Privacy Policy
How Ostany collects, uses and protects your personal data.
This is the English version. In the event of any discrepancy with the Bulgarian version, the Bulgarian version shall prevail.
Privacy Policy — protection of personal data
Version: 1.0
Date of publication: [date]
Date of entry into force: [date]
This Policy explains what personal data we collect, why and on what legal basis we process it, to whom we disclose it, how long we retain it and what rights you have.
It has been drawn up in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) and with the Bulgarian Personal Data Protection Act (Zakon za zashtita na lichnite danni).
The use of cookies is governed by a separate Cookie Policy — /legal/cookies-policy.
1. Who processes your data
1.1. Controller
| Name | [FULL LEGAL NAME INCLUDING LEGAL FORM] |
| UIC (Unified Identification Code) | [UIC] |
| Registered seat and management address | [address] |
| Correspondence address | [address] |
| Email for data protection enquiries | [privacy@domain] |
| Telephone | [telephone] |
| Website | [domain] |
1.2. Data protection officer
The Company has designated a data protection officer (DPO):
| Name or position | [name/position] |
| [dpo@domain] | |
| Postal address | [address] |
You may contact the DPO on all matters relating to the processing of your personal data and to the exercise of your rights under section 7.
1.3. Independent controllers
In addition to us, the following act as independent controllers in respect of your data:
| Who | For what | Relationship to us |
| The Host with whom you have made a Booking | Performance of the stay, keeping the register of accommodated persons, submitting data to the Unified Tourist Information System (ESTI), issuing documents | Independent controller. We transfer to the Host only what is necessary. The Host is responsible for its own processing. |
| Mollie B.V. | Payment processing, identification and verification under anti-money laundering legislation | Independent controller for payment and AML purposes. Policy: [link] |
| Competent authorities — the Ministry of Tourism, municipalities, the National Revenue Agency, the corresponding authorities in the other Member States | Compliance with legal obligations under Regulation (EU) 2024/1028, the Bulgarian Tourism Act (Zakon za turizma) and DAC7 | Independent controllers upon receipt of the data |
| Advertising platforms and social networks | Display and measurement of advertising — only within the scope of the consent given by you | Independent controllers for their own purposes. List and policies: see the Cookie Policy |
There is no joint controllership within the meaning of Article 26 GDPR between us and the Hosts — each of us independently determines the purposes and means of its own processing.
2. What data we collect
2.1. Data you provide to us
Necessary for the use of the Platform:
| Category | Specific data |
| Account and profile data | First name and surname, email address, telephone number, password (in hashed form), profile picture, date of birth, preferred language |
| Identity data (upon verification) | Image of an identity document, document number and validity period, nationality; where necessary — a selfie for comparison |
| Booking data | Dates, number and names of the guests, special requirements, messages with the Host |
| Payment data | Transaction identifier, last four digits of the card, type of payment instrument, amount, currency, date. Full card data is processed directly by Mollie and does not reach us. |
| Host data | Name, UIC, registered seat, details of the representative, bank account, details of the beneficial owners, tax identification number, VAT number, registration number of the Property, categorisation or registration document; for Properties in the Hellenic Republic — the ΑΦΜ (the Greek tax identification number) and an Α.Μ.Α. (Αριθμός Μητρώου Ακινήτου, the Greek property registry number) or ΜΗ.Τ.Ε. (Μητρώο Τουριστικών Επιχειρήσεων, the Register of Tourism Enterprises) number |
Data you provide optionally:
Additional profile information (description, city, languages spoken), reviews and ratings, photographs and other content, messages to us and to other users, survey responses, data relating to accompanying persons.
When you provide data about another person — for example a fellow traveller — you confirm that you have a basis for doing so and that you have made that person aware of this Policy.
