Royal Park Hotels and Resorts Co., Ltd. (the “Company”) is aware that information that could identify an individual customer of the Company (“Personal Information”) is valuable information, and has therefore established regulations on information management in order to handle Personal Information with the utmost care. Please review the Company’s basic policy on the handling of Personal Information set forth below.
I. Collection of Personal Information
The Company collects Personal Information only to the extent appropriate and necessary to conduct the Company’s business using the methods set forth below.
- Direct collection from customers: Collection via telephone, orally, in writing (including electronic records), from business cards, online (including information that is input when using websites of hotels managed and operated by the Company and information input when performing member registration), and so on. The information we collect from you is likely to include
- Collection from third parties duly authorized by customers: Collection from third parties such as users, potential users, referral agencies, travel trade professionals, and business partners. The information we collect from such third parties is likely to include
- Collection from publicly available sources: Collection from newspapers, online, telephone directories, books, and other such sources. The information we collect from such publicly available sources is likely to include your name, telephone or fax number, nationality, address, email address (including social media IDs and the like associated with email addresses), age, gender, date of birth, anniversary date, employer information, requests, and use history.
- Collection from businesses engaged in the management and operation of the hotels that use the Company’s trademarks under license from the Company (referred to collectively with hotels managed and operated by the Company as “Royal Park Hotels Group Hotels”): Personal Information will be collected by the relevant businesses and shared by means of shared use of Personal Information, as specified in the privacy policies of these businesses. The information we collect from such businesses is likely to include your name, membership registration number, telephone or fax number, nationality, passport number, address, email address (including social media IDs and the like associated with email addresses), age, gender, date of birth, anniversary date, employer information, requests, and use history.
II. Purposes of Use of Personal Information
The Company uses Personal Information for the following purposes.
- To provide services through the operation of hotel facilities such as accommodation, dining, and banquet space.
- To provide information regarding its facilities, products, services, and so on.
- To facilitate customer surveys and the like presented by the Company intended to improve the Company’s services.
- To provide various information and services in relation to its membership program provided by the Company.
- To respond to other matters ancillary or related to its operations when use is within the scope of the intended use specified at the time that the Personal Information was acquired.
III. Shared Use of Personal Information
In order to add high levels of value to the services provided to customers, the Company shares Personal Information as set forth below under strict controls and with appropriate security measures in place.
- Joint users of Personal Information: Businesses engaged in the management and operation of Royal Park Hotels Group Hotels, including guest service providers.
- Purposes of Shared Use:
(1) When providing services through the operation of hotel facilities such as accommodation, dining, and banquet space at Royal Park Hotels Group Hotels.
(2) When Royal Park Hotels Group Hotels provide information regarding facilities, products, services, and so on.
(3) When you participate in customer surveys and the like presented by the Company intended to improve Royal Park Hotels Group Hotel services.
(4) When the Company provides various information and services in relation to its membership programs provided by Royal Park Hotels Group Hotels.
(5) When Royal Park Hotels Group Hotels respond to other matters ancillary or related to their operations when use is within the scope of the intended use specified at the time that the Personal Information was acquired.
- Personal Information subject to shared use: your name, membership registration number, telephone or fax number, nationality, passport number, address, email address (including social media IDs and the like associated with email addresses), age, gender, date of birth, anniversary date, employer information, requests, and use history.
- Administrator of Personal Information subject to shared use: Royal Park Hotels and Resorts Co., Ltd.
IV. Provision of Personal Information to Third Parties
Except in the following cases, the Company shall not provide or disclose Personal Information to third parties. Subject to the requirements specified in Articles X and XI, the Company may disclose Personal Information to cloud service providers as long as such cloud service providers are precluded from using the Personal Information provided.
- When you consent.
- When the disclosure is based on laws and regulations.
- When there is a need to protect a human life, body or fortune, and when it is difficult to obtain your consent.
- When there is a need to cooperate in regard to a central government organization or a local government, or a person entrusted by them performing affairs prescribed by laws and regulations, and when there is a possibility that obtaining your consent would interfere with the performance of the said affairs.
V. Contact Information regarding Personal Information (Responsible Division)
Personal Information Enquiry Counter, Royal Park Hotels and Resorts Co., Ltd.
Address: Otemachi Building, 1-6-1 Otemachi, Chiyoda-ku, Tokyo 100-0004 JAPAN
Inquiries will be accepted by mail to the above address. The Company will respond to your inquiry in writing several days later (a separate processing fee may be required in some instances). Please note that depending on the nature of the inquiry, you may be requested to come to the Company’s offices to confirm your identity.
VI. Protection of Personal Information
The Company has established the Information Management Committee to manage Personal Information as it strives to protect Personal Information from unauthorized access. The Information Management Committee has implemented, and will continue to oversee, the following matters.
- To ensure the security of Personal Information and prevent unauthorized access to systems and the loss, destruction, alteration, or leak of Personal Information, the Company has implemented security countermeasures concerning both operational management and systems.
- Databases in which Personal Information is recorded are stored on systems protected by mechanisms (including firewalls) to prevent external access.
- Transmission and receipt of Personal Information with you via the Internet on the Company’s website use encrypted transmissions that employ Secure Sockets Layer (SSL). In cases where you use a browser that does not support SSL, you may not be able to access SSL secure pages or to input information.
VII. Internal Systems
The Company has implemented security measures to ensure that its employees carry out comprehensive protection of your Personal Information, and to appropriately monitor outside contractors and others.
