Data Privacy Policy
Our internal governance position on personal data. If you are a customer, a guest of a customer, or a visitor to this site, the detail you want is in the public Privacy Policy.
Awaiting legal review. The structure below is agreed. The clauses under each heading are to be drafted and approved by counsel before this page is published.
Purpose and scope
Why this policy exists alongside the public Privacy Policy, and which activities it governs internally.
Our role: controller and processor
Where we act as controller of our own data and where we process hotel and guest data on our customers’ instructions.
Principles we apply
Lawfulness, purpose limitation, minimization, accuracy, retention limits and accountability, in our own operating terms.
Lawful basis and instructions
How processing is authorized, and the requirement to act only on documented customer instruction.
Data subject rights
How requests reaching us are routed, including those that must be passed to the hotel as controller.
Retention and deletion
How long categories of data are held, and what happens at the end of a customer contract.
Cross-border transfers
Our approach where data moves between the markets we operate in, and the safeguards applied.
Subprocessors
How subprocessors are assessed and approved, and how customers are informed of changes.
Breach notification
Internal escalation, and the timelines for notifying customers and regulators.
Training and accountability
Who is trained, what records are kept, and how compliance is evidenced.
Looking for the public Privacy Policy?
What we collect, why, and the rights you have over it are set out in the Privacy Policy.
Data protection inquiries can be sent to [email protected].