Last updated: September 21, 2026
This policy explains in plain language how ALIMONI TURISM SRL processes the data of visitors, customers, guests, contact persons, and candidates through the website, bookings, and hotel services. It applies in conjunction with our Cookie Policy and the GDPR — your rights page.
Registered Office: Calea Bucovinei no. 148, Câmpulung Moldovenesc, Suceava county, 725100, Romania
Contact: contact@hotel-eden.ro · +40 230 314 733
1. The Data Controller and point of contact
ALIMONI TURISM SRL is the data controller for the data used to provide and manage the services of Hotel Eden Garden & Spa 4★ and Hotel Eden 3★. For any requests regarding personal data, please write to contact@hotel-eden.ro, with the subject line "Data Protection", or use the postal address above.
2. Data we may process
- Identification and contact data: first name, last name, e-mail, phone number, address, billing details, and signature when required.
- Stay details: hotel, room, dates, number of adults and children, children’s ages, rate plan, services, preferences, and special requests.
- Details of other guests: information necessary for the booking and, upon arrival, data required by the legal check-in/check-out form, verified against an identity document.
- Order and payment data: value, currency, status, transaction ID, method, and limited information about the payment instrument. We do not store the full card number or the CVV code.
- Communications: messages, requests, complaints, responses, communication preferences, and records of interactions with the reception, if documented.
- Technical data: IP address, browser, device, pages visited and actions taken, cookie identifiers, security logs, source of the visit, and consent provided.
- Job applications: CV, experience, education, desired position, and information provided voluntarily during the recruitment process.
- On-site data: data necessary for access and safety and, in signed areas, CCTV footage, if the system is active.
Please do not include sensitive data or copies of identity documents in open fields unless requested. If you provide health-related data regarding accessibility, allergies, or other special requirements, we use it only to manage your request and, when necessary, based on your explicit consent or another ground permitted by Art. 9 of the GDPR.
3. Purposes and legal grounds
| Purpose | Typical data | Legal basis |
|---|---|---|
| Checking availability, offers, and booking | dates, occupancy, children's ages, contact, room, rate | pre-contractual steps and performance of a contract — Art. 6(1)(b) GDPR |
| Payment, billing, accounting, and tax obligations | order, payment, and billing details | contract and legal obligation — Art. 6(1)(b) and (c) |
| Guest registration and safety | identity, check-in/check-out, hosted persons | legal obligation, including Government Decision no. 237/2001 — Art. 6(1)(c) |
| Answering questions, requests, and complaints | contact and content of the communication | contract/pre-contractual steps and legitimate interest in administration — Art. 6(1)(b) and (f) |
| Site security, fraud prevention, and legal defense | IP, logs, orders, communications | legitimate interest and legal obligations — Art. 6(1)(f) and (c) |
| Analysis, personalization, and marketing | online identifiers and interactions | consent — Art. 6(1)(a) and Law no. 506/2004; you may refuse without losing access to essential functions |
| Recruitment | CV and communications | steps at the candidate's request — Art. 6(1)(b); consent for future opportunities, where required |
When we rely on legitimate interest, we pursue the safe and efficient operation of our services, the prevention of abuse, and customer relationship management, without overriding your rights and freedoms. You may request information regarding the assessment of this interest and may object under the conditions of Art. 21 of the GDPR.
4. Source of the data
We receive data directly from you, from the person booking for a group, from Shopify, PynBooking, and the payment processor, as well as from agencies or platforms through which you chose to book. We may also receive data from authorities or partners when it is legal and necessary to resolve a situation.
5. Mandatory data
Fields marked as mandatory are necessary for the respective request. Without contact, occupancy, period, and payment data, we cannot conclude or execute the booking. Refusal to provide the data required for check-in may make the legal registration of the guest impossible. Consent for analysis and marketing is optional and does not condition the booking.
6. To whom we may disclose data
- Shopify, for hosting, cart, checkout, orders, security, and privacy tools. For Shopify's own processing, please consult the Shopify Consumer Privacy Policy.
- PYNBOOKING NET SRL / PynBooking, for availability, rates, and booking management, as a data processor for hotel client data. PynBooking describes this role in its Data Processing Annex pursuant to Art. 28 GDPR.
- Payment processors and financial institutions, depending on the method chosen at checkout.
- Operational providers for e-mail, IT, security, accounting, auditing, archiving, and consulting, only to the extent necessary.
- Google, when you load maps or Google resources; these services may receive your IP address and technical data according to their own policies.
- Public authorities, courts, and law enforcement agencies, if we have a legal obligation or a valid request.
We do not sell or rent your data. Third-party platforms through which you book may act as independent controllers; please check their policy before providing data to them.
7. Transfers outside the European Economic Area
Some international providers, including platform and infrastructure providers, may process data outside the EEA. We use the mechanisms provided by Chapter V of the GDPR, as applicable: adequacy decisions, Standard Contractual Clauses, and additional measures. You can ask for information about the relevant guarantee using our contact details.
8. How long we keep data
- Bookings and contractual communications: for the duration of the stay and, typically, 3 years after completion or cancellation, corresponding to the general limitation period for legal claims, unless there is a dispute or a longer legal obligation.
- Financial-accounting documents: 5 years calculated from July 1st of the year following the financial year in which they were drawn up, or the legal period applicable at that time.
- Guest records: for the period imposed by applicable regulations and thereafter only if there is another legal basis.
- Messages without bookings: generally up to 2 years from the last correspondence.
- Job applications: for the duration of the recruitment; for future opportunities, a maximum of 12 months or until withdrawal of consent.
- Security logs: as long as necessary for the investigation and protection of the service, typically up to 12 months, and longer only if there is an incident or legal obligation.
- Cookies: according to the durations in the Cookie Policy.
Upon the expiry of the period, the data is deleted, anonymized, or isolated from current use, with the exception of backup copies that are overwritten according to the technical cycle.
9. Automated decisions
Availability, rates, and room recommendations are calculated automatically from the data entered and the PynBooking inventory. These calculations do not represent an exclusively automated decision with legal effects in the sense of Art. 22 of the GDPR; you may request a verification by the reception at any time.
10. Children and companion data
Online booking is performed by an adult. We process children's ages for occupancy and rate purposes, and the identification data of all guests upon check-in, as required by law. The person booking must be authorized to provide this data to us and inform the parent/legal representative, as appropriate.
11. Your rights
Under the conditions of the GDPR, you have the right to access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and the right not to be subject to a decision based solely on automated processing which produces legal effects or similarly significantly affects you. Rights are not absolute; for example, we cannot delete documents that the law requires us to keep.
The complete procedure, timelines, and request form are available on the GDPR — your rights page.
12. Security and incidents
We apply technical and organizational measures proportional to the risk: encrypted connections, access control, authentication, backups, data limitation, and contractual collaboration with providers. No system can guarantee absolute security. If an incident presents a high risk to your rights, we will inform you in accordance with Art. 34 of the GDPR.
13. Complaints
We recommend that you contact us first so that we can resolve the situation quickly. You have the right to lodge a complaint with the ANSPDCP (National Supervisory Authority for Personal Data Processing), Bd. G-ral Gheorghe Magheru no. 28-30, sector 1, 010336 Bucharest, e-mail anspdcp@dataprotection.ro, or with the competent authority in the state where you live or work.
14. Updates
We may update this policy when our services, providers, or laws change. The current version date is displayed in the header. For major changes, we will use proportional notification before the new processing begins, where the law requires it.