Privacy Policy
Privacy Policy – Table of Contents
Preamble
Hôtel Aultia is committed to ensuring that the collection and processing of your data are carried out lawfully, fairly and transparently, in accordance with the General Data Protection Regulation (GDPR) and French Law No. 78-17 of 6 January 1978 on information technology, data files and civil liberties.
The collection of its customers’ personal data is limited to what is strictly necessary, in accordance with the principle of data minimisation, and specifies the purposes for which this data is collected, whether providing this data is optional or mandatory in order to handle requests, and who may have access to it.
I. About us
Hôtel Aultia is an establishment whose registered office is located at 25 rue de la Pêche, 80460 Ault Onival, France, registered with the Amiens Trade and Companies Register (RCS) under SIRET number 510 377 823 00016.
The Company offers the following services: hotel accommodation and catering (restaurant) services.
II. Definitions
Site means the Company’s website, namely https://www.hotelaultia.com
Cookies: a cookie is a piece of information placed on an internet user’s hard drive by the server of the website they visit. It contains several pieces of data: the name of the server that placed it, an identifier in the form of a unique number or text, and possibly an expiry date. This information is sometimes stored on the computer in a simple text file that a server accesses in order to read and record information.
Personal data means any information relating to a natural person who is identified or who can be identified, directly or indirectly, by reference to an identification number or to one or more factors specific to them. An example is the User’s email address.
Customer means any natural or legal person who makes a booking on the Site, through our partner providers (e.g. Booking.com) or directly with the receptionist on duty at the establishment whose address is set out in Article I.
Booking means any booking made by the User, Customer, Professional or Consumer in order to benefit from the Company’s Services.
General Terms and Conditions of Sale and Use or CGV/CGU mean the Company’s general terms and conditions of sale and use.
Consumer means the buyer, a natural person, who is not acting for professional purposes and/or is acting outside their professional activity.
Professional means the buyer, a legal or natural person, acting within the scope of their professional activity.
Services means all the services and/or products offered to Users, Customers and Professionals by the Company through the Sites owned by the Company.
Company means Hôtel Aultia, more fully identified in Article I hereof.
User means any person who uses the Site.
Account means the customer’s personal area with the Company’s partner providers.
Quote means a quotation drawn up by the Company for a specific, bespoke service requested by the Customer.
GDPR means the General Data Protection Regulation applicable from 25 May 2018.
Processing of personal data means any operation or set of operations performed on such data, whatever the method used (collection, recording, organisation, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or any other form of making available, alignment or combination, blocking, erasure or destruction, etc.).
III. Protection of Personal Data
In accordance with the French Data Protection Act (‘Informatique et Libertés’) of 6 January 1978 and General Data Protection Regulation 2016/679 (GDPR), the information concerning you is intended for the Company, acting as data controller. You have the right to access, rectify and erase the data concerning you (see Article VIII for details). You may exercise this right by sending an email to contact@hotelaultia.com
By connecting to the company’s hotelaultia.com website, you access content protected by law, in particular by the provisions of the French Intellectual Property Code (Code de la propriété intellectuelle). The Company authorises only strictly personal use of the information or content you access, limited to saving it on your computer for display on a single screen, as well as reproduction, where permitted (download link or button), for copying or printing on paper. Any other use is subject to our prior express authorisation. By continuing your visit, you agree to comply with the above restrictions.
The Company calls on its Customers, Users, Consumers and Professionals to comply with the laws in force and the customary ethical rules necessary to establish a relationship of trust between the Company and its Customers, Users, Consumers and Professionals.
The Company requires its Users to comply with a set of obligations through its CGV/CGU.
Any breach of these obligations may result in the cancellation, without notice, of a booking made on the Company’s website or directly with Hôtel Aultia.
PLEASE NOTE THAT THE COMPANY DOES NOT EXCHANGE OR RENT OUT THE FILES OF ITS CUSTOMERS AND PROSPECTS.
The Company’s website is not intended for minors. We do not knowingly collect or process personal data relating to minors. Should we become aware of the collection of personal data relating to minors without the prior authorisation of the holder of parental authority, we would take appropriate measures to delete such personal data from our servers.
IV. Data Controller
The controller of the personal data referred to herein is Mr Nicolas-Salvatore Morgillo, director of Hôtel Aultia, whose company details are set out in Article I on this page.
V. Nature of the Data Collected
User information and rights
The company hereby clearly informs you about the processing of personal data it carries out as part of its activity, and how data is collected, used and protected.
