Privacy Policy

Your privacy matters to us. Learn how we protect and handle your personal data.

Last updated: June 9, 2025 • Effective: June 9, 2025 • GDPR Compliant

Privacy Controls

Manage your privacy preferences and data settings

Essential Cookies

Always Active

Required for basic website functionality and security.

  • • Session management
  • • Security preferences
  • • Form submissions

Analytics

Help us improve our website by collecting usage statistics.

  • • Page views and interactions
  • • User journey analysis
  • • Performance metrics

Marketing

Personalized content and targeted advertisements.

  • • Personalized recommendations
  • • Targeted advertising
  • • Social media integration

1. Introduction

At The Island House Hotel, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

Your Trust Matters: We believe transparency is key to building trust. This policy uses clear, simple language to explain our data practices.

We comply with the General Data Protection Regulation (GDPR) and other applicable privacy laws.

2. Data Controller

The Island House Hotel B.V. is the data controller responsible for your personal information. This means we determine how and why your personal data is processed.

Controller Details:

Legal Entity:

The Island House Hotel B.V.

Registration:

KvK 12345678

Address:

Prinsengracht 263, 1016 GV Amsterdam, Netherlands

DPO Contact:

[email protected]

3. Data We Collect

We collect various types of information to provide and improve our services. Here's a comprehensive overview of the data we may collect:

Personal Information

  • • Full name and contact details
  • • Email address and phone number
  • • Postal address and nationality
  • • Date of birth and age verification
  • • Emergency contact information
  • • Special requirements and preferences

Booking Information

  • • Reservation details and dates
  • • Room preferences and requirements
  • • Guest count and composition
  • • Special requests and dietary needs
  • • Previous booking history
  • • Loyalty program participation

Payment Information

  • • Billing address and details
  • • Transaction history and receipts
  • • Payment method preferences
  • • Credit verification (when required)
  • • Refund and dispute records
  • Note: Card details are not stored

Technical Information

  • • IP address and location data
  • • Browser type and version
  • • Device information and OS
  • • Website usage and navigation
  • • Cookies and tracking pixels
  • • Performance and error logs

Sensitive Data: We may collect special categories of data (health information, dietary requirements) only when necessary for providing our services and with your explicit consent.

4. How We Collect Data

We collect your personal data through various methods and channels. Understanding how we collect your information helps you make informed decisions about your privacy.

1
Direct Collection

Information you provide directly to us:

  • • Account registration forms
  • • Booking and reservation forms
  • • Contact and inquiry forms
  • • Newsletter subscriptions
  • • Customer service interactions
  • • Survey and feedback responses
  • • Social media interactions
  • • Event registrations

2
Automatic Collection

Information collected automatically when you use our services:

  • • Website cookies and tracking
  • • Page views and click behavior
  • • Search queries and preferences
  • • Device and browser information
  • • Location data (with permission)
  • • Session recordings (anonymized)
  • • Performance metrics
  • • Error reports and logs

3
Third-Party Sources

Information we receive from external sources:

  • • Partner hotel reservations
  • • Social media platforms
  • • Payment processors
  • • Marketing partners
  • • Travel agencies and OTAs
  • • Analytics providers
  • • Customer review platforms
  • • Public databases (when permitted)

5. How We Use Your Data

We use your personal data for various purposes to provide, maintain, and improve our services. Here's how we use the information we collect:

Service Provision

  • • Process and manage bookings
  • • Provide customer support
  • • Facilitate payments and billing
  • • Manage your account and preferences
  • • Deliver requested services
  • • Handle cancellations and refunds

Communication

  • • Send booking confirmations
  • • Provide service updates
  • • Respond to inquiries
  • • Send newsletters (with consent)
  • • Share promotional offers
  • • Conduct satisfaction surveys

Personalization

  • • Customize user experience
  • • Recommend relevant hotels
  • • Remember your preferences
  • • Provide targeted content
  • • Optimize website layout
  • • Enhance mobile experience

Analytics & Improvement

  • • Analyze website usage patterns
  • • Improve service quality
  • • Develop new features
  • • Monitor performance
  • • Conduct research and analysis
  • • Measure marketing effectiveness

Legal and Compliance

We may also use your data to comply with legal obligations, resolve disputes, enforce our agreements, and protect our rights and the rights of others.

7. How We Share Your Data

We may share your personal data with third parties in specific circumstances. We never sell your personal data to third parties.

Partner Hotels

We share booking information with hotels to facilitate your reservation:

  • • Guest names and contact details
  • • Booking dates and preferences
  • • Special requests and requirements
  • • Payment confirmation

Service Providers

We work with trusted service providers who help us operate our business:

  • • Payment processors
  • • Email service providers
  • • Cloud hosting services
  • • Analytics providers

Legal Requirements

We may disclose your data when required by law:

  • • Legal proceedings
  • • Government requests
  • • Regulatory compliance
  • • Fraud prevention

Business Transfers

In case of business restructuring:

  • • Mergers and acquisitions
  • • Asset sales
  • • Bankruptcy proceedings
  • • Corporate restructuring

Data Protection Measures

When we share your data, we ensure:

  • • Contractual data protection obligations
  • • Appropriate technical and organizational measures
  • • Limited data sharing (only what's necessary)
  • • Regular security assessments
  • • Compliance with applicable privacy laws

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required by law.

Data Type Retention Period Reason
Account Information Until account deletion Service provision
Booking Records 7 years Legal/tax requirements
Payment Information 7 years Financial regulations
Marketing Preferences Until withdrawal Consent-based
Website Analytics 26 months Google Analytics default
Customer Support 3 years Service improvement

Automated Deletion

We have automated systems in place to delete personal data when retention periods expire, ensuring compliance with data minimization principles.

9. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your browsing experience, analyze website traffic, and personalize content.

Essential Cookies

Required for basic website functionality:

  • • Session management
  • • Security tokens
  • • Form submissions
  • • Language preferences
  • • Shopping cart functionality
Legal Basis: Legitimate interest

Performance Cookies

Help us improve website performance:

  • • Google Analytics
  • • Page load times
  • • Error tracking
  • • User behavior analysis
  • • A/B testing
Legal Basis: Consent

Marketing Cookies

Personalize your experience and ads:

  • • Personalized content
  • • Targeted advertising
  • • Social media integration
  • • Remarketing campaigns
  • • Interest-based ads
Legal Basis: Consent

Cookie Management

You can control cookies through:

  • • Our cookie preference center (available at the top of this page)
  • • Your browser settings
  • • Third-party opt-out tools
  • • Industry opt-out pages (e.g., aboutads.info)

Note: Disabling certain cookies may affect website functionality.

10. Your Privacy Rights

Under GDPR and other privacy laws, you have several rights regarding your personal data. Here's what you can do:

Right to Access

Request a copy of your personal data

  • • What data we have about you
  • • How we use your data
  • • Who we share it with
  • • How long we keep it

Right to Rectification

Correct inaccurate or incomplete data

  • • Update contact information
  • • Correct booking details
  • • Fix profile information
  • • Update preferences

Right to Erasure

Request deletion of your personal data

  • • Delete account and profile
  • • Remove marketing data
  • • Clear browsing history
  • • Cancel subscriptions

Right to Portability

Receive your data in a portable format

  • • Export account data
  • • Download booking history
  • • Transfer to another service
  • • Machine-readable format

Right to Restriction

Limit how we use your data

  • • Pause data processing
  • • Limit marketing use
  • • Restrict sharing
  • • Temporary processing halt

Right to Object

Object to certain data processing

  • • Stop direct marketing
  • • Object to profiling
  • • Refuse analytics tracking
  • • Opt-out of automated decisions

How to Exercise Your Rights

1
Contact Us

Email [email protected] or use our contact form

2
Verify Identity

We'll verify your identity to protect your privacy

3
Response

We'll respond within 30 days (or explain any delays)

11. Data Security

We implement comprehensive security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

Technical Security

  • • SSL/TLS encryption for all data transmission
  • • AES-256 encryption for data at rest
  • • Multi-factor authentication systems
  • • Regular security audits and penetration testing
  • • Automated threat detection and monitoring
  • • Secure cloud infrastructure (AWS/Azure)
  • • Regular software updates and patches

Organizational Security

  • • Comprehensive staff privacy training
  • • Role-based access controls
  • • Regular employee background checks
  • • Confidentiality agreements
  • • Incident response procedures
  • • Privacy by design principles
  • • Third-party security assessments

Security Certifications & Standards

ISO 27001
Information Security
SOC 2
Service Organization
PCI DSS
Payment Security
GDPR
Privacy Compliance

Data Breach Response

In the unlikely event of a data breach, we will:

  • • Contain the breach immediately
  • • Assess the scope and impact
  • • Notify relevant authorities within 72 hours
  • • Inform affected individuals promptly
  • • Provide clear guidance on protective measures
  • • Conduct a thorough investigation
  • • Implement additional safeguards

12. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). We ensure appropriate safeguards are in place for such transfers.

Adequacy Decisions

Countries with EU-approved privacy laws:

  • • United Kingdom
  • • Switzerland
  • • Canada (commercial organizations)
  • • Japan
  • • South Korea

Standard Contractual Clauses

For other countries, we use EU-approved contracts:

  • • United States (cloud providers)
  • • Australia (analytics services)
  • • Singapore (customer support)
  • • India (development services)

Transfer Safeguards

When transferring data internationally, we ensure:

  • • Appropriate legal mechanisms are in place
  • • Equivalent levels of data protection
  • • Regular compliance monitoring
  • • Right to obtain copies of transfer agreements
  • • Ability to lodge complaints with supervisory authorities

13. Children's Privacy

Age Restrictions

Our services are not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16.

Under 16: No account creation allowed
16-18 years: Parental consent required for certain activities
Hotel bookings: Must be 18+ or have adult supervision

If we become aware that we have collected personal information from a child under 16, we will take steps to delete such information promptly.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

How We Notify You

  • • Email notification to registered users
  • • Prominent notice on our website
  • • In-app notifications
  • • Social media announcements

Your Options

  • • Review changes carefully
  • • Contact us with questions
  • • Update your preferences
  • • Exercise your rights if needed

Version History

Version 3.0 June 9, 2025
Current

Major update: Enhanced GDPR compliance, new cookie controls, expanded data subject rights

Version 2.1 March 15, 2025

Updated data retention periods and third-party integrations

Version 2.0 January 1, 2025

Comprehensive rewrite for better clarity and new service features

15. Contact Us

If you have any questions about this Privacy Policy or our data practices, please don't hesitate to contact us.

Data Protection Officer

+31 20 123 4567 (ext. 201)

Privacy Office

Prinsengracht 263

1016 GV Amsterdam

Netherlands

Supervisory Authority

Dutch Data Protection Authority (AP)

Postbus 93374

2509 AJ Den Haag

Netherlands

You have the right to lodge a complaint with the supervisory authority if you believe your data protection rights have been violated.

Response Times

General Inquiries:

Within 2 business days

Data Subject Requests:

Within 30 days (may extend to 60 days for complex requests)

Data Breach Reports:

Within 72 hours of discovery

Thank You for Your Trust

Your privacy is fundamental to our relationship. We're committed to earning and maintaining your trust through transparent, responsible data practices.

Last updated: June 9, 2025 • Effective: June 9, 2025