Version 1.0 · effective date to follow

Privacy notice for guests

{{HOTEL_NAME}} · version {{HOTEL_NOTICE_VERSION}} · {{HOTEL_NOTICE_DATE}}

Template provided by ALiSiO. The accommodation provider named below is responsible for this notice and adapts it to its business; sections marked [if …] apply only when the function is used.

1. Who is responsible

Controller: {{HOTEL_LEGAL_NAME}}, {{HOTEL_ADDRESS}}, email {{HOTEL_EMAIL}}, phone {{HOTEL_PHONE}}. [if appointed] Data protection officer: {{HOTEL_DPO_CONTACT}}.

2. What data we process and why

Booking and stay. Name, contact details, dates of stay, room, number of guests, special requests, payment and invoice data — to take your booking, prepare and provide your stay, and invoice it (Art. 6(1)(b) GDPR).

Legal obligations. Data required by the registration law of {{HOTEL_COUNTRY}} (for example date of birth, nationality, address, identity document data for certain guests, signature on the registration form), data for tourist or city tax and exemptions from it, and invoices and accounting records we must keep (Art. 6(1)(c) GDPR).

Your guest page and access. [if guest page / kiosk / access codes are used] Your booking details, arrival instructions and — where used — room or door codes are shown on a personal page that only people with the link can open. Codes are shown only for the period of your stay (Art. 6(1)(b) and (f) GDPR).

Scanning your identity document. [if document recognition is used] You can type your document data yourself or take a photo of your document. If you take a photo, it is analysed by an automated recognition service to fill in the form; the photo is not stored permanently. This is voluntary (Art. 6(1)(a) GDPR); typing the data yourself is always possible.

Security and claims. Logs of access to your guest page and data about damage or unpaid amounts, to protect our property and guests and to enforce claims (Art. 6(1)(f) GDPR).

Messages and offers. [if used] We send you offers or ask for a review only with your consent or, where the law allows, about our similar services with the option to object in every message (Art. 6(1)(a) or (f) GDPR).

3. Where your data comes from

From you, from the person who booked for you, or from the booking platform or travel agency through which you booked.

4. Recipients

Some service providers are located outside the EU (for example in the USA). Transfers take place only with appropriate safeguards (adequacy decision, EU–U.S. Data Privacy Framework or standard contractual clauses).

5. How long we keep your data

6. Do you have to provide the data?

The data required by registration and tax law must be provided; without it we cannot check you in. Other data is needed to fulfil the booking or is voluntary.

7. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability, to withdraw consent with effect for the future, and to object to processing based on legitimate interests and to direct marketing at any time. Contact us at {{HOTEL_EMAIL}}.

You can also lodge a complaint with a data protection supervisory authority, for example: {{HOTEL_SUPERVISORY_AUTHORITY}}.

We do not use automated decision-making that has legal effects for you.