Data Privacy

Controller

Hoteli Punat d.d. Punat
Obala 102
OIB:    56485977409

headoffice.croatia@falkensteiner.com

 

Processing of Personal Data for the Purpose of Guest Registration

Subject and Purpose of Processing

As part of the guest registration process (check-in), we process personal data in order to properly document each guest’s stay, provide the services booked, and comply with statutory obligations. Processing also serves to uniquely identify with arriving guests, fulfilling contractual obligations under the accommodation agreement, and ensuring the organisational administration of stays, e.g. room allocation or guest list management.

Categories of Data Subjects and Personal Data

The people affected are all individuals staying at our hotel, in particular main guests and accompanying people. We process personal data such as title, first name, surname, date of birth, nationality, residential address, travel document details (e.g. passport number for persons subject to registration), arrival and departure dates, type of accommodation, and accompanying persons. These data are recorded manually or digitally upon arrival and stored in our system to ensure lawful registration and the proper execution of the stay.

Legal Basis

The processing of the above personal data is carried out on the basis of Article 6(1)(b) GDPR, as it is necessary for the performance of the accommodation contract. Failure to provide the necessary personal data will result in our inability to conclude the contract. Furthermore, as an accommodation provider, we are legally obliged under Article 4 of the Regulation on the eVisitor System from 2019 to collect certain guest data and transmit them to the competent authority. This statutory obligation constitutes an additional legal basis under Article 6 (1)(c) GDPR.

 

 

Processing of Personal Data for the Purpose of Issuing Guest Cards

Subject and Purpose of Processing

Depending on the tourism region, guest cards may be issued by the respective tourism association or the municipality. Guest cards offer significant added value by granting access to complimentary or discounted services, such as leisure activities, cultural programs, or mobility services.

Categories of Data Subjects and Personal Data

For this purpose, the following personal data may be processed: contact details, particularly the email address; core data such as name and date of birth; and travel data such as arrival and departure dates or accommodation details.

Legal Basis

Depending on the tourism region, the processing of personal data is carried out on the following legal bases:

  • Consent pursuant to Article 6(1)(a) GDPR:

Tourism associations or municipalities may provide – via a “guest registration form” – a means for guests to actively give their consent to receive a guest card. The controller for issuing and providing guest cards is the respective tourism association. Guests may withdraw their consent at any time with effect for the future, without needing to provide reasons, by contacting the tourism association.

  • Legal obligation pursuant to Article 6(1)(c) GDPR:

Municipalities may issue regulations requiring personal data to be transferred to the competent authority or tourism association. The legal basis for this processing arises from the relevant regulation in conjunction with Article 6(1)(c) GDPR.

 

Recipients

Your personal data will be transmitted exclusively to the tourism associations or municipalities in whose area the chosen accommodation establishment is located.

Retention Period

After transmission of the personal data, we do not carry out any further processing for this purpose.

 

 

Processing of Personal Data for the Purpose of Sending Our Newsletter

Subject and Purpose of Processing

If you subscribe to our newsletter, we process your personal data in order to send you regular email updates about current offers, events, seasonal promotions, and other news relating to our hotel. The purpose of this processing is to provide relevant content to interested guests and to strengthen customer loyalty through targeted communication.

Categories of Data Subjects and Personal Data

The data subjects are individuals who subscribe to our newsletter. The mandatory data processed consist of the email address; optionally, title, first name, surname, and areas of interest may also be processed to personalize the newsletter. In addition, the IP address and the time of subscription are stored to document lawful consent.

Legal Basis

The processing of personal data the purpose of sending the newsletter is based on Article 6(1)(a) GDPR, as it is carried out solely on the basis of your explicit consent. This consent is collected and recorded during the subscription process. You may withdraw your consent at any time with effect for the future.

Retention Period

Your data are stored for as long as you remain subscribed to the newsletter. After unsubscribing, your email address is removed from the active mailing list. Subscription log data (e.g. IP address and timestamp) are retained for up to three years to provide proof of lawful consent, after which they are deleted unless another legal basis requires longer retention.

 

 

Processing of Personal Data for the Purpose of Invoicing

Subject and Purpose of Processing

During your stay, we process personal data to issue accurate invoices and to conduct the associated payment process. This processing ensures the legally compliant settlement of services rendered, documentation for tax purposes, and compliance with statutory retention obligations. Additionally, processing may be required for the allocation of bookings, handling complaints, or processing refunds.

Categories of Data Subjects and Personal Data

The people affected are all guests who make use of chargeable services at the hotel. Personal data processed includes name, address, period of stay, booked services, invoice number, payment method, payment amount, and any applicable tax information. Depending on the booking process, further information such as booking codes, customer numbers, or vouchers may be processed if required for correct and complete billing.

