Privacy Policy

Last updated: April 2026

1. Introduction

As part of its furnished tourist accommodation business, ROSA (hereinafter "we") attaches great importance to the protection of your personal data. This policy details how we collect, use, and protect your data, in compliance with the General Data Protection Regulation (GDPR).

2. Data Collected

We only collect data that is strictly necessary for managing your reservations and your stay:

  • Identity Data: Last name, first name, nationality (for the mandatory individual police form for foreign clients), contact details (phone, email address).
  • Reservation Data: Dates of stay, room type, specific requests.
  • Payment Data: Securely managed by our payment providers (Smoobu and its operators). We do not store any banking data on our own servers.

3. Purpose of Processing

We currently do not conduct any commercial prospecting campaigns (email marketing). Your data is exclusively processed to:

  • Process and confirm your reservations.
  • Communicate with you regarding your arrival and departure (e.g., via WhatsApp or email).
  • Issue your invoices and comply with our legal and accounting obligations.
  • Fill out the mandatory police form for foreign nationals.

4. Retention Period

Your data is kept for the time necessary for the purpose for which it was collected:

  • Data related to reservations and invoices: 10 years (legal accounting obligation).
  • Individual police form: 6 months (legal obligation).

5. Data Sharing

Your data is neither sold nor transferred to third parties. It may be securely transmitted to:

  • Our booking engine and channel manager Smoobu.
  • Competent authorities (only in the event of a justified legal request).

6. Your Rights

In accordance with the GDPR, you have the right to access, rectify, delete, and port your data. You may also object to its processing in certain cases.

To exercise these rights, please contact us at the following address: gb@abfgroupe.com.