Privacy Policy & GDPR
Last updated: 4 September 2026
§1. Controller
The controller of personal data of Lodvena users (property owners and staff — Customers) at lodvena.com is Geomarine Global Patryk Zajdel, ul. Szkolna 26, 38-430 Miejsce Piastowe, Poland, VAT ID 6842640364, REGON 361224375. Data matters: kontakt@lodvena.com, telephone +48 513 153 731.
§2. Customer data
1. We process:
- account data (e-mail, name, irreversibly hashed password) — to conclude and perform the contract (art. 6(1)(b) GDPR), for the term of the contract and 30 days after it ends;
- billing data (company name, VAT ID, address, payment history) — for tax and accounting obligations (art. 6(1)(c) GDPR), for 5 years from the end of the tax year;
- the panel event history (who did what, and when) — in our legitimate interest of security and accountability (art. 6(1)(f) GDPR), for the term of the contract;
- correspondence — to handle enquiries (art. 6(1)(b) and (f) GDPR), for 3 years.
- page-visit statistics (the page address, the day, where the visit came from, country, device type, and a daily salted hash of IP address and browser whose key changes at midnight) — in our legitimate interest of measuring traffic without following anyone (art. 6(1)(f) GDPR), for 760 days. No cookies and no third-party tools are used for this, and the data is not joined to an account or a reservation. The collection covers Customers' own property websites too; for that statistic the Provider is the controller, not a processor under §3.
- content posted in the Community inside the panel (entries, comments, votes, the author's name) — in our legitimate interest of running the Community and developing the Service (art. 6(1)(f) GDPR), for as long as the Community runs and no longer than 3 years from the end of participation (§2.4 of the Community Rules); after that entries are deleted or stripped of the author's name. The author may object and ask for erasure (§5).
2. Data of the Customer's staff reaches us from the Customer, who opens their accounts in the Service (art. 14(2)(f) GDPR); the scope, purpose and retention are the same as for the account data listed above.
3. Providing the data is voluntary but necessary to use the Service. We do not profile Customers and take no automated decisions with legal effect towards them.
4. The periods above concern production systems. Data deleted from them remains in backups until the backups themselves expire, within the periods described in §3.5 — intended to be at most 90 days.
§3. Guests' data — processing on your behalf (art. 28 GDPR)
1. Guests' data (names, contacts, reservation and stay details, companions, property notes) belong to the Customer, who is their controller. Lodvena processes them as a processor, solely on the Customer's documented instruction, and — beyond what paragraph 6 describes — does not use them for its own purposes. The Customer's documented instruction consists of this Policy, the Terms, and the Customer's settings and actions in the panel (property, forms, check-in kiosk, guest messages, retention period, portal integrations), which the Customer can change in the panel; instructions beyond that scope are given by email to kontakt@lodvena.com. The instruction covers transfers to the recipients listed in §4, including outside the European Economic Area on the basis stated there. Where Union or Member State law requires the Provider to carry out a particular processing operation, the Provider informs the Customer before processing unless that law prohibits such information on important grounds of public interest (art. 28(3)(a) GDPR).
2. Scope of the entrustment: guest identification and contact data, reservation and stay-payment data, the content of automated messages. Purpose: providing the Services described in the Terms. Duration: the term of the contract with the Customer. The entrustment also covers Guests' data that a Customer posts in the Community contrary to the ban in §4 of the Community Rules — solely for the purpose of deleting it and of security, so that such data is never processed outside a processing agreement.
3. It is the Customer who decides what the forms, the check-in kiosk and the messages to Guests collect, what the Guests' information notices say, and how long Guests' data is kept (the retention setting in the panel). The Provider supplies the tools and carries out the Customer's settings.
4. Only people authorised by the Provider and bound to confidentiality are given access to the entrusted data (art. 28(3)(b) GDPR).
5. We apply technical and organisational measures appropriate to the risk, in particular: database-level isolation of each property's data (row-level security), encrypted integration keys, encrypted transport, an audit trail of actions in the panel, and a weekly check that a database dump can actually be restored. Database-level isolation covers database rows, not files: photographs, floor plans and logos uploaded to the Service are served from addresses that work without signing in for anyone who knows them, in the same way as iCal calendar links (§8.3 of the Terms). The Customer decides what to upload and who receives the addresses. In the normal running of the Service we take backups and keep them on the production server for 14 days (database dumps) and 30 days (file packages), and in backup storage off that server under a lifecycle rule set at the storage provider to 90 days. We check the effect of that rule periodically — where the storage configuration lets us read the object listing — and exceeding the period (with 7 days' tolerance) raises an operational alarm, which we answer by removing the excess copies. A backup serves to restore the Service after a failure — it is not an archiving service provided to the Customer and not a guarantee that data can be restored; the Customer's own copy is the export from the panel, or the copy issued on request (paragraph 7).
