top of page
Privacy Policy

Last updated: 22 August 2026

 

This Privacy Policy explains how LUMI•STAY processes personal data in connection with enquiries, direct bookings, Guest Cards, guest communication and stays in LUMI•STAY apartments and residences.

1. Data controller

The data controller is:

Successimo Monika Turczyńska
Email: monaturczynska@gmail.com
Telephone / WhatsApp: +48 697 777 444

2. What data we process

Depending on the booking channel and type of stay, we may process:

- name and surname,
- email address,
- telephone / WhatsApp number,
- booking reference,
- arrival and departure dates,
- apartment or residence selected,
- names of staying guests,
- number of guests,
- address or country of residence where needed,
- messages sent through booking platforms, email, telephone or WhatsApp,
- payment and invoicing information where applicable,
- information connected with damage, claims, complaints, safety issues or breach of house rules,
- technical website data, such as cookies or basic analytics data, where enabled.

For Warsaw stays, we do not request PESEL numbers or document scans.

The main guest may be asked to show an identity document for verification. No copy is retained for Warsaw stays.

For Croatian stays, where required by local law, guest details may be transferred to the authorised visitor registration system.

3. Why we process data

We process personal data for the following purposes:

- to answer enquiries,
- to organise and perform a stay,
- to confirm who is authorised to enter and stay in the apartment,
- to send check-in and check-out instructions,
- to communicate with guests before, during and after the stay,
- to protect guests, neighbours and the property,
- to handle complaints, claims, damages or guest misconduct,
- to comply with legal, tax, accounting or visitor registration obligations,
- to maintain website security and basic website functionality.

4. Legal basis

We process personal data on the following legal bases:

- performance of a contract or steps taken before entering into a contract — GDPR Article 6(1)(b),
- legitimate interests of the controller, including guest verification, property protection, neighbour protection, claim handling and safety — GDPR Article 6(1)(f),
- compliance with legal obligations, including tax, accounting or visitor registration duties where applicable — GDPR Article 6(1)(c),
- consent — only where consent is specifically requested, for example for optional marketing or non-essential cookies.

5. Guest Card

The LUMI•STAY Guest Card is used to confirm who is authorised to enter and stay in the apartment.

Final check-in instructions may be sent only after the complete Guest Card and house rules confirmation have been received.

The Guest Card helps us protect guests, neighbours, the apartment and the residential building.

6. How long we keep data

Guest Card data is normally deleted no later than 90 days after departure, unless a longer period is required by law or needed for a specific claim, complaint, damage case, chargeback, platform dispute or safety matter.

Booking, payment, tax and accounting data may be kept for the period required by applicable law.

Correspondence connected with complaints, claims, damage, house rule breaches or platform disputes may be kept for as long as necessary to establish, pursue or defend claims.

7. Who may receive the data

Personal data may be shared with:

- booking platforms used by the guest,
- website and form hosting providers,
- payment providers where applicable,
- accounting, legal or technical service providers,
- building administrators or emergency services where necessary for safety,
- public authorities where required by law,
- the authorised visitor registration system for Croatian stays, where required.

We do not sell guest data.

We do not use Guest Card data for marketing.

8. International transfers

Some technology providers may process data outside the European Economic Area.

Where this happens, we rely on appropriate safeguards required by data protection law, such as standard contractual clauses or other lawful transfer mechanisms.

9. Guest rights

Depending on the situation and applicable law, guests may have the right to:

- access their personal data,
- correct inaccurate data,
- request deletion of data,
- request restriction of processing,
- object to processing based on legitimate interests,
- request data portability,
- withdraw consent where processing is based on consent,
- lodge a complaint with the competent data protection authority.

In Poland, the supervisory authority is the President of the Personal Data Protection Office.

10. Automated decision-making

We do not use Guest Card data for automated decision-making or profiling.

11. Contact

For privacy questions or requests, contact:

monaturczynska@gmail.com

bottom of page