VIDEO SURVEILLANCE POLICY
TINT S.R.L. – TELEFERIC GRAND HOTEL
This Video Surveillance Policy describes how TINT S.R.L. – Teleferic Grand Hotel uses video surveillance systems and the measures adopted to protect the privacy and personal data of guests, visitors, employees, contractors and other persons entering monitored areas.
This Policy supplements the TINT S.R.L. Privacy Policy.
- Personal Data Controller
The controller of personal data processed through the video surveillance systems is:
TINT S.R.L. – Teleferic Grand Hotel
243 Poiana Soarelui Street
Poiana Brașov, Municipality of Brașov
Brașov County, postal code 500001
Romania
Tax Identification No.: 13694214
Trade Register No.: J08/1892/2013
Telephone: +40 368 100 200
E-mail: frontoffice@telefericgrandhotel.ro
For questions or requests concerning personal data protection, the following address may be used:
- Legal Framework
The processing of images through video surveillance systems is carried out in accordance with applicable legislation, including:
- Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data – GDPR;
- Romanian Law No. 190/2018 on measures implementing Regulation (EU) 2016/679;
- Romanian Law No. 333/2003 on the guarding of objectives, assets and valuables and the protection of persons, as subsequently amended and supplemented;
- Government Decision No. 301/2012 approving the methodological rules for the application of Law No. 333/2003, as subsequently amended and supplemented;
- Guidelines 3/2019 of the European Data Protection Board – EDPB on processing of personal data through video devices;
- other applicable legal provisions concerning the security of persons, property and personal data.
- Purposes of Video Surveillance
TINT S.R.L. uses video surveillance systems for the purpose of ensuring the security of persons, property and Hotel premises.
In particular, video surveillance is intended to:
- protect the life, physical integrity and safety of guests, visitors, employees and contractors;
- protect the property of TINT S.R.L., guests, employees and other persons;
- prevent, deter and investigate theft, damage, vandalism, unauthorised access and other security incidents;
- control and secure access to certain areas;
- prevent and investigate incidents that may affect the safety of persons or property;
- identify the circumstances in which a security incident occurred;
- comply with legal obligations concerning the guarding and security of premises, where applicable;
- establish, exercise or defend legal claims where video footage is relevant to a specific incident.
The video surveillance system is not used for marketing purposes and is not intended to monitor the commercial behaviour of guests.
- Legal Basis for Processing
Depending on the purpose and location of the surveillance system, the processing of video images may be based on:
- a) Legitimate Interests of TINT S.R.L.
TINT S.R.L. has legitimate interests in:
- the safety and security of persons;
- the security of the Hotel;
- the prevention and investigation of incidents;
- the protection of property;
- access control;
- the establishment, exercise and defence of the company’s lawful rights and interests.
Before using video surveillance systems, TINT S.R.L. assesses the necessity and proportionality of the processing and its impact on the rights and freedoms of data subjects.
- b) Compliance with Legal Obligations
Where legislation concerning guarding and security requires specific security measures to be implemented, the processing may be necessary for compliance with a legal obligation applicable to TINT S.R.L.
- c) Establishment, Exercise or Defence of Legal Claims
Recordings relating to a specific incident may be retained and used where this is necessary for the establishment, exercise or defence of legal rights or claims.
Consent of the person being recorded is not normally the legal basis for video surveillance used for Hotel security purposes.
- Principles Governing the Use of the System
TINT S.R.L. uses video surveillance in accordance with the principles of:
- lawfulness, fairness and transparency;
- purpose limitation;
- data minimisation;
- proportionality;
- storage limitation;
- integrity and confidentiality;
- accountability.
Cameras must be positioned and configured so that they monitor only the areas necessary for security purposes.
TINT S.R.L. seeks to avoid excessive or unjustified monitoring.
- Assessment of Necessity and Proportionality
Camera locations, viewing angles, retention periods and authorised access to recordings are determined taking into account:
- identified security risks;
- the purpose pursued;
- the characteristics of the monitored area;
- the possibility of using less intrusive measures;
- the rights and reasonable privacy expectations of data subjects.
The system is periodically reviewed to verify whether each camera remains necessary and proportionate to the purpose for which it was installed.
Where required by law or justified by the level of risk, TINT S.R.L. carries out the necessary data protection impact assessments.
- Characteristics of the CCTV System
The Teleferic Grand Hotel video surveillance system is used for security purposes.
Cameras may operate 24 hours a day, 7 days a week.
Recordings may contain:
- images of persons;
- the date of the recording;
- the time of the recording;
- the area or surveillance camera from which the image originates.
Image quality may allow the identification of persons within the camera’s field of view.
The security surveillance system:
- does not record audio;
- does not use facial recognition;
- does not perform automated biometric identification;
- is not used for profiling;
- does not make automated decisions concerning recorded persons.
Any significant change to these characteristics will be subject to a legal and data protection assessment prior to implementation.
- Monitored Areas
Cameras are installed in areas where monitoring is justified by security needs.
These may include, as applicable:
- Hotel entrances and exits;
- access routes;
- Reception;
- certain corridors and common areas;
- circulation and connecting areas;
- certain areas where goods or valuables are handled or stored;
- restricted-access areas;
- parking areas;
- vehicle and pedestrian access routes;
- certain external and perimeter areas.
Monitoring outside TINT S.R.L. property is limited, as far as possible, to what is strictly necessary to protect access points and the perimeter.
- Areas Where Video Surveillance Is Not Used
Surveillance cameras are not installed in areas where individuals have a high or maximum reasonable expectation of privacy, such as:
- guest rooms;
- toilets;
- shower cubicles;
- changing rooms;
- changing booths;
- treatment or procedure rooms where recording would unjustifiably interfere with an individual’s privacy;
- other similar areas.
Cameras are not intentionally directed towards areas that are not relevant to the security purpose.
- Categories of Personal Data Processed
The CCTV system may process the following categories of personal data:
- the person’s image;
- their visible appearance;
- movements and activities observable within the monitored area;
- date and time;
- the location where the person was captured by the system.
The system is not designed to collect or infer special categories of personal data.
The fact that an image may incidentally reveal certain characteristics of a person, including a visible disability, does not in itself mean that TINT S.R.L. processes the image for the purpose of inferring health data or classifying the person on the basis of a special category of personal data.
TINT S.R.L. does not use CCTV for biometric recognition or for classifying persons according to racial or ethnic origin, political opinions, religious beliefs, health status, sexual orientation or other protected characteristics.
- Video Surveillance and Employees
Cameras installed for Hotel security purposes may also capture employees during their work.
The system is not intended for the permanent monitoring of individual employee performance, productivity or professional efficiency.
To the extent that video surveillance involves monitoring employees at the workplace on the basis of the employer’s legitimate interests, TINT S.R.L. applies the requirements of Romanian Law No. 190/2018, including:
- proper justification of the legitimate interest;
- prior, complete and explicit information of employees;
- consultation with the trade union or, where applicable, the employees’ representatives before the introduction of monitoring systems;
• verification that other less intrusive forms and methods for achieving the intended purpose have previously proved ineffective;
• limitation of the retention period to what is necessary and proportionate, in compliance with the time limits provided by the applicable legislation and this Policy.
Recordings are not used for purposes incompatible with the original purpose unless an appropriate legal basis exists and all applicable legal requirements are met.
- Access to Video Recordings
Access to the surveillance system and recordings is restricted according to the need-to-know principle.
TINT S.R.L. determines and documents which persons and functions may:
- view live images;
- review recordings;
- perform searches;
- extract a relevant sequence;
- export or copy recordings;
- administer the system.
Access rights are granted only to the extent necessary for the duties of the relevant person.
Accessing or using recordings for purposes other than those authorised is prohibited.
- Staff and Confidentiality Obligations
Persons authorised to access video recordings receive training regarding:
- personal data protection;
- confidentiality of recordings;
- the purposes for which recordings may be used;
- the limits of their access rights;
- procedures applicable to security incidents.
Authorised personnel are subject to confidentiality obligations.
The unauthorised transmission, photographing, copying or disclosure of recordings is prohibited.
- External Service Providers
Maintenance, repair or technical administration of the system may also be carried out by specialised external service providers.
Where a service provider has or may have access to personal data on behalf of TINT S.R.L., the relationship is governed in accordance with the GDPR requirements applicable to processors.
Access by service providers must be restricted to what is strictly necessary for the relevant technical services.
Service providers are subject to security and confidentiality obligations.
