Privacy & data protection
The short version: this site asks you for nothing, tracks nothing, and uses no analytics or advertising cookies. Personal data only reaches us when you write or call to book. The full detail is below.
Last updated:
1. Who handles your data
The data controller is “Pensiunea Doina”, a guesthouse at Str. Șugău nr. 75, Sighetu Marmației, Maramureș, cod poștal 435503, Romania.
For anything to do with your data, write to us at [email protected] or call +40 730 117 052.
2. What the website itself collects
Nothing. There are no forms, no user accounts, no newsletter, and no analytics or advertising tools. You can read every page without telling us anything about yourself.
The site sets no cookies of its own and writes nothing to your browser’s storage. That is why you will not see a cookie banner here — there is nothing for us to ask you to accept.
As with any website, the server that hosts it keeps technical access logs (IP address, browser type, time of access), purely for operation and security. We do not use those logs to identify or profile you.
3. What we receive when you contact us
When you email us, message us on WhatsApp or ring to book, we receive whatever you choose to give us:
- your name
- a phone number and/or an email address
- details of the stay: dates, how many of you, preferences, anything special (including dietary requirements, if you tell us)
- on arrival, your identity document details, which Romanian law requires us to record in the guest register
The legal basis is performance of the accommodation contract (GDPR art. 6(1)(b)) for the booking and the stay, and legal obligation (GDPR art. 6(1)(c)) for the guest register and for tax records.
If you tell us about dietary requirements for medical reasons, that may count as health data. We use it for one thing only — cooking something that suits you — and delete it after your stay.
4. How long we keep it
- Messages and booking enquiries: as long as we need them for our correspondence with you and to organise the stay, then we delete them.
- Tax and accounting records: 10 years, as Romanian accounting law requires.
- The guest register: for the period set by the regulations in force.
You can ask us at any time to delete our correspondence with you, within the legal retention limits above.
5. Who else sees it
We do not sell or rent your data to anyone, and we do not use it for marketing. It does, unavoidably, pass through a few service providers that the site and the bookings depend on:
- Cloudflare Hosts the website and the photographs. Processes visitors’ IP addresses to deliver the pages and for security.
- Google — Fonts The site loads its typefaces from Google’s servers. Your IP address is sent to Google when a page loads.
- Google — Maps The map in the contact section is embedded from Google. When a page with the map loads, Google receives your IP address and may set its own cookies.
- PYNbooking — the booking system An outside provider. If you book through it, whatever you enter there is handled under their policy, not this one.
- WhatsApp (Meta) Only if you choose to message us on WhatsApp. The conversation is handled by Meta under their own policy.
- Yahoo Our email address is hosted by Yahoo, so messages you send us pass through their servers.
Beyond that, data may be shared with our accountant and, where the law requires it, with public authorities.
Some of these providers are companies outside the European Economic Area. Transfers rely on the mechanisms the GDPR provides, principally the standard contractual clauses adopted by the European Commission.
6. Photographs of guests
The site shows photographs taken at the guesthouse, some of them of groups of guests. We publish them only with the agreement of the people in the picture.
If you recognise yourself in a photograph and would rather not be there, write to us and we will take it down — no explanation needed, no delay.
7. Your rights
Under Regulation (EU) 2016/679 you have the right to:
- access — to find out what data we hold about you
- rectification — to have inaccurate data corrected
- erasure (“the right to be forgotten”), within our legal retention obligations
- restriction of processing
- data portability
- object to certain processing
- withdraw your consent, where the processing relies on it
- lodge a complaint with the supervisory authority
To exercise any of these, write to us at [email protected]. We reply within one month of receiving your request.
- A.N.S.P.D.C.P. — the Romanian data protection authority Where you can complain if you believe we have not respected your rights.
8. Keeping it safe
The site is served only over an encrypted connection (HTTPS). Access to the guesthouse’s correspondence and records is limited to the people who need it to do their work.
No system is perfectly secure, but we take reasonable measures — proportionate to a family guesthouse — to protect your data.
9. Changes to this policy
We will update this document whenever the way we handle data changes — if we add a contact form, for instance, or an analytics tool. The date of the last update is shown at the top of this page.