May 24th, 2018
At City Hotel Thessaloniki, we are committed to protecting and respecting your privacy. Please read this policy as it contains important information about how we use personal data that we collect from you or that you provide to us.
Information & Consent
When this policy mentions “booking system,” “booking engine,” “system,” “website,” “platform,” “app,” “webapp,” “services,” “online services,” it refers to all pages and functions under https://citythessaloniki.reserve-online.net/ unless specified otherwise.
By accessing the platform or providing information, you agree to our privacy practices as set out in this privacy statement. We may change this policy from time to time. You should check this policy frequently to ensure you are aware of the most recent version.
When this policy mentions “we,” “us,” or “our,”, “data controller,”, “controller,”, it refers to City Hotel Thessaloniki.
City Hotel Thessaloniki operates this booking system through a data processor, as explained below. For the purposes of the General Data Protection Regulation (“GDPR”) (EU) 2016/679, we are the Data Controller. There is a strict contractual framework between the data controller and the data processor for the protection of your personal information. We are:
City Hotel Thessaloniki “City Hotel - Macedonianhotels SA” 11 Komninon Str. 546 24, Thessaloniki GR
WebHotelier operates this booking system on behalf of City Hotel Thessaloniki and is committed to protecting the privacy of the users of this system. WebHotelier is:
WebHotelier Technologies Limited Mnasiadou 9 (Demokritos Building, Office 16) 1065 Nicosia Cyprus
For the purposes of the GDPR, where WebHotelier processes your personal data on behalf of City Hotel Thessaloniki, WebHotelier is the the Data Processor. When this policy mentions “data processor,” “processor,” “WebHotelier,” it refers to WebHotelier Technologies Limited.
The User may contact WebHotelier's Data Protection Officer:
Data Protection Officer firstname.lastname@example.org
Obligatory nature of providing the data
The data requested in the forms accessible from the booking engine are, in general, mandatory (unless specified otherwise in the required field) to meet the stated purposes. Accordingly, if they are not provided or are not provided correctly, we will be unable to process the request.
Personal data we collect and process
This will include:
- personal information about you which we ask you for (e.g. your name, address, and email address) when you make a booking from our booking engine;
- financial details in order to process your booking when we require pre-payment;
- details of transactions you carry out through our booking engine and details of the fulfilment of your orders.
- our data processor may only collect and process personal data collected and/or processed on behalf of us in accordance with our instructions. WebHotelier cannot process it in any other way or for any other purpose.
We grant permission to our data processor:
- to use your personal information for reserving rooms and/or other services for you at City Hotel Thessaloniki;
- to pass on your financial details to City Hotel Thessaloniki and/or appropriate third party (for example, credit card company) for the purpose of confirming or paying for a booking;
- to use your information for marketing purposes (where you explicitly agree to this); and
- to pre-complete forms and other details on our website to make your next visit to our booking engine easier (e.g. when amending or cancelling a booking).
In the event of registration and/or access through a third-party account, we may collect and access certain information of the User’s profile from the corresponding social network, solely for internal administrative purposes and/or for the purposes indicated above.
Third-party data (e.g. book for a friend)
Unless specifically requested, we ask that you not send us, and you not disclose, on or through the Services or otherwise to us, any Sensitive Personal Data (e.g., social security numbers, national identification number, data related to racial or ethnic origin, political opinions, religion, ideological or other beliefs, health, biometrics or genetic characteristics, criminal background, trade union membership, or administrative or criminal proceedings and sanctions).
Use of Services by Minors
The Services are not directed to individuals under the age of sixteen (16), and we request that they not provide Personal Data through the Services.
Purpose of processing personal data
Depending on the User’s requests, the personal data collected will be processed in accordance with the following purposes:
- To manage the bookings made, including payment management (where applicable) and the management of the user’s requests and preferences.
- To manage registration in loyalty or membership programs, as well as obtaining and redeeming points.
- To manage the User’s contact requests with us through the channels provided to this end.
