Privacy Policy
1. Preamble
By this Policy, the Company under the name “MOTVALDEN LTD GREECE BRANCH”, headquartered in Athens, 13 Mousson str, telephone number: 2130883945 and email address: info@neomahotel.com, (hereinafter the “Company”), which operates Hotel Neoma, provides as Data Controller, within the meaning of the applicable legislation, to the natural persons whose Personal Data processes, relevant information, based on its relationship with them.
2.Definitions
Data Controller: The Company, which determines the purposes and means of the processing of Personal Data.
Data Subject: Any of the people belonging in any of the categories mentioned below;
A. The users of Company’s website.
B. The guests (including potential guests) of Hotel Neoma.
C. People attending the premises of Hotel Neoma.
D. The suppliers of the Company.
E. Job applicants at the Company.
Personal data: Any information that can directly or indirectly identify a natural person (the “Data Subject”), such as name, surname, address, contact details (telephone number, e-mail address) etc.
Processing: Any operation or set of operations which is performed, whether or not by automated means, on Personal Data or on sets of Personal Data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, searching for information, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of Personal Data of which the Company has or will become aware, either directly from you through the website or under the transaction relationship with the Company.
Data Controller: A natural or legal person, which determines the purposes and means of the processing of Personal Data.
Data Processor: A natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Data Controller, under the article 28 of the General Data Protection Regulation E.U. 679/2016 (hereinafter “G.D.P.R.”).
Recipient: A natural or legal person, public authority, agency or other body, to which the Personal Data are disclosed, whether a third party or not.
Special categories of personal data: Personal Data, revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership, data concerning health or data concerning a natural person’s sex life or sexual orientation.
3. What type of Personal Data the Company collects, which are their retention periods and who are their recipients
The Company collects and processes the following Personal Data of yours on a case-by-case basis:
| Activity/ Communication channel | Personal Data Categories | Retention Period | Recipients |
|---|---|---|---|
| Visiting neomahotel.com | Personal Data of website users: IP address, date and time of access, access provider, browser and its version, operating system and its version |
2 days | Providers of IT support services (Data Processors) |
| Communication via Chatbot operating at the neomahotel.com | Chatbot users: Name, Surname, e-mail and the content of messagesNOTE: Communication with Chatbot is carried out through the secure environment of “BM RATE PARITY LTD”, acting as a Data Controller, after redirection. |
6 months | “BM RATE PARITY LTD” (Data Controller) |
| Booking a room via “Book a Room” at neomahotel.com | Personal Data of website users:
Mandatory data: Name, Surname, e-mail address, telephone Optional Data: Postal Address, City/Region, Territory, Postal Code, Company/Organization, Purpose of Travel, Comments/ Special Guidance NOTE: Booking a room via “Book a Room” at neomahotel.com is carried out through the secure environment of “Webhotelier”, acting as a Data Processor, after redirection. |
5 years | “Webhotelier”, acting as a Data Processor of the Company.
Accounting service providers (Data Processors) Providers of IT support services (Data Processors) Financial institutions, to the extent necessary for the execution of transactions. Tax authorities, in accordance with applicable tax legislation. Lawyers, in so far as this is necessary for the exercise of the Company’s rights and the protection of its legitimate interests. The competent judicial, prosecutorial and police authorities, in case needed. |
| Reserving a table via “Reserve a Table” at neomahotel.com | Personal Data of website users:
Mandatory data: Name, Surname, Country Code, mobile number and e-mail address Optional Data: Special Occasions, Dietary Restrictions, Reservation Notes NOTE: Reserving a table via “Reserve a Table” at neomahotel.com is carried out through the secure environment of “Innopolium Private Company”, acting as a Data Processor, after redirection. |
5 years | “Innopolium Private Company”, acting as a Data Processor of the Company.
