Skip to navigation Skip to main content
Wrong menu selected
  • Newsletter
  • Contact Us
  • FAQs
Hotel Pietroasa Hotel Pietroasa
  • Home
  • Rooms & Suites
  • Dining
  • SPA
  • Meetings & Events
  • Offers
RomânăEnglish
Book Now
RomânăEnglish
  • View Map
  • [email protected]
  • +40 720 999 437
  • Email
  • +40 720 999 437
  • Map
  • View Map
  • [email protected]
  • +40 720 999 437
  • Email
  • +40 720 999 437
  • Map

Privacy Policy

DOCUMENT 1 OF 3: GDPR (EU Reg. 2016/679) · Law no. 190/2018 · GEO 150/2024 · Law 102/2005. SC PIETROASA S.A. · CUI RO1153002 · www.hotelpietroasa.ro

Legal basis: Regulation (EU) 2016/679 (GDPR), art. 13-14; Law no. 190/2018 regarding GDPR implementation measures; GEO no. 150/2024 amending OG 58/1998 on tourism; Law no. 102/2005 regarding ANSPDCP. Effective date: May 12, 2026.

1. The identity and contact details of the operator

According to art. 13 para. (1) lit. a) from the GDPR, the operator of personal data for the website www.hotelpietroasa.ro is:

Company nameSC PIETROASA S.A.
No. RC registrationJ1991000023100
CUI / VAT codeRO1153002
Social headquartersDacia Square no. 2, Buzau, Buzau county, Romania
Legal representativeCoca Dragan
Telephone0720 999 437
E-mail contact[email protected]
Websitewww.hotelpietroasa.ro
Legal formJoint stock company (S.A.), established according to Law no. 31/1990

1.1 Data Protection Officer (DPO)

According to art. 37-39 GDPR and art. 10 of Law no. 190/2018, S.C. Pietroasa S.A. appointed a Data Protection Officer. You can contact him for any question related to the processing of your personal data:

DPO nameHotel Pietroasa — Responsible for Data Protection
DPO email[email protected]
DPO phone0720 999 437
Correspondence addressDacia Square no. 2, Buzau, Buzau County, Romania, Attention: Data Protection Officer
Answer deadlineMaximum 30 calendar days; extendable by 60 days in complex cases, with prior notification (art. 12 GDPR)

2. Categories of personal data collected

In accordance with the principle of data minimization (art. 5 para. (1) letter c) GDPR), we collect exclusively the data necessary for the purposes described below.

2.1 Data collected when booking online

  • Name and surname
  • Email address and phone number
  • Arrival and departure date, room type (single, double, apartment, suite)
  • The number of people (adults / children) and the age of the children
  • Special preferences: extra bed, floor, view, dietary requirements, accessibility
  • Preferred language of communication

2.2 Data collected when paying online

  • Bank card data — processed exclusively by PCI-DSS certified processors; SC Pietroasa S.A. it never stores the complete card data
  • Billing address (if different from contact address)
  • The amount, currency, date and time of the transaction

2.3 Mandatory data collected at check-in (legal obligation)

According to GEO no. 150/2024 amending OG 58/1998 and the methodological norms regarding the record of tourists staying in tourist reception structures, we are legally obliged to record:

  • Series and number of valid identity document (CI, passport, EU driving license)
  • Citizenship and nationality
  • Date of birth
  • Home address / residence
  • Purpose of visit (tourism, business, transit, other purpose)
ATTENTION: These data are collected based on a legal obligation [art. 6 para. (1) lit. c) GDPR]. The refusal to provide these data prevents the provision of accommodation services. The data are transmitted to the competent authorities according to the law.