- To manage the sending of personalised commercial communications from us, by electronic and/or conventional means, in cases in which the User expressly consents.
- To manage the provision of the contracted accommodation service, as well as additional services.
- To manage surveys and/or evaluations regarding the quality of the services provided by us and/or the perception of its image as a company.
The criteria used to determine our retention periods include:
- The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services or if you have a booking that has not yet been fulfilled)
- Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)
- Whether retention is advisable considering our legal position (such as, for statutes of limitations, litigation or regulatory investigations)
Legitimate interest for processing your data
The data processing required in fulfilment of the aforementioned purposes that require the User’s consent cannot be undertaken without said consent.
Likewise, in the event that the User withdraws their consent to any of the processing, this will not affect the legality of the processing carried out previously.
To revoke such consent, the User may contact us through the appropriate channels.
By the same token, in those cases in which it is necessary to process the User’s data for the fulfilment of a legal obligation or for the execution of the existing contractual relationship between us and the User, the processing would be legitimized as it is necessary for compliance with said purposes.
We will use and disclose Personal Data as we believe to be necessary or appropriate:
- to comply with applicable law, including laws outside your country of residence;
- to comply with legal process;
- to respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements;
- to enforce our terms and conditions;
- to protect our operations;
- to protect the rights, privacy, safety or property of our own, you or others; and
- to allow us to pursue available remedies or limit the damages that we may sustain.
We may use and disclose Other Data for any purpose, except where we are not allowed to under applicable law. In some instances, we may combine Other Data with Personal Data (such as combining your name with your location). If we do, we will treat the combined data as Personal Data as long as it is combined.
International transfers of personal data
We may transfer your personal information to our data processor(s) or/and sub-processor(s) based outside of the EEA for the purposes described in this policy. If we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law. These might be the use of model contracts in a form approved by regulators, or having our suppliers sign up to an independent privacy scheme approved by regulators (like the US ‘ Privacy Shield’ scheme).
Our data is stored in the cloud using Amazon Web Services in N. Virginia, USA and in Frankfurt, Germany. If you are accessing any of our systems from outside the USA, you acknowledge that your personal information may be transferred to the USA, a jurisdiction which may have different privacy and data security protections from those of your own jurisdiction, to be processed and stored.
Guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that the information furnished to us is true, accurate, complete and up-to-date. For these purposes, the User is responsible for the truthfulness of all the data communicated and will keep the information updated, so that said data reflects their actual situation.
Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where applicable, of the aspects contained in this document. Also guarantees that he/she has obtained the third party’s authorisation to provide their data to us for the purposes indicated.
Will be responsible for false or inaccurate information provided through the Website and for damages, whether direct or indirect, that this may cause to us or third parties.
Exercise of Rights
The User may contact us at any time free of charge, to:
- To obtain confirmation about whether or not personal data concerning the User are being processed by us.
- To access their personal details.
- To rectify any inaccurate or incomplete data.
- To request the deletion of their personal data when, among other reasons, the data are no longer necessary for the purposes for which they were collected.
- To confirm revocation of consent.
- To obtain from us the limitation of data processing when any of the conditions provided in the data protection regulations are met.
- To request the portability of your data.
Likewise, the user is informed that at any time he/she may file a complaint regarding the protection of their personal data before the competent Data Protection Authority.
We will process the User’s data at all times in an absolute confidential way and maintaining the mandatory duty to secrecy with regard to said data, in accordance with the provisions set out in applicable regulations, and to this end adopting the measures of a technical and organisational nature required to guarantee the security of their data and prevent them from being altered, lost, processed or accessed illegally, depending on the state of the technology, the nature of the stored data and the risks to which they are exposed.
What personal information about you do we collect?
When you directly register to use our services we may ask you to provide certain personal information including your full name, email address, contact number, registration and payment details.
What do we use your personal data for?
