LLC ” Hotel Guduri Resort ” (business registration number 405244515) Terms of personal data processing
These personal data processing conditions are governed by ” Hotel Guduri Resort ” ( Registration No. 405244515 ) (hereinafter “Company” ) , when using the website, to process personal data.
The company website is operated by “Area Inc.” LLC (Registration No.: 405122077 ) (hereinafter: “Area”) , and uses the services of JSC TBC Bank to provide the payment system.
Definition of terms:
Personal data − Any information relating to an identified or identifiable natural person. A natural person is identifiable when he or she can be identified, directly or indirectly, including by reference to a name, surname, identification number, geolocation data, electronic communication identifier, physical, physiological, mental, psychological, genetic, economic, cultural or social characteristic;
Data processing − Any action performed on data, including collecting, retrieving, accessing, photographing, video-monitoring and/or audio-monitoring, organizing, grouping, linking, storing, modifying, retrieving, retrieving, using, blocking, erasing or destroying data, as well as disclosing data by transmitting, making public, distributing or otherwise making available;
Data subject − Any natural person about whom data is being processed;
Person responsible for processing − A natural person, legal entity or public institution which, individually or jointly with others, determines the purposes and means of data processing and carries out the data processing directly or through a person authorized to process it;
Third person − A natural person, legal entity or public institution, other than the data subject, the personal data protection service, the person responsible for processing, the person authorized to process, the special representative and the person authorized to process the data under the direct instruction of the person responsible for processing or the person authorized to process.
Purpose of the personal data processing conditions
The purpose of these Personal Data Processing Terms is to explain which personal data the Company processes, for what purpose each personal data is processed, and what measures the Company takes to protect personal data.
The purpose of this document is to provide interested parties with basic information on how their personal data is processed by the company, how the company protects applicable legislation and the security of personal data.
The company processes and protects personal data in accordance with the requirements of Georgian legislation on personal data protection.
Basis for processing personal data
The basis for the processing of personal data of data subjects by the Company is the fulfillment of the Company’s obligations under the contract.
The Company processes data subjects’ data on the following grounds:
- Based on a hotel reservation service agreement concluded with the data subject/user. At which point the company acts as the data controller.
Sources of personal data collection
Personal data provided directly by the data subject:
- The data subject transfers his/her personal data to the Company via the website for the purpose of fulfilling the Company’s obligations to the data subject/providing services to him/her.
Principles of personal data processing
- The company processes personal data openly, fairly and lawfully, without violating the dignity of the individual;
- The company processes data for a specific and clearly defined purpose;
- The company adheres to the elements of proportionality and proportionality, namely, it processes only the data and to the extent necessary to achieve the purpose;
- Taking into account the purposes of the data processing, the Company will rectify, erase or destroy inaccurate data without undue delay;
- The Company will retain personal data for a legitimate period, namely as required by law or only for the period necessary to achieve a specific purpose. After the purpose has been achieved, the data must be deleted, destroyed or stored in a form that does not allow the identification of a person;
- The company maintains appropriate technical and organizational measures during the data processing process, in particular, complete data security is ensured by appropriate technical means.
Personal data category
The information processed by the Company may include the following categories of data in proportion to the purpose of their processing:
- Identification data – name, surname, gender, date of birth, personal identification number/passport number;
- Contact information – phone number, email address, residential address (registration, actual);
- Financial information – bank account details; (only JSC TBC Bank has access to this information)
- Other types of information – all information that the data subject shares with the company.
Personal data security
Because the company does not have its own platform and uses the website for its proper functioning Area The service, accordingly, is responsible for protecting the security of personal data (except credit card data) (website security) .
JSC TBC Bank is responsible for the security of credit card data.
Area and JSC TBC Bank All necessary organizational and technical measures have been taken to ensure data processing in accordance with the Law of Georgia on Personal Data Protection.
Area and JSC TBC Bank The organizational and technical measures taken by ensure the protection of personal data against accidental or unlawful destruction, alteration, disclosure, retrieval, unlawful use and loss.
Only those employees who need to process the data to perform their duties have access to personal data stored in the company. The company is responsible for any illegal actions taken by employees with respect to the personal data of data subjects (except for credit card data).
Data subject rights
The data subject has the right to request information about the processing of his or her personal data and to receive copies of this data. The data subject has the right to:
- To receive information about what data is being processed about him/her, in particular, what is the purpose and legal basis for their processing, information about the source of data collection;
- Receive information about whether his/her personal data has been transferred to a third party, information about the third party, the basis and purpose of the data transfer;
- Request the correction, update and/or addition of erroneous, inaccurate and/or incomplete data;
- At any time, without any explanation, withdraw the consent he/she has given to the processing of personal data and request the deletion of data processed on the basis of consent;
- Request the cessation, deletion or destruction of data processing if:
- Requires consent, which is the sole basis for data processing;
- The data processing is no longer necessary for the purpose for which it was processed;
- The data processing is being carried out illegally.
- Request data blocking if
- The authenticity or accuracy of the data is questionable;
- The processing of the data is unlawful, but he does not want to delete them and only requests their blocking;
- The data are no longer necessary for the purpose of their processing, but the data subject needs them for legal proceedings;
- A request for the cessation, deletion or destruction of data processing is being considered;
There is a need to preserve data for use as evidence.
The company will respond appropriately within the time limits established by the Law of Georgia on Personal Data Protection, no later than 10 working days from the receipt of the data subject’s notification.
The rights of the data subject may be restricted in accordance with the procedure established by the legislation of Georgia.
Restriction of data subject rights
The rights of the data subject may be restricted if their realization poses a threat to:
- State security, information security and cybersecurity and/or defense interests;
- public safety interests;
- Crime prevention, crime investigation, criminal prosecution, administration of justice;
- The country’s important financial or economic (including monetary, budgetary and tax), public health and social security interests;
- Detection of violations of professional, including regulated profession, ethical norms by the data subject and imposition of liability on him/her;
- the rights and freedoms of others;
- Protection of state, commercial, professional and other types of secrets provided for by law;
- Substantiation of a legal claim or response.
The Company applies restrictions of rights only to an extent that is adequate and proportionate to the purpose of the restriction.
Data sharing
The Company shares the personal data of data subjects with JSC TBC Bank And the area. They provide service promotion and support for the company.
International data transfer
The Company does not carry out international transfers of personal data of data subjects.
Personal data retention period
Personal data is stored for no more than 10 (ten) years from the date of data collection.
We retain personal data for as long as is necessary to fulfill the purposes for which we collected such information, including for legal purposes.
The criterion for determining the retention period for personal data is also the proper conduct of the company’s activities. The processing of personal data for the specified period is necessary for the company to operate properly.
After the expiration of this period, personal data will be automatically destroyed, unless there is a legitimate interest and appropriate legal basis for storing the personal data for a longer period.
Right of appeal by the data subject
The data subject has the right to apply to the company, the Personal Data Protection Service and/or the court in accordance with the procedure established by law in case of violation of the rights and established rules provided for by the Law of Georgia on Personal Data Protection.
The data subject has the opportunity to contact the company at the specified email address: residence@gudaurihills.com
The data subject has the right to request confirmation from the company whether data about him or her is being processed, whether the data processing is justified, and upon request, to receive information about him or her free of charge (for more details, see the chapter on data subject rights).
The data subject has the right to receive the above-mentioned information no later than 10 working days from the date of his/her request. This period may be extended by no more than 10 working days in exceptional cases and with due justification, of which the data subject shall be immediately notified.
Changes to the terms of personal data processing
These Terms of Use may be revised or changed. The Company reserves the right to change these Terms of Use by posting such changes on its website https://residencegudaurihills.com . We will notify data subjects of any changes to these Terms of Use by posting a notice on our website.
