GDPR PRIVACY POLICY

Introduction

This Privacy Policy (hereinafter referred to as the “Policy”) sets out how Fiatfalvi Ugron Castle accommodation and event center (hereinafter referred to as the “Castle”) collects, uses, discloses, and protects the personal data of its clients (hereinafter referred to as “Personal Data”) in accordance with the General Data Protection Regulation (GDPR – Regulation (EU) 2016/679).

Collected Information

We collect various types of Personal Data from our clients, including but not limited to:

  • First and last name
  • Email address
  • Telephone number
  • Billing address
  • Identification information, such as passport or ID card number
  • Payment information, including credit or debit card details
  • Accommodation preferences and special requests

Purpose and Legal Basis for Processing Personal Data

Personal Data is primarily collected and processed to provide services at the Castle and related facilities. The legal basis for processing Personal Data includes:

  • The performance of a contract with the client or taking pre-contractual steps at the client’s request.
  • Compliance with legal obligations applicable to the Castle, including accounting and taxation requirements.
  • The legitimate interest of the Castle in efficiently operating its business and delivering high-quality services.

Retention Period

  • Reservation data: kept up to 5 years (for legal and tax compliance purposes)

  • Newsletter subscriptions: until unsubscribed

  • Inquiry data: up to 1 year from the last communication

Protection of Personal Data

Appropriate technical and organizational measures are implemented to protect Personal Data against unauthorized access, loss, destruction, or alteration. Our employees are trained to maintain the confidentiality and security of Personal Data.

Disclosure of Personal Data

In certain circumstances, Personal Data may be shared with third parties, such as payment processors or public authorities, in compliance with applicable legal or contractual obligations. In such cases, the transfer of Personal Data is conducted in accordance with GDPR provisions, with appropriate safeguards to ensure confidentiality and security.

Third-party processors engaged include:

Reservation software provider: Previo srl

Payment service providers: Banca Transilvania S.A., Netopia Srl

Analytics service provider: Google LLC

Data Subject Rights

Under GDPR, data subjects have the right to access, rectify, erase, or restrict the processing of their Personal Data. They also have the right to object to the processing of their Personal Data under certain circumstances. To exercise these rights or for any questions or concerns regarding the processing of Personal Data, data subjects are encouraged to contact the Castle using the contact details provided at the end of this Policy.

Updated Privacy Policy

This Privacy Policy may be reviewed and updated periodically to reflect changes in our data practices and to comply with applicable laws and regulations. Any amendments take effect immediately upon publication on our website: www.ugroncastle.ro

Contact information

For any questions or concerns regarding this Privacy Policy or the exercise of your GDPR rights, please contact us at:

Email: info@ugroncastle.ro, Phone: +40 773 396 077

Video Surveillance Data Processing Policy

Purpose of Video Surveillance

The Castle operates a camera system to protect the safety and security of guests, employees, and property.

Recordings are made solely for security purposes and on the basis of legitimate interest (GDPR Article 6(1)(f)).

Camera Locations

Cameras are installed in public areas of the Castle, including:

  • Main entrance and reception
  • Restaurant and corridors
  • Parking and courtyard entrances
  • Staircases
  • Cameras are not installed in guest rooms, bathrooms, or event halls, as this would be prohibited under GDPR.

Notification

  • Guests are informed in advance of the presence of cameras via signs and pictograms at entrances.

  • Detailed information on data processing is available in the Privacy Policy and upon request at the reception desk.

Retention of Recordings

  • Recordings are retained for a maximum of 30 days.

  • In case of incidents (e.g., theft), relevant recordings may be retained longer solely as security copies until the conclusion of any official proceedings.

Access to Recordings

  • Only authorized security personnel may access the recordings.
  • Data may be disclosed to competent authorities upon lawful request (e.g., police).

Data Security Measures

  • Recordings are stored in a secure system with password protection and restricted access.
  • Unauthorized copying or sharing of recordings is strictly prohibited.

Data Subject Rights – Video Surveillance:

Guests are entitled to:
Request information on where and when recordings were made
Request access to their own recordings (upon identification)
Request deletion of recordings if there is no lawful reason for retention
File a complaint with the national data protection authority (ANSPDCP).

 

Scroll to Top