Privacy policy
The data controller is Hotel SOFIA, 16 Radon Todev Street, 2770 Bansko, Bulgaria, email sofiahotel2025@abv.bg.
1. What we collect
When you book through the site: country, first name, last name, email, phone, dates and party of the stay, chosen extras, children's ages and any notes you leave. At check-in: the identity document data required by the Bulgarian Tourism Act for the guest register. When you call or write: the data you give us.
2. What we use it for
To fulfil your booking and stay (performance of a contract), to send you the confirmation and stay information, to meet our legal registration and accounting duties, and to answer your enquiries. We do not send marketing messages without your consent.
3. Who has access
The data is processed by the hotel team and by the providers that run the website, the booking system and the email delivery, on our instructions only. Guest register data is passed to the authorities as the law requires. We do not sell or share data with third parties for their own purposes.
4. How long we keep it
Booking data is kept for 5 years after the stay for accounting requirements; guest register data for the period set by law. Enquiries without a booking are deleted within 12 months.
5. Cookies
The site uses only the strictly necessary cookie for the administrator's session. We use no tracking or advertising cookies. The embedded map on the Contact page is loaded from Google and may set its own cookies under Google's policy.
6. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (www.cpdp.bg). To exercise your rights, write to sofiahotel2025@abv.bg.
7. Changes
The current version of this policy is always on this page. Last updated: 1 October 2026.
