Privacy
Privacy Notice
Effective: August 26, 2026 · Version: 1.0
1. The data controller
The controller of personal data provided through the piposzbirtok.ro website is STEFI GROUP SRL (Piposz Birtok brand name).
- CUI: RO 22524235
- Company registration number: J19/926/2007
- Headquarters and postal address: 537161 Sat Valea Ugra, 671/A, Harghita County, Romania
- Privacy contact email: info@piposzbirtok.ro
- Privacy contact phone: +40 741 055 075
2. What data do we process and why?
Getting in touch
Name, email address and/or phone number, message, request ID and timestamp. We process these data to respond to and document the handling of your enquiry. Legal basis: Article 6(1)(f) GDPR, legitimate interests; for requests made in preparation for a contract, Article 6(1)(b) GDPR.
Booking, program and event inquiries
In addition to the contact details above, we process the arrival or planned date, number of guests, selected accommodation/activity, event type, accommodation requirements, message and optional organisational requests. The purpose is to check availability, provide an offer and discuss arrangements before entering into a contract. Legal basis: Article 6(1)(b) GDPR. Please do not enter health, religious, identity-document, payment or other sensitive data in free-text fields.
The mandatory check box is a confirmation of reading and acknowledgment of the information, not a legal basis for consent to data processing. Submitting the form does not mean an automatic booking; the request is checked by a staff member.
3. Retention periods
- Inquiries and requests for proposals not leading to a contract: 12 months from the last meaningful communication.
- The documents and accounting documents of the established booking or contract: from completion to the time of the applicable accounting, tax and legal obligation, where necessary, usually up to 10 years.
- Rate-limit imprint: exactly 10 minutes; anti-resend imprint: exactly 24 hours.
- The technical event log without personal form data: up to 100 entries and up to 90 days.
- Affected requests: only as long as necessary to verify the processing of the request and the legal procedure, subject to the applicable statute of limitations.
In the event of an ongoing legal claim or security incident, the required data can be stored separately until the case is closed. Data deleted from provider backups will disappear during the normal overwrite cycle.
4. Recipients and service providers
Designated employees of the data controller may only access the data to the extent necessary for their tasks. Website and email delivery uses Hostinger hosting, WordPress and SMTP service; the internal admin notification is currently sent via a temporary working route to the Google Gmail system. The current conditions of service providers: Hostinger Privacy Policy, Google Privacy Policy. Transfers or access outside the EEA may take place only with the applicable safeguards under Chapter V of the GDPR. Data are disclosed to authorities only where required by law, necessary for a legal claim or covered by appropriate authorisation.
5. Technical security, cookies and logs
The legal basis for security-related data processing is Article 6(1)(f) GDPR: our legitimate interest in system security. The system uses HTTPS, same-origin checks, WordPress nonces, field validation, a honeypot, rate limiting, duplicate-submission protection, limited logging and encrypted SMTP configuration. Complete security cannot be guaranteed.
The current release does not include analytics or marketing tracking. The public website’s own JavaScript does not use persistent cookies, localStorage or sessionStorage. Any new non-essential tracker may be activated only after an appropriate prior choice and updated privacy information have been provided.
6. Map and external links
The OpenStreetMap map does not load automatically. Only after activating the "Load map" button is a connection established with the OpenStreetMap server; then OSM may receive technical data such as IP address and browser data. Details: OpenStreetMap Foundation Privacy Policy.
Links to WhatsApp, Google Maps route planner, Határtalanul and Lynx are external sites. We do not forward form data to them until they click. WhatsApp is an outgoing link only; no WhatsApp or Twilio backend.
7. Minors
Anyone under 18 may submit a request only through an adult contact. The adult should provide only the information strictly necessary for arranging the stay and must not enter special-category personal data in the form.
8. Automated decisions
We do not perform profiling, and requests are not subject to solely automated decisions with legal or similar significant impact.
9. Your Rights
Under the GDPR, you may request access, rectification, erasure, restriction and—where applicable—data portability, and you may object to processing based on legitimate interests. Send your request to the email or postal address above. Please do not send a copy of any identity document in advance. As a rule, we respond within one month; for complex requests, this period may be extended by up to two further months in accordance with the GDPR, and we will notify you of any extension.
10. Complaint and remedy
You may lodge a complaint with the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) at the authority: B-dul with G. Gheorghe Magheru no. 28-30, Sector 1, 010336 București, România; anspdcp@dataprotection.ro; +40 318 059 211 / +40 318 059 212; complaints page. A judicial remedy is also available.
11. Amendment
The information is updated when the data management, service providers or legal environment changes. The current version will be available with the effective date.
Preparing the Romanian language version is a separate next task.
