Last updated: 15 September 2026

1. Who is responsible for your information

Hospitality International d.o.o., registered in Montenegro, is responsible for the personal information described in this policy (the data controller).
Registered office: Bjelastica 6, 85310 Budva, Montenegro.
For privacy questions or requests, email contact@hotelier.one.
This policy covers visitors to hotelier.one and people who contact us about our services. Personal information handled during a client assignment, including hotel guest records, is addressed separately in the relevant service and data-processing arrangements.

2. Information we receive

When you send an enquiry, we receive your name, role or position, email address, telephone number, property name and location, and message. You may also provide a property website, preferred messenger and service of interest. We keep relevant correspondence and notes about your enquiry.
The form identifies required and optional fields. Required fields help us identify the person and property and arrange a relevant response. You can email us instead of using the form. Without sufficient contact information, we may be unable to respond.
Website and form systems may process technical information, including IP address, browser information, submission time and source page, to operate the service and prevent abuse.
Please do not use the enquiry form to send hotel guest records, sensitive personal information, passwords, payment-card details, confidential financial reports or contracts. We agree appropriate arrangements before receiving confidential project materials.

3. Why we use information

We use enquiry information to respond, understand the request, assess whether we can assist, arrange an introductory conversation and prepare a relevant proposal.
Where you are a prospective contracting party, we process information to take steps at your request before entering into a contract. Where you represent a company or property, we rely on our legitimate interest in handling relevant business enquiries and communicating with its representatives, balanced against your rights. We also process information where necessary to protect our website, handle legal claims or meet legal obligations.
Sending an enquiry does not subscribe you to newsletters or unrelated promotional messages. Any future newsletter subscription will be offered separately. Where processing relies on consent, you may withdraw it without affecting processing that was lawful before withdrawal.
We do not sell personal information or make decisions producing legal or similarly significant effects about you solely by automated means.

4. Who may receive information

Access is limited to people authorised to handle enquiries and provide the requested services, subject to confidentiality obligations.
We use Tilda for website hosting and forms, Tilda CRM to organise enquiries, and Google Workspace for business email. Relevant information may also be disclosed to professional advisers or authorities where necessary for legal obligations or legal claims.
If you choose to communicate through an external messenger, that provider handles information under its own privacy terms.

5. International processing

We handle enquiries from Montenegro. Our providers operate internationally, so information is not necessarily stored or processed only in Montenegro or the European Union.
Tilda’s published Data Processing Agreement describes processing in the European Union and the United States, and standard contractual clauses for applicable transfers to the United Arab Emirates. Google’s published Cloud Data Processing Addendum describes its international processing and transfer arrangements. The arrangements applicable to a service depend on its contractual terms and applicable law.
You can contact us for information about the transfer arrangements relevant to your information and request a copy of applicable safeguards, subject to necessary redactions.

6. How long we keep information

If an enquiry does not lead to an engagement, our retention period is 12 months after the last substantive communication. We then delete the enquiry and related correspondence or irreversibly anonymise it. This period allows reasonable follow-up where a hotel project takes time to develop.
If an enquiry becomes an engagement, relevant information forms part of our client records and is retained for the engagement and applicable contractual, accounting and legal requirements. Information needed for a specific legal claim may be retained until that need ends.
The temporary copy in Tilda’s website Leads section is retained for 30 days, separately from email and CRM records. Provider-managed security logs and backups are subject to their applicable retention and deletion procedures; deleting a record from an active system does not necessarily remove every backup immediately.

7. Cookies and website analytics

We use Tilda’s simplified statistics to understand page views. This mode does not use cookies to track individual visitors or sessions. This website does not use Google Analytics, Google Tag Manager, Yandex Metrica or advertising pixels.
The hosting platform may use necessary technical cookies and process IP addresses to protect the website and its forms against abuse. You can manage cookies in your browser, although blocking necessary cookies may affect website functions.

8. Your rights

Contact contact@hotelier.one to ask whether we hold your personal information and request access, correction or deletion. Depending on applicable law and the circumstances, you may also request restriction or portability, object to processing based on legitimate interests, or withdraw consent where it is the basis for processing.
We may request proportionate information to verify your identity and will respond within the applicable statutory deadline. If information must be retained for a legal obligation or claim, or a request cannot be fulfilled in full, we will explain why.
You may complain to Montenegro’s Agency for Personal Data Protection and Free Access to Information. Where the GDPR applies, you may also complain to the relevant EU/EEA supervisory authority, including in your place of habitual residence or work.

9. Security and policy updates

Protecting information requires appropriate access controls and organisational measures. No internet service can guarantee absolute security.
We may update this policy when our services, systems or legal obligations change. The date above identifies the latest version. Material changes will be communicated as required by applicable law.