Skip to content
BELVOYAPLFind a hotel
Back to hotel search

YOUR DATA

Privacy notice

What we use your information for, who helps us provide the service and how you can exercise your rights.

Last updated: 11 October 2026.

1. Who is responsible for your data?

The controller of personal data processed in BELVOYA is K&K Global Solutions sp. z o.o., ul. Józefa Sowińskiego 59/46, 01-105 Warszawa, Polska, NIP 5842854900, KRS 0001117071. For privacy questions and requests, email kontakt@belvoya.pl.

2. What we process and why

Search and hotel information

You can search without creating an account. We process your destination or hotel, dates, occupancy, currency, filters and the nationality used for a rate request. These criteria are sent to Nuitée / LiteAPI to retrieve accommodation information and rates. The current search uses Polish guest nationality. Browser and server requests also contain technical information such as IP address, time and browser details.

Where these data relate to you, we use them to provide the service you request (Article 6(1)(b) GDPR). Limited technical information is also used for security and service reliability, based on our legitimate interest (Article 6(1)(f) GDPR).

Account and saved offers

We process your email address, account identifier, sign-in and account information, and the hotel, stay criteria and target price you save. If you choose Google sign-in, Google provides the information associated with that sign-in, which can include your email, name and profile picture. If Apple sign-in is available and you choose it, Apple provides an account identifier and your email address or a private relay address when you hide your email. Apple web sign-in does not supply your full name; you can enter it in your profile. We use these data to create and maintain your account, authenticate you and make your saved offers available (Article 6(1)(b) GDPR). Providing the information required for an account is voluntary, but necessary to use its features.

Bookings and payments

To complete an online booking, we process the booking holder and primary guest name and email, hotel, dates, occupancy, selected rate and conditions, booking and confirmation references, payment-status linkage and cancellation/refund information. These data are used to take steps at your request and perform the booking service (Article 6(1)(b) GDPR), and where applicable to meet legal obligations or handle claims. The booking data required by the accommodation flow are transmitted to Nuitée / LiteAPI. Payment-card fields are provided directly through the embedded production payment interface used in the supplier flow; BELVOYA does not receive or store the full card number or card security code.

Service messages and correspondence

We use your email to send messages necessary for sign-in and account security. We process the information you include when contacting us to answer your request, provide support or handle a complaint. Depending on the matter, the basis is performing the service (Article 6(1)(b)), complying with a legal obligation (Article 6(1)(c)) or our legitimate interest in responding to correspondence and protecting rights (Article 6(1)(f) GDPR).

An internal notification of a new registration is sent to the operator’s authorised administrator. This supports account administration and service supervision, based on our legitimate interest. It is not a newsletter subscription. We do not currently send automatic price-alert emails or use account registration as consent to advertising.

3. Who receives information?

Authorised personnel and the following service providers receive information to the extent needed for their role:

  • Vercel — website hosting, delivery and technical operation;
  • Supabase — account authentication, database and backend functions;
  • Resend — delivery of transactional emails and internal registration notifications;
  • Google — Google Analytics 4 usage statistics and optional Google sign-in, if you choose it;
  • Apple — optional Apple sign-in and private email relay, if you choose them;
  • Nuitée / LiteAPI — hotel information, rate searches, availability verification, booking creation and servicing, cancellation and the production payment flow, including the payment provider used by Nuitée;
  • Hotel-image providers — when your browser loads an external photograph, its host receives the technical data needed to deliver it, including your IP address.

Providers may use their own approved subprocessors. Information may also be disclosed to professional advisers or competent authorities where necessary and supported by a legal basis. Optional Google and Apple sign-in are also subject to the chosen provider’s privacy information.

Some providers operate internationally, so processing or access may occur outside the European Economic Area. Applicable safeguards depend on the provider and service, and can include an adequacy decision or the European Commission’s standard contractual clauses. You can request information about the safeguards relevant to your data and how to obtain a copy by contacting us. We do not represent that every service processes data exclusively in the EU.

4. How long do we keep data?

We keep account data and saved offers for the duration of the account service. Booking records may need to be retained after a stay, cancellation or account closure to perform the booking, handle complaints and refunds, comply with applicable legal obligations, or establish, exercise or defend specific legal claims. You can remove saved offers yourself and request account closure by email. After a deletion request, we assess which data can be removed and which limited booking or transaction records must lawfully be retained. We do not retain all account information indefinitely on that basis.

Correspondence is retained while the matter is handled and, where justified, for the period needed to meet applicable obligations or resolve related claims. Technical logs are retained according to their security and operational purpose and the provider settings. Deleted information may remain in protected backups until those backups expire under the relevant provider’s configured retention cycle; backups are not used as an active account database.

5. Cookies, browser storage and analytics

We use cookies and similar browser storage for sign-in, session security and preserving actions you request, such as returning to your search after sign-in. Session-storage entries for a search or a pending saved offer normally remain until that browser tab is closed. When you move from a reviewed offer into checkout, booking-holder and primary-guest details can be kept temporarily in the same tab so the checkout can be prefilled; that handoff is removed when the checkout reads it and is not placed in the page URL. Authentication tokens have limited lifetimes and may be refreshed during use.

We use Google Analytics 4 to understand which parts of BELVOYA are visited, whether hotel searches return results and which offers visitors view or select. Analytics starts automatically when the website opens. It uses a pseudonymous browser identifier and technical information such as device, browser, approximate location and activity time. This statistical measurement is separate from optional Google sign-in. We do not send your name, email, account identifier, payment details, authentication tokens or the text you type into search fields as analytics event parameters.

Our analytics events use a limited set of parameters, such as the currency, party size, stay length, result count, a recognised destination category and the supplier hotel identifier. Page URLs are sent without search parameters or fragments. Advertising storage, advertising personalisation and Google Signals are disabled. We do not record a visitor consent click or treat account registration as one. Details about analytics cookies and browser controls are available in our cookies information.

6. Your choices and rights

Depending on the legal basis and circumstances, you may request access to your data, a copy, correction, deletion, restriction of processing or data portability. You may object to processing based on legitimate interests. If we use consent as a basis in the future, you will be able to withdraw it without affecting the lawfulness of earlier processing.

Send requests to kontakt@belvoya.pl. We may ask for information necessary to verify your identity, without requesting more than needed. We respond without undue delay and normally within one month. If a lawful extension is needed because of complexity or the number of requests, we will explain it within that first month.

You may lodge a complaint with the President of the Polish Personal Data Protection Office (UODO), or another competent supervisory authority. uodo.gov.pl.

7. Automated decisions, bookings and changes

We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you. Filtering and sorting hotel results help you browse offers. Verified account holders can complete supported hotel bookings online. BELVOYA processes the booking holder, primary guest, stay, booking status and supplier references needed to create and service the reservation. Full payment-card numbers and card security codes are entered in the embedded payment interface and are not accepted or stored by BELVOYA servers.

When the service or its data processing changes, we update this notice and its date. If a change materially affects how we use your personal data, we will provide appropriate information before the new processing begins. New purposes requiring consent will not be authorised merely by changing this page.

Terms of service · Contact