Every User, Customer, Consumer and Professional has the right to request from the data controller, that is, Mr Nicolas-Salvatore Morgillo:
- access to the personal data provided;
- the rectification or erasure of that data;
- restriction of the processing relating to them;
- to object to the processing;
- the portability of the data;
- to lodge a complaint with the CNIL (the French data protection authority).
Sub-processing
The Company undertakes to ensure that any processor provides sufficient contractual guarantees regarding the implementation of appropriate technical and organisational measures, so that the processing meets the requirements of the European data protection regulation (see the list of data recipients in Article VII).
Data collected on the site (contact form)
When a Customer, User, Consumer or Professional makes a booking request on the site via our contact form, the following data is collected and processed by the Company: email, first name, surname, telephone, country, arrival date, departure date, number of adult(s), number of child(ren), and any additional information the Customer, Professional, User or Consumer deems necessary for their booking request.
Data collected on the site (via our provider TheOriginals Hotels)
When a Customer, User, Consumer or Professional makes a booking request on the site, the following data is collected and processed by our processor TheOriginals Hotels: email, first name, surname, country, telephone number, IP address, room type, booking rate, stay dates, bank card number (16 digits + expiry date), and any additional information the customer, consumer, professional or user may provide if they consider it appropriate and useful for their booking.
The data is then sent to us by email, with the exception of the bank card number (16 digits + expiry date), which remains securely stored on the TheOriginals Hotels server and that of our PMS. This data is only visible using a password and login via the intranet between the Company and its providers.
Data collected at the Company’s establishment
On a customer’s arrival, the following data is collected and processed: arrival and departure dates at the establishment, room number, number of breakfasts (if any), order history, complaints, incidents, and information relating to correspondence on our site or directly with the Company (email message sent directly).
Some data is collected automatically as a result of the user’s actions on the site (see the paragraph on cookies in Article IX).
Data collected by a partner provider
A customer, consumer or professional may book a service from the Company through a partner provider. Data collected in this way (e.g. Booking.com) is subject to the CGV/CGU and Privacy Policy of these Partner Providers as well as those of the Company.
The data submitted must not include sensitive personal data, such as government identifiers (e.g. social security numbers, driving licence numbers, or taxpayer identification numbers), full credit card numbers (unless requested, in particular when making a booking on the site by completing the relevant field of the booking form) or personal bank account numbers, medical records, or information relating to individuals’ care requests, this list not being exhaustive.
Regarding the collection of identity data
Making a room available requires the customer to be identified beforehand using their identity card or any other document enabling their identification. The personal details (surname, first name, postal address) appearing on the identity document are used to fulfil our legal obligations arising from the service provided as set out in the booking. The customer, consumer or professional must not provide false personal information and must not make a booking on behalf of another person without their authorisation. The contact details provided must always be accurate and up to date.
Collection of device data
Some technical data from your device is collected automatically by the Site and the server. This information includes, in particular, your IP address, internet service provider, hardware configuration, software configuration, and browser type and language. The collection of this data is necessary for proper browsing of the Company’s website.
The Company also offers a personalised experience using automated decision-making via its newsletter email messages.
Collection of technical data for commercial and statistical purposes
The technical data from your device is automatically collected and recorded by the server and our processors for advertising, commercial and statistical purposes. This information helps us to personalise and continuously improve your experience on our Site. We do not collect or retain any personal identifying data (surname, first name, address) that may be attached to a piece of technical data.
VI. Purposes of the Processing
The main purpose of collecting your personal data is to offer you a safe, optimal, efficient and personalised experience at the establishment. To this end, you agree that we may use your personal data to:
- provide our services and facilitate their operation, including by carrying out checks concerning you for this purpose;
- resolve any issues in order to improve the use of our site and services;
- personalise, assess and improve our services, content and documentation;
- analyse the volume and history of your use of the Company’s services;
- keep you informed about the Company’s services;
- prevent, detect and investigate any potentially prohibited and illegal activities, or activities contrary to good practice, and ensure compliance with the Company’s CGV/CGU;
- comply with our legal and regulatory obligations.
For customers who have made a booking directly on the site, by telephone or through the Company’s partner providers, we process their data for the performance of the service contract.
For our newsletter, we process your personal data on the basis of the explicit consent you have given for this purpose.
VII. Data Recipients
The personal data concerning you collected on the site, at the establishment and with partner providers is intended to be used by the Company and may be passed on to the sub-processing companies the Company may call upon in the course of delivering its services. The Company ensures compliance with data protection requirements for all its sub-processors. The Company does not sell or rent your personal data to third parties for marketing purposes. As a matter of ethics reflecting our values, we do not enter into any strategic partnership aimed at sharing your data to promote a third-party company’s service or product.