Special categories of personal data (Article 9 GDPR). As a matter of principle we do not collect special categories of personal data. In the following limited cases such data may be processed:
| Case | Data | Basis |
| You voluntarily communicate dietary or health-related requirements in a message to the Host | Health data | Explicit consent — Article 9(2)(a) GDPR. You are not obliged to provide such data; you may communicate it directly to the Host upon check-in. |
| You communicate accessibility requirements | Data concerning disability | Explicit consent — Article 9(2)(a) GDPR |
| You bring a claim or a challenge in which you rely on a health-related reason | Health data | Establishment, exercise or defence of legal claims — Article 9(2)(f) GDPR |
We do not use biometric identification. If in the future we introduce automated facial comparison in the identity verification process, this will take place only after your explicit separate consent, with a non-biometric alternative made available and following a data protection impact assessment under Article 35 GDPR.
Personal data relating to criminal convictions and offences (Article 10 GDPR) is neither collected nor processed.
2.2. Data collected automatically
| Category | Specific data |
| Technical data | IP address, browser and operating system type and version, language settings, time zone, device identifiers |
| Usage data | Searches, Listings viewed, clicks, dates and times of access, referring page, session duration, actions within the booking flow |
| Approximate location | City and country, determined on the basis of the IP address |
| Precise location | Only through the mobile application and only after your explicit permission, which you may withdraw at any time from your device settings |
| Data from cookies and similar technologies | See the Cookie Policy |
| Security logs | Records of log-ins, failed log-in attempts, changes to the account |
We collect some of this data also when you do not have an account or are not logged in — in that case it is necessary for the functioning and the security of the website.
2.3. Data from third-party sources
| Source | Data |
| Mollie | Payment status, identification status, information on disputed transactions |
| Public registers — the Commercial Register, the National Tourist Register, the Unified Tourist Information System (ESTI), registers of Member States | Registration and categorisation data, validity of registration numbers |
| Fraud prevention service providers | Transaction risk scores, alerts on matches with known risk profiles |
| Third-party single sign-on services (if you use such a log-in) | Name, email address, profile picture — only to the extent you have authorised |
| Other users | Content of reports, complaints, reviews and Damage Reports that concern you |
3. Why and on what basis we process the data
The table below fulfils the requirements of Article 13(1)(c) and Article 13(2)(a) GDPR — for each purpose the legal basis and the retention period are indicated.
3.1. Purposes, legal bases and retention periods
| No. | Purpose | Categories of data | Legal basis (Article 6 GDPR) | Retention period |
| A | Creation and maintenance of an account | Account, profile | Article 6(1)(b) GDPR — performance of a contract | For as long as the account is active + 5 years after its closure (the general limitation period under Article 110 of the Bulgarian Obligations and Contracts Act (Zakon za zadalzheniyata i dogovorite)) |
| A1 | Recording of access and security logs | Log-in records, failed attempts, changes to the account, IP address | Article 6(1)(f) GDPR — legitimate interest in the security of accounts | 12 months |
| B | Processing and performance of a Booking; communication between Guest and Host | Account, booking data, messages | Article 6(1)(b) GDPR — performance of a contract for the Guest; Article 6(1)(f) GDPR — legitimate interest in performing the Booking requested by the Guest, as regards the accompanying persons | 5 years from the end of the stay |
| C | Acceptance of payments and Payouts | Payment data, transaction identifier | Article 6(1)(b) GDPR — performance of a contract; Article 6(1)(c) GDPR — for accounting purposes | Accounting registers and financial statements — 10 years, counted from 1 January of the following reporting period (Article 12(1)(2) of the Bulgarian Accountancy Act (Zakon za schetovodstvoto)); invoices and primary accounting documents — until expiry of the periods under Article 38 of the Bulgarian Tax and Social Insurance Procedure Code (Danachno-osiguritelen protsesualen kodeks) and Article 121 of the Bulgarian Value Added Tax Act (Zakon za danak varhu dobavenata stoynost) |
| D | Issuing and keeping accounting and tax documents | Identification and payment data | Article 6(1)(c) GDPR — legal obligation (the Accountancy Act, the Value Added Tax Act, the Tax and Social Insurance Procedure Code) | Accounting registers and financial statements — 10 years, counted from 1 January of the following reporting period (Article 12(1)(2) of the Accountancy Act); invoices and primary accounting documents — until expiry of the periods under Article 38 of the Tax and Social Insurance Procedure Code and Article 121 of the Value Added Tax Act |
