Data protection · GDPR

Privacy policy

How we use, protect and keep your personal data, in plain language, and what rights you have over it.

Last updated: 1 September 2026Version 3.2
Velmora Grand Hotel & SpaVia delle Scogliere 12, Costa Velmora · +40 721 000 777 · rezervari@velmora.ro

01Who is the data controller

Your personal data is processed by the controller below, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Romanian law.

Controller
Velmora Hospitality S.R.L. (Velmora Grand Hotel & Spa)
Address
Via delle Scogliere 12, Costa Velmora
VAT no. / Reg. no.
RO 00000000 · J00/0000/2020
Data Protection Officer (DPO)
dpo@velmora.ro

02What data we collect

Booking form

Name, e-mail, phone, stay dates, chosen room, number of adults and children (including children's ages, to apply rates correctly), extra services and special notes. On arrival, as required by law, we may record details from your ID.

Contact form

Name, e-mail, phone (optional), subject and the content of your message.

Newsletter

Your e-mail address and the time of subscription.

Technical data

IP address, browser and device type, pages visited and language. Optional cookies are only activated with your consent (see the Cookie policy).

03Purposes, legal bases and retention

We process data only for specific purposes and keep it only as long as necessary:

PurposeLegal basisRetention
Managing bookings and your stayContract, Art. 6(1)(b) GDPRDuration of the contract
Guest registration, tax and accounting dutiesLegal obligation, Art. 6(1)(c)5 years for accounting records (or as required by law)
Replying to contact-form messagesLegitimate interest / pre-contract steps, Art. 6(1)(f) and (b)12 months after the last interaction
Newsletter and promotional messagesConsent, Art. 6(1)(a)Until consent is withdrawn
Special requirements (allergies, accessibility needs)Explicit consent, Art. 9(2)(a)Length of stay, then deleted (or on request)
Statistics and site improvement (analytics cookies)Consent, Art. 6(1)(a)Max. 13 months
Site security and fraud preventionLegitimate interest, Art. 6(1)(f)Max. 90 days (technical logs)

We do not make decisions based solely on automated processing and we never sell your data.

04Who we share data with

Access is limited to staff who need it. We use providers (processors) who handle data only on our instructions under a contract:

  • hosting and cloud infrastructure providers for the website;
  • the property management system (PMS) and transactional e-mail service;
  • analytics and marketing providers, only if you have consented;
  • accounting and legal advisers and public authorities, where required by law.

If a provider is located outside the European Economic Area, the transfer takes place only with appropriate safeguards (standard contractual clauses or a European Commission adequacy decision).

05Your rights

  • Access to the data we hold about you;
  • Rectification of inaccurate or incomplete data;
  • Erasure (“right to be forgotten”) where there is no longer a basis to keep it;
  • Restriction of processing in certain situations;
  • Portability of your data, in a structured format;
  • Objection to processing based on legitimate interest and to direct marketing;
  • Withdrawal of consent at any time, without affecting the lawfulness of earlier processing.

To exercise your rights write to us at dpo@velmora.ro. We reply within one month of receiving your request (extendable in complex cases, with notice to you).

06Security

We use appropriate technical and organisational measures: encrypted connections (HTTPS), role-based access, backups and staff training. In the event of a breach that affects your rights we will inform you and notify the authority within the legal deadlines.

07Children's data

The website is not aimed at persons under 16. Children's data (name, age) is provided only by a parent or guardian, solely to organise the stay and apply the correct rates.

08Complaints to the authority

If you are unhappy with how we process your data, you have the right to lodge a complaint with the Romanian supervisory authority:

ANSPDCP
National Supervisory Authority for Personal Data Processing
Address
B-dul G-ral. Gheorghe Magheru 28-30, sector 1, București
Web
dataprotection.ro

We would nevertheless welcome the chance to resolve any concern with you first.

09DPO contact and changes

Our Data Protection Officer can be reached at dpo@velmora.ro or by post at the hotel's address, marked “For the attention of the DPO”.

We may update this policy from time to time; the date of the latest update is shown at the top of the page, and significant changes will be communicated to you.

Demo document: Velmora Grand Hotel & Spa is a fictional hotel and the text above illustrates the structure of a real policy; it has no legal effect.