The Company does not disclose your personal data to third parties, except where:
- you request it or authorise the disclosure;
- disclosure is required to process transactions or provide services you have requested;
- the Company is compelled to do so by a government authority or regulatory body, in the event of a judicial requisition, a subpoena, or any other similar governmental or judicial requirement, or to establish or defend a legal claim;
- the third party is acting as the Company’s agent or processor in the performance of the services.
The data recipients are currently:
- MIXIT7: server management (IT outsourcing)
- XXX: operations relating to bookkeeping
- Nicolas-Salvatore Morgillo: publishing of the Site
- TheOriginals Hotels: management of bookings and payments
- Google Analytics: site statistics and technical analysis
- XXX: email exchange between the Company and its Users, Consumers, Customers and Professionals
- XXX: Wi-Fi service in the hotel available to customers, employees, consumers and professionals
VIII. Right of Access, Rectification and Erasure
In accordance with the French Data Protection Act (Informatique et Libertés) and General Data Protection Regulation 2016/679 (GDPR), you have the rights of access, rectification and erasure of the personal data concerning you, which you may exercise by sending an email to contact@hotelaultia.com
Your request will be processed within 30 days. We may ask you to accompany your request with a photocopy providing proof of identity or authority.
You may also, at any time, modify the personal data concerning you in relation to our newsletter yourself, by clicking the link at the bottom of each of our newsletter emails, either to unsubscribe or to update your contact details.
IX. Use of Cookies
Cookie retention period
In accordance with the CNIL’s recommendations, the maximum retention period for cookies is 13 months from when they are first placed on the User’s device, as is the period of validity of the User’s consent to the use of these cookies. The lifespan of cookies is not extended with each visit. The User’s consent must therefore be renewed at the end of this period.
Purpose of cookies
Cookies may be used for statistical purposes, in particular to optimise the services provided to the User, by processing information about access frequency, page personalisation, as well as the operations carried out and the information viewed.
You are informed that the Company may place cookies on your device. The cookie records information relating to browsing on the site (the pages you have viewed and may view) that we will be able to read during your subsequent visits.
The cookie will allow the Company, for the duration of the cookie’s validity or storage, to identify your computer during your future visits. The Company’s partners or providers, or third-party companies, may also, subject to your choices, place cookies on your computer.
There are two main categories of cookies:
- So-called ‘Technical’ cookies. These cookies are essential for browsing our site, in particular for the proper completion of the ordering process;
- So-called ‘Optional’ cookies. These cookies are not essential for browsing our site but may, for example, make your searches easier, optimise your user experience and, for us, better target your expectations, improve our offering, or optimise the operation of our site.
The retention period for this information on your computer is one year. Only the issuer of a cookie is able to read or modify the information contained in that cookie. No cookie enables us to identify your civil status.
The User’s right to refuse cookies
Deactivation may result in degraded operation of the service. You acknowledge that you have been informed that the Company may use cookies, and you authorise it to do so.
If you do not wish cookies to be used on your device, most browsers allow you to disable cookies through their settings options. You can object to cookies being stored by configuring your browser as follows:
For Chrome:
- On your computer, open Chrome.
- At the top right, click Settings (the three dots).
- Click Advanced settings, then Content settings.
- At the top of the page, turn off ‘Allow sites to save and read cookie data’.
For Mozilla Firefox:
- Select the ‘Tools’ menu, then ‘Options’.
- Click the ‘Privacy’ icon.
- Locate the ‘Cookie’ menu and select the options that suit you.
For Microsoft Internet Explorer:
- Select the ‘Tools’ menu, then ‘Internet Options’.
- Click the ‘Privacy’ tab.
- Select the desired level using the slider.
For Edge:
- Go to Settings.
- Under Clear browsing data, select Choose what to clear.
- Tick the boxes next to each type of data you wish to clear, then select Clear.
For Opera:
- Select the ‘File’ menu, then ‘Preferences’, then ‘Privacy’.
Please note: if you choose to refuse the storage of cookies on your computer, or if you delete those already stored, we accept no liability for the consequences relating to the degraded operation of our services arising from our inability to store or read the cookies necessary for their operation that you have refused or deleted.
