Burja Hoteli d.o.o. (“Burja Hoteli“, “we“, “our” or “us“) respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains how we collect, use, disclose and protect your personal data whenever you:
This Privacy Policy applies to all accommodation properties operated by Burja Hoteli d.o.o., including:
Please read this Privacy Policy carefully before using our services.
The controller responsible for processing your personal data is:
Burja Hoteli d.o.o.
Bonifacijeva ulica 11, 6330 Piran – Pirano
Company Registration Number: 3707296000
VAT Number: SI84255595
Email: info@burjahotels.com (or info@vilalipa.com)
General inquiries: info@burjahotels.com
Telephone: 00386 31 491 929
If you have any questions regarding this Privacy Policy or the processing of your personal data, you may contact us at any time.
We process personal data in accordance with:
Whenever we process personal data, we follow the GDPR principles of:
We only collect personal data that is necessary for the purposes described in this Privacy Policy.
Depending on the services you use, we may collect the following categories of personal data.
These data are required for guest registration under Slovenian legislation.
Depending on the booking method, payment information may be processed by certified payment service providers such as Stripe or Bankart.
Burja Hoteli does not store complete payment card numbers or CVV/CVC security codes on its own servers.
If you use our online check-in platform (GuestPortal.si), we may collect:
When you visit our websites we may automatically collect:
This information is collected through cookies and Google Analytics 4 where consent has been provided where required.
Some of our properties are protected by CCTV systems for the purposes of:
Information about CCTV monitoring is displayed at the monitored premises in accordance with Slovenian legislation.
We collect personal data:
For example when you:
If you book through third-party booking platforms, such as:
we receive personal data necessary to manage your reservation.
The exact data shared depends on the booking platform and your privacy settings with that provider.
Certain technical information is collected automatically through cookies, server logs and analytics technologies while using our websites.
In limited circumstances, we may receive or disclose information where required by law, including requests from competent Slovenian authorities.
We process personal data only where one or more of the legal bases under Article 6 GDPR apply.
We process personal data in order to:
We process personal data where required by law, including:
Providing this information is mandatory where required by applicable legislation.
Failure to provide legally required information may prevent us from providing accommodation services.
We process personal data only for specified, explicit and legitimate purposes.
The table below summarises the main processing activities carried out by Burja Hoteli.
| Purpose | Categories of Personal Data | Legal Basis |
|---|---|---|
| Managing reservations | Identification, contact and reservation data | Performance of a contract |
| Providing accommodation services | Identification, reservation and communication data | Performance of a contract |
| Online check-in | Identification and legally required registration data | Performance of a contract and legal obligation |
| Guest registration through the Slovenian eTurizem system | Identification data required by Slovenian legislation | Legal obligation |
| Issuing invoices and processing payments | Identification and payment data | Legal obligation and performance of a contract |
| Customer communication | Contact information and communication history | Performance of a contract or legitimate interests |
| Responding to enquiries | Contact details and enquiry content | Pre-contractual measures or legitimate interests |
| Security of guests and property | CCTV recordings | Legitimate interests and applicable legislation |
| Improving website performance | Technical and website usage data | Consent (where required) or legitimate interests |
| Website analytics | Google Analytics 4 | Consent where required |
| Compliance with legal obligations | Identification, reservation and payment records | Legal obligation |
| Establishing, exercising or defending legal claims | Relevant personal data | Legitimate interests |
We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.
Under Slovenian law, accommodation providers are required to register guests in the national eTurizem information system.
For this purpose, Burja Hoteli processes and submits personal data that are required by applicable legislation, including but not limited to:
The legal basis for this processing is compliance with legal obligations imposed by Slovenian legislation governing hospitality services and residence registration.
Submission of these data is mandatory. If a guest refuses to provide the legally required information, Burja Hoteli may be unable to provide accommodation services.
We disclose personal data only where necessary and only to recipients who have a lawful basis to receive such information.
Depending on the services used, recipients may include:
Where required by law, personal data may be disclosed to competent authorities, including but not limited to:
Such disclosures are made only where required or permitted by law.
Payments may be processed by:
These providers process payment information in accordance with their own privacy policies and applicable financial regulations.
Burja Hoteli does not have access to complete payment card numbers or security codes where payment processing is handled directly by these providers.
Reservation and guest management are carried out using the Hostel – MWore (Denis Poženel s.p.) Property Management System.
This provider processes personal data on our behalf under a data processing agreement where required by applicable law.
Online check-in services may be provided through GuestPortal.si.
The platform processes guest information required for online registration and statutory reporting.
We may engage trusted IT providers for:
Such providers may process personal data only under our documented instructions and appropriate contractual safeguards.
Where necessary, personal data may be disclosed to:
solely to the extent necessary for the provision of professional services.
We never sell personal data to third parties.
Some of our service providers may process personal data outside the European Economic Area (EEA).
Whenever personal data are transferred outside the EEA, we ensure that appropriate safeguards are implemented in accordance with Chapter V of the GDPR.
