Visitors Personal Data | ||
Data Sets | Purpose And Operations | Lawful Basis (Where and if the GDPR applies) |
Contact Communications: In the event you contact us for learning more about our Services or with any other inquiry, either through the online forms available on the Site, approaching our call center, by sending us an email or by other means of communications we make available, you will be requested to provide us with your name, email address, phone number, the name of the company on behalf of which you are contacting us, country, and any other information you choose to share with us. (collectively “Contact Communications”) |
We process such Contact Communications data solely for the purpose of contacting you, responding to your inquiries and provide you with the support or information you have requested. The correspondence with you may be processed and stored by us in order to improve our customer service, as well as in the event we reasonably determine it is needed for future assistance or to handle any dispute you might have with us. |
We process such Contact Details data subject to our legitimate interest in order to respond to your inquiry, and further, as part of our internal record keeping. |
Joining our Legacy Plan If you are interested in becoming a member of any of our legacy plans, you will be required to provide your full name, ID number, select a preferred month for a discount, email address, date of birth, and phone number, password, and payment details, etc. If any of our plans will require any payment or subscription, we will also collect, retain and process your billing data, in a secure manner under common standards. |
We will use this data to provide you, as a member of our special plans, with special offers, discounts, commercial proposals, information regarding our activity, etc. We will collect and retain your data in our systems, use the data for delivering you any such news and proposals, and keep a record of your membership with us. We will use your billing information in relevant cases for charging you the relevant subscription fees. |
We process your member data for fulfilling our contract with you. After termination of your membership, we will keep a record of your data as part of our legitimate interests. |
|
We process Online Identifiers and Site Usage Data through our or third-party services and tracking technologies for analytic, marketing and advertising purposes. For example, we process this data to understand how Visitors use our Site, personalize the Services for you and your preferences as well as to measure effectiveness of our features and content. In addition, Site Usage Data helps us to better understand our business, analyze our operations, maintain, improve, design, and develop the Services, conduct statistical analysis, etc. Further, Site Usage Data is used sometimes for operation, Site functionality, security and fraud prevention and debugging purposes, and to resolve technical problems. |
|
(collectively “RecruitmentData”). |
We process Recruitment Data as part of our recruitment and screening efforts to decide whether you can suit a position in Astral. Further, we may process such data in order to comply with corporate governance and legal and regulatory requirements (including the retention of such information). |
We process such Recruitment Data subject to our legitimate interest. If we process sensitive data to ensure diversity, we will do so upon your explicit consent, which you may withdraw at any time by contacting us. Further, if we reject your application, we will delete the Recruitment Data, unless we have requested your consent to keep you information for a future opportunity or if we are required by law. |
Newsletter Registration: In the event you register for our newsletter and other marketing materials you will be requested to provide us with your email address, and any other information you choose to share with us. |
We process such data in order to register you as a recipient of our newsletter, updates and news about Astral and the Services. We may further process your data to send you needed information related to our webinar as well as additional occasional communications and updates related to our Services, promotional and marketing emails (i.e., Direct Marketing, as defined above). |
We process such information subject to our legitimate interest. Direct Marketing is further based on our legitimate interest, you may opt-out at any time through the “unsubscribe” link within the email or by contacting us directly. Please note that if you opt-out we will not send you our marketing materials. |
Customers Personal Data | ||
Data Sets | Purpose And Operations | Lawful Basis (Where and if the GDPR applies) |
Booking and data regarding your stay with us When placing an order online via the Site, you will need to provide us with information such as full name, email address, number of people in your party and their basic details, hotel name, relevant dates, airport, phone number, ID number, and payment details. The payment is processed through the use of third-party systems, acting under common security standards (PCI-DSS). In addition, during your stay in one of our hotels, we will collect data regarding your stay, your family members, purchases you made during your stay, security video footage, requests, and any other information collected during your stay or following it (including any feedback). Please note that in the event you purchase through our call center, we will process your Purchase Information as well, during the call which is likely to be recorded. |
We will use and process Purchase Information in order to enable you to purchase our Services and stay in one of our hotels. We will use your information to contact you with respect to your reservation and stay with us, to offer you with deals and other services and asking for your opinion regarding your experience as our customer. Also, we may provide you with the option to revise or cancel your booking. |
We process such Purchase Information for the fulfillment of the contract between us. After we complete processing your order and after you check out from the hotel, we will keep your booking information as part of our legitimated interests. Some of the data will be retained by us under our legal obligations, such as bookkeeping, tax and custom laws, etc. |
Direct Marketing Communications When you subscribe as a Customer, we may use your provided contact information, such as email, phone number, etc., to contact you with occasional communications and updates related to the Services, as well as promotional and marketing emails, offers, materials and other marketing content, through mail, SMS, etc. (“Direct Marketing”). |
We may send you such promotional content, per applicable law, through email or SMS. | Direct Marketing is based on our legitimate interest, you may opt-out at any time through the “unsubscribe” link within the email or by contacting us directly. Please note that if you opt-out we will not send you our marketing materials however we will continue to send you Services related communications such as communications related to transactions, etc. |
Customer Communications: In the event you contact us regarding your reservation and staying with us, support and technical issues, billing or any other matter pertaining to the Services you have purchased, we may collect certain information to address your inquiry and request, such as relevant reservation data, details about your staying, and any other information you choose to share with us. |
We process such data to respond to your inquiries and provide you with the support or information you have requested. We may do so using our customer management systems, such as CRMs and ERPs, including through the use of third-party SaaS providers used for storage and management of such inquiries. The correspondence with you may be processed and stored by us in order to improve our customer service, as well as in the event we reasonably determine it is needed for future assistance or to handle any dispute you might have with us. |
Under the GDPR, we process Personal Data for the fulfillment of the contract between us. We may retain records of your interaction with us even after completing addressing your inquiry as part of our internal record keeping, per our legitimate interest. |
|
We process Online Identifiers and Site Usage Data through our or third-party services and tracking technologies for analytic, marketing and advertising purposes. For example, we process this data to understand how Visitors use our Site, personalize the Services for you, offer you upgrades and additional services, keep your preferences as well as to measure effectiveness of our features and content. In addition, Site Usage Data helps us to better understand our business, analyze our operations, maintain, improve, design, and develop the Service, conduct statistical analysis, etc. Further, Site Usage Data is used sometimes for operation, Site functionality, security and fraud prevention and debugging purposes, and to resolve technical problems. |
Under the GDPR, where we collect Online Identifies or Site Usage Data for analytic and advertising purposes, we process such data based on your consent which we will obtain through our cookie notice and consent management tool. You may withdraw consent or change your preferences at any time by using the cookie settings tool available on our Site. Where we collect Online Identifiers or Site Usage Data for operation and security, we process your data based on our legitimate interest. |
Category of Recipient | Data That Will Be Shared | Purpose of Sharing |
Service Providers |
All types of Personal Data | We share Personal Data with our trusted agents (such as legal counsels) and service providers (including, but not limited to, our Cloud Service Provider, Analytics Service Provider, CRM provider, etc.) so that they can perform the requested services on our behalf. Thus, we share your data with third party entities, for the purpose of storing such information on our behalf, or for other processing needs. These entities are prohibited from using your Personal Data for any purposes other than providing us with requested services |
Any acquirer of our business | All types of Personal Data | We may share Personal Data, in the event of a corporate transaction (e.g., sale of a substantial part of our business, merger, consolidation or asset sale). In the event of the above, our affiliated companies or acquiring company will assume the rights and obligations as described in this Policy. |
Affiliated companies, including all the companies in the Astral group | All types of Personal Data | Astral operates through various subsidiaries with whom it shares reservation data. |
Legal and law enforcement |
Subject to law enforcement authority request. | We may disclose certain data to law enforcement, governmental agencies, or authorized third parties, in response to a verified request relating to terror acts, criminal investigations or alleged illegal activity or any other activity that may expose us, you, or any other user to legal liability, and solely to the extent necessary to comply with such purpose. |
Right to Be Informed | You have the right to be provided with information regarding our Personal Data collection and privacy practices. All is detailed under this Privacy Policy. If you have any additional questions, please contact us as instructed below. |
Right to Know, Access Rights | You have the right to confirm whether we collect Personal Data about you and to know which Personal Data we specifically hold about you, and receive a copy of such or access it. |
Right to Correction/ Rectification | You have the right to request the updatingofPersonal Data that is not correct, taking into account the nature of the processing and the purposes. |
Right to Be Forgotten, Right to Deletion |
You have the right to request the erasure of certain Personal Data if specific conditions are satisfied. This right is not absolute. We may reject your request under certain circumstances, including where we must retain the data in order to comply with legal obligations or defend against legal claims, other legitimate interests such as record keeping with regards to our engagements, completing transactions, providing a good or service that you requested, taking actions reasonably anticipated within the context of our ongoing business relationship with you, fulfilling the terms of a written warranty, detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, or prosecuting those responsible for such activities; debugging products to identify and repair errors that impair existing intended functionality;exercising free speech, ensuring the right of another consumer to exercise their free speech rights, or exercising another right provided for by law; and engaging in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent. You do not need to create an account with us to submit a deletion request. |
Right to Restriction of Processing | You may be entitled to limit the purposes for which we process your Personal Data if one of the following conditions are satisfied: where the accuracy of the Personal Data is contested by you, for a period enabling us to verify the accuracy of the Personal Data; where the processing is unlawful and you oppose the erasure of the Personal Data and request the restriction of its use instead; where we no longer need the Personal Data for the purposes of the processing, but we are required by you to retain it for the establishment, exercise or defense of legal claims; where you objected to processing (as detailed below) pending the verification whether our legitimate grounds override your request. |
Right to Data Portability | You have the right to get a copy of your Personal Data in a portable formatand, to the extent technically feasible, readily usable format that allows you to transmit thePersonal Data to another entity without hindrance. We will select the format in which we provide your copy. |
Right to Withdraw Consent or Opt-Out (Object) Under the GDPR, and Specifically in the US the Right to Opt-Out From: (i) Selling Personal Data; (ii) Targeted Advertising; and (iii) Profiling & Automated Decision Making |
When the lawful basis for processing your Personal Data is your consent, you may withdraw such consent at any time. For example, you may unsubscribe at any time from our mailing list. You further have the right to object to the processing of Personal Data, in the event the basis for processing is our legitimate interests. However, we will be permitted to continue the processing if our legitimate interests override your rights, or when processing is necessary to establish, exercise, or defend a legal claim or right. You have the right to opt-out from direct marketing, if applicable, by unsubscribing through the email received. We do notprofile you in a manner that has a significant effect on you or other individuals, therefore there isn’t an opt-out option. We do not“sell” or “share” information as most people would commonly understand that term. We do not, and will not, disclose your Personal Data in direct exchange for money or some other form of payment; however, we do share Personal Data for analytic and marketing purposes, including targeted advertising, when we promote our Site or Services. In most cases we obtain Personal Data collected automatically from our Site and your actions therein through our use of cookies, and do not combine it with your actions on other websites, however, our third-party partners might do so, when providing analytic or advertising services to us. You have the right to opt-out of the “selling” or “sharing” of your Personal Data for “cross-contextual behavioral advertising”, or “targeted advertising”, often referred to as “interest-based advertising” as well.You can exercise these rights by using the cookies setting tool available on our Site. You are able to install privacy-controls in the browser's settings to automatically signal the opt-out preference to all websites you visit (such as the “Global Privacy Control”). In any event, please keep in mind that opt-out tools are limited to the browser or device you use because they work off your browser ID and device ID and, accordingly, you will need to opt-out on each browser and device you use. Your browser may save some information in its cookies and cache to maintain your privacy preferences. Clearing these may remove opt-out preferences, requiring you to opt-out again. |
Right To Appeal or Lodge Complaint |
If we decline to take action on your request, we will inform you without undue delay as required under applicable laws. The notification will include a justification for declining to take action and instructions on how you may appeal, if applicable. Under the GDPR you have the right to lodge a complaint with the applicable Data Protection Authorityin the EU or the Information Commissioner in the UK. Such a right also exists under other US state laws, as further detailed below. |
Non-Discrimination | Denying a good or service, providing a different level or quality of service, or charging different prices.We do not discriminate against our Visitors or Customers, but we reserve the right to deny a good or service, provide a different level or quality of service, or charge different prices, all subject to applicable laws. |