This notice explains how Elniey — Gestão Turística, Lda. ("Elniey") processes personal data collected through the Elniey platform, its website (elniey.com), its onboarding channels and its business operations. It is written to comply with the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Portuguese Lei n.º 58/2019 of 8 August, and the guidance issued by the Comissão Nacional de Proteção de Dados (CNPD). Should you have any question about the processing described here, please contact our Data Protection Officer at Miguel Serôdio Pinto — dpo@elniey.com.
1. Who we are
The controller for the processing described in this notice is Elniey — Gestão Turística, Lda., taxpayer number PT 514 829 301, registered office at Rua Garrett 5, 1200-204 Lisboa, Portugal. When we process personal data of guests on behalf of an operator using the Platform, we act as a data processor within the meaning of art. 28 GDPR — the operator remains the controller of the guest data.
2. What data we collect
We collect three broad categories of personal data:
(a) Operator data — the name, work email, telephone number, business identifier, IBAN and role of the individuals who access the Platform on behalf of a Client organisation. This data is collected at onboarding and updated by the operator through their user settings.
(b) Guest data — the identity documents required by the Serviço de Estrangeiros e Fronteiras (name, date of birth, nationality, document type, document number, photograph), the arrival and departure dates, the property assigned, the contact email and phone number, and any dietary or accessibility notes the guest chooses to share. This data is collected through the online check-in link.
(c) Website data — IP address, user agent, referral URL, cookie identifiers and pages visited. This data is collected automatically when a visitor uses elniey.com and is retained for a maximum of thirteen months.
3. Legal basis for processing
Operator data is processed on the basis of the contract between Elniey and the Client (art. 6(1)(b) GDPR). Guest data is processed on behalf of the Client, whose legal basis is typically the contract with the guest and, for the SEF submission, the legal obligation under Lei n.º 23/2007 (art. 6(1)(c) GDPR). Website analytics cookies are processed only with the visitor's consent (art. 6(1)(a) GDPR).
4. Retention
Guest identity documents are encrypted at rest with a per-tenant key, exposed to the operator only during the active stay, and purged automatically ninety days after the guest's departure — the retention window that the CNPD considers proportionate. Operator data is retained for the duration of the Client contract and for the ten-year archival period required by Portuguese fiscal law. Website analytics cookies expire thirteen months after they are set.
5. Sharing and international transfers
We share personal data with the following categories of recipients: (i) the Portuguese SEF, for the statutory Boletim de Alojamento submission; (ii) the Autoridade Tributária, in relation to fatura recibo issuance; (iii) our infrastructure providers Amazon Web Services EMEA (Ireland) and Cloudflare Portugal, both bound by the standard contractual clauses adopted by the European Commission; (iv) the third-party lock and access-control providers integrated with the guest's stay (Nuki, TTLock, Salto KS, Igloohome), each with a case-specific data-processing agreement in place.
Elniey does not sell personal data, does not use guest data for targeted advertising, and does not enrich guest records with third-party marketing data.
6. Your rights
You have the right to request access to your personal data, its rectification or erasure, the restriction of its processing, its portability, and the right to object to processing based on our legitimate interests. Requests may be addressed to Miguel Serôdio Pinto — dpo@elniey.com and will be answered within thirty days. You have the right to lodge a complaint with the CNPD at Comissão Nacional de Proteção de Dados (CNPD), Av. D. Carlos I, 134 — 1.º, 1200-651 Lisboa.
7. Security
All Platform traffic is encrypted in transit with TLS 1.3. Personal data at rest is encrypted with AES-256, and the encryption keys for guest identity documents are held in a hardware security module rotated quarterly. Access to production data is limited to a small number of named engineers, is logged in an append-only audit trail and reviewed monthly by the DPO.
8. Changes to this notice
We publish material changes to this notice at least thirty days before they take effect. The current version is always available at the URL of this page. A history of past versions is available on request from Miguel Serôdio Pinto — dpo@elniey.com.