P.A.L.A.D.A., limited liability company, registration number 34737413, with its registered office at: Gagarinskoe Plateau Street, 5, Odessa, Ukraine, 65009 (hereinafter: “Company”) respects the personal rights of its Guests, hence it prepared this Privacy Policy, which is available in electronic format at the Company's website at https://ok-odessa.com (hereinafter: the “website”) as well as in print format on reception in the hotel.
This Privacy Policy describes how the Company, which is providing hotel services under the MOZART HOTEL GROUP trademark, and its Affiliates and Subsidiaries (“we” or “us”) collects, uses, consults or otherwise processes your Personal Data.
The Company operates in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data (hereinafter as “GDPR”), and repealing Directive 95/46/EC (EU GDPR) as well as the current national Data Privacy Acts. When using the Internet, we are committed to the protection of your Personal Data by the current Law of Ukraine “On the Protection of Personal Data” dated 01.06.2010 No. 2297-VI, and by GDPR.
This Policy is developed to explain our practices regarding the Personal Data we collect from you or about you from our website, through written or verbal communications with us, when you visit one of our hotels from the MOZART HOTEL GROUP, or from other sources. We use Personal Data primarily to administer, provide, develop and maintain the hotel services, process your reservations, optimize your experience with respect to the services and individualize the communication with you.
Please read this Policy carefully to understand how and for what purposes we process your Personal Data.
By using the website or using any of our services and by agreeing to this Policy, you agree to the collection and use of Personal Data as described in this Policy.
Controller: A legal person, P.A.L.A.D.A., LLC, registration number 34737413, with its registered office at: Gagarinskoe Plateau Street, 5, Odessa, Ukraine, 65009, who determines the purposes and means of the processing of Personal Data.
Consent of the Data Subject: means any freely given, specific, informed and unambiguous indication of the Data Subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of Personal Data relating to him or her;
Processor: A natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.
Recipient: A natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not.
Third Party: A natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorized to process Personal Data.
Supervisory Authority: An independent public authority which is established by a Member State pursuant to Article 51 of the GDPR. Specifically, Commissioner for Human Rights of the Verkhovna Rada of Ukraine, address: 01008, Kiev, Institutskaya st., 21/8; phone - +38 (044) 253-75-89; +38 (080) 050-17-20; Email: hotline@ombudsman.gov.ua.
Personal Data: Any information relating to an identified or identifiable natural person (“Data Subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Processing: Any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
MOZART HOTEL GROUP: Companies from the MOZART HOTEL GROUP chain which can be based worldwide.
ODESSA HOTEL: (furthermore also as hotel) is a hotel operated by the Controller and located at Gagarinskoe Plateau Street, 5, Odessa, Ukraine, 65009.
Standard Contractual Clauses: Sets of standard contractual clauses for transfers as adopted by the European Commission for the international transfer of Personal Data.
Personal Data Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
We collect and process your Personal Data only where permitted by law. We only collect Personal Data relevant for the purpose described in this Privacy Policy. This Personal Data may include:
In the case of online, personal (paper-based) or phone reservations, we request/can request that the Guest makes the following information available:
Providing the required information by the Guests is a precondition for using hotel services. By signing the registration card, Guests consent to the hotel processing their Personal Data provided by filling in the registration card in order to verify that the contract was concluded and/or performed, as well as to possibly enforce claims.
Also we may ask for information about your joint travelers, including their names and additional information.
We draw your attention to the fact that in accordance with paragraph 2 of Art. 8 of the Law of Ukraine “On the Protection of Personal Data”, your Personal Data is located in the hotel you stay at.
The table below sets out why we process Personal Data of the Guests, the legal basis for the processing and the associated retention period. The following retention periods are applicable to personal data which is stored both in electronic and paper forms.
|
Activity |
Legitimate purpose for processing and storage of Personal Data |
Retention period |
1. |
Managing the reservation of rooms, submitting notifications to migration authorities, storage of legal documents in compliance with accounting standards. |
Performance of a contract with the customer. Necessary to comply with a legal obligation. |
3 years. |
2. |
Managing your stay at the hotel:
|
Performance of a contract with the customer. Necessary for Company’s legitimate interest in running its business and providing our guests with high quality services. |
For the duration of your stay at the hotel. |
|
30 calendar days. |
||
3. |
Managing hotel’s relationship with customers before, during and after stay at the hotel:
|
Performance of a contract with the customer and for the management of customer’s membership in the loyalty program. Necessary for Company’s legitimate interests in promoting its services, performing direct marketing activities (taking into account your commercial relationship with one of Company’s legal entities) and improving its services. |
3 years from the last date on which you have interacted with us in any way, if you are not a member of the loyalty program. 6 years from the last date on which you have interacted with us in any way, if you are a member of the loyalty program. |
4. |
Improving hotel services by:
|
Performance of contract with the customer in relation to the management of your membership in the loyalty program. Necessary for Company’s legitimate interests in promoting its services, performing direct marketing activities (taking into account your commercial relationship with one of MOZART HOTEL GROUP legal entities) and improving our services. |
3 years from the last date on which you have interacted with us in any way, if you are not a member of the loyalty program. 6 years from the last date on which you have interacted with us in any way, if you are a member of the loyalty program. |
5. |
Use a trusted third party to cross-check, analyse and combine your collected data at the time of booking or at the time of your stay, in order to determine your interests and develop your customer profile and to allow us to send you personalized offers. |
Necessary for Company’s legitimate interests in promoting its services, performing direct marketing activities (taking into account your commercial relationship with one of the MOZART HOTEL GROUP legal entities) and improving our services. |
3 years from the last date on which you have interacted with us in any way, if you are not a member of the loyalty program. 6 years from the last date on which you have interacted with us in any way, if you are a member of the loyalty program. |
6. |
Improving the Company’s services, in particular:
|
Performance of contract with the customer (for the management of customer membership in the loyalty program) Necessary for Company’s legitimate interests in promoting hotel services, performing direct marketing activities (taking into account your commercial relationship with one of MOZART HOTEL GROUP legal entities) and improving its services. |
3 years from the last date on which you have interacted with us in any way, if you are not a member of the loyalty program. 6 years from the last date on which you have interacted with us in any way, if you are a member of the loyalty program. 6 years from the date of closure of your file in case of a claim or a complaint. |
7. |
Securing and enhancing your use of website and services by:
|
Necessary for Company’s legitimate interests in running its business, provision of administration and IT services and network security to prevent fraud |
3 years from the last date on which you have interacted with us in any way. |
8. |
Internal management of lists of customers having behaved inappropriately during their stay at the hotel (aggressive and anti-social behaviour, non-compliance with safety regulations, theft, damage and vandalism or payment incidents). |
Necessary for Company’s legitimate interests in running its business and to prevent fraud and the abuse of hotel property and staff. |
Up to 3 years from the recording of an incident. |
9. |
Using services to search for persons staying in MOZART HOTEL GROUP hotels in the event of serious events affecting the hotel in question (natural disasters, terrorist attacks, etc.). |
Protection of the vital interests of the customers. |
For the duration of the event. |
10. |
Conforming to any applicable legislation (for example, storing of accounting documents), including: Managing requests to unsubscribe from newsletters, promotions, tourist offers and satisfaction surveys Managing requests regarding Personal Data. |
Necessary to comply with a legal obligation. |
3 years. |
It is important for us to keep your Personal Data up to date and accurate at all times, why we may import Personal Data about you from external sources such as public registers. When required by law, the consent for the processing of certain types of Personal Data or for certain forms of processing will be obtained from you before processing takes place.
We may also collect information about you from third parties, including information from airlines, payment systems and other partners; from online social services consistent with your settings on such services; and from other third-party sources that are lawfully entitled to share your data with us. The Company uses and shares this information for the purposes described in this Policy.
