Privacy Policy

Last updated: 27.07.2026

The privacy of your data matters to us. This policy explains what personal data we process when you book or stay at Via Aurum or use the viaaurum.ro website, for what purposes, who we share it with, and your rights under Regulation (EU) 2016/679 (GDPR) and Romanian Law no. 190/2018.

1. Data controller

  • Controller: Via Aurum, run by private hosts: [hosts’ full names].
  • Address: Ciuldești village, no. 21, Bistra commune, Alba County, Romania.
  • Data-protection contact: [email protected] · +40 731 787 226.
  • We have not appointed a Data Protection Officer (DPO), as this is not mandatory for our activity.

2. What data we process

  • Booking data: first and last name, phone number, email address, your message, stay details (period, number of guests, room) and the estimated amount.
  • Communication data: the content of messages you send us by email, phone, WhatsApp or social media.
  • Technical browsing data: IP address, device and browser type, pages visited and interactions, collected through analytics tools (see the cookies section).

3. Purposes and legal basis

Purpose Data Legal basis (art. 6 GDPR)
Processing the booking request and the stayidentification, contact, stay detailsPerformance of a contract / pre-contractual steps [art. 6(1)(b)]
Communicating with youcontact, message contentPerformance of a contract / legitimate interest [art. 6(1)(b)/(f)]
Complying with legal obligations (tax, guest records, where applicable)identification dataLegal obligation [art. 6(1)(c)] — [to confirm which apply]
Website traffic analysistechnical browsing dataConsent [art. 6(1)(a)]
Website securitytechnical dataLegitimate interest [art. 6(1)(f)]

4. Who we share data with

We do not sell your data. We may share it only with processors and third parties needed to run the service:

  • The website and server hosting provider: [provider / server location].
  • The email provider through which we receive booking requests: [email/SMTP provider].
  • The Contentsquare web analytics tool (Contentsquare SAS).
  • Google Maps (Google Ireland Ltd.), when the map is displayed on the Location page.
  • WhatsApp / Meta, if you contact us via WhatsApp or social media.
  • Public authorities, where there is a legal obligation.

5. Transfers outside the EEA

In principle, your data is processed within the European Union / European Economic Area. Some service providers (for example Google or Meta) may involve transfers to countries outside the EEA; in such cases the transfers rely on appropriate safeguards (EU standard contractual clauses or the EU–US Data Privacy Framework). [To be confirmed per provider.]

6. How long we keep data

  • Booking requests and stay data: [e.g. for the duration of the relationship and thereafter as required by law — to confirm].
  • Correspondence: [period].
  • Traffic-analysis data: as set by the analytics tool used.

7. Your rights

As a data subject you have the right of access, rectification, erasure, restriction of processing, portability, objection, and the right to withdraw your consent at any time (without affecting processing carried out before withdrawal).

You can exercise these rights by writing to [email protected]. You also have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 28-30 G-ral Gheorghe Magheru Blvd., Bucharest, www.dataprotection.ro.

8. Automated decisions

We do not use automated decision-making and do not carry out profiling with legal effects on you.

9. Cookies and analytics tools

The website uses cookies and similar technologies that are strictly necessary for it to function, as well as traffic-analysis tools (Contentsquare) and embedded third-party content (Google Maps). Cookies and tools that are not strictly necessary are activated only based on your consent. [To implement: a cookie banner that lets visitors accept or reject non-essential tools before they load.]

10. Data security

We apply reasonable technical and organisational measures to protect data (for example a secure HTTPS connection and limited access to information).

11. Changes to this policy

We may update this policy from time to time. The applicable version is the one published on the website, with the “last updated” date shown above.