CallaniaBooking

Privacy Policy — Callania Booking

version 1.2 · effective from 21 August 2026

Download as PDF

This translation is for information only. The binding version is the Slovak wording available at callania.eu/ochrana-udajov. In case of any discrepancy, the Slovak text prevails.

1. Who is the controller

  • Company: MACET, s.r.o. · Registered office: Nitrianska 32/189, 949 11 Nitra · Company ID (IČO): 35 953 781
  • Contact: booking@callania.eu

We have not appointed a Data Protection Officer (DPO) — we do not meet the conditions of Article 37 GDPR. If that changes, we will add the contact here.

2. Two different roles that need to be told apart

As a controller we process the data of people who create an account with us — our clients and prospects. That is what this document describes.

As a processor we process the data of our clients’ customers — people who book an appointment through the system. That data belongs to the client, who determines the purpose and the scope, and we only do with it what the client instructs. The relationship is governed by the Data Processing Agreement.

If you booked an appointment with someone and want to exercise your rights, contact that business. We will help them do it, but we cannot decide about their data.

3. What data we process as a controller

CategoryWhat it isLegal basisFor how long
Accountemail, password (stored as a hash, never readable), business name, languageperformance of a contractfor the life of the account and 14 days after the account is closed
Billing detailscompany name, registered office, company ID, tax ID, payment historyperformance of a contract and legal obligation10 years under the Accounting Act
Operational recordssign-ins, IP address, settings changes, auditlegitimate interest — security of the service12 months
Technical logsrequest paths, errors (tokens and phone numbers are masked)legitimate interest — operating the service and investigating incidents30 days
Contact form and prospectsemail, name, message, where they came fromlegitimate interest — replying to an enquiryuntil handled, at most 24 months
Marketing communicationemailconsentuntil consent is withdrawn

We do not process special categories of data (health, biometrics and the like) about our clients and we do not carry out automated decision-making or profiling with legal effect.

4. Where the data is held

The servers are in Germany, in the data centre of Hetzner Online GmbH. The data does not leave the European Economic Area.

5. Who receives the data

RecipientWhyWhere
Hetzner Online GmbHhosting and backupsGermany
Webglobe, a.s. (company ID 52486567)sending email (SMTP)Slovakia
BulkGate s. r. o.sending SMSCzechia

We do not sell the data and do not provide it for advertising purposes. We hand it to public authorities only where the law requires it.

6. Cookies and measurement

We use technical cookies necessary for sign-in and security (session, CSRF protection) — these are required for the service to work and cannot be switched off.

With every booking we store the source of the visit (where the person came from — campaign, social network, QR code, partner link). The value is first-party, lasts 30 days and helps the business know what brings it customers. We do not combine it with third-party advertising identifiers and we do not track people across other websites.

We do not use third-party analytics. If that changes, we will state here which tool, on what legal basis, and how to opt out.

7. Your rights

You have the right of access to your data, to rectification, erasure, restriction of processing, portability, and the right to object to processing based on legitimate interest. Consent, if you gave it, can be withdrawn at any time — withdrawal does not affect processing carried out before it.

Closing your account

You can close your account yourself under My account → Close account. It is confirmed with your password, not a checkbox.

What happens:

- We sign you out on every device and email your address a link that undoes the closure. - For 14 days the account is only marked. During that time one click reverses it. Signing in alone does not undo it — you have to click. - After 14 days the account is deleted: email, name, password hash, memberships, sign-ins, tokens, stored consents and unfinished business drafts.

The business does not disappear with you. If you are its only owner and someone else is still there, the closure first asks you to name a successor, who becomes the owner immediately. If you are there alone, you close the business first (it has its own period) and only then the account.

What stays even after deletion, and why:

WhatWhyFor how long
Issued invoices, including the customer’s name and addressthe Accounting Act; GDPR allows this in Art. 17(3)(b) — a legal obligation takes precedence over erasure. A document must also not be altered afterwards; rewriting the name would make it invalid10 years
Audit records (who did what)otherwise the audit could be emptied simply by closing an account. The link to the account is removed, only the record of the action remains12 months
Bookings you entered over the phonethey belong to the business and the guest, not to you. The system does not link your account to them at allper the business’s retention setting

We can show exactly what was deleted and what merely lost its link — every deletion writes a breakdown by record type into the audit.

Write to booking@callania.eu. We reply within one month; if it were to take longer, we will say why.

If you believe we handle your data incorrectly, you can contact the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky), Hraničná 12, 820 07 Bratislava.

8. How we protect the data

  • transfer exclusively over an encrypted connection (HTTPS)
  • passwords stored with argon2id, never readable
  • the database is not reachable from the internet; server access by key only, no passwords, no root
  • data of individual businesses is separated, verified by automated tests
  • backups are encrypted and once a month we automatically verify that they can be restored
  • tokens and phone numbers are masked in operational logs
  • access and changes are written to the audit

Should a personal data breach with a risk to people’s rights occur nevertheless, we will notify the authority within 72 hours and the people concerned without undue delay.

9. Changes

We may update this document. We will announce material changes to clients by email at least 30 days in advance; the date of the last change is shown at the top.


Related documents: Obchodné podmienky · Spracovateľská zmluva

Back to home · Contact