PRIVACY POLICY
1. Introduction
This Privacy Policy sets out in detail the manner in which Boiken Sh.p.k. (hereinafter referred to as the “Company”), collects, processes, uses, stores, and protects personal data of individuals who access or interact with its website, digital platforms, or services related to the touristic resort “Kep Merli”.
The Company is committed to ensuring that all personal data is processed lawfully, fairly, and transparently, in full compliance with Law no. 124/2024 “On personal data protection”, as well as applicable secondary legislation and best practices aligned with European data protection standards.
This Privacy Policy applies to all users, visitors, potential clients, and any individuals whose personal data is processed in the context of the Company’s activities.
2. Identity of the Data Controller
The data controller responsible for the processing of personal data is: Boiken Sh.p.k.
Registered address: Fshati Turistik, Parcela 5, 6ª, Vlorë, Sarandë, Ksamil, Albania
For any matters relating to personal data, the Company may be contacted through the contact details published on the Platform.
3. Principles of Processing
The Company processes personal data in accordance with the core principles established under Law nr. 124/2024. In particular, personal data is processed lawfully, based on a valid legal ground, and in a manner that is transparent to the data subject. The Company ensures that data is collected only for specified and legitimate purposes, that it is adequate and limited to what is necessary, accurate and kept up to date, stored for no longer than necessary, and processed in a manner that ensures appropriate security.
Any processing activity that deviates from these principles is strictly prohibited.
4. Categories of Personal Data
Depending on the interaction with the Platform or services, the Company may collect and process a wide range of personal data. This includes identification data such as name and surname; contact data such as email address, telephone number, and address; reservation and accommodation-related data such as booking details, preferences, and special requests; financial data where necessary to facilitate payments or guarantees; and communication data arising from correspondence between the user and the Company.
In addition, the Company may process technical and electronic data, including IP address, device identifiers, browser type, geolocation data where applicable, and logs reflecting user activity on the Platform. Such data may be collected automatically through cookies and similar technologies.
The Company does not intentionally collect sensitive categories of personal data unless strictly necessary and in compliance with the requirements of applicable law.
5. Sources of Data
Personal data may be collected directly from the data subject when they fill in forms, submit inquiries, make reservations, or otherwise interact with the Platform. Data may also be obtained indirectly through third-party booking platforms, partners, or service providers, provided that such third parties have a lawful basis for sharing the data.
In all cases, the Company ensures that the data subject is informed of the processing in accordance with legal requirements.
6. Purposes of Processing
The Company processes personal data for clearly defined and legitimate purposes. These include managing reservations and accommodation services, responding to inquiries, communicating with clients and potential clients, fulfilling contractual obligations, processing payments where applicable, ensuring the proper functioning and security of the Platform, complying with legal and regulatory obligations, and improving the quality of services offered.
Personal data may also be used for internal administrative purposes, including record-keeping, audits, and the establishment, exercise, or defense of legal claims.
Under no circumstances will personal data be processed in a manner incompatible with the purposes for which it was originally collected.
7. Legal Basis for Processing
The Company relies on several legal bases for the processing of personal data, as provided under Law nr. 124/2024. These include the necessity of processing for the performance of a contract or for taking steps prior to entering into a contract at the request of the data subject; compliance with legal obligations to which the Company is subject; the legitimate interests pursued by the Company, provided that such interests are not overridden by the rights and freedoms of the data subject; and, where required, the consent of the data subject.
Where processing is based on consent, such consent is obtained in a clear, informed, and unambiguous manner, and the data subject has the right to withdraw consent at any time without affecting the lawfulness of processing carried out prior to such withdrawal.
8. Data Sharing and Disclosure
The Company may disclose personal data to third parties strictly where necessary and in accordance with applicable law. Such third parties may include service providers supporting the operation of the Platform, IT and hosting providers, payment processors, professional advisors, and business partners involved in the provision of services related to the Kep Merli resort.
All third parties receiving personal data are bound by confidentiality obligations and are required to implement appropriate technical and organizational measures to protect such data.
Personal data may also be disclosed to competent public authorities where required by law or in response to lawful requests.
The Company does not sell personal data to third parties.
9. International Transfers
Where personal data is transferred outside the Republic of Albania, the Company ensures that such transfers are carried out in compliance with Law no. 124/2024, including the implementation of appropriate safeguards such as contractual clauses or reliance on adequacy decisions, where applicable.
10. Data Retention
Personal data is retained only for the period necessary to fulfill the purposes for which it was collected. Retention periods may vary depending on the nature of the data and the applicable legal requirements, including obligations related to accounting, taxation, and tourism regulations.
Where personal data is no longer required, it is securely deleted or anonymized.
11. Rights of Data Subjects
Data subjects are entitled to exercise a range of rights under Law no. 124/2024. These include the right to obtain confirmation as to whether their personal data is being processed, access to such data, rectification of inaccurate or incomplete data, erasure of data under certain conditions, restriction of processing, objection to processing based on legitimate interests, and the right to data portability where applicable.
The exercise of these rights is subject to the conditions and limitations set out in the law. The Company undertakes to respond to all valid requests within the statutory deadlines.
12. Automated Decision-Making
The Company does not carry out automated decision-making, including profiling, that produces legal effects concerning the data subject or similarly significantly affects them, unless explicitly permitted by law and accompanied by appropriate safeguards.
13. Security of Processing
The Company implements robust technical and organizational measures designed to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include access controls, encryption where appropriate, secure storage systems, and internal policies governing data access and handling.
Employees and collaborators who have access to personal data are bound by confidentiality obligations.
14. Data Breaches
In the event of a personal data breach, the Company shall take all necessary measures to mitigate its effects and shall notify the competent supervisory authority and, where required, the affected data subjects, in accordance with Law no. 124/2024.
15. Third-Party Platforms and Unauthorized Processing
The Company expressly disclaims responsibility for any unauthorized collection or processing of personal data carried out by third parties falsely presenting themselves as authorized agents of the Kep Merli resort.
Users are advised to ensure that they interact only with official communication channels of the Company. Any suspected misuse of personal data should be reported immediately.
16. Updates to this Policy
This Privacy Policy may be updated periodically to reflect changes in legal requirements or in the Company’s processing practices. Any updated version shall be published on the Platform and shall take effect from the date of publication.