1. What Personal Data do we collect?
Your Personal Data collected by Star Convention Hotel can be classified into the following:
Type of Personal Data
1. Personal details
such as full name, ID number, facial photo, gender, date of birth, nationality, country of residence, passport number or other identification numbers, number of family members and children, ages of children
such as Address, phone number, fax number, email address, LINE ID, Facebook account, Facebook ID, Google ID, Twitter ID, and other ID from social networking site
such as bank account number, credit card number and debit card number, and payment information.
such as account details, membership card number, reward points, member type, customer type, member join/registration date and month, membership period, bank account and payment details, service and product applications (i.e., membership application, insurance application)
such as IP address of computer, type of browser, cookies data, time zone setting, operational system, platform and technology of the equipment used to access the website and online appointment system
such as username and password, purchase history, interests, likes and information from survey responses.
such as ethnicity, beliefs, religion, health information (including food and general allergies) and biometric data, including criminal history data. In the event that we have unintentionally received it and have no intention of collecting such data, and the data is not intended to be used to facilitate your stays at our hotels, we will not process your sensitive data.
2. Purposes and legal ground for processing personal data
We will use your Personal Data for a number of different purposes. In all case we must have a reason and a legal ground for processing your personal data. Some of the most common legal grounds we rely on are briefly described as follows:
We process Personal Data based on consensual basis. In the event that you have provided us with explicit consent, we will process your Personal Data within the scope of the purpose of which we have informed you such as:
Marketing and Communications:
|2. PERFORMANCE OF CONTRACT|
3. LEGAL OBLIGATION
4. VITAL INTEREST
5. LEGITIMATE INTEREST
3. Period of storage of personal data and criteria for defining such period
We process and store your personal data for as long as required for us to fulfil the purpose for which we obtained it, and to comply with our legal and regulatory obligations. We will then erase and destroy your Personal Data except as may be required, by applicable laws or for protection of our interest. However, we may have to retain your Personal Data for a longer duration, as required by applicable law.
4. Sharing & Disclosure
- Our hotel and residences managed and operated by us.
- Our business partners and third parties involved in the delivery of our products and services to you – including those involved in the sale of all or part of our business operations or assets and those for business, operational and general administration
- Our marketing and advertisement partners
- Our agents, advisors, consultants, other third party suppliers and/or services providers to assist us to operate effectively and provide you with the best experiences with our services
- Social Media Platforms: Where you choose to interact with us through social media i.e., Facebook, Google, Instagram, your interaction with these programs typically allows the social media company to collect some information about you through digital cookies they place on your device and other tracking mechanisms.
- International transfers of your Personal Data we may outsource the processing of certain functions and/or information to third parties, which may be located in countries other than the country where your information is collected or your country of residences. When we do outsource the processing of your personal information to third parties or provide your personal information to third-party services providers, we oblige those third parties to protect your personal information with appropriate security measures
- Other third parties when we have your consent or are otherwise permitted by law to do so.
5. How we protect your Personal Data?
We take appropriate technical and organizational measures pursuant to applicable laws to protect your personal data against illegal or accidental destruction, loss or alteration as well as unauthorized disclosure and access. We implement appropriate technical and organizational measures that seek to ensure a level of security appropriate to the risk, taking into account technological reality, cost, the scope, context and purposes of processing weighted against the severity and likelihood that the processing could threaten individual rights and freedoms.
6. Data Subject Rights
6.1 Right to Access Personal Data: You have the right to request access and to obtain a copy of your Personal Data that we collect, use or disclose related to you under our responsibility.
6.2 Right to Rectification: You have the right to request modification of the data, including the correction or errors and the updating of incomplete information
6.3 Right to Erasure: you have the right to request that we “erase” your Data in certain circumstances.
6.4 Right to Restrict Data Processing: You have the right to have incomplete, inaccurate, misleading, or not up-to-date Personal Data that we collect, use or disclose about you rectified
6.5 Right to be notified: You must be informed about the uses of personal data in a clear manner and be told the actions that can be taken if you feel your rights are being impeded. You must also be informed of any rectification or erasure of your personal data.
6.6 Right to Data Portability: you have the right to request that we transfer your Data to another third party. This right of data portability only applies to certain types of Data.
6.7 Right to withdraw consent: You have the right to withdraw your consent on which the collection, storage, use, or disclosure is based at any time. As a result, we will stop the processing your information as soon as possible and if we do not have other lawful basis which allows us to process your Personal Data, we will then delete your information.
6.8 Lodge a complaint: You have the right to lodge a complaint with the relevant supervisory authority where you believe our collection, use or disclosure of your Personal Data is unlawful or noncompliant with applicable data protection law.
8. Changes to the Privacy Notice
We reserve the right to make changes to this Notice from time to time to ensure that it is appropriate and in accordance with the applicable laws. Please check frequently to see any update or change to our Privacy Notice.
9. Other sites
The website may contain links to other third-party websites. If you follow a link to any of those third-party websites, please note that they have their own privacy policies and that we do not accept any responsibility or liability for their policies or processing of your personal information. Please check these policies before you submit any personal information to such third-party websites.
10. To contact us
If you wish to exercise data subject rights or if you have any question or complaint, you can contact us via email: email@example.com