Hotel Coia de Vigo ****
Privacy Policy and Data
Privacy and data policy
Privacy and personal data policy: applicable to users of this hotel business when making a booking
Data Controller (us): the hospitality business that will provide you, the user, with the requested service. Our identification and contact details are available on the website you used to make your booking / to send us your enquiries. They will also appear on the invoice we will send you.
Data Compliance Officer: does not apply to Data Controllers’ activities.
User: you, who completed the booking form or any other documentation related to it.
Purpose: The purpose of processing the data provided through this form is to manage the bookings made by you, the user, and/or to respond to the questions/requests you raised.
Legal basis:
– Either the need to perform our contract with you, the user / the need to take steps at your request before entering into a contract.
– Or your consent, the user, by ticking the acceptance box of the Terms and conditions of which this Privacy and personal data policy is an integral part.
- Duration: We will store the data provided by you, the user, for as long as necessary for the management of the booking you made, as well as the accommodation services you requested. Once the management is completed, your data will be retained for six (6) months. If you agree to receive marketing and/or commercial information, your data will be stored until you revoke your consent.
- Processor: we contract our partner Guestcentric Group ( www.guestcentric.com ) to operate the booking engine for our business. Guestcentric acts under our authority and we have signed a contract with the Guestcentric Group for the provision of its services. We have instructed Guestcentric Group in writing on how the processing should be carried out.
- Data other than from the user: when you, the user, provide us with personal data belonging to a data subject other than yourself, you are responsible for such acts, as well as for obtaining the respective consent from such data subjects for the provision of their data.
- Data transfer: we will not transfer personal data to a third country outside the EEA (European Economic Area).
- Data subjects’ rights: data subjects may exercise their rights of access, rectification, cancellation and objection by sending an email or by post to the contact details on our booking website and on our invoices.
- Supervisory authority: if a data subject considers their rights to be affected, they may also refer the matter to the competent supervisory authority of the Member State concerned. For more information: https://ec.europa.eu/info/law/law-topic/data-protection/data-protection-eu_en