PRIVACY POLICY

This Privacy Policy ("Policy") applies to all users or guests ("you", "your, "yours") and demonstrates how 5 ATLANTIS AG, Döltschiweg 234, 8055 Zurich, Switzerland ("we", "us", "our") and our affiliates (together with us "FIVE Hotels and Resorts") use and protect your personal data or any personal data of other individuals that you give us when you use FIVE Hotels and Resorts services, products website or mobile application or that we may receive through other channels when you communicate with us ("Personal Data").

We are committed to ensuring your privacy is protected. Should we ask you to provide certain Personal Data when using our services, products and website or mobile application, then you can be assured it will only be used in accordance with the Policy.

We may change the Policy from time to time by updating this page. You should check this page regularly to ensure that you agree with any changes.

The Policy is effective from 30 May 2022.

By accessing our website, using our services (e.g. booking a stay), products or mobile application, agreeing to the Policy, e.g. in the context of registering for any of services, products (including Loyalty Programme) and/or communicating with us via the website forms, email or other channels, you agree to the collection, use and other processing of Personal Data as described in the Policy.

To the extent you provide us with Personal Data of individuals other than yourself (in particular, if you book for other guests or register additional guests), you assure us that such individuals have consented to and been provided with a link to or copy of this Policy.

  1. What Personal Data we collect

We may collect the following Personal Data:

1.1  Name and job title and business affiliations;

1.2  Contact information including postal address, email address, and phone number;

1.3  Date of birth, country of residence, citizenship, passport copies;

1.3  Demographic information such as preferences, interests and hobbies;

1.4  Public profiles on social media networks, including but not limited to Facebook, Twitter, Google +, Instagram, Snapchat, TikTok, Linked-In, or employer websites;

1.5  Other information relevant to customer surveys and/or offers;

1.6  Any Personal Data you provide us before, during or after your stay with us, which may include feedback as well as sensitive personal data such as dietary restrictions, or in respect to events, appointments or (general) inquiries;

1.7 Any Personal Data we receive from third parties, in particular our Third Party Providers (see 4. below).

  1. When Personal Data is collected

2.1  Direct booking via FIVE Hotels and Resorts phone, email, website or mobile application;

2.2  Indirect booking via other platforms;

2.3  Checking-in at FIVE Hotels and Resorts;

2.4  Enrolling in the FIVE Hotels and Resorts loyalty programme (if any) via the website or mobile application;

2.5  Completing pre-stay and post-stay emails;

2.6  Signing up for newsletters or other materials;

2.7  Communicating with us before, during or after your stay or in respect to events, appointments or (general) inquiries.

  1. What we do with the Personal Data

We require the Personal Data to understand your needs and provide you with a better service, and in particular for the following reasons:

3.1  Internal record keeping and maintaining our list of contacts;

3.2  To improve our products and services and manage our relationship with you;

3.3 To periodically send promotional emails about new services, products, special offers or other information, including from third parties, which we think you may find interesting using the email address you have provided;

3.4 For marketing and guest satisfaction (including to send you newsletters, event invitations, promotions, pre-/post-arrival or departure information);

3.5 To contact you periodically for market research purposes. We may contact you by email, phone, or post;

3.6  To customise our website or mobile application according to your interests;

3.7  To address any queries you may have or send information you may request and for communicating with you in general.

  1. How we share Personal Data

Depending on your use of our services, products, website and mobile application, Personal Data may be transferred to our third party providers ("Third Party Providers"), as follows:

  • To Salto Systems, S.L., C/ Arkotz 9, Poligono Lanbarren, 20180 Oiartzun (Guipúzcoa-Spain) & ASSA ABLOY Entrance Systems, Box 131, SE-261 22 Landskrona, the providers for our on-site door lock systems. They may receive or have access to your contact and check-in and check-out information (e.g. guest name(s), (email) address, reservation stay dates, booking confirmation numbers, etc.). Such Personal Data will be deleted by the providers following check-out. Their privacy related terms are accessible here: https://saltosystems.com/en/legal-data/privacy/contact; https://www.assaabloyentrance.com/global/en/privacy-center/privacy-notice-subject-access-request.
  • To HeroApps DWC LLC, Business Center, Dubai World Central, P.O. Box 712734, Dubai, United Arab Emirates, the provider of our IPTV system. It may receive or have access to your check-in and check-out information (e.g. guest name(s), room number(s) etc.). Such Personal Data will be deleted by the provider following check-out. Their privacy related terms are accessible here: [insert link].
  • SEVENROOMS INC, 228 Park Ave South, PMB 33706, New York, NY 10003, the provider of our restaurant reservation system. It may receive and share with us any personal data you provide to it, either directly, including by email, or through our website, mobile application or social media accounts. Its privacy related terms are accessible here: https://sevenrooms.com/en/privacy-policy/.
  • SpaGuru CC, 16 Dirkie Uys Road, Somerset West, Western Cape, South Africa, the provider of our spa reservation system (Chidesk). It may receive and share with us any personal data you provide to it either directly, including by email, or through our website, mobile application or social media accounts. Its privacy related terms are accessible here: https://www.chidesk.com/Terms/Privacy.
  • Amadeus Hospitality Americas, Inc., 75 New Hampshire Avenue, Portsmouth, NH 03801, our provider for channel management and guest management solutions. It may receive and share with us any personal data you provide to it when booking a stay with us either through our website, mobile application or through another website partnering with Amadeus Hospitality Americas, Inc. It may further receive from us or have access to your contact and check-in and check-out information (e.g. guest name(s), (email) address, phone number, etc.). Its privacy related terms are accessible here: https://www.amadeus-hospitality.com/privacy-policy/.
  • Shiji Information Technology Spain, S.A, Passeig de Gràcia, 17, planta 6, 08007 Barcelona (Spain), the provider of our guest experience improvement suite (ReviewPro). It may receive and share with us any personal data you provide to it through the dedicated platform in the course of providing a feedback on your stay. Its privacy related terms are accessible here: https://www.reviewpro.com/privacy/.
  • Tripleseat Software, 300 Baker Ave., Suite 205, Concord, MA 01742, our conference and events management provider. It may receive and share with us any personal data you provide to it (e.g. through our website or mobile application) when organizing or participating in a conference or another event. It may further receive from us or have access to your contact and event information (e.g. guest name(s), booking information including commercial details of the event, (email) address, phone number, company information, etc.). Its privacy related terms are accessible here: https://tripleseat.com/privacy-policy/.
  • We use Planet Payment Group Holdings Ltd., Martin House, IDA Business Park, Dangan, Galway, H91 A06C, as the provider for our payment processing solution (Planet/3C). We do not have access to and thereby do not control any personal data you directly share with or through Planet/3C. Please refer to their privacy statements with respect to their data processing, accessible here: https://www.planetpayment.com/en/privacy/; https://www.planetpayment.com/en/gdpr-compliance/

In the course of transfer of Personal Data to Third Party Providers or our affiliates, a transfer outside Switzerland and Ireland (or other countries of the European Economic Area), in particular to the United States, United Arab Emirates, as well as any territory used by the Third Party Providers as a hosting or processing location, may occur.

The United States and the United Arab Emirates do not provide for laws providing adequate protection of personal data from a Swiss perspective. In particular, the rights provided for by Swiss data protection law may only be guaranteed to a limited extent and foreign authorities may gain access to your Personal Data with or without your knowledge. Such access may also result in further observations by foreign authorities.

By using our or our Third Party Providers' services or products, agreeing to the Policy, and/or communicating with us, you explicitly consent to the transfer of your Personal Data to respective Third Party Providers and the countries mentioned above and acknowledge and agree to the related risks mentioned above.

  1. Our basis for processing your Personal Data

When processing your Personal Data for the purposes described in this Policy or other purposes permitted by applicable laws and regulations, we rely on your consent to this Policy, our legitimate interests in maintaining business-relationships and communicating with you about our products and services, operations and events and/or our performance of any contract or another ground for lawful processing of your Personal Data under applicable laws and regulations.