Depending on the recipient, these safeguards may include:
We do not transfer personal data internationally unless a lawful transfer mechanism is in place.
We use Google Analytics 4 to understand how visitors use our websites and to improve their functionality.
Google Analytics may collect information such as:
Where required by applicable law, Google Analytics cookies are activated only after obtaining your consent through our cookie management platform.
You may withdraw your consent at any time by changing your cookie preferences.
Visitors may voluntarily subscribe to receive newsletters and promotional communications. Subscription is entirely optional and based on your consent. You may withdraw your consent and unsubscribe at any time by:
We do not send marketing communications to individuals who have not provided the required consent, unless otherwise permitted by applicable legislation.
We retain personal data only for as long as necessary to fulfil the purposes for which they were collected or to comply with legal obligations.
The applicable retention periods generally include:
| Category | Retention Period |
|---|---|
| Reservation records | Up to 5 years after completion of the stay unless longer retention is required by law or necessary for legal claims |
| Guest registration records | As required by applicable Slovenian legislation |
| Accounting and tax documentation | 10 years or as required by tax legislation |
| Customer correspondence | Up to 5 years unless longer retention is necessary |
| CCTV recordings | Normally up to 30 days, unless required for investigation of an incident or where a longer retention period is prescribed by law |
| Newsletter subscription data | Until consent is withdrawn |
| Website analytics data | In accordance with Google Analytics retention settings |
When personal data are no longer required, they are securely deleted, anonymised or otherwise destroyed in accordance with our internal retention procedures.
Burja Hoteli is committed to protecting personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
To achieve this, we implement appropriate technical and organisational measures, including but not limited to:
Despite implementing appropriate safeguards, no electronic transmission or storage system can be guaranteed to be completely secure. We therefore encourage all users to take reasonable precautions when communicating personal information online.
Certain areas of our accommodation properties are protected by Closed-Circuit Television (CCTV) systems.
The purposes of CCTV monitoring include:
CCTV is operated in accordance with the General Data Protection Regulation (GDPR), the Slovenian Personal Data Protection Act (ZVOP-2), and other applicable legislation.
Clearly visible notices are displayed at monitored locations informing individuals that CCTV surveillance is in operation.
CCTV recordings are accessed only by authorised personnel and only where necessary to fulfil the purposes described above or where disclosure is required by law.
Unless required for the investigation of a specific incident or by applicable legislation, CCTV recordings are generally retained for no longer than 30 days, after which they are permanently deleted or overwritten.
Under the GDPR, you have the following rights regarding your personal data.
You have the right to obtain confirmation as to whether we process your personal data and, where applicable, to receive a copy of such data.
You have the right to request correction of inaccurate or incomplete personal data.
You may request deletion of your personal data where:
This right is not absolute and may be limited where processing is required to comply with legal obligations or to establish, exercise or defend legal claims.
You may request that processing of your personal data be restricted under the circumstances provided for by Article 18 GDPR.
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used and machine-readable format and to request transmission to another controller where technically feasible.
You have the right to object to processing based on our legitimate interests. If personal data are processed for direct marketing purposes, you may object at any time.
Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Burja Hoteli does not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.
Requests concerning personal data may be submitted by email or in writing.
To protect your privacy, we may ask you to verify your identity before responding. We will respond to your request without undue delay and, in any event, within one month of receiving your request, unless a longer period is permitted by applicable law.
Where requests are manifestly unfounded or excessive, we reserve the right to charge a reasonable administrative fee or refuse to act in accordance with Article 12 GDPR.
Our services are intended for guests of all ages, including families travelling with children.
Where required by Slovenian legislation, accommodation providers must collect identification information relating to minor guests for statutory guest registration purposes.
We do not knowingly collect personal data from children for marketing purposes without appropriate legal basis or parental involvement where required.
Our websites may contain links to third-party websites, booking platforms or social media services.
This Privacy Policy applies only to websites operated by Burja Hoteli. We are not responsible for the privacy practices or content of third-party websites and encourage users to review their respective privacy policies.
We may update this Privacy Policy from time to time to reflect:
The latest version will always be published on our websites.
Where required by applicable law, we will notify users of material changes.
If you believe that your personal data have been processed unlawfully, we encourage you to contact us first so that we may attempt to resolve your concerns.
You also have the right to lodge a complaint with the competent supervisory authority. For processing activities carried out in Slovenia, the competent authority is:
Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec)
Dunajska cesta 22
1000 Ljubljana
Slovenia
Website: https://www.ip-rs.si
For all questions concerning this Privacy Policy or the processing of your personal data, please contact:
Burja Hoteli d.o.o.
Address: Bonifacijeva ulica 11, 6330 Piran – Pirano
Email: info@burjahotels.com
General enquiries: info@burjahotels.com
Telephone: 00386 40 462 099
This Privacy Policy is effective as of the date stated below and replaces all previous versions published by Burja Hoteli.
Should any provision of this Privacy Policy become invalid or unenforceable, the remaining provisions shall remain in full force and effect.