Denham Grove
Denham Grove Star Denham Grove Star Denham Grove Star Denham Grove Star
Denham Grove
BOOK NOW

Tilehouse Lane, Denham, UB9 5DG Reservations: 01895 833 338

Privacy & Personal Data Policy

  • Home
  • /
  • Privacy & Personal Data Policy

PRIVACY AND PERSONAL DATA POLICY

For the purpose of applicable data protection legislation, the data controller of your personal data is:

“The Hotel”: The Clay Oven Group Ltd trading as Denham Grove Hotel, Tilehouse Lane, Denham, UB9 5DG

And:

“The Operator”: Countrywide Hotels Ltd, Kelmscott, Hattingley Road, Medstead, Alton, GU34 5NQ

  1. INTRODUCTION

This Privacy Statement applies to the processing by The Hotel or The Operator as relevant of your (our guests) personal data. We (i.e. The Hotel and The Operator), both take your privacy very seriously and treat all your personal data with great care, acting in accordance with the applicable data protection legislation at all times.

When you visit this website (or subdomains) (the “Website”), make a reservation, contact us, purchase products from us or visit one of our properties, we collect information from and about you. Some of the information we collect may be classed as personal data under data protection legislation, that is, “any information relating to an identified or identifiable natural person”. It may be collected any time you submit it to us, whatever the reason may be.

This Privacy Statement describes which personal data is collected and for which purposes this personal data is processed by The Hotel and The Operator. It also states which rights you have under applicable data protection legislation.

  1. COLLECTING YOUR PERSONAL DATA

The Hotel and The Operator collect information about you in the following ways.

Information you give to us. This includes personal data collected:

Information Automatically Collected. This includes information and personal data collected:

  1. WHY DO WE PROCESS YOUR PERSONAL DATA?

Your personal data will be stored in (i) centralized systems which are under the control of The Hotel and The Operator, and are accessible by authorized staff of The Hotel and The Operator as relevant, and the respective suppliers of each, and (ii) some local systems controlled solely by The Hotel.

We use the information we collect about you to process your bookings, answer your queries, process your gift card purchases, provide our hotel and restaurant facilities and services, enable you to manage your website user account and provide loyalty programmes.  With your consent, we will contact you via our marketing and sales channels (email/ phone/ post) about other related products and services we, or our group business, provide which we think may be of interest to you.  Our marketing communications are generally sent by email but we may sometimes use other methods of delivery such as by post or SMS.

We mainly collect, store and process personal data at two different stages: (i) before you decide to visit The Hotel and (ii) when you visit, or have visited, The Hotel.

  1. Before you decide to visit The Hotel.

When you visit our Website (www.denhamgrove.com), we collect information about your use of the Website. This includes both information we collect directly from you, and information we collect about your behaviour. This information may constitute ‘personal data’ under applicable law. We use this information to provide you with (personal) offers, both on our Website and via advertisements on other websites you visit.

Advertising

Generally. We may use other companies to serve third-party advertisements when you visit and use the Website. These companies may collect and use click stream information, browser type, time and date, subject of advertisements clicked or scrolled over during your visits to the Website and other websites in order to provide advertisements about goods and services likely to be of interest to you. These companies typically use tracking technologies to collect this information. Other companies’ use of their tracking technologies is subject to their own privacy policies.

Targeted Advertising. We use Website information to provide you with (personal) offers, both on our Website and via advertisements on other websites you visit. In order to serve offers and advertisements that may interest you, we may display targeted advertisements on the Website, or other digital properties or applications in conjunction with our content based on information provided to us by our users and information provided to us by third parties that they have independently collected. We do not provide personal data to advertisers when you interact with an advertisement.

  1. When you visit or have visited The Hotel.

When you make a reservation, you will have to provide us with your name, email address, phone number, the dates you are staying with us and a credit card token or other payment information as applicable. We use this personal data to process the reservation, for billing purposes, and to allow us to communicate with you about your reservation. When you stay in one of our properties, we will collect personal data about your preferences, use of our services, and location.

