Demo version — bookings and payments are for testing only.

Template — requires legal review before publication

Passages on a yellow background must be filled in before publication.

Legal information

Privacy policy

Version: 2026-10-04

Here we explain in plain language who processes your data, why, on what basis and for how long, when you browse this website or book a stay at the Romanka guesthouse. We describe it as our booking system really works.

Contents

1.Who is responsible for your data

The controller of your personal data is: [TO BE COMPLETED: name / full name, address, tax ID (NIP), e-mail] (the “Controller”).

For anything to do with your personal data, write to kontakt@romanka.local, call +48 000 000 000 or write to: ul. Świerkowa 1, 34-350 Żabnica.

[TO BE COMPLETED: whether a data protection officer has been appointed; if not, state that the Controller has not appointed one]

2.What data we process

Booking data
First and last name, e-mail address, phone number, country, notes you enter in the form, dates of the stay, rooms chosen, the number of adults and children (numbers only, no data about children), booking number, price, and the amounts and status of payments.
Consents and acceptances
The date and time you accepted the terms, with their version, and, only if you tick it, your marketing consent.
Payment data
Online payments are handled by Przelewy24. We do not see or store your card number or online-banking login. From the operator we receive only the status and amount of the payment.
Data from Booking.com and Airbnb
If you book through those platforms, we receive from them (through our booking synchronisation system) the data needed to welcome you at the Property: name, contact details, dates and number of guests.
Correspondence
The content of e-mails and the details you give during a phone call, if you contact us.
Abuse protection
A hash of your IP address: a one-way hash made with a secret salt, from which we do not recover the address (the IP address itself is not stored in our database). It is used to limit the number of requests and the number of unpaid bookings held at the same time from one address.
Admin logs
The staff panel records who changed a setting or a booking and when (the staff member’s e-mail address, the kind of action, an identifier). The logs contain no guest data, and the application’s own logs contain no personal data.
Server logs
[TO BE COMPLETED ONCE HOSTING IS CHOSEN: whether the hosting provider records IP addresses in server logs, and for how long]

Giving the data needed for a booking is voluntary, but without it we cannot accept the booking. Marketing consent is entirely voluntary and does not affect whether you can book. We do not ask for an ID card or passport number online.

Concluding and performing the accommodation contract
Booking, payment, confirmation, booking status and contact about your stay. Legal basis: Art. 6(1)(b) GDPR (necessary for the performance of a contract or for steps taken before entering into it).
Legal obligations
Keeping accounts and tax records, including settling the tourist tax. Legal basis: Art. 6(1)(c) GDPR.
Security, abuse prevention and claims
Protecting the booking form against bots and against dates being blocked, the log of changes in the system, and establishing, pursuing and defending legal claims. Legal basis: Art. 6(1)(f) GDPR (the legitimate interest of the Controller). You have the right to object to this processing (see Your rights).
Marketing
We send commercial information about the guesthouse only with your separate consent. Legal basis: Art. 6(1)(a) GDPR. Consent is voluntary, unticked by default, and you can withdraw it at any time; withdrawing does not affect the lawfulness of processing before the withdrawal.

4.Who receives your data

We pass data only to those who are needed to handle a booking. Those acting on our behalf process it under a data processing agreement.

