fbpx

PRIVACY POLICY

Privacy Statement

Effective Date: June 2020

This Privacy Statement applies to www.vitalityrelaxspa.com owned and operated by Vitality Relax Spa Suite. This Privacy Statement describes how we collect and use the information, which may include personal data, you provide on our web site: www.vitalityrelaxspa.com. It also describes the choices available to you regarding our use of your personal data and how you can access and update this data.

Data Collection

The types of personal data that we collect include:

  • Your first name, last name, email address, phone number and home address;
  • Credit card details (type of card, credit card number, name on card, expiration date and security code);
  • Guest stay data, including date of arrival and departure, special requests made, observations about your service preferences (including room preferences, facilities or any other services used);
  • Data you provide regarding your marketing preferences or in the course of participating in surveys, contests or promotional offers;

You may always choose what personal data (if any) you wish to provide to us. If you choose not to provide certain details, however, some of your transactions with us may be impacted.

Data we collect automatically

When using our website, we also collect information automatically, some of which may be personal data. This includes data such as language settings, IP address, location, device settings, device OS, log information, time of usage, URL requested, status report, user agent (information about the browser version), operating system, result (viewer or booker), browsing history, user Booking ID, and type of data viewed. We may also collect data automatically through cookies. For information on how we use cookies, click here.

 

Contact forms.

 

We use the contact form Contact Form 7, You can find more information about their privacy policy at: https://contactform7.com/privacy-policy/

 

 

Processing Purposes

We use your personal data for the following purposes:

  • Reservations: We use your personal data to complete and administer your online reservation.
  • Customer service: We use your personal data to provide customer service.
  • Guest reviews: We may use your contact data to invite you by email to write a guest review after your stay. This can help other travellers to choose the accommodation that suits them best. If you submit a guest review, your review may be published on our website.
  • Marketing activities: We also use your data for marketing activities, as permitted by law. Where we use your personal data for direct marketing purposes, such as commercial newsletters and marketing communications on new products and services or other offers which we think may be of interest to you, we include an unsubscribe link that you can use if you do not want us to send messages in the future.
  • Other communications: There may be other times when we get in touch by email, by post, by phone or by texting you, depending on the contact data you share with us. There could be a number of reasons for this:
    • We may need to respond to and handle requests you have made.
      b. If you have not finalised a reservation online, we may email you a reminder to continue with your reservation. We believe that this additional service is useful to you because it allows you to carry on with a reservation without having to search for the accommodation again or fill in all the reservation details from scratch.
      c. When you use our services, we may send you a questionnaire or invite you to provide a review about your experience with our website. We believe that this additional service is useful to you and to us as we will be able to improve our website based on your feedback.
  • Analytics, improvements and research: We use personal data to conduct research and analysis. We may involve a third party to do this on our behalf. We may share or disclose the results of such research, including to third-parties, in anonymous, aggregated form. We use your personal data for analytical purposes, to improve our services, to enhance the user experience, and to improve the functionality and quality of our online travel services.
  • Security, fraud detection and prevention: We use the information, which may include personal data, in order to prevent fraud and other illegal or infringing activities. We also use this information to investigate and detect fraud. We can use personal data for risk assessment and security purposes, including the authentication of users. For these purposes, personal data may be shared with third parties, such as law enforcement authorities as permitted by applicable law and external advisors.
  • Legal and compliance: In certain cases, we need to use the information provided, which may include personal data, to handle and resolve legal disputes or complaints, for regulatory investigations and compliance, or to enforce agreement(s) or to comply with lawful requests from law enforcement insofar as it is required by law.
  • If we use automated means to process personal data which produces legal effects or significantly affects you, we will implement suitable measures to safeguard your rights and freedoms, including the right to obtain human intervention.

Legal Bases

  • In view of purposes A and B we rely on the performance of a contract: The use of your data may be necessary to perform the contract that you have with us. For example, if you use our services to make an online reservation, we will use your data to carry out our obligation to complete and administer that reservation under the contract that we have with you.
  • In view of purposes C-H, we rely on its legitimate interests: We use your data for our legitimate interests, such as providing you with the best appropriate content for the website, emails and newsletters, to improve and promote our products and services and the content on our website, and for administrative, fraud detection and legal purposes. When using personal data to serve our legitimate interests, we will always balance your rights and interests in the protection of your information against our rights and interests.
  • In respect of purpose H, we also rely, where applicable, on our obligation to comply with applicable law.
  • Where needed under applicable law, we will obtain your consent prior to processing your personal data for direct marketing purposes.