6. Authorised staff of the Provider access data in the Customer's panel to the extent needed to handle enquiries, to maintain the Service and for aggregate statistics, and change the Customer's settings only on the Customer's instruction. Those statistics cover only aggregated data from which the Customer, the property and the Guest cannot be identified (§9.4 of the Terms). Entry into support mode in the Customer's panel is recorded in that Customer's own event journal — without the journal entry access is not granted — and so is every action the Provider takes on the Customer's account. We also use an internal operations console, restricted to authorised staff bound to confidentiality, in which account data including reservation data may be read for maintenance and support; such a read is not recorded in the Customer's event journal. We give information about the extent of that access on request (paragraph 9).
7. Return and deletion of the entrusted data. During the contract the Customer exports from the panel, as CSV: reservations from the current view (up to 10,000 rows), the guest register and the local tourist-levy summary for a chosen period (up to 5,000 rows). The self-service export does not include image files; a complete copy of the entrusted data — database rows together with the files (photographs, floor plans, logo) — in a machine-readable format is provided on the Customer's request, within 30 days of receiving it, both during the contract and within 30 days of its ending. The choice between return and deletion is the Customer's (art. 28(3)(g) GDPR). We delete the entrusted data — database rows together with the related files — promptly after the copy is provided, and where no request is made, no later than 90 days after the contract ends; the deletion also reaches files no database row points to any more. Deletion is started by authorised staff of the Provider rather than automatically; the Provider keeps a record of the deadlines and confirms the deletion on request. Data expires from backups within the periods in paragraph 5.
8. We assist the Customer with the duties under art. 32–36 GDPR and with responding to data-subject requests. We notify the Customer of a personal-data breach without undue delay after the Provider establishes it; notifying the supervisory authority and informing Guests is for the Customer as controller.
9. On the Customer's request we provide the information needed to demonstrate compliance with art. 28 GDPR, including the current list of sub-processors. The Customer may audit the entrustment — in person or through an auditor they mandate — no more than once a calendar year, on a date agreed at least 30 days ahead, at the Customer's cost, subject to confidentiality and to the security of other Customers' data. The limits on frequency and notice do not apply to an audit concerning a personal-data breach notified under paragraph 8, nor to an inspection by the supervisory authority — in those cases we make the inspection possible without delay, on a date agreed with the Customer or set by the authority. If in our opinion an instruction from the Customer infringes the GDPR or other data-protection provisions, we inform the Customer immediately (art. 28(3)(h) GDPR).
10. Sub-processing: the Customer gives a general authorisation for sub-processors necessary to provide the Services (hosting and infrastructure, backup storage, object storage for uploaded files, channel synchronisation, e-mail delivery, application error monitoring); they are listed in §4. Each of them is engaged under a contract imposing the same data-protection obligations as those set out in this section, in particular the duty to provide sufficient guarantees of appropriate technical and organisational measures (art. 28(4) GDPR). Where a sub-processor fails to fulfil its data-protection obligations, the Provider remains fully liable to the Customer for the performance of that sub-processor's obligations; §12 of the Terms does not limit that liability (§12.7(c) of the Terms). We give 14 days' notice of an intended change. The Customer may object; an objection does not stay the change but entitles the Customer to terminate the contract with effect from the day the change is made, with a proportional refund for the unused period.
§4. Recipients
- PayPro S.A. (Przelewy24), ul. Pastelowa 8, 60-198 Poznań, Poland — subscription payments; as regards Guests' payments, the controller of the transaction data is the Customer, and PayPro is a separate controller;
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany — hosting and server infrastructure; the servers sit in a Nuremberg data centre (Germany, EEA);
- Scaleway SAS, 8 rue de la Ville l'Évêque, 75008 Paris, France — backup storage away from the production server, held in a data centre near Paris (France, EEA);
- the DNS/CDN provider — Cloudflare, Inc. (USA) — network traffic only (including visitors' IP addresses); transferred under Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 (the EU–US Data Privacy Framework), so far as the recipient remains certified under it, and independently of that decision under Standard Contractual Clauses (art. 46(2)(c) GDPR) incorporated into the processing agreement concluded with the recipient;
- the booking-channel synchronisation provider — Channex.io LTD (England and Wales, no. 09250795) — on plans with full portal sync: reservation and Guest data exchanged between the portals and the Service; on the Website plan, only iCal calendar links passed directly to the portals the Customer chooses. Where the Customer connects their own Beds24 account, the contract with Beds24 GmbH stays theirs and the Provider uses only the access they grant. England and Wales lie outside the EEA; the transfer relies on Commission Implementing Decision (EU) 2021/1772 of 28 June 2021 finding an adequate level of protection in the United Kingdom and, should it lapse or be repealed, on Standard Contractual Clauses incorporated into the contract with the recipient;
- cyber_Folks S.A., ul. Wierzbięcice 1B, 61-569 Poznań, Poland (KRS 0000685595, VAT ID 7792467259) — the outgoing mail (SMTP) operator: delivery of transactional messages, including verification codes, payment reminders, invoices, and messages to Guests carrying their name and e-mail address;
- the object-storage provider — storage of files uploaded by the Customer (photographs, floor plans, logo), where the Service uses storage away from the production server;
- the application error-monitoring provider — technical error reports. Sending data that identifies a user is switched off in that tool, but the content of a report may incidentally contain data being processed when the error occurred;
- the Provider's accounting office — sales documents.
The names and seats of the current providers described above by category are given in the current list of sub-processors, which we supply on request (§3.9) and update on every change notified under §3.10.
Data held in the hosting infrastructure and in backups does not leave the European Economic Area. Where another recipient processes data outside the EEA, the transfer relies on the European Commission's adequacy decision for the country concerned and, independently of it, on Standard Contractual Clauses (art. 46 GDPR) concluded with that recipient. A copy of the safeguards applied is available on request to kontakt@lodvena.com (art. 13(1)(f) and 14(1)(f) GDPR).
§5. Your rights
Access, rectification, erasure, restriction, portability, and objection to processing based on our legitimate interest — via kontakt@lodvena.com. You may complain to the Polish supervisory authority (PUODO, ul. Stawki 2, 00-193 Warszawa) or to the authority of your country of residence. Guests' requests concerning reservation data should go to the property (the controller); received by us, they are forwarded to the Customer without delay.
We answer a request within one month; where a request is complex or there are many of them, we may extend that by two further months and will say so within the first month. Before acting on a request we may ask for information confirming the identity of the person making it. Requests that are manifestly unfounded or excessive, in particular because they are repetitive, may be refused or carry a reasonable fee (art. 12(5) GDPR).
§6. Cookies
Only cookies essential to operate the Service: sign-in session, language and theme, security. No third-party marketing or analytics cookies — which is why there is no consent banner. Visit statistics are kept without cookies and without third-party tools, as described in the fifth bullet of §2.1. Essential cookies are processed under art. 399(3)(2) of the Polish Electronic Communications Law and art. 6(1)(f) GDPR. This Policy covers the Lodvena Service; cookies and analytics tools on a property's own website are the Customer's, who switches them on.
The complete cookie list. All first-party; none is set by a third party.
| Name | What for | How long |
|---|---|---|
as_at | panel session token, unreadable by scripts (httpOnly) | until sign-out |
as_rt | renews the session so you do not sign in hourly (httpOnly) | until sign-out |
as_org | which company is selected, when an account has several | until sign-out |
as_lang | interface language | a year |
as_theme | the colour theme you picked | a year |
as_kiosk | arming the check-in tablet at a property | 24 hours |
as_seed_plan, as_seed_palette | what you chose on the price list, so signup does not ask twice | 7 days |
lv_* | the previous names of the above, still read after the rebrand | as above |
Browser local storage. These are not cookies and none of it reaches our server — it stays on your device and you can clear it in your browser. We keep view preferences there only: lv_day_panel and lv_weather_open (whether the day panel and the weather are expanded), as_hint_…, as_tour_… and as_tour_off (which hints you have dismissed), lodvena.nav.… (Navigator view settings) and — on a guest booking page — lv_consent (your answer to the consent question). The lv_ variants are the same keys under the previous name.
§7. Changes
Material changes are announced in the Service and by e-mail 14 days ahead. This version was published on 4 September 2026 and takes effect on 18 September 2026; until then the previous version applies, and events that occurred before the effective date are judged under the wording in force at the time. Earlier versions are sent on request to kontakt@lodvena.com. This is a translation of the Polish Polityka prywatności; in case of divergence the Polish text prevails.