Privacy Policy
“HUS Estate” Ltd. develops and implements the residential complex “Antea Beach Resort”, a front-line project on the Southern Black Sea coast, created with regard for people who seek a quality life, tranquillity and nature. Within the framework of this activity, the Company comes into contact with potential buyers, partners and visitors of the website and, in this connection, processes certain personal data. This Privacy Policy has been prepared in fulfilment of the obligations under Regulation (EU) 2016/679 (GDPR) and is intended to inform You clearly and understandably about what data we collect, for what purpose, on what legal basis and for what period we store it. We collect solely the data that we actually need, no more. We do not sell personal data to third parties and do not use it for purposes outside those expressly described in this document. The Policy applies to all processing operations carried out through the website of “Antea Beach Resort”, including through the contact form, the subscription for marketing communications and the automatically collected technical data upon a visit to the site. For questions related to the processing of Your personal data, You can contact us at any time at sales@antearesort.com, we respond within a period of up to one working day. We recommend that You read this Policy carefully before using the functionalities of the website.
Section I - Personal data controller and contact details
1.1 Identification of the Controller
The personal data controller within the meaning of Regulation (EU) 2016/679 (GDPR) is “HUS Estate” Ltd., entered in the Commercial Register at the Registry Agency under UIC 204946740, VAT number BG204946740, with registered office and address of management: city of Plovdiv, “Yuzhen” district, Okolovrasten pat, Baza Hus.
1.2 Contact details
For questions related to the processing of personal data, data subjects may contact the Controller at the following electronic address: sales@antearesort.com.
The appointment of a data protection officer (DPO) is not mandatory for the Controller, given the nature and scale of the activity it carries out, since the processing does not fall within the situations under Article 37, paragraph 1 of the GDPR.
Section II - Categories of personal data
2.1 Data provided by the subject
The Controller treats as personal data any information that identifies a specific natural person or that relates to a natural person through which the latter can be identified. The processing of personal data represents an action or a set of actions that may be carried out with regard to personal data by automatic or other means.
Through the contact form of the website, “HUS Estate” Ltd. collects the following personal data, provided voluntarily by the subject:
- Two names - for the purpose of identification during the communication;
- Electronic address - for sending a response to the enquiry and, where consent is given, for marketing communications;
- Telephone number - for feedback where additional clarification is needed.
The provision of the data is voluntary. The failure to provide the mandatory fields (names and electronic address) makes it impossible to review the specific enquiry. The failure to provide a telephone number does not affect the review of the enquiry.
Upon a request for downloading information materials (brochures, plans, price lists), the Controller may collect names and an electronic address for the purpose of sending the requested content and subsequent contact on the enquiry. The legal basis is the legitimate interest of the Controller under Article 6, paragraph 1, letter “f” of the GDPR for managing an expressed interest in the project. The data is stored for a period of up to 2 years from the last contact.
When the data subject has marked an express tick for marketing consent, the data provided is also used for the purposes under item 3.1. In the absence of such a tick, the data is processed solely for the purposes under item 3.2.
2.2 Data collected automatically
Upon a visit to the website, the automatic collection of technical data is possible, the IP address, type and version of the browser, operating system and pages loaded during the session. This data is collected through cookies and similar technologies, for more information regarding which data subjects should familiarise themselves with the Cookie Policy of the site.
2.3 Special categories of data
The Controller does not collect and does not process special categories of personal data within the meaning of Article 9 of the GDPR, such as data on health condition, ethnic origin, political views or biometric data.
2.4 Data of children
The website is intended solely for persons who have reached the age of 18. “HUS Estate” Ltd. does not knowingly collect personal data of minors. Upon establishing that data of a person under the age of 18 has been collected without the knowledge of a parent or legal guardian, the Controller deletes this data immediately.
Section III - Purposes and legal bases for processing
3.1 Processing on the basis of consent
When the data subject has provided express consent through the contact form, “HUS Estate” Ltd. processes their personal data for sending marketing communications regarding current and upcoming projects, news and invitations to events. The communications are sent by electronic mail and/or through Viber communications to the telephone number provided. The legal basis is Article 6, paragraph 1, letter “a” of the GDPR. The consent is voluntary, may be withdrawn at any time in accordance with item 12.1 and is not a condition for reviewing the enquiry made.
3.2 Processing of enquiries through the contact form
The data provided through the contact form is processed for the purpose of managing incoming business enquiries. The legal basis is Article 6, paragraph 1, letter “f” of the GDPR. The processing in this case covers solely the data necessary for carrying out the requested communication. The legitimate interest is expressed in the receipt and processing of incoming enquiries from persons who have shown an active interest in acquiring a property.
3.3 Processing for compliance with a legal obligation
In certain cases, the Controller may be obliged to process personal data for the fulfilment of statutory obligations, accounting, tax or those arising from orders of competent authorities. The legal basis in these cases is Article 6, paragraph 1, letter “c” of the GDPR.
3.4 Processing on the basis of legitimate interest
The Controller may also process personal data on the basis of legitimate interest within the meaning of Article 6, paragraph 1, letter “f” of the GDPR, for example for the protection of its rights and interests in the event of possible legal claims, for improving the functionality of the website or for ensuring the security of its information systems. With each reliance on this basis, the Controller carries out a prior assessment of whether its interest does not override the rights and freedoms of the data subjects. The legitimate interest is expressed in the protection of the Company in the event of legal claims and in ensuring the technical security of the information systems.
3.5 Limitation of the purposes
Personal data is processed solely for the purposes for which it was collected. Where a need arises for processing for a new, incompatible purpose, the Controller will inform the data subject and, where applicable, will request new consent before commencing such processing.
4.1 Absence of automated decision-making
“HUS Estate” Ltd. does not apply automated decision-making within the meaning of Article 22, paragraph 1 of the GDPR, that is, decisions based solely on automated processing and producing legal consequences for the subject or significantly affecting them. All decisions related to the processing of data of potential clients are made by natural persons.
5.1 Profiling for remarketing purposes
Where express consent for marketing cookies is present, “HUS Estate” Ltd. uses the technologies Meta Pixel (operator: Meta Platforms Ireland Ltd.) and Google Ads (operator: Google LLC) for displaying personalised advertising communications to persons who have visited the website, so-called remarketing. This activity constitutes profiling within the meaning of Article 4, item 4 of the GDPR, since it includes the automated processing of data on the behaviour of the user for the purpose of assessing and predicting their preferences and interests.
Profiling for remarketing purposes:
- is carried out solely on the basis of express consent under Article 6, paragraph 1, letter “a” of the GDPR, provided through the cookie management tool upon the first visit to the website;
- does not produce legal consequences for the subject and does not affect their access to the website or to any content;
- may be terminated at any time through the withdrawal of consent for marketing cookies or directly through the settings of the advertising platform.
Detailed information about the cookies used and the consent management mechanism is contained in the Cookie Policy, available on the website.
Section IV - Recipients of personal data. International transfers of personal data.
6.1 Categories of recipients
The Controller may provide personal data to third parties solely in the cases and under the conditions provided for in this Policy or in the applicable legislation. The recipients of personal data are carefully selected and bound by appropriate contractual guarantees for data protection.
6.2 Affiliated companies
Within the group of companies to which the Controller belongs, the sharing of personal data with affiliated legal entities for internal organisational and administrative purposes is possible, insofar as this is necessary and proportionate to the pursued purpose. The legal basis for such transfer is the legitimate interest of the Controller under Article 6, paragraph 1, letter “f” of the GDPR for internal administrative coordination within the group. This transfer is carried out in compliance with the applicable requirements for personal data protection.
6.3 Personal data processors
For carrying out its activity, the Controller uses the services of external providers acting in the capacity of personal data processors within the meaning of Article 28 of the GDPR, such as: providers of email marketing tools, web hosting services and web analytics tools. These companies process personal data solely on the instruction of the Controller and are not entitled to use it for their own purposes.
6.4 Public authorities and institutions
In the presence of a legal obligation or by order of a competent state authority, such as: a court, prosecutor’s office, Commission for Personal Data Protection or another institution, the Controller may provide personal data without prior notification of the data subject, insofar as the applicable law requires or permits this.
7.1 International transfers of data
Some of the service providers with which “HUS Estate” Ltd. works process personal data on servers physically located outside the territory of the European Economic Area (EEA). The transfer of data to these providers is carried out in the presence of appropriate guarantees under Chapter V of the GDPR, described in the table below.
The standard contractual clauses (SCC) are approved by the European Commission as an appropriate mechanism for ensuring an equivalent level of data protection upon its transfer to third countries.
7.2 Transfer of data collected from cookies
The transfer of data to Google LLC and Meta Platforms Ireland Ltd. is carried out solely where express consent of the subject for analytical and/or marketing cookies has been provided in accordance with the Cookie Policy. Where consent has not been provided, the data does not leave the EEA.
Section V - Storage periods. Data security.
8.1 General principle
The Controller stores personal data for a period no longer than necessary for achieving the purposes for which it was collected, unless the applicable legislation provides for a longer mandatory storage period.
8.2 Data processed on the basis of consent
Personal data collected for marketing purposes on the basis of consent is stored until the moment of withdrawal of consent on the part of the data subject. After the withdrawal of consent, contacts for marketing purposes are terminated immediately, and the data is deleted or anonymised within a period of up to 30 days, unless another legal basis exists for continuing the processing. The record of the consent given and withdrawn is stored separately for a period of 2 years in accordance with item 12.1, for the purpose of proving the lawfulness of the processing.
8.3 Data processed for pre-contractual and contractual purposes
The data provided in connection with an enquiry made or pre-contractual communication is stored for a period of up to 2 years from the last contact, unless a contract has been concluded, in which case the applicable contractual and statutory periods take precedence.
8.4 Data stored by virtue of a legal obligation
When the processing of personal data is necessary for the fulfilment of accounting, tax or other statutory obligations, the data is stored for the periods provided for in the applicable legislation, namely up to 10 years for accounting registers and financial statements within the meaning of Article 12, paragraph 1 of the Accountancy Act, respectively up to 5 years for receivables within the meaning of Article 110 of the Obligations and Contracts Act.
8.5 Technical data and data from cookies
The technical data collected automatically upon a visit to the website (IP address, browser type, operating system, pages visited) is stored for a period of up to 90 days from the date of its collection, after which it is deleted automatically or anonymised. The analytical data processed through Google Analytics is stored for a period configured by the Controller within the platform, but no longer than 14 months, after which it is aggregated and deleted by Google LLC.
8.6 Deletion and anonymisation
After the expiry of the applicable storage period, the personal data is deleted in a secure manner or anonymised in such a way that the identification of the data subject becomes impossible. The Controller undertakes periodic reviews of the stored data for the purpose of ensuring compliance with the principle of storage limitation.
9.1 General approach to data security
“HUS Estate” Ltd. applies appropriate technical and organisational measures for the protection of personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, in accordance with Article 32 of the GDPR. The choice and scope of the measures are determined on the basis of an assessment of the risks, taking into account the nature, scope, context and purposes of the processing, as well as the probability and severity of possible risks to the rights and freedoms of the subjects.
9.2 Technical measures
From a technical point of view, the Controller applies, without the enumeration being exhaustive:
- Encryption of the data upon transfer by means of the TLS protocol (HTTPS) for all communications between the browser of the user and the website;
- Restricted access to the personal data, solely authorised persons with an operational need have access to it;
- Pseudonymisation and/or aggregation of the analytical data collected through Google Analytics, by means of an activated function for shortening the IP address;
- Regular backup of the data for the purpose of ensuring its availability and integrity;
- Maintenance of up-to-date antivirus and firewall protection of the infrastructure.
9.3 Organisational measures
From an organisational point of view, the Controller applies:
- Internal rules and procedures for working with personal data, binding on all persons with access to it;
- Contractual confidentiality obligations with all employees and processors having access to personal data;
- Periodic review of the applied security measures for the purpose of establishing and removing weaknesses;
- Inclusion of data security requirements in the contracts with all processors within the meaning of Article 28 of the GDPR.
10.1 Notification in the event of a security breach
Upon establishing a breach of the security of personal data, “HUS Estate” Ltd. notifies the Commission for Personal Data Protection within a period of up to 72 hours from becoming aware of the breach, where it is likely to result in a risk to the rights and freedoms of natural persons, in accordance with Article 33 of the GDPR. When the breach is likely to give rise to a high risk to the rights and freedoms of the affected persons, the Controller also notifies the data subjects themselves without undue delay, in accordance with Article 34 of the GDPR, describing the nature of the breach, the categories of affected data and the recommended protective measures.
10.2 Register in the event of security breaches
All security breaches, regardless of their severity, are documented internally in accordance with Article 33, paragraph 5 of the GDPR.
Section VI - Rights of data subjects and mechanism for their exercise
11.1 Rights of data subjects
Every natural person whose personal data is processed by the Controller has the following rights under the GDPR:
- Right of access - to receive confirmation of whether their personal data is being processed and access to it;
- Right to rectification - to request the rectification of inaccurate or incomplete data;
- Right to erasure - to request the erasure of their personal data where a ground under Article 17 of the GDPR is present;
- Right to restriction of processing - to request the temporary suspension of the processing under the conditions of Article 18 of the GDPR;
- Right to portability - to receive their data in a structured, commonly used and machine-readable format;
- Right to object - to object to processing based on legitimate interest, including for the purposes of direct marketing;
- Right to withdraw consent - to withdraw the consent given at any time, without this affecting the lawfulness of the processing prior to the withdrawal.
11.2 Mechanism for the exercise of the rights
Data subjects may exercise their rights by sending a written request to the electronic address sales@antearesort.com. The Controller reviews the requests received and provides a response within a period of up to one month from their receipt. In case of factual complexity or a large number of requests, this period may be extended by a further two months, of which the data subject is expressly notified within the initial one-month period.
11.3 Establishment of identity upon the exercise of rights
In the event of a reasonable doubt regarding the identity of the person who submitted the request, the Controller may request the provision of additional information, necessary solely for confirming the identity, in accordance with Article 12, paragraph 6 of the GDPR.
11.4 Free exercise of the rights
The exercise of the rights is free of charge. The Controller reserves the right to refuse to take action on manifestly unfounded or excessive requests, or to charge a reasonable fee, taking into account the administrative costs of processing them, within the meaning of Article 12, paragraph 5 of the GDPR.
11.5 Applicability of the right to portability
The right to portability under item 11.5 is applicable solely to data processed on the basis of consent or a contract and by automated means. It does not apply to data processed on the basis of legitimate interest.
12.1 Absolute right to object to direct marketing
The data subject has an absolute and unconditional right at any time to object to the processing of their personal data for the purposes of direct marketing, including against profiling, insofar as it is related to direct marketing, in accordance with Article 21, paragraph 2 of the GDPR. Upon the submission of such an objection, “HUS Estate” Ltd. terminates the processing for this purpose immediately and without exceptions, the Controller may not rely on any ground for refusal.
Unsubscribing from marketing communications may be carried out in one of the following ways:
- Through the “Unsubscribe” link placed at the end of each marketing communication sent;
- Through a written request to the electronic address sales@antearesort.com.
The unsubscription takes effect within a period of up to 3 working days from the receipt of the request. The record of the consent given and withdrawn is stored for a period of 2 years for the purpose of proving the lawfulness of the previous processing.
13.1 Right to complaint
Every data subject has the right to file a complaint with the competent supervisory authority, if they consider that the processing of their personal data violates the provisions of the GDPR or the applicable national legislation. This right may be exercised at any time and is not bound by the prior submission of a request to the Controller.
13.2 Competent supervisory authority
The competent supervisory authority for the territory of the Republic of Bulgaria is the Commission for Personal Data Protection (CPDP). A complaint or signal may be submitted in one of the following ways:
- In person on paper - at the registry of the CPDP at the address: city of Sofia 1592, “Prof. Tsvetan Lazarov” Blvd. No. 2.
- By letter - to the address: city of Sofia 1592, “Prof. Tsvetan Lazarov” Blvd. No. 2, Commission for Personal Data Protection.
- To the electronic mail of the CPDP - kzld@cpdp.bg. Upon the submission of a complaint in this manner, it must be formatted as an electronic document signed with a qualified electronic signature (QES). Complaints that are scanned or photographed and submitted to the electronic mail, but not signed with a QES, are not reviewed by the CPDP.
- Through the Secure Electronic Delivery System, maintained by the State e-Government Agency - https://edelivery.egov.bg.
13.3 Prior referral to the Controller
Before the submission of a complaint to the CPDP, the Controller encourages data subjects to contact it at the address sales@antearesort.com for the purpose of finding a quick and mutually beneficial solution. This is not a mandatory condition and does not in any way limit the right to complaint to the supervisory authority.
14.1 Right to judicial protection
Regardless of the possibility of filing a complaint with the CPDP, data subjects have the right to effective judicial protection against the Controller, if they consider that their rights under the GDPR have been violated as a result of the processing of their personal data in non-compliance with the applicable legislation.
Section VII - Cookies. Changes in the Privacy Policy. Final provisions.
15.1. Use of cookies
Upon a visit to the Site, cookies and similar tracking technologies are used. Detailed information regarding the types of cookies, their specific names, their providers and the exact storage periods is contained in the separate Cookie Policy of the Controller, available on the Site. This section governs solely the principles and mechanisms for managing consent.
15.2. Consent management software (CMP)
The Controller uses the CookieScript platform as a consent management system (CMP) within the meaning of Article 2, item 14 of this Policy. Through it, the data subject exercises detailed control over the cookies loaded upon a visit to the Site, by categories, before any processing has commenced. The cookies requiring consent are not loaded until the moment of its express provision.
15.3. Differentiated consent for individual categories of cookies in view of their purposes
Consent is provided separately for each category of cookies, other than those strictly necessary for the functioning of the Site. The Controller does not receive aggregated or bundled consent for all categories simultaneously. The failure to provide consent for analytical or marketing cookies does not limit the access of the subject to the Site or to any of its content.
16.1 Right to amendment
The Controller reserves the right to update and amend this Privacy Policy at any time, upon a change in the applicable legislation, in the nature of the processed data or in the technologies and services used. The current version of the policy is available at any time on the website of the Controller.
16.2 Notification in the event of substantial changes
Upon making substantial changes that may affect the rights or interests of data subjects, the Controller will make reasonable efforts to notify the affected persons by electronic means or through a visible notice on the website before the entry into force of the changes.
16.3 Date of entry into force
Each updated version of this policy enters into force from the date of its publication on the website, unless another date is expressly indicated. We recommend that data subjects periodically review the policy in order to be informed of the manner in which the Controller protects their personal data.
17.1 Applicable law
This Privacy Policy is interpreted and applied in accordance with Regulation (EU) 2016/679 (GDPR), the Personal Data Protection Act of the Republic of Bulgaria and the remaining applicable European and national legislation in the field of personal data protection.