GDPR and Data Protection

Privacy Policy

Data Controller: Hotelconsult s.r.o.
Effective as of: July 1, 2026

1. Who We Are

The data controller is:

Hotelconsult s.r.o.
Brutovce 73, 05373 Brutovce
Company ID: 47552212, Tax ID: SK2023979683
Managing Director: Dávid Kálmán
Email: frontdesk@hotelsovask.sbs
Phone: +421 905 926 601
Website: www.hotelsovask.sbs
Location: SOVA Hotel&Restaurant, Ždiar 460, 05955 Ždiar

Contact for GDPR inquiries and exercising your rights: frontdesk@hotelsovask.sbs

2. What personal data do we process and why
2.1 Reservations and the Provision of Accommodation and Hotel Services

Purpose: To enter into and fulfill a contract for accommodation and hotel services, including reservation management, check-in, billing, and communication with the guest.

Legal basis: Article 6(1)(b) of the GDPR – performance of a contract or pre-contractual measures.

Data Categories: first name, last name, address, email, phone number, dates of stay, room type, price, payment details, reservation number, special requests.

Recipients: hotel front desk staff, accountant, Horeca Group s.r.o. (PMS system, channel manager, point-of-sale system), Tatra banka, a.s. (payment processing).

Retention period: 10 years for accounting and tax documents pursuant to Act No. 431/2002 Coll. Operational records of a non-accounting nature: 3 years from the end of the stay.

2.2 Statutory Guest Registration

Purpose: To comply with the legal obligation to report guests’ stays pursuant to Act No. 404/2011 Coll. on the Residence of Foreigners, Act No. 253/1998 Coll. on Residence Registration, and for the purposes of the local accommodation tax pursuant to Act No. 582/2004 Coll.

Legal basis: Article 6(1)(c) of the GDPR – compliance with a legal obligation.

Data categories: first name, last name, date of birth, nationality, identity document number (for foreign nationals), permanent address, duration of stay.

Recipients: the municipality of Ždiar (local fee), the Foreigners’ Police (for foreign nationals), other authorities as provided by law.

Retention period: In accordance with the relevant legal regulation, generally 5 years.

2.3 Billing and Accounting

Purpose: Issuing invoices, maintaining accounting records, and fulfilling tax obligations.

Legal basis: Article 6(1)(c) GDPR – compliance with a legal obligation (Act No. 431/2002 Coll., Act No. 222/2004 Coll., Act No. 595/2003 Coll.).

Data categories: billing information (name/business name, address, company ID number, VAT ID number), amount, payment, date.

Recipients: accountant, Financial Administration of the Slovak Republic during a tax audit.

Retention period: 10 years from the end of the tax period.

2.4 Handling Complaints and Disputes

Purpose: To handle guest complaints, maintain a record of complaints, and defend against legal claims.

Legal basis: Article 6(1)(c) of the GDPR (legal obligation) and Article 6(1)(f) of the GDPR (legitimate interest—defense against legal claims).

Data Categories: Guest identification and contact information, description of the defect, communication regarding the complaint, supporting documents.

Recipients: reception staff, hotel management; in the event of a dispute: SOI, court, legal counsel.

Retention period: 3 years from the resolution of the complaint.

2.5 Direct Marketing – Newsletter and Hotel Promotions

Purpose: To send information about offers, promotions, news, and events at Hotel Sova.

Legal basis: Article 6(1)(a) of the GDPR—consent of the data subject. Consent is voluntary and may be withdrawn at any time.

Data categories: email, name.

Retention period: Until consent is withdrawn. After consent is withdrawn, we retain proof of the granting and withdrawal of consent for a period of 3 years.

2.6 Social Media Marketing Campaigns

Purpose: Promotion of the hotel on social media (Facebook, Instagram, and others).

Legal basis: Article 6(1)(a) of the GDPR—consent via a cookie banner (for retargeting).

Recipients: Meta Platforms Ireland Ltd. Transfer outside the EEA: possible—based on Standard Contractual Clauses (SCCs).

2.7 CCTV System

Purpose: Protection of the hotel’s property and the safety of guests and staff on the hotel premises.

Legal basis: Article 6(1)(f) of the GDPR – legitimate interests of the controller (protection of property and safety).

Data categories: video recordings.

Recipients: Authorized hotel employees; law enforcement authorities when required by law or in the event of an incident.

Retention period: Recordings are automatically deleted after 7 days, unless they are needed in connection with an incident.

Information about the camera system is posted at the entrance to monitored areas.

2.8 Handling Inquiries

Purpose: Communication with potential guests prior to booking.

Legal basis: Article 6(1)(b) of the GDPR—pre-contractual relationships.

Data categories: name, email address, message content.

Retention period: 1 year from the last communication, unless a reservation is made.

3. To Whom We Disclose Data

Recipient Role Reason
Horeca Group s.r.o. Processor PMS system, channel manager, point-of-sale system
Tatra banka, a.s. Recipient Payment processing
Accountant Processor Accounting and tax administration
Municipality of Ždiar Recipient (legal obligation) Local accommodation tax
Foreigners’ Police Recipient (legal obligation) Registration of foreign nationals
Meta Platforms Ireland Ltd. Recipient Advertising campaigns (with consent)
Law enforcement authorities Recipient (legal obligation) As required by law

We do not sell personal data to third parties for commercial purposes.

4. Data Transfer Outside the European Economic Area

Some recipients (Meta Platforms for advertising) may operate outside the EEA. The transfer is based on Standard Contractual Clauses (SCCs) approved by the European Commission pursuant to Article 46 of the GDPR.

5. Your Rights

Right Content Response Time
Access (Article 15 of the GDPR) The right to know what data we process about you Within 1 month
Rectification (Article 16 of the GDPR) The right to have inaccurate or incomplete data corrected Within 1 month
Erasure (Article 17 of the GDPR) The right to erasure if the purpose no longer applies or you have withdrawn your consent Within 1 month
Restriction (Article 18 of the GDPR) The right to restrict processing in cases specified by law Within 1 month
Data portability (Article 20 of the GDPR) The right to receive data in a machine-readable format Within 1 month
Objection (Article 21 of the GDPR) Right to object to processing based on a legitimate interest Without undue delay
Withdrawal of consent (Article 7 of the GDPR) Consent may be withdrawn at any time without prejudice Effective immediately
Complaint (Article 77 of the GDPR) Right to lodge a complaint with a supervisory authority –

Please send requests to: frontdesk@hotelsovask.sbs or in writing to the business address: SOVA Hotel&Restaurant, Ždiar 460, 05955 Ždiar.

Supervisory authority:
Office for Personal Data Protection of the Slovak Republic
Hraničná 12, 820 07 Bratislava
www.dataprotection.gov.sk

6. Data Security

We implement appropriate technical and organizational measures to protect personal data from unauthorized access, misuse, or loss. Access to personal data is restricted to authorized individuals bound by a duty of confidentiality.

7. Cookies

Information about the use of cookies on the website www.hotelsovask.sbs is provided in the Cookie Policy document available at www.hotelsovask.sbs/cookies/. You grant and manage your consent to cookies via the cookie banner on the website.

8. Automated Decision-Making

The hotel does not engage in automated individual decision-making or profiling of guests in a manner that would have legal effects or similarly significant consequences (Article 22 of the GDPR).

9. Changes to This Document

We may update this document. We will notify you of any material changes by publishing a new version at www.hotelsovask.sbs/gdpr/ with the effective date.

Valid and effective as of: July 1, 2026