Skip to main content

Apeiro Hotels

Privacy policy

Last updated: March 2026.

1. Introduction

Apeiro Hotel is committed to protecting the privacy of its guests and website visitors. This Privacy Policy explains how we collect, use, and protect personal data when you visit the website apeirohotels.com, submit an accommodation availability request through our contact form, subscribe to our newsletter, or use reservation systems available on the website.

Personal data processing is carried out in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR).

2. Data Controller

The controller responsible for processing personal data is:

VB Solution d.o.o. Sarajevo

Hadžiristića 1

71000 Sarajevo

Bosnia and Herzegovina

Email: info@apeirohotels.com

Website: apeirohotels.com

For any questions regarding personal data protection, you may contact us using the email address listed above.

3. Data We Collect

During the use of our website, certain personal and technical data may be collected depending on how users interact with the website.

3.1 Accommodation availability inquiries

When a user submits an inquiry via the website contact form, the following data may be collected:

  • first and last name
  • email address
  • phone number
  • check-in date
  • check-out date
  • additional requests or message

This information is used exclusively to process accommodation availability inquiries and to communicate with guests regarding their stay.

3.2 Newsletter subscription

Users may subscribe to receive special offers and updates via our newsletter form. In that case, we collect:

  • name
  • email address

This information is used exclusively for sending promotional updates and special offers from the hotel. Users may unsubscribe at any time using the unsubscribe link included in each email.

4. Legal Basis for Processing

Personal data is processed based on one of the following legal grounds:

  • User consent – when a user voluntarily provides personal data through the contact form or newsletter subscription.
  • Legitimate interest – for ensuring website security, preventing misuse, analyzing website usage, and improving the user experience.

5. Data Retention Period

Personal data is retained only for as long as necessary for the purpose for which it was collected:

  • contact form inquiries are stored for up to 12 months
  • newsletter subscription data is stored until the user unsubscribes

After the retention period expires, personal data is deleted or anonymized.

6. Third-Party Reservation Systems

Reservations for accommodation and restaurant services are handled via third-party booking platforms.

6.1 Accommodation reservations

The website uses the booking platform PHOBS. Users may use the embedded booking widget available on the website, after which the reservation and possible payment process is completed on the PHOBS platform.

PHOBS may collect and process additional information required to complete accommodation reservations, including payment details. Data processing within the PHOBS reservation system is governed by the privacy policies of that service provider.

More information: https://www.phobs.net/

6.2 Restaurant reservations

Reservations for the Amber restaurant are handled through the Eventlin platform. During the reservation process, users may be redirected to Eventlin where the reservation is finalized. Data processing on that platform is subject to Eventlin’s own privacy policies.

More information: https://www.eventlin.com/

7. Analytics and Advertising

The website uses tools for analyzing website usage and managing digital advertising campaigns, including:

  • Google Analytics (GA4)
  • Google Tag Manager
  • Google Search Console
  • Meta Pixel
  • Google Ads
  • Google Ads remarketing
  • Meta remarketing

These tools may collect anonymous statistical data regarding website usage, such as IP address, device type, session duration, and interactions with website content. This information is used solely to analyze website performance and improve user experience.

8. Cookies

The website uses cookies to ensure proper functionality and improve user experience. Cookie management is implemented via the CookieYes platform.

Cookies may fall into the following categories:

  • essential
  • functional
  • analytics
  • marketing

Users can manage cookie preferences at any time through the cookie banner settings.

9. Google reCAPTCHA

To prevent abuse of contact forms and automated attacks, the website uses Google reCAPTCHA v2. This service may collect certain technical data such as IP address and user interaction patterns to verify that a user is a human visitor. Data processing is carried out in accordance with Google’s privacy policy.

10. Sharing Data with Third Parties

Personal data may be accessible to trusted service providers acting as data processors on behalf of the hotel, including:

  • hosting providers
  • analytics services
  • advertising platforms
  • reservation systems

These service providers process data solely for the purpose of providing their services and in compliance with applicable data protection regulations. The hotel does not sell or rent personal data to third parties.

11. International Data Transfers

Some services used on the website, such as analytics and advertising platforms, may process data outside the European Economic Area. In such cases, data transfers are carried out with appropriate safeguards in accordance with GDPR, including standard contractual clauses approved by the European Commission.

12. Hosting, Server Logs and Cloudflare

The website is hosted by Globalhost d.o.o.. Hosting servers may automatically collect certain technical information through server logs, including IP address, date and time of access, browser type, operating system, and referring URL. These logs are used solely for ensuring system security and the proper functioning of the website.

For security and performance optimization purposes, the website uses the infrastructure of Cloudflare, which operates as a content delivery network (CDN) and security layer between users and the server. Cloudflare may process technical data such as IP addresses, network requests, and security logs in order to protect the website from abuse, automated attacks, and other security threats.

13. Data Security

Apeiro Hotel implements appropriate technical and organizational measures to protect personal data from unauthorized access, loss, or misuse. Access to personal data is restricted to individuals who require it for the purpose of providing hotel services.

14. User Rights

Under the GDPR, users have the following rights:

  • the right to access personal data
  • the right to rectification of inaccurate data
  • the right to erasure
  • the right to restrict processing
  • the right to data portability
  • the right to object to processing

To exercise these rights, users may contact the hotel via email: info@apeirohotels.com

15. Right to Lodge a Complaint

If you believe that your personal data has been processed in violation of applicable data protection laws, you have the right to lodge a complaint with the competent supervisory authority.

In Bosnia and Herzegovina, the competent authority is the Personal Data Protection Agency in Bosnia and Herzegovina: https://azlp.ba/Default.aspx?pageIndex=1&langTag=en-US

16. Protection of Minors

The Apeiro Hotel website is not intended for individuals under the age of 16 without supervision or consent of a parent or legal guardian. We do not knowingly collect personal data from individuals under the age of 16 through our website. If you believe that a minor has submitted personal data via our website, please contact us at info@apeirohotels.com so that we can remove such data.

17. Changes to This Privacy Policy

Apeiro Hotel reserves the right to modify this Privacy Policy in case of changes in data processing practices or legal requirements. Any updates will be published on this page.