The Informative Text on Processing Personal Data for CPI Hotels, a.s. clients
In accordance with European Parliament and Council (EU) Regulation No. 2016/679 dated 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, “GDPR”), this page provides important details concerning your personal data that is processed by CPI Hotels, a.s., ID No.: 47116757, with registered office at Bečvářova 2081/14, 100 00 Prague, registered in the Commercial Register at Prague Municipal Court, file no. B 1914 (“CPI Hotels” or “we”).
CPI Hotels operates the following brands: Budha-Bar Hotel Prague, Clarion Hotels, Quality Hotels, Comfort Hotels, Mamaison Hotels & Residences, Spa & Kur Hotels, Holiday-Inn, Fortuna Hotels, Private Label Hotels, Ubytovny.cz and the Benada Restaurant.
1. What data do we process?
A) Client data
Based on your reservation (including stays without reservations), we process the personal data of clients in the following scope:
- identification and contact details (first and last name, permanent residence, ID card number or the number of a similar form of identification, as well as email address and phone number),
- in the case of entrepreneurs, we also process their business name, registered office, ID number, tax ID and VAT payer details,
- in the case of business trips by persons who are not entrepreneurs we also process the details of the organisation ordering or paying for the stay),
- purpose of the stay or specification that the client is a person not subject to the fee for spa or recreation stays,
- information about your membership in our loyalty program,
- details of your stay and the services you use as well as the amount and form of payment for provided services (if paid via bank transfer or payment card details),
- in the case of foreign nationals we also collect their date of birth, nationality, passport number, visa number, and permanent address abroad,
- and in the case of guests who park at our hotel we process the registration plates of their vehicle.
We provide spa care at our Spa & Kur Hotels in addition to accommodations. If you use our spa services, we also process the following data in addition to the details specified above:
- data concerning your diagnoses received directly from you by our physician during the initial medical exam,
- details of medical care provided to you at our facilities during your treatment stay (medical exam or complications occurring during your stay, etc.)
B) Photo documentation from organised events
We do take photos of events held at our facilities (situational footage of events) for the purpose of subsequent publication of selected photographs on our website for promotional use by CPI Hotels. Such footage is not primarily focused on showing visitors to specific events; instead, it focuses on the overall atmosphere of the event, photos are not published in detailed resolution and we do not append descriptions of specific persons visiting such events to such footage. In the professional opinion of the Personal Data Protection Office, such use is not primarily subject to personal data protection, and instead is subject to privacy protection under the Civil Code; consent to the processing of personal data in the case of “illustrative” footage is not required.
Visitors are notified in advance of such photo documentation by the camera pictogram and our photographers are visibly identified and such photo documentation is only acquired in the main room of the given event, while visitors always have the option to use areas where no photos are taken. Please contact us using the information provided below if you have any questions or concerns related to footage and photo documentation.
2. On what basis and for what purpose do we process your personal data?
A) Processing necessary to comply with legal obligations
The provision and processing of all of the personal data listed above, with the exception of your email address and telephone number and information about your membership in the loyalty program, is necessary to comply with our legal obligations, in particular those under the Act on Local Fees and the Act on Alien Residence in the Czech Republic and under applicable accounting and tax regulations.
B) Processing necessary to perform our contractual arrangement
The processing of your identification data and information about your stay and services provided and the amount and manner of their payment is necessary for the purpose of fulfilling our contractual arrangement concerning your stay, i.e. assuring orders and reservations, and concluding and fulfilling agreements relating to accommodation and related services.
In the case of spa care, we process the data provided on the registration card, the data about your treatment stays and the medical care provided to you in our facilities, as well as payment for your stay. We process this data based on the legal arrangement between you and CPI Hotels, the subject of which is providing spa treatment, rehabilitation care and related services (accommodations, catering services, etc.). The purpose of this processing is to provide the specified services.
C) Consequences of failure to provide data
We cannot provide our accommodation services if you do not provide the data specified above. We do not need your personal data to provide catering and other services and therefore we do not obtain or process your data for such purposes
D) Processing necessary for a legitimate interest
Your personal data in the scope of your first name, last name, email address and details concerning your stay are all processed for direct marketing purposes based on our legitimate interests, and the exclusive purpose of such processing is to send you marketing and business correspondence, specifically information about news, discounts and the like.
We also process personal data in this scope necessary to distribute a satisfaction survey after a stay in our hotels to determine your satisfaction with our services and to continuously improve the quality of our services for you.
In our hotels there are no doubts about the services or spa services provided to our guests. If such doubts were raised, we would be forced to process certain data regarding such provided services in the necessary scope with respect to the given dispute and exclusively for the purpose of defending our rights in such a dispute. We would likewise be forced to process certain data if we did not receive payment for our services or if we incurred damages.
E) Consent-based processing
Based on your consent or permission granted via the application settings in your web browser, we process certain technical information obtained when you visit our websites – for more details, see the separate informational text published at www.cpihotels.com/cs/cookies.
We offer our clients Wi-Fi network service and you have the option to choose between a paid connection or a free connection. If you choose the free connection, you are informed in advance that CPI Hotels will use your email address to send marketing information to keep you updated as to news, discounts, etc. You then have the ability to unsubscribe from such marketing communication at any time.
You may revoke your consent at any time by sending an explicit statement to such effect to our address (CPI Hotels, a.s. Bečvářova 2081/14 100 00 Praha 10), or via email email@example.com, using the contact form at www.cpihotels.com, or by changing the settings on your web browser. Consent is considered revoked once such correspondence is delivered to CPI Hotels. Under the GDPR, such revocation of consent has no effect on the lawfulness of processing based on consent prior to revocation.
F) Automated processing of your data
Under no circumstances do we make automated decisions or perform other automated processing of your personal data that would have any legal effect for you or otherwise affect you in a significant way.
3. Source of personal data
We receive all the specified data directly from you during the process of concluding our agreement and providing accommodation and catering services.
If your reservation of our services was made by another person (typically your employer in the case of business trips), we receive your basic identification and contact details (first name, last name and phone number or email address) directly from this person.
For reservations made via a reservation portal, we receive your identification and contact details (first name, last name and phone number or email address) directly from the reservation portal.
4. How long do we process your personal data for?
We process your personal data for the duration of your stay at our hotel. Once your stay ends, we only process:
- data we are obliged to process under the relevant legislation and exclusively for the period necessary under such legislation. (Such as the accounting and tax records that we issue to you, which also contain some of your personal data (first and last name, type of provided services and issue date of the record itself). We’ll only store these materials for the purpose of accomplishing the obligations stipulated in the relevant accounting and tax legislation and for the period defined therein.)
- Your first name, last name, email address and information concerning your stay for the direct marketing purposes of CPI Hotels (sending information about news, discounts on our services, etc.) and for distributing our satisfaction survey. We’ll only process data for distributing the satisfaction survey for the period in which such survey responses are evaluated (a maximum of 1 month after your stay). For direct marketing purposes, we only process the above-specified data for the period until you express your disagreement with such further processing.
- Data required due to an existing or imminent dispute. We only process this data until such time that a valid decision is handed down in the dispute and the obligations thereunder are fulfilled, or until such time that a dispute regarding provided services could occur as specified under valid legislation.
At the end of the above periods, we will periodically dispose of your personal information, both in paper and electronic form.
5. Who do we provide with access to your personal data?
A) Third parties
We do not provide your personal data or otherwise disclose such data to any third parties, with the exception of public authorities when so required under valid and enforceable legislation (this typically involves data that we process under the Act on Local Fees and the Act on Alien Residence in the Czech Republic).
With respect to spa treatment services, we do not provide your personal data to anyone and our physicians and other health care professionals are employees of CPI Hotels.
We make use of services provided by processors to provide certain support services (e.g. distributing marketing materials, improving communications and the segmentation of our offers, providing on-line hotel reservations and processing cookies). Such work is only performed for our company and per our specific instructions. We select processors based on their credibility and the quality of services they provide, including personal data processing. Processing is only permitted based on an official agreement concluded by CPI Hotels and a processor, in which the processor commits to afford personal data the same level of protection as provided by CPI Hotels. We will notify you of the processors we are currently cooperating with upon request.
C) Third countries
All our processors maintain registered offices and processing locations in the Czech Republic or another EU member state. Exclusively in the case of distributing and evaluating satisfaction surveys, and in the case of certain reservation systems, we do use processors located in the United States of America, all of which are renowned companies operating within international hotel, reservation and similar networks and providing services for hotels on a global scale.
Commission Implementing Decision (EU) 2016/1250 of 12 July 2016 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequacy of the protection provided by the EU-U.S. Privacy Shield was defined by the European Commission together with U.S. government authorities as a special instrument to ensure a sufficient level of protection for personal data once turned over to recipients in the United States of America. Based on this decision, a company located in the United States that commits to comply with the principles of the “Privacy Shield” program is considered to offer a commensurate level of protection for personal data. These processors located in the United States are among those companies who have committed to adhere to the principles of the Privacy Shield program. More information is available at the program’s official website https://www.privacyshield.gov. The Privacy Shield program remains in place, even after GDPR takes effect.
We do not anticipate the handover of any personal data outside of EU member states except those specified above.
6. How does CPI Hotels protect personal data
Anyone who comes into contact with personal data on our website is obliged to maintain confidentiality with respect to all processed personal data and the safety precautions deployed to protect such data. This obligation survives the termination of their working relationship with CPI Hotels or with a processor.
7. Your rights under valid legislation
Under valid personal data protection legislation, you have the following rights:
- the right to access your personal data we process, which includes receiving the following information from CPI Hotels:
- confirmation that CPI Hotels processes your personal data
- access to such personal data,
- information on the purposes of such processing,
- the categories of personal data involved,
- information on recipients or categories of recipients who will be provided access to such personal data,
- the planned archiving period and criteria for its determination,
- the existence of the right to correct or delete personal data, or restrict its processing, or the right to raise an objection to such processing,
- the right to file a complaint with the supervising authority,
- all available information on the sources of personal data, if not specifically obtained from the data subject, i.e. from you,
- if automated decision-making processes, including profiling, are performed,
- suitable guarantees regarding the transfer of personal data outside the EU,
- provided that the rights and freedoms of others are not adversely affected, as well as a copy of your personal information.
- the right to correct your personal information if incorrect, inaccurate or incomplete in any regard; correction shall be made by CPI Hotels when technically feasible without undue delay,
- the right to request the deletion of personal data in the instances specified in the GDPR, such as revocation of consent to processing or objection to processing, in the case of unlawful processing of personal data, where personal data is no longer necessary for the purposes for which such data was processed, etc. You may therefore request the deletion of your personal data, but this option does not apply where processing is necessary to fulfil a legal obligation, and in some other cases specified by the GDPR.
- the right to restrict the processing of personal data in the cases foreseen by the GDPR, such as if you doubt the accuracy of the personal data, object to its processing, etc.
- the right to transfer the data you provided and that we process in an automated manner based on your consent and based on the need for their processing to fulfil an agreement with you, or to take action prior to the conclusion thereof on your request. In such cases, we’ll permit you to access your personal data in a structured, commonly used and machine-readable format, or if technically feasible, we’ll provide it directly to another controller of your choosing,
- the right to object to the processing of your personal data given the need for processing based on legitimate interests, including processing for direct marketing purposes. In such case, we will not process your personal data unless we can prove serious legitimate reasons for processing that outweigh your interests or rights and freedoms, or to determine, exercise or defend legal claims.
- the right to revoke consent to the processing of personal data by sending an explicit notice sent to our address (CPI Hotels, a.s. Bečvářova 2081/14 100 00 Praha 10), via email firstname.lastname@example.org, using the contact form provided at www.cpihotels.com, or by changing the settings in your web browser. Consent is considered revoked once such correspondence is delivered to CPI Hotels. Under the GDPR, the revocation of consent has no prejudice on the lawfulness of processing based on consent granted prior to revocation.
- the right to be exempt from any decision based exclusively on automated processing, including profiling and which has legal effect for you or that materially affects you in a similar manner, except for the instances specifically identified in the GDPR,
- in addition to the rights specified above, if you believe that the processing of your personal data has violated the GDPR, you have the right to file a complaint with the supervising authority, specifically the Personal Data Protection Office located at Pplk. Sochora 27, 170 00 Prague.
8. Information text for the CCTV system used in CPI Hotels, a.s. premises
• data is processed to protect property and to increase safety
• the scope of processing is limited to video recordings made by the camera system, with no audio recordings
• identification of the controller: CPI Hotels, a.s., ID no.: 47116757, with registered office at Bečvářova 2081/14, Prague 10000
• CCTV system recordings are stored on a HDD/hard disk operated by CPI Hotels, a.s. and no other processor uses this CCTV system
• the place of processing is the registered office of CPI Hotels, a.s. and its premises located at Vladislavova 1390/17, Nové Město, 110 00 Prague, as well as the individual hotels it operates, which are presented with specification of the individual numbers of cameras installed:
|Hotel Fortuna West||Mrkvičkova 1091/2, 163 00 Prague, Řepy||32|
|Hotel Imperial Ostrava||Tyršova 1250/6, 702 00 Moravská Ostrava||35|
|Clarion Hotel Prague Old Town||Hradební 768/9, 110 00 Prague, Staré Město||8|
|Comfort Hotel Olomouc||Wolkerova 1197/29, 779 00 Olomouc||12|
|Buddha-Bar Hotel Prague||Jakubská 649/8, 110 00 Prague, Staré Město||33|
|Spa Kur Hotel Harvey||Dlouhá 222/2, 351 01 Františkovy Lázně||37|
|Grand Hotel Zlatý Lev||Gutenbergova 126/3, 460 05 Liberec||8|
|Clarion Hotel Špindlerův Mlýn||Labská 111, 543 51 Špindlerův Mlýn||13|
|Spa Kur Hotel Praha||Ruská 27/12, 351 01 Františkovy Lázně||18|
|Clarion Hotel České Budějovice||Pražská tř. 2306/14, 370 04 České Budějovice||63|
|Clarion Hotel Prague City||Tylovo náměstí 15/3, 120 00 Prague, Vinohrady||12|
|Mamaison Residence Belgická||Belgická 318/12, 120 00 Prague, Vinohrady||2|
|Clarion Congress Hotel Ostrava||Zkrácená 2703/84, 700 30 Ostrava, Zábřeh||30|
|Hotel Černigov Hradec Králové||Riegrovo náměstí 1494/4, 500 02 Hradec Králové||12|
|Mamaison Hotel Riverside||Janáčkovo nábřeží 1115/15, 150 00 Prague||8|
|Comfort Hotel Prague City East||Bečvářova 2081/14, 100 00 Prague 10||68|
|Quality Hotel Ostrava City||Hornopolní 3313/42, 702 00 Moravská Ostrava, Ostrava||26|
|Mamaison Residence Downtown Prague||Na Rybníčku 1329/5, 120 00 Nové Město, Prague||48|
• the only recipients of data from the CCTV system are law enforcement or administrative authorities for the purpose of infringement proceedings
• the cameras record:
- in individual hotels: entrance and reception areas, corridors and underground garage spaces, parking spaces in front of the hotel, entrances/exits, staff entrances, stocking and handling areas, terraces, fitness / wellness entries (in the case of Clarion in Špindlerův Mlýn and Ostrava), lobby/foyer, access to conference facilities, ramp, courtyard/inner yard.
• recordings are stored for a maximum of 7 days, after which they are automatically deleted as they are recorded over because the cameras operate on a loop
• CCTV system operation: continuous (or based on an automatic motion detector)
• contact details for information requests: registered office of CPI Hotels, a.s., or via email email@example.com
You have the following general rights under valid personal data protection legislation:
- the right to access your personal data that we process,
- the right to correct your personal information if incorrect, inaccurate or incomplete,
- the right to request deletion of your personal data or to limit its processing,
- the right to object to the processing of your personal data,
- in addition to the rights specified above, you have the right to file a complaint with the supervising authority, specifically the Personal Data Protection Office located at Pplk. Sochora 27, 170 00 Prague.
If you have any questions or concerns regarding the processing of your personal data, please contact us in writing at CPI Hotels, a.s. or via email at firstname.lastname@example.org.
9. Our contact details
If you have any questions or concerns regarding the processing of your personal data, please contact us in writing at CPI Hotels, a.s. Bečvářova 2081/14 100 00 Prague, via email to our personal data protection officer at email@example.com, or using the contact form posted on our website at www.cpihotels.com.