Confidentiality & GDPR

This policy explains how HOTEL APOLLO, operator of Hôtel Flanelles Paris, collects, uses, retains and protects personal data in connection with the https://hotelflanelles.fr/ website, enquiries, bookings and stays.

  1. Data controller

The data controller is:

Company

HOTEL APOLLO, a simplified joint-stock company with a capital of 8,000 euros

Registration

RCS Paris 442 364 014 – SIRET 442 364 014 00039

Address

11 Dunkirk Street, 75010 Paris

Personal data contact

bonjour@flanellesparis.fr

HOTEL APOLLO determines the purposes and means of the processing operations described in this policy. When a service provider processes data on its behalf, that service provider acts as a data processor within the limits of the instructions given to it.

  1. Scope

This policy applies to data processed in the context of:

  • the consultation and use of the website; ;
  • contact forms, requests for information and correspondence with the Institution; ;
  • reservations made directly or through a platform, agency or booking partner; ;
  • the preparation, execution and monitoring of stays; ;
  • invoicing, payment, bank guarantees and claims; ;
  • commercial communications and satisfaction surveys, where authorised.

Personal data means any information relating to an identified or identifiable natural person, including, for example, a name, contact details, an IP address or an online identifier.

  1. Data collected and sources

3.1 Categories of data that may be processed

  • Identity and contact details: title, last name, first name, postal address, email address and telephone number.
  • Booking and stay: dates of stay, number of guests, reserved room, rate, special requests, history and status of the booking.
  • Payment and warranty: payment status, amount, transaction references and data strictly necessary for the guarantee or payment. The bank card visual cryptogram is not intended to be kept after the transaction.
  • Customer relations: interactions, requests, communicated preferences, feedback, responses to satisfaction surveys, incidents and complaints.
  • Commercial communication: newsletter signup, communication preferences, consent and objection.
  • Technical data: IP address, technical logs, browser type, device used, pages visited and information from cookies or trackers.
  • Verification and security: elements necessary for fraud prevention or identity verification when justified. A copy of an identity document is only requested and kept when necessary and proportionate.

The Site and the forms are not intended to collect so-called sensitive data. Individuals are requested not to transmit such information, except when strictly necessary for a specific request related to the stay. In this case, they are processed with enhanced safeguards and on an appropriate legal basis.

3.2 Origin of the data

The data is mainly collected:

  • directly from the person concerned, during contact, a booking, a payment or a stay; ;
  • to the person making a reservation on behalf of another occupant; ;
  • with the agencies, platforms or booking partners used by the Client; ;
  • automatically when browsing the Site, subject to the choices expressed regarding cookies.
  1. Purposes, legal bases and retention periods

The data is processed solely for specified purposes and for a proportionate duration. The main operations are as follows:

Purpose

Legal basis

Main retention period

Respond to requests and prepare a booking

Pre-contractual measures requested by the individual

Time required to process the request; in the absence of a booking, up to 3 years after the last contact from the person.

Manage the booking, the stay, the guarantee, the payment and the post-stay service

Performance of the contract

During the contractual relationship, followed by the archiving of data necessary for proof and the defence of rights for the applicable limitation period, in principle 5 years.

Establish and keep invoices and accounting documents

Legal obligation

10 years from the close of the financial year in question, in accordance with accounting obligations.

Manage complaints, disputes and unpaid invoices

Performance of the contract and legitimate interest in defending the rights of HOTEL APOLLO

During the processing of the file, and for the applicable prescription or archiving period.

Preventing fraud and ensuring the security of the Site and systems

Legitimate interest of HOTEL APOLLO

Strictly necessary duration for security, incident analysis and the exercise of rights; technical logs are kept for a proportionate duration, generally less than or equal to 12 months.

Improve service quality and conduct customer satisfaction surveys

Legitimate interest; consent where required

Time required for analysis, followed by anonymisation or deletion; named responses are not kept beyond the time necessary for the stated purpose.

Send promotional offers and commercial information

Consent where required by law; legitimate interest for similar services addressed to existing customers, with the right to object

Until consent is withdrawn or an objection is raised and, at the latest, 3 years after the last active contact or the end of the business relationship. The information necessary to manage the objection may be kept for 3 years.

Measure audience and personalise content using non-essential tracking devices

Consent

According to the timeframes specified in the Cookie Policy and the choices recorded by the cookie management module.

Process requests to exercise rights

Legal obligation

During the processing of the request, then archiving of the elements necessary to prove the response for a proportionate duration, in principle 3 years.

Bank card data is processed for the purposes of booking, guarantee or payment. It is kept only for the duration necessary for the relevant purpose and, where applicable, in accordance with the time limits applicable to payment disputes. The visual cryptogram is not kept after the transaction. Payment service providers may apply their own retention periods in compliance with their legal obligations.

  1. Mandatory nature of the information

Fields marked as mandatory are required to respond to a request, confirm a booking, guarantee the stay or comply with a legal obligation. Failing to provide this information, HOTEL APOLLO may be unable to process the request or provide the service concerned. The other information is optional.

  1. Data recipients

Within the limits of their remit and on a need-to-know basis, the data may be accessed by:

  • to authorised members of staff of Hôtel Flanelles Paris and HOTEL APOLLO; ;
  • to the technical and commercial service providers involved in the hosting and maintenance of the Site, booking, hotel management, payment, messaging, sending communications, IT security or audience measurement; ;
  • to the agencies, platforms and booking partners concerned by the Client's request; ;
  • to advisers, insurers, statutory auditors or debt collection service providers, where necessary; ;
  • to administrative, judicial or regulatory authorities when required by law.

HOTEL APOLLO neither sells nor rents personal data. Processors are required to provide sufficient guarantees regarding confidentiality and security, and to process data solely for the purposes of the tasks entrusted to them.

  1. Transfers of data outside the European Economic Area

Certain technical service providers may process data from a country located outside the European Economic Area. When such a transfer takes place, HOTEL APOLLO ensures that it is based on an adequacy decision by the European Commission or on appropriate safeguards, such as standard contractual clauses, supplemented where necessary by additional measures. Information regarding the applicable safeguards can be requested at bonjour@flanellesparis.fr.

  1. Cookies and other trackers

The Site may use cookies or similar technologies to ensure its operation, secure navigation, remember certain choices, measure audience or offer tailored content.

Strictly necessary trackers for the operation of the Site may be used without consent. Non-necessary trackers, particularly advertising trackers or certain audience measurement tools, are only deposited after obtaining prior, free and specific consent. Choices can be modified at any time using the cookie management module accessible on the Site.

Detailed information regarding the cookie categories, their providers, their purposes and their retention periods must be set out in the Site's Cookie Policy.

  1. Security and privacy

HOTEL APOLLO implements technical and organisational measures appropriate to the risks in order to protect data against destruction, loss, alteration, unauthorised disclosure or access. These measures include, in particular, authorisation management, secure access, backup, traceability and the awareness-raising of authorised persons.

In the event of a data breach likely to result in a risk to the rights and freedoms of individuals, HOTEL APOLLO shall carry out the required notifications to the CNIL and, when the risk is high, inform the data subjects under the conditions provided for by the regulations.

  1. Rights of individuals

Under the conditions provided for by the regulations, any data subject may exercise:

  • Right of access: obtain confirmation that processing is being carried out and receive a copy of the data concerned.
  • Right of rectification: have inaccurate or incomplete data corrected or completed.
  • Right to erasure: request data deletion when the legal conditions are met.
  • Right to restriction of processing: request the temporary suspension of certain treatments.
  • Right to object: object, on grounds relating to your particular situation, to processing based on legitimate interest; objection to direct marketing can be exercised at any time and without justification.
  • Right to data portability: receive the provided data in a structured, machine-readable format when automated processing is based on consent or on a contract.
  • Withdrawal of consent: withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
  • Advance directives: define guidelines relating to the retention, erasure and communication of data after death, under the conditions of French law.

10.1 How to exercise these rights?

The request can be made free of charge:

  • by email: bonjour@flanellesparis.fr; ;
  • by post: HOTEL APOLLO – Hôtel Flanelles Paris – 11 rue de Dunkerque, 75010 Paris.

The request must make it possible to identify the person concerned and specify the right being exercised. Proof of identity is only requested in the event of reasonable doubt as to the identity of the applicant. HOTEL APOLLO will respond within the applicable timeframe, in principle one month from receipt of the request, subject to an authorised extension in the event of complexity or a large number of requests.

Every sales email also includes a simple way to unsubscribe or object to further communications.

  1. Complaint to the CNIL

Anyone who considers that their rights are not being respected may send a complaint to the Commission nationale de l'informatique et des libertés (CNIL), in particular via the website https://www.cnil.fr/fr/plaintes. It is recommended to contact HOTEL APOLLO first to enable the request to be examined and, if possible, resolved.

  1. Third-party sites and services

The Site may contain links to sites or services operated by third parties, notably booking platforms. HOTEL APOLLO is not responsible for the personal data practices of these third parties. Users are advised to consult their own privacy policies.

  1. Policy update

This policy may be amended to reflect legal, regulatory, technical or operational developments. The applicable version is the one published on the Site, along with its update date. In the event of a substantial modification, appropriate information may be brought to the attention of the individuals concerned.