Skip to content
Privacy

Privacy Policy

Effective 12 August 2026. This policy describes what personal data Castillia collects, why, who we share it with, and the rights you have over it. If anything in here is unclear, write to [email protected] and we will answer plainly.

II

Who we are

Castillia operates a heritage intelligence platform for castles, palaces, monasteries, vineyards, and other heritage properties. Our operating address is Piata Rosetti 6, Sector 2, Bucharest, Romania. For privacy questions you can reach us at [email protected].

For the purposes of the EU General Data Protection Regulation (GDPR), Castillia is the data controller for the personal data described below.

III

Data we collect

From visitors to castillia.com

  • Form submissions (contact, host inquiries, investor inquiries, careers, newsletter sign-ups): your name, email address, optional phone number, and the content of your message.
  • Server logs containing your IP address, browser user agent, and the pages you requested. We use these to debug errors and detect abuse.
  • A small set of cookies strictly necessary to keep you signed in. We do not run advertising or third-party analytics trackers at this time. If that changes, this policy will change first and a cookie banner will appear.

Information about properties, which may not come from you

Not everything on this site was given to us by the person it describes. Where a house is listed, we may hold details about the property and the people responsible for it, a custodian or an estate manager or a family representative, which reached us from the property’s owner, its agent, or a system they already used. We hold that information so we can introduce the house and answer enquiries about it.

Contact details for those individuals are treated as private: they are used to reach the people who look after a house, and they are never shown on the public pages of this site. If you are responsible for a listed property and you want to see what we hold, correct it, or have it removed, write to [email protected] and we will act on it.

From guests replying to an invitation

When you answer an invitation we record your reply, whether you are attending, and the note you leave us. If you are bringing someone we record the name you give for them.

We also ask two questions that touch on health: how you prefer to dine, and any allergies or sensitivities. Under the GDPR, information about allergies counts as data concerning health, and it is held to a higher standard than the rest of this page describes. We ask for it only because a kitchen has to cook for you safely.

  • We keep it only if you tick the box on the reply form that asks whether we may. If you leave that box unticked, we do not keep it. Your reply is still recorded; the dietary notes are not.
  • It is used for catering and nothing else. It is not used to profile you, it is not shared beyond the people preparing the evening, and it never appears on a public page.
  • You may withdraw at any time, either by unticking the box on your reply or by writing to us. Withdrawing clears the notes we hold.
  • Where you give us dietary details for a companion, you are giving us information about somebody else. We hold it for that one evening and clear it afterwards, and no consent you give on their behalf extends it, because it is not yours to give.

We do not ask for your telephone number when you answer an invitation. If we hold one for you, it came with your entry in the register described below and it is treated the same way as the rest of your contact details.

The list the evening is run from. Nobody seats a room from a screen. An administrator can therefore download the replies for one evening as a spreadsheet: who is coming, the name you gave for a companion, any note you left, and the dietary preferences and allergies where you consented to our keeping them. Only Castillia’s own administrators and the administrators of the house or organisation holding that evening can do this, and every download is recorded in our audit trail, so we can always say who took a copy and when.

Once that file exists it sits on somebody’s computer rather than on our platform. We ask everybody who takes one to treat it as the guest list it is, to share it only with the people preparing the evening, and to delete it once the evening is over. We say this plainly because the twelve-month clearing described further down reaches our own records and cannot reach a copy already downloaded.

The people we keep a record of, which may not come from you

Castillia keeps a register of the people connected to its houses and its evenings: guests, hosts, patrons, partners and the people who look after an estate. Most of the register did not come from the people in it. It was assembled from guest lists, invitation records and introductions supplied by the hosts and organisers we work with, which is how a register of this kind has always been built.

Being in the register does not mean you have an account. Most entries have never signed in and never will. For each person we may hold a name and courtesy title, a role or profession, a country and city, contact details, and a record of the evenings they were invited to and whether they came.

The register is private. It is visible only to Castillia’s own administrators, it is never published, never sold, and never shared with other hosts. If you would like to know whether you are in it, see what it says, correct it, or be removed, write to [email protected] and we will act on it. Asking to be removed is enough; you do not need to give a reason.

