PERSONAL DATA RELAIS & CHÂTEAUX PRIVACY POLICY
This Privacy Policy informs you of the origin and use of the information collected when you consult our website www.relaischateaux.com and its affiliated websites except for websites having specific privacy policies (hereinafter the "Website"), our mobile application and, more generally, within the framework of the relationship you may have with our company, including through social media websites (hereinafter the "Processing"). It is compliant with applicable French and European regulations on personal data protection. Relais & Châteaux reserves the right to amend this Policy at any time and advises you to consult it on a regular basis. For your part, we ask you to ensure that all the information you provide to Relais & Châteaux and/or the Properties is true, accurate and up to date. If you are required to provide access to information concerning third parties (for example persons staying with you), you guarantee that you: - have only provided access to strictly necessary information, - have ensured that these persons are informed thereof and have not objected, or, when consent is required, that you have obtained such consent, - will provide them with a copy of this Privacy Policy, in which the use of the term "you" applies both to you and the third parties in question.
1. DEFINITIONS
Capitalized terms and phrases, whether they are used in the singular or plural form, shall have the meaning indicated when they are first used either in this Policy or in our Booking Terms and Conditions accessible here https://static.relaischateaux.com/neo/legal/cgr_yield_en.pdf or in our Terms and Conditions of Sale and Use of Gift Offers accessible https://static.relaischateaux.com/neo/legal/comments_policy_fr.pdf, or our Terms and Conditions of Account Creation accessible here https://static.relaischateaux.com/neo/legal/cgu_hosp_en.pdf or lastly in Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data ("GDPR").
2. DATA CONTROLLER
We inform you that your Personal Data undergo Processing by Relais & Châteaux Entreprise, whose registered office is at 58-60 rue de Prony, 75017 Paris (hereinafter "Relais & Châteaux" or "We/Us"). When this Processing is done in the framework of the Guest Recognition Program, it is done jointly with Relais & Châteaux by the Properties in which you may stay, the list of which is available at https://www.relaischateaux.com/us/site-map/etablissements. The Properties and Relais & Châteaux have defined their respective obligations in this context by means of an agreement, in accordance with Article 26 of the GDPR. This agreement provides that Relais & Châteaux plays a predominant role in defining the main purposes, Processing means, storage 2 periods and applicable security measures. Regarding the exercise of your rights in accordance with Article 7 below, you may send your requests to Relais & Châteaux or the relevant Property, it being specified that, to improve efficiency, Relais & Châteaux alone shall take care of any update of your Personal Data on the shared tools.
3. PERSONAL DATA COLLECTED
You may be asked to provide your Personal Data when you browse the Website, use the mobile application or are in contact with Us. The mandatory or optional nature of the requested information is indicated with an asterisk when data are collected. Requested information that is marked with an asterisk is necessary to process your requests or Booking or to meet a regulatory obligation. Other information is generally designed to learn more about you or to improve the services offered to you. It is therefore optional. In addition, some Personal Data may be collected indirectly, particularly from the Properties. Relais & Châteaux particularly collects and Processes identification data (e.g. your last name and given name) and family and personal contact data (e.g. your address, phone number and email address), economic and financial data (such as your bank card number), data concerning your tastes, and your preferences and habits as regards your stays, marketing data, connection data (e.g. your IP address, your browsing data) and, more generally, data relating to the reason why you are in contact with us (e.g. data concerning your Bookings, Orders, requests for information, opinions, complaints). Relais & Châteaux does not intentionally collect sensitive data, such as information concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or details concerning your health or sexual life or preferences and asks you not to provide this kind of information.
4. PURPOSES OF COLLECTING YOUR PERSONAL DATA AND STORAGE PERIODS
➢ If you do not have a Guest Recognition Account Purpose Legal Basis/Bases Storage Period ▪ To manage your Bookings made on a non-professional basis Performance of a contract to which the data subject is a party or performance of pre-contractual measures taken at their request 3 years after the date of your stay or Order, then archived for seven years before deletion ▪ To manage your Orders for Gift Offers made on a nonprofessional basis ▪ To manage your Account (Standard Account) opened on a non-professional basis 3 years after the last connection to the Standard Account or after your last contact with Us ▪ To improve and customize Relais & Châteaux services Legitimate interests of Relais & Châteaux (improve our services and prospect) If you subscribe in the context of a Booking or Order: 3 years after your last contact with Us If you just subscribe to a newsletter: as long as you do not ask to unsubscribe ▪ To manage your subscription to newsletters ▪ To manage business development operations 3 ▪ To develop business statistics and statistical reports Legitimate interests of Relais & Châteaux (improve our services) 10 years after the date of your stay or Order. ▪ To manage, monitor and improve the guest relationship, assess quality and satisfaction (particularly pre- and post-Booking questionnaires) Performance of a contract to which the data subject is a party Legitimate interests of Relais & Châteaux (improve our services) 2 years after your last contact with Us or one of our Properties. 2 years after that last contact, the entire questionnaire is anonymized. ▪ To manage any litigation and unpaid amounts Performance of a contract to which the data subject is a party Legitimate interests of Relais & Châteaux (defend rights in court) For the duration of proceedings (until all remedies have expired) Invoices are stored for 10 years. ▪ To manage your rights in respect of your Personal Data Meeting the legal obligations of Relais & Châteaux 5 years after processing your request. ➢ If you have a Guest Recognition Account Subscribing to the Guest Recognition Program and opening a related Account aim at enabling you to be recognized when you stay at one of the Hotel Properties member of the Relais & Châteaux Association, to benefit from personalized services matching your expectations by sharing with them you stay preferences, but also to enable you to consult the history of your bookings and orders without time limitation. That is why, in the framework of your subscription to this program, We keep the major part of your Personal Data for all the duration of your membership, in accordance with the terms described below. Purpose Legal Basis/Bases Storage Period ▪ To manage your Bookings made on a non-professional basis Performance of a contract to which the data subject is a party or performance of pre-contractual measures taken at their request Throughout the term of membership and 30 days after its termination ▪ To manage your Orders for Gift Offers made on a non-professional basis ▪ To manage your Account opened on a non-professional basis / To perform and monitor the Guest Recognition Program ▪ To improve and customize Relais & Châteaux services Legitimate interests of Relais & Châteaux (improve our services and prospect) Throughout the term of membership and 30 days after its termination ▪ To manage your subscription to newsletters ▪ To manage business development operations ▪ To develop business statistics and statistical reports Legitimate interests of Relais & Châteaux (improve our services) 10 years after the date of your stay or Order. ▪ To manage, monitor and improve the guest relationship, assess quality and satisfaction (particularly pre- and post-Booking questionnaires) Performance of a contract to which the data subject is a party Legitimate interests of Relais & Châteaux (improve our services) 2 years after your last contact with Us or one of our Properties. 2 years after that last contact, the entire questionnaire is anonymized. 4 ▪ To manage any litigation and unpaid amounts Performance of a contract to which the data subject is a party Legitimate interests of Relais & Châteaux (defend rights in court) For the duration of proceedings (until all remedies have expired) Invoices are stored for ten years. ▪ To manage your rights in respect of your Personal Data Meeting the legal obligations of Relais & Châteaux 5 years after processing your request. The Personal Data Processed in the framework of the Guest Recognition Program will only be accessible to the Properties for the period necessary to prepare and monitor Bookings, i.e. up to one month maximum before your stay and one month after your departure. ➢ Data collected via cookies when you browse the Website or the mobile application Cookie Issuer Purpose Legal basis Storage period IDE googleadwordsremarketing googleadwordsconversion Advertising service Consent 1 year MUID bing Advertising service 1 year MUIDB bing Advertising service 1 year _uetsid bing Advertising service 1 day _uetvid bing Advertising service 16 days eb-profile earlybirds Advertising service 12 months eb-lastactivity-hash earlybirds Advertising service 12 months anj gamned Advertising service 180 days uuid2 gamned Advertising service 180 days IDSYNC gamned Advertising service 180 days APID gamned Advertising service 180 days B gamned Advertising service 180 days apx_conv1 gamned Advertising service 180 days 5 apx_conv1020997 gamned Advertising service 180 days apx_conv1021500 gamned Advertising service 180 days apx_seg1 gamned Advertising service 180 days apx_seg14205345 gamned Advertising service 180 days apx_seg14206188 gamned Advertising service 180 days fr facebook Social media 3 months _fbp facebook Social media 3 months _hjid hotjar Web analytics 1 year _hjIncludedInSample hotjar Web analytics Session _hjAbsoluteSessionInProgress hotjar Web analytics 30 minutes _hjTLDTest hotjar Web analytics Session _hjIncludedInSessionSample hotjar Web analytics 30 minutes etuix eulerian Web analytics 25 months ➢ General In any event, Personal Data are stored in an active database for a period not exceeding the period necessary to achieve the purposes for which they are collected, and particularly for the periods indicated in the table above. After that period, certain Personal Data will then be archived with restricted access for a period not exceeding statutory limitation periods or applicable archiving obligations, and then destroyed.
5. SHARING YOUR PERSONAL DATA
Your Personal Data collected in the framework of the Processing may be sent: − Internally, to the authorized departments of Relais & Châteaux; and − within the Relais & Châteaux group to the authorized departments of the Relais & Châteaux Association and its subsidiaries; − to the Relais & Châteaux Association Member Properties with which you make a Booking and/or that you may visit. Your Personal Data may also be transferred to Third Parties which may use them for their own needs (and particularly to authorized agents for the purpose of handling a dispute such as attorneys, process servers, etc. and to certain social media such as Facebook when you use our Website or mobile application in connection with these social media). Similarly, if any company in the group to which Relais & Châteaux belongs or all or part of its assets are acquired by a third party, your Personal Data may be made accessible to anyone involved in the preparation and completion of the transaction and included in the assets sold. 6 If you decide to use the 3X Oney financing solution offered by Oney Bank to buy one or several Gift Boxes, the Personal Data linked to your Order will als o be shared with Oney Bank. Oney Bank will then process these Personal Data as Data Controller, for its own purposes which include, in particular, the pre-filling of the requested credit subscription form, the analysis of applications in order to decide whether or not to grant the financing solutions, credit management, as well as the recovery of funds and the fight against fraud. Finally, your Personal Data will be transferred to Processors of Relais & Châteaux within the meaning of regulations; they are not authorized to use them for their own account.
6. INTERNATIONAL TRANSFERS
Your Personal Data may be made accessible to some of our Processors within the meaning of regulations, some of which may be located outside Europe, in countries recognized by the European authorities as providing an adequate level of Personal Data protection, but also in countries that do not benefit from such recognition. In order to ensure adequate protection of Data Subjects' privacy, Appropriate Safeguards have been established to govern Transfers. The countries concerned by these Transfers and the Appropriate Safeguards are summarized in the table below: Country European Commission adequacy decision Appropriate Safeguards Uruguay Yes Argentina Yes USA No Standard contractual clauses Japan No Standard contractual clauses Mauritius No Standard contractual clauses Australia No Standard contractual clauses India No Standard contractual clauses Brazil No Standard contractual clauses Mexico No Standard contractual clauses China No Standard contractual clauses Your Personal Data may also be made accessible to subsidiaries of the Relais & Châteaux Association located in Switzerland, the UK and the USA, and to certain Relais & Châteaux Properties (the list of which is available at https://www.relaischateaux.com/us/sitemap/etablissements) that may be located outside Europe, in countries recognized by the European authorities as providing an adequate level of personal data protection, but also in countries not benefitting from such recognition. The achievement of certain purposes described in Article 4 above, including in particular the management of your Bookings or the performance and monitoring of the Guest Recognition Program, therefore requires Personal Data Transfers outside Europe and renders them lawful. However, to guarantee an even higher level of protection of Data Subjects' privacy, each Property located outside Europe in a country not benefitting from the abovementioned recognition has signed with Relais & Châteaux the standard contractual clauses issued by the European Commission, to govern their relationship and ensure a high level of Personal Data protection. For more information about the Appropriate Safeguards governing these Transfers, you may contact the Relais & Châteaux Data Protection Officer at: dpo@relaischateaux.com.
7. YOUR RIGHTS
We remind you that you have a right of access to and rectification of incorrect data concerning you and, in the cases provided for by regulations, a right to object and a right of erasure of some of your Personal Data, a right to restrict their use or to request their portability for transfer to a third party, and a right to withdraw your consent, if We base processing on your consent, and also, if you reside in France, the right to define directives for the post-mortem processing of your Personal Data. To exercise any of these rights, please write to the Relais & Châteaux Data Protection Officer at: Relais & Châteaux Entreprise DPO 58-60, rue de Prony 75017 Paris France or send an email to: dpo@relaischateaux.com If We are unable to identify you with certainty, for security reasons, you must send a photocopy of an ID document with your request. You will be sent a reply within one month of your request being received, subject to any longer period in accordance with the provisions of the GDPR. Furthermore, you are reminded that Relais & Châteaux may, in accordance with regulations, refuse to grant certain requests concerning some of these rights (particularly the right of erasure), for legitimate reasons such as the need to defend rights in court or a legal obligation to retain certain data. You may also lodge a complaint with the Commission Nationale Informatique et Libertés (CNIL), the French data protection authority. We inform you that if you do not wish to be canvassed by telephone, you may register free of charge on the Bloctel Do Not Call list.