, the services we use or applicable legislation.
The current version will always be published on this page together with the date of the latest update.
Where significant changes are made, we may publish an additional notice on the website.
18. Contact Details
For questions about this policy or the processing of your personal data, please contact:
Turserviz LTD
Bansko Spa & Holidays
Hotel address: 29 Yavor Street, Bansko, Bulgaria
Email: office@banskospa.net
Telephone: +359 877 000 780