Being removed means we keep your name and the record that you were at an evening, and delete everything else: your email address, telephone number, postal address, anything you told us about how you dine, and any note we had written. The same across every invitation and reply, and any invitation link you hold stops working. We keep the name because an evening that happened is a real record, and one that cannot say who attended has lost the record rather than protected anybody. If you would rather your name went too, say so and we will do that instead.

People who speak at an evening

Where somebody is invited to speak, to moderate, or to take some other part in the programme, we record the part they are taking and a short biography: their role, their standing, and why they are on the programme. As with the rest of the register, most of this did not come from the person it describes. It was taken from the papers the organisers of the evening gave us, and from what is already published about somebody in public life.

It is used to build the programme, to brief the people running the evening, and to introduce a speaker to the room. It is visible only to Castillia’s own administrators and the people preparing that evening, and it is never shown on the public pages of this site. If you are named on a programme and you would like to see what we hold, correct it, or have it removed, write to [email protected] and we will act on it, on the same terms as the register above.

Analytics

Castillia uses its own first-party, self-hosted, cookieless analytics to count visits in aggregate. For each page view we record the page path and a coarse device family (mobile or desktop). We do not set any analytics cookie, we do not use third-party trackers (there is no Google Analytics), and we do not store your IP address or your full user agent. A visitor is represented only by a one-way hash that is rebuilt from a daily-rotating salt, so it cannot be reversed to identify you and cannot follow you from one day to the next. The result is a simple count of how pages are used, never a profile of who you are.

From platform users

  • Account credentials: email address and a bcrypt hash of your password. We never see your password in clear text.
  • Property and media content you upload: photographs, documents, 3D models, narratives, locations.
  • Activity records: an audit log of changes you make to properties on a tenant workspace, with timestamp, IP address, and user agent.

From media uploads

Photographs may contain GPS coordinates and other EXIF metadata. We extract this metadata to plot the property on a map and to detect duplicate uploads. If you do not want GPS coordinates retained, strip them from your file before upload.

IV

Why we process this data

  • To answer your inquiry. Contact, host, investor and careers messages reach a real person and we keep a record so we don't ask you the same questions twice. Legal basis: legitimate interest in responding to people who write to us.
  • To run the platform. Accounts, properties, audit log, media. All of this is operational. Legal basis: performance of a contract with you / your tenant.
  • To send essential email. Confirmation, password reset, tenant invitations, security notices. Legal basis: performance of a contract / our legitimate interest in account security.
  • To send the journal newsletter. Only after you confirm your subscription. Legal basis: consent. You can withdraw it at any time using the unsubscribe link in any newsletter.
  • To hold an evening and seat you at it. Invitations, replies, companion names and the programme you are shown. Legal basis: our legitimate interest, and yours, in running an event you were invited to and asked to attend.
  • To cook for you safely. Dietary preferences, allergies and sensitivities. Legal basis: your explicit consent, given on the reply form, under Article 9(2)(a) of the GDPR, which is what data concerning health requires. Withhold it and we simply do not keep the notes; withdraw it at any time and we clear them.
  • To keep the register of people connected to Castillia. Names, roles, contact details and a history of which evenings someone was invited to. Legal basis: legitimate interest in maintaining the relationships a house and its gatherings depend on. You may object at any time, and if you do we remove you rather than argue the point.
  • To meet legal obligations. We may retain certain records if required by law or to resolve a dispute. Legal basis: legal obligation / legitimate interest.
V

Who we share data with

Castillia is operated on its own infrastructure, an Ubuntu virtual private server in the European Union. We do not sell personal data. We use the following service providers as data processors, each bound by a data processing agreement and each chosen for EU-friendly data handling:

  • Resend, to deliver transactional and newsletter email (verification, password resets, tenant invitations, inquiry acknowledgements, and invitations to an evening). Resend receives the recipient address, the message body, and minimal headers. An invitation carries your name and the link that opens it; it does not carry dietary notes or anything else from your reply.
  • OpenStreetMap + Nominatim, to render maps and to convert addresses to coordinates. When you geocode an address it is sent to the OSM Nominatim service.
  • Anthropic, where we use AI to assist curation (extractions, summaries) the text or image is sent to Anthropic's Claude API. We do not send personal data through these calls; the inputs are property records and media you have uploaded.
  • Our hosting provider, the VPS where the application runs and where the Postgres database, the MinIO object store, and uploaded media live. Infrastructure is located in the European Union.

