INFORMATION ON THE PROCESSING OF PERSONAL DATA
OF THE DATA SUBJECT

pursuant to Art. 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)

 

The Controller ÁČKO a.s. considers compliance with the legal conditions for the processing of personal data of data subjects to be one of its priorities. All actions carried out in the individual stages of the personal data processing process are performed with maximum emphasis on the protection of the fundamental rights of data subjects, in particular the protection of personality and privacy and compliance with the principles of lawful processing of personal data.
ÁČKO a.s. (hereinafter also referred to as the “Controller”) processes all personal data in accordance with the applicable legal regulations, with particular emphasis on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR) (hereinafter also referred to as the “Regulation” or “GDPR”) and Act No. 18/2018 Coll. on the Protection of Personal Data and on Amendments to Certain Acts (hereinafter also referred to as the “Act” or “Act No. 18/2018”).
This document concerns primarily data subjects who are not employees of ÁČKO a.s. The information contained in this document constitutes information within the meaning of Art. 13 of the Regulation.

DETAILS OF THE CONTROLLER
Business name: ÁČKO a.s.
Registered office: Textilná 19 034 01 Ružomberok
Company ID (IČO): 31577148
Tax ID (DIČ): 2020430489
Establishment: Hotel, Hrabovská cesta 34, 034 01 Ružomberok

The proper processing of personal data is supervised by an authorised person, contact details:
e-mail: vedenie@hotelacko.sk
correspondence address: address of the company’s registered office

This information is effective from 1.6.2025, and the Controller is entitled to update it.

DEFINITIONS OF TERMS
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data of 27 April 2016.
Data subject – every person whose personal data are processed.
Personal data – any information relating to an identified natural person or an identifiable natural person.
Controller – a natural or legal person who has determined the manner and defined the purpose of the processing of personal data.

PRINCIPLES OF PERSONAL DATA PROCESSING
Compliance with the principles of processing customers’ personal data pursuant to Art. 5 of the Regulation.
Lawfulness of processing – every processing operation must be lawful, i.e. we have an appropriate legal basis.
Minimisation of personal data processing (necessity) – we process your personal data only to the extent necessary in relation to the purpose. We always consider the scope of personal data processing.
Minimisation of personal data storage (disposal) – we store data in a form that allows the identification of the data subject only for as long as necessary for the purposes. Your personal data are thoroughly disposed of after the purpose of processing has been fulfilled.
Integrity and confidentiality (security) – the Controller has adopted technical, organisational and personnel measures against the loss, destruction or damage of personal data.

NECESSITY OF PROVIDING PERSONAL DATA
The provision of personal data by an accommodated guest is necessary for the conclusion and performance of the accommodation contract, as well as for the fulfilment of the Controller’s legal obligations. In the event of failure to provide the required data, it is not possible to accommodate the guest and provide them with the legal and contractual services.

WE OBTAIN YOUR PERSONAL DATA
You provide us with your personal data most frequently:
when booking accommodation (by telephone, e-mail, online form or through booking portals),
upon arrival at the reception when filling in the accommodation form,
when using the hotel’s additional services (e.g. wellness, parking),
in the course of communication with the hotel staff.

PURPOSE OF PERSONAL DATA PROCESSING, LEGAL BASIS AND STORAGE PERIOD
Purpose of personal data processing
We process your personal data for the purpose of:
booking, providing and keeping records of accommodation services,
issuing accounting documents and keeping accounts,
reporting accommodated guests (in particular foreigners) to the competent authorities,
collecting the local accommodation tax,
fulfilling legal obligations and protecting the legal interests of the Controller (e.g. complaints, control of authorised entry, security).
Legal basis for processing
We process your personal data on the basis of:
Art. 6 par. 1 letter b) GDPR – performance of the accommodation contract,
Art. 6 par. 1 letter c) GDPR – legal obligations arising from legal regulations (e.g. the act on the residence of foreigners, the act on local taxes),
Art. 6 par. 1 letter f) GDPR – legitimate interest of the Controller (e.g. protection of property, guest satisfaction).
Personal data storage period
We store your personal data:
for the duration of the contractual relationship,
after its termination in accordance with the statutory periods, i.e. as a rule 10 years for accounting and tax purposes,
data necessary for keeping records of accommodated persons and local taxes are stored in accordance with the relevant laws, as a rule 5 years,
data processed on the basis of legitimate interest (e.g. camera system recordings) for a maximum of 3 days, unless incidents are detected.

