Privacy Notice

Effective Date: 10.09.2024.

At Hotel Brattia, we are committed to protecting and respecting your privacy. This policy outlines how we collect, use, and safeguard your personal data in compliance with the General Data Protection Regulation (GDPR) (EU Regulation 2016/679). Please take the time to read this policy carefully.

1. Data Controller

Hotel Brattia is the data controller responsible for your personal data. If you have any questions regarding this policy or how we handle your data, please contact us at:

2. Types of Personal Data We Collect

We collect and process personal data for the following purposes:

  • Personal Information: Name, email address, phone number, postal address, and identification details (e.g., passport information).
  • Booking Details: Reservation dates, room preferences, and related information.
  • Payment Information: Credit card details, billing addresses, and other financial information necessary for processing transactions.
  • Communication Data: Records of communication with us via email, phone, or other means.
  • Website Usage: IP addresses, browser types, and cookies when interacting with our website.

3. How We Use Your Data

We process your personal data for the following purposes:

  • Reservation Management: To process bookings, check-ins, and check-outs.
  • Payment Processing: To handle payments and ensure transactions are secure.
  • Customer Service: To respond to inquiries, requests, and provide personalized services.
  • Marketing and Promotions: With your consent, we may send you updates, offers, and news about Hotel Brattia.
  • Legal Obligations: To comply with tax, regulatory, and other legal obligations.

4. Legal Basis for Processing Personal Data

We process your personal data based on the following legal grounds:

  • Consent: Where you have given your explicit consent (e.g., for marketing emails).
  • Contractual Necessity: For the performance of a contract, such as your booking.
  • Legal Obligation: Where processing is required by law (e.g., tax or record-keeping requirements).
  • Legitimate Interest: For the purposes of improving our services, safeguarding our operations, and preventing fraud.

5. Your Rights Under GDPR

As a data subject, you have the following rights under GDPR:

  • Right to Access: You can request access to the personal data we hold about you.
  • Right to Rectification: You can request corrections to your personal data if it is inaccurate.
  • Right to Erasure: You can request the deletion of your personal data where there is no legal reason for us to retain it.
  • Right to Restrict Processing: You can request that we limit how we use your data in certain circumstances.
  • Right to Data Portability: You can request a copy of your personal data in a machine-readable format.
  • Right to Object: You can object to processing your personal data where we rely on legitimate interests.
  • Right to Withdraw Consent: If we process your data based on consent, you have the right to withdraw it at any time.

To exercise these rights, please contact us using the details provided above.

6. Data Retention

We retain personal data for as long as necessary to fulfill the purposes outlined in this policy or as required by law. Booking and payment records may be retained for tax and legal purposes for up to [Insert Duration].

7. Sharing Your Data

We do not sell your personal data to third parties. However, we may share your data with:

  • Service Providers: Third-party vendors assisting with payments, booking systems, or customer service.
  • Legal Authorities: To comply with legal obligations or in response to valid legal requests.
  • Business Transfers: In the event of a merger, sale, or acquisition of Hotel Brattia.

8. Security of Your Data

We implement appropriate technical and organizational security measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction. This includes encryption, secure servers, and restricted access.

9. Cookies

Our website uses cookies to improve functionality and user experience. You can manage your cookie preferences through your browser settings. For more information on our use of cookies, please refer to our Cookie Policy.

10. International Data Transfers

If we transfer your personal data outside the European Economic Area (EEA), we will ensure adequate protection measures are in place, such as standard contractual clauses, to safeguard your data.

11. Changes to This Policy

We may update this GDPR Privacy Policy from time to time. Any changes will be posted on our website and become effective immediately upon posting. Please review this policy regularly to stay informed of updates.

12. Complaints

If you believe that we have not processed your personal data in accordance with GDPR, you have the right to lodge a complaint with your local data protection authority.