Introduction
Melini Hotel Suites values your privacy and is committed to protecting your personal information.
This Privacy Policy (‘Policy’) explains how Melini Hotels Suites (‘Hotel’, ‘we’, ‘us’, ‘our’), a partnership incorporated under the laws of the Republic of Cyprus with registration number Σ 7597, being a Data Controller, collects and processes your personal information in accordance with the General Data Protection Regulation (2016/679) and the applicable Data Protection Laws of the Republic of Cyprus (‘the Law’).
Definitions
‘Data Controller’ means the person or organization which determines when, why and how to process Personal Data and implements appropriate technical and organizational measures to comply with the Law;
‘Data Protection Officer’ means the person who is formally appointed with the purpose of ensuring that we are aware of and comply with our data protection responsibilities and obligations according to the Law;
‘Data Subject’ means a living, identified or identifiable natural person about whom we hold Personal Data;
‘Personal data’ means data about the Data Subject who can be identified: (a) from that data; or (b) from that data and other information to which we have or are likely to have access.
‘Processing’ means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaption or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure or destruction;
‘Special Categories of Personal Data’ means the information revealing racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, physical or mental health conditions, sexual life, sexual orientation, biometric or genetic data.
For the purposes of this Policy, Personal Data includes Special Categories of Personal Data;
‘Third Party’ means the recipient of your Personal Data as defined below.
The kind of information we collect about you
The purpose of the Processing of your Personal Data is largely based on each of our services that you have requested:
- Contact details (e.g. name, email address, physical address, phone number);
- Payment information (e.g. payment card information);
- Any additional information that can be necessary for the provision of particular services.
In the event that you provide us with Personal Data about other individuals (e.g. your co-guest), you warrant to us that you have obtained such individuals’ permission to do so.
We do not collect or process Personal Data of children without prior consent from their parents or legal guardian.
We also may collect images and video data via security cameras located at the public areas, entrances and exits of our premises for monitoring and security purposes. Footage is securely stored and is only accessible to authorized employees. Footage may be shared with competent authorities if required and/or mandatory under the provisions of any legislation. For this purpose, we have placed signs inside and outside of our premises.
On what legal basis do we process your Personal Data
We may collect and process your Personal Data for any or all of the following purposes:
a) Are necessary to enter into a contract and/or to perform the contract in order to fulfill the services that you have requested (e.g. book a reservation, check-in, select your room and check out, payments);
b) You have given consent to the processing of your Personal Data for a specific purpose (e.g. consent for marketing and sales promotions – by email, by text etc.)
Consent may be withdrawn at any time by contacting our Data Protection Officer at the contact details provided below.
c) Are necessary for the purposes of our legitimate interests or of a third party (e.g. legal claims), except where these interests are overridden by your interests or fundamental rights and freedoms (especially in cases where the Data Subject is a child);
d) Is required for complying with the Law and/or any applicable law (e.g. the obligation of keeping records).
Who Receives your Personal Data
Your Personal Data are only accessible by the following Third Parties:
a) The employees with a need for access to fulfill the purposes set out above. All employees have signed a Confidentiality and Non – Disclosure Agreement;
b) Any of our sub-contractors and/or service providers, including but not limited to IT service providers, your travel agency-if any;
c) E-commerce companies/booking agents (e.g. booking.com) which offer online reservation services. Since the Personal Data (e.g. names, contact details, payment details, name of guests travelling with you and any other preference you specified when making a booking) is collected when making a reservation, these Personal Data will also be shared with them.
In case of an absence of your consent, your Personal Data will not be disclosed to any Third Party, other than the above-mentioned, unless the disclosure is required and/or mandatory under the provisions of any legislation, regulation or upon governmental, supervisory, competent authority request.
When we enter to an engagement with a Third Party pursuant to which your Personal Data may be processed by that party, we enter into a processing agreement with that party in order to ensure that this Third Party processes the Personal Data strictly according to our instructions and implements the appropriate administrative, physical and technical measures to protect the Personal Data from unauthorized or accidental use, collection, access, damage, loss or disclosure.
Transferring your Personal Data outside European Union (‘EU’) and European Economic Area (‘EEA’)
We generally do not transfer your Personal Data to countries outside of EU and EEA (‘Third Countries’), except where required by the purposes set out in this Policy. If we need to transfer any Personal Data to Third Countries, we always ensure that the transfer meets the relevant requirements of the Law and we take all steps required to ensure that your Personal Data continues to receive our standards of protection.
When can Personal Data be transferred outside of the EU and the EEA
- If the European Commission has made a finding that the third country, territory or sectors within the third country ensures an adequate level of privacy protection (Adequacy Decision);
- The Third Party has signed the standard data protection clauses (i.e. contact) adopted by the European Commission and agreed to apply the privacy standards of protection of the European Union;
- The Data Subject has provided consent to the transfer.
