At Ruskovets Resort, we are committed to protecting and respecting your privacy. Please read this notice as it contains important information about how we use the personal data we collect from you or that you provide to us.
Information and consent
This Privacy Policy describes how we collect, use, process, and disclose your information, including personal information about you (“User”), in connection with your access to and use of our reservation system.
By reading this Privacy Policy, the user is informed about how we collect, process and protect the personal data provided through the reservation system.
The User should carefully read this Privacy Policy, which is written in a clear and simple manner to facilitate understanding, and to decide freely and voluntarily whether he wishes to provide his personal data or that of third parties to Ruskovets Resort.
Where this notice mentions “booking system”, “booking engine”, “system”, “website”, “platform”, “app”, “web app”, “services”, “online services”, this refers to all pages and features of https://ruskovetsresort.reserve-online.net/ unless otherwise stated.
By accessing the Platform or providing information, you agree to our privacy practices as set forth in this Privacy Statement. We may change this notice from time to time. You should check this notice frequently to ensure that you are aware of the latest version.
Identity
Where this notice mentions “we”, “us” or “our”, “data controller”, “administrator”, it refers to the Ruskovets complex.
Data Administrator
Ruskovets Resort manages this reservation system through a data processor as explained below. For the purposes of the General Data Protection Regulation (“GDPR”) (EU) 2016/679, we are the data controller. There is a strict contractual framework between the data controller and the data processor to protect your personal information. We are.
Data processor
WebHotelier operates this reservation system on behalf of Ruskovets Resort and is committed to protecting the privacy of the users of this system. WebHotelier is:
WebHotelier Technologies Limited
Mnasiadou 9 (Demokritos building, office 16)
1065 Nicosia
Cyprus
For the purposes of GDPR, where WebHotelier processes your personal data on behalf of Ruskovets Resort, WebHotelier is the Data Processor. Where this notice mentions “Data Processor”, “Processor”, “WebHotelier”, it refers to WebHotelier Technologies Limited.
WebHotelier is a certified PCI-DSS Level 2 service provider, audited monthly by Trustwave.
The user may contact the WebHotelier Data Protection Officer: Data Protection Officer, dpo@webhotelier.net
Obligation to provide the data
The data required in the forms accessible from the booking engine are generally mandatory (unless otherwise specified in the mandatory field) to meet the stated purposes. Accordingly, if they are not provided or are not provided correctly, we will not be able to process the request.
Personal data we collect and process
This will include:
We give permission to our data processor:
Social Entry:
In the case of registration and/or access through a third party account, we may collect and access certain profile information from the relevant social network for internal administrative purposes only and/or for the purposes set out above.
Third-party data (e.g. book for a friend)
In the event that the User provides data to a third party, the User declares that it has the consent of the third party and undertakes to provide the interested party – the data owner – with the information contained in this Privacy Notice, duly releasing us and our data processor from any liability in this respect. We may, however, carry out the necessary checks to confirm this fact by taking the appropriate due diligence measures in accordance with data protection regulations.
Sensitive data
Unless specifically requested, we ask that you do not send us or disclose to us on or through the Services or otherwise to us any sensitive personal data (e.g., social security numbers, national identification numbers, data relating to racial or ethnic origin, political opinions, religion, ideological or other beliefs, health, biometric or genetic characteristics, criminal background, trade union membership, or administrative or criminal proceedings and sanctions).
Use of services by minors
The Services are not directed to individuals under the age of sixteen (16) and we require that they do not provide Personal Information through the Services.
Purpose of the processing of personal data
Depending on the user’s requests, the personal data collected will be processed in accordance with the following purposes:
To administer surveys and/or evaluations regarding the quality of our services and/or the perception of our image as a company.
Saving data
We will retain your Personal Data for the period necessary to fulfil the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law or if the User requests its withdrawal from us, objects or withdraws their consent.
The criteria used to determine our retention periods include:
Legitimate interest in processing your data
By the same logic, in cases where it is necessary to process the User’s data for the performance of a legal obligation or for the performance of an existing contractual relationship between us and the User, the processing will be legitimate as it is necessary for compliance with those purposes.
Disclosure of data
We will use and disclose Personal Information as we deem necessary or appropriate:
We may use and disclose Other Data for any purpose, except as permitted under applicable law. In some cases, we may combine Other Data with Personal Data (such as combining your name with your location). If we do, we will treat the combined data as Personal Data for as long as it is combined.
International transfers of personal data
We may transfer your personal information to our processor(s) and/or sub-processor(s) based outside the EEA for the purposes described in this notice. If we do so, your personal information will continue to be subject to one or more of the appropriate safeguards set out in the law. This may be the use of model contracts in a form approved by regulators, or the signing up of our suppliers to an independent privacy scheme approved by regulators (such as the US Privacy Shield scheme).
Our data is stored in the cloud using Amazon Web Services in Northern Virginia, USA and in Frankfurt, Germany. If you access any of our systems outside the United States, you acknowledge that your personal information may be transferred to the United States, a jurisdiction that may have different privacy and data security protections than your own jurisdiction, to be processed and stored.
User responsibility
User:
Will be liable for any false or inaccurate information provided via the website and for any damages, direct or indirect, that this may cause to us or to third parties.
Exercise of rights
The user can contact us at any time free of charge to:
The user is also informed that he or she may, at any time, lodge a complaint concerning the protection of his or her personal data with the competent data protection authority.
Security measures
We will process the User’s data at all times in an absolutely confidential manner and will maintain the mandatory duty of confidentiality in respect of such data, in accordance with the provisions set out in the applicable regulations, and to this end we will take technical and organisational measures of a necessary nature to ensure the security of their data and to prevent their alteration, loss, processing or unlawful access, depending on the state of the technology, the nature of the data stored and the risks to which they are exposed.