In order to offer you the high level of hotel services, we may share your Personal Data among members of MOZART HOTEL GROUP, our service providers, and other third parties as set forth in detail below:
We share your data with a number of authorised employees and departments in the MOZART HOTEL GROUP in order to offer you the best experience in our hotels. The following teams may have access to your data:
In particular, the information related to your stays, preferences, satisfaction and, if the case may be, your loyalty program membership are shared between the hotels operating under the MOZART HOTEL GROUP brand. This information is used to improve the quality of service and your experience in each of these hotels.
We may share your Personal Data with third-party providers of hotel services such as reception services, spa treatments or food delivery services. All our service providers are contractually obligated to protect your Personal Data and may not otherwise use or share it, except as required by law or stated in the contract.
Your Personal Data may be disclosed to governmental structures or public authorities if their requests are made on a legal basis or to protect the rights, privacy, safety or property of the Company according to the applicable law.
For the purposes described in this Policy, we may transfer your Personal Data to internal or external recipients who may be located in countries offering different levels of Personal Data protection.
By making a reservation, visiting or staying at the hotel, you understand that MOZART HOTEL GROUP may transfer your Personal Data worldwide. Consequently, in addition to implementation of this Policy, the Company employs appropriate measures to ensure secure transfer of your Personal Data to other MOZART HOTEL GROUP hotels or to an external recipient located in a country offering a different level of privacy from that in the country where the Personal Data was collected.
Your information may be sent, in particular as part of the reservation process, to MOZART HOTEL GROUP hotels or divisions located in Ukraine or in Russia.
In case you wish to obtain more details about our data transfer safeguards and the mechanisms in place, you may contact us at gdpr@ok-odessa.com.
The Loyalty Program of MOZART HOTEL GROUP is available to the guests throughout the hotels of MOZART HOTEL GROUP located in EEA and outside of it. The loyalty program is operated by Hotel Management Company s.r.o. (limited liability company registered under the legislation of Czech Republic) in cooperation with other companies working under the MOZART HOTEL GROUP trademark.
The Loyalty Program is designed to enable its members to enjoy various privileges during their stay at hotels of MOZART HOTEL GROUP.
A Guest may join the Loyalty Program in any of the following ways:
- During his/her stay at a hotel by filling a special registration form at the reception-desk;
- By registering online at any of the websites of MOZART HOTEL GROUP hotels.
Any member who joins the Loyalty Program further agrees to receive commercial information by email from the Loyalty Program, including promotions for members only. If the member no longer wishes to receive commercial communications by email, he/she may unsubscribe at any time from these commercial offers by clicking on the unsubscribe link at the end of the email or via his/her personal account. This action has no effect on his/her membership.
When you visit and interact with the website and other applications, the Company collects information that does not directly identify you about your use of the website, such as a catalog of the website pages you visit, and the number of visits to our website (“Other Information”). We use Other Information to deliver you email, online (on our website and other websites) and mobile advertisements. The Company may also use Other Information to allow third-party partners to recognize you as a MOZART HOTEL GROUP client when you visit the partner’s website or app, or to recognize you as one of their customers when you visit MOZART HOTEL GROUP websites or apps so that they may provide more relevant offers to you.
The website uses cookies and other technologies (such as “pixel tags,” “web beacons,” “clear GIFs”, links in emails, JavaScript, device IDs assigned by Google or Apple, or similar technologies) to relation to its digital services.
Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the information you chose to share with us.
You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of the website. If you want to remove or block cookies from your device at any time, you can update your browser settings (consult your browser’s “help” menu to learn how to remove or block Cookies).
The Company may use collected information, or anonymized personal information received from third parties, to understand more about our users. This includes demographic data, such as date of birth, gender and marital status, inferred commercial interests, such as favorite products or hobbies, and other information we may collect from you or from third parties.