Legal Basis

Processing for invoicing is based on Article 6(1)(b) GDPR, as it is necessary for performance of the accommodation contract. In addition, we are legally obliged to carry out proper accounting and bookkeeping under tax and levy regulations, particularly pursuant to General Tax Act and Accounting Act. This constitutes an additional legal basis pursuant to Article 6(1)(c) GDPR.

Retention Period

Personal data processed for invoicing are stored for eleven years in accordance with statutory retention obligations under the article 10 of the Accounting Act. After this period, the data are deleted unless further legal obligations or legitimate interests justify extended retention.

 

Processing of Personal Data for the Purpose of CCTV Surveillance in Particularly Sensitive Areas

Subject and Purpose of Processing

In the interest of ensuring the safety of guests, employees, and property, we use CCTV surveillance in particularly sensitive areas of our hotel. Processing serves to prevent, investigate, and document security-related incidents, as well as to protect against theft, property damage, or unauthorized access. CCTV may be used in sensitive areas such as hotel entrances, reception, currency exchange points, garage entrances and access roads, kitchen areas, pool areas and pool bars, the surroundings of wellness facilities, and staff areas. Recordings are stored locally on independent hard drives. Access is granted solely to authorised parties, including external security companies, the IT officer responsible, and hotel management.

Categories of Data Subjects and Personal Data

All people present in monitored hotel areas may be affected, including guests, visitors, suppliers, and employees. The processed data includes image recordings captured by fixed cameras as well as the date, time, and place of the recording. No audio recordings are made; cameras are positioned to capture only the areas that require surveillance for security reasons.

Legal Basis

CCTV surveillance is carried out pursuant to Article 6(1)(f) GDPR. Our legitimate interest lies in protecting individuals, property, and facilities, preventing and investigating criminal offences, and ensuring safety within hotel operations. Surveillance is limited to the extent necessary and conducted exclusively in areas with an increased need for protection.

Retention Period

Recordings are stored for a maximum of seventy-two hours unless a security-relevant incident is identified that requires longer retention. After this period, the data is automatically deleted. In the event of an incident (e.g. theft or property damage), recordings may be stored longer for evidence preservation or for transmission to authorities.

 

Processing of Personal Data for the Purpose of Reservations

Subject and Purpose of Processing

During the reservation process, we process personal data to receive and manage your booking request, check availability, and place a confirmed reservation for the requested stay. Processing is necessary to prepare the accommodation contract and ensure that the requested services (e.g. room category, travel dates, additional services) can be properly allocated and organised. Processing also enables us to contact you for confirmation, queries, or adjustments to the reservation.

Categories of Data Subjects and Personal Data

We process the following personal data in particular: title, first name, surname, email address, telephone number, travel dates, number of persons, preferred room category, selected additional services, and any personal notes or preferences. Depending on the reservation method and booking channel, payment data, country of origin, booking codes, and details of accompanying persons may also be processed if necessary.

Legal Basis

Processing of personal data during the reservation process is based on Article 6(1)(b) GDPR, as it is required for taking the necessary pre-contractual steps. This includes availability checks, provisional allocation of services, and communication for confirmation or coordination. If the necessary personal data are not provided, the reservation cannot be processed, and no contract can be prepared or concluded.

Retention Period

Personal data processed for reservation purposes are stored for eleven years pursuant to article 10 of the Accounting Act.

 

Processing of Personal Data for the Purpose of Marketing and Customer Loyalty

Subject and Purpose of Processing

For marketing and customer loyalty purposes, we process personal data to provide guests with targeted offers and maintain long-term customer relationships. Processing may include customer segmentation, analysis of booking behaviour, participation in loyalty programmes or club cards, and the provision of personalised benefits. It may also include sending personal greetings for special occasions such as birthdays or anniversaries. The purpose is to tailor our services to guests’ needs and interests and to enhance satisfaction and loyalty.

Categories of Data Subjects and Personal Data

Data subjects include guests who have made reservations or stayed at the hotel, or who participate in loyalty programmes or club systems. Processed data includes first name, surname, date of birth, contact details, booking history, length of stay, booked services, redeemed vouchers, participation in loyalty programs, and known preferences or interests. Dates of special occasions (e.g. birthdays) may also be processed if provided or inferred from prior interactions.

Legal Basis

Processing for marketing and customer loyalty purposes is based on Article 6(1)(f) GDPR. Our legitimate interest lies in cultivating relationships with guests, improving services, and providing targeted communication with relevant, personalised information and benefits. Data subjects may exercise their right to object at any time under Article 21(2) GDPR.

Retention Period

Personal data are stored for the duration of the customer relationship and for as long as a legitimate interest exists, or until an objection to processing is submitted.

