SL | EN
Last updated: July 20, 2026

GDPR Compliance Notice: This Privacy Policy is designed to comply with Regulation (EU) 2016/679 (the General Data Protection Regulation). We act as a data controller for personal data you provide directly to us, and as a data processor for property and booking data you authorise us to access. Our legal basis for processing is Article 6(1)(b) — contractual necessity and Article 6(1)(f) — legitimate interests, where applicable.

1. Data Controller Identity

For the purposes of the General Data Protection Regulation (GDPR), the data controller is:

S.Germain
Planina pri Cerknem 1
Cerkno, 5282
Slovenia
Company registration number: 7545258000
VAT ID: 18695728
Email: hello@s-germain.si

2. Information We Collect

We collect and process the following categories of personal data:

2.1 Identity and Contact Data (Article 4(1) GDPR)

  • Full name, email address, telephone number, postal address
  • Proof of identity (where required for verification)

2.2 Property and Commercial Data

  • Property address, platform account identifiers, listing URLs
  • Historical booking data, revenue figures, occupancy statistics
  • Guest review data (anonymised where possible)

2.3 Financial Data

  • Bank account details or payment card information (for commission invoicing only)
  • Historical revenue data used to establish contractual baselines

2.4 Technical Data

  • IP address, browser type and version, time zone setting, browser plug-in types and versions
  • Operating system and platform, device identifiers
  • Referral source, page interaction data, visit duration

2.5 Special Categories of Data

We do not process special category data as defined under Article 9 GDPR (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, sex life or sexual orientation data).

We process your personal data only where we have a valid legal basis under Article 6 GDPR:

Purpose Legal Basis GDPR Article
Service delivery (pricing, listing optimisation, audits) Contractual necessity Art. 6(1)(b)
Commission calculation and invoicing Contractual necessity Art. 6(1)(b)
Fraud prevention and legal compliance Legal obligation Art. 6(1)(c)
Service improvement and algorithm training (anonymised) Legitimate interests Art. 6(1)(f)
Marketing communications (with consent) Consent Art. 6(1)(a)

Where we rely on legitimate interests (Art. 6(1)(f)), those interests are: (i) improving our pricing algorithms to deliver better client outcomes; (ii) ensuring network and information security; and (iii) understanding website usage to improve user experience. We conduct a balancing test to ensure your rights and freedoms do not override these interests.

4. How We Use Your Information

We use your personal data strictly for the following purposes:

  • To perform our contract with you: Delivering dynamic pricing, listing optimisation, guest-attractiveness audits, and monthly commission invoicing.
  • To communicate with you: Service updates, monthly performance reports, invoice delivery, and customer support responses.
  • To comply with legal obligations: Tax reporting (VAT, income tax), accounting record-keeping, and responding to lawful requests from public authorities.
  • To improve our services: Aggregated, anonymised data may be used to train and refine our pricing models. Individual property data is pseudonymised before use for this purpose.

We do not use your personal data for automated profiling that produces legal or similarly significant effects (see Section 11 below).

5. Recipients and International Transfers

5.1 Categories of Recipients

We do not sell your personal data. We may share it only with:

  • Sub-processors (Article 28 GDPR): Cloud hosting providers (e.g., AWS EU regions), email delivery services (e.g., SendGrid), payment processors (e.g., Stripe), and accounting software providers. All sub-processors are bound by data processing agreements (DPAs) compliant with Article 28(3) GDPR.
  • Professional advisers: Lawyers, accountants, and insurers, where necessary for legal compliance or risk management.
  • Public authorities: Where required by law, court order, or regulatory request.

A current list of our sub-processors is available upon request to hello@s-germain.si.

5.2 International Transfers

Your personal data is stored and processed within the European Economic Area (EEA) unless otherwise specified. Where we use sub-processors outside the EEA (e.g., US-based cloud services), we ensure adequate protection through:

  • EU Commission adequacy decisions (where applicable);
  • Standard Contractual Clauses (SCCs) approved under Commission Implementing Decision (EU) 2021/914; or
  • Binding Corporate Rules (BCRs), where applicable.

You may request a copy of the SCCs in place by contacting our DPO.

6. Data Retention Periods

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, and reporting requirements.

Data Category Retention Period Legal Basis
Account and contact data Duration of contract + 6 years Tax and contract law
Booking and revenue data Duration of contract + 6 years Tax and accounting obligations
Website analytics data 26 months Legitimate interests
Marketing consent records Until consent withdrawn + 2 years Demonstrable consent

Upon expiry of the retention period, personal data is securely deleted or irreversibly anonymised. Backup copies may persist for up to 90 additional days before automatic purging.