Overview of activities under stage (i) and (ii):

We may at each of the stages outlined above use your personal data but only when and to the extent the law allows us to. Most commonly, we will use your personal data in the following circumstances:

For your convenience, we have made an overview of activities that involve the processing of your personal data:

Purpose/activity

  1. We store the personal data you provide to us in our systems for administrative purposes.
  2. Government regulations require us to ask you to provide us with certain information when you arrive at a The Hotel. This may include information such as: birth date, nationality, place of residence, date of arrival and profession.
  3. We will have to verify your identity when you arrive at a The Hotel. We will use your passport or other identification document. We will not store a copy of your passport, except to the extent permitted by law.
  4. We store your personal data in our database(s), also after your transaction has been completed and after you have stayed in one of our properties to the extent required by law, and if you have signed up a loyalty programme, to be able to contact you and welcome you again in the future.
  5. For many of our business purposes we use cloud based services. Therefore, for technical and organizational reasons, it is necessary that your personal data is transferred to servers located in the US, or to servers located in countries outside of the European Economic Area (‘EEA’).
  6. We process your booking, howsoever made directly via our website or via a third party (online) travel agent.
  7. We offer and provide services and products you request from us or which we may think you are interested in, via email, telephone or other media. These marketing communications contain commercial offers and news of The Hotel and The Operator and related third parties. If you sign up to receive newsletter, The Hotel and The Operator will use the email address you provide to send the newsletter to. If you no longer wish to receive the newsletter, you can unsubscribe and The Hotel and The Operator will no longer send you these marketing communications.
  8. We use credit card data or other payment data for invoicing purposes.
  9. If you would like to park in one of our parking areas we may collect your license plate number for security purposes.
  10. We collect data on your use of our Wi-Fi services for security and anti-piracy purposes (such as: IP address, your device’s MAC address, connections made, location, etc.). We do not process the content of traffic.
  11. We endeavour to provide a high level of security of both the information we store as well as our facilities, (IT) systems and premises, by means of encryption, physical security measures, passwords, company procedures and policies and professional IT support. Personal data may be processed in this context by The Hotel and The Operator as relevant and their respective vendors.
  12. We endeavour to prevent our services and facilities (properties) from being used for illegal purposes, of any kind. Personal data may be processed in this context by The Hotel as relevant and their respective vendors, such as through CCTV surveillance.
  13. We engage in activities required for compliance with legal obligations, third party claims or requests from public authorities, such as (i) the mandatory storage/containment of certain information because of a criminal investigation, (ii) requests from third parties for access to information (iii) any further instructions from third parties, such as supervisory authorities, that involve data processing.
  14. If you have special requirements then it may also be necessary to collect special categories of personal data in relation to diet or disability.

We are committed to collecting and using your personal data in accordance with applicable data protection laws.

We will only collect, use and share your personal data where we are satisfied that we have an appropriate legal basis to do this.

This may be because:

If you would like to find out more about the legal basis for which we process personal data please contact either The Hotel or The Operator, using the details set out in Section 10  below. If you have provided your consent to our processing of your personal data you can also withdraw this consent at any time by contacting us.

  1. SHARING YOUR DATA

We may share your personal data as follows:

  1. INTERNATIONAL DATA TRANSFERS

In some instances it is necessary to transfer your personal data overseas.  Any transfers will be made in full compliance with all aspects of the applicable regulations.

Both The Hotel and The Operator use cloud based services for many business services. Therefore, for technical and organizational reasons, it is necessary that your personal data is transferred to servers located in the US, or to servers located in countries outside of the EEA. When we transfer the data to a country outside of the EEA that does not offer an adequate level of data protection, we will ensure compliance with applicable law by way of EU Model Clauses, EU-US Privacy Shield-certification, or other legally accepted safeguards, as applicable.  Any requests for information we receive from law enforcement or regulators will be carefully validated before personal data is disclosed.  You have the right to find out more about the safeguards used where your personal data is transferred outside of the EEA. If you would like further information please contact either The Hotel or The Operator as relevant, using the details given in section 10 below.

  1. YOUR RIGHTS

The GDPR provides the following rights for individuals:

Right to revoke consent

If we process personal data on the basis of your consent, you have the legal right to revoke such consent at any time. We will then cease the relevant processing activity going forward.

Right of access to your information

If you want to know what personal data we have collected or process about you, you may request us to provide a copy of your personal data by contacting either The Hotel or The Operator as relevant, using the details given in section 10 below. We will ask you to identify yourself. We will not provide you with a copy of your personal data to the extent that the rights and freedoms of others are or may be adversely affected.

Right to rectification and erasure of data, and restriction of processing

If you believe that our processing of your personal data is incorrect, inaccurate, unlawful, excessive, incomplete, no longer relevant, or if you think that your data is stored longer than necessary, you may ask us to change or remove such personal data or restrict such processing activity.

Right to data portability

You have the right to receive your personal data, which you have provided to us, in a structured, commonly used and machine-readable format, in accordance with Article 20 of the General Data Protection Regulation.

Right to object

You have the legal right to object, on grounds relating to your particular personal situation, at any time to processing of your personal data which is based on our legitimate interests.  Furthermore, you have the right to object at any time to our processing of your personal data for direct marketing purposes or to profiling. You can do this by either (i) opting out by using the option we provide in the relevant direct marketing message (e.g. an email newsletter), or (ii) by contacting either The Hotel or The Operator as relevant, using the details given in section 10 below.

For the sake of clarity: without prejudice to the foregoing we are at all times entitled to send you messages that do not constitute direct marketing, i.e. service messages.

General information relevant for all requests and queries

Nothing in this Privacy Statement is intended to provide you with rights beyond or in addition to your rights as a data subject under applicable mandatory data protection law.

We will use reasonable endeavours to respond to your request or query within one month. We are entitled to extend this term by another two months if the complexity of the situation so requires. If your request is manifestly unfounded or excessive we may either (i) charge you a fee, or (ii) refuse to process your request. With respect to access requests we may also charge you for extra copies. If we decide not to honour your request or answer your query, we will explain our reasons for doing so in our reply.

You can find out more and exercise any of your rights by contacting either The Hotel or The Operator as relevant, using the details given in section 10 below.

  1. PROTECTION AND STORAGE OF YOUR DATA

We have used and will continue to use reasonable endeavours to protect your personal data against loss, alteration or any form of unlawful use. Where possible, your personal data will be encrypted and stored on a virtual private server that is secured by means of state of the art protection measures. A strictly limited amount of people have access to your personal data.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

  1. COOKIES

The Website uses various cookies. We may track and record your use of our online services, either through cookies or via other means. Cookies enable us and others to monitor your browsing behaviour. Information generated by the use of cookies may constitute personal data. We may use the personal data collected in this manner for the purposes as stipulated in this Privacy Statement. If you want to know more about our use of cookies, read our Cookie policy.

  1. RETENTION OF INFORMATION

We will only retain your personal data for the period necessary to fulfil the purposes outlined in this Privacy Statement.  This may be up to 4 years, unless a longer retention period is required or permitted by law (which is typically the case in the context of our obligations under tax law). In some cases we keep transactional records (which may include your personal data) for longer periods if required or permitted by law or to meet regulatory, tax or accounting needs.

Should you choose to unsubscribe from our mailing list, please note that your personal data may still be retained on our database to the extent permitted by law.

  1. GENERAL

We are committed to resolve any complaints about our collection or use of your personal data. In case you have any questions in relation to this Privacy Statement or our practices in relation to your personal data, or you wish to exercise any of your right you may contact us using the details below.

The Hotel:

By Post:               Denham Grove Hotel, Tilehouse Lane, Denham, UB9 5DG

By Email             events@denhamgrove.com

Or:

The Operator:

By Post:              Countrywide Hotels Ltd, Kelmscott, Hattingley Road, Medstead, Alton, GU34 5NQ

By Email:            compliance@countrywidehotels.co.uk

The Hotel and The Operator will work together to ensure that any request received is dealt with by the appropriate party.  We hope to resolve any complaint brought to our attention, however if you feel that your complaint has not been adequately resolved, you reserve the right to contact your local data protection supervisory authority, which for the UK, is the Information Commissioner’s Office.

We have done our best to make sure that this Privacy Statement explains the way in which we process your personal data, and rights you have in relation thereto. We may change this Privacy Statement from time to time to make sure it is still up to date and we will notify you if we make any material updates. We may also notify you in other ways from time to time about the processing of your personal information.

© All rights reserved.

Facebook - Denham Grove Instagram - Denham Grove LinkedIn - Denham Grove LinkedIn - Denham Grove