Privacy policy.
What personal data we collect through this website, why we collect it, who receives it and what you can ask of us in relation to it. This document follows Regulation (EU) 2016/679 (GDPR).
This English text is a translation provided for your convenience. The Romanian version of this document is the legally binding one; in case of any difference, the Romanian text prevails.
1. The data controller
The controller that decides the purposes and means of processing the data collected through this website is:
- Company name
- CASA CIUBĂRULUI BRAN S.R.L.
- Tax identification number (CUI)
- 49293701
- Trade Register no.
- J08/3636/2023
- Registered office / place of business
- Str. Nicolae Boboc nr. 11, Predeluț, com. Bran, jud. Brașov, România
- Phone
- 0774 061 026
- Website
- https://casacuciubar.ro
For any request concerning your data, write to us at contact@casaciubarului.ro.
2. What data we collect
When you book
- First and last name;
- Phone number;
- Email address (optional, but needed to receive the confirmation and the invoice);
- The details of the stay: the dates, the number of adults and children, the rooms chosen, the extras;
- Anything you write freely in the “Notes” field.
When you pay
- The amount, currency, date and status of the transaction, together with the transaction identifier received from the payment processor.
- We neither receive nor store your card details. The card number, expiry date and CVV are entered directly on the secure page of the processor EuPlătesc and never reach our servers.
Through the contact form
- Name, email, phone and the content of your message.
At check-in
- The details on guests' identity documents, which accommodation providers are legally required to record at check-in.
Automatically, technically
- Server logs (IP address, time of the request, page accessed, browser type), generated by the hosting provider for the operation and security of the website.
3. Why we collect it, and on what legal basis
- To process your booking and accommodate you — basis: performance of the contract to which you are a party (art. 6(1)(b) GDPR). Without a name, a phone number and the details of the stay we cannot confirm a booking.
- To take payment and issue the invoice — basis: performance of the contract and compliance with tax obligations (art. 6(1)(b) and (c) GDPR).
- For the register of guests staying — basis: legal obligation (art. 6(1)(c) GDPR).
- To answer messages sent through the contact form — basis: our legitimate interest in responding to enquiries (art. 6(1)(f) GDPR).
- For website security and fraud prevention — basis: legitimate interest (art. 6(1)(f) GDPR).
We do not use your data for profiling, behavioural advertising or automated decisions with legal effects.
4. Who we share the data with
We do not sell or rent personal data. We pass it only to the providers we need in order to operate, each strictly within its own role:
- EuPlătesc.ro (Euro Payment Services S.R.L.) — card payment processing. Receives the payer's name, the amount and the booking reference.
- Vercel Inc. — hosting of the website and the application.
- Neon Inc. — the database where bookings and messages are stored.
- Resend — sending confirmation emails and notifications.
- Public authorities — only where the law requires it (tax authorities, police, courts).
Calendar synchronisation with booking platforms (Booking.com, Airbnb and similar) is done through iCal files that contain only the occupied date ranges, marked “Unavailable”. No guest name, phone number or email leaves our system this way.
Some of the providers above may process data outside the European Economic Area. In those cases the transfer is made under the standard contractual clauses approved by the European Commission, or under an adequacy decision.
5. How long we keep the data
- Financial documents (invoices, payment records): 10 years, in line with accounting and tax law.
- Booking data: for the duration of the stay and afterwards for as long as there is a legitimate interest (complaints, disputes), but no longer than 3 years after the end of the stay, except for what is contained in financial documents.
- Contact form messages: a maximum of 2 years from the last exchange.
- Technical logs: short periods set by the hosting provider, usually under 30 days.
6. Cookies
This website uses no analytics, advertising or tracking cookies and integrates no tools such as Google Analytics or advertising pixels. We do not build visitor profiles and we sell data to no one.
Strictly necessary. We store on your device only the choice you make in the cookie banner, so that we do not have to ask again on every visit. To that is added a session cookie set exclusively when signing in to the admin area, used by our staff; ordinary visitors never receive it. For strictly necessary cookies the law does not require consent.
Optional — the embedded Google map. On the contact page we can show the map of the property in a Google Maps frame. Loading the map involves a connection to Google, which may set its own cookies and may learn your IP address. That is why the map does not load before you agree: until then a placeholder appears in its place, and the address and the link to Google Maps remain available. Declining limits nothing else on the site.
You can change your mind at any time. The choice can be changed from the “Cookie settings” link in the footer of every page, and the saved preferences can also be deleted from your browser settings, along with the rest of the site data.
The payment page belongs to the processor EuPlătesc and may use its own cookies, necessary for the security of the transaction. These are strictly necessary for the payment to take place and are governed by the processor's policy.
7. Data security
Traffic to the website is encrypted (HTTPS). Access to the database and to the admin area is restricted and protected by authentication. Payment takes place entirely on the processor's PCI-DSS certified infrastructure, and communication with it is cryptographically signed to prevent amounts being altered in transit.
8. Your rights
Under the GDPR you have the right:
- of access to the data we hold about you;
- to rectification of inaccurate or incomplete data;
- to erasure (the “right to be forgotten”), to the extent that we have no legal obligation to keep it;
- to restriction of processing;
- to portability of the data you provided;
- to object to processing based on legitimate interest;
- to withdraw consent at any time, where processing is based on it, without affecting the lawfulness of processing before that.
Requests are sent to contact@casaciubarului.ro and are answered within one month of receipt at the latest.
If our answer does not satisfy you, you have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, dataprotection.ro, or to go to court.
9. Minors
The website is not aimed at minors and we do not knowingly collect data from people under 18 outside the context of a booking made by an adult for their family. Data about children staying is limited to their number and, at check-in, to the information required by law.
10. Changes to this policy
We may update this policy when the way the website works, or the legal requirements, change. The version in force is always the one published here, and the date of the last revision appears below.
Last updated: 18 August 2026.