1. Introduction
At The Hotel, we care about your privacy. It is of the utmost importance for us that all processing of personal data take place in consideration of the privacy of the individual. This is why we always do our best to ensure that all processing of personal data takes place in accordance with the General Data Protection Regulation and other applicable legislation. This privacy policy (the “Policy”) applies to personal data about guests, visitors, customers and suppliers as well as other individuals who may be registered in IT systems (such as booking systems), website, apps, loyalty programs or the equivalent or personal data that is transferred from travel agencies, other booking sites or similar.
2. Who is the controller?
The Hotel Brussels
Boulevard de Waterloo 38, 1000 Brussels
Telephone: +32 2 504 11 11
This policy only relates to the activities of The Hotel Brussels (hereinafter — “controller”, “we”, “us”, “our” or “The Hotel”).
3. How we collect personal data
Depending on the situation, we collect information from you or from other sources.
From you
If you have contact with us regarding a reservation or making a hotel and / or restaurant reservation, have special requirements regarding your visit or use a social media that we provide, we will collect and process the information that you provide us with. These could include sensitive personal data, such as information about allergies.
From other sources
If someone makes a reservation for you, we process such personal data about you.
Also, sometimes we receive personal data from third parties (including other companies within our group) with whom we do business with or that are suppliers to us.
Under certain circumstances we process personal data about you that originates from publicly available sources, such as social media. This is for example the case when you make a review about our hotel on a website.
In those cases we process personal data about you that we receive from other sources than yourself, we will provide you with information in accordance with the GDPR (if possible).
4. Different types of processing activities
Information regarding hotel guests / visitors
Type of personal data
Contact information (for example your name, e-mail address, telephone number and address), demographic information (such as age, gender, age and language), guest stay information (which could include special categories of personal data, such as information about allergies), passport details (which can include your name and address, your place of birth and birthdate and your national identification number, the number of your passport or identity card and your nationality), loyalty program numbers, payment information (such as credit card number), business information, information relating to the reservation, guest assistance comments, personal information collected in the context of fitness center booking, conference room reservation and other additional services and facilities of the hotel, your feedback about our hotel and services that you submit to us (e.g. through customer satisfaction surveys) or that you post online as well as other personal data that you provide to us voluntarily (e.g. when making inquiries or complaints).
Lawful basis for the processing
Consent (in cases we have asked for that and you have accepted it), that processing is necessary for the performance of a contract to which you are a party or in order to take steps at the request of you to entering into a contract (for example in relation to a reservation) or for a legal obligation (for example a legal obligation for accommodation providers to register hotel guests). We may also process data based on our legitimate interests. We have for example a legitimate interest in contacting our guests to ask them about their stay in our hotel. When processing is based on legitimate interest, we shall make a balance between our legitimate interests and your rights and interests.
Purpose
To provide you with the services and products that you have asked for (for example in relation to a reservation), in order to evaluate and improve our services or in order to fulfil our legal obligations (for example to register hotel guests).
Information regarding contact persons
Type of personal data
Contact details such as name, e-mail address and telephone number.
Lawful basis for the processing
We process your personal data based on our contractual relationship or our legitimate interests. When processing based on legitimate interest, we shall make a balance between our legitimate interest and your rights and interests.
Purpose
We process personal data for the purpose of managing the supplier relationship, for contacts in various questions, billing and marketing (if applicable) or to communicate in other ways with you and your
company.
Social media
Type of personal data
The personal data that you submit to us on any social media platform (e.g. name, e-mail address and telephone number).
Lawful basis for the processing
Consent (in cases we have asked for that and you have accepted it) or that processing is necessary for the performance of a contract to which you are party or in order to take steps at the request of you to entering into a contract (for example in relation to a reservation) or legitimate interests. When processing based on legitimate interest, we shall make balance between our legitimate interests and your rights and interests.
Purpose
To provide you with the services and products that you want, to manage and market our services and products and to communicate with you.
Type of personal data
Name, e-mail address, telephone number and any other personal data that you submit to us via e-mail.
Lawful basis for the processing
Consent (in cases we have asked for that and you have accepted it) or that processing is necessary for the performance of a contract to which you are party or in order to take steps at the request of you to entering into a contract (for example in relation to a reservation) or legitimate interests.
Purpose
To provide you with the services and products that you want, to manage and market our services and products and to communicate with you.
Personal data regarding children
As far as we know, we are not in contact or collect personal data from children under 13 without relevant permission from a parent or guardian. If you believe we have inadvertently collected such information, please contact us so we can promptly obtain parental consent or remove the information.
Direct marketing communications, newsletters
Type of personal data
Name and e-mail address
Legal basis for processing
We have a legitimate interest in sending marketing communications to our existing customers regarding our own similar products and services (e.g. event invitations, promotions and special offers, …) including via social media. If you do not wish to receive our communications you can express your preference at the time we collect your personal information. In addition, if we process your personal data for marketing purposes, you have the right to opt-out from future marketing communications at any moment (for example, by clicking on the unsubscribe link in a marketing email you receive from us).
If you are not a guest or a client, we may use your personal data to send you marketing information (e.g. event invitations, promotions and special offers, …) including via social media if you have given us your prior consent to do so.
If you have consented to receive our marketing communications or digital newsletters, you may withdraw your consent your consent at any time.
Purpose
We use your personal data to keep you informed about our services, events and promotions.
Camera surveillance
We use camera surveillance at The Hotel. Camera surveillance is deemed to be particularly sensitive from a privacy perspective and it is of great importance that all camera surveillance takes place in accordance with the relevant legislation in effect from time to time. The camera images are processed on the basis of our legitimate interest to secure and protect our hotel, our guests, visitors and employees.
The Hotel has indicated the camera surveillance by means of a pictogram, and it has included information in a specific record.
Contact us if you would like more information about our camera surveillance (see contact details below).
Profiling
In order to provide you with premium service each time you visit our hotel, we may keep a profile about you, which can include information about your previous stays (such as how often you visit our hotel, when you visited our hotel the last time as well as financial information about your past stays).
The processing of your personal data is based on our legitimate interest to provide you a tailor-made customer service.
Jobs
Type of personal data
The information you provide us with, such as your name, telephone number, e-mail address, CV, and your cover letter. In a number of cases, The Hotel also receives data from third parties, such as social networks through which you apply, e.g. LinkedIn, selection and recruitment agencies, which carry out tests in the context of the application, your previous employer, but only if you have given your consent to do so.
Legal basis for processing
Depending on the individual case, the processing of your personal data for recruitment and selection purposes is based on your consent (e.g. to contact your former employer or to share your data; your request to take steps prior to entering into an agreement, for example if you send us your (spontaneous) application; or on the basis of our legitimate interest, including identifying, screening and evaluating applicants for potential employment and maintaining a recruitment reserve.
After the recruitment and selection procedure, The Hotel in certain cases (and with your prior consent) may retain your data in its recruitment database for future vacancies.
Purpose
The Hotel collects and uses your personal data exclusively for recruitment and selection purposes as set out above.
Contact us if you would like more information on how we process recruitment-related personal data (see contact details below).
5. Different kind of systems
Depending on the circumstances, we may process personal data in, or in relation to, inter alia, the following types of systems:
Property management system, property operation system, staff registration system, productivity system, telephone system, accounting system, clock system, yield management system, revenue center system, communication system, salary system, credit card system, key card system, TV and IT infrastructure (Internet etc.) and video surveillance system.
6. Who are the recipients or the categories of recipients which will receive the personal data?
In order to serve you, we may share your personal and anonymous data with:
- Other companies (including companies within the Pandox Group), such as vendors, contractors and co-operation companies. Their use of information is limited to these purposes and subject to agreements that require them to keep the information confidential. Our vendors provide assurance that they take reasonable steps to safeguard the data they hold on our behalf, although data security cannot be guaranteed,
- third parties that are data processors that perform services to us (e.g. companies that operate our hotels, assist us in marketing activities or IT operations),
- other group companies (e.g. to facilitate reservations),
- lawyers and advisors of the Pandox group,
- relevant authorities (e.g. in the context of our obligation to register guests),
- with trusted partners in order to provide you with relevant advertising offers or services,
- analytics companies may access anonymous data (such as your IP address or device ID) to help us understand how our services are used. They use this data solely on our behalf. They do not share it except in aggregate form; no data is shared as to any individual user, and
- potential acquirers of the company; in case (a part of) our business is sold to a third party, your data may be shared with the acquirer.
7. Will transfer be made to any third country?
As a main rule, we will not transfer any personal data outside the EEA. It is possible that service providers of The Hotel process your data outside the EEA. In this respect, The Hotel is committed to ensuring an adequate and sufficient level of protection for your data (e.g. by concluding an international data transfer agreement).
The Hotel shall meet its obligations under the applicable data protection law with respect to data transfers, including carrying out a due diligence on the level of protection of the laws of all third countries to which personal data are transferred and conducting a data transfer impact assessment to determine whether additional measures should be taken to ensure a level of data processing as required by belgian law.
If you have any questions about the transfer of your personal data outside the EEA or if you want to obtain a copy of the relevant documents, you can send your request to privacypandox@cranium.eu.
8. How long is the personal data saved?
We will not save personal data longer than necessary taking into consideration the purpose of the relevant processing. The responsible manager shall ensure that any routines applicable to deletion of personal data are complied with (please note that certain laws require that certain types of information must be saved for specified periods of time). Camera images are kept for a period of in principle one month.
9. What rights do you have as a data subject?
You have the right of access to your data, to have your personal data corrected, in certain cases to object to the processing and to require the personal data to be erased, that it should be restricted (a marking that the processing of the personal data should be restricted to a particular purpose), and that it should be turned over to you on an IT medium (data portability).
Please note, however, that certain personal data is necessary in order to be able to fulfil certain duties, such as payment information, and may therefore not be restricted or erased for this purpose.
You also have the right to withdraw your consent where the processing is based on consent. Where this is the case, this will be stated as the legal basis in the relevant sections.
In order to exercise your rights under the GDPR, please send in your request to privacypandox@cranium.eu. Please see below for a more detailed description of your rights as a data subject but note that exercising your rights may be subject to exceptions or conditions.
Right of access You are entitled to obtain access to your personal data we process about you. If you wish to exercise this right, send us a request as explained below.
The right to correction As a data subject, you have the right to require that we correct any incorrect personal data about you as a data subject. This also means that you, as a data subject, are entitled to supplement incomplete personal data, among other things by providing a supplemental statement. Such supplementation relates to personal data which is missing and which is relevant taking into consideration the purpose of the processing of the data.
The right to erasure You are entitled to contact us and request for your personal data to be erased. The personal data must be erased in the following cases: We are entitled to deny erasure in certain cases, among others in order to fulfil a legal obligation.
The right to restrict processing In certain cases, you have the right to require that we restrict the processing of your personal data. A restriction entails that the data is marked so that in the future it may only be processed for certain limited purposes. The right to restriction applies where you believe that the data is incorrect and request a correction. In these cases, you can request a restriction of the processing during the period of time in which we are investigating the accuracy of the data.
The right to data portability In certain cases, you have the right to receive personal data regarding you as a data subject and which you have provided to us and the right to transfer this data to another controller. This right applies to automated processing where the processing of personal data is supported by a consent from you as the data subject, or in order to perform an agreement with you and this applies only to such data as you yourself have provided.
The right to make objections You are entitled, at any time whatsoever, to object to our processing of your personal data where it involves personal data which is being processed based on a legitimate interest. In such case, we may no longer process the personal data unless we can demonstrate a compelling legitimate reason for the processing which overrides the interests, rights and freedoms of the data subject, or where the processing takes place in order to establish, exercise or defend against a legal claim. Where the personal data is processed for direct marketing, you as a data subject are entitled at any time whatsoever to object to the processing of personal data involving you for such marketing, including profiling to the extent this is connected to such direct marketing.
The right not to be subject to a decision based solely on automated means. You have the right not to be subject to decisions being made about you solely by ‘automated processing’ if the processing produces a legal effect, or similarly significantly affects you. Where this is occurring, you have the right to request human intervention, to express your point of view and to obtain an explanation as to how the system reached such decisions.
Have we asked for your consent? Then you can always withdraw your consent!
Under certain circumstances, we have to ask for your consent in order to provide you with services and process your personal data. Following your consent, we will only process your personal data for the purposes related to such service, product or similar.
In the following cases, inter alia, we may request your consent:
(i) Marketing activities;
(ii) In relation to processing of children’s data (where we will obtain consent from a parent);
(iii) If we process special categories of personal data (such as allergies);
(iv) If we transfer personal data to a third country:
(v) Processing of personal preferences for the purpose of personalization
Where the processing is based on consent, you are entitled at any time whatsoever to withdraw the consent (without this affecting the lawfulness of the processing carried out on the basis of the consent before the consent was withdrawn). If you would like to withdraw your consent, please refer to the same service, website or similar where you consented or contact us at the address or telephone number below.
You are always entitled to file a complaint with the Data Protection Authority. You can contact the Data Protection Authority via mail dpa@apd-gba.be or by post Rue de la Presse 35, 1000 Brussels.
However, in case of any questions or objects, we request you contact us first to enable us to resolve the issue.
10. Security measures
We have implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk with relevant processing activity (including reasonable steps to secure your personally identifiable information against unauthorized access or disclosure). We encrypt transmission of data on pages where you provide payment information. However, no security or encryption method can be guaranteed to protect information from hackers or human error. Please always use the internet with caution.
11. Miscellaneous
You are not obligated to provide us with any information and personal data about you. However, in some cases, we will not be able to provide you with some of our services or products if we are not allowed to process your personal data.
12. Contact details
If you have any questions or concerns about our privacy policies or our processing of your personal data, please contact us:
The Hotel Brussels
Boulevard de Waterloo 38, 1000 Brussels
Telephone: +32 2 504 11 11
Email: privacypandox@cranium.eu
13. Updates of this policy
This policy was last changed on 03/04/2024. We may update this Policy from time to time. We will always post an updated copy on our relevant websites. Therefore, please check our site for updates.