Retention of Personal Data:
We will retain your Personal Data for as long as it is necessary to fulfill the purpose for which it was collected or for as long as is required/permitted by applicable law.
The camera recordings will be retained for two (2) weeks.
Protection of Personal Data:
To safeguard your Personal Data from unauthorized access, collection, use, damage, loss disclosure, copying or similar risks, we have introduced appropriate administrative, physical and technical measures such as up to date antivirus protection, encryption and the use of privacy filters to secure all storage and transmission of Personal Data to Third Parties. We also allow access to Personal Data only to those employees who need to know such data and they will only process your Personal Data on our instructions.
However, no method of transmission over the internet or method of electronic storage is completely secure. While security cannot be guarantee, we try to protect the security of the Data Subject’s Personal Data and we constantly review and enhance our information security measures.
Your rights in relation to your Personal Data
Right to access:
Request access to your Personal Data (commonly referred to as a “data subject access request”). This enables you to receive a copy of your Personal Data that we hold about you;
Right to rectification:
Request to correct or update any of your Personal Data which the Hotel holds. This enables you to have any incomplete or inaccurate information the Hotel holds about you corrected. We strive to retain only Personal Data that is accurate, complete and up to date;
Right to data portability:
Request the transfer of your Personal Data to another party;
Right to erasure:
Request to delete your Personal Data. However, we may need to retain certain information for legal or administrative purposes, such as record keeping and detect fraudulent activities.
Right to restrict processing:
Request to restrict the use of your Personal Data;
Right to object:
You have the right to object to the collection and use of your Personal Data (e.g. when we use your Personal Data on the basis of your consent, you can withdraw that consent at any time);
How can you exercise your rights in relation to your Personal Data:
If you wish to exercise any of your rights, you may contact our Data Protection Officer in writing or via email at the contact details provided below:
Name: PANAYIOTIS Z. TOULOURAS LLC
Address: 13 Griva Digeni Avenue, 5th floor, office 501, 6030, Larnaca, Cyprus
Email: [email protected]
The Data Protection Officer has the right to require the individual making the request to provide certain identification documents/information to be able to verify his/her identity.
The Data Protection Officer will respond to your requests within thirty (30) days after receiving your email/letter.
Right to lodge a complaint:
You have the right to lodge a complaint about the use of your Personal Data by contacting the Office of the Commissioner for Personal Data Protection in Cyprus at the contact details below:
Office address: Iasonos 1, 1082 Nicosia, Cyprus
Postal address: P.O. Box 23378, 1682 Nicosia, Cyprus
Tel: +357 22818456
Fax: +357 22304565
Email: commissionerdataprotection.gov.cy
Effect of Policy and Changes to Policy
We keep this Policy under review, and we may modify it from time to time without any prior notice. You should consult this page periodically to ensure that you are aware of any such modifications/updates.
COOKIES POLICY
Our website uses cookie technology. Cookies are small files saved to your computer or mobile device that track, save and store information as well as your interactions and usage of our website. The primary purpose for collection of data from users to our site is to allow us to provide a smooth efficient and personalized experience while using our site. Users are advised that if they wish to deny the use and saving of cookies from this website on to their computers hard drive, they should take necessary steps within their web browsers security settings to block all cookies from this website and its external serving vendors.
We also collect other forms of non-personal information such as browsers used to access our website, search terms used to find the website, traffic referrals and links to our website. Cookies collected by us are used to enable certain functions and tools of our website, assist in the navigation of the website, track resources and data used on this site and remember computer settings. You may prevent your computer from accepting cookies by modifying the properties on your web browser (see your browser’s “Help” option on how to do this).
We also use the services of Google Analytics software to analyze traffic to our website. Neither of these programs creates individual profile for visitors, nor do we collect any personally identification information using these services. Data collected regarding site usage is compiled in aggregate to improve the performance of the website. If you do not wish your information to be included in this aggregated data through Google Analytics, modify the properties on your web browser to prevent your computer or mobile device from accepting cookies. Please read the Google privacy policy.
Types of Cookies
Strictly Necessary Cookies:
These cookies are necessary for the website in order to enable you to use certain features of the website, such as request specific services, setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.
Functionality Cookies:
These are used to allow the website to remember choices you make (such as language) and provide enhanced features to improve your web experience.
Navigation Cookies:
These cookies enable the site to function correctly and are used to gather information about how visitors use the site. This information is used to compile reports and help us to improve the site. Cookies gather information in anonymous form, including the number of visitors to the site, where visitors came from and the pages they viewed.
Analytical Cookies:
These cookies are used to produce statistical analyses of the way users navigate the site (using computers or mobile devices), the number of pages viewed, or the number of clicks made on a page during navigation of a site.
Disabling Cookies
You can prevent the setting cookies by adjusting the settings on your browser (see your browser’s “Help” option on how to do this). Be aware that disabling cookies may affect the functionality of this and other websites that you visit.Suites