FIVE is committed to ensuring fair and secure Processing of any information relating to its employees, external/third-party personnel, including Customers, consultants, interns, and contractors in accordance with the data privacy laws in the countries it operates, industry-leading practices, and recognized international standards on privacy and the protection of personal information.
The main objective of the FIVE Data Privacy Policy are:
The policy is applicable to all guests, employees, external/third party personnel including consultants, interns, and contractors at FIVE as well as the former employees. FIVE operates the domain www.fivehotelsandresorts.com and www.fiveglobalholdings.com for hosting its website and booking platform.
The purpose of this policy is to articulate FIVE’s position on privacy and protection of personal identifiable information (PII) and sensitive Personal Information (SPI) (Refer APPENDIX) collected during the course of its business operations, and therefore to:
Dubai – FIVE Hotel FZE, - PO Box 6438. FIVE Palm Jumeirah Dubai. No. 1, Palm Jumeirah. Dubai, United Arab Emirates
Personal Information shall be processed lawfully, fairly and in a transparent manner in relation to the Data Subject (‘lawfulness, fairness, transparency’). FIVE must ensure their practices around data collection don’t compromise the law and that their use of data is transparent to Data Subjects (refer to definitions).
Personal information should only be collected for specific, clear, and legal reasons, and it shouldn't be used in a way that goes against those reasons.
Personal information must be accurate, useful, and limited to what is needed for the purpose it is being used for. Five can't gather personal information just in case it could be useful in the future. If they keep and collect more information than they need, they may not be following this data privacy principle.
When personal information is collected, it must be correct and, if necessary, kept up to date. Every reasonable step must be taken to make sure that personal information that is wrong, given the purpose for which it is being processed, is erased or fixed as soon as possible.
Personal information should not be kept for longer than is needed for the purposes for which it is used. Personal information can be kept for longer as long as it is only used for public interest, scientific or historical research, or statistical purposes (refer appendix).
Personal information must be handled in a way that protects it from unauthorized or illegal processing and accidental loss, destruction, or damage. This can be done with the help of appropriate technical or organizational measures. FIVE needs to make sure that all the right steps are taken to keep personal information safe. This could include protecting against accidental damage or loss, unauthorized use, and threats from the outside.
Appropriate consent will be obtained from Data Subjects before their Personal Information is transferred to or from FIVE’s systems. The consent which is obtained by FIVE should be saved and retained. FIVE must be able to demonstrate that the appropriate methods and procedures are in place to manage the records of the consent, withdrawal of consent and the periodic evaluation of the records of consent should be conducted.
FIVE is required to make available the means and procedures for data subjects to exercise the following rights:
9.1.1 Rights
The Data Subject will have the right to request FIVE and obtain the following information:
9.1.2 Limitations to the right to information
FIVE may refuse to provide information, or restrict or delay the provision of information if:
Furthermore, it is possible to refuse, restrict or delay the provision of information in the following cases:
FIVE shall indicate why it is refusing, restricting or delaying the provision of the information.
The Data Subject will have the right to receive his/her Personal Information in a structured and machine-readable format where the:
The data subject may also request the controller to transfer their personal data to another controller if the above requirements are met and no disproportionate effort is required.
FIVE may refuse, restrict or delay the delivery or transfer of personal data for the reasons in 9.1.2 and provide reasons to refuse, restrict or delay the delivery or transfer.
The Data Subject shall have the right to have inaccurate Personal Information rectified. Depending on the reason for processing, a data subject may also be able to have incomplete personal information completed.
A data subject has the right to request to erase some or all of the Personal Information FIVE holds about them. but only if one of the following applies:
Data Subject will have the right to require the FIVE to restrict and stop his/her Personal Information from being used in any way. The Data Subject can exercise this right in the following circumstances:
The Data Subjects will also have the right to require the FIVE to stop the Processing of his/her Personal Information in the following circumstances:
Data Subject shall have the right to object to any decision based solely on automated processing including profiling, which produces legal consequences concerning him or other seriously impactful consequences and to require such decision to be reviewed manually.
The Data Subjects have a number of other rights in relation to their personal data. They can require FIVE to:
Cookies are information files that the web browser stores on the hard drive or in the memory of your computer when you visit our website. Cookies are assigned identification numbers that enable your browser to be identified, and allow the information contained in the cookie to be read.
Cookies are used to make your visit to our website easier, more enjoyable, and more meaningful. FIVE uses cookies for various purposes that are necessary for the desired use of the website, i.e., "technically necessary." For example, cookies are used to identify the individual as a registered user after logging in, so one does not need to log in again when navigating to different subpages. The provision of ordering and booking functions also relies on the use of cookies. Furthermore, cookies perform other technical functions necessary for the operation of the website, such as load balancing, which distributes the workload of the site across various web servers to relieve the servers. Cookies are also used for security purposes, such as preventing the unauthorized posting of content. Finally, cookies are used in the design and programming of our website, for example, to enable the uploading of scripts or codes.
Cookies in so far as they are used to identify users, qualify as Personal Information and are therefore subject to the Data Privacy law.
FIVE needs to ensure that this shall be regularly updated and reviewed by respective department SPOCs.
Data Subjects shall be notified if any additional information is obtained from them.
13.2 USE OF INFORMATION Any of the information collected by FIVE may be used in one of the following ways:
13.3 QUALITY OF PERSONAL INFORMATION
FIVE shall ensure completeness and accuracy of the Personal Information collected at the time of collection and that the Personal Information shall be kept up to date and validated on an ongoing basis
13.4 Data Processing when contacting FIVE
If the guest/ employee/ any data subject contacts FIVE through our contact addresses and channels (e.g., by e-mail, phone, or contact form), your personal data is processed. We process the data you provide us with, such as your name, email address, phone number, and your request. Additionally, the time of receipt of the request will be documented.
13.5 Data Processing when using our Chat Function
If the guest/ employee/ any data subject contact FIVE through chat for reservations/ special requests/ complaints/ concerns, their personal data will be processed. FIVE processes the data provided, such as the name of the company, name, role, email address and request. Additionally, the time of receipt of the request will be documented. This data is processed to exclusively address the request (e.g., providing information about the Hotel, assisting with contract processing such as questions about the booking, incorporating feedback to improve services, etc.)
13.6 Data Processing for Guest Profile
For creation of guest profile/ new booking/ account creation (for group bookings/ events), the following data is collected:
This personal data may be utilized to verify the identity and to check the requirements for registration. Email address is collected for future communication with the guest, which is necessary for the execution of the contract. Additionally, this data may be stored in the system/ shared drives for future reference. The data is additionally utilized to offer a comprehensive view of the individual's bookings and associated services. It aids in streamlining the handling of personal information and managing contractual commitments. This encompasses tasks such as establishing, defining content, processing, and making modifications to agreements formed with the individual through their customer account, particularly in connection to their reservations.
The processing of language and gender details serves the purpose of tailoring personalized offers, leveraging insights from the individual's profile and specific requirements. These details are subjected to statistical scrutiny and assessment of chosen proposals, contributing to the optimization of recommendations and offerings.13.7 Data Processing during website bookingsOn the FIVE websites, individuals are provided with the option to reserve an overnight accommodation. For this purpose, FIVE collects the following data, whereby mandatory fields during the booking process are marked with an asterisk (*):
The data collected serves the purpose of establishing the individual's identity prior to entering into a contractual agreement. The email address is required for booking confirmation and future communication essential for contract fulfillment. FIVE retains this data alongside pertinent booking particulars (such as room category, duration of stay, as well as description, price, and attributes of services), payment details (including chosen payment method, payment verification, and timing), and information concerning contract execution and performance (covering issues like complaints handling) to ensure accurate processing of reservations and proper contract execution.
As needed for contract fulfillment, there is the possibility of disclosing necessary information to relevant third-party service providers (such as organizers or transportation companies).
The submission of non-mandatory data is at the discretion of the individual. This data is subjected to processing with the aim of customizing FIVE's offerings according to the individual's specific requirements. Additionally, it aids in simplifying contract execution, enabling alternate communication methods if essential for contract fulfillment, and contributing to the accumulation and examination of statistical data for the purpose of enhancing the FIVE's offerings.
