Privacy Policy
Effective from: 2026-08-09
Accommodation provider: Business system s. r. o., Bystrická 27, 841 07 Bratislava – Devínska Nová Ves city district, Slovak Republic. Company ID (IČO) 47 571 420, Tax ID (DIČ) 2024008998, registered in the Commercial Register of the City Court Bratislava III, Section Sro, Insert No. 96388/B. Email business.system.sro@gmail.com, telephone +421 903 788 711. We operate apartments under the brand T&O Apartments at the website toapartments.eu. Full identification details are on the Contact page.
The controller has not appointed a Data Protection Officer (DPO), unless that obligation arises under Article 37 of the GDPR. Requests from data subjects should be sent to business.system.sro@gmail.com.
1. Scope of this policy
This policy applies to direct and platform bookings, communication with guests, accommodation, statutory guest registration, payments, complaints and visits to the website toapartments.eu. Booking platforms and payment providers may act as independent controllers in their own processing.
2. What personal data we process
- identification and contact data — name, surname, address, email, telephone, where necessary date of birth;
- booking data — apartment, dates, number of guests, special requests, arrival time and booking change history;
- guest registration book data — name, surname, ID card or travel document number, permanent address and length of stay; for foreign nationals also nationality, date of birth and residence notification data including the signature on the official form;
- payment and accounting data — amount, currency, payment status, transaction identifier, billing details and accommodation tax data; complete payment card data is processed exclusively by the payment institution;
- communication, complaints and evidence — messages, any photographs of defect or damage, resolution record;
- website technical data — IP address, device and browser type, security logs and cookie identifiers.
Do not provide special categories of data (for example health data) unless they are necessary for a specific request. We do not operate camera systems in apartments or common areas. We process electronic records of door opening only to the extent generated by the apartment lock and only for security purposes.
3. Purposes, legal bases and retention periods
- Inquiry, booking and stay — contact and booking data, communication. Legal basis: contract performance, Article 6(1)(b) of the GDPR. Period: during booking and stay, then as a rule 3 years to protect legal claims.
- Payments, accounting and taxes — transaction, invoice, stay and accommodation tax data. Legal basis: legal obligation, Article 6(1)(c). Period: accounting records 10 years after the end of the relevant accounting period.
- Guest registration book and residence notification for foreign nationals — identity, document, nationality, length of stay. Legal basis: legal obligation under Act No. 253/1998 Coll. and Section 113 of Act No. 404/2011 Coll. Period: the statutory inspection and archival period; completed stay notification forms with signature are removed from our systems after the set retention period and at the latest together with anonymization of guest data.
- Online registration before arrival — unapproved and unused registration submissions are automatically deleted within 90 days.
- Complaints and legal claims — booking, messages, photographs. Legal basis: Article 6(1)(b), (c) and (f). Period: until closure of the matter and as a rule 3 years, longer if proceedings are ongoing.
- Security and fraud prevention — logs, accesses, incidents. Legal basis: legitimate interest, Article 6(1)(f). Period: operational logs as a rule 90 days, internal notification records 180 days, incident record until expiry of claims.
- Internal record of changes (audit) — who and when changed a record. Legal basis: legitimate interest. Period: as a rule 2 years.
- Photographs from cleaning and maintenance — documentation of apartment condition. Legal basis: legitimate interest. Period: 1 year (cleaning), 2 years (fault and damage records).
- Essential cookies — cookie, IP, security log. Legal basis: necessity of service expressly requested by the user. Period: session or technically required period.
- Analytical cookies — online identifiers and website activity. Legal basis: consent under Section 109(8) of Act No. 452/2021 Coll. Period: until withdrawal of consent or until expiry of the specific cookie.
After the end of stay and expiry of the stated periods, the guest's personal data is anonymized; at the latest this occurs 10 years after departure, which corresponds to statutory limitation and archival periods. We will delete or anonymize data earlier if the purpose ceases to exist and there is no obligation or legitimate need for further retention. Backup copies are overwritten according to the backup cycle.