| E | Verification of the identity of Hosts and of their Properties | Identity data, registration data, documents | Article 6(1)(c) GDPR — Article 30 of Regulation (EU) 2022/2065 and Regulation (EU) 2024/1028 | 6 months after termination of the contractual relationship, unless a law requires a longer period |
| F | Reporting of short-term accommodation activity data to the competent authorities | Registration number, address, URL, number of nights, number of guests, country of residence of the guests | Article 6(1)(c) GDPR — Article 9 of Regulation (EU) 2024/1028 | As required by the Regulation; the receiving authorities retain the data for no more than 18 months |
| F1 | Storing your preferences — language, currency, region, recent searches — through functional cookies | Data from functional cookies | Article 6(1)(a) GDPR — consent | Until withdrawal of consent or until expiry of the lifetime of the relevant cookie |
| G | Due diligence and reporting to the National Revenue Agency under DAC7; notifying the Host of the information reported in respect of it. In accordance with Article 25(4) of Directive 2011/16/EU, we notify each Host who is a natural person individually and in sufficient time before the reporting, at least once a year, of the information that will be submitted in respect of that Host. | Name, address, TIN, VAT number, date of birth, address of the Property, quarterly amounts | Article 6(1)(c) GDPR — Directive (EU) 2021/514 and Section VIII of Chapter Sixteen of the Tax and Social Insurance Procedure Code | 10 years — in accordance with the requirements for the retention of tax documentation |
| H | Customer support and handling of enquiries | Messages, account data, content of the communication | Article 6(1)(b) GDPR for enquiries relating to the contract; Article 6(1)(f) GDPR — legitimate interest in providing quality support | 3 years from closure of the case |
| I | Prevention, detection and investigation of fraud and abuse; security of the Platform | Technical data, usage data, reports, risk scores | Article 6(1)(f) GDPR — legitimate interest in protecting the Platform, its users and third parties against fraud and abuse | 3 years from the last recorded event; where fraud is established — 5 years |
| J | Content moderation and handling of reports and complaints | Content, reports, case file | Article 6(1)(c) GDPR — Regulation (EU) 2022/2065; Article 6(1)(f) GDPR — legitimate interest in maintaining a safe environment | 2 years from closure of the case file |
| K | Resolution of disputes, including Damage Reports | Booking data, evidence, communication | Article 6(1)(f) GDPR — legitimate interests; Article 9(2)(f) GDPR where the claim contains health data | 5 years from closure (Article 110 of the Obligations and Contracts Act) |
| L | Display, ranking and recommendation of Listings | Search and usage data, booking history | Article 6(1)(f) GDPR — legitimate interest in providing a relevant service | 2 years from the last activity |
| M | Personalised recommendations based on profiling | Search and booking history, behavioural data, cookie data | Article 6(1)(a) GDPR — consent, withdrawable at any time | Until withdrawal of consent or 2 years from the last activity |
| N | Direct marketing by email to our own customers | Email address, booking history | Article 6(1)(a) GDPR — consent (Article 6 of the Bulgarian E-Commerce Act (Zakon za elektronnata targoviya)) and Article 261 of the Bulgarian Electronic Communications Act (Zakon za elektronnite saobshteniya) | Until withdrawal of consent |
| O1 | Server-side analytics and improvement of the services on pseudonymised data | Aggregated and pseudonymised usage data | Article 6(1)(f) GDPR — legitimate interest in developing the service | 2 years, after which — only in anonymised form |
| O2 | Analytics through cookies and similar technologies | Data from analytics cookies | Article 6(1)(a) GDPR — consent | Until withdrawal of consent or until expiry of the lifetime of the cookie |
| P | Development and improvement of artificial intelligence models | Pseudonymised usage data and communications | Article 6(1)(a) GDPR — consent; you may opt out from your profile settings | Until withdrawal of consent |
| Q | Compliance with orders of competent authorities and defence of legal claims | All relevant data | Article 6(1)(c) GDPR — legal obligation; Article 6(1)(f) GDPR — legitimate interest in defending our rights | Until conclusion of the proceedings + the applicable limitation period |
| R | Protection of life and health in an emergency | Contact and location data | Article 6(1)(d) GDPR — vital interests | Until the necessity ceases to exist |
| S | Advertising profiling, retargeting and measurement of campaign performance through cookies and similar technologies | Cookie data, identifiers, data on interaction with the advertisements | Article 6(1)(a) GDPR — consent | Until withdrawal of consent or until expiry of the lifetime of the relevant cookie |
3.2. Data relating to persons who have not provided it to us themselves
(1) Where we process data of accompanying persons, the source of the data is the Guest who made the Booking. The categories of data are limited to the name and, where necessary for the accommodation, the age.
