CUSTOMER PERSONAL DATA PROTECTION CHARTER
1. Raffles Spa’s commitment to protecting privacy
2. Scope of application
3. Raffles Spa’s seven principles for protecting your personal data
4. What personal data is collected?
5. When is your personal data collected?
6. What purposes is your data collected for and how long do we retain it?
7. Conditions of third-party access to your personal data
8. Protection of your personal data during international transfers
9. Data security
11. Your rights
13. Questions and contacts
1. Raffles Spa’s COMMITMENT TO PROTECTING PRIVACY
We consider you an important customer. Our first priority is to offer you exceptional experiences throughout the Raffles Spa Site.
Your complete satisfaction and confidence in Raffles Spa is absolutely essential to us.
2. SCOPE OF APPLICATION
In this charter, “Raffles Spa” means:
- Raffles Hotel Singapore, the Raffles Spa parent company, with registered offices at 1 Beach Road, Singapore 189673.
- Subsidiary or “family” companies of Raffles Hotel Singapore involved in the hotel businesses of Raffles Hotel Singapore; and
- outlets/shops operating within Raffles Hotel Singapore. This list of restaurants and shops are regularly updated and can be viewed on rafflessingapore.com.
Raffles Hotel Singapore has communicated the principles set out in this charter to all of the restaurants and shops of Raffles Hotel Singapore and their respective owners. We will do our upmost to ensure that all outlets comply with the applicable data protection laws and this charter in relation to the processing of your personal data..
3. Raffles Spa’s SEVEN PRINCIPLES FOR PROTECTING YOUR PERSONAL DATA
In accordance with applicable regulations, in particular the European General Data Protection Regulation, we have instituted the following ten principles throughout Raffles Hotel Singapore:
- Lawfulness: We use personal data only if:
- we obtain the consentof the person, OR
- it is necessary to do so for the performanceof a contract to which the person is a party, OR
- it is necessary for compliancewith a legal obligation, OR
- it is necessary in order to protect the vital interestsof the person, OR
- we have a legitimate interest in using personal data and our usage does not adversely affect the persons’ rights
- Fairness: We can explain why we need the personal data we collect.
- Purpose limitation and data minimisation: We only use personal data that we really need. If the result can be achieved with less personal data, then we make sure we use the minimum data required.
- Transparency: We inform people about the way we use their personal data
- We facilitate the exercise of the people’s rights: access to their personal data, rectification and erasure of their personal data and the right to object to the use of their personal data
- Storage limitation: We retain personal data for a limited period
- If personal data is transferred outside Singapore, we ensure this transferis covered by specific legal tools.
- If personal data is compromised (lost, stolen, damaged, unavailable…), we notify such breaches to the respective country’s responsible authority and to the person concerned, if the breachis likely to cause a high-risk in respect of the rights and freedoms of this person.
For any questions concerning the seven principles of Raffles Spa’s data protection policies, please contact the Marketing Communications team for Raffles Spa.
4. WHAT PERSONAL DATA IS COLLECTED?
At various times, we may collect information about you and/or the persons accompanying you, including the following:
- Contact details (for example, last name, first name, telephone number, email)
- Personal information (for example, date of birth, nationality)
- Information relating to your children (for example, first name, date of birth, age)
- Your credit card number (for transaction purposes)
- Information contained on a form of identification (such as ID card, passport or driver license)
- Your membership number for the Raffles Spa loyalty program or another partner program (for example, an airline loyalty programme) and information related to your activities within the context of the loyalty program
- Your preferences and interests (for example, fashion, lifestyle, type of newspapers/magazines, sports, cultural interests, food and beverages preferences, etc.)
- Your questions/comments, during or following an experience in one of the establishments located within in Raffles Hotel Singapore.
- Technical and location data you generate as a result of using our websites and applications.
The information collected in relation to persons under 16 years of age is limited to their name, nationality and date of birth, which can only be supplied to us by an adult. We would be grateful if you could ensure that your children do not send us any personal data without your consent (particularly via the Internet). If such data is sent, you can contact the Marketing Communications team for Raffles Spa to arrange for this information to be deleted.
In order to meet your requirements or provide you with a specific service (such as dietary requirements), we may have to collect sensitive information, such as information concerning race, ethnicity, political opinions, religious and philosophical beliefs, union membership, or details of health or sexual orientation. In this case, we will only process this data if you provide your express prior consent.
5. WHEN IS YOUR PERSONAL DATA COLLECTED?
Personal data may be collected on a variety of occasions, including:
- Hotel activities:
- Ordering at Raffles Spa
- Requests, complaints and/or disputes.
- Participation in marketing programs or events:
- Transmission of information from third parties:
- Tour operators, travel agencies (online or not), online shopping systems and others
- Internet activities:
- Connection to Raffles Hotel Singapore’s and Raffles Spa’s websites (IP address, cookies in accordance with our Policy about the use of tracers)
- Online forms (online reservation, questionnaires, Raffles Hotel Singapore’s pages on social networks, social networks login devices such as Facebook login, conversations with chatbot, etc.).
6. WHAT PURPOSES IS YOUR DATA COLLECTED FOR AND HOW LONG DO WE RETAIN IT?
The table below sets out why we process your data, the lawful basis for the processing and the associated retention period:
7. CONDITIONS OF THIRD-PARTY ACCESS TO YOUR PERSONAL DATA
The Raffles Hotel Singapore endeavours to provide you with the same and/or more improved services throughout your journey with us. Thus, we have to share your personal data with internal and external recipients subject to the following conditions:
- We share your data with a number of authorized people and departments in Raffles Hotel Singapore in order to offer you the best experience in our outlets and shops. The following teams may have access to your data:
- Hotel staff
- IT departments
- Commercial partners and marketing services
- Legal services if applicable
- Generally, any appropriate person within Raffles Hotel Singapore entities for certain specific categories of personal data.
In particular, the data related to your preferences, satisfaction and, if the case may be, your loyalty program membership is shared within the operations under the Raffles Hotel Singapore brand. This data is used to improve the quality of service and your experience in each of these outlets in Raffles Spa. In this context, your data is processed jointly by Raffles Spa and Raffles Hotel Singapore. In order to pursue this legitimate interest, whilst safeguarding your rights and liberties, a specific joint controllership agreement describes the obligations and responsibilities of Raffles Spa and Raffles Hotel Singapore. You may, at any time, object to the sharing of this data between the hotel and Raffles Spa by contacting the Marketing Communications department whose details appear in the clause "Your rights". You can also request a summary of the key points of the joint controllership agreement.
- With service providers and partners:your personal data may be sent to a third party for the purposes of supplying you with services and improving your stay, for example:
- External service providers: IT sub-contractors, international call centres, banks, credit card issuers, external lawyers, dispatchers.
- Commercial partners: Raffles Spa may, unless you specify otherwise to the Marketing Communications department of Raffles Spa, enhance your profile by sharing certain personal information with its preferred commercial partners. In this case, a trusted third party may cross-check, analyse and combine your data. This data processing will allow Raffles Spa and its privileged contractual partners to determine your interests and customer profile to allow us to send you personalized offers.
- Social networking sites: In order to allow you to be identified on the Raffles Spa website without the need to fill out a registration form, Raffles Spa may put in place a social network login system. If you log in using the social network login system, you explicitly authorize Raffles Spa to access and store the public data on your social network account (e.g. Facebook, LinkedIn, Google, Instagram…), as well as other data stated during use of such social network login system. Raffles Spa may also communicate your email address to social networks in order to identify whether you are already a user of the concerned social network and in order to post personalized, relevant adverts on your social network account if appropriate.
- With local authorities:We may be obliged to send your information to local authorities if this is required by law or as part of an inquiry. We will ensure that any such transfer is carried out in accordance with local regulations.
8. PROTECTION OF YOUR PERSONAL DATA DURING INTERNATIONAL TRANSFERS
For the purposes set out in clause 6 of this charter, we may transfer your personal data to internal or external recipients who may be in countries offering different levels of personal data protection.
Consequently, in addition to implementation of this charter, Raffles Spa employs appropriate measures to ensure secure transfer of your personal data to Raffles Hotel Singapore entity or to an external recipient located in a country offering a different level of privacy from that in the country where the personal data was collected.
9. DATA SECURITY
Raffles Spa takes appropriate technical and organizational measures, in accordance with applicable legal provisions (in particular: Art. 32 GDPR), to protect your personal data against illicit or accidental destruction, alteration or loss misuse and unauthorized access, modification or disclosure. To this end, we have taken technical measures (such as firewalls) and organizational measures (such as a user ID/password system, means of physical protection etc.) to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services. In relation to the submission of credit card data when making a reservation, SSL (Secure Socket Layer) encryption technology is used to guarantee a secure transaction. Organizational measures ensure the security of the processing.
11. YOUR RIGHTS
You have the right to obtain information about and access your personal data collected by Raffles Spa, subject to applicable legal provisions. Also, you have the right to have your personal data rectified, erased or have the processing of it restricted. Furthermore you have the right to data portability and to issue instructions on how your data is to be treated after your death (hopefully as late as possible!). You can also object to the processing of your personal data, in particular to the sharing of the data related to your preferences and satisfaction between the outlets operating in Raffles Spa.
In the event that you wish to exercise any of your above rights, please contact the Marketing Communications department for Raffles Spa directly by sending an email to email@example.com or by writing to the address below:
Raffles Hotel Singapore
Marketing Communications Department
1 Beach Road, Singapore 189673
For the purposes of confidentiality and personal data protection, we will need to check your identity in order to respond to your request. In case of reasonable doubts concerning your identity you may be asked to include a copy of an official piece of identification, such as an ID card or passport, along with your request. A black and white copy of the relevant page of your identity document is sufficient.
All requests will receive a response as swiftly as possible.
You may also exercise your rights in respect of your personal data that is stored and processed by a hotel as a data controller. To do this, you must contact the hotel directly.
You also have the right to lodge a complaint with a data protection authority. For your information,
You can contact Raffles Hotel Singapore’s data protection officer by writing to firstname.lastname@example.org or to the above postal address
We may modify this charter from time to time. Consequently, we recommend that you consult it regularly.
13. QUESTIONS AND CONTACTS
For any questions concerning Raffles Spa’s personal data protection policy, please contact the Marketing Communications department for Raffles Spa (See clause "Your rights").