1.1. COLLECTION AND TREATMENT OF USER DATA
In connection with the provision of the website hosted at www.hotel-imperatriz.com ("Site"), the conclusion of any contracts (namely hotel services, catering, loyalty cards, vouchers and mobile application), the provision of information, (including the "Services") to its users ("User") and other entities related to it, the Aparthotel Imperatriz – António de Sousa, with headquarters at Rua Imperatriz Dª. Amelia, 72 - 9000-018 Funchal, registered with the Commercial Registry of Funchal under the unique registration number and VAT number 142396966 (hereinafter "Hotel Imperatriz") may require the User to make personal data available, that is, information provided by User that allow Hotel Imperatriz to identify you and / or to contact you ("Personal Information").
As a rule, Personal Data is requested when the User registers on the Site, requests a contact and / or sending newsletters, subscribes to a certain service, provides or requests information, acquires a product or establishes a contractual relationship with Hotel Imperatriz.
The Personal Data collected and processed consists essentially of information regarding the name, gender, date of birth, telephone, mobile phone, email, address, tax identification number, credit card data (collected for billing purposes only), although they may come to collect other Personal Data that may be necessary or convenient for the provision or collection of Services by the Hotel Imperatriz.
After the collection of Personal Data, Hotel Imperatriz provides the User with detailed information about the nature of the data collected and about the purpose and treatment that will be carried out with respect to Personal Data, as well as the information mentioned in clause 8.
Hotel Imperatriz also collects and manages information on the features of the hardware device and the browser / software features as well as information about the pages visited by the User within the Site. This information may include your browser type, domain name, access times and links through which the User has accessed the Site ("Usability Information"). We use this information only to improve the quality of your visit to our Site.
1.2. DATA COLLECTION CHANNELS
Hotel Imperatriz may collect data directly (i.e. directly from the User) or indirectly (i.e. through partner entities or third parties). The collection can be done through the following channels:
Direct collection: in person, by phone, by e-mail and through the Site;
Indirect collection: through partners.
2. GENERAL PRINCIPLES APPLICABLE TO THE PROCESSING OF USER DATA
In terms of general principles regarding the processing of personal data, Hotel Imperatriz undertakes to ensure that the User Data processed by you are:
• Object of a treatment in accordance with the law, fair and transparent in relation to the User;
• Collected for specific, objective and legitimate purposes and not subsequently treated in a manner contrary to these purposes;
• Adequate, justified and limited to what is necessary in relation to the purposes for which they are processed;
• Accurate and up-to-date whenever necessary, and all necessary measures are taken to ensure that inaccurate data, taking into account the purposes for which they are processed, are erased or corrected without delay;
• Preserved in a way that allows the identification of the User only for the period necessary for the purposes for which the data is processed;
• Treaties in a way that guarantees their safety, including protection against their unauthorized or illegal treatment and against their loss, destruction or unforeseen damage, and taking appropriate technical or organizational measures.
Data processing performed by Hotel Imperatriz is permitted and legal when at least one of the following situations occurs:
• You have given your consent to the processing of User Data without any doubt for one or more specific purposes;
• The processing is necessary for the execution of a contract in which the User is a party, or for pre-contractual procedures at the request of the User;
• The treatment is necessary to fulfill a legal obligation to which the Hotel Imperatriz is subject;
• Treatment is necessary for the defense of the fundamental interests of the User or another individual;
• Treatment is necessary for the legal interests pursued by Hotel Imperatriz or by third parties (except if the interests or fundamental rights and freedoms of the User that require the protection of personal data prevail).
Hotel Imperatriz undertakes to ensure that the processing of User Data is only done under the conditions listed above and with respect to the principles mentioned above.
When the User Data is processed by Hotel Imperatriz based on the User's agreement, the User has the right to withdraw his / her consent at any time. The withdrawal of the consent, however, does not compromise the legality of the treatment made by Hotel Imperatriz based on the consent previously given by the User.
The length of time during which the data is stored and stored varies according to the purpose for which the information is processed.
Effectively, there are legal requirements that require you to retain the data for a minimum period of time. Thus, and where there is no specific legal obligation, the data will be stored and kept only for the minimum period necessary for the purposes that led to their collection or subsequent processing, which in the end will be eliminated.
3. USING AND USING THE DATA PROCESSING PURPOSES
In general terms, Hotel Imperatriz uses User Data for the following purposes:
• Provision of web services and associated services (graphic design, hosting, domain registration, etc.);
• Management of contacts with the User;
• Billing and billing to the User;
• User Registration on the Site;
• To inform the User, who has requested it, of new products and services made available on the Site, special offers and campaigns, updated information on the activity of Hotel Imperatriz and, in general, for marketing purposes of Hotel Imperatriz, through any means of communication, including electronic media;
• Allow access to restricted areas of the Site, in accordance with previously established terms;
• Ensure that the Site meets User's needs by developing and publishing content that is as adapted as possible to the requests and type of User, improving the search capabilities and functionality of the Site and obtaining associated or statistical information in relation to the User's profile (analysis of consumption profiles);
• Provision of Services, and other services, such as newsletters, opinion surveys, or other information or products requested or purchased by the User;
• Hotel Imperatriz can combine an Usability Information with anonymous demographic information for the purpose of research, and may use the result of that combination to provide you with more relevant content on the Site. In certain restricted areas of the Site, Hotel Imperatriz may combine Personal Data with Usability Information to provide the User with more personalized content.
The User Data collected by Hotel Imperatriz is not shared with third parties without the consent of the User, except for the situations mentioned in the following paragraph. However, in the event that the User engages with Hotel Imperatriz services that are provided by other entities responsible for the processing of personal data, User Data may be consulted or accessed by such entities, to the extent that it is necessary for the provision of the services.
4. IMPLEMENTED TECHNICAL, ORGANIZATIONAL AND SECURITY MEASURES
In order to guarantee the security of the User Data and the maximum confidentiality, Hotel Imperatriz treats the information you have provided in an absolutely confidential way, in accordance with its internal security and confidentiality policies and procedures, which are updated periodically according to the needs , as well as with the legally established terms and conditions.
Due to the nature, scope, context and purpose of data processing, as well as the risks arising from the treatment of the rights and freedoms of the User, Hotel Imperatriz undertakes to apply, both when defining the means of treatment as well as the technical and organizational measures necessary and appropriate for the protection of User Data and compliance with legal requirements.
It also undertakes to ensure that, by default, only data that is necessary for each specific purpose of treatment is processed and that such data are not made available without human intervention to an indeterminate number of persons.
Communication between the user's device and Site Hotel Imperatriz is done through secure channels and communications using the HTTPS protocol and the SSL security standard. Nevertheless, in terms of general measures, Hotel Imperatriz adopts the following.
Awareness and training of personnel involved in data processing operations.
Mechanisms capable of ensuring the permanent confidentiality, availability and resilience of information systems.
Mechanisms to ensure the restoration of information systems and access to personal data quickly in the event of a physical or technical incident.
5. TRANSFER OF DATA OUT OF THE EUROPEAN UNION
The personal data collected and used by Hotel Imperatriz are not available to third parties established outside the European Union. If in the future this transfer takes place for the reasons mentioned above, Hotel Imperatriz undertakes to ensure that the transfer complies with applicable legal provisions, in particular as regards the determination of the suitability of such country as regards data protection and applicable requirements to such transfers.
7. RIGHT TO INFORMATION
7.1. Information provided to the User by Hotel Imperatriz (when data is collected directly from the User):
• The identity and contacts of Hotel Imperatriz, responsible for the treatment and, if applicable, of its representative;
• The contacts of the Data Protection Officer;
• The purposes of the treatment to which the personal data are intended, as well as, if applicable, the legal reasons for the treatment;
• If the processing of the data is based on the legitimate interests of Hotel Imperatriz or a third party, indication of such interests;
• Where applicable, the recipients or categories of recipients of personal data;
• If applicable, indication that personal data will be transferred to a third country or an international organization, and whether there is a compliance decision adopted by the Commission or reference to appropriate or appropriate transfer guarantees;
• Deadline for the preservation of personal data;
• The right to request from Hotel Imperatriz the permission to personal data, as well as its correction, elimination or limitation, the right to oppose the treatment and the right to access the data;
• If the processing of the data is based on the consent of the User, the right to withdraw it at any time, without compromising the legality of the treatment made based on the consent previously given;
• The right to file a complaint with the CNPD or other supervisory authority;
• Indication whether the disclosure of personal data constitutes a legal or contractual obligation, or a requirement to conclude a contract, and whether the holder is required to provide the personal data and any consequences of not providing such data;
• If applicable, the existence of automatic decisions, including the definition of profiles, and information regarding the basic concept, as well as the importance and expected consequences of such treatment for the data subject;
• In case User Data is not collected directly by Hotel Imperatriz from the User, in addition to the information referred to above, the User is also informed about the categories of personal data being processed, as well as the origin of the data and , possibly if they are from sources accessible to the public;
• In the event that Hotel Imperatriz intends to proceed to the further processing of the User Data for a purpose other than that for which the data were collected, before this treatment Hotel Imperatriz will provide the User with information about this purpose and any other information of interest, in the above.
7.2. Procedures and measures implemented to fulfill the right to information.
The information referred to in 7.1. is provided in writing (including by electronic means) by Hotel Imperatriz to the User prior to the processing of personal data in question. In accordance with applicable law, Hotel Imperatriz does not have the obligation to provide the User with the information mentioned in 7.1 when and to the extent that the User is already aware of them.
The information is provided by the Hotel Imperatriz without any cost.
8. RIGHT TO ACCESS PERSONAL DATA
Hotel Imperatriz guarantees the means by which the User can consult his Personal Data.
The User has the right to obtain from the Hotel Imperatriz the confirmation that the personal data concerning him are treated or not and, as the case may be, the right to access his personal data and the following information:
• The purposes of data processing;
• the categories of personal data in question;
• the addressees or categories of recipients to whom personal data have been or will be disclosed, in particular to recipients established in third countries or belonging to international organizations;
• The period of conservation of personal data;
• Right to request from Hotel Imperatriz the correction, elimination or limitation of the processing of personal data, or the right to prevent such processing;
• Right to file a complaint with the CNPD or other supervisory authority;
• If the data has not been collected from the User, the available information on the origin of such data;
• The existence of automated decisions, including the definition of profiles, and information on the underlying logic, as well as the importance and expected consequences of such treatment for the data subject;
• The right to be informed about the appropriate safeguards associated with the transfer of data to third countries or international organizations.
Upon request, Hotel Imperatriz will provide the User, free of charge, with a copy of the User Data that is being processed. The provision of other copies requested by the User may entail administrative costs.
9. RIGHT TO RE-FORM PERSONAL DATA
The User has the right to request, at any time, the rectification of his Personal Data and also the right to have incomplete personal data completed, including by means of an additional declaration.
In case of rectification of the data, the Hotel Imperatriz communicates to each addressee to whom the data have been forwarded to the rectification, unless such communication is considered impossible or involves a disproportionate effort for Hotel Imperatriz.
10. RIGHT TO THE DELETING OF PERSONAL DATA ("RIGHT TO BE FORGOTTEN")
The User has the right to obtain, on the part of Hotel Imperatriz, the elimination of its data when one of the following reasons applies:
• User Data is no longer required for the purpose for which it was collected or processed;
• The User withdraws the consent on which the data treatment is based and there is no other legal basis for such treatment;
• The User opposes treatment under the right of opposition and there are no prevailing legitimate interests justifying treatment;
• If User Data is treated illegally;
• If User Data must be deleted in order to comply with a legal obligation to which Hotel Imperatriz is subject;
• Under the applicable legal terms, Hotel Imperatriz is under no obligation to delete User Data to the extent that the processing proves necessary to fulfill a legal obligation to which Hotel Imperatriz is subject or for the purposes of declaration, exercise or defense of a right of the Hotel Imperatriz in a judicial proceeding.
In case of the elimination of the data, Hotel Imperatriz communicates to each recipient / entity to whom the data has been transmitted the erasure, unless such communication proves impossible or involves a disproportionate effort for Hotel Imperatriz.
When Hotel Imperatriz has made public the User Data and is obliged to delete it under the right of such elimination, Hotel Imperatriz undertakes to ensure that measures are reasonable, including of a technical nature, taking into account the available technology and the costs of its application, to inform those responsible for the effective treatment of personal data that the User has requested the deletion of the links to these personal data, as well as copies or reproductions thereof.
11. RIGHT TO LIMIT THE TREATMENT OF PERSONAL DATA
The User has the right to obtain, on the part of Hotel Imperatriz, the limitation of the processing of the User Data, if one of the following situations applies (the limitation is to insert a mark in the personal data conserved with the purpose of limiting its treatment in the future):
• If you challenge the accuracy of personal data, during a period that allows Hotel Imperatriz to verify its accuracy;
• If the treatment is unlawful and the User opposes the deletion of the data, requesting, however, the limitation of its use;
• If Hotel Imperatriz no longer requires User Data for treatment purposes, but such data is required by the User for the purposes of declaration, exercise or defense of a right in a judicial process;
• If the User has objected to the treatment, until it is verified that the legitimate reasons of Hotel Imperatriz prevail over those of the User.
When User Data is subject to limitation, they may only, with the exception of conservation, be treated with the consent of the User or for the purpose of declaring, exercising or defending a right in a judicial process, defending the rights of another natural or legal person. or for reasons of public interest legally envisaged.
The User who has obtained the limitation of the treatment of his data in the above cases will be informed by Hotel Imperatriz before the treatment limitation is annulled.
In case of limitation of the processing of the data, Hotel Imperatriz will communicate each addressee to whom the data have been transmitted to the respective limitation, unless this communication proves impossible or involves a disproportionate effort for Hotel Imperatriz.
12. RIGHT OF PORTABILITY OF PERSONAL DATA
The User has the right to receive the personal data concerning him and which he has provided to Hotel Imperatriz in a structured, current and automatic reading format and the right to transmit this data to another person responsible for the treatment if:
• The treatment is based on the consent or a contract to which the User is a party; and
• Treatment is by automated means.
The portability right does not include inferred data or derived data, i.e. personal data that are generated by Hotel Imperatriz as a consequence or result of the analysis of the data being processed.
The User is entitled to have his or her personal data transmitted directly between those responsible for the treatment, whenever this is technically possible.
13. RIGHT OF OPPOSITION TO TREATMENT
The User has the right to oppose, at any time, for reasons related to his / her particular situation, the processing of personal data concerning him / her that is based on the legitimate interests pursued by Hotel Imperatriz or when the treatment is carried out for purposes that are not those for which personal data have been collected, including the definition of profiles, or when personal data are processed for statistical purposes.
Hotel Imperatriz will finalize the processing of User Data, unless it presents urgent and legitimate reasons for such treatment that prevail over the interests, rights and freedoms of the User, or for the purposes of declaration, exercise or defense of a right of Hotel Imperatriz in a judicial process.
When User Data is processed for the purpose of direct marketing (marketing), the User has the right to oppose at any time the processing of the data that concern him for the purposes of said commercialization, which includes the definition of profiles in the insofar as it relates to direct marketing. Should User oppose the processing of its data for the purposes of direct marketing, Hotel Imperatriz ceases processing of data for this purpose.
You also have the right not to be subject to any decision made solely on the basis of automated processing, including profiling, that has legal effects or significantly affects it in a similar way, unless the decision:
• It is necessary for the execution or execution of a contract between the User and Hotel Imperatriz;
• Is authorized by legislation to which Hotel Imperatriz is subject; or
• It is based on the explicit consent of the User.
14. PROCEDURES WITH REGARD TO THE EXERCISE OF THE RIGHTS BY THE USER
The Hotel Imperatriz will respond in writing (including by electronic means) to the request of the User within a maximum of one month from the receipt of the request, except in cases of special complexity, where this period can be extended up to two months.
If the requests presented by the User are manifestly unjustified or excessive, in particular due to their repetitive nature, Hotel Imperatriz reserves the right to charge administrative costs or refuse to comply with the request.
15. VIOLATIONS OF PERSONAL DATA
In the event of a breach of data and to the extent that such breach is likely to pose a high risk to the rights and freedoms of the User, Hotel Imperatriz undertakes to report the breach of personal data to the User concerned within 72 hours from the knowledge of the incident.
In legal terms, communication to the User is not required in the following cases:
• If Hotel Imperatriz has applied adequate protection measures, both technical and organizational, and these measures have been applied to personal data affected by the violation of personal data, especially measures that make personal data incomprehensible to anyone unauthorized to access them such as encryption;
• If Hotel Imperatriz has taken subsequent measures to ensure that the high risk to the rights and freedoms of the User is no longer likely to materialize; or
• If communication to the User implies a disproportionate effort for Hotel Imperatriz. In this case, Hotel Imperatriz will make a public communication or take a similar action through which the User will be informed.
17. APPLICABLE LAW AND FORUM