We may use your information for the following purposes:
- in the normal course of our business, to allow us to manage your reservation on the basis that processing is necessary in order to perform our contract with you to provide our services;
- to allow us to understand your personal preferences, personalise our services to you as our guest ;
- to store your data to pre-populate fields to make it easier for you to provide information when you return to our sites;
- to communicate with you and send you information about products and services which we think may be of interest to you. You will be able to opt-out of such communications at any time by sending us an email at: email@example.com;
- to validate your information (and, in some cases, match it against information that has been collected by a third party such as travel sites and online intermediaries) to check that the data we hold about our customers/users is accurate, consistent and up to date on the basis that processing is necessary in order to perform our contract with you to provide our services;
- in pursuit of our legitimate interests, to record CCTV footage to ensure the safety and security of our premises, staff and customers;
- to comply with any legal obligations to which we are subject; and
- We shall periodically check that the personal data we store for you is accurate. If you would like to update the personal data we hold about you, please contact us on firstname.lastname@example.org with your request.
- The provision of certain personal information is mandatory if you are to use our services. If you fail to provide such data we shall be unable to provide our services.
Who do we share your information with?
As part f using our services, you consent to us sharing your personal information with the following parties:
- our agents, other service providers and third party partners, who process and store data on our behalf;
- professional advisors;
- law enforcement agencies;
- [if you select via the [opt-in process], trusted third parties whose products, services and other offers we believe may be of interest to you.
- any member of our TOR hotels group and other companies which may be added to our group from time to time.
We may also share your personal information with third parties:
- in the event that we, our business, or substantially all of its assets are acquired by a third party (in which case personal information about customers will be one of the transferred assets);
- if we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply any contract with you; or to protect our rights, property, or safety of our employees, customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
We may transfer yur personal data outside of the European Economic Area (EEA). We shall ensure that any such transfers are lawful and that yur information is kept secure in accordance with the GDPR.
How long do we store your personal data for?
We nly store your personal information for as long as necessary for the purposes provided for in the law (taxation, legal claims, law enforcement)
What are your rights?
Access t your personal data: Yu may request access to a copy of your personal data.
Right t withdraw: Where yu have given your consent for us to use your personal data, you may withdraw your consent at any time. Please contact us if you would like to withdraw your consent and we will delete your data in line with your right to erasure described below.
Rectificatin: Yu may ask us to rectify inaccurate information held about you. If you would like to update the data we hold about you, please contact us using the details below and provide the updated information.
Erasure: Yu may ask us to delete your personal data. If you would like us to delete the personal data we hold about you, please contact us using the details below, specifying why you would like us to delete your personal data.
Prtability: Yu may ask us to provide you with the personal information that we hold about you in a structured, commonly used, machine readable form, or ask for us to send such personal data to another data controller.
Make a cmplaint: Yu may make a complaint about our data processing activities to a supervisory authority, for Greece this is the Data Protection Authority at www.dpa.gr
Yu are advised that if you do not consent to the use and saving of cookies from this website on to your computer hard drive then you should take necessary steps within your web browser security settings to block all cookies from this website and its external serving vendors.
Other cokies may be stored on your computer hard drive by external vendors when this website uses referral programs, sponsored links or adverts. Such cookies are used for conversion and referral tracking and typically expire after 30 days, though some may take longer. It should be noted that no personal information is stored, saved or collected.
Security and Data Storage
We will treat all of your information in strict confidence and we will endeavour to take all reasonable steps to keep your personal information secure once it has been transferred to our systems. We adopt appropriate data collection, storage and processing practices and security measures to protect against unauthorised access, alteration, disclosure or destruction of your personal information, and data stored on the website and associated database.
Please note that the internet is not a secure medium and we cannot guarantee the security of any data you disclose online. You accept the inherent security risks of providing information and dealing online over the Internet and will not hold us liable for any data breach.
If we change this Privacy Plicy we shall notify you by means of notice on our site homepage.
This Privacy Plicy was last amended on 10 May 2018