1. General provisions
The privacy policy explains how “LUX HOSPITALITY” SRL (hereinafter referred to as the “Company” or the “Operator”) collects, uses, stores and protects personal data.
The policy applies to the processing of data in connection with the use of the official website, mobile and online services, reservation systems, e-mail, telephone communications, social networks and messaging services of the Company, as well as in the case of personal visits and receipt of services offered by the Company.
The policy was prepared in accordance with the Law of the Republic of Moldova no. 195/2024 on the protection of personal data and other applicable normative acts of the Republic of Moldova. In cases where the Company’s activity falls under Regulation (EU) 2016/679 (GDPR), the corresponding processing is also carried out in accordance with GDPR.
The policy covers the Company’s activity in the following areas:
- hotel services and related services for guests
- restaurant
- beauty salon
- SPA services, body care treatments (which do not constitute medical services)
- organizing and managing events
- making conference rooms and other spaces available
- loyalty programs, gift cards, campaigns and marketing communications
- ensuring the security of the premises, including access control and video surveillance.
If a particular domain, service or event requires additional information, the Company provides a brief special notice that applies in conjunction with this Policy.
2. Information about the operator
| Operator | LUX HOSPITALITY SRL |
|---|---|
| Address | Republic of Moldova, MD-2012, Chișinău, 132 Ștefan cel Mare și Sfânt Boulevard |
| Phone | +373 68 400 400 |
| General email | info@nobil.md |
| Contact for the protection of personal data | dpo@nobil.md / dpo@luxhospitality.md |
| Contact for IT and Security | it@nobil.md |
Requests regarding the exercise of data subjects’ rights must be sent to dpo@nobil.md / dpo@luxhospitality.md or to the Company’s postal address. The it@nobil.md contact is intended for notifications about technical and informational security and does not replace the channel for exercising the rights of data subjects.
3. To whom the Policy applies
The Policy applies to users of the website and online services, customers and potential customers, hotel guests, restaurant, beauty salon and SPA visitors, customers and event attendees, partner representatives, visitors to the Company’s facilities, employees, job candidates, as well as other people who interact with the Company.
The processing of employee data is regulated by internal notices and separate documents of the Company. Candidates for the positions may be provided with a separate notification upon receipt of the CV.
4. Categories of personal data
4.1. Users of the website and online services
- IP address, device and session identifiers
- device type, operating system, browser and language settings
- pages visited, date, time and duration of the visit
- reference source, site actions, technical logs
- cookies and other online identifiers
- data entered in web forms, chats or other communication channels.
4.2. Hotel services
- name, surname, contact and identification data
- information about the document, necessary for registration and compliance with the requirements of the law
- period of stay, room type, number and composition of guests
- booking history, changes, cancellations, requests and complaints
- preferences and special requests
- vehicle and access information when required
- contractual, invoicing and payment data.
4.3. Restaurant
- name and contact details of the person making the booking or order
- date, time, number of guests, order and event information
- food preferences
- information about allergies and dietary restrictions, voluntarily provided for safe serving
4.4. Beauty salon and SPA
- name, contact details and appointment information
- procedures chosen, and preferences
- information about contraindications, allergies, pregnancy, health or other circumstances, if necessary for the safe provision of the chosen service
- client questionnaires, confirmations of awareness of contraindications and consents
- payment information,
4.5. Events and conference rooms
- data of the client, the organizer and their representatives
- contractual, financial and contact data
- information about the event, participants, accommodation, meals and technical requirements
- the list of participants and guests, if provided by the organizer
- access and permission information.
4.6. Partners and representatives of organizations
- name, surname, position and organization
- service contact details
- contractual correspondence and powers of attorney
- information about services, invoices, payments and settlements
- credentials for access to Company systems, if required and permitted.
4.7. Video surveillance and access control
- image, date, time and location in the controlled area
- ID data, entry and exit information
- materials related to security incidents.
4.8. Payment
Depending on the payment method, the Company may process the payer’s name, amount paid, date, purpose, bank account/IBAN, billing address, identifier and transaction status. Full bank card details are usually processed by the bank or payment provider; The Company receives limited information necessary to confirm and record the payment.
