Privacy Policy

UAB “Voltaras”, operating as Dunetton Hotel, is committed to protecting your personal information. We comply with the European Union’s General Data Protection Regulation (GDPR) and all other applicable laws governing the protection of your personal data.

Please read this Privacy Policy carefully to understand how we collect, use, store and protect information about you. If you have any questions or if any part of this notice is unclear, our Data Protection Officer is available to assist you as described in Section 10 of this Policy.

Any reference to “we”, “us” or “our” in this Policy refers to UAB “Voltaras” as set out in Section 2 below.

1. How Should I Read This Policy?

This Policy answers key questions about how we collect, use and protect information about you as a guest, website visitor, or user of any services provided by Dunetton Hotel. It covers:

  • Personal data collected when you make a reservation or check in to the hotel
  • Personal data collected when you use our website (dunettonhotel.lt), including through cookies and analytics tools
  • Your rights under GDPR and how to exercise them

2. Who Is Responsible for Protecting My Information?

The data controller responsible for your personal data is:

UAB “Voltaras”

Trading as: Dunetton Hotel

Legal entity code: 307096643

Hotel address: Jūros st. 23, Klaiпėda, LT-92125

Website: dunettonhotel.lt

Email: hello@dunettonhotel.lt

3. Why Do You Collect Information About Me?

We collect, use and store your personal data for the following purposes:

  • Hotel reservations and guest services: to process your booking, manage your stay, issue invoices and provide any services you request during your visit to Dunetton Hotel.
  • Self check-in: Dunetton Hotel operates a self check-in system. We collect and verify your identification data to grant access to your room and to comply with hotel registration requirements under Lithuanian law.
  • Guest communications: to send you booking confirmations, pre-arrival instructions, access codes for self check-in, and other information directly relevant to your stay.
  • Marketing and promotional messages: with your consent, we may send you special offers, news and promotions from Dunetton Hotel.
  • Legal and accounting obligations: your data is required for us to comply with obligations in the areas of accounting, taxation and legal document retention.
  • Security and safety: we operate CCTV cameras on our premises to protect our property, guests and staff, and to preserve evidence in the event of an incident.
  • Legitimate interests – legal disputes and insurance: if necessary, we may use your personal data to assert our rights before courts or other dispute resolution bodies, and to communicate with insurance companies in the event of damage to our property.
  • Website analytics: we use Google Analytics and Google Tag Manager on our website (dunettonhotel.lt) to understand how visitors interact with our site, improve user experience, and measure the effectiveness of our content. These tools may collect data through cookies and similar tracking technologies.

4. What Information Should I Provide and Why?

In order to make a reservation and for us to perform our service contract with you, you must provide the following information:

  • Identification data: name, surname, date of birth
  • Contact details: phone number, email address
  • Payment information: as required to process your booking payment securely via our payment service provider
  • Stay details: arrival and departure dates, room preferences and number of guests

Providing this information is necessary to enter into a service contract with you, to perform our obligations under that contract, and to comply with our legal obligations under Lithuanian law regarding hotel guest registration.

5. What Is the Legal Basis for Collecting Information About Me?

We collect information about you lawfully on the following grounds:

  • Performance of a contract (Article 6(1)(b) GDPR): processing is necessary to enter into and perform your reservation and accommodation contract with us, including managing your check-in via our self check-in system.
  • Legal obligation (Article 6(1)(c) GDPR): processing is necessary for us to comply with applicable legal obligations, including hotel guest registration, accounting and taxation requirements.
  • Legitimate interests (Article 6(1)(f) GDPR): we have a legitimate interest in ensuring the security of our premises (CCTV), asserting our rights before courts or other bodies, and communicating information to insurance companies in the event of property damage caused by a guest.
  • Consent (Article 6(1)(a) GDPR): where we send marketing communications or use non-essential cookies on our website (e.g. Google Analytics), we rely on your freely given consent. You may withdraw your consent at any time.

6. Cookies and Website Analytics

6.1 What Are Cookies?

Cookies are small text files placed on your device when you visit our website. They help us recognise your device, remember your preferences and understand how you use our site.

6.2 Google Analytics

We use Google Analytics, a web analytics service provided by Google LLC, to collect information about how visitors use dunettonhotel.lt. Google Analytics uses cookies to collect data such as:

  • Pages visited and time spent on each page
  • How you arrived at our website (search engine, direct link, referral, etc.)
  • General geographic location (country / city level)
  • Device type, browser and operating system

This data is aggregated and anonymised and is used solely for the purpose of improving our website. Google Analytics data is transmitted to and stored on Google servers, which may be located outside the European Economic Area. Google acts as a data processor on our behalf under a Data Processing Agreement. For more information on how Google processes data, please see Google’s Privacy Policy.

