13.10.2018 Views

artotel_less_arty_issues_v2_180910

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

21<br />

All entities that accept, store, process or transmit credit card<br />

data must comply with the PCI DSS. Where PCI or PCI DSS is<br />

mentioned, it is referring to Payment Card Industry Data<br />

Security Standard version 2.0<br />

The hotel privacy policies<br />

PPHE Hotel Group and its affiliates and subsidiaries, including<br />

art’otel, have adopted privacy policies to protect the guest data<br />

we collect from and about guests: through our websites, the<br />

reservation system, our loyalty programmes, and the hotels we<br />

own or operate. Our privacy policies reflect the importance we<br />

place on earning and keeping the trust of guests who share<br />

their personal information with us.<br />

art’otel privacy policies describe what guest data art’otel and<br />

its affiliates and subsidiaries collect, how art’otel uses it, with<br />

whom art’otel shares it, and for what purposes. The art’otel<br />

privacy policies state that when art’otel shares guest data with<br />

its Licensees, the Licensees are legally bound to use that guest<br />

data only for the purposes for which art’otel provides it to the<br />

Licensee, and to take its best efforts to protect the data against<br />

unauthorised access or misuse. Should art’otel share data with<br />

a Licensee not located in the EU, an assessment of the legal<br />

requirements in order to share data must be performed.<br />

To review art’otel privacy policies, visit;<br />

http://www.pphe.com/site-services/privacy-policy<br />

Ownership & processing of guest data<br />

As between Licensee and art’otel, art’otel owns all art’otel guest<br />

data. Licensee may process art’otel guest data subject to the<br />

following terms and conditions:<br />

Limited purposes<br />

Licensee may process art’otel guest data only in connection<br />

with the operation of an art’otel, and only for the purposes for<br />

which it was originally collected or to which the guest has<br />

since consented.<br />

Compliance with laws<br />

Licensee may process art’otel guest data only as permitted<br />

under applicable privacy and data protection laws. These laws<br />

vary from country to country, and the laws of more than 1<br />

country may apply. Licensee should consult legal counsel for<br />

advice regarding Licensee’s obligations under privacy and<br />

data protection laws.<br />

Respecting choices<br />

Licensee must respect guest privacy preferences, which include<br />

email delivery preferences.<br />

Access<br />

Licensee must promptly forward to art’otel any individual’s<br />

request for access to his or her guest data, and co-operate with<br />

art’otel, as art’otel may reasonably require, to respond to the<br />

guest’s request.<br />

Retention<br />

Where (local) data protection laws do not impose a maximum<br />

length of storage of data, and such laws must at all times be<br />

complied with, Licensee must return or securely dispose of (i.e.,<br />

shred, securely wipe or degauss) all paper or electronic media<br />

containing art’otel guest data that is not stored in the property<br />

management system if and when:<br />

• It is no longer needed for the purposes for which it was<br />

provided to you<br />

• art’otel requests that you do so<br />

• Licensee ceases to be an art’otel Licensee<br />

Security<br />

Licensee must develop, implement, maintain, assess and update<br />

appropriate administrative, technical and physical safeguards<br />

to protect the confidentiality, security and integrity of art’otel<br />

guest data. This includes acquiring and maintaining PCI<br />

compliance.<br />

Sharing<br />

Licensee may not disclose art’otel guest data without the written<br />

consent of the guest, except that you may disclose guest data:<br />

• To Team Members who have a need to know to perform<br />

their duties, and who have been made aware of their<br />

responsibility to protect the confidentiality and security of<br />

guest data; and<br />

• To Team Members, contractors and service providers who<br />

have a need to know to perform services on your behalf,<br />

provided they are legally bound by obligations comparable<br />

to those set forth in these terms and conditions, to the extent<br />

required by applicable law, subpoena, court order or other<br />

legal process, provided you have the guests’ written<br />

approval; and<br />

• Given art’otel prior written notice of the required<br />

disclosure and the opportunity, if reasonably possible,<br />

to contest the required disclosure; and<br />

• You have, to the extent reasonably possible, taken<br />

measures to limit the disclosure, and protect the<br />

confidentiality and security of the information requested<br />

International Transfers<br />

You may not transfer art’otel guest data to another country<br />

without taking adequate measures to protect the guest data in<br />

accordance with applicable laws.<br />

Enforcement<br />

You must promptly notify art’otel of any complaints received,<br />

and any notices of investigation or non-compliance received<br />

from any governmental or regulatory authority or agency<br />

related to the processing of guest data, and co-operate with<br />

art’otel with respect to any such complaint or investigation.<br />

The <strong>less</strong> <strong>arty</strong> <strong>issues</strong><br />

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!