  1. Retention and Deletion of Personal Data

We retain Personal Data in our data centers in Switzerland, Ireland and the United Arab Emirates only for the period necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required or permitted by applicable laws, regulations, or best practice retention requirements.

We will delete Personal Data as early as possible and in a way that the Personal Data may not be restored or reconstructed. If printed on paper, Personal Data will be destroyed in a secure manner, such as by cross-shredding or incinerating the paper documents or otherwise. If saved in electronic form, Personal Data will be destroyed by technical means to ensure it may not be restored or reconstructed at a later time.

  1. Security

We are committed to ensuring Personal Data is secure. In order to prevent unauthorized access or disclosure, we have put in place state of the art technical and organizational measures, including physical, electronic, and managerial procedures to safeguard and secure the confidentiality and integrity of the Personal Data we collect online or obtain otherwise. We regularly review our security policies and procedures to ensure our systems are secure and protected.

We restrict the use of and access to your Personal Data to those who provide you with our services or products or access to our website or mobile application and/or communicate with you as well as our Third Party Providers (see 4. above). Further, some of our suppliers may have access to certain Personal Data when they perform services on our behalf, mainly to maintain and support our IT systems.

  1. Controlling your Personal Data

You may choose to restrict the collection or use of Personal Data in the following ways:

8.1  Whenever you are asked to fill in a form on the website or mobile application, look for the box that you can click to indicate that you do not want the Personal Data to be used by anybody for direct marketing purposes.

8.2  If you have previously agreed to us using your Personal Data for direct marketing purposes, you may change your mind at any time by emailing us at [email protected].

We will not sell, distribute or lease your Personal Data to third parties other than as indicated in the Policy, unless we have your permission or are required by laws or regulations to do so. We may use your Personal Data to send you promotional information about third parties, which we think you may find interesting, unless you tell us that you do not wish this to happen.

You may request details of Personal Data which we hold about you. If you would like a copy of the Personal Data held on you, please email us at [email protected].

If you believe any Personal Data we are holding on you is incorrect or incomplete, please email us at the above address. We will promptly correct or complete any Personal Data found to be incorrect or incomplete.

To the extent provided by applicable data protection legislation, you may further have the right to:

  • request deletion of your Personal Data;
  • object to certain Personal Data about you being processed;
  • request that Personal Data processing be temporarily restricted in certain cases;
  • receive your Personal Data in a structured, commonly used and machine-readable format or have your Personal Data transferred to another data controller, where our processing is based on your consent or necessary for the performance of a contract with you and carried out by automated means; and
  • withdraw your consent, where our processing is based on your consent.

Please note that above-described deletion, objection and restriction requests or withdrawal of your consent, as applicable, may mean we will no longer be able to provide our services or products or to communicate with you.

In order to make use of your rights, please contact us directly (see our contact details set out below under 10.).

  1. How we use cookies

9.1  Our website and mobile application use cookies. A cookie is a small file which asks permission to be placed on your device's hard drive. Once you agree, the file is added and the cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences.

9.2  We use traffic log cookies to identify which pages are being used. This helps us analyse data about web page traffic and improve our website or mobile application in order to tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system.

9.3  Overall, cookies help us provide you with a better website or mobile application, by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.

9.4  You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of our website or mobile application.

More details on our deployment of third party cookies and the management of cookies can be found in the Cookie Policy, available here https://zurich.fivehotelsandresorts.com/cookie-policy, which forms an integral part of this Policy.

  1. Links to other websites

Our website or mobile application may contain links to enable you to visit other websites of interest easily. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any (personal) information which you provide whilst visiting such sites and such sites are not governed by the Policy. You should exercise caution and look at the privacy statement applicable to the website in question.

  1. Contacts

If you have any questions about how we process your Personal Data, please feel free to reach out to us at [email protected] or write to 5 ATLANTIS AG, Döltschiweg 234, 8055 Zurich, Switzerland.