6.3 Google Tag Manager

We use Google Tag Manager to manage and deploy tracking scripts on our website. Google Tag Manager itself does not collect personal data; it acts as a container that fires other tags (such as the Google Analytics tag) based on rules we define.

6.4 Managing Cookies

When you first visit our website, you will be asked to consent to the use of non-essential cookies. You may withdraw your consent or change your cookie preferences at any time by:

  • Using the cookie settings link in the footer of our website
  • Configuring your browser settings to block or delete cookies
  • Using the Google Analytics opt-out browser add-on available at: tools.google.com/dlpage/gaoptout

Please note that disabling cookies may affect the functionality of certain parts of our website.

7. Do You Collect Sensitive Information About Me?

We do not routinely collect sensitive (“special category”) personal data about you. However, we may process your health data with your explicit consent (Article 9(2)(a) GDPR). For example, if you contact us with health-related information in connection with your stay (e.g. accessibility requirements or a request to adjust your booking), we consider that you have consented to us processing that data solely for the purpose for which it was shared. All such health data is deleted once it is no longer required for that purpose.

8. Do You Share Information About Me with Anyone?

Information about you may be transferred to:

  • Government and local authorities: e.g. the State Tax Inspectorate and other public bodies, in the cases and to the extent required by applicable legislation, including the mandatory registration of hotel guests.
  • Service providers: companies providing IT systems, IT services, booking platform services, payment processing, communication (email and SMS) and data storage services. All such providers are bound by confidentiality and security obligations under applicable data protection law.
  • Google LLC: in connection with the use of Google Analytics and Google Tag Manager on our website, as described in Section 6.
  • Insurance companies: to the extent necessary for the investigation of insured events.
  • Legal services and law firms: to the extent necessary to obtain legal advice or to defend our legitimate interests.
  • Courts and competent authorities: to the extent necessary for the protection of our legitimate interests or as required by law.
  • Debt collection and enforcement: bailiffs and out-of-court debt collection companies, to the extent necessary for the recovery of outstanding amounts or enforcement of decisions.

9. How Long Do You Keep Information About Me?

We store your personal data in accordance with the following retention periods:

  • Reservation and stay data: information relating to the performance of your accommodation contract (reservation details, correspondence, payments, invoices) is kept for 10 years after the end of the contract.
  • Tax and accounting records: VAT invoices and related financial records are kept for 10 years in accordance with legal requirements.
  • Guest registration records: records of guest registration required under Lithuanian law are retained for the period prescribed by applicable legislation.
  • CCTV footage: video surveillance recordings are kept for 7 calendar days, after which they are automatically overwritten, unless retention is required in connection with an incident or legal claim.
  • Court and dispute records: documents submitted to courts or other dispute resolution bodies are kept for 1 year after the final decision.
  • Insurance claim records: information relating to insurance claims is kept for 1 year after the insurance company’s decision.
  • Court orders and enforcement: court orders and bailiff warrants are kept for 10 years after the end of payments.
  • Website analytics data: data collected via Google Analytics is retained in accordance with the retention settings configured in our Google Analytics account (typically 14 months), after which it is automatically deleted.
  • Marketing consent records: records of your consent to receive marketing communications are kept until you withdraw your consent, plus an additional period as required for legal compliance.

10. What Are My Rights?

Under GDPR, you have the following rights in relation to your personal data. Please note that these rights are subject to statutory conditions and exceptions:

  • Right of access: you may request access to the personal data we hold about you.
  • Right to rectification: you may request the correction or completion of inaccurate or incomplete personal data.
  • Right to erasure (“right to be forgotten”): you may request deletion of your data where: (i) processing was based on your consent which you have since withdrawn; (ii) we are processing your data unlawfully; (iii) your data is no longer necessary for the purposes for which it was collected; (iv) you have successfully objected to processing based on our legitimate interests; or (v) we are under a legal obligation to delete the data.
  • Right to restriction of processing: you may request that we restrict processing of your data where you contest its accuracy, object to processing, or require the data to assert legal claims.
  • Right to object: you may object to processing of your data where we rely on legitimate interests as the legal basis.
  • Right to data portability: where processing is based on your consent or on a contract with you, and is carried out by automated means, you may request a copy of your data in a structured, commonly used and machine-readable format.
  • Right to withdraw consent: where processing is based on your consent (e.g. marketing communications, non-essential cookies), you may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
  • Right to lodge a complaint: you have the right to lodge a complaint with the State Data Protection Inspectorate of Lithuania. More information is available at vdai.lrv.lt

11. How Can You Help Me? – Contact Our Data Protection Officer

If you have any questions, comments or complaints about how we collect, use or store your personal data, our Data Protection Officer is here to help.

Data Protection Officer, UAB “Voltaras” / Dunetton Hotel

Email: hello@dunettonhotel.lt

12. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements or the services we offer. The current version will always be available on our website at dunettonhotel.lt. We encourage you to review this Policy periodically.