Privacy Policy

1. General information

This Privacy Policy aims to inform visitors and customers of the Blyan Family Hotel website about the way in which their personal data is collected, processed and stored.

The personal data administrator is:

Blyanika OOD
UIC: 110545479
Head office and address of management: Chiflik village, Villa zone, Bulgaria
Represented by: Biser Bonchevski – Manager

By using this website, you agree to the terms described in this policy.


2. What personal data do we collect?

Depending on how you use the site, we may collect the following categories of data:

Data provided voluntarily by the user:

  • First and last name;

  • Phone number;

  • Email address;

  • Data provided through contact forms;

  • Data provided upon booking;

  • Data provided when ordering products or vouchers.

Data collected automatically:

  • IP address;

  • Device type;

  • Internet browser;

  • Operating system;

  • Visited pages;

  • Time spent on the site;

  • Source of the visit.


3. Purposes of processing

Personal data is processed for the following purposes:

  • Making reservations;

  • Processing orders in the online store;

  • Issuance and administration of gift vouchers;

  • Responding to customer inquiries;

  • Sending information related to orders placed;

  • Fulfillment of legal obligations;

  • Improving the quality of services;

  • User behavior analysis and site optimization.


4. Legal basis for processing

The processing of personal data is carried out on the basis of:

  • Explicit consent of the user;

  • Performance of a contract or taking steps prior to entering into a contract;

  • Legal obligations of the administrator;

  • Legitimate interest of the administrator to improve the services offered.


5. Online reservations and orders

The site offers the opportunity to:

  • Online reservations through Quendoo platform;

  • Purchase vouchers and services through the online store.

When using these functionalities, data necessary to process the relevant reservation or order may be collected.


6. Payments

To process online payments, the site uses certified payment solutions through:

  • BORICA Payments;

  • Virtual POS terminals;

  • Banks transfer through the reservationnata system Quendoo.

The site does not store bank card data.

All card data is processed directly by the relevant payment operator in compliance with applicable security standards.


7. External providers and systems used

To provide its services, the site uses the following external systems:

  • Quendoo – online reservation system;

  • BORICA Payments – electronic payment processing;

  • Google Analytics – traffic analysis;

  • Google Tag Manager – management of analytical and marketing tools;

  • Meta Pixel (Facebook Pixel) – marketing analysis;

  • GoHighLevel Chat – online communication with customers;

  • SMTP services for sending system messages and emails;

  • WPML – multilingual content management.

These providers may process a limited amount of information solely for the purposes of providing the relevant service.


8. Cookies

The site uses cookies to improve user experience, traffic analysis and marketing purposes.

The following categories are used:

Necessary cookies

They ensure the normal functioning of the site.

Analytical cookies

They are used to measure attendance and user behavior.

Marketing cookies

They are used to measure the effectiveness of advertising campaigns.

Functional cookies

They improve the performance of the site and remember user preferences.

Users can manage their consent through the cookie banner settings.


9. Storage periods

Personal data is stored for a period necessary to fulfill the relevant purpose:

  • Данни от контактни форми – до 12 месеца;

  • Reservation and order data – up to 5 years;

  • Data related to accounting documents – in accordance with applicable legislation;

  • Data from analytical systems – according to the deadlines of the relevant platforms.

After the applicable deadlines have expired, the information is deleted or anonymized.


10. Data protection

The protection of personal data is ensured through:

  • HTTPS encrypted connection;

  • SSL certificate;

  • Limited administrative access;

  • Regular system updates;

  • Technical measures to protect against unauthorized access;

  • Measures to protect against common web attacks.


11. Rights of data subjects

Every user has the right:

  • To receive information about the personal data being processed;

  • To request correction of inaccurate data;

  • To request deletion of personal data;

  • To request restriction of processing;

  • To object to processing;

  • To receive a copy of your personal data;

  • To file a complaint with the Personal Data Protection Commission.


12. Contact

If you have any questions regarding the processing of personal data, you can contact us via the contacts published on the site.


13. Policy update

This policy may be updated in the event of changes in legislation, technologies used or services offered.

We recommend that you periodically review its contents for information regarding any changes.