We do not run third-party advertising trackers, cross-site analytics, or social-media pixels.

VI

How long we keep things

  • Accounts and property records: for as long as the account is active, plus 30 days after deletion to recover from accidental removal.
  • Inquiries (contact, host, investor, careers): 24 months from the date of the message, then deleted unless an active conversation continues.
  • Newsletter subscribers: until you unsubscribe. Unconfirmed subscriptions are purged after 30 days.
  • Audit log: retained for the lifetime of the tenant. It is part of how we keep the platform honest.
  • Replies to an invitation: the reply itself, and who came, are kept as part of the record of the evening. The dietary preferences and allergies attached to it are cleared twelve months after the event ends, along with anything given for a companion. Correcting your note does not restart that clock; it runs from the evening, not from your last edit.
  • A guest list already downloaded: outside that clock, and outside our reach. The clearing above runs against our own records. Where an administrator has taken the spreadsheet described in section III, that copy is on their computer, and we can ask for it to be deleted after the evening but we cannot delete it ourselves. We would rather say so than promise you a window we cannot keep.
  • Speaking roles and biographies: kept while the evening is being planned and afterwards as part of the record of it. There is no automatic clearing for these at present. They are removed when you ask us to remove them, and they are removed in full when we retire an entry from the register.
  • Dietary details held against a person in the register: cleared twelve months after they were recorded, unless that person has consented to our keeping them.
  • Register entries: kept while the relationship is a live one, and removed on request.
  • Sign-in attempt records: 30 days, then pruned.
  • Page-view counts: 180 days. These carry no IP address and no identifier that survives the day, as described above.
  • Server logs: 14 days.
VII

How we protect your data

  • HTTPS everywhere, HSTS enabled.
  • Passwords hashed with bcrypt at cost 12. We never store them in clear text.
  • Email verification, single-use password-reset tokens, and rate-limited sign-in.
  • Tenant data isolation in Postgres (every record carries a tenant identifier and is only readable by members of that tenant).
  • HMAC-signed webhooks with replay protection and SSRF guards.
  • Daily automated backups of the database and media; restores tested periodically.

No system is invulnerable. If a breach affects your data we will notify the relevant supervisory authority within 72 hours and the affected users without undue delay, as required by GDPR Article 33.

VIII

Your rights

If you are in the EU, the EEA, or the UK, the GDPR gives you the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased, with certain exceptions;
  • restrict how we process it;
  • port your data to another provider in a machine-readable format;
  • object to processing based on our legitimate interest;
  • withdraw consent at any time without affecting prior lawful processing.

Two of these matter particularly here. If you are in the register and you object, we remove you; we do not ask you to justify it. And if you gave us dietary or allergy notes, you can withdraw that consent by unticking the box on your reply, which clears them without needing to write to anyone.

To exercise any of these rights, write to [email protected]. We respond within 30 days. You also have the right to lodge a complaint with your local data protection authority. In Romania, that is ANSPDCP (dataprotection.ro).

IX

Children

Castillia is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, write to us and we will delete it.

X

International transfers

Our infrastructure and processors operate primarily within the European Union. Resend and Anthropic may process data in jurisdictions outside the EU. Where this happens, the transfer is governed by Standard Contractual Clauses approved by the European Commission.

XI

Changes to this policy

We will update this page when we add new processors, change retention windows, or alter the legal basis for any processing. Material changes will be announced by email to active platform users at least 30 days before they take effect.

XII

Get in touch

For any privacy question, including formal data-subject requests, write to [email protected]. If your question is about the marketplace or a specific property, our contact page is a faster route.

Effective 12 August 2026.