Privacy Policy – Porta Solis
Last updated: 19 September 2026
1. Controller and contact
Porta Solis is operated by:
Aleksandra Drežančić
Joachimsthaler Str. 4
91126 Schwabach
Germany
Email: info@portasolis.com
You can also contact this address with questions about data protection and to exercise your rights.
This information describes processing on portasolis.com, including the German, Croatian and English sections of the website, landlord accounts and the guest and stay functions provided.
2. Porta Solis, landlords and travellers
Porta Solis processes data for its own platform purposes, in particular registration and user accounts, technical provision, security, communication and its own platform services. Landlords process guest data for their own accommodation services, performance of contracts and the statutory registration obligations applicable to them. Porta Solis provides technical functions for this, such as the digital guest guide, pre-check-in and manual eVisitor preparation.
The landlord who receives your stay data is determined by the accommodation selected, your enquiry or the guest access provided to you. Where Porta Solis provides technical functions for processing guest data for a landlord, the allocation of data protection roles depends on the specific process and the agreements made for it. This must be distinguished from the platform purposes pursued by Porta Solis itself. Providing shared technical functions does not in itself establish joint controllership. This Privacy Policy supplements the information provided by the respective landlord about their own processing purposes, obligations and further recipients.
We receive information directly from you and, depending on the process, from the responsible landlord or the person organising a stay for several travellers. This may include, in particular, names, contact details, stay details, details of accompanying travellers and document information. Anyone submitting information about other people should inform those people about the processing and provide only necessary information.
3. Purposes, legal bases and required information
We process data to set up and use your account, handle specific service enquiries and provide agreed Porta Solis services on the basis of Article 6(1)(b) of the General Data Protection Regulation (DSGVO/GDPR), where you are a party to the contract or request corresponding pre-contractual measures.
Article 6(1)(f) GDPR applies to secure technical operation, prevention of misuse, handling general contact enquiries, audience measurement that minimises data processing and the necessary traceability of processes. Our respective interests are explained in the following sections. Processing required by law is governed by Article 6(1)(c) GDPR and the obligation applicable to the specific process. Consent under Article 6(1)(a) GDPR is a legal basis only where we actually obtain it for a specific voluntary purpose.
For the landlord’s own accommodation and registration purposes, the legal basis depends on their specific relationship with the traveller and the obligations applicable to them. A mandatory form field does not in itself establish a statutory registration obligation. By providing the technical functions, Porta Solis does not make a blanket legal classification of all information as required by law.
We need information marked as required for the process described in each case. Without it, for example, an account cannot be created, an enquiry cannot be assigned or a complete pre-check-in cannot be submitted. You do not have to provide voluntary information. Please do not enter health data or other particularly confidential information in message fields unless it is necessary for your enquiry.
4. Hosting, technical access data and security
The website, database and configured email transport are operated at ALL-INKL.COM – Neue Medien Münnich, proprietor René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. According to the provider, it uses data centres in Germany. Hosting also involves technical processing of the content and data provided for the website. Further provider information: ALL-INKL data protection.
Accessing the website generates technical connection data, in particular IP address, time, requested address, browser and operating system information and, where applicable, the referring page. Server and error logs support delivery, troubleshooting, stability and detection of misuse. This serves our interest in a secure and functional service under Article 6(1)(f) GDPR.
Retention of these operational logs depends on their specific security and diagnostic purpose and the hosting and logging functions used. In the event of a security incident, necessary extracts may be required until the incident has been clarified and, where applicable, for legal proceedings. The specific 30-day rule for pre-check-in audit data is not a general server log retention period.
The website uses HTTPS. Sensitive operational data records are additionally stored in encrypted form to the extent described in the following sections. This is not end-to-end encryption that excludes the operator: authorised functions and responsible administrators can process the data required for their tasks. Public accommodation images, ordinary contact forms and general technical metadata are not all covered by this additional field encryption.
5. Contact and contact forms
When you contact us, we process your contact details, the content of the message and, where applicable, information about accommodation, a trip or a requested service. Recipients are the people responsible for your enquiry and, where this is the subject of your enquiry, the responsible landlord or expressly selected provider. Messages may be stored in the website database and the email mailboxes involved.
The legal basis is Article 6(1)(b) GDPR for initiating or processing a contract at your request, and otherwise Article 6(1)(f) GDPR based on our interest in responding to your enquiry.
For the general contact form, automatic deletion of form data is configured for 180 days after documented completion. For the separate Forminator handover forms for accommodation submissions and guest guide orders, the period is 30 days after documented completion; the handover must also be confirmed. This concerns their form entries, not the accommodation or guest guide subsequently maintained. Stored form IP data is subject to a separate 90-day rule. Open cases or cases blocked for a justified reason are not treated as completed solely because of their age.
These rules concern the respective form entries. They do not automatically delete a registration, a service enquiry in the guest guide or an email copy. Their purposes and retention are described separately.
6. Landlord registration, account, login and password reset
During registration and account use, we process in particular the username, email address, password as a verification value that is not directly readable, role, language, profile information and technical account management information. Further contact, address and business data may be added when a host profile is created or edited.
This processing provides the account and the requested platform services under Article 6(1)(b) GDPR. Access protection and prevention of misuse are additionally based on our legitimate security interest under Article 6(1)(f) GDPR.
Registered landlords have access to their own assigned properties and processes. Administrative functions are reserved for separately authorised people. Passwords are not sent in the registration email. To reset a password, a dedicated link is sent to the email address on file.
Account data is needed for the duration of the account and the associated service relationship. After this ends, further retention of individual data depends on whether there are open cases, billing matters, statutory obligations or specific claims. Documents still required for these purposes must be distinguished from ongoing account use; there is no blanket permission for unlimited retention.
7. System and registration emails
We send necessary account messages, in particular registration and password reset emails, as well as process-related notifications concerning enquiries and services used. Registration messages are prepared in German, Croatian or English according to the language context. They may contain, for example, the email address, username, process details and an account or guest link.
Emails are sent via the configured ALL-INKL mail server. The respective recipients’ email providers also process the messages. Depending on the function, responsible landlords also receive a notification. Service emails may contain contact details and enquiry content; contract emails may contain a contract or a PDF. Pre-check-in traveller and document records are not intended to be sent as ordinary email.
Necessary system communication serves the respective service or access security. Registration does not constitute consent to advertising.
Newsletter „Porta Solis Inspiration“
Der freiwillige Newsletter informiert über Unterkünfte, Reiseideen und Angebote. Grundlage ist Ihre Einwilligung. Wir speichern E-Mail-Adresse, Einwilligung, Anmelde- und Bestätigungszeitpunkt sowie die zum Nachweis und Missbrauchsschutz erforderlichen technischen Angaben lokal in WordPress/MailPoet. Der Versand erfolgt über den bestehenden ALL-INKL-Mailserver, ohne externen Newsletterdienst und ohne Öffnungs- oder Klicktracking. Die Anmeldung wird erst nach Bestätigung per E-Mail aktiv. Ein Widerruf ist jederzeit über den Abmeldelink oder info@portasolis.com möglich. Danach endet der Versand; erforderliche Einwilligungs- und Sperrnachweise bleiben von einer Löschung getrennt.
Delivery status and technical sending times may be stored for troubleshooting and to prevent duplicate messages. Mailbox copies have their own lifecycle: handling of the process, any applicable documentation and retention obligations, and outstanding claims determine this. Deleting a form record does not also delete messages already delivered to the recipient.
8. Accommodation, host profiles and uploads
Landlords can submit and edit accommodation details, descriptions, addresses, facilities, prices, availability, contact details and images. We process this information to manage, review and present the offer as agreed. Submission stages and processing status may also be stored for this purpose.
Information intended for publication is visible to visitors on the respective accommodation or profile page. Internal administrative and contractual information is handled separately. Images may contain people or additional image information. Please upload only content you are entitled to use and publish, and avoid unnecessary personal information in images.
Processing takes place to provide the agreed service under Article 6(1)(b) GDPR; necessary checks and security measures are based on Article 6(1)(f) GDPR. Where information about other people is involved, the lawfulness of providing it must be considered separately.
Retention depends on use of the listing, handling changes and open cases, and any documentation and retention obligations. Unpublished drafts, media and earlier editing stages are separate data sets.
9. Accommodation and service enquiries
For enquiries, we process in particular names, email addresses or telephone numbers, the accommodation or service, requested dates, number of people and the message. Further processes may involve price information, processing status, agreed services and manually documented payment information.
The data is used to handle your enquiry and is made available to the responsible landlord or selected service provider. Merely submitting an enquiry does not make it a binding booking or payment. The applicable bases are Article 6(1)(b) GDPR for pre-contractual measures you request or performance of the contract and, for general enquiries, Article 6(1)(f) GDPR.
Accommodation enquiries and more recent service processes use protected data storage, some of which is additionally encrypted. Older service enquiries are held in access-restricted form and process data whose fields are not all encrypted. We therefore do not claim that all messages on the platform are stored in the database with additional encryption.
Retention depends on completion and handling of the specific process as well as necessary evidence, statutory obligations and outstanding claims. A time-limited guest link does not automatically determine the deletion period for the associated process.
10. Digital guest guides and guest access
Digital guest guides contain information about the accommodation and stay, such as a welcome, arrival details, Wi-Fi, house rules, contacts and additional offers. Content and access are assigned to the respective accommodation and responsible landlord. Public information is separate from protected guest information.
Guest access may be provided through a special link without a WordPress account. The link contains a technical access identifier and must be kept confidential. Anyone who receives such a link can access the associated view within the access granted. Expiry, revocation and assignment checks limit access. Personal traveller and document details are not included as form values in the guest URL.
Processing serves to provide and use the requested guest information and services. Article 6(1)(b) GDPR applies to our own contractual services; access protection is based on Article 6(1)(f) GDPR. Use of guest data for the landlord’s own purposes is governed by their legal basis.
Guest guide content and general contact details have their own lifecycle according to their use. The short pre-check-in period described below is not a blanket deletion period for all accommodation information.
11. Stays, guest portal and pre-check-in
Stays are assigned to the accommodation, responsible landlord and, where applicable, a guest guide. This includes in particular arrival, departure, number of guests, lead guest and necessary contact and service details. Information released for this purpose can be viewed and the intended details supplemented in the guest portal.
Pre-check-in enables the submission of information requested about the lead guest and accompanying travellers for the respective stay. Depending on the process, we process:
- first and last name, date and place of birth;
- nationality and, where applicable, gender;
- residential address and country;
- necessary contact details such as email address and telephone number;
- document type, document number, country of issue and, where applicable, issue and expiry dates;
- assignment to the stay, submission status and time.
Accompanying minors may also be included in the stay information. The details must match the number of guests on file.
No scans or photographs of identity documents are requested or stored during pre-check-in.
Traveller and document details are stored in encrypted form and can be accessed only through authorised functions. Technical assignments and status and time information must be distinguished from these. Landlords can access only the stays assigned to them; necessary administrative access remains possible.
Collection serves to prepare and carry out the stay and to help the landlord prepare necessary registration data. Whether and which information is required under a specific accommodation or registration obligation depends on the individual process; pre-check-in alone does not constitute an official registration by Porta Solis.
12. Deletion of pre-check-in data
Sensitive traveller and document data from pre-check-in is generally due for deletion 24 hours after departure. If an open registration or eVisitor correction case is documented before the deadline, the period may be extended to a maximum of seven days after departure. Technical delays in actual deletion are possible. Deletion also covers stored corrections and manual eVisitor preparations.
Technical evidence of completed deletion is retained for up to 30 days from actual deletion or creation of the deletion report. It does not contain the actual traveller or document data, but may be indirectly linked to a stay. It serves the traceability of deletion and system security under Article 6(1)(f) GDPR.
Section 20 applies to backups. The short pre-check-in periods do not apply across the board to contracts, invoices, separate service processes, system logs or email mailboxes.
13. Manual eVisitor preparation
Porta Solis offers internal preparation of registration data: existing pre-check-in data can be transferred and checked and corrected for each traveller by the authorised landlord. The prepared registration data is stored in encrypted form and is included in the pre-check-in deletion described above.
Porta Solis currently does not automatically transmit traveller data to eVisitor. An internal review status does not mean that an official registration has been made.
