Contour line
Our company

Information about secure communication and the protection of reservation data

At Sava Hotels & Resorts, we take the security of personal data and the trust of our guests very seriously. We therefore wish to provide guests with clear and transparent information about a security incident that occurred on 4 June 2026 involving our external provider of the online reservation system, and to offer recommendations for secure communication regarding reservations.

What happened?
Our contracted provider of the online reservation system that we use to manage reservations informed us of a security incident affecting its IT system. 
According to the information received from the provider, unauthorised access may have been gained to certain reservation-related data. 

What data may have been accessed?
Based on the information currently available, the following reservation-related data may have been accessed:

•    name and surname,
•    contact details, such as email address, telephone number and residential address, if provided when making the reservation,
•    reservation details, such as arrival and departure dates, type of accommodation, selected hotel or other accommodation, and reservation number,
•    a limited amount of payment card data, such as the card type, the last four digits of the card number, the expiry date and the cardholder’s name.

According to the information provided to us by the external service provider, full payment card numbers and CVV security codes were not disclosed. CVV security codes are not stored in the system.

Is my reservation still valid?
Yes. Your reservation with Sava Hotels & Resorts remains valid. This notification does not mean that you have to reconfirm your reservation, re-enter your payment card details or make any additional payment via links received by email, text message, WhatsApp, or other communication channels.

What should you look out for?
Incidents of this kind may increase the risk of receiving unusual or suspicious messages from senders falsely claiming to represent a hotel, accommodation provider, reservation system or another partner.

Please be particularly vigilant regarding messages asking you to:

•    make an additional payment,
•    re-enter your payment card details,
•    provide your CVV, PIN, or one-time banking codes,
•    send a photograph of your payment card,
•    click on unverified links,
•    act urgently under pressure or the threat that your reservation will be cancelled.

Sava Hotels & Resorts will never ask you to provide your PIN, CVV, one-time banking codes, or photographs of your payment card via WhatsApp, text messages, links in emails, or similar unofficial communication channels.

What should you do if you receive a suspicious message?
If you receive a message that appears unusual or suspicious:

•    do not reply to it,
•    do not click on any links,
•    do not provide payment card details or other sensitive information,
•    do not make additional payments via unverified links,
•    verify the authenticity of the message using the official Sava Hotels & Resorts contact details.

To verify a message or ask a question about your reservation, please contact us at:
Sava Hotels & Resorts Reservation Centre: info.shr@sava.si
Sava Hotels & Resorts Data Protection Officer: dpo@sava.si

What measures have we taken?
Immediately after receiving notification of the incident, Sava Hotels & Resorts activated its internal security incident response procedure and began investigating the circumstances of the incident, its potential scope, and any possible consequences for our guests.

We notified the competent authorities and took additional measures to protect our guests, including notifying them of the incident and advising them to exercise caution regarding potentially suspicious messages.

The external provider of the online reservation system informed us that, after detecting the incident, it remedied the identified vulnerability and implemented additional security measures to prevent similar incidents in the future. It also engaged cybersecurity and data protection experts to assist with the investigation.

If we receive new information that could materially affect the assessment of the risks to guests or our understanding of the scope of the incident, we will notify our guests accordingly.

Why are we informing you?
We are informing you of the incident in the interests of responsible, open and transparent communication and in accordance with the applicable personal data protection legislation, including the General Data Protection Regulation (GDPR or Regulation (EU) 2016/679)).

We understand that notifications of this kind may cause concern. We therefore wish to emphasise that the security of personal data and the trust of our guests remain extremely important to us. We will continue to take all reasonable measures to protect personal data and ensure secure communication with our guests.

Contact information
If you have any questions about this notification, wish to verify the authenticity of a message, or require further information about personal data protection, please contact:
Sava Hotels & Resorts Reservation Centre: info.shr@sava.si
Sava Hotels & Resorts Data Protection Officer: dpo@sava.si

Gift vouchers