Privacy Policy
How Villa Severka processes and protects your personal data (GDPR).
We value the privacy of all individuals and respect their right to the protection of personal data. In processing personal data, the operator acts in accordance with Act No. 18/2018 Coll. on the protection of personal data and on amendments to certain acts, and with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the General Data Protection Regulation), (hereinafter the "Act").
In connection with our activities, we process personal data for various purposes. In most cases the processing of personal data is necessary under a specific regulation or an international treaty by which the Slovak Republic is bound.
The operator processes personal data only on lawful legal bases: the performance of a contract or pre-contractual measures; compliance with our legal obligation under a specific regulation; the performance of a task carried out in the public interest; the pursuit of our legitimate interests, provided these are not overridden by the legitimate interests of the data subject; or where it is necessary to protect the life, health or property of the data subject or another natural person. In other cases we process the personal data of data subjects only with the data subject's consent, which the data subject may withdraw at any time.
1. Who is the controller of your data?
The controller who determines the purposes and means of processing your personal data is:
- Name: Tatiana Tursunovová
- Registered office: Dankovského 9, 811 03 Bratislava
- Company ID (IČO): 43291317
- E-mail: info@villaseverka.sk
- Phone: +421 908 105 084
2. What data do we collect and for what purpose?
We process your data only to the extent necessary for the following purposes:
| Purpose of processing | Legal basis | Categories of data | Retention period |
|---|---|---|---|
| Reservation and provision of accommodation | Performance of a contract (Art. 6(1)(b) GDPR) | Name, surname, e-mail, phone number, permanent address, payment details. | For the duration of the contractual relationship and until all obligations are settled. |
| Keeping the house book and reporting of stays | Compliance with a legal obligation (Art. 6(1)(c) GDPR) | ID card/passport number, date of birth, nationality (for foreign nationals). | According to specific regulations (standardly 5 years). |
| Accounting and tax agenda | Compliance with a legal obligation (Art. 6(1)(c) GDPR) | Billing data, name, address. | 10 years following the year to which they relate. |
3. Who has access to your data? (Recipients)
Your personal data is safe with us. However, to ensure the running of the accommodation we must, to the necessary extent, provide it to selected partners (processors):
- Providers of online reservation systems and web hosting.
- An external accounting office / accountant.
- State authorities and institutions (e.g. the local authority for the accommodation fee, the foreign police), where required by law.
We do not sell your personal data, do not trade in it and do not transfer it to third countries outside the EU/EEA.
4. Your rights as a data subject
In connection with the processing of personal data you have the following rights under the GDPR:
- Right of access: you have the right to know what data we process about you.
- Right to rectification: if your data is incorrect, we will correct it at any time.
- Right to erasure: you can request the deletion of data if it is no longer needed for the stated purposes (does not apply to legal obligations).
- Right to restriction of processing: in specific cases you can request a restriction on the use of your data.
- Right to object: you have the right to object to processing for direct marketing purposes.
- Right to lodge a complaint: you have the right to contact the Office for Personal Data Protection of the Slovak Republic.
5. The security of your data
We use an encrypted connection on the website (an SSL certificate), only authorised persons have access to the databases, and physical documents are securely locked away.
This policy is effective from: 15 June 2026