Personal Data Processing Policy
How we protect the data of tourists, visitors, and our partners.
The privacy of your data is the foundation of trust in the GIAConnect platform. This document transparently details how we collect, use, store and protect your information, in strict compliance with Regulation (EU) 2016/679 (GDPR), Law no. 190/2018 on GDPR implementation measures in Romania, and applicable legislation in the EU member states where we operate.
Table of Contents
1 Data Controller Identity
In accordance with Art. 13 and 14 GDPR, we inform you that your personal data is processed by:
Identification Data
- Company Name: LAVALI ONLINE SHOP SRL
- VAT ID: RO48870445
- Trade Register No.: J23/6383/2023
- Registered Office: Str. Oituz, nr. 80, Popești-Leordeni, Jud. Ilfov, 077160, România
- Country: România (UE)
Data Protection Officer (DPO)
For any questions or requests regarding personal data, you can contact us:
- dpo@giaconnect.com
- contact@giaconnect.com
- +40 762 777 111
Response time: max. 30 calendar days
2 Essential Definitions
| Personal data | Any information relating to an identified or identifiable natural person (name, email, phone, IP address, location data, etc.) |
| Processing | Any operation performed on data: collection, recording, organization, storage, modification, consultation, use, transmission, deletion. |
| Controller | LAVALI ONLINE SHOP SRL - the entity that determines the purposes and means of processing. |
| Processor | Third-party entities that process data on our behalf (technical providers, cloud services). |
| Data subject | You - the user of the GIAConnect platform (tourist or accommodation owner). |
3 Categories of Data Collected
We collect only the data strictly necessary for the operation of the platform, in accordance with the data minimization principle (Art. 5 GDPR):
For Tourists:
- Identification data: First name, last name
- Contact data: Email address, phone number
- Travel preferences: Favorite destinations, approximate budget (optional)
- Content of messages sent through the platform to property owners
For Accommodation Property Owners:
- Company identification data: Name, Tax ID, Trade Register No., Registered office
- Legal representative data: Name, surname, position
- Contact data: Email, phone, correspondence address
- Banking data: IBAN for payment verification (we do NOT store card data)
- Documents: Tourism classification certificate, authorizations
- Property data: Descriptions, photos, rates, availability
- IP address (anonymized in analytics reports)
- Browser type and version, operating system
- Device used (desktop, mobile, tablet)
- Pages visited, visit duration, traffic source
- Approximate location based on IP (country, region) - for displaying relevant content
- Data from cookies and similar technologies (see Cookie Policy)
Our virtual assistant GIA uses artificial intelligence to provide you with personalized recommendations. We process:
- Your questions and conversations with the GIA assistant
- Expressed preferences (accommodation type, budget, desired location)
- Search history on the platform (for improving suggestions)
GIAConnect does NOT intentionally collect special category data, such as:
- Racial or ethnic origin
- Political opinions, religious beliefs
- Health data
- Biometric or genetic data
- Sexual orientation
If you voluntarily provide us with such information (e.g., in a message), it will be treated with maximum confidentiality and deleted upon request.
4 Purposes and Legal Bases for Processing
We process your data exclusively based on one of the legal bases provided by Art. 6 GDPR:
| Processing Purpose | Legal Basis | Details |
|---|---|---|
| Account creation and management | Contract performance Art. 6(1)(b) |
Necessary to allow you access to platform features according to the Terms and Conditions. |
| Booking intermediation | Contract performance Art. 6(1)(b) |
Transmission of contact data to the accommodation owner for booking completion. |
| Property owner subscription invoicing | Legal obligation Art. 6(1)(c) |
Issuance of tax invoices according to Romanian Tax Code and EU VAT regulations. |
| Payment processing (Netopia) | Contract performance Art. 6(1)(b) |
Payments are processed by Netopia Payments. We do NOT store card data on our servers. |
| AI Assistance (GIA) | Consent / Legitimate interest Art. 6(1)(a)/(f) |
Generation of personalized recommendations for experience improvement. You can disable anytime. |
| Traffic analysis (Analytics) | Consent Art. 6(1)(a) |
Understanding platform usage for improvement. Requires explicit consent for cookies. |
| Security and fraud prevention | Legitimate interest Art. 6(1)(f) |
Protecting the platform and users against unauthorized access, attacks, and fraud. |
| Direct marketing (Newsletter) | Consent Art. 6(1)(a) |
Sending offers and news. Only with explicit consent. Unsubscribe available in every email. |
| Response to legal requests | Legal obligation Art. 6(1)(c) |
Providing data to authorities (Tax Authority, courts, police) only upon documented official request. |
5 Personal Data Recipients
We share your data only with the following categories of recipients, strictly for the mentioned purposes:
Data shared: Name, email, phone (for booking processing)
Property owners become independent controllers for the data received.
Netopia Payments SRL
PCI-DSS certified. Processes property owner subscription payments.
