Privacy Policy
1. Data Controller
The data controller responsible for your personal data is:
Email: info@joryrahotelhaven.com
If we have appointed a Data Protection Officer, you may contact them at: info@joryrahotelhaven.com (Subject: "Attention: The Data Protection Officer").
2. Personal Data We Collect
We collect the following categories of personal data:
| Category | Examples | Source |
|---|---|---|
| Identity data | Name, date of birth, nationality | You, directly |
| Contact data | Email, phone, postal address | You, directly |
| Reservation data | Booking details, stay dates, preferences | You, directly |
| Financial data | Payment card details (processed via PCI-DSS payment processor) | You, directly |
| Technical data | IP address, browser type, device identifiers, cookie IDs | Automatically |
| Usage data | Pages visited, session duration, clicks, referral URLs | Automatically |
| Marketing preferences | Newsletter opt-in/out, communication preferences | You, directly |
We do not knowingly collect sensitive ("special category") personal data such as health data, biometric data, or data revealing racial origin, unless required by law or explicitly consented to.
3. Legal Basis for Processing (GDPR Article 6)
| Purpose | Legal Basis |
|---|---|
| Processing reservations and delivering services | Contract performance (Art. 6(1)(b)) |
| Legal and regulatory compliance (e.g., anti-money laundering, age verification) | Legal obligation (Art. 6(1)(c)) |
| Sending marketing communications (where opted in) | Consent (Art. 6(1)(a)) |
| Analytics, fraud prevention, service improvement | Legitimate interests (Art. 6(1)(f)) |
| Non-essential cookies and tracking | Consent (Art. 6(1)(a)) |
Where we rely on consent, you have the right to withdraw it at any time. Withdrawal does not affect processing carried out prior to withdrawal.
4. How We Use Your Data
- To manage and confirm hotel and casino reservations
- To process payments securely
- To send booking confirmations, pre-arrival and post-stay communications
- To comply with legal obligations (age verification, AML, KYC where applicable)
- To personalise your experience based on previous stays
- To send promotional offers and newsletters (with your consent)
- To analyse website usage for performance and improvement
- To detect and prevent fraud and security incidents
5. Data Sharing and Transfers
We share personal data with:
- Service providers: payment processors, IT infrastructure providers, email delivery services — only to the extent necessary and under data processing agreements
- Regulatory authorities: law enforcement, gaming regulators, tax authorities, as required by applicable law
- Group companies: affiliated entities within the same corporate group, for operational purposes
We do not sell your personal data to third parties.
International transfers: Where data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place (Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms under GDPR Chapter V).
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Reservation and guest records | 7 years (legal/tax obligations) |
| Payment transaction records | 7 years |
| Marketing consent records | Until consent withdrawn + 3 years |
| Website analytics (cookies) | Up to 24 months |
| Customer service correspondence | 3 years after resolution |
| Responsible gambling records | 5 years (regulatory requirement) |
7. Your Rights Under GDPR
Subject to applicable law, you have the following rights:
- Right of access (Art. 15): Request a copy of the personal data we hold about you
- Right to rectification (Art. 16): Correct inaccurate or incomplete data
- Right to erasure (Art. 17): Request deletion of your data ("right to be forgotten") where no legal basis exists for retention
- Right to restriction (Art. 18): Request that we limit processing of your data
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format
- Right to object (Art. 21): Object to processing based on legitimate interests or for direct marketing
- Rights related to automated decisions (Art. 22): Not to be subject to solely automated decisions that significantly affect you
- Right to withdraw consent: At any time, without affecting prior lawful processing
To exercise any of these rights, contact us at info@joryrahotelhaven.com. We will respond within 30 days. We may request proof of identity before fulfilling a request.
You also have the right to lodge a complaint with your local supervisory authority. In the EU, find your authority at edpb.europa.eu.
8. Cookies
We use cookies and similar tracking technologies. For full details, see our Cookie Policy. You can manage your cookie preferences at any time via the cookie consent banner on our website.
9. Security
We implement appropriate technical and organisational security measures to protect your personal data against accidental loss, unauthorised access, disclosure, alteration, or destruction. Payment card data is processed exclusively by PCI-DSS certified payment processors — we do not store full card numbers.
10. Children
Our services are strictly for adults aged 18 and over. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us immediately at info@joryrahotelhaven.com.
11. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via prominent notice on our website or by email. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of our services after the effective date constitutes acceptance of the updated policy.
12. Contact Us
For any questions, requests, or complaints regarding your personal data:
Email: info@joryrahotelhaven.com
Post: ,