Privacy policy
Last updated: 23 September 2026
info-slovenija.si brings together two services, run by two different companies. The business directory is operated by Veldes net d.o.o., Plemljeva ulica 8, 1210 Ljubljana – Šentvid, Slovenija. Accommodation bookings and the payments behind them are operated by SEA LINE napredne storitve d.o.o., Spodnje Gorje 153A, 4247 Zgornje Gorje, Slovenija, company registration number 7516088000, tax number 93879512.
Each company is the data controller for its own part of the service. If you only use the directory, your data is processed by the first; if you book a stay, or host one, the data needed for the booking and the payout is processed by the second. Each group of data below says which service it belongs to.
We process personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Slovenian law.
Data we collect
Directory (all users):
- Registration and listing data: name or company name, email, phone, address and listing content.
- Contact and inquiry data: name, email, phone and message content. When you submit an inquiry or a review we also store the IP address, solely to prevent abuse.
- Technical visit data: page-view and search statistics are kept in aggregate (a count per day), not linked to an individual. See the Cookie policy.
- Questions asked of the on-site assistant are stored without any record of who asked them, and are used to improve the answers.
Data we collect when you book a stay
This data is processed only when you make a reservation:
- Booker details: name, email, phone, stay dates, number of guests and any notes.
- Payment data: the amount, the payment status, the card brand and the last four digits. **We never receive or store the full card number** — the payment is made directly with the payment service provider.
- **Guest registration data (eTurizem or eVisitor):** for each guest, full name, date of birth, gender, citizenship, and the type and number of an identity document. The data set is the same; the system depends on the country of the property — eTurizem for Slovenian properties (residence-registration and tourism acts), eVisitor for Croatian ones, where the host must register the guest within 24 hours. Without this data, guest registration cannot be handled.
- Tourist-tax data: the guest’s age bracket, which determines the rate or an exemption. For Croatian properties, where the host pays an annual flat amount per bed, no per-night tourist tax is charged to the guest.
- If you write a review of a stay, the review text, the rating and the IP address are stored.
Stays booked elsewhere
A host may also enter a stay that was booked through Booking, Airbnb or directly with them, and record the same registration data for that guest. In that case the guest booked nothing with us: the host enters the data as the controller, and we only process it on their instructions — storing it, submitting it to eTurizem or eVisitor, and putting it on an invoice if one is issued.
The data set, the retention period and the guest’s rights are the same as for bookings made through the portal. Because the host is the controller, questions about such an entry go to them; we will help you reach them.
Data we collect from hosts
This data is processed only when you host a property:
- Business data: name, address, tax and registration numbers, and the accommodation register number (RNO).
- Payout data: bank account and legal-representative details, including an identity document. **Identity verification is carried out by the payment service provider and the document is uploaded directly to them; we neither see nor store it.**
- Fiscal-verification data: tax number, business-premises details and the digital certificate used to sign invoices. The certificate is stored encrypted and used solely to sign your own invoices.
- Direct eTurizem submission data (only if the host enables that option with their own AJPES account): the AJPES portal username and password and a qualified digital certificate. The password and certificate are stored encrypted and used solely to submit the guest book in the host’s name; the host can remove them at any time.
- A record of your acceptance of the host terms: the date, the version of the terms and the commission rate in force at that moment.
- Messages you send us from the control panel: the message, any attached image, the page you were on and your browser details.
Purposes and legal bases
- **Performance of a contract** (Art. 6(1)(b) GDPR): running your account, publishing a listing, carrying out a reservation, calculating and paying out to the host, issuing invoices, and support.
- **Legal obligation** (Art. 6(1)(c) GDPR): guest registration in eTurizem (Slovenia) or eVisitor (Croatia), tourist-tax calculation and remittance, fiscal verification of invoices with FURS for Slovenian properties, retention of accounting records, and platform reporting (DAC7).