If needed in accordance with applicable law, we will ask your consent. You can withdraw your consent anytime by contacting us at any of the addresses at the end of this Privacy Statement.

If you wish to object to the processing set out under C-F and no opt-out mechanism is available to you directly (for instance in your account settings), to the extent applicable, please contact info@vitalityrelaxspa.com .

 

 

 

 

Data Sharing

 

GOOGLE MAPS

On our website, we use Google Maps API (Application Programming Interface, “Google Maps”) provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, for the visual representation of geographic information (maps). When you use Google Maps, information about the use of our website including your IP address is transmitted to a server belonging to Google in the USA and stored there.

The legal basis for processing data for this purpose is to pursue our legitimate interests in accordance with Art. 6 (1) (f) GDPR.

It is possible to deactivate the Google Maps service and prevent data being transferred to Google by deactivating JavaScript in your browser. However, we would like to point out that if you do so, you will not be able to use the map view.

More information about the collection, processing and use of your data by Google and your rights in this regard can be found in the privacy policy of Google at https://policies.google.com/privacy, as well as in the additional terms of use for Google Maps or Google Earth at https://www.google.com/intl/en_de/help/terms_maps/.

 

 

LINK TO OUR OWN SOCIAL MEDIA PRESENCE

We have embedded links on our website to our social media profiles in the following networks:

  • Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA,
  • Instagram Inc., 1601 Willow Road, Menlo Park, California 94025, USA; and
  • Twitter Inc.,1355 Market Street, Suite 900, San Francisco, CA 94103, USA.

If you click on a social network icon, you will be automatically forwarded to our profile on the respective social network. To use the functions of that network, you may have to log into your user account on the respective network.

If you open a link to one of our social media profiles, a direct connection will be established between your browser and the server of the social network concerned. This gives the network the information that you have visited our website with your IP address and clicked on the link. If you open a link to a network while you are logged into your account on that network, the content of our website may be linked to your network profile, meaning that the network can directly associate your visit to our website with your user account. If you wish to prevent this, you should log out before clicking on any links. The connection is made in any case if you log into the respective network after clicking on the link.

 

 

Room reservation system

Personal data relating to room reservations on the website are collected and sent to us by

HOTEL BOOKING

Nicdark d.o.o.

VAT : 67100082

Partizanska Cesta 37

6210 Sežana ( Slovenia )

 

https://www.nicdark.com/

 

 

 

Payments

We accept payments through PayPal. When processing payments some of your data will be passed to PayPal, including the information required to process or support the payment, such as the total purchase and billing information.

Please check PayPal’s privacy policy for more details.

https://www.paypal.com/us/webapps/mpp/ua/privacy-full

 

 

Credit card payments

 

If you pay on the website by credit card, we pass on your credit card information to your credit card issuer and to the credit card acquirer. To this end, we work with the software platform “Stripe” provided by

 

Stripe Inc.

510 Townsend Street,

CA 94107 San Francisco, USA.

 

If you decide to pay by credit card, you are asked each time to enter all mandatory information. The legal basis for processing data for this purpose is the performance of a contract in accordance with Art. 6 (1) (b) GDPR. Regarding the processing of your credit card information by these third parties, please also read the general terms and conditions and the privacy policy of your credit card issuer.

 

 

  • com:We have teamed up with Booking.com B.V., located at Herengracht 597, 1017 CE Amsterdam, The Netherlands (www.booking.com) (hereafter Booking.com) to offer you our online reservation services. While we provide the content to this website and you make a reservation directly with us, the reservations are processed through Booking.com. The information you enter into this website will therefore also be shared with Booking.com and its affiliates. This information may include personal data such as your name, your contact details, your payment details, the names of guests traveling with you and any preferences you specified when making a booking.
    To find out more about the Booking.com corporate family, visit About Booking.com.

Booking.com will send you a confirmation email, a pre-arrival email and provide you with information about the area and our accommodation. Booking.com will also provide you with international customer service 24/7 from its local offices in more than 20 languages. Sharing your details with Booking.com’s global customer service staff allows them to respond when you need assistance. Booking.com may use your data for technical, analytical and marketing purposes as further described in the Booking.com Privacy Policy. This includes that your data might also be shared with other members of the Booking Holdings Inc. group of companies for analysis to provide you with travel-related offers that may be of interest to you and to offer you customised service. If needed under applicable law, Booking.com will first ask your consent. If your data is transferred to a country outside the European Economic Area, Booking.com will make contractual arrangements to ensure that your personal data is still protected in line with European standards. If you have questions about the processing of your personal data by Booking.com, please contact dataprotectionoffice@booking.com.