Hosting and database
[TO BE COMPLETED: name of the hosting and database provider and the location of the servers]. Stores booking data and runs the website.
E-mail sending
[TO BE COMPLETED: name of the e-mail sending provider]. Sends confirmations and booking-status messages.
Przelewy24 (PayPro S.A.)
Online payment operator. We pass it your e-mail address, the amount and the payment title (booking number), and the return address of the booking status page that you are sent back to after paying; that address contains the access key to your booking. You enter card or bank details only with it. It processes payment data on its own terms, under its own privacy policy.
Beds24 (booking synchronisation system)
A channel manager. It synchronises room availability with Booking.com and Airbnb and passes to us the bookings made on those platforms. We send it only availability, prices and the minimum number of nights, with no guest data from our own form.
Booking.com and Airbnb
If you book through those platforms, they are separate controllers of your data for their own services; see their privacy policies.
Cloudflare Turnstile
A tool that protects the booking form against bots (provider: Cloudflare, Inc.). While you fill in the form it may process technical data of your browser, and our server passes a verification token and your IP address to Cloudflare to check the result. Legal basis: Art. 6(1)(f) GDPR.
OpenTopoMap and Waymarked Trails (maps)
The map of the area loads as you approach the “Contact” section while scrolling, and a route map only after you click the name of a trail. Then your browser fetches map tiles from the OpenTopoMap and Waymarked Trails servers, which may process your IP address and technical data under their own rules.
Accounting
[TO BE COMPLETED: accounting firm or tax adviser, if we use one].
Public authorities
We disclose data to authorities and bodies entitled to it by law.

5.Transfers outside the EEA

[TO BE COMPLETED: information about transfers of data outside the European Economic Area (e.g. to the USA: Cloudflare, Inc.) and the safeguards used, e.g. a European Commission adequacy decision or standard contractual clauses]

6.How long we keep data

Booking data
For 36 months after the day of departure, so that we can show the contract was performed and defend against claims. After that we anonymise it automatically: first name, last name, e-mail, phone and notes are replaced with an anonymous marker. The amounts and dates of the stay remain, without personal data.
Unpaid and expired bookings
Bookings that did not go ahead (expired, or cancelled without a payment) are anonymised 30 days after the booking was made.
Accounting and tax records
For the period required by tax and accounting law.
Marketing consent
Until you withdraw it, and no longer than until the booking it comes from is anonymised.
IP address hashes
In the request-limit register: one day at most. With a booking: until the hold on the rooms ends, at the latest 48 hours.
Correspondence
For as long as needed to handle the matter, and then until the limitation periods for claims have passed.
Admin logs
[TO BE COMPLETED BY THE OWNER: how long panel logs are kept, e.g. 5 years]

7.Your rights

You have:

  • the right of access to your data and to receive a copy of it (Art. 15 GDPR);
  • the right to have your data rectified (Art. 16);
  • the right to have your data erased (Art. 17), unless a rule requires us to keep it, as with accounting records;
  • the right to restrict processing (Art. 18);
  • the right to data portability (Art. 20): we will give it to you in a structured format, e.g. JSON;
  • the right to object to processing based on a legitimate interest (Art. 21);
  • the right to withdraw consent at any time (Art. 7(3)), without affecting the lawfulness of processing before the withdrawal;
  • the right to lodge a complaint with the supervisory authority: the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, PUODO), ul. Stawki 2, 00-193 Warszawa, Poland, uodo.gov.pl.

To use these rights, write to kontakt@romanka.local. We will reply without undue delay, and within one month at the latest (Art. 12(3) GDPR). If needed, we will ask for information confirming your identity, such as the booking number and the e-mail address used for the booking.

We do not profile guests or make automated decisions about them that have legal effects (Art. 22 GDPR).

8.Cookies

  • The public website sets no cookies and uses no analytics or advertising tools, which is why we show no cookie banner.
  • Fonts are hosted by us and are not fetched from external servers. The maps (OpenTopoMap, Waymarked Trails) load only as you approach the “Contact” section or when you open a route map.
  • The booking form uses Cloudflare Turnstile, which may process technical data of your browser (e.g. IP address and browser parameters) to tell a human from a bot.
  • The staff panel (available only to the Property’s staff) uses only strictly necessary session cookies, which keep you signed in. They are not used for tracking and need no consent.

9.Data security

Among other things, we protect data like this:

  • connections to the website are encrypted (HTTPS);
  • only authorised people can open bookings in the panel, and signing in requires two-factor authentication;
  • we store only a hash of the access key to the booking status page in our database; the key itself is in the link we e-mail to you and in the payment return address;
  • IP addresses are stored only as a hash made with a secret salt;
  • card and bank-account data never reach our systems.

10.Changes to this policy

We always publish the current version of this policy on this page. Current version: 2026-10-04.