Privacy Policy
Dear Customer,
This information on personal data and privacy protection applies to you and your personal data because you are our customer. Our company acts as the data controller when processing your personal data. We would like to explain how we will use personal data obtained from you or third parties during the duration of your contractual relationship with us or after its termination. This document also serves to fulfill our obligation to provide information under Article 13 of Regulation (EU) No. 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons concerning the processing of personal data and the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation), and Act No. 18/2018 Coll., from 29 November 2017 on the protection of personal data and the amendment and supplementation of certain laws.
1. Types of Personal Data We Process
We process the following data:
- Personal contact details. For example, your first name, last name, permanent address, mailing address, email address, contact phone number, ID/passport number, birth number, academic title, and date of birth.
- Work contact details. For example, the company address you represent, work email, and phone number.
- Contractual details. Such as the content of the contract concluded with our company, including all its amendments, scope of services provided, type of end device, and its designation.
- Family members and relatives' information for the purpose of enrolling in discounted customer groups.
- Payment information such as bank account number and the amount of charged services.
- Correspondence and communication data such as email correspondence, internet data transmissions, and IP address.
- Access rights. Your access rights to various applications within the company's IT infrastructure.
- Security-related information such as your access card number, information on whether you are in the building, and records from the camera system.
2. Purposes and Objectives of Data Processing
We process your data for the following purposes:
- Providing accommodation services. We must keep records of accommodated guests under special regulations. The legal basis is the fulfillment of the operator's legal obligation.
- Loyalty program. Customer registration and sending news about the latest offers and services associated with membership in our VIP program. The legal basis is the contract between us and the legitimate interest of the operator.
- Direct marketing. We are focused on improving your stays with us and developing our services by creating tailor-made offers. The legal basis is the operator's legitimate interest.
- Taxes and accounting. To fulfill tax law obligations and other financial regulations, we are required to process certain personal data. The legal basis is the fulfillment of legal obligations.
- Operational and network security. We monitor the functionality, security, and stability of our network in which you are a participant. The legal basis is the fulfillment of legal obligations and the legitimate interest of the operator. We also have a camera system installed to protect you; the legal basis is the legitimate interest of the operator.
- Dispute resolution and investigation of violations. We may process personal data to resolve disputes, complaints, or legal proceedings or to investigate suspected violations. The legal basis is the fulfillment of legal obligations and the legitimate interest of the operator.
- Legal compliance. We may need to process your personal data to comply with laws (e.g., checking your name against designated party lists and adhering to anti-money laundering laws) or to comply with a court order.
- Marketing consents. Other data may be used but only based on specific consents obtained from you in advance. The legal basis is your consent.
- Customer administration. We keep records of all our customers and their services. Based on the analysis of our records, we make strategic decisions about offers for our customers. The legal basis is the contract between us and the legitimate interest of the operator.
3. Who Has Access to Your Data
The operator may share your data with third parties under the following circumstances: We may share your personal data with other third parties acting on our behalf, such as service providers. In such cases, these third parties may use your personal data only for the purposes described above and only following our instructions. Contractually, they are required to adhere to security instructions stipulated by law. Our employees have access to personal data only if necessary for the purposes mentioned above and only if the employee is bound by confidentiality obligations. If required by law or court order, we may share your personal data with, for example, our suppliers or clients, tax authorities, social security offices, law enforcement, or other government authorities.
4. Location of Your Personal Data
Your personal data will be located exclusively within the European Union and the European Economic Area.
5. Retention of Personal Data
We retain your personal data for a limited time and will delete it once it is no longer necessary for processing purposes. In most cases, this means we will retain your data for the duration of your relationship with us. Where possible, we will delete the data while you are still in a relationship with us, as soon as it is no longer necessary. In any case, we will delete your personal records no later than after the statutory periods following the end of the contractual relationship unless the legislation requires their retention. We may process your personal data for a more extended period after the relationship ends in case of ongoing legal disputes or if you have given us permission to retain your personal data long-term.
6. Legal Basis for Processing Your Data
In most cases, we process your personal data based on the necessity of processing for our legitimate interest, contractual basis, or your consent as the data subject. You may withdraw your consent at any time by submitting verifiable notification on our website. In many cases, we must also process your personal data based on a legal obligation under specific regulations. In the case of processing based on consent, you always have the option to withdraw your consent.
7. Rights of Data Subjects
It is essential to understand that these are your personal data we process, and we want you to be aware of this. Even though we do not need your permission to process your personal data when required by law or associated with our contract, you have many rights regarding the processing of your personal data. The text above answers most of your questions.
Your Rights
- Right of access - You may request information on how we process your personal data, including details on:
- Why we process your personal data
- Categories of personal data we process
- With whom we share your personal data
- How long we retain your personal data or the criteria used to determine this period
- Your rights
- The origin of your personal data (if we did not obtain it from you)
- If processing involves automated decision-making (so-called profiling)
- If your personal data has been transferred outside the EEA, how we ensure its protection.
All the above information is available in this document. You may also request a copy of the personal data we process about you. However, additional copies will be subject to a fee.
-
Right to rectification - It is important for us to have accurate information about you, so we ask you to inform us if any of your personal data is incorrect, for example, if you have changed your name or moved.
-
Right to erasure - If we process your personal data unlawfully, such as processing your personal data longer than necessary or without reason, you may request the deletion of these data.
-
Right to restriction - From the moment you request the correction of your personal data or object to processing and until we can investigate the issue or confirm the accuracy of your personal data (or modify it per your instructions), you are entitled to restricted processing. This means that we may only process your personal data with your consent, if necessary concerning legal claims, to protect someone else's rights, or if there is a significant public interest in processing.
-
Right to object - If you believe we have no right to process your personal data, you may object to our processing. In such cases, we may continue processing only if we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms. However, we may always process your data if necessary to establish, exercise, or defend legal claims.
-
Right to data portability - You may request your personal data that you provided us for processing on the basis of consent or for contract fulfillment, to be provided in a structured, commonly used, and machine-readable format. You also have the right to request the transfer of this information to another data controller.
8. Withdrawal of Consent
You have the right to withdraw your consent, and we will subsequently stop processing activities based on this legal ground. We will also inform other parties to whom we may have provided your personal data of your request(s).
If you have any doubts, you have the right to file a petition to initiate proceedings under § 100 of the Data Protection Act with the competent supervisory authority, for example, via www.dataprotection.gov.sk.
How Can I Complain About the Use of My Data or Exercise My Rights?
If you wish to complain about how we process your personal data, including your above rights, you may contact us at hotelboboty@vratna.sk, and your suggestions and requests will be reviewed. If you are not satisfied with our response or believe we process your data unfairly or unlawfully, you may complain to the competent supervisory authority, which is the Office for Personal Data Protection (ÚOOÚ). For more information on ÚOOÚ and their complaint process, please see www.dataprotection.gov.sk.
8. Contact Details
If you have any questions regarding the processing of your personal data, please feel free to contact us at:
Hotel Boboty
Vrátna Valley 582, Terchová
Email: hotelboboty@vratna.sk
Phone: +421 902 969 205