- **Legitimate interest** (Art. 6(1)(f) GDPR): preventing abuse and fraud, securing the service, aggregate visit statistics, and recovering unpaid amounts.
- **Consent** (Art. 6(1)(a) GDPR): optional cookies and analytics, and update emails where you switch them on. Consent can be withdrawn at any time.
- We do not carry out automated decision-making with legal effects, or profiling in that sense.
Who we share data with
We do not sell personal data. We share it only where it is needed to deliver the service or where the law requires it:
- **The host of the property you booked**: name, email, phone, stay dates, number of guests and the guest registration data. For delivering the stay and for the statutory guest registration, the host is an independent controller.
- **The payment service provider** (Stripe), to take the payment, pay out the host, and carry out statutory identity verification.
- **The Financial Administration of the Republic of Slovenia (FURS)**, for fiscal verification of invoices, to the extent the law prescribes.
- **AJPES / eTurizem** (Slovenian properties) or the **Croatian National Tourist Board / eVisitor** (Croatian properties): the registration itself is filed by the host, who carries that obligation; our role is to prepare and hand over the data you entered. If the host enables direct submission in their control panel, we transmit the guest-book data to AJPES through the official eTurizem interface on the host’s instruction and in their name; every submission is triggered by the host, and we store the submission receipt. We do not submit anything to eVisitor ourselves.
- **The municipality or local tourist board** to which the host remits the tourist and promotion tax.
- Processors that make the service work technically: hosting and server infrastructure, email delivery, accounting, maps, and the language-model provider behind the on-site assistant and the reading of identity documents for the guest book. Only a crop of the lower half of the document (the names and the machine-readable zone) is processed, never the holder’s photograph; the image is not stored — it is read in the moment and discarded. We have data-processing agreements with all of them.
- A copy of the email we send you is also kept in the mailbox we reply from.
Transfers outside the European Economic Area
Some processors — the payment service provider and the language-model provider among them — may process data outside the EEA. Those transfers rely on the European Commission’s standard contractual clauses or on an adequacy decision; you can request a copy of the safeguards at the address below.
How long we keep data
- **Guest registration data (name, date of birth, gender, citizenship, document): 90 days after check-out**, then deleted automatically. Until then it is visible only to you and the host. The booking link is protected twice: besides the random token in the address, opening it requires the date of birth of one of the guests or a one-time code sent to the booking email address — so a forwarded link is not enough on its own.
- Reservation and payment data: until the contractual limitation periods expire, as a rule five years.
- Issued invoices and accounting records: as long as tax and accounting law requires, as a rule ten years.
- Account and listing data: for as long as the relationship lasts; after an account is deleted we remove or anonymise it, except what the law requires us to keep.
- Unconfirmed registrations: cleaned up automatically shortly after the confirmation link expires.
- Aggregate visit and search statistics: contain no personal data and are therefore not time-limited.
Your rights
Under the GDPR you have the right to:
- access your data and correct inaccurate data,
- erase data and restrict processing,
- object to processing and withdraw consent,
- data portability,
- lodge a complaint with the Information Commissioner of the Republic of Slovenia (Dunajska cesta 22, 1000 Ljubljana, gp.ip@ip-rs.si).
What those rights do not cover
Data we are required by law to collect and keep — guest registration data, or the details on an invoice already issued — cannot be erased on request before the statutory period ends. Nor can we erase data the host holds as an independent controller; in that case please contact them directly, and we will help you do so.
Security
Access to personal data is limited to those who need it for their work. The connection to the site is encrypted, passwords are stored only in a form they cannot be read back from, and hosts’ digital certificates are encrypted on top of that. Guest registration data is deleted automatically when its period ends, with no human involvement.
Contact
To exercise your rights or for privacy questions, email podpora@info-slovenija.si or call 030 744 680. For questions about reservations and payouts, write to pravno@info-slovenija.si.
Changes to this policy
We update this policy whenever the way we process data changes. The date of the last change is shown at the top. For significant changes we notify registered users by email or in the control panel.

