This policy explains in plain terms how we handle your personal data under Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR). It applies to guests of Hotel Raj, visitors to this website, cooperative members, suppliers and contractual partners.
Who the controller is
The controller processing your personal data is TRADIČNÉ DRUŽSTVO, registered office at J. Kráľa 21, 960 01 Zvolen, Slovak Republic, company ID 52 945 715. Hotel Raj, Dobšinská Maša 73, 049 73 Dedinky, is its accommodation facility.
Data protection officer: info@td-coop.eu. Correspondence address: Popradská 17, 064 01 Stará Ľubovňa, Slovak Republic.
For matters concerning your stay you may contact the hotel reception directly: reception@hotelraj.eu, +421 911 930 991.
Why we process personal data
We process personal data so that we can provide accommodation and related services, meet our legal obligations and protect our legitimate interests.
Purposes and legal bases
- Booking and stay, including related communication — performance of a contract (Art. 6(1)(b) GDPR).
- Contact form on the website — consent given when you submit it (Art. 6(1)(a) GDPR), or pre-contractual steps (point b).
- Sending a discount code from the website form — consent (Art. 6(1)(a) GDPR). We use the e-mail address solely to send the code and to evidence that it was sent; we do not send a newsletter.
- Guest register and reporting duties — compliance with legal obligations (Art. 6(1)(c) GDPR).
- Accounting and tax purposes — compliance with legal obligations (Art. 6(1)(c) GDPR).
- IT security — compliance with legal obligations (Art. 6(1)(c) GDPR).
- Establishment, exercise and defence of legal claims — legitimate interest (Art. 6(1)(f) GDPR).
- Website visit statistics (Google Analytics) — consent (Art. 6(1)(a) GDPR). Without consent nothing is measured.
- Cooperative membership, payroll, HR and records management — under contract and legal obligations.
Who we share data with
Besides us and our employees, the following processors may have access to the data:
- IWESYS s. r. o., Hviezdoslavova 7, 040 01 Košice, company ID 48 150 291 — development, testing, delivery, maintenance and support of IT systems.
- ArchITecture s. r. o., Nová Ľubovňa 491, 065 11 Nová Ľubovňa, company ID 56 844 352 — development, testing, delivery, maintenance and support of IT systems.
- adv accounting s. r. o., Farbiarska 53/29, 064 01 Stará Ľubovňa, company ID 52 104 265 — bookkeeping.
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland — website visit statistics through Google Analytics, and only where you have given consent to analytics cookies on the site.
Booking and payment
Bookings and payments are made in the HOLIDAY TD reservation system at holiday.td-coop.eu, operated by Tradičné družstvo — the same controller.
Payments by the general public are processed by the Stripe payment gateway (Stripe Payments Europe, Limited, Ireland); payments by members of Tradičné družstvo by the TD-Pay gateway. We neither obtain nor store payment card details — these are processed by the payment service provider.
A current list of processors is available on request.
Transfers outside the EU
We process data in the European Union. The only exception is website visit statistics: if you have consented to analytics cookies, Google Ireland Limited may also process data on servers outside the European Union, in particular in the United States.
That transfer relies on the European Commission’s adequacy decision for the United States under the EU–US Data Privacy Framework, in which Google participates, and on standard contractual clauses approved by the European Commission.
If you do not consent to analytics cookies, or you withdraw consent, no such transfer takes place at all — the Google tag is never written into the page and Google learns nothing about your visit.
Automated decision-making
To improve our services we also process data by automated means, that is, through information systems and applications. We carry out no profiling and no automated decision-making producing legal effects concerning you.
How long we keep data
We keep data only for as long as is necessary for the purpose for which it is processed. Where a retention period follows from legislation, we apply it; otherwise it is set by our internal records plan.
- Booking and stay — for the duration of the contractual relationship and then for the limitation periods.
- Accounting and tax documents — 10 years.
- Contact form — for as long as needed to handle the enquiry and then no more than 1 year.
- Records of discount code requests — for as long as needed to send the code and evidence the sending, no more than 1 year, or until consent is withdrawn.
- Cooperative membership records — for the duration of membership and 5 years after it ends.
- Payroll and HR purposes — for the duration of employment and after the statutory periods expire.
- Records management — from 5 to 30 years under the records rules.
- Website visit statistics (Google Analytics) — 14 months from the last visit.
Whether you must provide data
Where the legal basis is a contract, providing the data is a requirement for entering into it — without it we cannot conclude the contract. Where the legal basis is a legal obligation, it is a statutory requirement.
Where we process data on the basis of legitimate interest, you have the right to object to such processing. Where the legal basis is consent, you are not obliged to give it and may withdraw it at any time; not providing the data has no negative consequences, though it may reduce the convenience of some services.
Your rights
In relation to the processing of personal data you have the following rights:
- The right of access to the personal data concerning you and to a copy of it (Art. 15 GDPR).
- The right to rectification of inaccurate data and completion of incomplete data (Art. 16 GDPR).
- The right to erasure, the “right to be forgotten”, where one of the statutory grounds applies (Art. 17 GDPR).
- The right to restriction of processing (Art. 18 GDPR).
- The right to data portability in a structured, commonly used and machine-readable format (Art. 20 GDPR).
- The right to object to processing, including direct marketing and profiling (Art. 21 GDPR).
- The right to lodge a complaint with the supervisory authority.
- The right to withdraw consent at any time; withdrawal does not affect the lawfulness of processing before it.
How to exercise your rights
You may withdraw consent by e-mail at info@td-coop.eu or by a written request sent to the controller’s registered office marked “GDPR – odvolanie súhlasu” on the envelope. The same routes apply to your other rights.
You may lodge a complaint with the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava, in particular if you believe that the processing infringes your rights.
How we protect your data
We give data protection due attention. We have put in place generally accepted technical and organisational measures to protect the data we process, in particular against loss, misuse, unauthorised alteration, destruction or other impact on the rights and freedoms of data subjects.
Cookies
This site uses cookies. Without your consent we load no analytics or marketing cookies, and the Google Analytics tag is not written into the page at all. We do not use advertising features, Google signals, or any link to advertising accounts. A list of the specific cookies and their lifetimes is on the separate cookies page.
Social networks
We run a Facebook page. We have only limited influence over how the platform’s operator processes personal data — we act within the options the platform gives us. The platform operator runs the entire IT infrastructure of the service, sets its own data protection terms and is responsible for matters relating to your user profile, to which we have no access.
This policy is valid and effective from 15 September 2026 and may be updated. The current wording is always published on this page.