 

Processing of Personal Data for the Purpose of Human Resources Administration

Subject and Purpose of Processing

As part of human resources (HR) administration, we process personal data to fulfil employment, social security, and tax obligations, and to establish, manage, and document employment relationships. Processing includes contract preparation, payroll accounting, time recording, working hours administration, leave and absence management, reporting obligations to authorities, and internal organisation and communication. Certain data may also be processed to comply with statutory retention and documentation obligations.

Categories of Data Subjects and Personal Data

Data subjects include all employees: full-time and part-time staff, temporary workers, apprentices, interns, and applicants who enter an employment relationship. Processed personal data includes name, address, contact details, social security number, date of birth, nationality, marital status, bank details, tax information, qualifications, employment duration, working hours, leave, absences, contractual details, and salary data. Depending on the role or legal requirements, health data (e.g. sick notes) and security-related information (e.g. access authorisations) may also be processed. Application documents and interview notes are processed if the candidate is hired.

Legal Basis

HR data processing is conducted pursuant to Article 6(1)(b) GDPR for the performance of the employment contract or pre-contractual steps. Additional statutory obligations apply under Article 6(1)(c) GDPR, arising from employment, social security, and tax laws, including the Labour law and General Tax Act.

Where special categories of data (e.g. health data) are concerned, processing is based on Article 9(2)(b) GDPR for exercising rights and obligations in employment law.

Retention Period

After termination of employment, personal data are stored in accordance with Article 9 of the Regulation on the Content and Method of Keeping Records of Employees Employed by the Employer. Application documents for rejected candidates are deleted within six months after completion of the recruitment process unless explicit consent for longer retention exists or legitimate interests apply (e.g. defense against legal claims).

Processing of Personal Data for the Purpose of Using the WLAN

Subject and Purpose of Processing

When providing free Wi-Fi access, we process personal data to enable guests to use the network and to ensure network and operational security. Processing supports technical functionality, prevents misuse, and fulfils potential legal obligations to provide information. Connection data may be temporarily logged to detect and trace unlawful or security-critical activities.

Categories of Data Subjects and Personal Data

All guests who use Wi-Fi access are affected. The processed data typically includes device identifiers (MAC address), assigned IP address, connection time, duration of use, and accessed destination addresses (metadata only, no content data). Depending on the login method, the room number or a personalized login (e.g. name or booking code) may also be processed. Data are used exclusively to ensure secure internet access and are not used for content monitoring or profiling.

Legal Basis

Processing is based on Article 6(1)(b) GDPR, as Wi-Fi access constitutes a secondary service provided under the accommodation contract.

Retention Period

Connection data are stored for up to fourteen days for network security, error analysis, and investigation of technical incidents. Longer retention occurs only when required to investigate specific security events or to fulfil statutory obligations. Content data are not stored.

 

Processing of Personal Data for the Purpose of Using an Access Control System (Key Cards)

Subject and Purpose of Processing

During your stay, you receive electronic access keys (key cards) that allow entry to your room and designated hotel areas. Processing of personal data enables access control, the technical management of the access system, and the safeguarding of persons and property. Usage may be logged to trace which card accessed which area, for example in the event of a card loss or a security incident. Processing is strictly limited to ensuring secure and orderly hotel operations.

 

Categories of Data Subjects and Personal Data

Data subjects include all guests who receive a key card. The processed data includes the name, room number, duration of stay, and an anonymised card ID linked to the respective booking.

Legal Basis

Processing is based on Article 6(1)(b) GDPR for the performance of the accommodation contract and Article 6(1)(f) GDPR for our legitimate interest in ensuring safety and access management. Processing is limited to what is necessary.

Retention Period

Data is retained for the duration of the stay. The link between the guest and the key card is automatically deactivated upon check-out. Access logs, if recorded, are deleted after fourteen days unless a security incident requires longer retention.

 

Processing of Personal Data for the Purpose of Events and Conferences

Subject and Purpose of Processing

In organising and conducting events, meetings, or conferences, we process personal data for the planning, communication, execution, and billing of such activities. This includes events organised for corporate clients, organisers, or private individuals. Processing supports participant administration, room and resource planning, and the provision of technical equipment.

Categories of Data Subjects and Personal Data

Data subjects include organisers, speakers, participants, and external service providers involved in the event. Processed data include the name, title, contact details, company affiliation, role, booking details, catering preferences, technical requirements, and – if needed – billing information.

Legal Basis

The processing of personal data in connection with the organization of events and conferences is carried out on the basis of Article 6(1)(b) GDPR, insofar as it is necessary for the performance of a contract or for taking pre-contractual steps.

Retention Period

Data are stored until the event and related processes are completed. Where statutory retention periods apply,  particularly under Article 10 of Accounting Act, data are stored for eleven years.

