Shiadu Hotels and Guesthouses
PRIVACY POLICY
Your privacy is a priority for SHIADURBE PORTUGAL, S.A., a company based in Portugal with its registered office at Rua do Ferragial, 5, 1st basement, Warehouse A, 1200-182 Lisbon, Portugal, and company registration number PT507961307 (hereinafter referred to as “SHIADU” or the “Company”).
This Privacy Policy aims to provide users of the website hosted at www.shiadu.com (the “Website”) and guests of SHIADU accommodation units with clear and detailed information on how the Company, as the Data Controller, processes their personal data, in accordance with Regulation (EU) 2016/679 of 27 April 2016 (“GDPR”) and other applicable national legislation. Any questions regarding the processing of your personal data may be sent to the following email address: privacidade@shiadu.com.
01. Personal data collected
As a general rule, personal data is collected when users browse the Website, make a booking (directly or through booking agencies and platforms), communicate with the Company (by email, telephone, forms or the Website’s chat assistant), check in at one of our properties, respond to satisfaction surveys or subscribe to communications. The data processed mainly consists of:
- Identification data (name, nationality, date of birth, identification document);
- Contact details (address, email address, telephone number);
- Tax identification number (for invoicing purposes);
- Booking and stay details (dates, property, room type, preferences, special requests);
- Payment details (collected exclusively for payment purposes);
- Communications exchanged with the Company (email, telephone, forms, chat assistant);
- Responses to satisfaction surveys;
- Website browsing data (IP address, device and browser type, pages visited), collected through cookies with consent;
- CCTV footage in the common areas of the properties, where applicable and duly signposted.
02. Purposes of Processing and Legal Bases
The Company processes your personal data for the following purposes and on the following legal grounds:
- Management of bookings and provision of accommodation and related services — performance of a contract or steps taken prior to entering into a contract (Art. 6(1)(b) GDPR);
- Invoicing and payment collection — compliance with a legal obligation (Art. 6(1)(c) GDPR);
- Mandatory reporting of foreign guests staying at the accommodation to the competent authorities — compliance with a legal obligation (Art. 6(1)(c) GDPR);
- Responding to contacts, information requests and enquiries submitted through the Website — steps taken prior to entering into a contract or legitimate interest (Art. 6(1)(b) and (f) GDPR);
- Sending marketing communications and newsletters — consent (Art. 6(1)(a) GDPR);
- Sending satisfaction surveys and improving service quality — legitimate interest (Art. 6(1)(f) GDPR);
- Analysis of Website use and improvement of the browsing experience — consent (Art. 6(1)(a) GDPR);
- Video surveillance for the safety of people and property — legitimate interest (Art. 6(1)(f) GDPR).
Where processing is based on consent, users have the right to withdraw their consent at any time, without affecting the lawfulness of processing carried out prior to its withdrawal.
Consent to receive marketing communications and newsletters is separate and distinct from consent to the use of analytical and marketing cookies: subscribing to the newsletter does not imply acceptance of cookies, nor does acceptance of cookies imply subscription to marketing communications. Each of these consents may be given or withdrawn separately and at any time.
03. Data Recipients
Personal data is not shared with third parties without a legal basis. The Company may engage data processors who process data on its behalf and in accordance with its instructions, bound by a contract pursuant to Article 28 of the GDPR, particularly in the following categories:
- Providers of hotel management systems, booking engines and distribution channels;
- Providers of guest communication platforms and chat assistants;
- Internet hosting and technology infrastructure providers;
- Email and communications delivery service providers;
- Payment processing service providers;
- Accounting, auditing, consultancy and legal service providers.
Data may also be disclosed to public authorities where required by law, particularly to the competent border control authorities and tax authorities.
04. International Data Transfers
The Company generally stores your personal data within the European Economic Area. If any provider involves a transfer of data outside the European Economic Area, the Company ensures that the transfer complies with applicable legal requirements, including the existence of an adequacy decision by the European Commission or appropriate safeguards, such as standard contractual clauses.
05. Data Retention Period
Personal data is retained only for as long as necessary for the purposes for which it was collected, taking into account legally required retention periods (particularly for tax and accounting purposes). Once these periods have expired, the data is deleted or anonymised. Data processed on the basis of consent is retained until consent is withdrawn.
06. Security Measures
The Company has implemented appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised use or access, including limiting access to data to those who have a genuine need to know it. Anyone processing your data will only do so with authorisation and will be subject to a duty of confidentiality. Communication between the user’s device and the Website is carried out through secure channels (HTTPS protocol). The Company also has procedures in place in the event of a suspected personal data breach and, where legally required, will notify the user and the competent supervisory authority.
07. Data Protection Officer
Under Article 37 of the GDPR, the appointment of a Data Protection Officer (DPO) is only mandatory where the processing is carried out by a public authority or body, where the controller’s core activities consist of processing operations that require regular and systematic monitoring of data subjects on a large scale, or where the core activities consist of large-scale processing of special categories of data. The Company’s activities — managing bookings and providing accommodation services — do not fall within these criteria, and therefore the Company has not appointed a Data Protection Officer. Nevertheless, all matters relating to the protection of personal data are handled internally and may be addressed to privacidade@shiadu.com.
08. Cookies
The Website uses cookies — small text files stored on the user’s device — to ensure its operation, improve the browsing experience and, with consent, for analytical and marketing purposes. Except for cookies that are strictly necessary for the Website to function, cookies are only installed with the user’s express consent, which can be managed at any time through the cookie manager available on the Website.
09. Your Rights
Under the GDPR, you have certain rights in relation to the processing of your personal data:
- Right to be informed: You have the right to receive clear, transparent and easily understandable information about how we use your personal data and your rights.
- Right of access: You have the right to obtain access to your personal data.
- Right to rectification: You have the right to have your personal data rectified if it is inaccurate or incomplete.
- Right to erasure: This right allows you to request the deletion or removal of your personal data when there is no compelling reason for us to continue using it. This right is not absolute and exceptions may apply.
- Right to restrict processing: You have the right to ‘block’ or suppress the further use of your personal data. Where processing is restricted, we may still store your personal data, but we will have to stop using it.
- Right to data portability: You have the right to obtain and reuse your personal data for your own purposes across different services.
- Right to object to processing: You have the right to object to certain types of processing, including processing for direct marketing purposes.
- Right to withdraw consent: If you have given your consent to any processing of your personal data, you have the right to withdraw it at any time.
- Right not to be subject to automated decision-making: You have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects (or similarly significant effects) concerning you.
10. Exercising Your Rights
You may exercise your rights free of charge by sending a written request to the following email address: privacidade@shiadu.com. The Company will respond within a maximum period of one month from receipt of the request, except in cases of particular complexity, where this period may be extended by up to two months. In certain cases, a request may be refused if it concerns the deletion of data that is necessary to comply with legal obligations. If requests are manifestly unfounded or excessive, particularly due to their repetitive nature, the Company reserves the right to charge a reasonable fee corresponding to the administrative costs.
11. Changes to the Privacy Policy
The Company reserves the right to amend this Privacy Policy at any time, with the updated version being published on the Website. We recommend that you review this document regularly.
12. Complaints to the Supervisory Authority
The Company seeks to resolve any questions or concerns raised regarding the use of your personal data. Everyone has the right to lodge a complaint with a supervisory authority. In Portugal, the supervisory authority is the Comissão Nacional de Proteção de Dados (CNPD), located at Av. D. Carlos I, 134 – 1st floor, 1200-651 Lisbon, telephone (+351) 213 928 400, email: geral@cnpd.pt. In Spain, the supervisory authority is the Agencia Española de Protección de Datos (AEPD). You may also lodge a complaint with the supervisory authority in the Member State where you live, work or where the alleged infringement took place.