(2) In accordance with Article 14(5)(b) of Regulation (EU) 2016/679, providing the information directly to those persons would involve a disproportionate effort, since we do not hold their contact details. For that reason we publish this information and we task the Guest who provides the data with making them aware of it.
(3) Those persons have the same rights under section 7 and may exercise them at [privacy@domain].
3.3. Legitimate interests — specification
Where we rely on legitimate interests (Article 6(1)(f) GDPR), we have carried out and documented a balancing assessment in accordance with Guidelines 1/2024 of the European Data Protection Board. Our specific interests are:
Purpose I — protection of the Platform, of our users and of third parties against fraud, account takeover, money laundering and abuse. Without this processing we would be unable to detect fraudulent Listings and compromised accounts.
Purpose J — maintaining a lawful and safe environment, which is also our obligation under the Digital Services Act.
Purpose K — the ability to resolve disputes between Guests and Hosts objectively, instead of leaving the parties to their own devices.
Purpose L — the delivery of relevant results; without processing search data the service would be practically unusable.
Purpose O1 — identifying problems and improving the service, using pseudonymised data.
You have the right to object to any processing based on legitimate interests — see section 7.
3.4. Tax reporting under DAC7 — special notice
(1) The Platform is a platform operator required to report information under Directive (EU) 2021/514 (DAC7) and Section VIII of Chapter Sixteen of the Bulgarian Tax and Social Insurance Procedure Code.
(2) If you are a Host, every year in January, before the report is filed, you will receive an individual notification by email containing a statement of the data that will be reported in respect of you: identification data, the address of each Property, the number of days let, the total consideration paid out per quarter, and the fees and commissions withheld. The same statement is available at any time in your account.
(3) The data is submitted to the National Revenue Agency by 31 January of the year following the reporting year. For Properties in other Member States, including the Hellenic Republic, the information is exchanged automatically between the National Revenue Agency and the relevant national tax authority.
(4) If you do not provide the data requested, then after two reminders and upon the expiry of 60 days the Platform is required by law to suspend Payouts to you and/or to close your account.
4. To whom we disclose the data
4.1. Categories of recipients
| Recipient | What data | Why |
| The Host of the booked Property | Name, number of guests, dates, messages, telephone number upon a confirmed booking, special requirements you have communicated | Performance of the accommodation contract |
| The Guest, in the case of Hosts | Name, public profile, contact details upon a confirmed booking, address and access instructions | Performance of the accommodation contract |
| Mollie B.V. (the Netherlands) | Identification, payment and transaction data; for Hosts — the full KYC package | Payment processing, obligations under AML legislation |
| Hosting and cloud infrastructure provider — [name, country] | All data stored on the Platform | Technical operation |
| Email and notification service provider — [name, country] | Name, email address, content of the notification | Sending transactional and marketing messages |
| Analytics service provider — [name, country] | Pseudonymised usage data | Statistics and improvement — only after consent to analytics cookies |
| Advertising platforms and social networks — [name, country] | Pseudonymised identifiers and interaction data | Display and measurement of advertising — only within the scope of the consent given by you; they act as independent controllers for their own purposes |
| Fraud prevention service provider — [name, country] | Technical data, transaction data | Risk assessment |
| Competent authorities under Regulation (EU) 2024/1028 — for the Republic of Bulgaria, the Ministry of Tourism and/or the single digital entry point; for the Hellenic Republic, the competent authority and the Greek single digital entry point; for other Member States — the relevant national authority | Registration number, address, URL of the Listing, number of nights, number of guests, country of residence | Legal obligation |
| Ανεξάρτητη Αρχή Δημοσίων Εσόδων (Α.Α.Δ.Ε., the Greek Independent Authority for Public Revenue), Hellenic Republic | Data identifying Hosts of Greek Properties, upon request | Legal obligation — Article 111(7) of Greek Law 4446/2016; and automatic exchange under DAC7 through the National Revenue Agency |
| National Revenue Agency | Host data under DAC7 | Legal obligation |
| Law enforcement authorities, courts, supervisory authorities | The relevant data | Legal obligation or defence of rights |
