Last updated: September 21, 2026
This page serves as a practical guide for exercising the rights provided by Regulation (EU) 2016/679. A full explanation of the processing activities can be found in our Privacy Policy.
Address: Calea Bucovinei nr. 148, Câmpulung Moldovenesc, Suceava County, 725100, Romania
Contact: contact@hotel-eden.ro · +40 230 314 733
1. How to submit a request
You may submit your request:
- by e-mail at contact@hotel-eden.ro, with the subject line "GDPR Request";
- by mail or in person at Calea Bucovinei nr. 148, Câmpulung Moldovenesc, Suceava County, 725100;
- through a representative, with proof of authorization.
Please mention your name, contact details, your relationship with the hotel (e.g., booking number and dates), and the right you wish to exercise. Do not send a full copy of your ID document on your own initiative. If we have reasonable doubts regarding your identity, we will request only proportional additional information, and unnecessary copies will be deleted.
2. Your rights
Access — Art. 15
You may request confirmation of whether we process your data, a copy of the data, and information regarding the purposes, categories, recipients, transfers, storage periods, and sources. Additional copies may incur a reasonable fee only in cases permitted by law.
Rectification — Art. 16
You may request the correction of inaccurate data and the completion of incomplete data. For an upcoming booking, please also contact the reception to avoid any disruption to your stay.
Erasure — Art. 17
You may request the erasure of data when it is no longer necessary, when consent is withdrawn and there is no other legal ground, when an objection is upheld, or when processing is unlawful. We cannot erase data necessary for a legal obligation, the defense of legal claims, or other cases provided for in Art. 17(3).
Restriction — Art. 18
You may request to limit the use of your data while we verify the accuracy, legality, or an objection, or when you need the data to establish, exercise, or defend legal claims.
Portability — Art. 20
For data provided by you, processed automatically based on consent or a contract, you may request it in a structured, commonly used, and machine-readable format and, where feasible, have it transmitted directly to another controller.
Objection — Art. 21
You may object, on grounds relating to your specific situation, to processing based on legitimate interest. We will stop processing unless we demonstrate compelling legitimate grounds or the necessity for legal claims. Objection to direct marketing is unconditional and takes effect for the future.
Withdrawal of consent — Art. 7
You may withdraw your consent at any time for cookies, marketing, CV storage, or optionally provided sensitive data. Withdrawal does not affect previous processing or operations based on a contract or law. For cookies, use .
Automated decision-making — Art. 22
You may request human intervention, express your point of view, and contest an exclusively automated decision that produces legal or similarly significant effects, where this right is applicable. Automated room recommendations and availability calculations can be verified by the reception.
3. Response time
We respond without undue delay and, in principle, within one month of receiving the request. For complex or numerous requests, the deadline may be extended by up to two months; we will inform you of the extension and the reasons within the first month.
If we do not comply with your request, we will inform you of the reasons and your right to file a complaint or use a judicial remedy.
4. Costs
Exercising your rights is free of charge. For manifestly unfounded or excessive requests, particularly those that are repetitive, we may charge a reasonable fee based on administrative costs or we may refuse to act on the request, in accordance with Art. 12(5) GDPR.
5. Limits and data of other persons
We will protect the rights and freedoms of others. A copy of your data may be anonymized or redacted if the document contains data about other guests. If you submit a request on behalf of someone else, we require proof of authorization; parents or legal representatives may exercise the rights of minors in accordance with the law.
6. Cookies and commercial communications
You may refuse or modify analysis and marketing at any time without affecting essential services. For commercial emails, use the unsubscribe link or write to us. Operational messages regarding your booking are not marketing and may continue as long as they are necessary for the contract.
7. Security and incident notification
If you suspect unauthorized access, immediately send details to contact@hotel-eden.ro, without including passwords or card details. We investigate incidents and notify the ANSPDCP within the legal deadline when required; if the risk to individuals is high, we will also inform the affected persons without undue delay.
8. Complaint to the supervisory authority
If you believe your rights have been violated, you may file a complaint with:
Bd. G-ral Gheorghe Magheru nr. 28-30, sector 1, 010336 Bucharest
E-mail: anspdcp@dataprotection.ro · Phone: +40 31 805 9211
www.dataprotection.ro
You may also refer the matter to the authority of the Member State of your habitual residence, place of work, or place of the alleged infringement and may pursue judicial remedies provided by law.
9. Record of requests
We keep a minimal record of the request, our verifications, and our response to demonstrate GDPR compliance and for the defense of rights, usually for 3 years from the closure of the request, and longer only if there is litigation or a legal obligation.