TRANSFER OF PERSONAL DATA TO THIRD COUNTRIES AND AUTOMATED INDIVIDUAL DECISION-MAKING
No transfer of personal data to a third country or to an international organisation takes place. Personal data will not be used for automated individual decision-making, including profiling.

DISCLOSURE OF PERSONAL DATA
Personal data will not be disclosed.

CONFIDENTIALITY
We would like to assure you that our employees and associates who will process your personal data are obliged to maintain confidentiality regarding personal data. This confidentiality continues even after the termination of contractual relationships with us.

SECURITY OF PERSONAL DATA
In accordance with Articles 24 and 32 of the GDPR, we adopt appropriate technical and organisational measures to ensure a level of protection of personal data appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons. Such measures include, in particular, the protection of the confidentiality, integrity and availability of data through the control of physical access to personal data, as well as access to them, their entry, disclosure, ensuring availability and separation. Furthermore, we have introduced procedures to ensure the exercise of the data subject’s rights, the erasure of personal data and the response to personal data breaches. In addition, we take the protection of personal data into account already in the development and selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default settings appropriate for data protection (Art. 25 GDPR).

“COOKIES” FILES ON OUR WEBSITE
We are entitled to collect and otherwise process data about visitors and users of our website through tools used for the automated collection of data, in particular cookies, logs and other commonly used tools for obtaining information through a website.
A cookie can be understood as a small amount of data that is sent as a file to your computer (tablet, smartphone) from the website you are currently visiting. The data file is stored on the computer and, on each subsequent visit to the same website, the computer sends the information to our server.
Most websites, including ours, use cookies. The purpose of cookies is to make the use of our website easier and more pleasant for you. A cookie file allows the website to recognise whether you have visited it in the past and which section you were interested in. At the same time, it is cookies that allow you to save your user settings, such as language recognition or remembering your login name. Using cookies, we store data that we do not associate with your person, and we do not identify the customer through the data obtained. The use of cookies is not dangerous for you; cookies cannot transmit viruses or read data from the hard disk of the device.
This procedure follows from § 109 par. 8 of Act No. 452/2021 Coll. on Electronic Communications.
The use of cookies and their enabling in the web browser is at the free will of each user of the website. You can freely delete cookies or set your internet browser in advance so that it either refuses to accept cookies or notifies you when a server tries to send you a cookie. In that case, however, it may happen that websites that are dependent on cookie support will not function as you would expect, or that parts of the websites will not be available to you. We use persistent cookies, which help us identify your device when you revisit the Website and thus enable us to provide services in accordance with your expectations.
How can cookie settings be changed?
You can accept or refuse cookies – including those used for website tracking – by selecting the appropriate settings for your browser. You can set your browser to notify you when you receive a new cookie, or block them completely.
You can find out more about how the cookies policy can be managed in the most commonly used browsers here:

RIGHTS OF DATA SUBJECTS UNDER THE REGULATION AND THE ACT ON THE PROTECTION OF PERSONAL DATA
We consider it important that you understand that the personal data we process are your data and that rights are associated with their processing. In addition to the right to withdraw consent to the processing of personal data, you also have other rights arising from the Regulation and the Act on the Protection of Personal Data, namely:
Right of access – you have the right to be provided with a copy of the personal data we hold about you, as well as information about how we use your personal data. In most cases, your personal data will be provided to you in written paper form, unless you request otherwise. If you have requested the provision of this information by electronic means, it will be provided to you electronically, if technically possible.
Right to rectification – we take reasonable measures to ensure the accuracy, completeness and currency of the information we hold about you. If you believe that the data we hold are inaccurate, incomplete or out of date, please do not hesitate to ask us to amend, update or supplement this information.
Right to erasure – under certain circumstances, you have the right to ask us to erase your personal data, for example if the personal data we have obtained about you are no longer necessary to fulfil the original purpose of processing, or if you withdraw your consent to processing. However, your right must be assessed in light of all relevant circumstances. For example, we may have certain legal and regulatory obligations, which means that we will not be able to comply with your request.
Right to restriction of processing – under certain circumstances, you are entitled to ask us to stop using your personal data. This applies, for example, to cases where you believe that the personal data we hold about you may be inaccurate, or where you believe that we no longer need to use your personal data.
Right to data portability – under certain circumstances, you have the right to ask us to transfer the personal data you have provided to us to another third party of your choice. However, the right to portability applies only to personal data that we have obtained from you on the basis of consent or on the basis of a contract to which you are one of the contracting parties.
Right to object – you have the right to object to the processing of data that is based on our legitimate interests (for example, we process personal data for the purpose of network and infrastructure security). If we do not have a compelling legitimate reason for the processing and you raise an objection, we will not further process your personal data.
Rights related to automated decision-making – you have the right to refuse automated decision-making, including profiling, which produces legal or similarly significant effects concerning you. The Controller does not usually use automated decision-making or profiling in the context of employment.
Right to withdraw consent – in most cases, we do not process your personal data on the basis of your consent. However, it may happen that in specific cases we ask for your consent. In cases where we do so, you have the right to withdraw your consent to the further use of your personal data. (e.g. a photograph)
Right to lodge a complaint – if you wish to lodge a complaint about the way your personal data are processed, including the exercise of the rights set out above, you can contact our Responsible Person (contact details are given above). We will duly investigate all your suggestions and complaints.
If you are not satisfied with our response, or if you believe that we are processing your personal data unfairly or unlawfully, you can lodge a complaint with the supervisory authority, which is the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky), https://dataprotection.gov.sk, Hraničná 12, 820 07 Bratislava 27; E-mail: statny.dozor@pdp.gov.sk. However, we would appreciate it if you would first address your objections with us.

HOW TO PROCEED WHEN EXERCISING YOUR RIGHTS
You always exercise your rights with the entity that processes your personal data, i.e. with the specific controller. If the controller has a responsible person, you may also address your request to this person. The request may be oral, written, electronic or submitted by other means (the General Data Protection Regulation does not prescribe a specific form). We recommend using the written or electronic form in particular.
Prepare identification data on the basis of which the controller will be able to identify you in its environment and thus provide you with the data concerning you.
We will respond to your request free of charge within 30 days. In the case of complexity or a large number of requests, we are entitled to extend this period by a further 60 days. If this happens, we will inform you of this as well as of the reasons. In the case of a repeated request, we are entitled to charge a reasonable administrative fee to cover the costs associated with providing this service.
The data subject’s right to object to automated decision-making cannot be exercised, because the described processing activity does not include automated decision-making.

WHERE AND HOW YOU CAN EXERCISE YOUR RIGHTS
The Controller has not appointed a data protection officer, as this is not a legal necessity. In the case of any questions concerning the processing of your personal data, or if you are interested in more detailed information, you can contact us by e-mail or in writing at our address.

CONCLUSION
If you have questions regarding the protection of personal data, you can contact us at any time by e-mail or by post at the registered office of the Controller. In the event that you exercise any of the rights of a data subject under the legal regulations governing the protection of personal data and it is not possible to verify the identity of the applicant from your request, or in the event that we have justified doubts in connection with the identity of the person submitting the request, we reserve the right to ask this person to provide additional information necessary to confirm the identity of the person exercising this request.