The subsequent manual entry in eVisitor is a separate step carried out by the landlord. A link to the external portal does not pass traveller data in its address. In connection with the stay, the landlord provides information about their registration obligations, the relevant recipients and processing in the external system. Porta Solis does not replace this information with its internal preparation view.
14. Contracts, PDFs, confirmations and signatures
Where the contract function is used for a process, it processes contracting parties, addresses, accommodation and stay data, contract texts, prices and, where applicable, deposit information. Confirmation or signature adds the evidence provided, timestamp, version and integrity features. Contract views and PDF versions may be generated from this.
The function serves to create, perform and provide evidence of the specific contract. Article 6(1)(b) GDPR may apply to the respective contracting party; required statutory retention is governed by Article 6(1)(c) GDPR. Safeguarding and defending specific claims may be justified under Article 6(1)(f) GDPR. The landlord’s legal basis must be distinguished from Porta Solis’s own contracts.
Contract snapshots, signature evidence and final PDF data are retained in encrypted form in the designated protected storage. They are decrypted with authorisation for display or sending. A temporary readable file may be created for an email attachment and is subsequently removed by the regular sending process. Recipients of the contract email receive their own copy of the attachment.
Completed versions are protected against ordinary overwriting. This integrity protection does not justify unlimited retention. The necessary duration depends on the specific contractual purpose, outstanding claims and statutory documentation obligations that actually apply. We do not claim a blanket statutory period for all contracts. The function is also not described as a qualified electronic signature or biometric identity verification.
15. Service, payment, deposit and damage information
Where service or contractual processes are actually used, price and invoice information, manually recorded payment statuses, deposits and necessary evidence of damage may be processed. The purpose is performance, billing and, where applicable, assessment of claims. The legal basis depends on the specific contractual, evidentiary or statutory purpose as described in section 14.
A displayed payment status does not mean that Porta Solis itself has processed a payment through an external payment service. If external payment or provider links are expressly selected, processing there takes place with the respective provider. Payment services not actively used are not presented as recipients of your data.
16. Cookies, local storage and languages
Technically necessary session and security information is used for a requested login and protected functions. A protected contract session may require its own session cookie. The favourites list may store accommodation identifiers you select locally in your browser; these entries can be deleted through the function or the browser data.
Where storage or access on your device is strictly necessary for an expressly requested function, it takes place under section 25(2), no. 2 TDDDG. Subsequent personal data processing is governed by the respective contractual or security purpose. Any further use requiring consent is subject to separate consent.
The page language is primarily determined by the address: German at the main address, Croatian under /hr/ and English under /en/.
Browsers can block or delete cookies and local data. This may restrict login, the favourites list and protected functions.
17. Audience measurement with Independent Analytics
We use Independent Analytics for local audience measurement in WordPress. We analyse, for example, page views, times, referring pages, browser and device categories and approximate geographical location. Analytics data remains on our hosting and is not transmitted to the provider. No tracking cookies are set.
The IP address and browser identifier (User-Agent) are processed to create a pseudonymous visitor identifier; the IP address is also used for approximate geolocation. It is not stored as a plain value in the analytics database. The additional value (salt) used for the visitor identifier changes daily. Logged-in users are not recorded.
The retention period is 90 days. The legal basis is our legitimate interest in analysing audience reach and technical use while minimising data processing under Article 6(1)(f) GDPR. Further information: Independent Analytics.
18. Partner links, redirects and external communication
The website contains links to landlords, travel and service providers and, where applicable, affiliate links. A booking or use through a labelled partner link may generate a commission. Link parameters may identify the referring channel or offer.
Pretty Links is used for our own short and redirect URLs. It does not create our own click profiles or Pretty Links tracking cookies. Independently of this, the technical access data described in section 4 is generated.
Only opening an ordinary external link takes you to the respective destination page. There, the IP address, browser information, link parameters passed and, depending on the browser, a referring address may be processed. Independent data processing on that destination page is governed by its privacy information. This must be distinguished from external images loaded when the page is accessed; see section 19.