Card data does NOT transit our servers.
- Google Cloud / Firebase - Hosting and infrastructure
- Google (Gemini AI) - GIA virtual assistant
- Google Analytics - Traffic analysis (with anonymized IP)
- Brevo (Sendinblue) - Transactional email sending
Only upon documented official request:
- ANAF (Tax authority)
- Courts of law
- Police / Prosecutor (in criminal investigations)
- ANSPDCP (Supervisory authority)
6 Data Transfer Outside EU/EEA
GIAConnect is an international platform. In certain situations, data may be transferred to countries outside the European Economic Area:
Transfers to USA
Some providers (Google, potentially others) may process data on US servers. These transfers are protected through:
- EU-US Data Privacy Framework - European Commission adequacy decision of July 10, 2023
- Standard Contractual Clauses (SCC) - Approved by the European Commission
- Supplementary measures - End-to-end encryption, pseudonymization where possible
You can request detailed information about safeguards applied to international transfers by contacting us at the DPO address.
7 Data Retention Period
We keep your data only as long as necessary for the purposes for which it was collected:
| Data Type | Retention Period | Justification |
|---|---|---|
| User account data | Duration of account existence + 30 days | Possibility of reactivation |
| Booking data | 3 years from booking date | Statute of limitations for complaints |
| Invoices and tax data | 10 years | Legal obligation (Tax Code) |
| Security logs | 12 months | Security incident investigation |
| AI conversations (GIA) | 90 days | Service improvement, then anonymization |
| Marketing consent | Until consent withdrawal | Proof of consent |
| Cookie data | Variable (see Cookie Policy) | According to cookie type |
Upon expiration of the retention period, data is permanently deleted or irreversibly anonymized for aggregate statistics.
8 Your Rights (Art. 15-22 GDPR)
GDPR grants you extensive rights over your personal data. You can exercise them free of charge by contacting us:
Right of access: To know what data we have about you.
You can obtain confirmation that we process your data and a copy of it in electronic format.
Right to rectification: To correct incorrect data.
You can request correction of inaccurate data or completion of incomplete data.
Right to erasure (\\\\\\\"Right to be forgotten\\\\\\\"): To ask for data deletion (unless there are opposing legal obligations).
\\\\\\\"Right to be forgotten\\\\\\\" - you can request deletion of your data, except those kept due to legal obligations (invoices).
Right to Restriction
You can request limitation of processing in certain situations (e.g., you contest the accuracy of the data).
Right to portability: To receive data in a standard format.
You can receive your data in a structured format (JSON/CSV) and transmit it to another controller.
Right to Object
You can object to processing based on legitimate interest, including profiling for marketing purposes.
Withdrawal of Consent
When processing is based on consent, you can withdraw it at any time, without affecting the lawfulness of prior processing.
Human Intervention (AI)
You can request that a decision made automatically by AI systems be reviewed by a human operator.
How to exercise your rights?
- Send a request to: dpo@giaconnect.com or contact@giaconnect.com
- Specify the right you wish to exercise and your identification data
- We will respond within 30 calendar days (extendable by 60 days in complex cases)
We may request identity verification to prevent unauthorized access to data.
9 Data Security
We implement appropriate technical and organizational measures to protect data (Art. 32 GDPR):
Encryption
SSL/TLS for all connections. AES-256 encryption for stored sensitive data.
Access Control
Two-factor authentication available. Role-based access control (RBAC).
Backup
Daily encrypted backups. Servers in ISO 27001 certified data centers.
10 Use of Artificial Intelligence
GIA Virtual Assistant
GIA is an artificial intelligence-based assistant (Google Gemini) that helps you find suitable accommodations and tourist information. GIA analyzes your expressed preferences to generate personalized recommendations.
Our AI principles:
- Transparency: When interacting with GIA, you know you are talking to an AI system, not a human.
- No discriminatory profiling: We do not use AI to make automated decisions that significantly affect you without human oversight.
- Human oversight: You can request at any time that a recommendation or decision be reviewed by our team.
- Data minimization: We transmit to AI services only the information necessary to generate the response.
GIAConnect monitors the evolution of the EU Artificial Intelligence Regulation (AI Act) and will implement applicable requirements.
11 Protection of Minors
12 Supervisory Authority and Complaints
Main Authority
Since our registered office is in Romania, the competent supervisory authority is:
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București
+40 318 059 211
www.dataprotection.ro
For users from other EU countries: You have the right to file a complaint with the local authority in your country of residence. The complete list of European authorities is available on the EDPB (European Data Protection Board).
Policy Changes
We reserve the right to update this policy to reflect changes in our practices or legislation. Significant changes will be communicated through:
- Email (for users with accounts)
- Website banner on first visit after change
- Update of the \\\\\\\"Last modified\\\\\\\" date in this document
Do you have questions about your data?
We are here to help. Do not hesitate to contact us for any clarification.
Previous versions of this policy are available upon request.