4. Data sources
We obtain data directly from the guest, from the person making the reservation for a group, from the booking platform, from the payment provider, from the corporate customer or automatically when using the website. Anyone providing the data of other guests must inform them about this policy.
5. Recipients and processors
We disclose personal data only to the necessary extent and on the basis of a data processing agreement:
- booking platforms and channel manager — Booking.com, Airbnb, Beds24 (synchronization of bookings and availability);
- payment institutions and banks — Stripe Payments Europe, Ltd. (card payments) and the accommodation provider's bank (transfers, QR payments);
- hosting and infrastructure — Hetzner Online GmbH, servers in the European Union;
- email communication — Google Ireland Ltd. (Gmail / Google Workspace);
- machine processing of documents during guest registration — Google Cloud Vision, processing on a European endpoint; image data is not retained, only the text result is transferred;
- website analytics — Google Analytics 4, activated exclusively upon granting consent to analytical cookies;
- internal operational team notifications — Telegram (guest name, apartment and dates to the extent necessary for operations);
- machine translation of website content — Anthropic (Claude); only editorial content is translated, not guest personal data;
- accountant, cleaning, maintenance and emergency services — to the necessary extent;
- public authorities — the Capital City of Bratislava (accommodation tax), the Police Force of the Slovak Republic (residence notification for foreign nationals), tax, court and supervisory authorities, if required by law;
- legal advisors, insurance companies and auditors — in case of specific claims.
We do not sell or provide personal data to third parties for their own marketing purposes.
6. Transfers outside the EEA
We process data primarily in the European Union. If any of the mentioned suppliers processes data outside the European Economic Area, the transfer is carried out on the basis of a European Commission adequacy decision, standard contractual clauses and, if necessary, supplementary measures. Information on specific safeguards can be requested at business.system.sro@gmail.com.
7. Cookies and online technologies
We use essential cookies for the website to function and for security. Analytical cookies are activated only after your demonstrable consent. Details, including a list of the specific cookies, are in our Cookie Usage Policy.
8. Direct marketing
We currently do not operate a newsletter or advertising email campaigns. We only send service communications related to a specific booking (confirmation, payment reminders, arrival instructions, request for feedback after stay). Should we introduce marketing communications in the future, we will request separate consent with the option of simple and free opt-out.
9. Automated decision-making
We do not perform automated decision-making or profiling with legal or similarly significant effect on the data subject.
10. Security
We use appropriate technical and organizational measures, in particular role-based access control, two-factor authentication for administrator accounts, encrypted transmission (HTTPS), encrypted backups, regular updates, data minimization, agreements with processors and a process for handling security incidents. Data breaches are handled in accordance with Articles 33 and 34 of the GDPR.
11. Data subject rights
- right of access and copy of data;
- right to rectification and completion;
- right to erasure if there is no legal obligation or other reason for retention;
- right to restrict processing;
- right to data portability if legal conditions are met;
- right to object to processing based on legitimate interest;
- right to withdraw consent at any time with effect for the future.
Send your request to business.system.sro@gmail.com. We may reasonably verify your identity. We respond without undue delay, as a rule within one month; for complex requests the period may be extended in accordance with the GDPR. Please note that we cannot delete data from the guest registration book or the residence notification forms before the statutory period expires.
A complaint can be filed with the Office for the Protection of Personal Data of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27, dataprotection.gov.sk. Contacting the controller first is not a precondition.
12. Obligation to provide data and children
Data marked as mandatory during booking and registration is necessary to conclude the contract or to fulfill the legal registration obligation. Without it, the booking cannot be confirmed or the stay legally provided. Optional cookies are voluntary. The booking is made by an adult; data of minor guests is processed only to the necessary extent with the participation of a responsible adult.
13. Changes to this policy
The current version of this policy is always available on this page and states the effective date. A material change will not be applied retroactively in violation of the law. If new consent is required, we will request it separately.
Legal framework: Regulation (EU) 2016/679 (GDPR); Act No. 18/2018 Coll.; Act No. 253/1998 Coll.; Section 113 of Act No. 404/2011 Coll.; Section 109(8) of Act No. 452/2021 Coll.