4.9. Telephone conversations
In the case of contacting the reception or other official telephone lines of the Company, the voice, telephone number, date, time and duration of the call may be processed, as well as the information voluntarily provided during the conversation, including the name, details of the reservation, order, request or complaint. The company does not ask for excessive information over the phone and does not recommend providing data unrelated to the purpose of the contact.
5. Purposes, Data and Legal Basis
The Company processes data only when there is an applicable legal basis. Consent is not the only basis and is not required where processing is necessary for a contract or for the performance of an obligation provided by law.
| Purpose | Main data | Legal grounds |
|---|---|---|
| Processing the request, calculating the offer, registering or booking | Contact data, request content, selected services | Pre-contractual measures at the request of the person; legitimate interest in the organization of communication |
| Providing hotel, restaurant, beauty, SPA, events and conference services | Identification, contact, booking, contractual and service data | Conclusion and execution of a contract; legal obligation, and when applicable |
| Guest registration, accounting, tax and other mandatory records | Identification, contractual and financial data | Fulfillment of legal obligation |
| Safe provision of beauty, SPA and restaurant services | Contraindications, allergies and other necessary information communicated voluntarily | Execution of the contract and, for special categories of data, explicit consent or other basis specifically provided by law |
| Payments, refunds and fraud prevention | Payment data, amount, identifiers and transaction status | Execution of the contract; legal obligation; legitimate interest in preventing abuses |
| Safety of people, goods and buildings | Video recordings, access control data and incidents | Legitimate interest of the Company and third parties in ensuring security and protecting rights |
| Review of requests, reviews, complaints and legal defense | Contact, contractual, correspondence and evidence data | Execution of the contract; legal obligation; legitimate interest in the protection of rights |
| Direct advertising, newsletters and personalized offers | Contact details, marketing preferences, consent information | Consent or other directly applicable legal basis; the right of opposition remains valid |
| Analytical and advertising cookies | Online Identifiers, Site Usage Information | Prior consent, when required |
| Recruitment | CV, contact details, qualifications and communication results | Pre-contractual measures; consent to keep personnel in reserve; legal obligation, if applicable |
| Photo and video materials for advertising | Images, voice, event information | Separate consent or other appropriate basis after prior information |
| Audio recording and fixing of telephone conversations (reception) | Voice, telephone number, date and time of call, information communicated during conversation (including name and details of booking, order or request) | Pre-contractual measures at the request of the person and/or execution of the contract — for the preparation and confirmation of the request, reservation or order; the Company’s legitimate interest after assessing necessity and proportionality — for quality control, staff training, abuse prevention and dispute resolution; consent — only when chosen as the basis for a particular operation and given after clear prior information. The basis is determined separately for each purpose and does not needlessly apply cumulatively. |
When the Company relies on legitimate interest, it assesses the necessity and proportionality of the processing and takes into account the rights and reasonable expectations of data subjects. The data subject has the right to object to such processing in the cases provided for by law.
6. Special categories of personal data
In the provision of restaurant, hotel, salon and SPA services, the client may voluntarily communicate information about health, allergies, disabilities, pregnancy, contraindications, religious or dietary restrictions. Company:
- does not collect such information automatically or “just in case”
- only requests the information objectively necessary for the secure provision of the specific service
- ensure access only to employees and contracted specialists who need this data
- do not use this information for incompatible purposes or advertising without a separate basis
- delete or anonymize the information after the expiration of the established term
- if necessary, obtain the subject’s clear, specific and informed consent.
The withdrawal of consent does not affect the legality of the processing carried out before the withdrawal. If without certain information the procedure cannot be performed safely, the Company may refuse this procedure by providing a safe alternative available.
7. Data acquisition sources
The Company obtains the data directly from the subject and, depending on the situation:
- from the person making the reservation for other guests
- from the employer, corporate client, travel agent or event organizer
- through hotel and tourist booking platforms and other similar platforms
- from payment organizations and banks
- from public registers and open legal sources
- automatically when using the Company’s website and systems.
The person who transmits to the Company the data of other persons must have a legal basis for such transmission and inform them. The Company provides subjects with the mandatory information under the conditions and terms established by law, unless a legal exception applies.
8. Obligation to provide data
The data necessary for the conclusion and execution of the contract, the registration of the guest, the payment or the fulfillment of an obligation provided by law are mandatory for the corresponding operation. Without these, the Company may not be able to confirm the booking or provide the service. Providing additional preferences and consent to marketing is voluntary; the refusal does not affect the receipt of the main service.
9. Beneficiaries and service providers
To the extent necessary and based on a legal basis, the data may be accessed or transmitted:
- to the employees and authorized subdivisions of the Company
- hotel, restaurant, CRM, beauty/SPA service providers and online scheduling systems
- booking platform operators and tourism partners
- banks and payment service providers
- providers of hosting, cloud infrastructure, email, communications and technical support
- security services and access control system providers
- event contractors, including technical suppliers, photographers and videographers, when necessary and lawful
- accountants, auditors, insurers, lawyers and other professional consultants
- governmental, regulatory, judicial and law enforcement authorities — where there is a legal requirement or obligation.
Suppliers who process data at Company’s request are bound by contractual requirements regarding confidentiality, security and processing only according to Company’s documented instructions. In separate cases, the recipient acts as an independent operator and provides its own notice.
10. International Data Transfer
Some providers of cloud, communication, analytical, payment or reservation services may process data outside the Republic of Moldova. Before the transfer, the Company checks the existence of the mechanism provided by law and applies the necessary guarantees, including the decision on an adequate level of protection, standard contractual clauses, mandatory rules or any other permitted basis.
When the processing is carried out in accordance with the GDPR, the international transfer is additionally carried out in accordance with the requirements of Chapter V of the GDPR. Information about the specific mechanism can be requested at dpo@nobil.md / dpo@luxhospitality.md; some information may be restricted to protect trade secrets and security.
11. Retention Periods
The Company retains data no longer than is necessary for the appropriate purpose, taking into account mandatory retention periods, limitation periods, the need to resolve disputes and the protection of rights. The specific periods are set out in the internal retention schedule.
| Category | Period or criterion |
|---|---|
| Unconfirmed requests and bookings | Until the communication is completed, then for a limited period necessary to confirm the processing of the request and protect the rights; marketing — only on a separate basis |
| Contracts, bookings and history of services provided | During the validity of the contract and the applicable retention and limitation periods |
| Registration, fiscal and accounting documents | During the terms expressly established by the legislation of the Republic of Moldova |
| Beauty/SPA questionnaires and information on contraindications | For the necessary justified period for safe services, the resolution of complaints and compliance with legal requirements; subsequent deletion or anonymization |
| Marketing data and consents | Until withdrawal of consent or opposition; proof of consent/withdrawal — for the duration necessary to comply with the obligation and protect rights |
| Resumes | Until the selection is completed; for staff reserve — for the duration communicated separately, with existing consent |
| Video surveillance | As a rule, no more than 30 calendar days, if the recording is not kept for a longer period due to a specific incident, an investigation, a requirement of the authority or the protection of rights |
| Cookies | In accordance with the purpose and terms specified in the settings and in the Cookie Policy |
| Technical logs and security | For the duration corresponding to the purpose of diagnostics, incident prevention and system protection |
| Telephone call recordings | As a rule, no more than 90 calendar days from the date of the call. Retaining a specific record for a longer period is permitted if it is necessary to manage an ongoing request, investigate an incident, fulfill a legal obligation or establish, exercise or protect rights; in this case, the record is kept until the completion of the appropriate procedure and the applicable protection term. |
At the end of the period, the data is deleted, destroyed, irreversibly anonymized or isolated from normal use, if temporary retention is required by law or for the protection of rights.
12. Video surveillance and recording of telephone conversations
12.1. Security video surveillance
Video surveillance is used to ensure the safety of guests, visitors and employees, incident prevention and investigation, property protection and access control. This is done based on the legitimate interest of the Company and third parties, respecting the principles of necessity, proportionality, data minimization and transparency.