To process bookings through the Website, FIVE uses a software application provided by Travelclick, (Amadeus Hospitality Americas, Inc., 75 New Hampshire Avenue, Portsmouth, NH 03801), provider for channel management and guest management solutions. It may receive and share with us any personal data you provide to it when booking a stay with us either through our website, mobile application or through another website partnering with Amadeus Hospitality Americas, Inc. It may further receive from us or have access to your contact and check-in and check-out information (e.g. guest name(s), (email) address, phone number, etc.). Its privacy related terms are accessible here: https://www.amadeus-hospitality.com/privacy-policy/). Therefore, the data may be stored in a database of the party, which may allow the party to access your data if this is necessary for providing the software and supporting its use. Information about data processing by third parties and any potential transfer abroad can be found in this Privacy Policy
13.8 Data Processing during bookings received through a booking platform
When reservations are made via a third-party platform (such as Booking, Hotel, Expedia, TripAdvisor, Trivago, and similar platforms), FIVE obtains a variety of personal information pertaining to the booking from the corresponding platform operator. Typically, these details align with the information outlined in Section 13.7 of the Privacy Policy. Furthermore, any queries or concerns relating to the booking might be relayed to the establishment. FIVE will process this data using the individual's name to ensure precise recording of the booking and seamless provision of the requested services.
13.9 Data Processing when Reserving a Table
On FIVE’s website, guests have the option to initiate a table reservation at a restaurant featured on the website. To facilitate this process, the establishment gathers specific data, and obligatory fields for reservations made via the website are identified by an asterisk (*):
The data is collected and processed with the primary objective of managing the reservation procedure. This encompasses tailoring the reservation request according to the individual's preferences and initiating contact in case of uncertainties or issues. FIVE retains this data alongside pertinent reservation particulars (such as request date and time), reservation information (including table assignment), and information related to contract execution and performance. This approach ensures the accurate processing of reservations and proper fulfillment of contractual obligations.
To process table reservations, FIVE uses a software application provided by SEVENROOMS INC, 228 Park Ave South, PMB 33706, New York, NY 10003, the provider of our restaurant reservation system. It may receive and share with us any personal data you provide to it, either directly, including by email, or through our website, mobile application or social media accounts. Its privacy related terms are accessible here: https://sevenrooms.com/en/privacy-policy/.
13.10 Data processing during payment processing
When guests use electronic payment methods for purchases, services, or reservations at FIVE (including F&B outlets), personal data processing is required. Payment instrument details are sent to payment providers via terminals. These providers also receive transaction specifics. FIVE gets payment confirmations with receipt numbers. In case of online booking and payments, Guests should check provider policies and terms.
For processing payment through payment links sent to guests/ payment processing at the hotel, FIVE uses services of a third-party platform, Planet Payment Group Holdings Ltd., Martin House, IDA Business Park, Dangan, Galway, H91 A06C, as the provider for our payment processing solution (Planet/3C). FIVE does not have access to and thereby does not control any personal data directly shared with or through Planet/3C. Please refer to their privacy statements with respect to their data processing, accessible here: https://www.planetpayment.com/en/privacy/; https://www.planetpayment.com/en/gdpr-compliance/
13.11 Data Processing related to the recording and Invoicing of rendered Services
In instances where guests avail themselves of services throughout their stay (such as extended nights, wellness treatments, restaurant amenities, or activities), beyond their contractual information, FIVE undertakes the collection and processing of booking particulars (comprising booking time and comments) along with data pertinent to the reserved and rendered services (encompassing service description, cost, and time of service provision). The primary intent of this data processing is to effectively manage the execution of the provided service.
13.12 Data Processing related to Email Marketing
If the guest registers for FIVE’s marketing emails to be aware of the marketing offers, (eg. as part of an order, booking, or reservation), the following data is collected. Mandatory fields are marked with an asterisk (*):
By agreeing to the terms and conditions, the guest consents to the processing of this data in order to receive marketing emails from us about our hotel and related information on products and services. These marketing emails may also include invitations to participate in contests, to provide feedback, or to rate our products and services. The collection of the salutation, first and last name allows us to associate the registration with any existing customer profile and personalize the content of the marketing emails accordingly.