| The other party to a dispute | Data from the dispute case file | So that it can submit its position and evidence — legitimate interest in an adversarial and objective examination of the dispute |
| External legal, accounting and audit advisers | The relevant data | Legitimate interest in professional advice and defence |
| An acquirer in the event of a corporate reorganisation or a transfer of the business | All data | Legitimate interests; we will notify you in advance |
4.2. Publicly visible information
The following are publicly visible on the Platform: your name (or part of it), your profile picture, your profile description, the reviews you have given and received, and the approximate location of the Property (for Hosts — the exact address is disclosed only after a confirmed booking).
Publicly visible information may be indexed by search engines. Reviews and other content you have shared may remain visible after the closure of your account, except where you request their erasure and there is no ground for retention.
4.3. Processors
We have concluded agreements under Article 28 GDPR with all providers that process personal data on our behalf, obliging them to process the data only on our instructions, to guarantee an appropriate level of security and not to engage sub-processors without our authorisation.
4.4. What we do not do
We do not sell personal data. Data is provided to advertising platforms only within the scope of the consent you have given to marketing cookies and that consent may be withdrawn at any time. We do not use the content of your messages for advertising purposes.
5. International transfers
(1) As a matter of principle we process data within the territory of the European Economic Area. Mollie B.V. is established in the Netherlands — no transfer outside the EEA takes place.
(2) Where an individual provider processes data outside the European Economic Area, we apply an appropriate mechanism under Chapter V of Regulation (EU) 2016/679 — an adequacy decision or Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914, accompanied by a transfer impact assessment and by supplementary technical measures, including encryption in transit and at rest and pseudonymisation. An up-to-date list of such providers and of the mechanisms applied is made available on request at [privacy@domain].
(3) We do not rely on the derogations under Article 49 GDPR as a general basis for systematic transfers. The derogations are applied only to occasional transfers, in accordance with EDPB Guidelines 2/2018.
(4) You have the right to obtain a copy of the safeguards applied — write to [privacy@domain].
6. Retention periods
(1) The specific periods are set out in the table in section 3.
(2) The general principles we apply are:
| Ground for retention | Period |
| Payroll records | 50 years — Article 12(1)(1) of the Accountancy Act |
| Accounting registers and financial statements | 10 years, counted from 1 January of the reporting period following the one to which they relate — Article 12(1)(2) of the Accountancy Act |
| Invoices and other primary accounting documents | Until expiry of the periods under Article 38 of the Tax and Social Insurance Procedure Code and Article 121 of the Value Added Tax Act |
| Tax documentation and DAC7 | 10 years and until expiry of the limitation periods under the Tax and Social Insurance Procedure Code |
| Contractual relationships and potential claims | 5 years — the general limitation period under Article 110 of the Obligations and Contracts Act |
| Traceability data on Business Hosts | 6 months after termination of the relationship — Article 30 of Regulation (EU) 2022/2065 |
| Security logs | 12 months |
| Records of communications with customer support | 3 years; call recordings — 30 days |
| Record of cookie consent | 24 months |
| Record of the withdrawal of marketing consent | 5 years |
| Reports under Regulation (EU) 2024/1028 | 24 months from transmission, in order to demonstrate compliance |
| Tax and accounting documentation for Properties in the Hellenic Republic | 10 years |
| Data processed on the basis of consent | Until withdrawal of consent |
(2a) Closing your account. When you delete your account we erase your profile (name, photo, description, contact details, log-in data, saved payment cards, payout bank details, identity-verification data, messages, device history, saved places, notifications and preferences). Bookings, payments and the related accounting records are retained for the periods above in pseudonymised form (no longer linked to your name or e-mail) because we are legally obliged to keep them, and may be used in that form for statistical and research purposes (Article 89 GDPR). Reviews remain visible under "Former guest". A Host's Listings are deactivated and kept without the street address and exact location. You cannot delete your account while you have a current or future booking (as Guest or Host) or earnings not yet paid out — complete or cancel them first.