X. Data Retention
General
The Company collects and retains your personal data for the purposes of performing its contractual obligations, as well as information on how and how often our services are used. Personal data must be retained only for as long as necessary to achieve the purpose for which it was collected. The Company stores your data only for as long as necessary to provide the service and, accordingly, the Company erases your bank details once the service has been completed. The retention of our customers’, professionals’, consumers’ and users’ data varies according to the type of data concerned. For example, your statistical data that is more than 13 months old will be deleted. Other data may be deleted at any time, in accordance with the provisions set out above.
Retention period for personal and sensitive data
In accordance with Article 6-5° of French Law No. 78-17 of 6 January 1978 on information technology, data files and civil liberties, sensitive data (Bank Card) undergoing processing is not retained beyond the time necessary to perform the obligations defined at the conclusion of the contract or the predefined duration of the contractual relationship.
Personal data (surname, first name, email, postal address) undergoing processing is retained for a period of 3 years in our booking software.
Deletion of data after account closure
Data purging measures are in place to provide for effective deletion once the retention or archiving period necessary to fulfil the determined or required purposes has been reached. In accordance with French Law No. 78-17 of 6 January 1978 on information technology, data files and civil liberties, you also have a right to erase your data, which you may exercise at any time by contacting the Company.
Deletion of data after 3 years of inactivity
For security reasons, if you have not visited our establishment for more than 3 years, your personal data will be deleted.
Deletion of data after 12 months in the Newsletter
If you have not been active within the newsletter, that is, opened and/or clicked a link in an email, for a defined period, you will receive an email inviting you to carry out an action (clicking a link) before permanent deletion from the relevant list.
XI. Data Storage Location and Transfers
The hosting servers on which the Company processes and stores your data on the site are located exclusively within the European Union.
The Company undertakes to inform you immediately, insofar as we are legally permitted to do so, in the event of a request from an administrative or judicial authority relating to your data.
XII. Security
As part of its services, the Company attaches the utmost importance to the security and integrity of the personal data of its customers, consumers, professionals and users. Accordingly, and in accordance with the GDPR, the Company undertakes to take all appropriate precautions to preserve the security of the data and, in particular, to protect it against any accidental or unlawful destruction, accidental loss, alteration, unauthorised disclosure or access, as well as against any other form of unlawful processing or communication to unauthorised persons.
To this end, the Company implements the digital industry’s standard security measures to protect personal data from unauthorised disclosure. By using the encoding methods recommended by the digital industry, the Company takes the necessary measures to protect payment-related information, it being noted that the Company does not offer payment directly on site but goes through an external service secured by our processor TheOriginals Hotels.
Furthermore, in order to prevent, in particular, any unauthorised access and to ensure the accuracy and proper use of the data, the Company has put in place electronic and manual procedures to safeguard and preserve the data collected through its services.
Nevertheless, no one can consider themselves completely safe from a hacker attack. This is why, should a security breach affect you, the Company undertakes to inform you as soon as possible and to use its best efforts to take all possible measures to neutralise the intrusion and minimise its impact.
Should you suffer harm as a result of a third party exploiting a security breach, the Company undertakes to provide you with all the assistance necessary for you to assert your rights.
It should be borne in mind that any user, customer or hacker who discovers and exploits a security breach is liable to criminal penalties, and that the Company will take all measures, including filing a complaint and/or bringing legal action, to protect the data and rights of its users and its own, and to limit the impact as far as possible.
Informing the User in the event of a security breach
We undertake to implement all appropriate technical and organisational measures, through physical and logistical security means, in order to guarantee a level of security appropriate to the risks of accidental, unauthorised or unlawful access to, disclosure, alteration, loss or destruction of the personal data concerning you. In the event that we become aware of unlawful access to the personal data concerning you stored on our servers or those of our providers, or of unauthorised access resulting in the materialisation of the risks identified above, we undertake to:
- notify you of the incident as soon as possible where this is a legal requirement;
- investigate the causes of the incident;
- take the necessary measures, within reason, to mitigate the adverse effects and harm that may result from the said incident.
Under no circumstances may the commitments defined in the point above regarding notification in the event of a security breach be construed as any acknowledgement of fault or liability as to the occurrence of the incident in question.
XIII. Liability and Warranties
Except in cases of force majeure, the Company guarantees the User, Consumer, Customer and Professional the proper performance of its service in accordance with these General Terms and Conditions.
Any compensation payable by the Company to the User or to a third party, by reason of the liability of the Company, its subsidiaries or its partners, in connection with the performance hereof, may not exceed the price paid by the User, Customer, Professional or Consumer in consideration for the service(s) giving rise to that liability (e.g. the price of a room).