Accounting service providers (Data Processors) Providers of IT support services (Data Processors) Financial institutions, to the extent necessary for the execution of transactions. Tax authorities, in accordance with applicable tax legislation. Lawyers, in so far as this is necessary for the exercise of the Company’s rights and the protection of its legitimate interests. The competent judicial, prosecutorial and police authorities, in case needed. |
| Booking a room through the digital platform “Booking” | Personal Data of Booking users/ Company’s guests: Name, Surname, Country |
5 years | Accounting service providers (Data Processors)
Providers of IT support services (Data Processors) Financial institutions, to the extent necessary for the execution of transactions. Tax authorities, in accordance with applicable tax legislation. Lawyers, in so far as this is necessary for the exercise of the Company’s rights and the protection of its legitimate interests. The competent judicial, prosecutorial and police authorities, in case needed. |
| Booking a room through the digital platforms; “EXPEDIA” “HOTELBEDS” “TABLET HOTELS” “OTS GLOBE” |
Personal Data of Booking users/ Company’s guests: Name, Surname, mobile number |
5 years | Accounting service providers (Data Processors)
Providers of IT support services (Data Processors) Financial institutions, to the extent necessary for the execution of transactions. Tax authorities, in accordance with applicable tax legislation. Lawyers, in so far as this is necessary for the exercise of the Company’s rights and the protection of its legitimate interests. The competent judicial, prosecutorial and police authorities, in case needed. |
| ➢ Booking a room directly with the Company or through travel agencies
➢ Filling Company’s Registration Form during a guest’s stay at Hotel Neoma |
Personal Data of Company’s Guests:
Mandatory Data: Optional Data: Special Occasions, Dietary Restrictions, Reservation Notes |
5 years | Accounting service providers (Data Processors)
Providers of IT support services (Data Processors) Financial institutions, to the extent necessary for the execution of transactions Tax authorities, in accordance with applicable tax legislation Lawyers, in so far as this is necessary for the exercise of the Company’s rights and the protection of its legitimate interests. The competent judicial, prosecutorial and police authorities, in case needed. |
| Reserving a table directly with the Company | Personal Data of Company’s clients:
Mandatory data: Name, Surname, Country Code, mobile number and e-mail address Optional Data: any Special Occasion, any Dietary Restriction, any Reservation Notes |
5 years | Accounting service providers (Data Processors)
Providers of IT support services (Data Processors) Financial institutions, to the extent necessary for the execution of transactions. Tax authorities, in accordance with applicable tax legislation. Lawyers, in so far as this is necessary for the exercise of the Company’s rights and the protection of its legitimate interests. The competent judicial, prosecutorial and police authorities, in case needed. |
| CCTV operation at the premises of Hotel Neoma | Personal Data of people visiting Company’s premises: Image and voice |
3 days
For longer periods in case of an incident involving the Company and/ or a third party |
The competent judicial, prosecutorial and police authorities, should information be necessary for the investigation of a criminal offence involving persons or property of the Controller.
Τhe victim or the offender, should the data constitute evidence of a criminal offence. |
| Providing services and/or goods to the Company | Personal Data of Company’s Suppliers: Name, Surname, father’s name number of National Identity Card or Passport, Tax Identification Number, postal and e-mail address, telephone number, profession |
5 years | Accounting service providers (Data Processors)
Providers of IT support services (Data Processors) Financial institutions, to the extent necessary for the execution of transactions. Tax authorities, in accordance with applicable tax legislation. Lawyers, in so far as this is necessary for the exercise of the Company’s rights and the protection of its legitimate interests. The competent judicial, prosecutorial and police authorities, in case needed. |
| Applying for a job at the Company | Personal Data of job applicants: Surname, Name, father’s name, gender, date and place of birth, ID number/ passport number, postal and e-mail address, telephone number, marital status, education and qualifications data, work experience, department/ position of interest, language skills, military obligations |
1 year | Providers of IT support services (Data Processors) |
4. Processing of special categories of personal data
Our Company does not process special categories of personal data through its website, such as data related to your racial or ethnic origin, your religious or philosophical beliefs, health data or data related to your sex life or your sexual orientation, as the above data are not necessary for us.
For this reason, we kindly ask you not to include such data when filling in message fields, the communication form or while using the chatbot.
However, special categories of personal data may be processed by the Company on your own initiative and as an integral part of a request you may have (indicative example: preferences during the reservation regarding your stay or the way of serving you, particular requests or needs regarding our provision of services to you).
We store this information to provide the necessary assistance and information in case of an emergency.
5. Personal Data concerning minors
Company’s website does not concern natural persons, who have not reached the age of eighteen (18).