If you use a WhatsApp link provided, the external service is opened; its provider for users in the European region is WhatsApp Ireland Limited, Ireland. Depending on the link, a prepared enquiry text with contact or date information may be passed. Use is voluntary; alternatively, you can use the contact method provided on the website. Please do not submit document numbers or complete traveller records through such links. The following also applies: WhatsApp’s privacy information, including its international processing.
19. Embedded resources
The domain kroatien-ferienhausvermittlung.de is also used for individual images. According to its legal notice, it is also operated by Aleksandra Drežančić. When an image stored there is accessed, the server delivering it receives the technically necessary connection data. The purpose is to display the selected website content; the legal basis is Article 6(1)(f) GDPR.
20. Backups, restoration and test environments
Backups are created regularly to safeguard and restore the website. They are retained only for a limited period and replaced periodically. Separate backup and restoration copies are retained only as long as required for the specific backup, restoration or troubleshooting purpose. The legal basis is our legitimate interest in the availability and integrity of the website under Article 6(1)(f) GDPR.
Data already deleted from the production system may remain in backups until their scheduled expiry. If a backup is restored, data already effectively deleted will not be permanently returned to production use.
Only authorised people have access to backups and necessary system copies. Synthetic data is used for functional tests; technically necessary system copies remain separate from production guest access.
21. Further retention and technical evidence
Outside the specifically stated periods, the duration depends on the respective purpose: duration of the account or service relationship, handling and completion of a process, necessary contractual and billing evidence, outstanding claims and statutory obligations that actually apply. Once the purpose and any reasons requiring retention cease to exist, the data concerned must be deleted or reduced to a non-personal data set.
General security, contract and service logs, as well as data protection enquiries, may contain property or user identifiers, actions, statuses and times. They serve security, clarification of errors and necessary accountability. Even without names, such information may be personal data. It does not automatically fall under the specific 30-day pre-check-in period. The fact that a system protects a record against alteration is not in itself a reason to retain it indefinitely.
Documents required by law are retained only to the extent necessary and for the relevant obligation. On request, we will explain the criteria applicable to your specific process. Deletion in the Porta Solis system does not automatically extend to separate records lawfully retained by the landlord or copies already received by other recipients.
22. Recipients and processing outside the EU/EEA
Depending on the process, data is received by the responsible landlord or service provider, authorised platform staff, the hosting and email provider and the respective email recipients. Authorities, advisers or legal representatives may receive data where a legal basis exists in the individual case. Data is not made available to other landlords solely because they are registered.
Local platform storage must be distinguished from external services and destination pages. External WhatsApp or partner links you use may involve additional processing outside the EU/EEA. The respective providers’ information describes their processing. Porta Solis currently does not automatically transmit data to eVisitor.
You can request information about the recipients and safeguards relevant to a specific transfer we carry out through our data protection contact. The privacy information of external destination pages applies to their independent processing and does not replace our information about resources we embed ourselves.
23. Your rights
Subject to the statutory conditions, you have in particular the following rights:
- access to information about processing and a copy of your personal data, Article 15 GDPR;
- rectification of inaccurate data and completion of incomplete data, Article 16 GDPR;
- erasure, Article 17 GDPR, unless a statutory exception applies;
- restriction of processing, Article 18 GDPR;
- data portability for the automated processing covered by this right on the basis of consent or a contract, Article 20 GDPR;
- withdrawal of consent actually given with effect for the future, without affecting the lawfulness of previous processing.
Objection: Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. For direct marketing, you have the right to object at any time without giving reasons. Further conditions are set out in Article 21 GDPR.
You can contact info@portasolis.com with your request. To prevent unauthorised disclosure or deletion, we may need appropriate information to verify your identity and link your request to the relevant process. Please do not send us an unsolicited copy of your identity document. If your request concerns a landlord’s independent processing, their involvement or direct handling may also be necessary.
You can lodge a complaint with a data protection supervisory authority, particularly in the place of your habitual residence, workplace or the suspected infringement. For private companies in Bavaria, the competent authority is the Bayerische Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach. Information and the option to lodge a complaint: www.lda.bayern.de.
24. Changes and language versions
This information is updated to reflect actual changes to functions and data processing. This Privacy Policy is available in German, Croatian and English.