FIVE shall use the data to send marketing emails until consent is withdrawn. The guest can withdraw their consent at any time, in particular by using the unsubscribe link included in all marketing emails. For sending marketing emails, we use a software application provided by Travelclick (Amadeus Hospitality). Therefore, your data may be stored in a database of the company, which may allow them to access data if this is necessary for providing the software and supporting its use.
13.13 Data Processing when Submitting Guest Feedback
During stay or post-stay, all guests have an opportunity to provide FIVE with feedback (e.g., positive feedback, criticism, and suggestions for improvement) through in-stay and post-stay survey with questions grading on cleanliness, services, sustainability among others. For this purpose, the following data is collected –
The processing of your data is carried out as part of our quality management and ultimately aims to better tailor our services and products to the needs of our guests. Specifically, your data is processed for the following purposes:
- Clarification of the request, e.g., obtaining input from employees and supervisors or seeking further information from you, etc.;
- Evaluation and analysis of information, e.g. compiling satisfaction statistics, com-paring individual services, etc.; or
- Taking organizational measures based on the findings, e.g. addressing shortcomings/deficiencies/misconduct, for example, through repairing defective equipment, providing instructions, as well as giving praise or issuing warnings to employees
In connection with guest feedback, FIVE uses a software application provided by Shiji Information Technology Spain, S.A, Passeig de Gràcia, 17, planta 6, 08007 Barcelona (Spain), the provider of our guest experience improvement suite (ReviewPro). It may receive and share with us any personal data you provide to it through the dedicated platform in the course of providing a feedback on the stay. Its privacy related terms are accessible here: https://www.reviewpro.com/privacy/.
13.14 Data Processing in connection with Video Surveillance
To ensure the safety of our guests, employees, and our property, as well as to prevent and address unlawful behavior (in particular, theft and property damage), the entrance area and the publicly accessible areas of our hotel, excluding sanitary facilities and employee office premises, maybe monitored by cameras. The image data will only be viewed if there is a suspicion of unlawful behaviour. Otherwise, the recorded images will be automatically deleted as per the guidelines suggested by local laws and regulations.
We currently use video surveillance as described below. We believe such use is necessary for legitimate business purposes, including:
Camera locations are chosen to minimize viewing of areas not relevant to the legitimate purpose of surveillance. As far as practicable, surveillance cameras are not aimed at private homes, gardens or other areas of private property.
Personnel using surveillance systems are appropriately trained to ensure they understand and comply with legal requirements related to the processing of relevant data.
The server is stored at a central secure place in the Engineering Office (locked). The system is set up with an authorization structure that will only give selected employees (access to the video recordings.
Recording Duration: Detected movements are recorded with this system and deleted again after 72 hours in order to comply with data protection requirements. (in case of Zurich). Applicable timeline in case of Dubai as per regulatory requirements.
To ensure that the rights of those captured by the CCTV system are protected, we will ensure that the data captured by CCTV cameras is stored in a manner that maintains its integrity and security. This may also include encrypting the data where possible.
The data recorded by the CCTV system is stored digitally. CCTV camera data is not kept indefinitely but is permanently deleted once there is no longer a reason to keep the recorded information in line with legal requirements. Exactly how long the images are kept depends on the purpose for which they were recorded.
13.15 Data Processing for Fulfilling Legal Reporting Obligations
Upon arrival at the hotel, FIVE may require the following information from the guests and their accompanying persons:
FIVE collects this information to fulfil legal reporting obligations, which arise in particular from hospitality or police regulations. To the extent required by applicable laws, this information is forwarded to the competent authority.
13.16 Data Processing in Job Applications
Applicants can apply for a position at FIVE either spontaneously or in response to a specific job advertisement. In both cases, FIVE will process the personal data provided by the applicants.
FIVE uses the data to assess the application and suitability for employment. Application documents from unsuccessful applicants may be retained for a period of five years.
13.17 Data Processing when Visiting our Website (Log File Data)
When an individual visits the FIVE Website, the servers of our hosting provider may temporarily store every access in a log file. The following data is collected without your intervention and stored by us until automatically deleted:
This data is automatically deleted post termination of access and not stored on our server.
Finally, when you visit the FIVE Website, cookies are used, as well as other applications and tools that rely on the use of cookies. In this context, the data described here may also be processed. For more information, please refer to Section 10 of this Privacy Policy.
