Privacy policy
Last updated: August 15, 2026
1. Who is responsible
- Controller
- Lazar Kocic
- Tax ID
- Z4523536Q (Spain)
- Address
- Calle Oriente 21, Pta 3 — 46006 Valencia, Spain
- Contact
- [email protected]
2. What data is processed, and why
This website has no forms. We only process personal data if you write to us by email or call us, and in that case the data is whatever you provide yourself: usually name, email, phone number and the content of your message.
The purpose is to answer your inquiry, prepare a proposal where appropriate, and — if we reach an agreement — manage the working relationship and its invoicing.
We also keep a working list of vacation rental businesses we intend to contact, built from publicly available professional sources: business name, city, listing URL and a business phone number or email. It exists so we can offer the service and so we don't contact the same business twice.
3. On what basis
- Your consent when you contact us on your own initiative.
- Performance of a contract for delivering the service you have engaged.
- Legal obligation for retaining invoices and tax records.
- Legitimate interest where we contact vacation rental professionals to offer our services, using data from public professional sources and limited to what that contact requires.
Those categories come from the GDPR, which applies to us because we are established in the European Union. They apply whether you are in the United States, the United Kingdom or anywhere else, which in practice means you get a stricter standard than most US privacy laws require.
4. How long it is kept
Inquiries that do not lead to an engagement are kept for the duration of the contact and up to a year afterwards, unless you ask for deletion sooner. Client data is kept for the duration of the relationship and thereafter for as long as tax and accounting obligations require.
If you appear in our list of professional contacts and ask to be removed, the entire record is deleted immediately and permanently — not flagged, deleted.
5. Who else has access
We do not sell personal information and we do not share it for cross-context behavioral advertising. Only the providers needed to deliver the service have access, each under a data processing agreement:
- Cloudflare — hosting and infrastructure for this site and the websites we maintain.
- Cloudflare Email Service — sending automated emails (booking confirmations and sign-in links) and receiving the domain’s mail.
- Stripe — payment provider for our clients' websites. Payment details are handled by Stripe directly; we neither see nor store them.
- Our accountant, and public authorities where the law requires it.
6. Data belonging to our clients' guests
This distinction matters. On the websites we build and maintain, the controller of guest data is the property owner, not us. We act as the processor: we process that data solely on their instructions and in order to run the website and its bookings.
Booking data is limited to what managing the stay requires, and the property owner can export it or request its deletion at any time. A data processing agreement is signed with every client.
7. Cookies
This website uses no analytics, profiling or advertising cookies and includes no third-party measurement tools. That is why you will not see a cookie banner: there is nothing to consent to.
The infrastructure provider may set strictly technical security cookies, needed to protect the service against abusive traffic. These are necessary for the site to work and are not used to track you.
8. Your rights
Whoever you are and wherever you are, write to [email protected] saying what you want and we will act on it: a copy of your data, a correction, or deletion. We reply within thirty days at the latest, and we do not charge for it or treat you differently for asking.
If you are in the United Kingdom or the European Union, you also have the right to object, to restrict processing and to data portability, and you may complain to your data protection authority — in the UK, the Information Commissioner’s Office (ico.org.uk).
If you are a California resident, the CCPA gives you the right to know what we collect, to have it deleted, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information, so there is nothing to opt out of. Several other states — Colorado, Connecticut, Virginia and others — give comparable rights, and the same email address covers all of them.
9. Security
We apply reasonable technical and organizational measures to protect data: encryption in transit, restricted access, passwords never stored in plain text, and strict separation of each client's data so that no client can reach another's information.
10. Changes to this policy
If the way we handle data changes, we will update this page and its date. It's worth checking back occasionally.