Privacy Policy
Last updated: July 2026.
This document explains what personal data the Destination Digital Card platform processes, why, how long we keep it and what rights you have — before any interaction with the platform.
Who the data controller is
The data controller is the Destination Management Organization (DMO) Vatra Dornei / Țara Dornelor, which runs the Destination Digital Card program. The card is a free benefit for tourists with a confirmed booking in the destination: a QR code granting direct discounts at local partners. Benefit payments never pass through the platform — the discount is applied directly by the partner when the card is validated.
What data we process
The platform processes strictly the data needed to issue and validate the card, taken from the confirmed booking:
- Full name of the booking holder — shown on the card so the partner can verify the holder.
- E-mail address from the booking — the card is sent to it and the rights below are exercised through it.
- Stay period (check-in and check-out dates) — determines the validity of the card.
- Accommodation name and booking number — identify the stay the card was issued for.
- QR code — an opaque, randomly generated identifier; it contains no personal data.
- Usage records — each scan records the date, the partner where the card was used and the benefit applied.
That much and nothing more: the platform collects no payment data, address, phone number, location data or any other data categories. We use no tracking cookies on the public pages of the card.
Legal basis
Processing is based on the performance of the contract — the card is part of the services attached to your confirmed booking in the destination. Aggregate statistics about the program (number of cards, number of validations per partner) rest on the legitimate interest of the DMO in evaluating and reporting the program; they identify no individuals.
Why we use the data
- To generate the card and send it to the booking e-mail address.
- To validate the card at partners — the operator of the partner sees the name of the holder and the validity so the benefit is applied to the entitled person.
- For aggregate statistics about the program (how many cards, how many uses, at which partners) — without identifying tourists.
The data is not used for marketing, is not sold and is not transferred outside the destination.
Who has access to the data
When the card is validated, the operator of the partner you present it to sees the name of the holder, the validity period and the applicable benefit — only as much as needed to apply the discount. The DMO administrators of the program have access to card data for support and program oversight. The card e-mail is sent through our e-mail provider. There are no other recipients.
How long we keep the data
The card is tied to the stay: it expires on the check-out date and the benefits end. Your identity (name and e-mail address) is kept for 24 months after the end of the stay — the window in which the program is reported and any disputes can be verified — after which it is automatically anonymized. Usage records remain after anonymization only in statistical form, with no link to your identity. You can request anonymization earlier, at any time, through the flow below.
Your rights and how to exercise them
Under the GDPR you have the right of access, rectification, erasure, restriction of processing and data portability.
You exercise them directly on this platform, without an account: on the My data page you enter the booking e-mail address and receive a secure link, valid for 24 hours, through which you can view and download your data (JSON format), request their erasure (immediate anonymization) or send a rectification or restriction request to the DMO.
For any other question about your data you can write to contact@taradornelor.online. You also have the right to lodge a complaint with the Romanian supervisory authority (ANSPDCP).