Skip to content
SFERIN

Data processing agreement

When you take bookings and register guests through your SFERIN website, we process their personal data on your behalf. This agreement sets out how.

This is an English translation for convenience. The legally binding text is the Slovak version, which prevails in case of any difference.

Article 1 – Parties and how the agreement is made

The controller is the SFERIN client – the accommodation provider who takes bookings and registers guests through their website. The processor is WebiSfer s. r. o., Talinská 2388/9, 040 12 Košice – mestská časť Nad jazerom, Slovakia, Company ID (IČO) 57 475 687, registered in the Commercial Register of the Košice Municipal Court (Obchodný register Mestského súdu Košice), section Sro, file No. 65153/V, contact info@sferin.sk.

This agreement is made under Article 28(3) of Regulation (EU) 2016/679 (“GDPR”). It is concluded together with the contract for the SFERIN service, i.e. by accepting the Terms and conditions when ordering, and forms part of it. It lasts as long as the service contract and then until the data is deleted or returned under Article 9. On data protection matters, this agreement prevails over the terms and conditions.

Article 2 – Subject matter, nature and purpose of processing

The processor processes personal data on the controller’s behalf only to run the controller’s website with a booking system, for these purposes:

  • running the website and the booking form,
  • receiving and managing bookings and booking requests,
  • keeping the guest register and guest records, including online check-in,
  • preparing tourist tax reports for the municipality,
  • sending emails to guests (booking confirmation, deposit invoice, stay information).

Processing mainly means collecting data through forms on the website, storing it in a database, displaying it in the admin area, sending emails and preparing reports. The data is not used for any other purpose, such as the processor’s own marketing.

Article 3 – Categories of data and data subjects

Data subjects: guests of the property and people who submit a booking request or booking.

Categories of personal data:

  • identification data – name, date and place of birth, nationality,
  • contact data – email, phone, permanent address,
  • identity document data – document type and number,
  • for foreign nationals, the data the host collects under Slovak Act No. 404/2011 Coll. on the residence of foreigners (for example visa number and validity and purpose of stay),
  • booking data – dates of stay, number of guests, price, payments, notes and communication with the guest.

No special categories of personal data under Article 9 GDPR are processed.

Article 4 – Controller’s instructions

The processor processes personal data only on documented instructions from the controller (Article 28(3)(a) GDPR). The instructions are this agreement, the settings the controller chooses in the admin area and requests sent by email. If, in the processor’s opinion, an instruction infringes the GDPR or other data protection law, it will inform the controller immediately. It does not transfer data to third countries except in line with Chapter V GDPR (see Article 7).

The controller is responsible for having a legal basis for processing guest data, for informing guests (the property’s privacy policy) and for entering only the data it needs.

Article 5 – Confidentiality

The processor ensures that persons authorised to process personal data are bound by confidentiality (Article 28(3)(b) GDPR and Section 79 of Slovak Act No. 18/2018 Coll. on personal data protection). Confidentiality continues after the agreement ends.

Article 6 – Security

The processor has adopted these technical and organisational measures under Article 32 GDPR:

  • all communication with the website and admin area is encrypted (HTTPS, SSL certificate),
  • identity document and visa data is stored encrypted in the database (AES-256-GCM),
  • the server is located in a data centre in the European Union,
  • data is backed up,
  • access to the admin area is protected by a password with optional two-factor authentication; each controller sees only the data of its own property,
  • the website is protected against attacks and bots by Cloudflare,
  • software is kept up to date and important changes are logged.

Article 7 – Sub-processors

The controller gives general authorisation for the processor to use the sub-processors listed below (Article 28(2) GDPR). The processor will inform the controller by email in advance of any intended addition or replacement; the controller may object within 30 days and, if no agreement is reached, may cancel the service. The processor binds sub-processors to the same data protection obligations (Article 28(4) GDPR).

  • Contabo GmbH, Germany – hosting, the server with the database and website in a data centre in the EU,
  • Cloudflare, Inc., USA – DNS, network protection and website acceleration, bot protection for forms (Turnstile); transfers to the USA are covered by the EU-US Data Privacy Framework,
  • Websupport s. r. o., Slovakia – mailbox and sending emails to guests, where emails are sent through a mailbox set up by the processor.

Services called directly by the visitor’s browser. The map on the website loads tiles from OpenStreetMap and a library from unpkg.com; the address autocomplete in online check-in sends the partially typed address to Photon (komoot GmbH, Germany) and Nominatim (OpenStreetMap). These services receive the visitor’s IP address and the typed text, not data from the database. The Google Maps directions link opens only when clicked. Google Analytics or Google Tag Manager run on the website only if the controller enables them and only with the visitor’s consent; the controller is then responsible for them.

Article 8 – Assistance and personal data breaches

The processor assists the controller in responding to guests’ requests to exercise their rights – access, rectification, erasure, restriction, portability and objection (Article 28(3)(e) GDPR). If a guest sends such a request directly to the processor, it forwards it to the controller without undue delay. It also assists the controller with its obligations under Articles 32 to 36 GDPR (point (f)).

If the processor becomes aware of a personal data breach, it notifies the controller without undue delay and no later than 48 hours after becoming aware of it (Article 33(2) GDPR). The notification contains the information available to it that the controller needs to meet its obligation under Article 33(3) GDPR (nature of the breach, data and people affected, likely consequences and measures taken). Notifying the Slovak data protection authority and guests is the controller’s task.

Article 9 – When the agreement ends

When the service ends, the processor returns the data as an export (bookings and guest records) if the controller asks within 30 days of the end, and deletes the personal data, including copies, no later than 90 days after the end, unless EU or Slovak law requires it to be kept (Article 28(3)(g) GDPR). This matches Article 10 of the terms and conditions.

Article 10 – Information and audits

The processor makes available to the controller all information necessary to demonstrate compliance with Article 28 GDPR and allows for audits or inspections by the controller or an auditor it appoints (Article 28(3)(h) GDPR). The date and scope of an audit are agreed in advance so that it does not disrupt the service or the security of other clients’ data.

Article 11 – Final provisions

Liability for damage caused by an infringement of the GDPR is governed by Article 82 GDPR. Matters not covered by this agreement are governed by the GDPR, Slovak Act No. 18/2018 Coll. on personal data protection and the SFERIN terms and conditions. The agreement is governed by Slovak law and is valid and effective from 11 October 2026.