Privacy Policy
Last updated: 3 July 2026
This Privacy Policy explains how GutoFloodo Ltd., an Irish limited company, collects, uses, stores and shares personal data when you use the CastleDAO accommodation booking website at accomodation.castledao.ie.
This website is used for accommodation bookings at Rock Farm Slane in connection with CastleDAO.
In this policy, "we", "us" and "our" mean GutoFloodo Ltd. "You" means a guest, account holder, website user, or person included in a booking.
1. Who we are
The data controller for your personal data is:
GutoFloodo Ltd.
Registered office: Dogpatch Labs, CHQ Building, Dublin 1, Ireland
Email: info@castledao.ie
As data controller, we decide how and why your personal data is used.
2. What personal data we collect
Account data
When you create an account, we collect:
- your email address;
- your password, if you register using email and password; and
- authentication details needed to keep your account secure.
If you sign in using Google, we may receive basic account information from Google, such as your email address and Google account identifier. We do not receive your Google password.
Booking data
When you make or submit a booking request, we collect:
- your name;
- email address;
- phone number;
- booking dates;
- number of guests;
- free-text notes or messages you choose to submit;
- booking status;
- payment status; and
- booking reference or transaction reference.
Please do not include sensitive personal data in free-text notes unless it is necessary for your booking.
Payment data
Payments are handled through Revolut.
We receive information confirming whether your payment has succeeded or failed, together with payment references and related booking information.
We do not store your full card number or full card security details on our systems.
Communication data
If you contact us, we may collect:
- your name;
- email address;
- phone number;
- the content of your message;
- any replies we send; and
- records of booking-related communications.
Technical and security data
We may collect limited technical data needed to operate the website securely, including:
- login/session information;
- authentication cookies;
- IP address;
- device/browser information;
- security logs; and
- error logs.
We only use this type of data where needed to run, secure and maintain the website.
3. How we use your personal data
We use your personal data for the following purposes:
| Purpose | Personal data used | GDPR legal basis |
|---|---|---|
| Creating and managing your account | Email, password/authentication data, Google sign-in data if used | Contract; legitimate interest in operating a secure booking website |
| Processing booking requests | Name, email, phone number, dates, guest numbers, notes, booking status | Contract |
| Taking and confirming payment | Booking details, payment status, transaction references | Contract |
| Communicating with you about your booking | Name, email, phone number, booking details, messages | Contract; legitimate interest in responding to guest queries |
| Managing changes, cancellations and refunds | Booking details, communications, payment references | Contract; legitimate interest in handling booking administration |
| Complying with tax, accounting and legal obligations | Booking records, invoices, payment records, accounting records | Legal obligation |
| Preventing fraud, misuse or security issues | Account data, login/session data, technical logs | Legitimate interest in protecting our website, guests and business |
| Establishing or defending legal claims | Booking records, communications, payment records | Legitimate interest; legal obligation where applicable |
We do not sell your personal data.
We do not use your personal data for marketing.
We do not use analytics or advertising cookies.
4. Cookies and similar technologies
We use only cookies and similar technologies that are strictly necessary to provide the booking website, account login, authentication, session management and website security.
These cookies may be used to:
- keep you logged in;
- remember your session;
- protect your account;
- process booking steps;
- prevent fraud or misuse; and
- keep the website functioning properly.
Because we only use strictly necessary cookies, we do not use a cookie consent banner.
We do not use advertising cookies, tracking cookies, or analytics cookies.
You can block cookies in your browser settings, but if you block strictly necessary cookies, parts of the website may not work properly, including account login and booking functions.
5. Who we share personal data with
We share personal data only where needed to operate the booking website, process bookings, process payments, communicate with guests, or comply with legal obligations.
Our key service providers are:
| Provider | Purpose |
|---|---|
| Supabase | Database hosting, authentication and related infrastructure. Our Supabase Postgres database is EU-hosted. |
| Revolut | Payment processing. Revolut handles card payment details and payment processing. |
| Google OAuth sign-in, if you choose to use Google to log in. | |
| Email provider | Sending booking confirmations, replies and other transactional emails. |
These providers may process personal data for us or, in some cases, act as independent controllers for parts of their services, such as payment processing or account sign-in.
We may also share personal data if required by law, tax authorities, regulators, courts, professional advisers, insurers, or where necessary to protect our legal rights.
6. International transfers
We aim to use EU-hosted services where possible.
Our Supabase database is hosted in the EU.
Some of our service providers, or their group companies or support teams, may process personal data outside the European Economic Area. Where this happens, we rely on appropriate safeguards, such as:
- an adequacy decision by the European Commission;
- Standard Contractual Clauses approved by the European Commission; or
- other safeguards permitted under GDPR.
7. How long we keep personal data
We keep personal data only for as long as reasonably necessary for the purposes described in this policy.
In general:
| Data type | Retention period |
|---|---|
| Account data | For as long as your account remains active, and for a reasonable period after closure where needed for security, legal or accounting reasons |
| Booking records | Up to 6 years after the end of the relevant financial year, where needed for tax, accounting and legal record-keeping |
| Payment records | Up to 6 years after the end of the relevant financial year, where needed for tax, accounting and legal record-keeping |
| Booking communications | Up to 6 years where they relate to a booking, dispute, refund, accounting record or legal issue |
| Technical/security logs | For a limited period needed for security, troubleshooting and fraud prevention, unless longer retention is required for an investigation or legal issue |
| Unsuccessful or abandoned booking requests | For a reasonable period needed to manage enquiries, prevent misuse and maintain records, unless longer retention is required by law |
We may keep some data for longer if required by law, tax rules, accounting rules, insurance requirements, dispute resolution, fraud prevention, or legal claims.
8. Security
We take reasonable technical and organisational measures to protect your personal data.
These may include:
- secure database hosting;
- access controls;
- password protection and authentication controls;
- encryption where appropriate;
- use of trusted service providers;
- limiting access to personal data to people who need it;
- monitoring for security issues; and
- keeping systems and services under review.
No online system is completely secure, but we take data protection and security seriously.
9. Your GDPR rights
Subject to certain limits under GDPR, you have the following rights:
Access
You can ask us for a copy of the personal data we hold about you.
Rectification
You can ask us to correct inaccurate or incomplete personal data.
Erasure
You can ask us to delete your personal data where there is no good reason for us to continue holding it.
We may not be able to delete data that we need to keep for tax, accounting, legal, fraud prevention, dispute resolution or contract reasons.
Restriction
You can ask us to restrict how we use your personal data in certain circumstances.
Portability
You can ask us to provide certain personal data in a structured, commonly used and machine-readable format.
Objection
You can object to processing based on legitimate interests.
If you object, we will stop processing unless we have compelling legitimate grounds to continue, or the processing is needed for legal claims.
Complaint
You have the right to complain to the Irish Data Protection Commission.
Website: dataprotection.ie
We would appreciate the chance to deal with your concern first, but you are not required to contact us before contacting the Data Protection Commission.
10. How to contact us
For privacy questions or GDPR requests, contact us at:
Please include enough information for us to identify you and understand your request.
We may need to verify your identity before responding to certain requests.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
The latest version will be published on this page with the "Last updated" date shown above.