7. Your Rights Under GDPR

Under the GDPR, you have the following rights in relation to your personal data:

  • Right of access (Art. 15): You may request a copy of the personal data we hold about you, together with information about how and why it is processed.
  • Right to rectification (Art. 16): You may request that we correct inaccurate or incomplete personal data without undue delay.
  • Right to erasure ('right to be forgotten') (Art. 17): You may request deletion of your personal data where there is no overriding legal basis for continued processing. This right is not absolute and may be limited by legal retention requirements.
  • Right to restriction of processing (Art. 18): You may request that we restrict processing of your data in specific circumstances, such as where you contest its accuracy.
  • Right to data portability (Art. 20): You may request your personal data in a structured, commonly used, and machine-readable format, and transmit it to another controller.
  • Right to object (Art. 21): You may object to processing based on legitimate interests (including direct marketing) at any time. We will cease processing unless we demonstrate compelling legitimate grounds.
  • Right to withdraw consent (Art. 7(3)): Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
  • Right to lodge a complaint (Art. 77): You have the right to lodge a complaint with a supervisory authority in your country of habitual residence, place of work, or place of the alleged infringement.

To exercise any of these rights, contact our Data Protection Officer at hello@s-germain.si. We will respond within one month of receipt, free of charge, unless the request is manifestly unfounded or excessive.

8. Data Protection Officer (DPO)

We have appointed a Data Protection Officer responsible for overseeing GDPR compliance. You may contact our DPO regarding any data protection matter:

Data Protection Officer
Jože Svetičič
Email: hello@s-germain.si

Response time: Within 72 hours

9. Data Security Measures

We implement appropriate technical and organisational measures (TOMs) to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR:

  • Pseudonymisation and encryption: Personal data is encrypted at rest (AES-256) and in transit (TLS 1.3).
  • Access controls: Role-based access with principle of least privilege. Multi-factor authentication (MFA) enforced for all contractors.
  • Regular testing and assessment: Annual penetration testing, vulnerability scanning, and security audits.
  • Incident response: Documented breach response procedures with 72-hour internal escalation to DPO.
  • Contractor training: Annual GDPR and information security training for all personnel with data access.
  • Physical security: Servers hosted in ISO 27001-certified data centres within the EEA.

10. Cookies and Consent

Our website uses cookies and similar tracking technologies. Under the ePrivacy Directive and national implementing laws, we obtain your prior, informed consent for non-essential cookies.

10.1 Cookie Categories

  • Strictly necessary cookies: Required for the website to function (e.g., session management, security). These do not require consent under Art. 5(3) ePrivacy Directive.
  • Analytics cookies: Help us understand website usage (e.g., Google Analytics, Matomo). Placed only after consent.
  • Marketing cookies: Used to measure marketing campaign effectiveness. Placed only after consent.

10.2 Consent Management

Upon your first visit, a cookie banner will request your consent for non-essential cookies. You may:

  • Accept analytics cookies
  • Reject analytics cookies

You may withdraw or modify your consent at any time by clearing this site's stored data in your browser — the consent banner will appear again on your next visit. Consent records are stored for 2 years to demonstrate compliance.

10.3 Third-Party Processors

Analytics data may be processed by Google Analytics (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). We have configured Google Analytics to anonymise IP addresses and disabled data sharing with Google for advertising purposes.

11. Automated Decision-Making

Our dynamic pricing algorithm makes automated decisions about optimal nightly rates for your property. However, these decisions:

  • Operate within floor and ceiling prices that you set;
  • Do not produce legal effects or similarly significant effects on you as a natural person (Article 22 GDPR);
  • Are reviewed by human operators for anomalies;
  • Can be overridden by you at any time by contacting us.

Therefore, Article 22 GDPR does not apply to our pricing algorithm in its current configuration. If this changes, we will notify you and provide the right to obtain human intervention, express your point of view, and contest the decision.

12. Personal Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (Article 33 GDPR);
  • Notify you without undue delay if the breach is likely to result in a high risk to your rights and freedoms (Article 34 GDPR);
  • Document all breaches, including the facts, effects, and remedial action taken (Article 33(5)).

13. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. Material changes will be notified to you via email at least 30 days before taking effect. The "Last updated" date at the top of this page indicates the current version.

Continued use of our services after changes take effect constitutes acceptance of the revised policy. If you do not agree with the changes, you may terminate your account in accordance with our Terms of Service.

14. Contact and Supervisory Authority

For any questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us:

S.Germain
Data Protection Officer: hello@s-germain.si
General enquiries: hello@s-germain.si
Postal: S.Germain d.o.o., Planina pri Cerknem 1, 5282 Cerkno, Slovenia
Phone: +386 41 991 715

You also have the right to lodge a complaint with your local supervisory authority:

Information Commissioner of the Republic of Slovenia
(Informacijski pooblaščenec)
Dunajska cesta 22, 1000 Ljubljana, Slovenia
Email: gp.ip@ip-rs.si · Web: www.ip-rs.si

We are committed to resolving any data protection concerns amicably and efficiently. Please contact our DPO in the first instance before escalating to a supervisory authority.