VIII. Personal Information on Third-Party Linked Sites
In order to provide more useful information and services to you, the Company’s websites contain links to the websites of third parties (other companies and organizations). The Company assumes no responsibility regarding the collection and handling of Personal Information by such linked third-party websites.
- If any changes occur to information registered with the Company or if you want Personal Information to be deleted, please promptly contact the hotel that registered the information so that the services can be effectively provided.
X. Handling of Personal Information of EEA residents
In addition to Articles I-IX above, the provisions in this Article X and Article XI below shall apply to the handling of Personal Information of persons in the European Economic Area (EEA) that is subject to the General Data Protection Regulation (REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL). If any provision of these Articles X and XI conflicts with the provisions of Articles I-IX above, the provisions of Articles X and XI shall prevail.
- Legal basis for processing: The Company will process and use Personal Information to manage its contractual relationship with you, to pursue a legitimate interest, and/or to comply with a legal obligation.
It will be necessary for the Company to use your Personal Information to complete a booking you have made with us. For example, we will need to use information such as your contact details and payment information to provide you with the stay and/or restaurant booking you have requested and paid for.
Alternatively, we may collect and use your Personal Information where you have given your specific consent to us doing so.
- Collection of access data: In addition to the information specified in Article I, we automatically collect data related to you when you visit our websites. This data that we obtain from you when you visit us (“access data”) includes access logs, web beacons (also known as pixel tags), cookies, etc. For more information about how we use your access data, please see Article XI below.
- Disclosure of your Personal Information to recipients： We may share your Personal Information with businesses engaged in the management and operation of Royal Park Hotels Group Hotels for the purpose described in “III Shared Use of Personal Information”. We may also share your Personal Information with internet service providers, cloud service providers, guest service providers, Most of these recipients are located in Japan. We will ensure an adequate level of protection of your Personal Information when they are disclosed to a recipient located outside the EEA.
- Transfer of your Personal Information: Your Personal Information may be transferred to and stored by the Company and our service providers in countries outside the country in which you are located and outside the EEA. The Company operates businesses in multiple jurisdictions, some of which are not located in the EEA, such as Japan, China and the USA. Where we transfer your Personal Information outside the EEA, we will ensure that:
(a) the recipient destination has been subject to a finding from the European Commission that it ensures an adequate level of protection for the rights and freedoms that you possess in respect of your Personal Information; or
(b) the recipient enters into standard data protection clauses with us that have been approved by the European Commission.
You can obtain more detailed information about the protection given to your Personal Information when it is transferred outside the EEA (including a copy of the standard data protection clauses which we have entered into with recipients of your Personal Information) by contacting us in accordance with the contact information provided above.
Retention of Your Personal Information: The Company will keep your information for as long as we need it for the purpose it is being processed for. For example, where you book a stay with us we will keep the information related to your booking, so we can fulfill the specific travel arrangements you have made and after that, we will keep the information for a period which enables us to handle or respond to any complaints, queries or concerns relating to the booking. The information may also be retained so that we can continue to improve your experience with us and to ensure that you receive any loyalty rewards which are due to you.
We will actively review the information we hold and delete it securely, or in some cases anonymize it, when there is no longer a legal, business or customer need for it to be retained.
- Your Data Protection Rights: Under certain circumstances prescribed by law, you have the right to:
• Request information about whether we hold Personal Information about you, and, if so, what that information is and why we are holding and using it.
• Request access to your Personal Information (commonly known as a “data subject access request”). This enables you to receive a copy of the Personal Information we hold about you and to check that we are processing it lawfully.
• Request correction of the Personal Information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
• Request erasure of your Personal Information. This enables you to ask us to delete or remove Personal Information where there is no basis for us to continue to process it. You also have the right to ask us to delete or remove your Personal Information where you have exercised your right to object to it being processed.
• Request restriction of processing of your Personal Information. You may request restriction in certain circumstances. For example, you can request it when you dispute the accuracy of your Personal Information or when you want to confirm the legal grounds for the lawful processing of your Personal Information.
• Object to the processing of your Personal Information where we are relying on a legitimate interest (or those of a third party) and you want to object to processing on this ground owing to some aspect of your particular circumstances. You also have the right to object where we are processing your Personal Information for direct marketing purposes.
• Object to automated decision-making including profiling. You may request not to be the subject of any automated decision-making which uses your Personal Information or profiles you.
• Request transfer of your Personal Information in an electronic and structured form to you or to another party (commonly known as the right to “data portability”). This enables you to receive your data from us in an electronically useable format and to transfer your data to another party in an electronically useable format.
• Withdraw consent. Where you have provided your consent to the collection, processing and transfer of your Personal Information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law. If you withdraw this consent, in some circumstances, we will not be able to provide all or parts of the services you have requested from us and you will not be able to earn points, cancel your booking or obtain a refund of any charges you have paid.
If you want to exercise any of these rights listed above, please send an email to email@example.com
You also have the right to lodge a complaint with the competent data protection authority if you think that any of your rights have been infringed by the Company.
XI. Use of Access Data
- The Company collects and uses the following types of access data from visitors to our websites and users of our services.
- In some cases, the Company makes use of information known as cookies on its websites and so on for the purpose of enhancing customer convenience. You can disable cookie functionality by changing browser settings, but it may not be possible to use some services as a result. To find out how to change your cookie settings, please select “Help” from the menu bar of your browser and search for the word “cookie”.
- Access logs. The Company may use access log information for the purpose of statistical analysis such as investigating the number of times that the Company’s website is used, but such information does not include personally identifiable information.
- The following third-party providers may have access to the access data collected by us.
President and Chief Privacy Officer
Royal Park Hotels and Resorts Co., Ltd.