Privacy Policy (GDPR)

We, Roset Hotel & Residence, are committed to safeguarding the privacy of our guests and visitors.

Privacy
Policy (GDPR)

At Roset Hotel & Residence, we are committed to protecting the privacy of our guests and visitors to the fullest extent.

For this purpose, we have prepared this Privacy Policy to explain how we process personal data obtained from you or about you through visits to our website, our premises, written or verbal communication with you, or from other sources (hereinafter referred to as the “Policy”).

This Policy explains how we collect, use and protect personal data, as well as the rights of data subjects, particularly in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and applicable data protection legislation.

A.
Controller

Since 2022, Roset Hotel & Residence has been operated by T&H Management, s.r.o., which also acts as the controller of personal data in accordance with the applicable legal regulations:

T&H Management, s.r.o.
Štúrova 10, 811 02 Bratislava, Slovak Republic
Company ID (IČO): 53570219
Registered in the Commercial Register of the Municipal Court Bratislava III, Section Sro, File No. 150463/B

(hereinafter referred to as “Roset Hotel & Residence” or the “Controller”)

B.
Scope and Purpose of
Personal Data Processing

We collect and process personal data when you visit our website, our premises, make reservations, use accommodation services, communicate with us in writing or verbally, or through other sources.

The scope of personal data processed depends on the services provided and the purposes of processing. Personal data are processed mainly for the following purposes:

• reservation and provision of accommodation services
• guest registration, stay records and compliance with legal obligations
• fulfilment of obligations arising from legal regulations relating to guest registration and reporting obligations
• handling requests, enquiries and communication
• accounting, invoicing and payment processing
• protection of property and persons
• operation of the website and analytical tools

Personal Data of Children

Personal data relating to children are processed solely to the extent necessary for the provision of accommodation services, compliance with legal obligations and guest registration requirements.

Special Categories of Personal Data

Special categories of personal data include, in particular, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data, health-related data or data concerning a person’s sex life or sexual orientation.

Special categories of personal data are not processed unless such processing is required by applicable legal regulations or unless such data are voluntarily provided by the data subject.

Health-related information may be processed to the extent necessary to ensure the provision of services or to accommodate specific guest requirements.

C.
How We Collect
Personal Data

We obtain personal data directly from you or from other sources in connection with the provision of accommodation services, hotel operations and related services.

Personal data may be collected in particular:

Personal data may also be obtained from third parties where necessary for the provision of services or compliance with contractual or legal obligations.

D.
How We Use
Your Personal
Data

Personal data are used solely to the extent necessary for the provision of services, compliance with contractual and legal obligations and the proper operation of the hotel.

Personal data may be processed for the following purposes in particular:

Personal data may be processed on the basis of:

Marketing information is sent only where permitted by applicable legal regulations or based on the consent of the data subject. If you no longer wish to receive marketing information, you may contact us at .

Data may also be processed for statistical purposes, analysis of website usage and improvement of the services provided.

We pay maximum attention to the protection of personal data regardless of the manner in which they were obtained and ensure their protection throughout the entire period of processing.

This Privacy Policy and related information on personal data processing are available throughout the entire service process, from reservation and guest stay until the completion of the services provided.

E.
Retention Period
of Personal Data

Personal data are retained for the period necessary for the provision of services, compliance with contractual and legal obligations or for the protection of the legitimate interests of the Controller.

The retention period of personal data may be extended where required by applicable legal regulations or where necessary to protect the rights and legitimate interests of the Controller.

Personal data are retained in particular for the following periods:

Upon expiry of the retention period, personal data are securely deleted, anonymised or destroyed in a manner preventing their recovery or further processing.

F.
Rights of
Data Subjects

A data subject is any natural person whose personal data are processed by the Controller.

The data subject has the right to:

If you no longer wish to receive marketing information or wish to exercise any of your rights, you may contact us at .

Requests from data subjects shall be handled in accordance with the applicable legal regulations and within reasonable time limits.

G.
Recipients and Processors
of Personal Data

Personal data may, to the extent necessary, be disclosed to or processed by third parties providing services to the Controller or ensuring the operation of the hotel and related services.

The Controller has implemented appropriate technical and organisational measures to ensure that all recipients and processors process personal data in accordance with applicable legal regulations.

Personal data may be processed in particular by the following recipients and processors:

Personal data may also be disclosed to other recipients where required by applicable legal regulations or where necessary for the provision of services.

The Controller may update this section of the Privacy Policy from time to time.

H.
Transfer of Personal
Data to Third Countries

Certain recipients or processors of personal data may be established or process personal data outside the European Union or the European Economic Area.

Transfers of personal data are carried out solely in accordance with applicable legal regulations and subject to appropriate safeguards ensuring an adequate level of personal data protection.

The Controller may use the services of international providers, including Google LLC, Microsoft Corporation, Booking Holdings Inc., Expedia Group and other related service providers.

Where personal data are transferred outside the European Union or the European Economic Area, the Controller ensures appropriate safeguards in accordance with the GDPR.

I.
Security

We implement appropriate technical, organisational and security measures to protect personal data against unauthorised access, loss, damage, disclosure or any other unauthorised processing.

Employees, processors and recipients of personal data are required to maintain confidentiality and act in accordance with the adopted security measures.

Personal data are processed in both electronic and paper form with an appropriate level of protection throughout the entire period of processing.

J.
Cookies and
Analytical Tools

Cookies and similar technologies may be used when visiting the website to ensure the proper functioning of the website, analytical purposes and improvement of user experience.

The website may use analytical and marketing tools, including Google Analytics (GA4), Google Ads, Google Hotels and related services.

The use of cookies is governed by separate cookie settings or policies available on the website.

K.
Links and References 
to Other Websites

The website may contain links to third-party websites.

The Controller shall not be responsible for the content, security or personal data processing practices of third-party websites. We recommend reviewing the privacy policies of the respective operators of such websites.

L.
Updates to the
Privacy Policy

This Privacy Policy may be updated or amended from time to time.

The current version of the Privacy Policy is always published on the Controller’s website.

Any changes shall become effective upon publication unless stated otherwise.

M.
Contact Details

If you have any questions regarding personal data protection or wish to exercise your rights as a data subject, you may contact us at:

Roset Hotel & Residence
Štúrova 10
811 02 Bratislava
Slovak Republic

E-mail:

This Privacy Policy becomes effective on: 20.05.2026

Book online The lowest price guarantee