Privacy Policy

Last updated: 3 July 2026

This Privacy Policy explains how GutoFloodo Ltd., an Irish limited company, collects, uses, stores and shares personal data when you use the CastleDAO accommodation booking website at accomodation.castledao.ie.

This website is used for accommodation bookings at Rock Farm Slane in connection with CastleDAO.

In this policy, "we", "us" and "our" mean GutoFloodo Ltd. "You" means a guest, account holder, website user, or person included in a booking.

1. Who we are

The data controller for your personal data is:

GutoFloodo Ltd.
Registered office: Dogpatch Labs, CHQ Building, Dublin 1, Ireland
Email: info@castledao.ie

As data controller, we decide how and why your personal data is used.

2. What personal data we collect

Account data

When you create an account, we collect:

  • your email address;
  • your password, if you register using email and password; and
  • authentication details needed to keep your account secure.

If you sign in using Google, we may receive basic account information from Google, such as your email address and Google account identifier. We do not receive your Google password.

Booking data

When you make or submit a booking request, we collect:

  • your name;
  • email address;
  • phone number;
  • booking dates;
  • number of guests;
  • free-text notes or messages you choose to submit;
  • booking status;
  • payment status; and
  • booking reference or transaction reference.

Please do not include sensitive personal data in free-text notes unless it is necessary for your booking.

Payment data

Payments are handled through Revolut.

We receive information confirming whether your payment has succeeded or failed, together with payment references and related booking information.

We do not store your full card number or full card security details on our systems.

Communication data

If you contact us, we may collect:

  • your name;
  • email address;
  • phone number;
  • the content of your message;
  • any replies we send; and
  • records of booking-related communications.

Technical and security data

We may collect limited technical data needed to operate the website securely, including:

  • login/session information;
  • authentication cookies;
  • IP address;
  • device/browser information;
  • security logs; and
  • error logs.

We only use this type of data where needed to run, secure and maintain the website.

3. How we use your personal data

We use your personal data for the following purposes:

PurposePersonal data usedGDPR legal basis
Creating and managing your accountEmail, password/authentication data, Google sign-in data if usedContract; legitimate interest in operating a secure booking website
Processing booking requestsName, email, phone number, dates, guest numbers, notes, booking statusContract
Taking and confirming paymentBooking details, payment status, transaction referencesContract
Communicating with you about your bookingName, email, phone number, booking details, messagesContract; legitimate interest in responding to guest queries
Managing changes, cancellations and refundsBooking details, communications, payment referencesContract; legitimate interest in handling booking administration
Complying with tax, accounting and legal obligationsBooking records, invoices, payment records, accounting recordsLegal obligation
Preventing fraud, misuse or security issuesAccount data, login/session data, technical logsLegitimate interest in protecting our website, guests and business
Establishing or defending legal claimsBooking records, communications, payment recordsLegitimate interest; legal obligation where applicable

We do not sell your personal data.

We do not use your personal data for marketing.

We do not use analytics or advertising cookies.

4. Cookies and similar technologies

We use only cookies and similar technologies that are strictly necessary to provide the booking website, account login, authentication, session management and website security.

These cookies may be used to:

  • keep you logged in;
  • remember your session;
  • protect your account;
  • process booking steps;
  • prevent fraud or misuse; and
  • keep the website functioning properly.

Because we only use strictly necessary cookies, we do not use a cookie consent banner.

We do not use advertising cookies, tracking cookies, or analytics cookies.

You can block cookies in your browser settings, but if you block strictly necessary cookies, parts of the website may not work properly, including account login and booking functions.

5. Who we share personal data with

We share personal data only where needed to operate the booking website, process bookings, process payments, communicate with guests, or comply with legal obligations.

Our key service providers are:

ProviderPurpose
SupabaseDatabase hosting, authentication and related infrastructure. Our Supabase Postgres database is EU-hosted.
RevolutPayment processing. Revolut handles card payment details and payment processing.
GoogleGoogle OAuth sign-in, if you choose to use Google to log in.
Email providerSending booking confirmations, replies and other transactional emails.

These providers may process personal data for us or, in some cases, act as independent controllers for parts of their services, such as payment processing or account sign-in.

We may also share personal data if required by law, tax authorities, regulators, courts, professional advisers, insurers, or where necessary to protect our legal rights.

6. International transfers

We aim to use EU-hosted services where possible.

Our Supabase database is hosted in the EU.

Some of our service providers, or their group companies or support teams, may process personal data outside the European Economic Area. Where this happens, we rely on appropriate safeguards, such as:

  • an adequacy decision by the European Commission;
  • Standard Contractual Clauses approved by the European Commission; or
  • other safeguards permitted under GDPR.

7. How long we keep personal data

We keep personal data only for as long as reasonably necessary for the purposes described in this policy.

In general:

Data typeRetention period
Account dataFor as long as your account remains active, and for a reasonable period after closure where needed for security, legal or accounting reasons
Booking recordsUp to 6 years after the end of the relevant financial year, where needed for tax, accounting and legal record-keeping
Payment recordsUp to 6 years after the end of the relevant financial year, where needed for tax, accounting and legal record-keeping
Booking communicationsUp to 6 years where they relate to a booking, dispute, refund, accounting record or legal issue
Technical/security logsFor a limited period needed for security, troubleshooting and fraud prevention, unless longer retention is required for an investigation or legal issue
Unsuccessful or abandoned booking requestsFor a reasonable period needed to manage enquiries, prevent misuse and maintain records, unless longer retention is required by law

We may keep some data for longer if required by law, tax rules, accounting rules, insurance requirements, dispute resolution, fraud prevention, or legal claims.

8. Security

We take reasonable technical and organisational measures to protect your personal data.

These may include:

  • secure database hosting;
  • access controls;
  • password protection and authentication controls;
  • encryption where appropriate;
  • use of trusted service providers;
  • limiting access to personal data to people who need it;
  • monitoring for security issues; and
  • keeping systems and services under review.

No online system is completely secure, but we take data protection and security seriously.

9. Your GDPR rights

Subject to certain limits under GDPR, you have the following rights:

Access

You can ask us for a copy of the personal data we hold about you.

Rectification

You can ask us to correct inaccurate or incomplete personal data.

Erasure

You can ask us to delete your personal data where there is no good reason for us to continue holding it.

We may not be able to delete data that we need to keep for tax, accounting, legal, fraud prevention, dispute resolution or contract reasons.

Restriction

You can ask us to restrict how we use your personal data in certain circumstances.

Portability

You can ask us to provide certain personal data in a structured, commonly used and machine-readable format.

Objection

You can object to processing based on legitimate interests.

If you object, we will stop processing unless we have compelling legitimate grounds to continue, or the processing is needed for legal claims.

Complaint

You have the right to complain to the Irish Data Protection Commission.

Website: dataprotection.ie

We would appreciate the chance to deal with your concern first, but you are not required to contact us before contacting the Data Protection Commission.

10. How to contact us

For privacy questions or GDPR requests, contact us at:

info@castledao.ie

Please include enough information for us to identify you and understand your request.

We may need to verify your identity before responding to certain requests.

11. Changes to this Privacy Policy

We may update this Privacy Policy from time to time.

The latest version will be published on this page with the "Last updated" date shown above.