The Company does not systematically monitor the way in which its services are used, in particular the use of the equipment available in the room and the common areas, which remains the responsibility of the Customer, Consumer or Professional.
Under no circumstances may the Company be held liable towards third parties for any harm resulting from the use of the services on behalf of the User, Customer, Consumer or Professional, on any grounds whatsoever.
The User’s liability
The Customer, Consumer, Professional and User is solely responsible for the way in which they use the room, the common areas and the equipment made available to them in connection with the performance hereof.
The User, Customer, Consumer or Professional may be held liable for failure to comply with these General Terms and Conditions of Sale and Use, as well as the privacy policy, or any applicable legal or regulatory provision or provision arising from an international convention.
The User, Customer, Consumer or Professional shall indemnify the Company against any harm, claim or third-party recourse resulting from a breach, by the User, Customer, Consumer or Professional, of these General Terms and Conditions of Sale and Use as well as the Company’s Privacy Policy, or of any applicable legal or regulatory provision or provision arising from an international convention.
XIV. Data Portability
The Company undertakes to offer you the possibility of having all the data concerning you returned to you on simple request. The User is thereby guaranteed better control over their data and retains the possibility of reusing it. This data must be provided in an open and easily reusable format, directly to another data controller where desired and technically possible.
XV. Deletion of Data
Deletion of data on request
The User, Customer, Consumer or Professional may delete their Data at any time, by simple request to the Company or directly via a link at the bottom of each of our newsletter emails.
Cancellation of a booking in the event of a breach of the Privacy Policy
In the event of a breach of one or more provisions hereof, or of any other document incorporated herein by reference, the Company reserves the right to cancel your booking with no possibility of a refund where payment has already been made.
XVI. Transfer of Data to Countries with an Equivalent Level of Protection
The Company undertakes to comply with the applicable regulations on data transfers, even though the Company currently does not transfer data to foreign countries for almost all of its processing activities. Where this is necessary to provide our services, it is done in the following ways:
- The Company transfers the personal data of its Users, Customers, Consumers and Professionals to countries recognised as offering an equivalent level of protection and recognised by the CNIL as having a sufficient level of protection.
- The Company transfers personal data to recipients able to provide sufficient guarantees of GDPR compliance.
- The Company transfers personal data only to the extent strictly necessary for the purpose of the processing concerned, that is, booking a room at Hôtel Aultia.
Currently, the only processing activities affected by this provision concern:
The booking of services offered by the Company to the user who has decided to make a booking via the processor TheOriginals Hotels from the company’s website. Only the following data is transferred: CUSTOMER ID, email address, purchase amount, product designation, telephone, postal address (if provided), the 16 digits of the bank card and its expiry date.
The management of the ethical and personalised commercial relationship through information pushed to Facebook via the ‘Custom Audience’ feature offered by Facebook. The email address is the only data transferred, in order to enable Facebook to identify its users and build an audience.
Questionnaires completed by the customer on Google’s services (Google Doc, Google Drive, Google Form, Google Sheet, etc.). The Personal Data depends on what the customer wishes to share (company name, SIRET number, surname, first name, email).
For the list of countries providing a sufficient legal level of protection: CNIL – Data protection around the world.
XVII. Changes to the Privacy Policy
The Company reserves the right to change this Privacy Policy at any time, in particular to reflect changes to the laws and regulations in force. Any changes made will be notified to you via our website and/or by email, where possible at least thirty (30) days before they come into effect. We recommend that you check these rules from time to time to stay informed of our procedures and rules regarding your personal information.
In the event of any changes hereto, the Company undertakes not to substantially lower the level of confidentiality without first informing the persons concerned.
XVIII. Governing Law and Language
This Privacy Policy is governed by French law. This reference document is drafted in French. Should it be translated into one or more languages, only the French text shall prevail in the event of a dispute. The invalidity of any clause does not render the Privacy Policy invalid. The temporary or permanent non-application by the Company of one or more clauses hereof shall not constitute a waiver on its part of the other clauses hereof, which continue to have effect.
XIX. Disputes and Jurisdiction
Any dispute to which the privacy policy may give rise, in particular concerning its validity, interpretation and performance, their consequences and any follow-up thereto, shall be submitted to the courts having jurisdiction in the district of the city of Amiens.
XX. Contact
Any question concerning the Company’s Privacy Policy may be sent by email to contact@hotelaultia.com or by post to the following address:
Hôtel Aultia, 25 rue de la Pêche, 80460 Ault Onival, France.
Telephone: +33 3 22 30 04 04
Email address: contact@hotelaultia.com