(3) Upon expiry of the period the data is erased or irreversibly anonymised. Back-ups are overwritten according to an established schedule and are erased no later than 90 days after erasure in the production environment.
(4) Where a dispute, proceedings or investigation is pending, we retain the relevant data until its final conclusion, irrespective of the periods indicated above.
7. Your rights
Under Regulation (EU) 2016/679 you have the following rights:
| Right | Article | What it means |
| Access | Article 15 | To obtain confirmation as to whether we process your data, a copy of it and information about the processing |
| Rectification | Article 16 | To request the correction of inaccurate data and the completion of incomplete data |
| Erasure ("right to be forgotten") | Article 17 | To request erasure where the data is no longer necessary, you have withdrawn your consent, you have objected on justified grounds, or the processing is unlawful |
| Restriction of processing | Article 18 | To request the temporary suspension of the processing while the accuracy of the data or the merits of an objection are verified |
| Data portability | Article 20 | To receive the data you have provided to us in a structured, commonly used and machine-readable format and to transmit it to another controller |
| Objection | Article 21 | To object to processing based on legitimate interests. You may object to direct marketing at any time and the processing is then discontinued unconditionally. |
| Withdrawal of consent | Article 7(3) | To withdraw a consent given at any time, without this affecting the lawfulness of processing carried out before the withdrawal |
| Human intervention in automated decision-making | Article 22(3) | See section 8 |
| Complaint to a supervisory authority | Article 77 | See section 12 |
7.1. How to exercise your rights
(1) Through your profile settings — for access, rectification, downloading your data and managing your consents.
(2) By a written request to [privacy@domain] or to the address [postal address].
(3) In order to protect your data, we may request additional information to confirm your identity. We do not request more data than is necessary for identification.
(4) We respond within one month of receipt of the request. Where the request is complex or where a large number of requests is received, that period may be extended by a further two months, and we will inform you of the extension and of the reasons for it within the first month.
(5) The exercise of your rights is free of charge. Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, we may charge a reasonable fee or refuse to act, giving reasons for the refusal.
(6) If we refuse to comply with a request, we state the grounds and inform you of your right to lodge a complaint with the CPDP and of your right to an effective judicial remedy.
8. Automated decision-making and profiling
8.1. Profiling without legal effects
We use profiling for: the ranking and recommendation of Listings (purposes L and M); and fraud risk scoring (purpose I). These processes do not in themselves produce legal effects concerning you.
8.2. Automated decisions with legal or similarly significant effects
(1) In limited cases automated systems may restrict or suspend your access to the Platform, block a transaction or decline a booking where they detect conduct indicating fraud, a compromised account or a safety risk.
(2) Logic involved: the system analyses a combination of signals — the correspondence between the payment data and the account data, the speed and sequence of actions, matches with known fraud patterns, account history, technical characteristics of the device and the connection, and alerts from our fraud prevention provider. Each signal carries a weight and, where a defined threshold is exceeded, a measure is triggered.
(3) Significance and envisaged consequences: the possible consequences are the refusal of a specific transaction, the temporary restriction of access to certain functionalities, the suspension of the account or a refusal to publish a Listing. These measures may prevent you from completing a booking or, in the case of Hosts, from receiving a Payout.
(4) Your rights under Article 22(3) GDPR. You have the right to:
request human intervention on our part;
express your point of view and provide additional information;
contest the decision.