- Recipients of Video Recordings
Recordings are not routinely disclosed to third parties.
Relevant recordings or sequences may be disclosed, where there is a valid legal basis and disclosure is necessary, to:
- the Romanian Police;
- public prosecutors;
- courts of law;
- other competent public authorities;
- insurance companies, where recordings are necessary for handling an insured event and an appropriate legal basis exists;
- lawyers, advisers or other professionals involved in the establishment, exercise or defence of legal rights;
- data subjects exercising their right of access, subject to protection of the rights of other persons.
Disclosure to public authorities is carried out in accordance with the law and, where appropriate, on the basis of an official request or where TINT S.R.L. has the legal right or obligation to notify the authorities.
There are no periodic or routine transfers of recordings to public authorities.
- Security Measures
TINT S.R.L. applies appropriate technical and organisational measures to protect the surveillance system and recordings.
These may include:
- limiting access to authorised persons;
- individual user accounts and access rights, where applicable;
- protecting equipment and the areas in which it is located;
- protecting the system against unauthorised access;
- procedures governing the export and disclosure of recordings;
- training authorised personnel;
- confidentiality obligations;
- periodic review of access rights;
- separate and secure storage of recordings extracted for the investigation of an incident.
- Retention Period
CCTV recordings are ordinarily retained for 20 days, after which they are automatically deleted or overwritten unless there is a specific and justified reason to retain a particular recording.
TINT S.R.L. keeps this retention period under review and periodically assesses whether the 20-day period remains necessary and proportionate to the risks and specific characteristics of hotel operations.
Where an incident is identified during the retention period, strictly relevant recordings may be extracted from the system and retained separately.
Such recordings may be kept for the period necessary for:
- investigating the incident;
- resolving a complaint;
- handling an insurance claim;
- a disciplinary investigation, where permitted by law;
- litigation;
- a criminal investigation;
- the establishment, exercise or defence of legal rights.
Extracted recordings are not automatically retained for a fixed period of one year, but only for as long as a specific and legitimate purpose for their retention exists.
Once the reason for retention no longer applies, the recordings are deleted in accordance with the applicable procedures.
- Information for Individuals Regarding Video Surveillance
TINT S.R.L. provides information to data subjects through a multi-layered approach:
Layer 1 – CCTV sign/notice
Monitored areas are marked by visible signs or notices positioned so that, as far as possible, individuals are made aware of the video surveillance before entering the monitored area.
The first-layer notice indicates, at a minimum, that the area is under video surveillance, the identity of the controller – TINT S.R.L., the main purpose of the surveillance, the usual retention period for the recordings, the existence of data subject rights, and the means by which the full information regarding the processing of personal data can be accessed.
Layer 2 – Information Notice on Premises Security, Access Control and Video Surveillance
The Notice provides the essential information regarding the controller, the personal data processed, the purposes and legal bases of the processing, the recipients, the retention period and the rights of data subjects.
Layer 3 – Video Surveillance Policy
This Policy provides detailed information on the organisation and operation of the CCTV system, the monitored areas, access to video footage, security measures, retention periods, the procedure for exercising data subject rights and the applicable internal rules.
The Information Notice and this Policy may be consulted on the Teleferic Grand Hotel website, at the Hotel Reception and, where applicable, by other means indicated on the CCTV notices.
- Rights of Data Subjects
Subject to the GDPR and applicable legislation, persons recorded by the CCTV system may have, as applicable:
- the right of access to personal data concerning them;
- the right to erasure, where the legal conditions are met;
- the right to restriction of processing;
- the right to object, where processing is based on legitimate interests;
- the right to be informed about the processing;
- the right to lodge a complaint with the supervisory authority;
- the right to seek judicial remedies.
The right to rectification has limited applicability in the context of video recordings because a recording reproducing an event cannot normally be “corrected” without altering the record itself.
These rights are not absolute and may be restricted in circumstances provided by law, including where necessary to protect the rights and freedoms of other persons, preserve evidence or comply with a legal obligation.
- Right of Access to Recordings
A person wishing to obtain access to recordings in which they appear must provide sufficient information to identify the relevant footage.
Where possible, the request should indicate:
- the approximate date;
- the approximate time interval;
- the area where the person was present;
- relevant circumstances.
TINT S.R.L. may request additional information strictly necessary to identify the relevant footage.
Where there are reasonable doubts concerning the identity of the requester, TINT S.R.L. may request information necessary to confirm their identity.
Identity verification must be proportionate and does not automatically require the provision of a photograph or a copy of an identity document where the person’s identity can be verified by a less intrusive method.
- Recordings Containing Other Persons
Where requested footage also contains other persons, TINT S.R.L. must protect their rights and freedoms.
Depending on the circumstances, access may be provided by:
- allowing the requester to view the footage;
- providing a relevant sequence;
- blurring or masking other persons;
- extracting only the relevant segment;
- applying other reasonable technical measures.
A person’s right of access must not unjustifiably affect the rights of other persons captured by the system.
- Time Limit for Responding to Requests
TINT S.R.L. responds to requests concerning the exercise of data protection rights without undue delay and, in any event, within one month of receipt of the request.
This period may be extended by up to two additional months where necessary, taking into account the complexity and number of requests.
The data subject will be informed of any extension and the reasons for it within the initial one-month period.
Where TINT S.R.L. does not take action on a request, the person will be informed of the reasons and of their right to lodge a complaint with the supervisory authority and seek a judicial remedy.
- How to Exercise Your Rights
Requests relating to video surveillance and data protection may be sent to:
TINT S.R.L. – Teleferic Grand Hotel
243 Poiana Soarelui Street
Poiana Brașov, Brașov 500001
Romania
General e-mail:
frontoffice@telefericgrandhotel.ro
Data Protection / DPO:
dpo@telefericgrandhotel.ro
For faster identification of the request, it is recommended that the subject line include:
“GDPR Request – Video Surveillance”
- Right to Lodge a Complaint
Data subjects have the right to lodge a complaint with:
The Romanian National Supervisory Authority for Personal Data Processing – ANSPDCP
Exercising this right does not affect the person’s right to use any other administrative or judicial remedy provided by law.
- Investigation of Incidents
In the event of a security incident, access to relevant recordings is limited to persons who require access for the investigation and resolution of the matter.
Any extraction of recordings must be limited to:
- the necessary time interval;
- relevant cameras;
- relevant persons and events.
Extracted copies must be protected against unauthorised use, access or disclosure.
- Use of Recordings for Other Purposes
Recordings will not subsequently be used for a purpose incompatible with the purpose for which they were collected.
Any subsequent use must be assessed in terms of:
- compatibility of purpose;
- existence of a legal basis;
- necessity;
- proportionality;
- impact on data subjects.
Recordings are not used for advertising, social media or promotional materials unless there is a separate valid legal basis and the rights of the persons concerned are respected.
- Review of the System
TINT S.R.L. periodically reviews the video surveillance system and this Policy.
The review considers, in particular, whether:
- each camera remains necessary;
- its location and viewing angle remain appropriate;
- the system continues to serve its stated purposes;
- less intrusive alternatives are available;
- the retention period remains justified;
- persons with access to the system remain authorised;
- security measures remain adequate;
- information provided to data subjects is accurate and up to date;
- the system and procedures continue to comply with applicable legislation.
- Technological Solutions and Privacy Protection
When purchasing, replacing or expanding video surveillance systems, TINT S.R.L. will take into account the principles of data protection by design and by default.
Where reasonably possible, preference will be given to solutions that allow:
- limitation of camera viewing angles;
- granular access control;
- limitation of retention periods;
- automatic deletion or overwriting;
- protection of exported recordings;
- reduction of the risk of unauthorised access.
- Amendments to This Policy
This Policy may be updated in the event of:
- changes to the CCTV system;
- installation or removal of cameras;
- changes to the purposes of processing;
- changes to the retention period;
- changes in applicable legislation;
- changes to internal procedures;
- the introduction of new technologies or relevant risks.
The updated version will be published on the website together with the date of the latest revision.
- Contact
For any questions regarding this Policy:
TINT S.R.L. – Teleferic Grand Hotel
243 Poiana Soarelui Street
Poiana Brașov, Brașov 500001
Romania
Telephone: +40 368 100 200
E-mail: frontoffice@telefericgrandhotel.ro
Data Protection / DPO:
dpo@telefericgrandhotel.ro
Website: www.telefericgrandhotel.ro
Last updated: 30 September 2026