CONDITIONS FOR PROCESSING PERSONAL DATA

(“Terms and Conditions”)

 

USED TERMS

Data controller: Hotel Racek, Levínská 134, Úštěk 41145 (hereinafter “Hotel”)

Customer: natural or legal person using the services of the operator

Regulation: Regulation (EU) No 2016/679 of the European Parliament and of the Council of 27 April 2016, General Data Protection Regulation

GENERAL PROVISIONS

1. The subject of these terms and conditions is to ensure the processing of personal data of customers obtained in the course of the Hotel’s business activities and to establish the obligation to maintain confidentiality of such information obtained, to the extent and under the conditions set out in these terms and conditions.

2. The hotel undertakes to process the personal data of customers in accordance with these terms and conditions. These terms and conditions are made within the scope of the rights and obligations arising from the relevant legislation, in particular Regulation (EU) No 2016/679 of the European Parliament and of the Council of 27 April 2016, the General Data Protection Regulation (“the Regulation”), when processing personal data pursuant to the preceding paragraph.

RIGHTS, OBLIGATIONS AND CONFIDENTIALITY

1. The Hotel undertakes to take such technical, personnel and other necessary measures to prevent unauthorised or accidental access to, alteration, destruction or loss of personal data, unauthorised transmissions, other unauthorised processing or other misuse of personal data.

2. In connection with the provision of accommodation services, the Hotel is obliged to process the personal data of guests. These data are handled in particular by:
a) Hotel receptionist
b) Hotel manager
c) Accountant
d) Restaurant staff
e) Marketing consultant

3. The above-mentioned users have been informed about the sensitivity of personal data. They handle the personal data of guests exclusively within the scope of the services provided by the Hotel. Neither the Hotel nor its employees pass on guests’ personal data to other entities.

4. The conditions of processing and handling of guests’ personal data are regulated in the processing contract between the hotel and the processor.

DPO, CREDENTIALS

1. A data protection officer is not required by the nature of the business.

2. The managing director and responsible person of the Hotel is Miloš Doležal (mdolezal@racekhotel.cz).

CUSTOMER INFORMATION

1. The hotel has a legal obligation to keep certain personal data about its guests, in particular name, surname, date of birth, address and period of accommodation, number and type of document, any visa, purpose of stay. This obligation is governed by the Act on the Residence of Foreigners in the Czech Republic (326/1999) and the Act on Local Taxes (565/1990). According to this legislation, the hotel is obliged to keep personal data on customers for 6 years.

2. The customer has the right to ask the hotel for an overview of his/her personal data at any time. This information is stored in (i) the guest card in the hotel system, (ii) the housekeeping book and (iii) the register book, which are kept in hard copy in a locked room. In the event of a request for deletion of personal data, the Hotel will delete the guest card and shred the guest register and the register book. However, the Hotel must comply with the above laws. The personal data listed above can only be deleted after the legal deadline has passed.

TECHNICAL AND ORGANISATIONAL SAFEGUARDS FOR THE PROTECTION OF PERSONAL DATA

1. The Hotel undertakes to ensure the technical and organisational protection of the personal data processed in such a way that unauthorised or accidental access, alteration, destruction or loss of data, unauthorised transfers, other unauthorised processing and other misuse of data cannot occur and that all the obligations of the data controller arising from legal regulations, in particular the Regulation, are ensured by staff and organisation at all times during the processing of the data.

2. The hotel undertakes to ensure that the processing of data is secured in particular in the following way:
(a) only authorised persons of the Hotel, who will have the conditions and scope of data processing determined by the Hotel, will have access to the personal data and each such person will access the personal data under his/her unique identifier;
(b) the personal data will be processed in the Hotel’s premises, to which only authorised persons or its contractors (subcontractors), bound by the same obligations, will have access;
c) the Hotel shall prevent the unauthorised reading, creation, copying, transmission, modification or deletion of records containing personal data;
d) it shall take measures to identify and verify to whom the personal data have been transmitted, processed, modified or deleted.

3. The Hotel undertakes to ensure through its own internal regulations or special contractual arrangements that its employees and other persons who will process personal data will do so only under the conditions and to the extent specified by the Hotel and in accordance with the Hotel’s instructions. In particular, he/she will himself/herself (and will also bind such persons named) to maintain the confidentiality of personal data and security measures, the disclosure of which would compromise the security of personal data, even after termination of employment or relevant work with the Hotel.

CAMERA SYSTEM

1. The hotel uses a CCTV system for the prevention and protection of its customers and their property. The hotel declares that it does not work with the recordings in any way, does not provide them to third parties or entities.

 

Last update date: April 2026