Privacy policy
This document explains what personal data the booking system holds about you, why, and what you can do about it. It covers this system only; the hotels' own websites are separate.
Who controls your data
What we collect, and why
To make and perform your booking (performance of a contract):
- your name, email address and telephone number (optional);
- the stay: hotel, room type, rate plan, arrival and departure dates, number of nights and guests;
- the price: total, currency, any discount applied, and the per-night breakdown;
- the booking reference, its status and its payment status.
For payment:
- the amount, currency, payment status and Paysera's payment reference. We do not receive or store card details.
If you create an account (optional):
- your email address, name, telephone number, language, and a cryptographic hash of your password (we do not store the password itself);
- sign-in sessions: only a hash of the session token, its expiry and your browser's user-agent string;
- your loyalty ledger: every accrual and redemption, linked to the stay that caused it.
For correspondence and customer service:
- your email correspondence with the hotel — messages received and sent are stored and linked to your contact record;
- a contact record: name, email, telephone, company, language, where the record came from, and notes;
- an append-only timeline: notes, status changes, emails in and out, bookings, and consent events.
Your past stay history from the hotels' property-management system is copied into this system each night, so that the hotel can see a guest's whole history in one place.
Marketing and consent
We send marketing email only with your consent. Consent is stored in three states: granted, declined, or unknown. Nothing is sent unless it is granted — unknown is not consent.
Email about your booking — the confirmation, practical information before arrival — is sent to perform the contract and does not depend on consent.
Every marketing email carries a one-click unsubscribe (RFC 8058) that also works directly from your mail client. Once you unsubscribe, the address goes on a suppression list and is dropped from every send, even if someone adds it to a list by hand.
You can withdraw consent at any time. Withdrawal applies from the moment you give it and does not affect processing carried out before then.
Automated processing
A reply to your email may be drafted by an automated assistant, but it sends nothing: a member of staff reads and sends every reply. No decision about your booking is taken automatically.
Who your data reaches
We do not sell your data. To perform your booking it reaches:
- Paysera, the payment provider, which receives the amount, the currency and the booking reference;
- the hotel's property-management system (Ericsoft), where the hotel runs the stay;
- the hotel's own staff, who answer your emails and check you in.
We do not sell personal data and do not pass it to anyone for their own marketing. Only the service providers listed below help us process it, acting on our instructions and under contracts with us.
The database. The database is provided by Neon (Neon Inc.) and runs on Amazon Web Services infrastructure in Germany, in the Frankfurt region. Everything described in this document is held there.
Server hosting. The application runs on a server provided by Hetzner Online GmbH (Germany). The most recent database backups are kept on the same server.
Email. The hotels' mailboxes are hosted by their email providers in Lithuania: the Bohema and Prie Parko mailboxes are on meganora.hostingas.lt, the Navalis mailbox on agurkas.serveriai.lt. All mail in and out passes through them, so they hold the whole of your correspondence with us.
The hotel management system. The hotels run stays in Ericsoft, hosted by Lantika (server tubinas.lantika.eu, Lithuania). Data is copied from it into this system each night so that the hotel can see a guest's whole history in one place; this system writes nothing back to it.
Payments. When a payment is made, Paysera receives only the amount, the currency, the booking reference and the payment description, which names the booking reference and the hotel. We do not pass it your name, email address or telephone number. Card details are entered on Paysera's own page and never reach our system.
Public authorities. We disclose data only where the law or a lawful order of an authority requires it.
Where the processing happens. Every processor listed above processes data within the European Economic Area. We make no transfer outside it.
What is not here. There is no analytics, advertising, tag manager, profiling or social-network script anywhere in this system, so browsing here leaves no trace with any of them. Fonts and photographs are served from the same server, not from outside networks.
Built but switched off. The system contains a prepared but inactive transactional email service, Brevo (France), and an automated reply-drafting tool, Anthropic (United States). No personal data has ever been sent to either. Before enabling either of them we will update this document, and for Anthropic we will also state the legal basis for the transfer outside the European Economic Area.
How long we keep it
We keep data for as long as it is needed for the purpose it was collected for, and for as long as the law requires. The periods differ by category, so what follows is the criteria we use to determine them.
Booking and payment records. Kept for the stay and for as long as the obligations arising from it are being performed; then for as long as is needed to deal with complaints and to bring or defend legal claims, and for as long as tax and accounting duties require. Some of these records are accounting documents that Lithuanian law obliges us to keep for a set period, so we cannot delete them earlier, even on request.
Correspondence with the hotel. Messages received and sent are kept for as long as is needed for customer service, to finish matters already raised, to deal with complaints, and to bring or defend claims.
Your contact record and its timeline. Kept while the relationship with you is maintained, and for as long as is needed to show what consent you gave or withdrew, and when.
A guest portal account. Kept for as long as the account exists. A sign-in session is valid for 30 days from sign-in and stops working once that period ends; single-use links — sign-in, password reset, email verification — are valid from 15 minutes to one day.
Loyalty records. Every accrual, redemption and reversal is written as its own dated entry and is not edited afterwards. They are kept while the account exists and for as long as is needed to substantiate the balance.
The suppression list. If you unsubscribe from marketing email, your address is written to a suppression list and kept there indefinitely. That is the only way to guarantee that nothing is sent to you again: deleting the entry would delete the fact that you opted out. The list is used to stop sending and for nothing else.
The copy of the hotel management system. Stay data copied over each night is kept for as long as it is kept in the hotel's own system. Records marked there as anonymised are treated as anonymised here too: we do not mail them and do not include them in marketing or contact lists.
Backups. The database is backed up each night; only the most recent copies are kept and older ones are removed. Deleted data therefore remains in backups for a period; those are used only to restore the system after a failure.
Once data is no longer needed for any of the purposes above and the law no longer requires it to be kept, it is deleted or anonymised. Anonymised data can no longer identify you and is used only for statistics.
If you want your data erased, write to info@smilciu.lt. We act on the request as far as the legal duties described above allow, and our reply says what was erased and what has to be kept, and why.
Your rights
In relation to your data you have the right to:
- obtain access to them and a copy;
- have inaccurate data corrected;
- have data erased;
- restrict how the data is processed;
- receive the data in a structured format and have it ported elsewhere;
- object to processing;
- withdraw any consent you have given, at any time.
Write to the email address given above. You also have the right to complain to a supervisory authority: