Privacy Policy
DOCUMENT 1 OF 3: GDPR (EU Reg. 2016/679) · Law no. 190/2018 · GEO 150/2024 · Law 102/2005. SC PIETROASA S.A. · CUI RO1153002 · www.hotelpietroasa.ro
Legal basis: Regulation (EU) 2016/679 (GDPR), art. 13-14; Law no. 190/2018 regarding GDPR implementation measures; GEO no. 150/2024 amending OG 58/1998 on tourism; Law no. 102/2005 regarding ANSPDCP. Effective date: May 12, 2026.
1. The identity and contact details of the operator
According to art. 13 para. (1) lit. a) from the GDPR, the operator of personal data for the website www.hotelpietroasa.ro is:
| Company name | SC PIETROASA S.A. |
| No. RC registration | J1991000023100 |
| CUI / VAT code | RO1153002 |
| Social headquarters | Dacia Square no. 2, Buzau, Buzau county, Romania |
| Legal representative | Coca Dragan |
| Telephone | 0720 999 437 |
| E-mail contact | [email protected] |
| Website | www.hotelpietroasa.ro |
| Legal form | Joint stock company (S.A.), established according to Law no. 31/1990 |
1.1 Data Protection Officer (DPO)
According to art. 37-39 GDPR and art. 10 of Law no. 190/2018, S.C. Pietroasa S.A. appointed a Data Protection Officer. You can contact him for any question related to the processing of your personal data:
| DPO name | Hotel Pietroasa — Responsible for Data Protection |
| DPO email | [email protected] |
| DPO phone | 0720 999 437 |
| Correspondence address | Dacia Square no. 2, Buzau, Buzau County, Romania, Attention: Data Protection Officer |
| Answer deadline | Maximum 30 calendar days; extendable by 60 days in complex cases, with prior notification (art. 12 GDPR) |
2. Categories of personal data collected
In accordance with the principle of data minimization (art. 5 para. (1) letter c) GDPR), we collect exclusively the data necessary for the purposes described below.
2.1 Data collected when booking online
- Name and surname
- Email address and phone number
- Arrival and departure date, room type (single, double, apartment, suite)
- The number of people (adults / children) and the age of the children
- Special preferences: extra bed, floor, view, dietary requirements, accessibility
- Preferred language of communication
2.2 Data collected when paying online
- Bank card data — processed exclusively by PCI-DSS certified processors; SC Pietroasa S.A. it never stores the complete card data
- Billing address (if different from contact address)
- The amount, currency, date and time of the transaction
2.3 Mandatory data collected at check-in (legal obligation)
According to GEO no. 150/2024 amending OG 58/1998 and the methodological norms regarding the record of tourists staying in tourist reception structures, we are legally obliged to record:
- Series and number of valid identity document (CI, passport, EU driving license)
- Citizenship and nationality
- Date of birth
- Home address / residence
- Purpose of visit (tourism, business, transit, other purpose)
ATTENTION: These data are collected based on a legal obligation [art. 6 para. (1) lit. c) GDPR]. The refusal to provide these data prevents the provision of accommodation services. The data are transmitted to the competent authorities according to the law.
2.4 Data collected through the website (browsing and cookies)
- The IP address of the device
- Browser type, operating system, screen resolution
- Pages visited, actions performed, session duration
- Traffic source (search engine, social networks, direct access, OTA platform)
- Data collected through cookies — detailed in Document 3 "Cookie Policy"
2.5 Data collected through the contact form / e-mail / telephone
- Name and surname
- Email address and/or phone number
- The content of the message, the requests and complaints sent
2.6 Data collected through the CCTV system
Video images of common spaces: reception, main hall, entrances, corridors, parking
Private spaces (accommodation rooms, bathrooms) are NOT under video surveillance. The existence of the CCTV system is indicated by displays at the entrance to each monitored space, according to Law no. 333/2003 regarding the protection of objectives, republished.
2.7 Special categories of data (art. 9 GDPR)
SC Pietroasa S.A. does not intentionally collect data from special categories (health, racial origin, religious beliefs, etc.). If you communicate such data (eg: medical dietary requirements), they will be used exclusively for the provision of the requested service.
3. Purposes of processing and legal basis
A. Execution of the contract [art. 6 para. (1) lit. b) GDPR]
- Processing, confirmation and management of reservations made on www.hotelpietroasa.ro
- Communications regarding the reservation: written confirmation, modification, cancellation, fiscal invoice
- Check-in and check-out
- Processing payments and issuing fiscal documents
- Management of special requests and accommodation preferences
- Resolving complaints related to purchased services
B. Legal obligations [art. 6 para. (1) lit. c) GDPR]
- Registration and reporting of tourist identity data according to GEO 150/2024
- Keeping accounting and fiscal documents: Law no. 82/1991 and Law no. 227/2015 (Fiscal Code)
- Communication of data at the request of ANAF, the Police, ANT or other competent authorities
- Compliance with tourist classification obligations: ANT order no. 65/2013, amended by Order no. 510/2022
C. Interese legitime [art. 6 alin. (1) lit. f) GDPR]
- Fraud prevention and hotel property security
- Video surveillance (CCTV) of common spaces — security and property protection
- Improving services through anonymized statistical analysis of behavior on the website
- Defense of S.C. rights Pietroasa S.A. before the courts
D. Consent [art. 6 para. (1) lit. a) GDPR]
- Sending newsletters and promotional offers by e-mail or SMS
- Use of analysis and marketing cookies (detailed in Document 3)
- Publishing customer reviews and photos on the website or social networks
The consent can be withdrawn at any time, without affecting the legality of the processing prior to the withdrawal (art. 7 para. (3) GDPR).