Therefore, our Company may process Personal Data of minors only on their parents’ initiative and/or with their parents’ consent (indicative example: child’s preferences, particular requests or needs regarding our provision of services to it).
6. CCTV and security information
For the safety and security of guests, employees and visitors and for the protection of people and property, CCTV cameras may operate in selected areas of the Hotel Neoma.
CCTV will not be installed in areas where individuals have a reasonable expectation of privacy, such as guest rooms, bathrooms or changing rooms.
7. How do we collect your Personal Data
We may collect Personal Data:
- directly from you
- when you make a reservation
- when you communicate with Hotel Neoma
- when you check in or use our Company’s services
- through online booking platforms or travel agencies (as stated in the above table)
- through Company’s website
- when you use the restaurant at Hotel Neoma or its swimming pool
- through service providers acting on Company’s behalf
- through CCTV systems installed at Hotel Neoma, where applicable
- where required or permitted by law, from public authorities or other lawful sources.
Please note that when you make a reservation through an online travel agency or another booking platform, that platform may also process your Personal Data as a separate data controller in accordance with its own privacy policy.
8. Purposes of Processing
❖ Our Company processes Personal Data in order to:
- ✓ receive and manage reservations
- ✓ confirm and administer bookings
- ✓ provide accommodation
- ✓ manage check-in and check-out
- ✓ communicate with guests
- ✓ fulfil special requests
- ✓ manage cancellations and amendments
- ✓ provide customer service.
❖ Our Company may process Personal Data where necessary to comply with obligations imposed by applicable Greek or EU legislation, including obligations relating to:
- ✓ guest registration
- ✓ accounting and taxation
- ✓ financial records
- ✓ invoicing
- ✓ regulatory requirements
- ✓ lawful requests from competent authorities.
❖ Our Company processes Personal Data where necessary to:
- ✓ manage restaurant reservations
- ✓ communicate with customers
- ✓ provide restaurant services
- ✓ fulfil legitimate customer requests
- ✓ manage payments and billing
- ✓ respond to complaints or enquiries.
If you voluntarily provide information about allergies, intolerances or dietary requirements, we may use such information solely to provide the requested service and to take reasonable measures in response to your request.
❖ Our Company may process Personal Data where necessary to:
- ✓ manage access to the swimming pool
- ✓ maintain the safety of guests
- ✓ comply with applicable safety requirements
- ✓ investigate incidents
- ✓ respond to emergencies.
❖ Where CCTV is used, the processing is carried out for purposes including:
- ✓ protection of guests, employees and visitors
- ✓ prevention and investigation of incidents
- ✓ protection of the property and guests of Hotel Neoma
- ✓ prevention of unlawful activities
- ✓ establishment, exercise or defense of legal claims.
❖ Our Company may process Personal Data to respond to:
- ✓ enquiries
- ✓ requests
- ✓ complaints
- ✓ feedback
- ✓ disputes
- ✓ claims.
❖ Where permitted by applicable law, our Company may send you information about:
- ✓ the services offered by Hotel Neoma;
- ✓ special offers;
- ✓ promotions;
- ✓ events;
- ✓ restaurant services;
- ✓ other services offered by Hotel Neoma.
9. Automated Decision -making and Profiling
The Company does not make decisions concerning guests based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect them, unless specifically stated otherwise and appropriate safeguards are provided in accordance with applicable law.
10. Legal Bases of Processing
Company processes Personal Data only for specified and legitimate purposes.
Depending on the circumstances, the legal basis for processing may include:
- ✓ Article 6(1)(b) GDPR – performance of a contract, where processing is necessary to provide accommodation or other services requested by you.
- ✓ Article 6(1)(c) GDPR – compliance with a legal obligation, where processing is required by applicable law.
- ✓ Article 6(1)(f) GDPR – legitimate interests, where processing is necessary for Company’s legitimate interests and those interests are not overridden by your rights and freedoms.
- ✓ Article 6(1)(a) GDPR – consent, where you have provided your consent and consent is required.
- ✓ Article 6(1)(d) GDPR – protection of vital interests, in exceptional circumstances where processing is necessary to protect someone’s life or physical integrity.
11. Security of your Personal Data
Our company applies reasonable and appropriate technical and organizational security measures to ensure an appropriate level of security and protection of your Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored or otherwise processed as well as to ensure the preservation of both technical and physical security in accordance with article 32 of the GDPR. The Company applies the principles of processing in accordance with the art. 5 of GDPR, in order to ensure the availability, integrity, and confidentiality of your Personal Data.
12. Transmission of Personal Data
Some of our service providers may process Personal Data outside the European Economic Area (“EEA”). Where Personal Data is transferred outside the EEA, we will ensure that the transfer is carried out in accordance with Chapter V of G.D.P.R. and is supported by an appropriate legal mechanism, such as:
- an adequacy decision of the European Commission,
- Standard Contractual Clauses,
- another lawful transfer mechanism under applicable data protection legislation.
13. What are your data protection rights
13.1. We would like to make sure you are fully aware of all of your data protection rights. Some of the rights apply generally, while certain rights apply only in certain cases.
Every Data Subject is entitled to the following:
✓ The right to access – You have the right to request us for copies of your Personal Data held by us. You also have the right to access to information regarding the purposes, categories, receivers, and the time-period of storing the Personal Data processed by us. For any further copies, we may charge you a small fee for this service.
✓ The right to rectification – You have the right to request that we correct any information you believe is inaccurate. You are also entitled to request us to complete the information you believe is incomplete.
✓ The right to erasure – You have the right to request that we erase your Personal Data, under certain conditions. Please note that we may retain your Personal Data in order to comply with specific legal obligations under European Union or Greek legislation, or in order to establish, exercise or support our legal claims.
✓ The right to restrict processing – You have the right to request that we restrict the processing of your Personal Data, under the following conditions;
(a) if you contest the accuracy of your Personal Data for a time period that enables us to verify the accuracy of the Personal Data,
(b) processing is unlawful and instead of erasing Personal Data you opt for restriction,
(c) we no longer need your Personal Data but you require the Personal Data for the establishment, exercise or defense of legal claims, or
(d) you have objected to your Personal Data processing by us, in the context of your right to object (as described below).
✓ The right to object to processing – You have the right to object to our processing of your Personal Data at any time based on grounds specific to your situation if such processing is for direct marketing or if it is based on the legal basis of a public interest or of a legitimate interest of Company.
In case you object to your Personal Data process on the legal basis of a public interest or of a legitimate interest, we will no longer process your Personal Data for these purposes unless we have overriding legitimate grounds for continuing processing your Personal Data or for the establishment, exercise, or defense of legal claims. In case of processing your data for direct marketing purposes you have the right to object at any time and ask Company to cease processing your data for these direct marketing purposes by sending an e-mail to the following address. In such a case, the Company will cease processing your Personal Data immediately for that specific reason.
13.2. If you would like to exercise any of these rights, you have the following options;
❖ Contact us at the e-mail: manager@neomahotelcom
❖ Send us a letter at the postal address: Mouson 13, 11741, Athens, Greece
13.3. In the context of exercising any of your rights, as described above, we will provide you with information regarding your request without any delay and in any case within one month from receiving your request. That deadline might be suspended for two more months, if needed and especially after taking into consideration request’s complexity and the number of requests.
13.4. Moreover, you have the right to file a complaint before the competent supervisory authority in the Member State in which you have your residence or place of work or is the place of the alleged infringement, if you consider that the processing of your personal data infringes the GDPR (art. 77 GDPR) and that your request has not been sufficiently satisfied by us.
The competent supervisory authority in Greece is the Hellenic Data Protection Authority (1–3 Kifisias Avenue, 115 23, Athens, +30 2106475600, contact@dpa.gr).
14. Privacy policies of other webpages
Our Company’s webpage may contain links to other webpages. Our Privacy Policy applies only to our Company, so if you click on a link to another webpage, you should read their Privacy Policy.
15. Changes to our Privacy Policy
We may make changes to this Privacy Policy from time to time. Any changes will become effective upon upload of the revised version of this Privacy Policy on Company’s Webpage. You are requested to review this Privacy Policy periodically to remain informed about how we are protecting your Personal Data.
16. How to contact us
If you have any questions about our Privacy Policy and/or the Personal Data we have processed, you can communicate with us in the following ways:
❖ Contact us at the e-mail: manager@neomahotelcom
❖ Call us at: tel 2130883945
❖ Send us a letter at the postal address: Mouson 13, 11741, Athens, Greece
