Privacy policy for Hotel Menstrup Kro

One of Hotel Menstrup Kro's overall goals is to maintain the highest level of safety for our guests, customers, suppliers, job applicants and employees. This also applies when it comes to the protection of personal data. With this policy, Hotel Menstrup Kro wants to map out in a clear and comprehensible way how Hotel Menstrup Kro handles your personal data. 

Data controller

Hotel Menstrup Kro is the data controller.

Contact details are:

Hotel Menstrup Kro
Menstrup Bygade 29
DK-4700 Næstved
Phone: + 45 5544 3003
Email: menstrup @finishing this.menstrupkro.dk

Management/contact person:
Julie Larsen
Phone: + 45 5060 0158
Email: gdpr@danske-hoteller.dk

Hotel Menstrup Kro handles all personal information in accordance with current personal data legislation.

Hotel Menstrup Kro enters into agreements with guests, customers and suppliers on the delivery – purchase and sale – of various services and products.

When a guest/customer orders and purchases one or more of Hotel Menstrup Kro's services and, as part of this, submits his personal data to Hotel Menstrup Kro, he also gives his consent for the guest's/customer's/supplier's personal data to be processed by Hotel Menstrup Kro.

The same applies with regard to any personal data that suppliers to Hotel Menstrup Kro provide to Hotel Menstrup Kro in connection with making offers or entering into agreements with Hotel Menstrup Kro.

Hotel Menstrup Kro's collection of personal data

Personal information is collected by Hotel Menstrup Kro in the following way:

  • When a guest/customer - or a representative of this - chooses to obtain an offer for and/or buy one of Hotel Menstrup Kro's services/products, or when a supplier makes an offer or sells products or services to Hotel Menstrup Kro.
  • From B2B market. For example, in a sales situation where a quote is requested for one of Hotel Menstrup Kro's services and/or a cooperation agreement is requested.
  • Through browser cookies and web beacons.
  • In connection with the use of Hotel Menstrup Kro's digital services.
  • By participating in Danske Hoteller's bonus/advantage program and by subscribing to Danske Hoteller's newsletter.
  • From social media, advertising and analysis providers as well as public records.
  • Via video and TV surveillance.

Collection and processing of personal data, cf. the above, will always take place in accordance with applicable personal data laws.

Video surveillance, which is set up in various places where there is a sign stating that there is surveillance, takes place as part of crime prevention and also functions as a safety-creating measure for employees and guests.

Information that Hotel Menstrup Kro collects

Hotel Menstrup Kro collects the following personal data:

  • Name, address, telephone number, e-mail address, date of birth and other general non-personally sensitive personal data.
  • Payment card details – typically as a guarantee for a reservation and for payment of a stay.
  • Demographic information.
  • Purchase history, including the use of the Hotel Menstrup Kros app and/or other digital services.
  • The use of Danske Hoteller's bonus/advantage program.
  • Information from Hotel Menstrup Kro's customer surveys.
  • Information from any tendered competitions
  • Information from Hotel Menstrup Kro's social media and other digital platforms belonging to Hotel Menstrup Kro.
  • Browser Information.
  • Information about the guest's / customer's business and relevant contacts.
  • Information about the suppliers' business and information about relevant contacts and key persons including key accounts.

A guest/customer/supplier may voluntarily and at his own choice provide Hotel Menstrup Kro with additional personal data that he believes may be important for Hotel Menstrup Kro's operation/servicing of the guest/customer/supplier, or that the person concerned believes should be provided by security regards.

This can e.g. be information about:

  • Handicap
  • Allergy
  • Special food preferences
  • Other health or medicine information
  • Political/religious beliefs

If a guest/customer/supplier chooses to provide such information voluntarily and by their own choice, Hotel Menstrup Kro perceives this as consent to be able to register and store this sensitive information about the person concerned.

In addition to the information that Hotel Menstrup Kro receives directly from guests/customers/suppliers, Hotel Menstrup Kro will in some cases obtain or process additional information that Hotel Menstrup Kro has received from third parties, e.g. a travel agency, another intermediary or an employee of the company where the data subject is employed.

Where this is the case, the relevant third party is obliged to inform the relevant guests/customers/suppliers about Hotel Menstrup Kro's terms and conditions as well as Hotel Menstrup Kro's personal data policy. It is also the responsibility of the third party in question to ensure that there is the necessary legal basis for the collection and processing of the information in question, including obtaining any necessary consent for the processing of any sensitive information.

Payment by payment card  

Hotel Menstrup Kro uses Netaxept (Nets) for redeeming payments with debit and credit cards. Netaxept and Hotel Menstrup Kro are approved and certified by the Bank's Payment System (www.pbs.dk). 

For orders and bookings, Hotel Menstrup Kro stores the information provided by the guest/customer/supplier for as long as it is deemed relevant, after which the information is deleted.

In addition to handling the order, the information provided is only used if a guest/customer/supplier e.g. contact with questions or if there is an error in the order. 

What is the purpose of the collection and processing?

Hotel Menstrup Kro only collects personal data that is necessary to fulfill the agreements entered into with guests/customers/suppliers regarding the provision of services, e.g. an overnight stay, or purchase/sale of products or services.

It is the content of the individual agreement/the nature of the service that determines which personal data Hotel Menstrup Kro collects and processes, and which determines the purpose of the collection.

The purpose of collecting and processing personal data will primarily be:

  • Processing of guests/customers' booking and purchase of Hotel Menstrup Kro's services.
  • Processing suppliers' offers for - and sales - of products and services.
  • Contact to the guest / customer before, during or after their stay.
  • Fulfillment of the guest's / customer's request for offers or purchases of services.
  • Improvement and development of Hotel Menstrup Kro's services.
  • Adaptation of Hotel Menstrup Kro's marketing and other communications.
  • Analysis of guests/customers/suppliers' user behavior and marketing towards them.
  • Adaptation of Hotel Menstrup Kro's business partners' communication and marketing to guests/customers/suppliers.
  • Administration of guests/customers/suppliers' relationship with Hotel Menstrup Kro, including possible participation in Danske Hoteller's bonus/advantage program.
  • Compliance with legal requirements, eg. requirement to register overnight guests according to the Aliens Act and the Passport Order.

Authorization – the legal basis – for the processing

Hotel Menstrup Kro will most often process personal data because it is necessary to fulfill an agreement with Hotel Menstrup Kro, to which a guest/customer or a supplier is a party. This may, for example, be in connection with hotel stays, meeting arrangements and/or handling and fulfillment of cooperation and supplier agreements.

In addition, Hotel Menstrup Kro will process personal data in connection with booking prior to an overnight stay, handling of meetings, companies, conferences, etc. and prior to entering into supplier agreements.

In some cases, Hotel Menstrup Kro's processing of personal data will take place as part of Hotel Menstrup Kro's pursuit of a legitimate/fair interest that precedes the interests of the guest/customer/supplier (the data subject).

Such a legitimate interest can for example be the preparation of statistics, customer surveys, marketing and analysis of general guest/customer behaviour, which is intended to generally improve the experience at Hotel Menstrup Kro and the quality of Hotel Menstrup Kro's services and products.

If a guest/customer discloses special personal preferences or considerations in connection with their stay/visit at Hotel Menstrup Kro, including e.g. health information, disability, religious beliefs or the like, Hotel Menstrup Kro only uses the information to ensure that the guest/customer's personal preferences, health etc. are taken into account.

In some situations, Hotel Menstrup Kro receives personal data from third parties, e.g. a travel agency, an agent or the like, i.a. in connection with group bookings. When this happens, the third party in question is required to inform the guests/customers/suppliers in question about Hotel Menstrup Kro's terms and conditions and the content of this personal data policy.

Hotel Menstrup Kro is additionally according to law, cf. above under section 5, obliged to register various information about overnight guests. This information must be stored for a minimum of one year and a maximum of two years. 

The data subject's rights

According to the rules in the Personal Data Regulation, the registered (customers/guests/suppliers) have different rights.

  • A registered person has the right at any time to gain insight into which personal data Hotel Menstrup Kro processes about the registered person.
  • A registered person has the right at any time to have the personal data that Hotel Menstrup Kro has about the registered person corrected and updated.
  • A registered person has the right at any time to have the personal data that Hotel Menstrup Kro has about the registered person deleted. If a registered person requests deletion, all the information that Hotel Menstrup Kro is not legally obliged to store will be deleted. A deletion of the registered person's information may in some cases mean that Hotel Menstrup Kro cannot fulfill any concluded agreements or provide certain services to the data subject.

If some of the information that Hotel Menstrup Kro has about the data subject is given on the basis of the data subject's consent, the data subject has the right to withdraw consent at any time, which means that the information is deleted or no longer used by Hotel Menstrup Kro . This does not apply to information, cf. above, which Hotel Menstrup Kro is legally obliged to store.

The possibility to request deletion etc. may, however, be limited for reasons of the protection of other people's privacy, trade secrets and intellectual property rights, as well as e.g. for the sake of the possibility of enforcing potential legal claims.

The registered person can at any time ask Hotel Menstrup Kro in writing to get an overview of and a copy of the personal data about the registered person that Hotel Menstrup Kro holds.

A written request for this must be signed by the data subject and contain his name, address, telephone number, e-mail address.

The data subject can also contact Hotel Menstrup Kro if the data subject believes that his personal data is being processed in violation of the law or in violation of other legal obligations, e.g. the agreement/contract that the data subject has with Hotel Menstrup Kro.

Written request is sent to Hotel Menstrup Kro, see contact information above under section 1.

Hotel Menstrup Kro will, as far as possible, within 1 month of receiving the registered person's written request, send it to the registered person's postal address.

If the data subject requests correction and/or deletion of his personal data, Hotel Menstrup Kro will assess whether the conditions for the request are met, and Hotel Menstrup Kro will, in that case, carry out changes or deletion as soon as possible.

Hotel Menstrup Kro reserves the right to reject requests which are of a harassing repetition nature or which require disproportionate technical measures (e.g. development of a new IT system) or which affect the protection of other data subjects' personal data or in other situations where it will be disproportionately resource-intensive or very complicated to accommodate the request.

If you are applying for a position at Hotel Menstrup Kro

Hotel Menstrup Kro is the data controller for the processing of the information that is contained in applications or that appears as part of an employment process.

As part of Hotel Menstrup Kro's recruitment, Hotel Menstrup Kro processes the information that applicants provide in their applications, including information such as name, address, education, work experience, etc., i.e. basically only general information. It is not recommended to provide personally sensitive information, such as health information, race, religion, trade union affiliation, criminal record, etc. in the application. If Hotel Menstrup Kro needs to obtain and process sensitive information, e.g. criminal record, if an applicant, this will only be done with the prior consent of the applicant in question.

The personal information comes partly from the applicant, but possibly also from publicly available sources (such as Facebook and LinkedIn). Hotel Menstrup Kro does not use personal profiling to make automatic decisions that can significantly affect the applicant's rights and freedoms.

The authority to process the applicant's information is found in Article 6 of the Personal Data Regulation, letter a (consent), letter b (measures prior to entering into a contract) and letter f (protection of interests).

Hotel Menstrup Kro can in certain cases pass on applicants' personal data if this is required by applicable legislation or a court decision. Information can also be passed on to external recipients, including possible recruitment agencies/headhunters, accountants and data processors. Some of Hotel Menstrup Kro's data processors may be located outside the EU/EEA, but all with a legal basis for transfer.

If an applicant is rejected for the job applied for, Hotel Menstrup Kro stores the applicant's application and information for up to six months after the rejection, and if other positions that match the applicant's profile become available, Hotel Menstrup Kro can contact the applicant in question applicant for the purpose of filling this position. Applications are thus deleted after 6 months, unless the applicant in question gives permission for Hotel Menstrup Kro to save the application for a longer period of time.

Applicants always have the right to be told what information Hotel Menstrup Kro has about the applicant. Applicants also have the right to have their information corrected if it is not correct, just as applicants have the right to object to or request deletion or restriction of the processing of the applicant's information.

If the applicant is offered employment at Hotel Menstrup Kro, the information obtained in connection with the employment procedure is stored. Information about employees is processed in accordance with Hotel Menstrup Kro's personal data policy for employees, which can be found in Danske Hoteller's Personnel Guide.

Hotel Menstrup Kro has taken a number of technological and organizational security measures to protect applicants' personal data against manipulation, loss, etc., as well as against others gaining unauthorized access to applicants' information. Only the employees of Hotel Menstrup Kro, who as part of their work need to know applicants' personal data, have access to this. Hotel Menstrup Kro's security procedures are continuously revised based on the latest technological developments.

Security and sharing of personal data

Hotel Menstrup Kro protects the data subject's personal data and has established guidelines that protect the data subject's personal data from unauthorized disclosure and from unauthorized persons gaining access or knowledge of it.

Only the persons/employees at Hotel Menstrup Kro who, by virtue of their job function, need the personal data of the registered persons, have access to this.

Hotel Menstrup Kro continuously checks that there is no unauthorized access to the registered person's personal data.

Hotel Menstrup Kro regularly backs up the registered personal data.

All customer cards with personal data are anonymised in Hotel Menstrup Kro's booking system after 1 year of inactivity.

In the event of a security breach, where there is a high risk of misuse of the registered person's personal data, including e.g. identity theft, financial loss, loss of reputation or other form of abuse, Hotel Menstrup Kro will notify the data subjects of the security breach as soon as possible.

Hotel Menstrup Kro's security procedures are continuously reassessed and updated in relation to technological developments.

Hotel Menstrup Kro uses a number of external suppliers of IT services, IT systems, payment solutions, etc.

Hotel Menstrup Kro enters into ongoing data processing agreements with all of Hotel Menstrup Kro's suppliers, whereby it is also ensured in relation to external data processors that these maintain a necessary and high level of protection, as far as the personal data of the registered are concerned. Some of Hotel Menstrup Kro's data processors may be located outside the EU/EEA, but all with a legal basis for transfer.

In order to fulfill agreements with those registered and to meet the needs of guests, customers and suppliers, Hotel Menstrup Kro shares selected personal data with external suppliers such as banks, accountants, restaurants, hotels etc.

Hotel Menstrup Kro is part of a group. Therefore, the personal data of the registered may also be shared and passed on internally within the group. The purpose of this sharing is to be able to provide the guest/customer/supplier with the best handling and service, regardless of which hotel or which department in the group the guest/customer/supplier uses.

Hotel Menstrup Kro is in some cases legally obliged to pass on personal data or obliged to do so as a result of a decision by a public authority.

Hotel Menstrup Kro deletes your personal data when Hotel Menstrup Kro's legal obligation ends or when the purpose for collecting and processing the information is no longer present.

Cookies

Hotel Menstrup Kro uses cookies. Further information about Hotel Menstrup Kro's cookie policy can be obtained on the company's website.

Lawsuit

Complaints about Hotel Menstrup Kro's processing of personal data can be made to the Data Protection Authority, Carl Jacobsens Vej 35, 2500 Valby, telephone + 45 3319 3200 – e-mail dt@datatilsynet.dk.

Updated June 22, 2023