Privacy policy
Cuprins
- Who the data controller is
- Scope
- Categories of data processed
- Sources of the data
- Purposes and legal bases for processing
- Providers and recipients
- International transfers
- Retention periods
- Card details
- Cookies and analytics
- Rights of the data subject
- Exercising these rights
- Children's data
- Automated decisions
- Data security
- External links
- Updating this policy
Who the data controller is
The controller of the data processed through the website www.hiddenhills.ro and in connection with Hidden Hills bookings is the legal provider of the accommodation services, with the address for correspondence Strada Crizantemelor nr. 2, Țipărești, Cocorăștii Mislii commune, Prahova County, telephone +40 740 087 777 and email contact@hiddenhills.ro. The accommodation establishment is identified by Classification certificate no. 33588, issued on 25 November 2024 in the name of “Hidden Hills”.
Scope
This policy explains how the data of people who access the website, request information, make bookings, pay for services, stay at the property or communicate with the Hidden Hills team is collected, used, stored and disclosed.
Categories of data processed
- Identification and contact data: surname, first name, email, telephone, address, as applicable.
- Booking data: the period, the number of guests, adults/children, preferences and special requests.
- Invoicing and transaction data: the information needed for tax documents and for confirming payment. Full card details are not received by Hidden Hills.
- Data required for the tourist register, in accordance with the legal obligations applicable to accommodation establishments.
- Data from communications: emails, messages, requests and complaints.
- Technical data: IP address, browser, device, pages visited, security logs and cookies, depending on consent.
- Data on marketing preferences, only where the person has given their consent.
- Data provided for reviews or content, only where the person submits it or approves its use.
For in-person check-in, only the data required for the legal tourist register is collected.
Sources of the data
- Directly from the data subject, through forms, the booking, email, telephone or check-in.
- From Smoobu, when the booking is made through the direct engine.
- From Booking or Airbnb, when the booking comes from that platform.
- From Stripe, only in the form of payment status information and the data permitted by the integration.
- From cookies and similar technologies, according to the user's preferences.
Purposes and legal bases for processing
| Purpose | Data used | Legal basis |
|---|---|---|
| Responding to enquiries and preparing an offer | Contact details and message | Pre-contractual steps / legitimate interest, as applicable |
| Administering the booking and providing the accommodation | Identification, contact, period, guests | Performance of the contract |
| Processing and confirming payment | Transaction data | Performance of the contract |
| Invoicing and legal obligations | Identification and invoicing data | Legal obligation |
| The tourist register and safety | The data required by law | Legal obligation |
| Assistance and complaints | Booking and communications | Contract / legitimate interest |
| Website security | IP address and logs | Legitimate interest |
| Optional analytics | Online identifiers | Consent |
| Marketing and newsletter | Email and preferences | Consent |
| Requesting a review after the stay | Contact and booking data | Legitimate interest or consent, depending on configuration |
Providers and recipients
Data may be transmitted, to the extent necessary, to the following categories:
- Smoobu — administering bookings and the calendar.
- Stripe — processing card payments.
- The website hosting and maintenance provider.
- The email and communications provider.
- Analytics and marketing providers, only after consent.
- Accountants, legal advisers or other professionals bound by confidentiality.
- Public authorities, where disclosure is required by law.
- Booking and Airbnb, in relation to bookings made through those platforms.
International transfers
Some providers may process data outside the European Economic Area. In such cases, the controller must verify that an adequate legal mechanism is in place, such as an adequacy decision or standard contractual clauses. The final list and the specific mechanisms will be completed once all providers have been chosen.
Retention periods
Data is kept only for as long as is necessary for the purpose for which it was collected and for compliance with legal obligations. The indicative criteria are:
- Enquiries that do not lead to a booking: for the period needed to reply and a reasonable period for continuing the correspondence, subject to an internal limit of 6 months.
- Booking and contract data: for the duration of the contractual relationship and the statutory limitation periods.
- Tax and accounting documents: for the period laid down by the applicable tax and accounting legislation.
- Data for the tourist register: in accordance with the periods laid down by the applicable rules.
- Security logs: for a limited period set by the technical policy, of 6 months.
- Marketing: until consent is withdrawn or the internal review period expires.
- Cookies: for the durations stated in the Cookie Policy.
Card details
Online payments are processed by Stripe through the integration with the booking system. Hidden Hills does not store the full card number or the security code. Stripe may act in accordance with its own data protection obligations and policies.
Rights of the data subject
- The right of access.
- The right to rectification.
- The right to erasure, where the legal conditions are met.
- The right to restriction of processing.
- The right to data portability, where applicable.
- The right to object.
- The right to withdraw consent, without affecting processing carried out beforehand.
- The right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP).
- The right to apply to the competent courts.
Exercising these rights
Requests concerning data protection should be sent to contact@hiddenhills.ro. The controller may ask for reasonable additional information in order to verify identity, without collecting more data than is necessary.
Children's data
Children's data is processed only to the extent necessary for the booking, the accommodation, safety and compliance with legal obligations, through the adult responsible for the booking. The website is not intended for independent use by children to make bookings.
Automated decisions
Hidden Hills does not intend to take decisions producing legal effects solely by automated processing. Availability and rates may be calculated automatically by the booking system, but the confirmation and the performance of the service remain governed by the conditions of the booking.
Data security
Proportionate technical and organisational measures are used, including restricted access, passwords, authentication, updates, secure connections, backups and appropriately contracted providers. No measure can eliminate risk entirely, and incidents will be handled in accordance with the law.
External links
The website may contain links to Smoobu, Stripe, Booking, Airbnb, Instagram, Facebook, Google Maps and Ținutul Stejarilor. The policies of those operators apply separately once their platforms are accessed.
Updating this policy
This policy may be updated to reflect legislative, technical or operational changes. The date of the last update must be displayed at the top of the page. Significant changes will be communicated by appropriate means.