Skip to content

Data protection

Privacy policy

This policy explains which personal data we process through hotelcorvaris.ro and in connection with a booking, why, for how long, and what your rights are. It follows Regulation (EU) 2016/679 (GDPR) and Romanian Law no. 190/2018.

1. Who processes your data

The data controller is CORVARIS GROUP S.R.L., VAT no. RO17014132, trade register J40/20202/2004, registered office Șoseaua Olteniței nr. 125, Sector 4, 041306 București, România, which operates Hotel Corvaris (3-star hotel).

For any question or request about your data, write to office@hotelcorvaris.ro or call +40 21 332 51 46. We are not legally required to appoint a data protection officer (DPO); requests are handled by the hotel's management.

2. What we process, why and for how long

Booking request sent through the site — in two steps. When checking availability, your browser sends our server your dates, guest and room counts, room type and language; the server queries PynBooking using the dates, language, currency and hotel identifier and does not send your name or contact details at this stage. When you submit the request, we send PynBooking your name, email, phone, address, country, stay details and notes, including your breakfast preference, and the request is recorded as a pending booking in the hotel's reservation system. Fields marked * are required to process a request through the form; notes are optional; without the required fields you can contact reception by phone or email. Purpose: checking availability and recording the booking request. Legal basis: art. 6(1)(b) GDPR (steps at your request before a contract and performance of it). Retention: requests that do not result in a booking are kept for 12 months from the request date; for accepted bookings, operational data is kept for 12 months after check-out, and the tax and accounting records of the stay are kept for the statutory archiving period (currently 5 years under Romanian Accounting Law no. 82/1991), under art. 6(1)(c) GDPR.

Booking on the official booking site (hotel-corvaris.pynbooking.direct) — the data you enter there is processed for the same purpose and on the same basis, in the PynBooking system provided to the hotel. If you choose to pay online on that site, card data is handled solely by the platform's payment processor; hotelcorvaris.ro never sees or stores card data.

Contact form — the form attempts to open your email app with your name, the address you entered, the subject and the message prepared; it sends nothing automatically. We receive the message only if you send it from your email app, together with the actual sender address and the ordinary technical data of an email, at office@hotelcorvaris.ro (a mailbox hosted on Microsoft 365). Purpose: replying to you. Basis: art. 6(1)(f) GDPR (our legitimate interest in answering enquiries) or (b) where the message concerns a booking. Retention: until the enquiry is resolved, then at most 12 months.

Technical access data — IP address, browser type, page requested and time are logged automatically in the server logs at our hosting provider (Railway Corp., servers in Amsterdam, Netherlands (EU)). The same provider technically processes the requests sent to our server (availability check and booking request). Purpose: security and operation of the site. Basis: art. 6(1)(f) GDPR. Retention: the logs contain the IP address, the HTTP request, the time and any error messages and are kept for at most 30 days; we build no profiles and do not combine these logs with other data.

On arrival at the hotel — the law requires us to complete the guest arrival/departure form from your identity document (Government Decision no. 237/2001). Basis: art. 6(1)(c) GDPR (legal obligation). This data may be made available to the competent authorities on request and is kept for the period set by the guest-registration rules.

Google Map — optional, loaded only after you press the accept button, to show the hotel's location interactively. On loading, Google Ireland Ltd. receives technical data, including your IP address, and may use cookies. Basis: art. 6(1)(a) GDPR (consent), which you can withdraw with "Disable map"; withdrawal does not delete cookies Google has already set, which you can manage in your browser.

What we do NOT do — the site sets no first-party cookies and uses no traffic analytics, tracking pixels or advertising; we send no newsletters; we make no automated decisions and no profiling.

3. Who receives your data

  • PYNBOOKING NET S.R.L. (PynBooking, Bucharest) — the hotel's reservation system; processes booking data as a processor under a data processing agreement.
  • Railway Corp. — hosting of the site, servers in Amsterdam, Netherlands (EU); processes technical logs and requests to the server as a processor under the provider's data processing addendum (DPA).
  • Microsoft Ireland Operations Ltd. (Microsoft 365) — hosts the hotel's mailbox through which we receive messages and booking correspondence.
  • Google Ireland Ltd. — only if you choose to load the Google Map on the Home or Contact page; nothing is sent to Google until you press the button.
  • Public authorities — where the law requires it (for example guest registration, tax or inspection bodies).

We do not sell or rent your data to anyone.

4. Transfers outside the European Union

The site is hosted in Amsterdam, Netherlands (EU), and the reservation system and mailbox are operated by providers established in the European Union. The hosting provider is a US company; for its technical access from outside the European Economic Area, the standard contractual clauses approved by the European Commission, included in its data processing addendum, apply. If you load the Google Map, Google may process data outside the EEA under the safeguards of art. 45–46 GDPR, per its privacy policy. Information about the applicable safeguards and a copy of them can be requested at office@hotelcorvaris.ro.

5. Your rights

You have the right of access to your data, to rectification, erasure, restriction of processing, portability, the right to object to processing based on legitimate interest, and the right to withdraw consent where processing relies on it (without affecting earlier processing).

To exercise them, write to office@hotelcorvaris.ro. We respond without undue delay and within one month of receiving your request; if an extension is necessary under the GDPR, we inform you within that month of the extension and its reasons. We may ask for additional information to confirm your identity.

If you believe your rights have been infringed, you may lodge a complaint with the Romanian supervisory authority (ANSPDCP) — B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, 010336 București, anspdcp@dataprotection.ro, +40 318 059 211, https://www.dataprotection.ro — or with the competent courts.

6. Security and minors

The site is served over HTTPS only, and booking requests are sent encrypted to the reservation system. Within the hotel, access to booking data is limited to front-desk staff and management; the processors listed above have technical access within the scope of their services.

Our services are aimed at adults. Bookings for minors are made by parents or guardians.

7. Changes

We update this policy whenever the processing changes (for example if we introduce traffic statistics). The version in force is the one published on this page, with the update date shown below.

Last updated: 26 September 2026 · CORVARIS GROUP S.R.L.