You exercise these rights via [privacy@domain] or through the internal complaint-handling system at [link]. We examine the request without automated means and issue a reasoned decision within 14 days.
(5) Automated decisions are not based on special categories of personal data within the meaning of Article 9 GDPR.
8.3. Artificial intelligence
(1) We use artificial intelligence systems for the ranking and recommendation of Listings and for the automated detection of fraud and abuse.
(2) The Platform does not provide an automated assistant (chatbot) and does not publish content generated wholly or partly by artificial intelligence, including automatic translation. If such functionality is introduced, you will be informed before the beginning of any conversation with an automated assistant and will be able to request to be transferred to a human, and the generated content will be labelled as such.
(3) We use your personal data for the development and improvement of artificial intelligence models only after your consent (purpose P). You may opt out or withdraw your consent from your profile settings at [link], without this restricting your use of the Platform.
9. Security
(1) We implement appropriate technical and organisational measures under Article 32 GDPR, including: encryption in transit (TLS) and encryption of sensitive data at rest; hashing of passwords; access control on a need-to-know basis; multi-factor authentication for administrative access; logging of access to personal data; regular back-ups; vulnerability and patch management; and staff training.
(2) We do not store full payment card data. It is processed directly by Mollie in accordance with the PCI DSS standard.
(3) In the event of a personal data breach resulting in a high risk to your rights and freedoms, we will notify you without undue delay and will notify the CPDP within 72 hours of becoming aware of it, in accordance with Articles 33 and 34 GDPR.
10. Children's data
(1) The Platform is not intended for persons under 18 years of age and we do not knowingly collect the data of such persons for registration purposes.
(2) Data concerning minors may be processed only as part of a booking made by an adult — and then only to a minimal extent (name and age, where necessary for the accommodation).
(3) If we establish that we have registered an account of a person under 18 years of age in breach of paragraph 1, we close the account and erase the data. This does not affect the processing under paragraph 2. If you believe that we hold such data, write to [privacy@domain].
11. Cookies and similar technologies
(1) The use of cookies, local storage, pixels and similar technologies is governed by the separate Cookie Policy — /legal/cookies-policy.
(2) We apply prior consent (opt-in) for all technologies that are not strictly necessary for the provision of the service explicitly requested by you. The requirement follows from Article 5(3) of Directive 2002/58/EC as amended by Directive 2009/136/EC and from Article 4(11) and Article 6(1)(a) of Regulation (EU) 2016/679. Article 4a of the Bulgarian E-Commerce Act governs the national regime, and the Platform applies the higher standard of consent.
(3) Consent is given granularly, per purpose, through equally prominent options to accept and to refuse, and may be withdrawn at any time as easily as it was given.
12. Right to lodge a complaint
(1) If you consider that the processing of your personal data infringes the law, you have the right to lodge a complaint with:
the Bulgarian Commission for Personal Data Protection (CPDP)
Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd.
Telephone: 02/915 3518
Email: kzld@cpdp.bg
Website: www.cpdp.bg
If your habitual residence is in the Hellenic Republic, or the infringement relates to a Property located there, you may also lodge a complaint with:
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (the Hellenic Data Protection Authority)
Κηφισίας 1-3, 115 23 Αθήνα, Ελλάδα (Kifisias 1-3, 115 23 Athens, Greece)
Telephone: +30 210 6475600
Email: contact@dpa.gr
Website: www.dpa.gr
(2) You also have the right to lodge a complaint with the supervisory authority of your habitual residence or of the place of the alleged infringement.
(3) You also have the right to an effective judicial remedy against a decision of a supervisory authority and against a controller or processor (Articles 78 and 79 GDPR).
(4) Before doing so, we would be glad to look into the matter — write to us at [privacy@domain].
13. Amendments to the Policy
(1) We may amend this Policy. The current version is always available at [link], with the date indicated.
(2) In the event of material amendments — affecting the purposes, the legal bases, the categories of recipients or the retention periods — we will notify you by email at least 30 days before they enter into force.
(3) Where an amendment requires new consent, we will request it from you explicitly. Without consent, processing on the relevant basis does not take place.
(4) Archive of previous versions: [link].