13.18 Data Processing with regards to Social Media platforms
FIVE website contains links to its profiles on the social networks of the following providers:
If the individual clicks on the icons of the social networks, the individual will be automatically redirected to our profile on the respective network. This establishes a direct connection between your browser and the server of the respective social network. As a result, the social network receives information that the individual has visited the FIVE Website with the IP address and clicked on the link. This may also involve the transfer of data to servers abroad.
If the individual clicks on a link to a social network while logged into their user account on that social network, the content of our website can be associated with your profile, allowing the social network to directly link your visit to our website to your account. If this must be prevented, please log out of the account before clicking on the respective links. A connection between access to the website and the user account will always be established if one logs in to the respective social network after clicking on the link. The data processing associated with this is the responsibility of the respective provider in terms of data protection. Therefore, please refer to the privacy notices on the social network's website.
Social media plugins are added to make it easier for the individual to share content from the website. The social media plugins help us to increase the visibility of our content on social networks, thereby contributing to better marketing.
The plugins are deactivated by default on the website, and therefore, no data is sent to the social networks when the Website is accessed. To enhance data protection, FIVE has integrated the plugins in such a way that a connection is not automatically established with the servers of the social networks. Only when the individual activates the plugins by clicking on them, and thus give the consent to the transmission and further processing of data by the providers of the social networks, the browser establishes a direct connection to the servers of the respective social network.
13.19 Online advertising and targeting
We use the services of various companies to provide you with interesting offers online. In the process of doing this, your user behavior on our website and websites of other providers is analyzed in order to subsequently be able to show you online advertising that is individually tailored to you.
Most technologies for tracking your user behavior (Tracking) and displaying targeted advertising (Targeting) utilize cookies, which allow your browser to be recognized across different websites. Depending on the service provider, it may also be possible for you to be recognized online even when using different end devices (e.g., laptop and smartphone).
In addition to the data already mentioned, which is collected when visiting websites and using cookies and which may be transmitted to the companies involved in the advertising networks, the following data, in particular, is used to select the advertising that is potentially most relevant to you:
We and our service providers use this data to determine whether you belong to the target audience we address and take this into account when selecting advertisements. . For example, after visiting our website, you may see advertisements for the products or ser-vices you have viewed when you visit other sites (Re-targeting). Depending on the amount of data, a user profile may also be created, which is automatically analyzed; the advertisements are then selected based on the information stored in the profile, such as belonging to certain demographic segments or potential interests or behaviors’. These advertisements may be displayed to you on various channels, including our website or app (as part of on- and in-app marketing), as well as advertising placements provided through the online advertising networks we use, such as Google.
The data may then be analyzed for the purpose of settlement with the service provider, as well as for evaluating the effectiveness of advertising measures in order to better understand the needs of our users and customers and to improve future campaigns. This may also include information that the performance of an action (e.g., visiting certain sections of our Website or submitting information) can be attributed to a specific advertising. We also receive from service providers aggregated reports of advertisement activity and information on how users interact with our website and advertisements.
As explained earlier, this website uses the services of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (Google) for online advertising. Google uses cookies (see the list here), which allow your browser to be recognized when you visit other websites. The information generated by the cookies about your visit to these websites (including your IP address) is transmitted to and stored by Google on servers in the United States (for information on the absence of an adequate level of data protection and the proposed safeguards, see Sections 5.2 and 5.3). Further information on data protection at Google can be found here. You can withdraw your consent at any time by rejecting or deactivating the relevant cookies in the settings of your web browser. Further options for blocking advertising can be found here.
The information should not be provided to data gathering companies for marketing purposes.
16.2 CROSS- BORDER DATA TRANSFERS INTRA-GROUP
Personal Information transferred across geographies from where FIVE operates should follow the following:
Binding corporate rules that ensure an adequate level of data protection in cross-border data flows within a single legal entity or a group of affiliated companies.
DATA TRANSFER TO THIRD PARTIES
Individuals are responsible for helping FIVE keep their personal data updated. The following are the responsibilities of individuals who have access to personal data:
The RACI Matrix lays out all the deliverables against members' roles, while responsibilities and decision-making are delegated to each role using the four elements comprising RACI.
FIVE may hold the following types of SPI: