Legal information
Privacy Policy
How Situation, s.r.o. processes personal data for direct bookings and guest communication under the GDPR.
Draft notice: This text is a working draft pending final legal review and approval by the owner.
1. Controller
Situation, s.r.o. is the controller of personal data processed through the Vlado Apartments website and for direct accommodation bookings. Privacy questions and requests may be sent to info@vladoapartments.com.
2. Data we collect
We collect information supplied in a booking request or booking, including the guest's name, email address, telephone number, stay dates, guest counts, message, company billing details when provided, consent record and booking reference. We also process booking status, price and payment records and operational correspondence.
The website may process limited technical data needed for security, service operation and language preference, including IP address, request metadata and the NEXT_LOCALE language cookie. Card details are handled by the payment provider and are not stored as full card numbers by Situation, s.r.o.
3. Purposes and legal bases
We process booking and contact data to answer requests, take steps before entering a contract, administer and perform accommodation contracts, collect payments, provide arrival information and customer support, meet tax and accounting duties, protect the accommodation and establish or defend legal claims.
The legal bases are performance of a contract or pre-contractual steps, compliance with legal obligations and legitimate interests in operating a secure accommodation service and protecting legal rights. Where processing relies on consent, consent may be withdrawn for future processing without affecting earlier lawful processing.
4. Recipients and email delivery
Data is shared only as needed with service providers supporting hosting, database operations, payment processing, professional advice and booking administration, or with public authorities where legally required. Providers act under appropriate data-protection obligations.
Booking emails are sent through Hostinger SMTP infrastructure. This requires relevant contact and message data to be transmitted to Hostinger for email delivery. Any transfer outside the European Economic Area will use a lawful GDPR transfer mechanism where required.
5. Retention and security
Unsuccessful booking-request data is generally kept for up to 12 months so we can respond and resolve follow-up questions. Confirmed booking, payment, tax and accounting records are kept for the period required by Slovak law, generally up to 10 years. Other correspondence is retained only as long as needed for the purpose or an applicable limitation period.
We use proportionate technical and organisational safeguards, access controls and data minimisation. No internet service is risk-free, but suspected personal-data breaches are assessed and notified as required by the GDPR.
6. Your rights
Subject to the GDPR, you may request access to your personal data, correction, erasure, restriction, portability or objection to processing based on legitimate interests. You may also withdraw consent where it is the legal basis. We may ask for information needed to verify identity before acting on a request.
You may lodge a complaint with the Slovak Office for Personal Data Protection or another competent supervisory authority. Contacting us first may allow the concern to be resolved promptly and does not limit the right to complain.
