GDPR PRIVACY POLICY
Introduction
This Privacy Policy (hereinafter referred to as the “Policy”) sets out how Fiatfalvi Ugron Castle accommodation and event center (hereinafter referred to as the “Castle”) collects, uses, discloses, and protects the personal data of its clients (hereinafter referred to as “Personal Data”) in accordance with the General Data Protection Regulation (GDPR – Regulation (EU) 2016/679).
Collected Information
We collect various types of Personal Data from our clients, including but not limited to:
- First and last name
- Email address
- Telephone number
- Billing address
- Identification information, such as passport or ID card number
- Payment information, including credit or debit card details
- Accommodation preferences and special requests
Purpose and Legal Basis for Processing Personal Data
Personal Data is primarily collected and processed to provide services at the Castle and related facilities. The legal basis for processing Personal Data includes:
- The performance of a contract with the client or taking pre-contractual steps at the client’s request.
- Compliance with legal obligations applicable to the Castle, including accounting and taxation requirements.
- The legitimate interest of the Castle in efficiently operating its business and delivering high-quality services.
Retention Period
Reservation data: kept up to 5 years (for legal and tax compliance purposes)
Newsletter subscriptions: until unsubscribed
Inquiry data: up to 1 year from the last communication
Protection of Personal Data
Appropriate technical and organizational measures are implemented to protect Personal Data against unauthorized access, loss, destruction, or alteration. Our employees are trained to maintain the confidentiality and security of Personal Data.
Disclosure of Personal Data
In certain circumstances, Personal Data may be shared with third parties, such as payment processors or public authorities, in compliance with applicable legal or contractual obligations. In such cases, the transfer of Personal Data is conducted in accordance with GDPR provisions, with appropriate safeguards to ensure confidentiality and security.
Third-party processors engaged include:
Reservation software provider: Previo srl
Payment service providers: Banca Transilvania S.A., Netopia Srl
Analytics service provider: Google LLC
Data Subject Rights
Under GDPR, data subjects have the right to access, rectify, erase, or restrict the processing of their Personal Data. They also have the right to object to the processing of their Personal Data under certain circumstances. To exercise these rights or for any questions or concerns regarding the processing of Personal Data, data subjects are encouraged to contact the Castle using the contact details provided at the end of this Policy.
Updated Privacy Policy
This Privacy Policy may be reviewed and updated periodically to reflect changes in our data practices and to comply with applicable laws and regulations. Any amendments take effect immediately upon publication on our website: www.ugroncastle.ro
Contact information
For any questions or concerns regarding this Privacy Policy or the exercise of your GDPR rights, please contact us at:
Email: info@ugroncastle.ro, Phone: +40 773 396 077
Video Surveillance Data Processing Policy
Purpose of Video Surveillance
The Castle operates a camera system to protect the safety and security of guests, employees, and property.
Recordings are made solely for security purposes and on the basis of legitimate interest (GDPR Article 6(1)(f)).
Camera Locations
Cameras are installed in public areas of the Castle, including:
- Main entrance and reception
- Restaurant and corridors
- Parking and courtyard entrances
- Staircases
- Cameras are not installed in guest rooms, bathrooms, or event halls, as this would be prohibited under GDPR.
Notification
Guests are informed in advance of the presence of cameras via signs and pictograms at entrances.
Detailed information on data processing is available in the Privacy Policy and upon request at the reception desk.
Retention of Recordings
Recordings are retained for a maximum of 30 days.
In case of incidents (e.g., theft), relevant recordings may be retained longer solely as security copies until the conclusion of any official proceedings.
Access to Recordings
- Only authorized security personnel may access the recordings.
- Data may be disclosed to competent authorities upon lawful request (e.g., police).
Data Security Measures
- Recordings are stored in a secure system with password protection and restricted access.
- Unauthorized copying or sharing of recordings is strictly prohibited.
Data Subject Rights – Video Surveillance:
Guests are entitled to:
Request information on where and when recordings were made
Request access to their own recordings (upon identification)
Request deletion of recordings if there is no lawful reason for retention
File a complaint with the national data protection authority (ANSPDCP).