2.4 Data collected through the website (browsing and cookies)

  • The IP address of the device
  • Browser type, operating system, screen resolution
  • Pages visited, actions performed, session duration
  • Traffic source (search engine, social networks, direct access, OTA platform)
  • Data collected through cookies — detailed in Document 3 "Cookie Policy"

2.5 Data collected through the contact form / e-mail / telephone

  • Name and surname
  • Email address and/or phone number
  • The content of the message, the requests and complaints sent

2.6 Data collected through the CCTV system

Video images of common spaces: reception, main hall, entrances, corridors, parking

Private spaces (accommodation rooms, bathrooms) are NOT under video surveillance. The existence of the CCTV system is indicated by displays at the entrance to each monitored space, according to Law no. 333/2003 regarding the protection of objectives, republished.

2.7 Special categories of data (art. 9 GDPR)

SC Pietroasa S.A. does not intentionally collect data from special categories (health, racial origin, religious beliefs, etc.). If you communicate such data (eg: medical dietary requirements), they will be used exclusively for the provision of the requested service.

3. Purposes of processing and legal basis

A. Execution of the contract [art. 6 para. (1) lit. b) GDPR]

  • Processing, confirmation and management of reservations made on www.hotelpietroasa.ro
  • Communications regarding the reservation: written confirmation, modification, cancellation, fiscal invoice
  • Check-in and check-out
  • Processing payments and issuing fiscal documents
  • Management of special requests and accommodation preferences
  • Resolving complaints related to purchased services

B. Legal obligations [art. 6 para. (1) lit. c) GDPR]

  • Registration and reporting of tourist identity data according to GEO 150/2024
  • Keeping accounting and fiscal documents: Law no. 82/1991 and Law no. 227/2015 (Fiscal Code)
  • Communication of data at the request of ANAF, the Police, ANT or other competent authorities
  • Compliance with tourist classification obligations: ANT order no. 65/2013, amended by Order no. 510/2022

C. Interese legitime [art. 6 alin. (1) lit. f) GDPR]

  • Fraud prevention and hotel property security
  • Video surveillance (CCTV) of common spaces — security and property protection
  • Improving services through anonymized statistical analysis of behavior on the website
  • Defense of S.C. rights Pietroasa S.A. before the courts

D. Consent [art. 6 para. (1) lit. a) GDPR]

  • Sending newsletters and promotional offers by e-mail or SMS
  • Use of analysis and marketing cookies (detailed in Document 3)
  • Publishing customer reviews and photos on the website or social networks

The consent can be withdrawn at any time, without affecting the legality of the processing prior to the withdrawal (art. 7 para. (3) GDPR).

4. Recipients of personal data

According to art. 13 para. (1) lit. e) GDPR, your data may be disclosed to the following categories of recipients:

Payment processorsPCI-DSS certified processors — for secure processing of card transactions
IT providers / hostingThe provider of the reservation platform and the website, with a processing contract according to art. 28 GDPR
Public authoritiesANAF, Police, ANT, health authorities — exclusively upon express legal request
Accountant / auditorExternal accounting firm, based on the confidentiality agreement
OTA platformsBooking.com, Expedia and other online distribution platforms — for reservations made through them
E-mail marketingNewsletter service providers — exclusively for customers who have expressed their consent
Insurer / legalIn case of litigation, insurance claims or legal proceedings

SC Pietroasa S.A. does not sell, rent or transfer your personal data to third parties for their own commercial purposes.

5. International data transfers

According to art. 44-49 GDPR, in the case of using suppliers based outside the European Economic Area (EEA), data transfer is carried out exclusively on the basis of legal mechanisms approved by the European Commission (Standard Contractual Clauses — EC Decision 2021/914; Data Privacy Framework for the USA; Adequacy Decisions).

