Data Privacy Policy

Our internal governance position on personal data. If you are a customer, a guest of a customer, or a visitor to this site, the detail you want is in the public Privacy Policy.

Awaiting legal review. The structure below is agreed. The clauses under each heading are to be drafted and approved by counsel before this page is published.

Owner: Compliance Version: Draft Applies to: All staff and processing activities
01

Purpose and scope

Why this policy exists alongside the public Privacy Policy, and which activities it governs internally.

02

Our role: controller and processor

Where we act as controller of our own data and where we process hotel and guest data on our customers’ instructions.

03

Principles we apply

Lawfulness, purpose limitation, minimization, accuracy, retention limits and accountability, in our own operating terms.

04

Lawful basis and instructions

How processing is authorized, and the requirement to act only on documented customer instruction.

05

Data subject rights

How requests reaching us are routed, including those that must be passed to the hotel as controller.

06

Retention and deletion

How long categories of data are held, and what happens at the end of a customer contract.

07

Cross-border transfers

Our approach where data moves between the markets we operate in, and the safeguards applied.

08

Subprocessors

How subprocessors are assessed and approved, and how customers are informed of changes.

09

Breach notification

Internal escalation, and the timelines for notifying customers and regulators.

10

Training and accountability

Who is trained, what records are kept, and how compliance is evidenced.

Looking for the public Privacy Policy?

What we collect, why, and the rights you have over it are set out in the Privacy Policy.

Data protection inquiries can be sent to [email protected].