  • BookingSuite:Your personal data may be shared with BookingSuite B.V. located at Herengracht 597, 1017 CE Amsterdam, the Netherlands, the company which operates this website and the website suite.booking.com.
  • Third-party service providers:We use service providers to process your personal data strictly on our behalf. This processing would be for purposes as included in this Privacy Statement such as facilitating reservation payments, sending out marketing material or for analytical support services. These service providers are bound by confidentiality clauses and are not allowed to use your personal data for their own purposes or any other purpose.
  • Competent authorities:We disclose personal data to law enforcement and other governmental authorities insofar as it is required by law or is strictly necessary for the prevention, detection or prosecution of criminal acts and fraud.

 

 

TRACKING TOOLS

1.12.1 Google Analytics

We use the web analysis service of Google Analytics for the purpose of designing and continuously optimizing our website to meet your needs. To this end, pseudonymized utilization profiles are created and small text files used (“cookies”) that are stored on your computer. The information generated by the cookie about your use of this website is transferred to the servers of the provider of these services, stored there and processed for us. In addition to the data listed under section 1.1, we may receive the following information:

  • The navigation path you follow on the website,
  • the length of time you stay on the website or subpage,
  • the subpage from which you leave the website,
  • the country, region or town from which the website is accessed,
  • the device (type, version, depth of colour, resolution, width and height of browser window) and
  • whether you are a new or repeat visitor.

The information is used to evaluate the use of the website, compile reports on website activities, and provide further services related to website and internet utilization for market research purposes and for designing this website according to your needs. This information may also be transferred to third parties if this is required by law or if these data are processed by third parties on our behalf.

The provider of Google Analytics is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). Before sending the data to the provider, the IP address is truncated by activating the IP anonymization function (“anonymizeIP”) on this website within member states of the European Union or in other states that are party to the Agreement on the European Economic Area. The anonymized IP address transmitted by your browser in connection with Google Analytics is not combined with other data held by Google. In exceptional cases only, the full IP address is transmitted to a Google server in the United States and truncated there. In these cases, we ensure with contractual warranties that Google maintains a sufficient level of data protection. According to Google, the IP address will under no circumstances be linked to other data relating to the user.

Users can prevent the information generated by the cookie and concerning their use of the website (including the IP address) from being recorded and processed by Google by downloading and installing the browser plugin available here: http://tools.google.com/dlpage/gaoptout?hl=en

 

For more information on the web analysis services used, see Google’s website here https://policies.google.com/privacy?hl=en&gl=ZZ. For instructions how to prevent the processing of your data by the web analysis service, see here https://tools.google.com/dlpage/gaoptout?hl=en.

The legal basis for processing data for this purpose is your consent in accordance with (Art. 6 (1) (a) GDPR). You may revoke your consent at any time with future effect.

 

1.12.2 Creating pseudonymized utilization profiles

To provide you with personalized services and information on our website (on-site targeting), we use and analyse the data we collect about you whenever you visit the website. Processing these data may involve the use of cookies. The analysis of your user behaviour can lead to the creation of a so-called utilization profile. The utilization data are combined using only pseudonyms, but never with non-pseudonymized personal data.

The legal basis for processing data for this purpose constitutes our legitimate interests in optimizing and individualizing our website and our advertising communication in accordance with Art. 6 (1) (f) GDPR.

 

1.12.3 Facebook Connect

On our website, you can register to create a customer account or sign in via the social media plugin “Facebook Connect” provided by the social network Facebook, operated by Facebook Inc., Hacker Way, Menlo Park, CA 94025, USA (“Facebook”) using so-called single sign-on technology if you have a Facebook profile. The “Facebook Connect” social media plugins can be recognized on our website by the button with the Facebook logo labelled “Connect with Facebook,” “Log in with Facebook,” or “Sign in with Facebook”.

If you visit one of our websites that contains a plugin of this kind, your browser creates a direct link to the servers of Facebook. The content of the plugin is transmitted directly to your browser by Facebook and integrated into the page. As a result, Facebook receives the information that your browser has called up the corresponding page on our website, even if you do not have a Facebook profile or are not currently logged into Facebook. This information (including your IP address) is sent directly from your browser to a server at Facebook in the USA and stored there.

You can also use the Facebook Connect button on our website to log in or register using your Facebook user data. When you click on the “Facebook Connect” button, you are asked to give your consent to the exchange of data before you log in. Only if you give your express consent in accordance with Art. 6 (1) (a) GDPR do we receive the general and publicly accessible information stored in your profile, depending on your personal data protection settings on Facebook. This information includes your user ID, your name, profile picture, age and gender.

Please note that following changes to Facebook’s privacy policy and conditions of use, granting your consent can lead to your profile pictures, your friends’ user IDs, and your friends list also being transferred if these have been marked as “public” in your Facebook privacy settings. We store and process the data sent to us by Facebook for the purpose of creating a user account with the required data, if you allow this in your Facebook settings (title, first name, last name, address, country, email address, date of birth). Conversely, based on your consent, data (e.g. information on your surfing or purchasing behaviour) can be transferred from us to your Facebook profile.

You may revoke your consent at any time with future effect.

For information on the purpose and extent of data capture and the further processing and use of data by

Facebook, as well your rights in this regard and setting options for the protection of your personal privacy, please refer to Facebook’s privacy policy:

http://www.facebook.com/policy.php

If you do not want Facebook to assign the data collected via our website to your Facebook profile, you must log out of Facebook before you visit our website.

 

1.12.4 Privacy regulations on the application and use of Google Remarketing

Vitality Relax Spa Suite has integrated the services of Google Remarketing on this website. Google Remarketing is a function of Google AdWords that allows a company to show advertisements to internet users who previously visited the company’s website. Integrating Google Remarketing therefore enables a company to create user-related ads and consequently show advertising to internet users that is relevant to their interests.

Google Remarketing services are provided by Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

The purpose of Google Remarketing is to show interest-based ads. Google Remarketing allows us to show ads via the Google Display Network or on other websites that are tailored to the individual needs and interests of internet users.

Google Remarketing sets a cookie on the data subject’s IT system. This allows Google to recognize visitors to our website when they subsequently call up other websites that are also members of the Google Display Network. Every time the data subject visits a website that incorporates the services of Google Remarketing, the data subject’s browser automatically identifies itself to Google. In the course of this technical process, Google receives the data subject’s personal data, such as their IP address or information on their surfing behaviour, which Google uses to show ads that are relevant to the user’s interests, among others.

The cookie is used to store personal information, such as the websites visited by the data subject. Each time our websites are visited, personal data including the IP address of the internet connection used by the data subject are transferred to Google in the United States. These personal data are then stored by Google in the USA. Google may possibly pass on these personal data to third parties.

You can prevent the setting of cookies by our website at any time, as described above, by adjusting the settings of your internet browser and thus permanently object to the setting of cookies. Adjusting your browser settings in this way also prevents Google from setting a cookie on your IT system. In addition, you can delete a cookie already set by Google Analytics at any time via the browser or other software programs.

Furthermore, you have the possibility of objecting to interest-based advertising by Google. To do this, you must call up the link https://www.google.en/settings/ads from each browser you use and make the corresponding settings there.

For more information and Google’s applicable privacy policy, see https://www.google.de/intl/en/policies/privacy/.

The legal basis for processing data as described above is for the purpose of pursing our legitimate interests in offering individualized and interest-based advertising of our services in accordance with Art. 6 (1) (f) GDPR.

1.12.5 Privacy regulations on the application and use of Google AdWords

Vitality Relax Spa Suite has integrated Google AdWords on this website. Google AdWords is an internet advertising service that allows advertisers to place ads both in Google search engine results and in the Google Display Network. Google AdWords allows advertisers to define certain keywords in advance that are used to display an ad in Google’s search engine results only when the user searches for a result containing the keywords. In the Google Display Network, the ads are shown on websites with a similar subject matter using an automatic algorithm and taking into account the previously defined keywords.

Google Adwords services are provided by Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

The purpose of Google AdWords is to market our website by showing interest-based ads on the websites of third-party companies and in Google’s search engine results, as well as showing third-party ads on our website.

If you reach our website via a Google ad, Google sets a so-called conversion tracking cookie on your IT system. A conversion tracking cookie loses its validity after thirty days and is not used for the purpose of identifying data subjects. As long as the cookie has not yet expired, it is used to track whether certain subpages, such as the shopping cart of an online shop system, have been accessed on our website. Conversion tracking allows both us and Google to track whether a user who reached our website via an AdWords ad generated turnover, i.e. purchased goods or cancelled a purchase.

Google uses the data and information collected through the conversion tracking cookie to compile statistics about visits to our website. We use these statistics, on the other hand, to determine the overall number of users referred to us via AdWords ads, i.e. to determine the success or failure of the respective AdWords ad campaign, and to optimize our AdWords ads in the future. Neither our company nor other Google AdWords advertisers receive information from Google that could be used to identify data subjects.

Personal information, such as the websites visited by the data subject, may be stored with a conversion tracking cookie. Each time you visit our websites, your personal data including the IP address of the internet connection used are transferred to Google in the United States, where they are stored. Google may possibly pass on these personal data to third parties.

You can prevent the setting of cookies by our website at any time, as described above, by adjusting the settings of your internet browser and thus permanently object to the setting of cookies. Adjusting your browser settings in this way also prevents Google from setting a conversion tracking cookie on your IT system. In addition, you can delete a cookie already set by Google Analytics at any time via the browser or other software programs.

Furthermore, you have the possibility of objecting to interest-based advertising by Google. To do this, you must call up the link https://www.google.en/settings/ads from each browser you use and make the corresponding settings there.

For more information and Google’s applicable privacy policy, see https://policies.google.com/privacy?hl=en&gl=de.

The legal basis for processing data as described above is for the purpose of pursing our legitimate interests in offering individualized and interest-based advertising of our services in accordance with Art. 6 (1) (f) GDPR.

 

 

 

International Data Transfers

The transmission of personal data as described in this Privacy Statement may include overseas transfers of personal data to countries whose data protection laws are not as comprehensive as those of the countries within the European Union. Where required by European law, we shall only transfer personal data to recipients offering an adequate level of data protection. In these situations, we make contractual arrangements to ensure that your personal data is still protected in line with European standards. You can ask us to see a copy of these clauses using the contact details below.

Security

BookingSuite observes reasonable procedures to prevent unauthorised access to, and the misuse of, information including personal data. We use appropriate business systems and procedures to protect and safeguard information including personal data. We also use security procedures and technical and physical restrictions for accessing and using the personal data on our servers. Only authorised personnel are permitted to access personal data in the course of their work.

 

Analysis

We use programs to analyze the behavior of our website:

Google Analytics; https://policies.google.com/privacy

MonsterInsigts https://www.monsterinsights.com/privacy-policy/

 

Data Retention

We will retain your information, which may include personal data for as long as we deem it necessary to provide services to you, comply with applicable laws, resolve disputes with any parties and otherwise as necessary to allow us to conduct our business including to detect and prevent fraud or other illegal activities. All personal data we retain will be subject to this Privacy Statement. If you have a question about a specific retention period for certain types of personal data we process about you, please contact us via the contact details included below.

Your choices and rights

We want you to be in control of how your personal data is used by us. You can do this in the following ways:

  • You can ask us for a copy of the personal data we hold about you;
  • you can inform us of any changes to your personal data, or you can ask us to correct any of the personal data we hold about you;
  • in certain situations, you can ask us to erase or block or restrict the processing of the personal data we hold about you, or object to particular ways in which we are using your personal data; and
  • in certain situations, you can also ask us to send the personal data you have given us to a third party.

Where we are using your personal data on the basis of your consent, you are entitled to withdraw that consent at any time subject to applicable law. Moreover, where we process your personal data based on legitimate interest or the public interest, you have the right to object at any time to that use of your personal data subject to applicable law.

We rely on you to ensure that your personal data is complete, accurate and current. Please do inform us promptly of any changes to or inaccuracies of to your personal data by contacting info@vitalityrelaxspa.com . We will handle your request in accordance with the applicable law.

Questions or Complaints

If you have questions or concerns about our processing of your personal data, or if you wish to exercise any of the rights you have under this notice, you are welcome to contact us via  info@vitalityrelaxspa.com . You may also contact your local data protection authority with questions and complaints.

Changes to the Notice

Just as our business changes constantly, this Privacy Statement may also change for time to time. If you want to see changes made to this Privacy Statement from time to time, we invite you to access this Privacy Statement to see the changes. If we make material changes or changes that will have an impact on you (e.g. when we start processing your personal data for other purposes than set out above), we will contact you prior to commencing that processing.