Video surveillance is not installed in hotel rooms, restrooms, changing rooms, procedure rooms and other places where there is a reasonable expectation of increased privacy.
- before entering the controlled area, clear informational indications are displayed, which allow obtaining basic information about the processing and familiarizing yourself with this Policy
- access to video recordings is granted only to a limited circle of authorized persons, to the extent necessary for the performance of their duties
- recordings are not used for advertising, evaluation of service quality or other incompatible purposes
- transmission of records to state authorities, courts or law enforcement bodies is carried out only in the presence of a basis provided by law
- video surveillance is not accompanied by audio recording (sound recording).
The request for access to the video recording is examined taking into account the rights and freedoms of other persons, the technical possibility of search and the need to preserve evidence. The Company has the right to apply image masking to third parties or to grant access by other means provided by law.
12.2. Recording phone calls (audio recording)
In order to document and confirm requests, reservations and orders, prevent abuses, as well as warn and resolve disputed situations, control the quality of services, the Company can record calls received and made through the official telephone lines of the reception.
The registration and further processing is carried out only if there is an applicable legal basis, provided by the Law of the Republic of Moldova no. 195/2024 and, as the case may be, the GDPR: taking measures before the conclusion of the contract at the request of the person, the execution of the contract, the legitimate interest of the Company after assessing the necessity and proportionality or the consent of the person concerned. The Company determines the basis taking into account the specific purpose of the processing and does not use consent to replace another appropriate basis.
- before the start of the recording, the person is informed by an automatic voice message or, in the case of the initiated call, by another clear verbal notification. Recommended wording: “We draw your attention: the conversation may be recorded for the purpose of documenting and confirming your request, resolving disputed situations and controlling the quality of services. By continuing the conversation, you confirm that you have been informed about the processing of personal data. Detailed information and alternative contact channels are available in the Privacy Policy on the Company’s website”
- if, in the specific case, the legal basis is consent, continuing the conversation after a clear alert is considered a clear affirmative action only on the condition that the person can effectively refuse the recording without adverse consequences and use an alternative contact channel available; the fact and content of the notification are documented
- the person who does not want to continue the recorded conversation can interrupt the call and use the alternative channel indicated by the Company: e-mail, web form on the website or personal address. The alternative channel must not unduly diminish the possibility of obtaining the main service
- during the conversation, only the data related to the purpose of the request are processed; special categories of data are not requested if this is not objectively necessary and there is no special legal basis
- only specially authorized employees and IT administrators have access to the audio recordings, who need this access to perform their job duties; actions on records are subject to monitoring and, where technically possible, logging
- Audio recordings are not used for advertising or other incompatible purposes and are not transmitted to third parties, except to service providers acting in accordance with the Company’s documented instructions, professional consultants and authorities who have the legal right to obtain them
- Recordings are kept for a limited period, determined by the internal storage program, after which they are automatically deleted, except where a particular recording is necessary to fulfill a legal obligation, investigate an incident or establish, exercise or defend legal rights
- The data subject may exercise the rights provided in sections 18–19 of this Policy, including requesting access to the record that concerns him, subject to the rights of third parties and restrictions provided by law.
13. Photographing and filming events
Security video surveillance differs from photographing and filming events. If the Company organizes the filming for advertising purposes, for the website or social networks, the participants are informed in advance, and when necessary — they are asked for separate consent. Ordering or participating in the event does not in itself mean consent to the use of the image for advertising purposes.
If the filming is organized by the customer or an independent contractor, their roles and data protection obligations are determined by the contract and the actual purposes of the processing. Participants are provided with appropriate information.
14. Cookies and Similar Technologies
The site may use strictly necessary, functional, analytical and advertising cookies. Strictly necessary cookies are used for the operation and security of the site. Analytical, advertising and other non-mandatory cookies are activated only after obtaining prior consent, when required by law.
The visitor can accept or refuse some of the categories and can later modify the choice through the cookie settings. The refusal must not prevent access to the basic content of the site, except for functions that objectively depend on the corresponding technology. The detailed list of providers, purposes and durations is available in a separate Policy on the use of cookies and in the settings panel.
