Privacy policy

Ultima actualizare

Cuprins
  1. Who the data controller is
  2. Scope
  3. Categories of data processed
  4. Sources of the data
  5. Purposes and legal bases for processing
  6. Providers and recipients
  7. International transfers
  8. Retention periods
  9. Card details
  10. Cookies and analytics
  11. Rights of the data subject
  12. Exercising these rights
  13. Children's data
  14. Automated decisions
  15. Data security
  16. External links
  17. Updating this policy

Who the data controller is

The controller of the data processed through the website www.hiddenhills.ro and in connection with Hidden Hills bookings is the legal provider of the accommodation services, with the address for correspondence Strada Crizantemelor nr. 2, Țipărești, Cocorăștii Mislii commune, Prahova County, telephone +40 740 087 777 and email contact@hiddenhills.ro. The accommodation establishment is identified by Classification certificate no. 33588, issued on 25 November 2024 in the name of “Hidden Hills”.

Scope

This policy explains how the data of people who access the website, request information, make bookings, pay for services, stay at the property or communicate with the Hidden Hills team is collected, used, stored and disclosed.

Categories of data processed

  • Identification and contact data: surname, first name, email, telephone, address, as applicable.
  • Booking data: the period, the number of guests, adults/children, preferences and special requests.
  • Invoicing and transaction data: the information needed for tax documents and for confirming payment. Full card details are not received by Hidden Hills.
  • Data required for the tourist register, in accordance with the legal obligations applicable to accommodation establishments.
  • Data from communications: emails, messages, requests and complaints.
  • Technical data: IP address, browser, device, pages visited, security logs and cookies, depending on consent.
  • Data on marketing preferences, only where the person has given their consent.
  • Data provided for reviews or content, only where the person submits it or approves its use.

For in-person check-in, only the data required for the legal tourist register is collected.

Sources of the data

  • Directly from the data subject, through forms, the booking, email, telephone or check-in.
  • From Smoobu, when the booking is made through the direct engine.
  • From Booking or Airbnb, when the booking comes from that platform.
  • From Stripe, only in the form of payment status information and the data permitted by the integration.
  • From cookies and similar technologies, according to the user's preferences.

Providers and recipients

Data may be transmitted, to the extent necessary, to the following categories:

  • Smoobu — administering bookings and the calendar.
  • Stripe — processing card payments.
  • The website hosting and maintenance provider.
  • The email and communications provider.
  • Analytics and marketing providers, only after consent.
  • Accountants, legal advisers or other professionals bound by confidentiality.
  • Public authorities, where disclosure is required by law.
  • Booking and Airbnb, in relation to bookings made through those platforms.

International transfers

Some providers may process data outside the European Economic Area. In such cases, the controller must verify that an adequate legal mechanism is in place, such as an adequacy decision or standard contractual clauses. The final list and the specific mechanisms will be completed once all providers have been chosen.

Retention periods

Data is kept only for as long as is necessary for the purpose for which it was collected and for compliance with legal obligations. The indicative criteria are:

  • Enquiries that do not lead to a booking: for the period needed to reply and a reasonable period for continuing the correspondence, subject to an internal limit of 6 months.
  • Booking and contract data: for the duration of the contractual relationship and the statutory limitation periods.
  • Tax and accounting documents: for the period laid down by the applicable tax and accounting legislation.
  • Data for the tourist register: in accordance with the periods laid down by the applicable rules.
  • Security logs: for a limited period set by the technical policy, of 6 months.
  • Marketing: until consent is withdrawn or the internal review period expires.
  • Cookies: for the durations stated in the Cookie Policy.

Card details

Online payments are processed by Stripe through the integration with the booking system. Hidden Hills does not store the full card number or the security code. Stripe may act in accordance with its own data protection obligations and policies.

Cookies and analytics

Strictly necessary cookies may operate without consent where they are indispensable to the functioning or the security of the website. Analytics and marketing cookies are activated only after the user has agreed. Preferences may be changed later.

Rights of the data subject

  • The right of access.
  • The right to rectification.
  • The right to erasure, where the legal conditions are met.
  • The right to restriction of processing.
  • The right to data portability, where applicable.
  • The right to object.
  • The right to withdraw consent, without affecting processing carried out beforehand.
  • The right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP).
  • The right to apply to the competent courts.

Exercising these rights

Requests concerning data protection should be sent to contact@hiddenhills.ro. The controller may ask for reasonable additional information in order to verify identity, without collecting more data than is necessary.

Children's data

Children's data is processed only to the extent necessary for the booking, the accommodation, safety and compliance with legal obligations, through the adult responsible for the booking. The website is not intended for independent use by children to make bookings.

Automated decisions

Hidden Hills does not intend to take decisions producing legal effects solely by automated processing. Availability and rates may be calculated automatically by the booking system, but the confirmation and the performance of the service remain governed by the conditions of the booking.

Data security

Proportionate technical and organisational measures are used, including restricted access, passwords, authentication, updates, secure connections, backups and appropriately contracted providers. No measure can eliminate risk entirely, and incidents will be handled in accordance with the law.

Updating this policy

This policy may be updated to reflect legislative, technical or operational changes. The date of the last update must be displayed at the top of the page. Significant changes will be communicated by appropriate means.

Book Hidden Hills

The property is rented as a whole, for a maximum of 10 guests. Select your dates and check real-time availability.