Because Other Information does not personally identify you, such information may be disclosed for any purpose where permitted by law. In some instances, we may combine Other Information with your Personal Data. If we do combine any Other Information with your Personal Data, the combined information will be treated by us as Personal Data in accordance with this Policy.
The term “sensitive information” refers to information related to your racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life, or sexual orientation, genetic information, criminal background, and any biometric data used for the purpose of unique identification. We do not generally collect sensitive information unless it is volunteered by you. We may use health data provided by you to serve you better and meet your particular needs (for example, information that you state in the “Notes” section during the reservation procedure).
We do not knowingly collect Personal Data from individuals under 18 years of age. As a parent or legal guardian, please do not to allow your children to submit their Personal Data without your permission.
In the event we learn that we have collected Personal Data from a child under the age of 18 without verification of parental consent, steps will be taken promptly to remove that information. If you believe that we have or may have information from or about a child under 18 years of age, please contact us at gdpr@ok-odessa.com.
The Company takes reasonable measures to: (i) protect Personal Data from unauthorized access, disclosure, alteration or destruction, and (ii) keep Personal Data accurate and up-to-date as appropriate. We also seek to require our partners and service providers with whom we share Personal Data to exercise reasonable efforts to maintain the confidentiality of Personal Data about you.
The Company uses SSL cryptography on its website for online reservations. Any information shared by the Data Subject with the Company shall be encrypted automatically and be protected when transferred through the network. When the information is received by our server, it is decoded by using an individual private key. SSL enables the browser to connect to the website and establish a secure communication channel in a transparent manner. SSL is the most widely used and most successful cryptographic system. In order to use the system, the Data Subjects simply need to verify their browsers' compatibility.
Other security-related activities the Company shall ensure transparency to control and establish how and what Personal Data are transferred by applying data transferring devices, who and when entered which data into the system, and shall also make sure that the system can be restored in the case of a failure. Reports are generated with regard to errors occurring in the course of automated processing. The Company shall manage Personal Data confidentially, and shall not disclose them to unauthorized persons. The Company shall particularly protect Personal Data from unauthorized access, modification, transfer, publication, deletion or destruction as well as from accidental destruction, harm and inaccessibility due to modification of the applied technology. The Company shall take all security measures in order to ensure the technical protection of Personal Data.
For online transactions, we use reasonable technological measures to protect the Personal Data that you transmit to us via our website. Unfortunately, however, no security system or system of transmitting data over the Internet can be guaranteed to be entirely secure.
For your own privacy protection, please do not send payment card numbers or any other confidential personal information to us via email.
We will not contact you by mobile/text messaging or email to ask for your confidential personal information or payment card details. In case of receiving a request about your payment card information by e-mail or SMS, please, do not reply, most probably you are communicating with swindlers.
We have an Internal regulation regarding GDPR for our personnel which is available for our guests at the reception of the hotel.
For the processing of payment card numbers and another financial data we use services of TravelClick service. For more details, you may apply to TravelClick Privacy Policy;
For the collecting of information about your usage of the website we use Google analytics services. For more details, you may apply to Google Privacy Policy;
For the purpose of processing emails we use services of MailChimp. For more details, you may apply to MailChimp Privacy Policy;
For the processing of your reviews and comments about hotels of MOZART HOTEL GROUP we use services of ReviewPro. For more details, you may apply to ReviewPro Privacy Policy.
GDPR grants specific rights, summarized below, which you can in principle exercise free of charge, subject to statutory exceptions. These rights may be limited, for example if fulfilling your request would reveal Personal Data of another person, or if you ask us to delete information which we are required by law to keep or have compelling legitimate interests in keeping.
11.1. Right to withdraw consent
Wherever we rely on your consent, you will be able to withdraw that consent at any time you choose and at your own initiative on our website or by contacting us at unsubscribe@ok-odessa.com . The withdrawal of your consent will not affect the lawfulness of the collection and processing of your data based on your consent up until the moment where you withdraw your consent. Please note that we may have other legal grounds for processing your data for other purposes, such as those set out in this Privacy Policy.