15. Marketing Messages
The Company only sends direct marketing messages if there is an applicable basis. Consent to marketing is separate from consent to receive the main service, is not pre-checked and can be withdrawn at any time. Every electronic marketing message contains an accessible method of unsubscribing free of charge. After opting out, the contact can be kept in a minimal exception list to avoid sending again.
16. Data of minors
The Company may process information about minor guests when this is necessary for reservation, accommodation, participation in events or provision of a service and is permitted by law. Depending on the age of the minor, the nature of the service and the applicable basis, the data is provided by the legal representative, with his participation, or is processed on another appropriate basis. If consent is required, the Company checks who is required to provide it under applicable law and takes reasonable steps to confirm the authority of the legal representative. The company only collects the minimum necessary information, does not use children’s data and applies increased transparency and security measures.
17. Automated decisions
As of the date of this text, the Company does not make decisions regarding customers based solely on automated processing, including profiling, which generate legal consequences or similarly significantly affect them. If such processing will be implemented, the Company will provide in advance the information required by law, including the logic and possible consequences, and provide the necessary guarantees.
18. Rights of data subjects
Depending on the applicable law and the circumstances, the data subject has the right to:
- receive information about the processing and access to his data
- request the correction of inaccurate data or the completion of incomplete ones
- request the deletion of the data, if there is no legal basis for their retention
- request restriction of processing
- receive data in a structured, recognizable and machine-readable format and request its transmission to another operator when the right to portability applies
- challenge processing based on legitimate interest, taking into account the exceptions provided by law
- at any time and without explanation, contest direct marketing
- withdraw the consent without affecting the legality of the processing until its withdrawal
- not be subject to a decision based solely on automatic processing, when such a decision generates substantial legal or similar consequences, unless the exception is provided by law
- file a complaint with the competent supervisory authority and use other means of protection.
Rights are not absolute. For example, the Company may continue to store the data if this is necessary to fulfill a legal obligation, to establish, exercise or defend legal rights or on another basis provided by law.
19. Procedure for exercising rights
The request can be sent to dpo@nobil.md / dpo@luxhospitality.md or to the Company’s postal address. The request must describe the request and the data that allows the identification of the corresponding information. To prevent unauthorized disclosure, the Company has the right to request reasonable confirmation of identity without collecting excessive information.
The request is examined without undue delay and within the time limit set by the applicable legislation. If the request is complex or numerous, the deadline can be extended within the limits provided by law, with notification of the reasons to the applicant. Exercising the rights is generally free; for repeated obviously unjustified or excessive requests, the measures provided for by law may be applied.
20. The supervisory authority
If you consider that the processing violates the legislation, you have the right to contact the National Center for the Protection of Personal Data of the Republic of Moldova (CNPDCP):
- address: MD-2004, Chisinau municipality, 48 Sergiu Lazo str
- phone: +373 22 820 801
- email: centru@datepersonale.md
- website: https://datepersonale.md.
21. Data security
The Company applies technical and organizational measures commensurate with risks, including access management and distribution of duties, account and system protection, backups, logging, staff training, contractual confidentiality obligations, vendor verification and incident response procedures. For operations that may involve an increased risk for the rights and freedoms of individuals, the Company carries out a preliminary risk assessment and, when required by law, an assessment of the impact on the protection of personal data. The measures are periodically reviewed, taking into account the nature of data, technologies, cost of implementation, probability and severity of risks. No mode of transmission or storage guarantees absolute security. In the event of a security breach, the Company documents and assesses the incident and, when required by law, notifies the supervisory authority and data subjects.
22. Modification of the Policy
The Company has the right to update the Policy in case of changes in legislation, activity, technologies or processing processes. The current version is published on the website with the date of application. In case of significant changes, the Company uses additional reasonable methods of information.
23. Contacts
For questions regarding this Policy and the processing of personal data, please contact:
- dpo@nobil.md / dpo@luxhospitality.md — contact for personal data protection
- info@nobil.md — general requests
- +373 68 400 400 — phone
- LUX HOSPITALITY SRL, MD-2012, Chișinău, 132 Ștefan cel Mare și Sfânt Boulevard, Republic of Moldova — postal address.