Google (Analytics, Ads)USA — Data Privacy Framework + Standard Contractual Clauses (SCC)
Meta (Facebook Pixel)SUA — Data Privacy Framework + SCC
Banca TransilvaniaRomania (EU) — does not involve extra-EEA transfer

6. Data retention period

Reservation / contract data5 years calculated from July 1 of the year following the end of the financial year in which they were drawn up (art. 25 Law no. 82/1991)
Identity document data (accommodation)According to the methodological rules GEO 150/2024
Fiscal documents / invoices10 years (art. 25 Law 82/1991 + Fiscal Code — Law 227/2015)
CCTV footageMaximum 30 calendar days, if there is no incident under investigation
Analytical cookie dataMaximum 24 months (ANSPDCP recommendations)
Date marketing / newsletterUntil withdrawal of consent or deletion request
Date formular de contact12 months from the last communication, if no contractual relationship resulted

7. The rights of data subjects (art. 15-22 GDPR)

In accordance with Chapter III GDPR and Law no. 190/2018, you have the following rights:

The right of access (art. 15)You can obtain a copy of the processed data and information about purposes, recipients, duration
The right to rectification (art. 16)You can request the correction of inaccurate data or the completion of incomplete data
The right to erasure (art. 17)You can request the deletion of the data when they are no longer necessary for the initial purpose or the consent has been withdrawn
The right to restriction (art. 18)You can request the temporary suspension of processing while disputing the accuracy of the data
Data portability (art. 20)You can receive the data in a structured, common, machine-readable format (CSV/JSON)
The right to opposition (art. 21)You can always object to the processing of data for direct marketing purposes
No automated decision (art. 22)SC Pietroasa S.A. does not use exclusively automated decision systems with legal effects
Withdrawal of consent (art. 7)You can withdraw your consent at any time, without affecting the legality of the previous processing

To exercise any of these rights, send a written request to:

E-mail[email protected]
Telephone0720 999 437
The address has becomeDacia Square no. 2, Buzau, Buzau County, Romania, Attention: Data Protection Officer

You can file a complaint with the National Authority for the Supervision of Personal Data Processing (ANSPDCP): www.dataprotection.ro, e-mail: [email protected], phone: +40 318 059 211, address: B-dul G-ral. Gheorghe Magheru no. 28-30, Sector 1, Bucharest.

8. Data security

According to art. 32 GDPR, S.C. Pietroasa S.A. implement appropriate technical and organizational measures:

  • SSL/TLS secure connection (HTTPS) on the entire website www.hotelpietroasa.ro
  • Encryption of sensitive data stored in databases
  • Restricting access to data based on the need-to-know principle
  • Periodic training of personnel in the field of data protection
  • Documented procedures for responding to security incidents (data breaches)

In case of a high-risk data breach, we will notify you without undue delay (art. 34 GDPR). ANSPDCP will be notified within a maximum of 72 hours (art. 33 GDPR).

9. Modification of this policy

We reserve the right to update this Privacy Policy whenever necessary. The updated version will be published on www.hotelpietroasa.ro with the date of entry into force.

Current version2.0
Date of entry into forceMay 12, 2026
Main Applicable LawsGDPR (EU Reg. 2016/679), Law 190/2018, GEO 150/2024, Law 102/2005

Where Heritage Lives
Where Stories Begin.

  • Piața Daciei 2, Buzău, Romania
  • +40 720 999 437
  • [email protected]
Explore
  • Rooms & Suites
  • SPA & Wellness
  • Meetings & Events
  • Dining
  • Offers
Hotel Pietroasa
  • Press
Legal
  • Strategic plan for food waste management
  • Privacy Policy
  • Terms and Conditions
  • Cookies Policy
© 2026 Hotel Pietroasa. All rights reserved.
RomânăEnglish
  • Home
  • Rooms & Suites
  • Dining
  • SPA
  • Meetings & Events
  • Offers
Manage consent
To provide the best experience, we use technologies such as cookies to store and/or access device information. Consent to these technologies allows us to process data such as browsing behavior or unique IDs on this site. If you do not give your consent or withdraw your given consent it may have negative effects on certain functionalities and functions.
function Always active
Technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by a subscriber or user or for the sole purpose of executing the transmission of a communication over an electronic communications network.
Preferences
Technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
statistically
Technical storage or access that is used exclusively for statistical purposes. Technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance from your Internet Service Provider, or additional records from a third party, information stored or retrieved solely for this purpose cannot typically be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles to which we send advertising or to track the user across one or more websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
See preferences
  • {title}
  • {title}
  • {title}