4. Recipients of personal data
According to art. 13 para. (1) lit. e) GDPR, your data may be disclosed to the following categories of recipients:
| Payment processors | PCI-DSS certified processors — for secure processing of card transactions |
| IT providers / hosting | The provider of the reservation platform and the website, with a processing contract according to art. 28 GDPR |
| Public authorities | ANAF, Police, ANT, health authorities — exclusively upon express legal request |
| Accountant / auditor | External accounting firm, based on the confidentiality agreement |
| OTA platforms | Booking.com, Expedia and other online distribution platforms — for reservations made through them |
| E-mail marketing | Newsletter service providers — exclusively for customers who have expressed their consent |
| Insurer / legal | In case of litigation, insurance claims or legal proceedings |
SC Pietroasa S.A. does not sell, rent or transfer your personal data to third parties for their own commercial purposes.
5. International data transfers
According to art. 44-49 GDPR, in the case of using suppliers based outside the European Economic Area (EEA), data transfer is carried out exclusively on the basis of legal mechanisms approved by the European Commission (Standard Contractual Clauses — EC Decision 2021/914; Data Privacy Framework for the USA; Adequacy Decisions).
| Google (Analytics, Ads) | USA — Data Privacy Framework + Standard Contractual Clauses (SCC) |
| Meta (Facebook Pixel) | SUA — Data Privacy Framework + SCC |
| Banca Transilvania | Romania (EU) — does not involve extra-EEA transfer |
6. Data retention period
| Reservation / contract data | 5 years calculated from July 1 of the year following the end of the financial year in which they were drawn up (art. 25 Law no. 82/1991) |
| Identity document data (accommodation) | According to the methodological rules GEO 150/2024 |
| Fiscal documents / invoices | 10 years (art. 25 Law 82/1991 + Fiscal Code — Law 227/2015) |
| CCTV footage | Maximum 30 calendar days, if there is no incident under investigation |
| Analytical cookie data | Maximum 24 months (ANSPDCP recommendations) |
| Date marketing / newsletter | Until withdrawal of consent or deletion request |
| Date formular de contact | 12 months from the last communication, if no contractual relationship resulted |
7. The rights of data subjects (art. 15-22 GDPR)
In accordance with Chapter III GDPR and Law no. 190/2018, you have the following rights:
| The right of access (art. 15) | You can obtain a copy of the processed data and information about purposes, recipients, duration |
| The right to rectification (art. 16) | You can request the correction of inaccurate data or the completion of incomplete data |
| The right to erasure (art. 17) | You can request the deletion of the data when they are no longer necessary for the initial purpose or the consent has been withdrawn |
| The right to restriction (art. 18) | You can request the temporary suspension of processing while disputing the accuracy of the data |
| Data portability (art. 20) | You can receive the data in a structured, common, machine-readable format (CSV/JSON) |
| The right to opposition (art. 21) | You can always object to the processing of data for direct marketing purposes |
| No automated decision (art. 22) | SC Pietroasa S.A. does not use exclusively automated decision systems with legal effects |
| Withdrawal of consent (art. 7) | You can withdraw your consent at any time, without affecting the legality of the previous processing |
To exercise any of these rights, send a written request to:
| [email protected] | |
| Telephone | 0720 999 437 |
| The address has become | Dacia Square no. 2, Buzau, Buzau County, Romania, Attention: Data Protection Officer |
You can file a complaint with the National Authority for the Supervision of Personal Data Processing (ANSPDCP): www.dataprotection.ro, e-mail: [email protected], phone: +40 318 059 211, address: B-dul G-ral. Gheorghe Magheru no. 28-30, Sector 1, Bucharest.
8. Data security
According to art. 32 GDPR, S.C. Pietroasa S.A. implement appropriate technical and organizational measures:
- SSL/TLS secure connection (HTTPS) on the entire website www.hotelpietroasa.ro
- Encryption of sensitive data stored in databases
- Restricting access to data based on the need-to-know principle
- Periodic training of personnel in the field of data protection
- Documented procedures for responding to security incidents (data breaches)
In case of a high-risk data breach, we will notify you without undue delay (art. 34 GDPR). ANSPDCP will be notified within a maximum of 72 hours (art. 33 GDPR).
9. Modification of this policy
We reserve the right to update this Privacy Policy whenever necessary. The updated version will be published on www.hotelpietroasa.ro with the date of entry into force.
| Current version | 2.0 |
| Date of entry into force | May 12, 2026 |
| Main Applicable Laws | GDPR (EU Reg. 2016/679), Law 190/2018, GEO 150/2024, Law 102/2005 |