Controller
The data controller is KALPACITE EOOD, UIC 204422620, VAT number BG204422620, registered address: Bulgaria, Gotse Delchev 2900, 1 Hristo Silyanov St., entrance A. The company is represented by its manager Vasil Dimitrov Orakov. For privacy questions, contact us at kalpacite@gmail.com or +359 897 459 208.
Merchant Details
KALPACITE EOOD is a single-member limited liability company registered on 24 January 2017, with main economic activity 55.10 - hotels and similar accommodation. kalpacite.com is used to present Kalpacite guest houses and receive enquiries and booking requests.
Data We Collect
For bookings or enquiries we may process name, phone, email, stay dates, guest count, selected rooms, stay notes and booking source information. The admin system may also store operational notes, booking statuses and payment information.
Categories Of Personal Data
We may process identification data such as first and last name; contact data such as phone and email; stay data such as arrival date, departure date, adults, children and selected rooms; technical data such as IP address, device, browser and language preference where needed for security, statistics or cookies; communication data from messages, notes and special requests; financial and operational data such as deposit, payment status, booking source, Gifto/Makaroon voucher partner and internal notes.
Legal Bases
Processing is based on contract performance or steps before entering into a contract for bookings; legal obligations for accounting, tax and registration requirements; legitimate interest for protecting company rights, managing availability, preventing abuse and improving the service; consent for optional marketing and analytics cookies or marketing communication where requested.
Purpose
We use this data to process and confirm bookings, check room availability, communicate with guests, provide the stay, process partner vouchers, administer payments and deposits, issue and retain accounting documents, manage enquiries, improve the website, measure campaigns after consent and protect our rights in disputes or misuse.
Encryption And Security
Personal data in the booking and admin system is stored with application-level encryption for sensitive fields. Names, phone numbers, emails, notes and internal notes are encrypted before database storage using AES-256-GCM and decrypted only when legitimately needed in the admin panel. Admin access is restricted through sessions with HttpOnly cookies, SameSite=Strict, automatic idle expiry and access permissions. No system can guarantee absolute security, and in case of an incident we will take the necessary actions under applicable law.
Recipients
Data may be accessed by the manager and authorised staff handling bookings; accountants, legal and technical providers; hosting, email and analytics providers; partners such as Gifto or Makaroon only when the guest requests a booking using such a voucher; public authorities where required by law.
International Transfers
If we use providers outside the European Economic Area, transfers will rely on an applicable safeguard such as an adequacy decision, standard contractual clauses or another valid GDPR mechanism.
Cookies And Analytics
The website uses necessary cookies for normal operation, security, language preferences and storing your cookie choice. Analytics and marketing cookies are used only after consent to measure visits, campaign effectiveness and interest in offers. You can decline optional cookies from the banner or delete them from your browser.
Marketing Emails And Unsubscribe
Marketing emails are sent only where there is an appropriate basis, such as consent or another permitted communication with a guest. Every marketing or follow-up email includes a clear unsubscribe button. After unsubscribing, the email address is stored in a suppression list so it is not used for future marketing messages.
Retention
We keep data for as long as needed for the booking, guest communication, statutory accounting and tax periods, defence of claims and legitimate business needs. Unconfirmed enquiry data may be kept for a shorter period, while data related to actual bookings and accounting documents may be kept for legally required periods. Afterwards, data is deleted, securely archived or anonymised where applicable.
Your Rights
You may request access, correction, deletion, restriction, objection, portability, withdrawal of consent for future processing and lodge a complaint with the Bulgarian data protection authority. To exercise rights, contact kalpacite@gmail.com. We may request additional information to verify identity before acting on a request.
Children's Data
We do not knowingly collect data from children through the website without a parent or legal guardian. Where a booking states the number of children, this is used only to organise capacity and the stay.