 

Processing of Personal Data for the Purpose of Collecting Vehicle Data for the Parking Service

Subject and Purpose of Processing

For our parking service, we process vehicle-related personal data to enable guests to park during their stay and to ensure orderly management of entry, exit, key handling, and vehicle allocation.

Categories of Data Subjects and Personal Data

Data subjects include guests who park a vehicle on hotel premises. Processed data include licence plate number, vehicle type, make, key number (if applicable), and booking-related information such as name, room number, and duration of stay.

Legal Basis

Processing is based on Article 6(1)(b) GDPR for fulfilment of contractual or pre-contractual obligations related to the accommodation contract. A legitimate interest also exists under Article 6(1)(f) GDPR, particularly for ensuring safety on hotel premises and the proper allocation of vehicles.

Retention Period

Data is retained for the duration of the stay and the use of the parking service. Data are deleted after departure or return of the vehicle unless legitimate interests or statutory obligations justify longer retention.

 

Processing of Personal Data for the Purpose of Collecting Data of Accompanying Persons

Subject and Purpose of Processing

It may be necessary to collect personal data of accompanying people for the proper administration of the reservation, the fulfilment of statutory registration obligations, or the preparation of individual services. Processing ensures correct allocation of rooms, accurate recording of all guests, and compliance with legal requirements.

Categories of Data Subjects and Personal Data

Data subjects are accompanying persons of the booking guest. Processed data include, as required, the name, date of birth, nationality, and duration of stay. Data is processed solely for accommodation purposes, statutory registration, or fulfilling individual guest preferences.

Legal Basis

Processing is based on Article 6(1)(b) GDPR, as it is necessary for the performance of the accommodation contract. Additionally, processing is required to meet statutory obligations under Article 6(1)(c) GDPR in conjunction with the Tourist Tax Act. If data are not provided, the accompanying person cannot be accommodated.

Retention Period

Data are stored for ten years pursuant to Article 7 of the Regulation on the eVisitor System.

Data Transfers

As part of our service provision, the following data transfers may occur. These transfers are necessary to organise and invoice services. In addition, we are legally obliged to notify municipalities of guest data. This includes transferring personal data of guests, booking information, and internal operational data.

 

Recipients

Purpose of Software Use

Apaleo GmbH, Munich, Germany

 

Open cloud platform for hotels (Property Management System). Enables the integration of various apps and automated processes such as reservations, check-in/out, and payment processing. Purpose: digitalization and increased flexibility in hotel operations.

Hotelbird GmbH, Munich, Germany

 

Digital guest-journey platform for online check-in/out, digital room access, mobile payments, and guest communication. Purpose: reducing waiting times and enhancing the guest experience.

Protel Hotelsoftware GmbH, Dortmund, Germany

Traditional Property Management System (PMS). Supports front office processes, real-time data exchange, and integration with partner solutions such as Hotelbird.

 

Amadeus IT Group S.A., Madrid, Spain

CRM system for guest loyalty, personalized communication, and marketing automation. Purpose: revenue optimization and improved guest satisfaction.

TravelClick Inc. (part of Amadeus), New York City, USA

Guest management and marketing tools focusing on pricing, distribution, and data-driven marketing strategies for revenue optimization.

 

TAC Informationstechnologie GmbH, Hartberg, Austria

Software for spa and wellness management. Supports appointment scheduling, resource allocation, and customer data management for hotel wellness areas.

 

Novacom software gmbh, Sießreithstraße 165, 8990 Bad Aussee

Internal solution for hotel processes and interface management. Used within front office system environments; detailed specifications not documented.

Flexkeeping d.o.o., Ljubljana, Slovenia

 

Housekeeping and operations management tool. Coordinates cleaning plans, departmental communication, and efficiency improvements. Note: potential data protection risks when used by external users.

Municipalities

 

Statutory data transfers to the competent municipality for registration purposes under the Registration Act. Includes required personal data of guests.

Tourism Associations

Personal data is transferred exclusively to the tourism associations or municipalities in whose area the accommodation establishment is located. Transfers fulfil statutory or contractual obligations related to guest registration and tourism services, including local tourist tax administration and statistical reporting.

 

Your Rights

You have the right to access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction of processing (Article 18 GDPR), data portability (Article 20 GDPR), and objection (Article 21 GDPR). To exercise these rights, please contact the Controller. If processing is based on your consent, you may withdraw this consent at any time without giving reasons. The withdrawal does not affect the lawfulness of processing carried out before the withdrawal. If you believe that the processing of your personal data violates the GDPR, please do not hesitate to contact us (see contact details above).
In addition, you have the right to lodge a complaint with a supervisory authority.

In Croatia, this is:

Agencija za zaštitu osobnih podataka
Ulica Metela Ožegovića 16,
10000 Zagreb

Phone: + 385 (0)1 4609-000,

e-mail: azop@azop.hr,

web: https://www.azop.hr