ROEN

Privacy and cookie policy

Version 3 · 03.10.2026

1. Who we are

1.1. The data controller is Sorin, persoană fizică autorizată să închirieze în regim hotelier, address Bucuresti ("we"). For any question or request about your data, write to contact@whiteflat.ro or call 0724603382.

1.2. This policy explains what data we process when you visit whiteflat.ro, make a booking (directly or through Booking.com / Airbnb), complete the online check-in, stay in one of our apartments or leave a review. It follows Regulation (EU) 2016/679 ("GDPR") and Romanian Law 190/2018.

2. What data we process

2.1. Booking: name, email, phone, country, language, apartment, arrival and departure dates, number of guests, estimated arrival time, bed preferences, messages you send us, price and discounts.

2.2. Online check-in (for each adult guest and for accompanied children): first and last name, date of birth, nationality, home address, type, series and number of the identity document, photo of the document (if requested), the lead guest's signature, email and phone.

2.3. Payment: amount, date, method and payment reference. For card payments, card details are entered directly on the page of the payment processor Revolut; we never see or store them. For bank transfers we see the payer's name and account. For refunds, the account you give us.

2.4. Invoice (if requested): name or company name, tax ID, registration number, address, email.

2.5. Review: display name, country or city, rating, text and our reply.

2.6. Technical data: IP address, browser type, date and time of form submissions and of document acceptance, the cookies described in section 11.

2.7. From Booking.com and Airbnb we receive, through calendar synchronisation and platform messages, the booking details (name, dates, booking number and sometimes contact details).

3. Purposes and legal bases

3.1. Concluding and performing the booking — confirmation, payment, preparing the apartment, sending access instructions, communication during the stay, refunds (Art. 6(1)(b) GDPR — contract).

3.2. Guest registration — the arrival and departure registration form, completed through the online check-in and kept for inspection by the authorities (Art. 6(1)(c) GDPR — legal obligation, Government Decision 237/2001).

3.3. Tax and accounting obligations — income records, invoices, city tax, reports to authorities (Art. 6(1)(c) GDPR — legal obligation).

3.4. Safety of guests and apartments — verifying the identity of the persons who receive the access codes (the apartments have no reception), fraud prevention, recording damage, proof of acceptance of the terms, defending our rights in a dispute (Art. 6(1)(f) GDPR — legitimate interest). The photo of the identity document is used only for this check and is deleted automatically (section 7).

3.5. Recognising returning guests for the loyalty discount (by email or phone) and asking for a review after the stay (Art. 6(1)(f) GDPR — legitimate interest; you can object at any time).

3.6. Publishing your review on the website, with the display name you choose (Art. 6(1)(a) GDPR — consent, which you can withdraw at any time).

3.7. We do not send newsletters and do not use data for advertising, marketing profiling or sale to third parties.

4. Do you have to give us your data?

Booking details are needed to conclude the contract, and check-in details are required by law. Without them we cannot confirm the booking or accommodate you. The ID photo, the review and optional messages are not mandatory, unless the photo is explicitly requested at check-in.

5. Who we share data with

We share only the data needed for each purpose, with:

  • the persons who clean and prepare the apartments — only the lead guest's name, the dates, the number of guests and bed preferences (never identity document data);
  • our service providers, as processors: website and database hosting, email service, the messaging services used for internal booking notifications (Telegram, WhatsApp, including through the CallMeBot service) — with minimal data (name, apartment, dates, phone);
  • Revolut and the banks involved in payments and refunds, as independent controllers;
  • Booking.com and Airbnb, for bookings made through them, as independent controllers;
  • our accountant and the tax authorities (including the RO e-Factura system, where applicable);
  • public authorities (police, tax or tourism authorities), only upon lawful request;
  • lawyers, bailiffs or courts, only where necessary to defend our rights.

We do not sell or rent your data.

6. Transfers outside the European Economic Area

The website and database are hosted by HOST GATE SRL. Some services used for internal notifications or for the map (Telegram, WhatsApp, Google) may involve transfers outside the EEA. In these cases the transfer is based on a European Commission adequacy decision (for example the EU-US Data Privacy Framework) or on the standard contractual clauses used by the provider, and the data shared is kept to a minimum.

7. How long we keep data

  • booking and payment data and invoices: 5 years from 1 July of the year following the year the documents were issued (Romanian Accounting Law 82/1991), or as long as tax rules require;
  • the check-in form (guest registration data and signature): 5 years after departure (Government Decision 237/2001), then deleted automatically;
  • the photo of the identity document: deleted automatically 30 days after departure;
  • proof of acceptance of the terms and policies: as long as we keep the related booking;
  • reviews: as long as they are published or until you ask us to delete them;
  • the booking history and the messages sent about it: together with the booking;
  • technical logs of internal notifications: at most 180 days;
  • your requests about the rights below: 3 years, so that we can prove how we handled them.

After these periods data is deleted or anonymised.

8. Your rights

You have the right:

  • of access — to know what data we hold about you and to receive a copy;
  • to rectification — to correct inaccurate or incomplete data;
  • to erasure — to ask us to delete data, except data the law requires us to keep;
  • to restriction of processing, in the cases provided by law;
  • to data portability — to receive the data you gave us in a structured, commonly used format;
  • to object — to processing based on our legitimate interest (including review requests);
  • to withdraw your consent at any time (for example for publishing your review), without affecting earlier processing;
  • not to be subject to a decision based solely on automated processing that significantly affects you — we take no such decisions; the loyalty discount is applied automatically only in your favour.

To exercise your rights, write to contact@whiteflat.ro. We reply within one month (extendable by two further months for complex requests, in which case we will let you know). We may ask for additional information to confirm your identity.

You have the right to lodge a complaint with the Romanian data protection authority (ANSPDCP), 28-30 G-ral Gheorghe Magheru Blvd., Sector 1, Bucharest, www.dataprotection.ro, anspdcp@dataprotection.ro, or with the authority in your country of residence.

9. Children

Bookings can only be made by persons aged at least 18. Children's details are entered at check-in by a parent or accompanying adult, only to the extent required for guest registration.

10. Data security

The website uses an encrypted connection (HTTPS). Identity document numbers are stored encrypted, and document photos and signatures are kept in an area of the server that is not publicly accessible. Access to the administration area is password-protected, with limited login attempts, and is granted only to the persons who need the data for their work. Apartment access codes are shown only after check-in. If a security breach occurs that may affect your rights, we will inform you and the ANSPDCP, as required by law.

11. Cookies and similar technologies

11.1. We use only the cookies needed for the website to work:

  • WFSESS — session cookie, needed for forms (protection against forged submissions) and for administrator login; deleted when you close the browser;
  • wf_lang — remembers the language you chose (Romanian / English), for one year.

11.2. We do not use analytics or advertising cookies and do not track visitors across websites. For our own visitor statistics (how many people visit the website, from which country, where they came from — for example Google or direct — and which pages they view) we use, without cookies, a technical fingerprint that changes every day; the IP address is not stored, the country is derived from the browser time zone, and the data is deleted after 13 months (legitimate interest, Art. 6(1)(f) GDPR).

11.3. The Google map on the home page loads only after you press "Show map"; from then on Google may set its own cookies, under Google's policy (policies.google.com/privacy). Links to Booking.com, Airbnb, Google Maps, WhatsApp or Revolut lead to websites with their own policies.

11.4. You can delete or block cookies at any time in your browser settings; without the session cookie, forms cannot be sent.

12. Changes

We may update this policy; each version is published on the website with its number and date.