Central Square Apartments

UA · EN

Privacy Notice

Last updated: 30 July 2026 · Version 1.0

In short. Central Square Apartments (Chernivtsi, Ukraine) is the controller of your personal data. We use it to provide your stay, to meet our legal duties (guest records, tourist tax, accounting) and to keep the service secure. Your data is hosted in the EU (Frankfurt). ID/passport photos are deleted within 30 days. You can access, correct or erase your data, and complain to a data-protection authority — details below.

1. Who we are (controller)

Controller: Central Square Apartments, Chernivtsi, Ukraine.
Contact: +380502648312.

We are established in Ukraine and offer accommodation to guests located in the EU, so the GDPR applies (Art. 3(2)). For GDPR matters you can contact us directly at the number above; an EU representative under Art. 27 is being designated and will be named here once appointed. We do not have (and are not required to have) a Data Protection Officer at our scale.

2. What data we collect

We collect only what we need (data minimisation). We do not collect special-category data (health, religion, biometrics) from guests.

3. Where we get your data

Directly from you (when you book, check in, upload an ID or message us) and from Booking.com when you reserve through it (your name, dates and reservation details).

4. Why we use it and our legal basis

Purpose Legal basis
Managing your booking, check-in/out and communication about the stay Performance of a contract
GDPR 6(1)(b) · Law 2297-VI Art. 11
Guest registration, tourist tax and accounting/tax records Legal obligation
GDPR 6(1)(c) · Law 2297-VI Art. 11
Keeping the service and property secure, preventing fraud/damage, and improving the service — including AI-assisted drafting of replies (a human always sends them) Legitimate interest
GDPR 6(1)(f)
Optional messages (e.g. offers), if you opt in Consent
GDPR 6(1)(a)

5. Who we share it with

Only providers and authorities needed to run the stay:

6. International data transfers

Your data is stored on servers in the EU (Frankfurt). As we are based in Ukraine, we also process it there; transfers between the EU and Ukraine, and to any provider outside the EU, are protected by appropriate safeguards — the European Commission’s Standard Contractual Clauses and, for Booking.com (an EU company), transfer within the EU. You can request a copy of these safeguards.

7. How long we keep it

You can ask us to erase your data sooner where no legal duty requires us to keep it (see your rights).

8. Your rights

You have the right to:

To exercise any right, contact us at +380502648312. We respond within one month (30 days). Withdrawing consent does not affect processing done before the withdrawal.

9. Automated decisions

We do not make automated decisions with legal or similarly significant effects. Our AI assistant only proposes draft text for a person to review and send — it never decides anything about you.

10. Is providing data required?

Booking details and ID/registration data are needed to perform the accommodation contract and to meet our legal duties. Without them we cannot provide the stay. Optional items (e.g. marketing) are always your free choice.

11. How we protect your data

Data is encrypted at rest and in transit, stored in a private EU cloud, and access is limited by role (housekeeping staff cannot see your ID, messages or payment data). ID and receipt images are served only through short-lived, single-use links and auto-deleted.

12. Complaints

If you have concerns, please contact us first. You also have the right to lodge a complaint:

13. Changes to this notice

We may update this notice. The version and date at the top show the current one; significant changes will be communicated where appropriate.

This notice is written in plain language for guests and is not a substitute for the full text of the GDPR or Ukrainian law.