PRIVACY STATEMENT Revision Date: 25/05/2018
Royal Blue Resort & Spa recognizes that privacy is important to you and wants you to be familiar with how we collect, use and disclose data.
“Personal Data” are data that identify you as an individual or relate to an identifiable individual.
This Privacy Statement describes the privacy practices of Royal Blue Resort & Spa and is compliant with the General Data Protection Regulation EU 2016/679 as well as with the National Data Protection legislation. It explains what information we collect about you when you visit our site and/or when you make a reservation with us and how we handle your information to ensure that your rights are always respected.
Who we are
Royal Blue Resort & Spa is a 5 star Luxury Hotel established in Rethymno, Crete, Greece.
The Rοyal Blue
Panormo Geropotamou, GR 74057 Rethymno, Crete, Greece. Tel: +30 28340 55000 Fax: +30 2810 334037
1. What personal data we collect
When you directly register to make a reservation or use our services and upon your check-in in one of our hotels we may ask you to provide certain personal information including your full name, identity card, passport, physical and email address, credit card number, telephone number, registration, payment details etc.
2. Children’s data
Our website is not intended for children under 16 years of age, and we do not knowingly collect information from children to sell or promote our services.
3. Legal basis for processing your personal data
We process your personal data in accordance with the EU Regulations for one or more of the following reasons:
A. Necessary for the performance of a contract
- To carry out our obligations with respect to any contractual agreements between us with respect to information and services that you may request from us,
- To process a hotel reservation,
- To process your check-in
- To process your payment
- To take your reservation for events
- To facilitate your participation in tours
B. Necessary for Royal Blue Resort & Spa to comply with a legal obligation
- To fulfil our tax, accounting and reporting obligations.
C. To serve our (and third party) legitimate business interests,
legitimate interest is when we have a business or commercial reason to use your information. But even then, such use is consistent with the fundamental rights of individuals, for example:
- To provide you with effective customer service and support,
- To respond to your requests,
- To improve the security and usability of our website and services,
- To perform customer satisfaction surveys,
- To execute business transactions with you,
- To keep you updated on our new services and offers,
- To operate CCTV systems to prevent illegal actions, to protect you and our staff and our property
D. You have given us your consent
Subject to a valid consent you have freely provided the lawfulness of such processing is based on that consent.
4. How we share your data
In the course of the performance of our contractual and legal obligations your personal data may be provided to various service providers and suppliers. Those service providers and suppliers are bound by Data Processing Agreements, and they are obliged to safeguard confidentiality and data protection according to the data protection regulation.
Such service providers and suppliers may be:
- External legal consultants
- Information technology companies
- Financial and business advisors,
- Cloud providers
- External auditors and accountants
- Marketing Companies
- Outsourcing services companies
- Law enforcement agencies
- Third parties you have used to contact us
- Card payment companies
- Travel agencies
5. Transfers of Data outside the European Economic Area (“EEA”).
Your personal data may be transferred to third countries in order to fulfil a legal or contractual obligation or because you have given us your consent. Processors in third countries are obligated to comply with the European data protection regulations and to provide appropriate safeguards in relation to the transfer of your data in accordance with GDPR Article 46.
6. Data Retention
We will process and store your Personal Data for the duration of our relationship with you, and as long as necessary to fulfill our contractual and legal obligations.
We will delete your data:
- When it is no longer necessary for the purposes for which that information was collected and processed;
- Upon your request or objection, provided there are no overriding legal grounds requiring Royal Blue Resort & Spa to maintain that information;
- When necessary to comply with our legal obligations; and
- If our collection of information was based on your consent, upon the withdrawal of your consent.
7. Automated decision and Profiling
In executing our business activities, we do not use any automated decision-making. We may from time to time process some aspects of your data automatically, in order to enter into a business relationship with you
8. How we use your personal data for marketing activities
- We may process your personal data to tell you about products, services and offers that may be of interest to you or your business. The personal data that we process for this purpose consists of information you provide to us and data we collect when you use our products.
- We can only use your personal data to promote our products and services to you if we have your consent to do so or if we consider that it is in our legitimate interest to do so.
- You have the right to object at any time to the processing of your personal data for marketing purposes, which includes profiling.
9. Your data protection rights
You have the following rights in terms of your personal data:
- The right to request access to your Personal Data, you can ask to receive a copy of your data and to check if they are lawfully processed.
- The right to have your Personal Data corrected or erased;
- The right to object to or restrict the processing of your Personal Data, for example where such information is not accurate or no longer serve the purpose they were collected,
- The right to data portability, i.e. to receive a copy of your data in electronic form or to have your Personal Data transferred from us to another party;
- The right to object automated decision-making or profiling based on your Personal Data;
- The right to withdraw your consent, any withdrawal of consent shall not affect the lawfulness of processing based on consent before it was withdrawn by you.
- The right
10. Right to lodge a complaint
The right to lodge a complaint with a supervisory authority (www.dpa.gr). If you have exercised any of your data protection rights and still feel that your concerns about how we use your personal data have not been adequately addressed by us.
Our website uses small files known as cookies to enhance user experience and for functionality reasons
12. Changes to This Privacy Statement
We reserve the right to modify this Privacy Statement and related business practices at any time. We will notify you appropriately when we make changes to this privacy statement and we will amend the revision date.
13. CONTACT US
If you have any questions about this Privacy Polity or how Royal Blue Resort & Spa processes your personal information, or if you wish to either provide a compliment or a complaint, please contact us by email at email@example.com
- Remember your language and other preferences;
- Ensure you obtain all requested information;
- Provide a safe and secure service for online transactions;
- Track your response to advertisements and website or app content for analysis and the number of times we send you the same advertisement;
- Measure how many people use the Site, and how they use it, so that we may keep it running quickly and efficiently
Below we explain the different types of Cookies that may be used on the Site.
Essential Cookies. Essential Cookies are necessary for the Site to work, and enable you to move around it and use its services and features. Disabling these Cookies may make the services and features unavailable.
Functional Cookies. We use Functional Cookies to save your settings on the Site-settings such as your language preference, or booking information you have previously used when booking a hotel with us.
Session Cookies. These types of Cookies are stored only temporarily during a browsing session, and are deleted from your device when you close the browser. We use Session Cookies to support the functionality of the Site and to understand your use of the Site-that is, which pages you visit, which links you use and how long you stay on each page.
Persistent Cookies: These types of Cookies are not deleted when you close your browser, but are saved on your device for a fixed period of time or until you delete them. Each time you visit the Site, the server that set the Cookie will recognize the persistent Cookie saved on your device. We and others use persistent Cookies to store your preferences, so that they are available for your next visit, to keep a more accurate account of how often you visit the Site, how often you return, how your use of the Site may vary over time and the effectiveness of advertising efforts.
As noted below, some Analytics Cookies and Other Technologies are used in part to facilitate advertising.
Advertising Cookies also include Social Plug-In Cookies. Social Plug-In Cookies are used to share content from the Site with members and non-members of social media networks such as Facebook, Twitter, YouTube and Pinterest. These Cookies are usually set by the social networking provider, enabling such sharing to be smooth and seamless.
Analytics Cookies collect information about your use of the Site, and enable us to improve the way it works. These Cookies give us aggregated information that we use to monitor site performance, count page visits, spot technical errors, see how users reach the Site, and measure the effectiveness of advertising (including emails we send to you).
Other Technologies may be used for the same purposes as our Cookies, to allow us and third parties to know when you visit the Site, and to understand how you interact with emails or advertisements. Through Other Technologies, non-personal information (e.g., your operating system, your browser version, and the URL you came from) or aggregate information may be obtained and used to enhance your experience and understand traffic patterns.
MANAGING COOKIES AND OTHER TECHNOLOGIES
If you want to remove or block Cookies from your device at any time, you can update your browser settings (consult your browser's "help" menu to learn how to remove or block Cookies). Royal Blue Resort & Spa is not responsible for your browser settings. You can find good and simple instructions on how to manage Cookies on the different types of web browsers at www.allaboutcookies.org.
Please be aware that rejecting Cookies may affect your ability to perform certain transactions on the Site, and our ability to recognize your browser from one visit to the next.
You can also control tracking Cookies by installing browser extensions like Ghostery: https://www.ghostery.com/products/
If you want to clean out all of the Cookies left behind by the websites you have visited, here are links where you can download programs that clean out tracking Cookies: