Gliffaes Hotel – Privacy Notice
This privacy notice (“Privacy Notice”) together with our Terms and Conditions any other documents referred to in these documents, describes what information we collect from hotel guests and visitors to gliffaeshotel.com and other websites and mobile Apps operated by us, Gift Certificate buyers and any other individuals who contact us (collectively each referred to as a “guest”, “user”, “you”, “your”). We will also identify the way in which Gliffaes Hotel uses this information for legitimate business purposes and to better serve the needs of our current and prospective guests. Please note that this website is not intended for children under the age of 16.
Please read these documents carefully. By visiting our website or otherwise interacting with us by, for example, using our services, you acknowledge the processing activities undertaken by us which are described in this Privacy Notice, our terms and any other related documents referenced herein. Please note that any websites that may be linked to our websites are subject to their own privacy notice.
If you have any questions about this notice, please contact us by email at firstname.lastname@example.org or write to, The Manager, Gliffaes Hotel, Crickhowell, Powys, NP8 1RH. Please note your enquiries will be received during UK office hours and we will aim to respond to your enquiry as soon as reasonably possible.
We may change this Privacy Notice from time to time and will let you know about any changes by posting them on our website. Your continued use of our website after any such changes have been made will amount to your acknowledgement of the amended notice.
What is Personal Information?
“Personal Information” or “Personal data” means any information relating to an identified or identifiable natural person (each a ‘data subject’). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or by one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Personal Information may include name; address; email address; phone number; IP address; location data; payment details; information about movements around our websites and other digital media such as mobile app or social media; information concerning your interests; bookings; purchases and product and service preferences; data captured in authentication and tracking logs; and information collected from cookies and similar technologies.
- What personal information might we collect about you?
We may process the following personal data about you:
Information you give us. You may give us information about you by, even partially, filling in forms, setting up a user account or profile, subscribing to newsletters and other services, making or cancelling a booking or ordering a product, making applications in respect of job postings, uploading information on our website, putting in an “enquiry” about our hotel, using our enquiry form or participating in one of our on-line surveys, participating in prize draws or promotions or by communicating with us by e-mail, phone or otherwise, e.g. by calling one of our reservation team. This information may include your name, email address, billing address, room preferences or special requests, phone number, guarantee and deposit information to secure your reservation. You are under no obligation to provide this information, but without it, we may not be able to provide you with some of our content, services or information you may request.
Information collected during your stay with us. We record your itemised spending and other expenses billed to your room. Information particular to your stay may also be stored (i.e. food intolerances, payment difficulties, special requests, service issues). The information specific to your stay is stored in the property management systems and is combined with information from previous visits that you have made to Gliffaes Hotel. In addition, we may retain the content of any document (including letters, comment cards, electronic documents such as e-mails and other similar forms of communication) that you send to us before, during or following your stay.
Information we collect about you. With regard to each of your visits to our website we may collect:
-Technical information, including the Internet protocol (IP) address used to connect your computer to the Internet, browser type and version, time zone setting, geographical information, date and time you access our website, and the Internet address of the website from which you linked directly to our website, browser plug-in types and versions, operating system and platform and similar information; and
– Information about your visit, including the full Uniform Resource Locators (URL) clickstream to, through and from our website, pages you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page.
Information about minors obtained from parents or guardians. Gliffaes Hotel does not knowingly collect personally identifiable information via our websites from any person we actually know is a person under the age of 18. We may collect personally identifiable information from persons under the age of 18 as part of the guest reservation and registration processes, but always with the consent of such person’s parent or guardian.
Information obtained from someone making a booking on your behalf. If you are entering data on behalf of another person, you warrant to us that you are authorised by that person to enter their personal data into our system, and that information you enter is accurate and correct. If any non-compliance by you with respect to this provision results in any loss or damage being incurred by us, you may be required to compensate us in respect of such loss.
Information about you obtained from third party sources. These third party sources may include credit reference agencies and other third parties. In addition, in preparation for your stay, we may collect your photograph from publically available sources so that we can recognise you in order to provide you with outstanding customer service.
Cookie Statement –
What Exactly Are Cookies?
A cookie is a small piece of information which is sent to your browser and stored on your computer’s hard drive, mobile phone or other device.
You can set your browser to notify you when you receive a cookie. This enables you to decide if you want to accept it or not. However, some of the services and features offered through our website may not function properly if your cookies are disabled.
Cookies can be first party or third party cookies.
-First party cookies – cookies that the website you are visiting places on your computer.
-Third party cookies – cookies placed on your computer through the website but by third parties, such as, Google.
The Cookies Placed On Our Website
We use the following cookies on our website. We may combine information from these types of cookies and technologies with information about you from any other source.
Strictly necessary cookies. These cookies are essential in order to enable you to move around our website and use its features. Without these cookies, services you have asked for cannot be provided. They are deleted when you close the browser. These are first party cookies.
Performance cookies. These cookies collect information in an anonymous form about how visitors use our website and apps. They allow us to recognise and count the number of visitors, see how visitors move around the site when they are using it and identify the regions that they are visiting from. These are first party cookies.
Functionality cookies. These cookies allow our website and apps to remember choices you make (such as your user name, language or the region you are in) and provide enhanced, more personal features. The information these cookies collect will be anonymised and they cannot track your browsing activity on other websites. These are first party cookies.
Analytics. We may use third party analytics services such as Google Analytics and other providers. These service providers help us analyse how users use our website and to identify user patterns. The information generated by the cookie about your use of the website (including your IP address) will be transmitted to and stored by third party analytics service providers on servers outside EEA. The information collected for this purpose (including your IP address and other information collected by automated means) will be disclosed to or collected directly by these service providers. On our behalf third party analytics service providers will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet activity in connection with the use of the website. These service providers may retain and use anonymised, aggregated data collected from users of our Website in connection with their own businesses, including in order to improve their products and services. In addition, authentication and tracking logs will be used to compile user statistics.
Targeting or advertising cookies. These cookies allow us and our advertisers to deliver information more relevant to you and your interests. They are also used to limit the number of times you see an advertisement as well as help measure the effectiveness of advertising campaigns. They remember that you have visited our website, the length of your visit, the ads you viewed and may help us in compiling your “utilisation profile”. These are persistent cookies which will be kept on your device until their expiration or earlier manual deletion.
Social Media cookies. These cookies together with social media plug-ins allow you to use functionalities of social media networks such as Facebook, Google’s +1 button, Twitter, Instagram and others on our website. These are persistent cookies which will be kept on your device until their expiration or earlier manual deletion. If you use these functionalities, the plug-in and its content are loaded directly from the social media provider’s servers and included in the website by your browser. If you log into your respective social media account at the time you interact with the social media plug-ins on our website, the social media provider will connect this information with your social media user profile. We cannot influence which personal data the social media provider will collect about you. Please see their privacy notices for further information:
Cookie Consent and Opting Out
We assume that you are happy for us to place cookies on your device. Most Internet browsers automatically accept cookies. However, if you, or another user of your device, wish to withdraw your consent at any time, you have the ability to accept or decline cookies by modifying your browser setting. If you choose to decline cookies, you may not be able to fully experience the interactive features of our website, our platforms and our services.
In some instances, when you opt-out, a new cookie (Opt-Out-Cookie) is placed in your web browser. This tells the third party provider to cease data collection from your browser and prevents advertisements from being delivered to you.
For more information about cookies please visit www.allaboutcookies.org.
Why do we capture and store your personal information?
We will only process your personal data, in accordance with applicable law, for the following purposes:
(a.) responding to your queries, comments, complaints and requests;
(b.) managing and administering your user account;
(c.) processing your bookings or cancellations. Bookings made for the restaurant and afternoon tea service made by non-residents are recorded in a paper diary held at reception. Your name and contact number is the only information recorded;
(d.) delivering any services, products, information requested by you, including newsletters. We will only send electronic messages at appropriate intervals to the e-mail address you gave us, if you have given us consent to do so or have opted in via our website or contact form. In deciding whether or not to join such lists, please note that they are only used for internal purposes and we do not sell or rent our subscription lists to anyone. The Gliffaes Hotel email database is held by email specialists, “Mailchimp”, located in the United States. You can unsubscribe at any time by email to email@example.com or clicking on any of the unsubscribe links contained within every marketing email we send or by phone on 01874 730 371. Please note your enquiries will be received during UK office hours and we will aim to respond to your enquiry as soon as reasonably possible;
(e.) providing you with a customised and premium service. Our goal is to provide you with a personalised customer service before, during and after your stay, whether you are a new or a returning guest. For these purposes we may create a profile including your user account as well as online session data. We store transaction information in our Property Management Systems (“PMS”). This information may also include details of the number of nights of each stay you have had with us, your spend with us and notes we may have made concerning special requests, likes or dislikes we have made during your previous stays at Gliffaes Hotel.
(f.) verifying your identity, when required;
(g.) communicate with you about, and administer your participation in, special events, programs, surveys, contests, sweepstakes, and other offers or promotions;
(h.) display content on our websites and apps, such as stories, product reviews, comments and photos, provided by you;
(i.) allowing you to participate in interactive features of our apps and websites, when you choose to do so;
(j.) process claims we receive in connection with our websites, products and services;
(k.) handling any job application that you may make to us and managing your login details on our staffing platforms;
(l.) implement and enforce our general terms and conditions of business or any other agreements concluded with you;
(m.) enabling our suppliers and service providers to carry out certain functions on our behalf, including the hosting of our websites, apps and booking platforms, verification, technical, logistical or other functions, as may be required, in order to make available our website and services. For example, when you make a reservation your credit card number will be verified using by the card provider, but we do not authorise any payments at this point;
(n.) administering financial operations, including credit checks and debt recoveries;
(o.) sending you personalised marketing communications and alerts requested by you;
(p.) serving personalised advertising to your devices,including delivering ads based on your interests ascertained from your past searches, visits of subpages on our websites, and other data obtained through the use of “cookies” placed on your devices. Please see our Cookie Statement above;
(q.) ensuring the security of your user account and our business;
(r.) preventing or detecting fraud or abuses of our websites, products and services, for example, by requesting verification information in order to reset your account password;
(s.) administering technical aspects of our website, including troubleshooting, diagnosis of technical and service problems, testing, encryption and similar operations;
(t.) for internal business operations, including data analysis, research, trend analysis, statistical and survey purposes, for example to gather demographic information about our users, determine how much time users spend on webpages of our website and to gather information on how our users navigate through our website. We may wish to contact guests to conduct surveys or focus groups to receive your views on our properties and service delivery. Occasionally we will combine information from a number of guests to better understand trends and guest expectations. When this occurs, all identifiers are removed and the aggregate information cannot be linked to any specific guests;
(u.) developing and improving our website, products and services and determining the effectiveness of our business efforts, for example, by reviewing demand for websites, products and services and user comments or other contributions; and
(v.) to comply with applicable law, for example, in response to a request from a court or regulatory body, where such request is made in accordance with the law. We also record information to comply with financial reporting requirements, including those imposed by auditors and government regulators. We may also collect certain information as required by local laws (e.g. passport number, car registration number, names of all sleepers’ including children and partners).
Legal basis for processing
The legal basis for our processing of your personal data for the purposes described above will typically include:
-processing necessary to fulfil a contract, such as website terms or booking contract, that we have in place with you, such as the processing for the purposes set out in paragraphs 4 (a.), (b.), (c.), (d.), (e.), (f.), (g.), (h.), (i.), (j.), (l.), (m.) and (n.);
-processing necessary for our or a third party’s legitimate interests, such as the processing for the purposes set out in paragraphs 4 (f.), (g.), (h.), (j.), (k.), (l.), (o.), (p.), (q.), (r.), (s.), (t.) and (u.), unless consent is required under applicable law;
-your consent, such as the processing for the purposes set out in paragraphs 4 (o.) and (p.), where such consent is required under applicable law; and
-processing necessary for compliance with a legal obligation to which we are subject, such as the processing for the purposes set out in paragraph 4 (v.); and
-other applicable legal grounds for processing.
Disclosure of your information
There are circumstances where we wish to disclose or are compelled to disclose your personal data to third parties. This will only take place in accordance with the applicable law and for the purposes listed above. These scenarios include disclosure:
-to our outsourced suppliers and service providers in order for them to facilitate the provision of our website, services or content to our users. For example, when you make a reservation via our website or one of our Apps, your information will be transferred to our property management systems in order to complete your booking;
-to the payer, such as your employer. If your stay has been paid for by a third party we will provide billing information to such paying party;
-to our analytics partners such as a customer relationship management company and/or a marketing and communications company for statistical and analysis purposes. For example, survey information may be collected by a third party under contract with us;
-subject to your consent, to our marketing partners, who may contact you by post, email, telephone, SMS or by other means. If you do not wish to be contacted, you may unsubscribe at any time;
-to third party service providers and consultants, for example, in order to protect the security or integrity of our business, including our databases and systems and for incident response or business continuity reasons;
-to another legal entity, on a temporary or permanent basis, for the purposes of a joint venture, collaboration, financing, sale, merger, reorganisation, change of legal form, dissolution or similar event. In the case of a merger or sale, your personal data will be permanently transferred to a successor company or new owner.
-to public authorities where we are required by law to do so; and
-to any other third party where you have provided your consent.
How is my Personal Information secured?
We endeavour to protect the privacy of your account and other Personal Information that we hold in our records. Unfortunately, we cannot always guarantee complete security. Unauthorized entry or use, hardware or software failures, and other factors, may compromise the security of user information. Also, while we endeavour to put adequate contractual protections in place we cannot guarantee the security of any Personal Information in databases hosted by third parties.
Gliffaes Hotel stores Personal Information in a secure location, be it a database, PMS, marketing and research database or a filing cabinet. Furthermore, we take steps to ensure that only designated individuals have access to this information. In addition, due to the personal nature of the information you provide when making a reservation through our website or mobile Apps, Gliffaes Hotel employs encryption technology to keep your data secure.
Credit card information is transmitted and stored in encrypted format and only unencrypted when required for taking payments or guaranteeing future stays. Access to unencrypted credit card details is restricted to designated individuals as per PCI DSS industry best practise.
We work to protect the security of your information during transmission by using Secure Sockets Layer (SSL) technology, which encrypts information you input and which is certified by the Secure Server Certification Authority. We reveal only the last four digits of your credit card numbers when confirming a reservation or processing on-line purchase transactions. Of course, we transmit the entire credit card number to the appropriate credit card company for verification or during payment. It is important for you to protect yourself against unauthorized access to your password and to your computer. Be sure to sign off when you have finished using a shared computer.
It is important to note that e-mail communications are not secure. This is a risk inherent in the use of e-mail. Please be aware of this when requesting information or sending forms to us by e-mail (for example, from the “Contact Us” section of our web site). We recommend that you do not include any confidential information (i.e. credit card information) when using e-mail. For your protection, our e-mail responses to you will not include any confidential information.
Finally, to be prudent, please be sure to always close your browsers when you are done using a form or the reservation site. Although the session will terminate after a short period of inactivity, it is best to close your browsers immediately upon completion.
Is my Personal Information transferred overseas?
We may transfer your information outside of the country in which it was collected for various reasons. These reasons include: the purpose of entering into or fulfilling a contract with you, reserving a room, processing on-line purchase transactions, replying to or taking actions in response to your enquiries or requests, for processing by us or on behalf of the hotels and residences properties managed by us, enhancing personalization of services provided to you, communicating news and promotions to you relating to Gliffaes Hotel related products and services and other products and services we think may be of interest to you, and statistical and analysis purposes. Our core business systems, including property management systems, are located in data centres within EEA or US.
How long is my Personal Information retained?
Your personal data will be retained for seven years for the purposes listed above or as required by applicable local law.
We may keep an anonymized form of your personal data, which will no longer refer to you, for statistical purposes without time limits, to the extent that we have a legitimate and lawful interest in doing so.
If you wish to exercise any of your rights in relation to your Personal Information, please send your request using the following method of communication.
-via e-mail at firstname.lastname@example.org for any consent withdrawal/unsubscribe requests;
-via telephone on 01874 730 371
Right to make subject access request (SAR)
We understand that you may like to know what Personal Information we hold about you. We are happy to assist you with your request. However, to protect your Personal Information we require that you prove your identity to us at the time your request is made. You may also make a request by email.
When you make a request, we will require you to produce some form of photo identification such as a passport or a driver’s license and you may be asked to sign a request form. If the request is made in writing via email or letter we require other information so we can check them with our files and satisfy ourselves as to your identity.
The above information is required to create an audit trail of how the request has been handled. Where a request is made, any correspondence or application may be kept and added to your Personal Information.
Gliffaes Hotel will respond to any enquiries as soon as possible but no later than within the timeframes prescribed by law.
Gliffaes Hotel reserves the right to decline access to your Personal Information under certain circumstances, as permitted by law. If your Personal Information is not disclosed to you, you will be provided with the reasons for this non-disclosure.
Right to object to processing, including automated processing and profiling.
If at any time you wish for your Personal Information to be deleted from our guest database and systems, or wish to not be part of our profiling module, please contact us.
Gliffaes Hotel will aim to respond to your enquiry within 72 hours. However it might take up to 7 days to have your profile deleted from all our systems.
Right to rectification
You may request that we rectify any inaccurate and/or complete any incomplete personal data.
Right to withdraw consent
You may, as permitted by applicable law, withdraw your consent to the processing of your Personal Data at any time. Such withdrawal will not affect the lawfulness of processing based on your previous consent. Please note that if you withdraw your consent, you may not be able to benefit certain service features for which the processing of your personal data is essential.
Right to erasure
You may request that we erase your Personal Data and we will comply, unless there is a lawful reason for not doing so. For example, there may be an overriding legitimate ground for keeping your Personal Data, such as, a legal obligation that we have to comply with, or if retention is necessary for us to comply with our legal obligations. If you wish to have your data removed from our system please contact email@example.com
Right to data portability
In certain circumstances, you may request that we provide your personal data to you in a structured, commonly used and machine readable format and have it transferred to another provider of the same or similar services. Although we do not consider that this is relevant to our services, we will comply with such transfer request as required by law. Please note that a transfer to another provider does not imply erasure of your Personal Data which may still be required for legitimate and lawful purposes.
Your right to lodge a complaint with the supervisory authority
We suggest that you contact us about any questions or if you have a complaint in relation to how we process your Personal Data. However, you do have the right to contact the relevant supervisory authority directly. A list of EU national data protection authorities can be found here.