11.2. Right to access and rectify your data
You have the right to access, review, and rectify your Personal Data. You may be entitled to ask us for a copy of your information, to review or correct it if you wish to rectify any information like your name, email address, passwords and/or any other preferences, you can easily do so by logging in to your account on our website (if you have one) or by contacting us at gdpr@ok-odessa.com. You may also request a copy of the Personal Data processed as described in this Privacy Policy.
11.3. Right to erasure
In accordance with GDPR, you have the right to erasure of your Personal Data processed by us as described in this Privacy Policy in case it is no longer needed for the purposes for which the Personal Data was initially collected or processed or in the event you have withdrawn your consent or objected to processing as described in this Privacy Policy and no other legal ground for processing applies. Should you wish to have your Personal Data erased, please file a request via email at unsubscribe@ok-odessa.com .
11.4. Right to restriction of processing
Under certain circumstances described in GDPR, you may ask us to restrict the processing of your Personal Data. This is for example the case when you contest the accuracy of your Personal Data. In such event, we will restrict the processing until we can verify the accuracy of your data.
11.5. Right to object to processing
Under certain circumstances described in GDPR, you may object to the processing of your Personal Data, including where your Personal Data is processed for direct marketing purposes. If you object the processing for marketing purposes, the Company will not process your Personal Data anymore for this purpose.
11.6. Right to data portability
Where you have provided your Personal Data directly to us and where the processing is based on your consent or the performance of a contract between you and us, you have the right to receive the Personal Data processed about you in a structured, commonly used and machine-readable format, and to transmit this data to another service provider.
Should you have unresolved concerns, you have the right to lodge a complaint with a Supervisory Authority where you live or where you believe a breach may have occurred. We encourage you to come to us in the first instance but, to the extent that this right applies to you, you are entitled to complain directly to the relevant Supervisory Authority.
We will make all required updates and changes within the time specified by applicable law and, where permitted by law, may charge an appropriate fee to cover the costs of responding to the request. Such requests must be submitted by email at gdpr@ok-odessa.com or in writing to the following postal address: ODESSA HOTEL, Gagarinskoe Plateau Street, 5, Odessa, Ukraine, 65009. To protect your confidentiality, we can only respond to such requests to the email address that you have registered or otherwise provided to us. Please remember that if you make such a request, we may not be able to provide you with the same quality and variety of services to which you are accustomed.
In addition, in some circumstances based on applicable law, you may request that we cease sharing personal information about you with our business partners or that the Company ceases using personal information about you by contacting via email. We will seek to honor those requests consistently with applicable law.
If you have given us your contact information (mail address, fax number, email address or phone number), we may want to inform you in accordance with any preferences you have expressed, and with your consent where required, about our products and services or invite you to events via email, online advertising, social media, telephone, text message (including SMS and MMS), push notifications, in-app alerts, postal mail, our customer service call center, and other means.
If you prefer not to receive email marketing materials from us, you may opt-out at any time by using the unsubscribe function in the email you receive from us.
The Company may modify this Privacy Policy from time to time. When we make material changes to this Policy we will post a link to the revised Policy on the homepage of our website, and if you have registered for any of our products or services, will may also inform you through a communications channel that you have provided. You can tell when this Policy was last updated by looking at the link and at the date at the top of the Policy. Any changes to our Policy will become effective upon posting of the revised Policy on the website. Use of the website, any of our products and services, and/or providing consent to the updated Policy following such changes constitutes your acceptance of the revised Policy then in effect.
If you have any questions about this Policy or how the Company or MOZART HOTEL GROUP process your Personal Data, please contact us by email at gdpr@ok-odessa.com or by mail to ODESSA HOTEL, Gagarinskoe Plateau Street, 5, Odessa, Ukraine, 65009.