Privacy Policy of Heuvelpoort Hotel B.V.
Heuvelpoort Hotel B.V. (hereinafter: Heuvelpoort), with its registered office at Heuvel 37, (5038 CP) Tilburg, with Chamber of Commerce number: 18072526, is responsible for the processing of personal data as set out in this privacy statement. We process information about individuals on a daily basis in order to provide our services. We handle your data with care and are committed to transparency regarding its processing. In this privacy statement, you can read more about how we process your data.
1 What personal data do we process, and for what purpose?
Heuvelpoort processes various categories of personal data for different purposes. Heuvelpoort processes your personal data because you use our services and/or because you provide it to us yourself.
Guests:
When you book an overnight stay, we are legally obliged to process your first name and surname, date of arrival, type of ID/travel document, date of departure and country of origin. In addition, Heuvelpoort is legally obliged to verify your identity. In this regard, we may also store a copy of your identity document, excluding your BSN number.
Furthermore, when you make a booking for an overnight stay, reserve a table at the restaurant, hire a meeting room or organise an event, you are entering into a contract with Heuvelpoort. In order to fulfil the agreement, in addition to the personal data required by law when booking an overnight stay, we also process your gender, date of birth, telephone number, email address, nationality, payment details and, where applicable, your ALL (Accor Live Limitless) membership details.
When you make a booking at our restaurant or sauna, or to hire a meeting room, we may process your first name, surname, telephone number and/or email address.
In addition, we may ask you for further details in order to provide our services, such as dietary requirements or other preferences. This data will only be processed if you have given your consent.
Cookies
Our website uses cookies. Cookies are small pieces of information stored on your computer by your browser. We use functional cookies to make the website more user-friendly for visitors. We also use analytical cookies, for example to analyse visitor statistics.
Under the law, we are permitted to store cookies on your device if they are strictly necessary for the website to function (so-called functional cookies). For all other types of cookies, we need your consent. When you visit the website, a notification will appear asking you to accept cookies, and further information will be provided about the cookies in question.
If you do not accept cookies or set your browser not to accept cookies, this may mean that you are unable to make full use of our website.
CCTV
Heuvelpoort has a legitimate interest in using CCTV in public areas, where necessary, to secure its premises and protect its guests and staff. Through CCTV footage and audio recordings, Heuvelpoort gains an insight into people’s activities.
Heuvelpoort does not make decisions based on automated processing regarding matters that may have (significant) consequences for individuals. CCTV footage is automatically deleted after three weeks, unless it has recorded an incident that is still under investigation.
2 Partners
Heuvelpoort does not share your data with third parties, except in the following circumstances:
- where this is necessary for the performance of the contract. For example, we use a third party to process (online) payments, as well as subcontractors, our franchisor and suppliers.
- when third parties process personal data on our instructions and in accordance with our policy. Examples include our IT suppliers and IT system administrators. Heuvelpoort has entered into a data processing agreement with these parties to ensure the same level of security and confidentiality for your data. Heuvelpoort remains responsible for these processing operations.
- where, on the basis of a legal obligation, it is necessary for Heuvelpoort to share data. Examples include fraud investigations, national statistical surveys, tax inspectors, and local authorities in connection with tourist tax.
- where this is stated at the time you provide us with your personal data.
Some of these partners process personal data outside the European Economic Area. Personal data will only be transferred to a country outside the European Economic Area if the legal requirements are met.
3 How long do we keep your data?
Heuvelpoort does not retain your personal data for any longer than is strictly necessary to fulfil the purposes for which your data is collected. Most data is retained in accordance with a statutory retention period. Examples include the personal data contained in our financial records, for which the statutory retention period of 7 years applies.
When you make a restaurant booking via our online booking system, your booking is automatically deleted after two years. However, a copy of your ID is destroyed immediately once you have checked out.
If you have any questions about retention periods, please do not hesitate to contact us.
4 Exercising rights
You have the right to access, correct or delete your personal data. You also have the right to withdraw any consent you may have given for the processing of your personal data, or to object to the processing of your personal data by Heuvelpoort, and you have the right to data portability. This means that you can submit a request to us to send the personal data we hold about you in a computer file to you or to another organisation specified by you. You can send a request to access, rectify or erase your personal data, a request for data portability, or a request to withdraw your consent or object to the processing of your personal data to privacy@mercure-tilburg.nl
We will respond to your enquiry as soon as possible. Heuvelpoort would also like to point out that you have the option of lodging a complaint with the national supervisory authority, the Dutch Data Protection Authority. You can do so via the following link: https://autoriteitpersoonsgegevens.nl/nl/contact-met-de-autoriteit-persoonsgegevens/tip-on
5 Security
Heuvelpoort takes the protection of your data seriously and takes appropriate measures to prevent misuse, loss, unauthorised access, unauthorised disclosure and unauthorised alteration. For example, our booking systems, payment system and terminals are PCI-compliant, and our staff undergo PCI training. If you feel that your data is not properly secured or there are indications of misuse, please contact us at privacy@heuvelpoort.n
6 Miscellaneous
This privacy statement complies with the General Data Protection Regulation. We reserve the right to update this privacy statement from time to time. The latest version will be published on our website. We therefore recommend that you review the privacy statement regularly.
7 Contact
If you have any questions about the content of this privacy notice, please contact us at privacy@heuvelpoort.nl