Continuum logo
--°C
← Guidebooks

Policy of Confidentiality

Privacy & Cookie Policy

At CONTINUUM, we are committed to protecting your personal information, respecting your privacy and explaining clearly how we collect, use and share data. This Privacy & Cookie Policy applies to our website continuum4.me, the “SPACE” digital concierge, all booking communications, guest support channels and any related services or integrations that we operate (collectively, the “Services”). By accessing or using our Services, you acknowledge that you have read this Policy and agree to its terms.

1. Controller and Contact Information

CONTINUUM (property management) acts as the data controller for personal data processed via our Services. For privacy requests or questions, you can reach us by email at info@continuum4.me or via WhatsApp at +382 68 472 109. When you book through external platforms (e.g. Beds24, Booking.com or Airbnb), those platforms may act as independent controllers for the data they collect; please refer to their privacy policies for more details.

2. Data We Collect

  • Identity and contact details: name, surname, preferred salutation, email address, phone or WhatsApp number, postal address and messaging usernames. If you book on behalf of a company, we may also collect business name and tax identifiers.
  • Reservation information: the type of accommodation or service requested, check‑in and check‑out dates, number of guests and bedrooms, dietary or accessibility requirements, pet information, “kitchen needed” selection and any other preferences you provide via our forms.
  • Official registration documents: passport or ID images, document numbers and expiration dates where required by law. These are processed strictly to comply with tourism regulations and deleted after we confirm registration with the authorities.
  • Payment and billing data: transaction identifiers, payment amounts, billing address and limited card details (we do not store full card numbers). Payments are handled by secure third‑party providers such as Revolut, Stripe or PayPal; their privacy policies apply to the payment credentials you provide.
  • Technical and device data: IP address, device identifiers, browser type and version, operating system, general location (country or region), referring URLs, page response times and download errors. We collect this data to maintain the security and performance of our Services.
  • Usage and analytics data: anonymised or pseudonymised statistics about page views, navigation patterns and interactions with our site. We use privacy‑friendly analytics tools and do not employ third‑party advertising trackers.
  • Communication records: messages and attachments you send to us via email, contact forms, WhatsApp, Telegram or other messaging services, as well as support transcripts and feedback.
  • Marketing preferences and consents: your choices about receiving promotional emails or messages, cookie preferences and consent logs capturing when you accepted or rejected cookies. These logs help us demonstrate compliance with privacy laws.
  • Social media and referral data: if you interact with our social media pages or arrive via a referral link, we may receive certain profile information and referral identifiers in accordance with your settings on that platform.
  • Third‑party platform data: we receive booking details, guest names, contact information and stay information from channel managers or online travel agencies such as Beds24, Booking.com and Airbnb. These services may collect additional data under their own privacy policies.
  • Signup and contact forms: if you subscribe to our newsletter, request a quote, contact us for assistance or fill in any other form on our website, we collect the information you provide (e.g. name, email, message content) to fulfil your request.
  • Optional integrations: if you choose to link social accounts or use single sign‑on features (when available), we may receive limited profile data from those providers (e.g. public username, profile photo) according to your settings.

3. Purposes and Legal Bases

  • Service delivery: we use personal data to process reservation requests, facilitate check‑in and check‑out, provide accommodations, communicate with you about your booking, manage payments and respond to your enquiries. Legal basis: performance of a contract and/or steps taken at your request before entering into a contract; legal obligation.
  • Compliance with law: we process data to meet legal obligations such as guest registration with authorities, accounting and taxation, anti‑money laundering measures and anti‑fraud requirements. Legal basis: legal obligation.
  • Personalisation and user experience: we use cookies and other data to remember your preferences (e.g. language or number of guests), personalise content in our digital concierge, and provide a seamless user experience. Legal basis: legitimate interests and, where required, your consent.
  • Communication and support: we contact you to confirm your reservation, send pre‑arrival information, provide service updates, respond to support requests and share important notices. Legal basis: performance of a contract and legitimate interests.
  • Marketing: if you opt in, we send newsletters, special offers or event invitations via email or messaging applications. You can opt out at any time. Legal basis: consent.
  • Analytics and improvement: we analyse aggregated usage data to improve our Services, understand performance, develop new features and enhance security. Legal basis: legitimate interests.
  • Security and fraud prevention: we monitor technical logs to detect suspicious activity, protect our systems against unauthorised access and enforce our Terms. Legal basis: legitimate interests and legal obligation.
  • Legal defence: we may use personal data to establish, exercise or defend legal claims. Legal basis: legitimate interests.
  • Consent records: we keep a record of your consents (e.g. cookie acceptance, marketing opt‑in) and preferences to comply with data protection laws. Legal basis: legal obligation.

4. Cookies & Similar Technologies

Our website uses cookies, pixels and local storage to provide core functionality, remember your preferences and measure how the site is used. When you first visit, you will see a cookie banner generated by iubenda’s Privacy Controls & Cookie Solution. The banner presents equally prominent “Accept” and “Reject” buttons for non‑essential cookies, as required by EU and Brazilian law. You can reopen the banner or edit your preferences at any time via the “Cookie Settings” link or privacy widget in the footer. A dedicated "Do Not Sell or Share My Personal Information" link is provided for users subject to California law.

  • Strictly necessary cookies: enable core features such as security tokens (session ID, CSRF), language settings and form submission. These cookies cannot be disabled via the banner because our site will not function properly without them.
  • Functional cookies: remember options you choose (e.g. number of guests, dates of stay, UI preferences) and enhance the user experience. These cookies are optional and used only with your consent.
  • Analytics cookies: collect aggregated, pseudonymised information on page views, navigation patterns and response times to help us improve our Services. We use privacy‑friendly first‑party analytics and do not employ third‑party advertising cookies.
  • Optional third‑party cookies: when we embed content or integrate with external services—such as Google Maps for property location, YouTube videos or social media widgets—these providers may set cookies or similar technologies. We list these third‑party cookies in our detailed Cookie Policy and link to the providers’ privacy notices.

The iubenda Cookie Solution stores your cookie preferences in a Consent Database so that we can demonstrate compliance if requested by regulators. Our configuration includes a privacy widget that allows you to change your preferences at any time and re‑open the banner. Advanced settings (e.g. remote configuration) enable us to update the banner’s text, design or compliance settings centrally without re‑embedding code on the site. We recommend enabling the privacy widget if you choose to create your own cookie banner.

5. Cookie & Tracking Policy

For full transparency, we provide a separate Cookie & Tracking Policy that lists all cookies and similar technologies used on our website, including name, purpose, provider, duration and whether the cookie is first‑party or third‑party. The policy includes descriptions of third‑party services that install cookies and links to their privacy notices. You can access this policy from the footer or via the cookie banner. If you are using screen readers or accessibility tools, our cookie banner and policies are designed to be accessible; please let us know if you encounter issues.

6. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described above or as required by law. Specific retention periods include:

  • Bookings and guest files: personal and booking data are retained for up to ten years after your stay to comply with legal obligations (e.g. tax, accounting) and to handle potential disputes.
  • Unsuccessful enquiries: data provided for enquiries that do not lead to a booking is retained for up to twelve months and then deleted or anonymised.
  • Registration documents: passport or ID images are deleted immediately after we confirm registration with the authorities and send a confirmation to the guest.
  • Payment records: retained as required by accounting and tax laws (typically five to ten years). We do not store full card numbers.
  • Support communications and feedback: stored for up to three years unless needed to defend legal claims.
  • Technical logs and security data: server access and error logs are kept for a limited period (typically thirty to one hundred eighty days) for security and troubleshooting. Backups of our servers are encrypted and retained on a rolling basis (seven to thirty days) before being automatically purged. Backup archives are not used for any other purpose.
  • Consent logs: kept for as long as necessary to demonstrate compliance with privacy and cookie regulations.

7. Hosting & Security

Our data is hosted on managed servers provided by Hetzner Online GmbH in Germany and Finland. We have a Data Processing Agreement (DPA) with Hetzner and rely on their ISO/IEC 27001 certified infrastructure. Our security measures include:

  • Encryption of data in transit via HTTPS/TLS; optional encryption at rest for sensitive files.
  • Strict access controls and the principle of least privilege for administrators.
  • Network firewalls, intrusion detection systems and continuous monitoring of access and error logs.
  • Regular software updates, patch management and system hardening to mitigate vulnerabilities.
  • Disaster recovery plans, including off‑site encrypted backups within the EU, rotated according to our retention schedule.

If we migrate data to other hosting providers or cloud services (e.g. encrypted storage on Google Drive), we will maintain equivalent security standards and update this Policy accordingly.

8. Sharing & Processors

We do not sell personal data. We may share your information with trusted third parties to provide and improve our Services. These recipients act either as processors under our instructions or as separate controllers for the data they collect. We require processors to implement appropriate safeguards and use your data only for the contracted purposes. Categories of recipients include:

  • Property management systems and channel managers: Beds24 and other OTA integrations (e.g. Booking.com, Airbnb) used to synchronise availability, rates and reservations. These platforms may collect additional data under their own policies.
  • Payment processors: Revolut, Stripe, PayPal and similar providers process payments on our behalf. We share only the information required to process your payment and issue refunds; they may collect additional data under their policies.
  • Booking engines and widgets: calendars, forms or scheduling tools embedded on our site (including B24 widgets) to facilitate bookings. If these widgets are operated by third parties, they collect data directly via their interfaces.
  • Communication and CRM services: email delivery providers, messaging APIs (WhatsApp Business API), customer support platforms and CRM systems used to send confirmations, reminders, support responses and marketing communications.
  • Analytics and performance providers: privacy‑friendly analytics services (self‑hosted or third‑party) and logging platforms used to monitor site performance. These tools receive pseudonymised technical data; we do not share personal identifiers with ad networks.
  • Mapping, media and weather services: Google Maps is embedded to show property locations; open‑meteo provides real‑time weather data; embedded media players such as YouTube display videos or virtual tours. These services may collect technical data like your IP address and set their own cookies.
  • Cloud backup and storage: encrypted backups may be stored using services like Google Drive or other EU‑compliant providers for disaster recovery.
  • Professional advisers and regulators: auditors, accountants, legal consultants or public authorities where disclosure is required by law or necessary to protect our rights.

Should we engage new processors or significantly change our data‑sharing practices, we will update this Policy and, where required, ask for your consent.

9. International Transfers

Some of our service providers are located outside the European Economic Area (EEA). When personal data is transferred internationally, we ensure that adequate safeguards are in place—for example, by using Standard Contractual Clauses (SCCs) approved by the European Commission, relying on adequacy decisions, or implementing other legally recognised mechanisms. You can request a copy of these safeguards by contacting us.

10. Consent Records & Preferences

Our website uses iubenda’s Consent Management Platform (CMP) to collect, record and manage user consents for cookies and other data processing activities. The CMP logs the date, time and choices you make on our cookie banner and stores them securely in a Consent Database. This allows us to provide regulators with proof of consent if required. You can review or update your preferences at any time via the privacy widget or by contacting us.

If your browser or device supports the Global Privacy Control (GPC) signal, we recognise this signal to help you manage consent preferences automatically. However, due to regional differences, additional steps may still be required (e.g. clicking “Do Not Sell or Share My Personal Information” for California).

11. Additional Clauses

Depending on how you interact with our Services, additional clauses may apply:

  • Newsletter subscriptions: when you subscribe, we collect your email address and send you marketing content. You can unsubscribe at any time using the link provided in every email.
  • Internal analytics: we may use aggregated, pseudonymised data to study trends and improve our operations. This analysis does not involve profiling or targeted advertising.
  • Terms & Conditions: please refer to our separate Terms & Conditions for contractual terms governing use of our Services. A link to this document is available in the footer.
  • Multilingual support: the website may be available in multiple languages. We strive to provide our legal documents in all supported languages and ensure that each translation conveys the same meaning. In case of discrepancies, the English version will prevail.
  • US‑specific clauses: residents of the United States, particularly California and other states with privacy laws, have additional rights. These include the right to know what personal information we collect, request deletion, opt out of sales or sharing of personal information, and not be discriminated against for exercising your rights. We provide a “Your Privacy Choices” link (also referred to as “Do Not Sell or Share My Personal Information”) in the footer to help you exercise these rights.

12. Your Rights

  • Access: request confirmation of whether we process your personal data and receive a copy of that data.
  • Rectification: request correction of inaccurate or incomplete data.
  • Erasure: request deletion of personal data when it is no longer necessary or when processing is unlawful.
  • Restriction: ask us to limit the processing of your data in certain circumstances (for example, while we verify accuracy).
  • Portability: receive your data in a structured, commonly used and machine‑readable format and have it transferred to another controller where technically feasible.
  • Objection: object to processing based on our legitimate interests, including profiling. We will cease processing unless we demonstrate compelling legitimate grounds.
  • Withdraw consent: withdraw your consent for marketing communications or non‑essential cookies at any time. Prior processing based on your consent remains lawful.
  • Complaint: lodge a complaint with your local data protection authority if you believe we have violated applicable privacy laws.
  • Automated decision‑making: we do not use automated decision‑making that produces legal or similarly significant effects. If we implement such mechanisms in the future, we will notify you and provide appropriate safeguards.
  • US/California rights: California residents may request information about personal data we collect and disclose, opt out of any sale or sharing, request deletion and not be discriminated against for exercising these rights. The “Your Privacy Choices” link or contact channels provide a direct way to exercise these rights.

To exercise any of these rights, please email us at info@continuum4.me or send a message via WhatsApp. We may ask you to verify your identity to protect your privacy. We generally respond within one month of receiving your request (this period may be extended by two months for complex requests). If you are unsatisfied with our response, you may contact your data protection authority.

13. Children’s Privacy

Our Services are not designed for or directed to children under the age of 16, and we do not knowingly collect personal data from minors. If you believe that a child has provided us with personal data without parental consent, please contact us so that we can remove the information.

14. Security

We implement technical, organisational and physical measures to protect your personal data. These include encryption in transit, robust access controls, security training for employees, regular audits and an incident response process. While we strive to secure our systems, no method of transmission or storage is completely secure. If you suspect a security issue, please notify us immediately.

15. Contact Us

If you have any questions about this Policy or our data practices, or if you wish to exercise any of your rights, please contact us at info@continuum4.me or via WhatsApp at +382 68 472 109. We are happy to assist and will do our best to address your concerns.

16. Updates to This Policy

We may update this Privacy & Cookie Policy to reflect changes in our Services, legal requirements or industry best practices. When we make significant changes, we will post the updated Policy with a new effective date and, where appropriate, provide a notice (such as an on‑site banner or email). Please review this Policy periodically to stay informed about how we protect your personal data.

Last updated: 24 September 2025.

Policy of Confidentiality | CONTINUUM Guidebook