Privacy Policy

INTRODUCTION

HOTEL BEIRA MAR values respect for privacy and the protection of data of guests/clients, visitors, website users, as well as people who relate to us as suppliers, service providers, and partners.

It is important that you read and understand the guidelines that steer how we process your personal data, especially how we make decisions regarding the purposes and the manner in which they will be collected, used, stored, shared, and deleted.

The expressions “HOTEL BEIRA MAR”, “Hotel”, “we”, and “our” in this Privacy Policy refer to HOTELEIRA HBM LTDA and other affiliated group companies, which are controllers of your personal information.I. OBJECTIVE

The objective of this Privacy Policy is to establish guidelines, principles, and concepts to be followed by all individuals and institutions that interact with HOTEL BEIRA MAR and describe how we collect, for what purpose, with whom we share, and how we process your personal data.

Furthermore, it addresses the collection of data via cookies, the storage period of the information obtained through them, and the security measures we use.

These privacy guidelines present, simply and transparently, the necessary information about the processing of your data—allowing you to make the best decisions about its concession or not—as well as the security measures necessary to ensure your privacy.

If you do not expressly agree with the collection and processing of personal data described in this policy—all of which are necessary for the provision of our services—you may opt out of the service provision or discontinue your access to the website.

The provisions contained in this Policy must be interpreted in conjunction with applicable national legislation, especially those related to data privacy, such as the General Data Protection Law – LGPD (Law No. 13.709/2018).

HOTEL BEIRA MAR is committed to always adopting the best personal data governance practices, paying attention to the fulfillment of the provisions foreseen in the LGPD and other applicable regulations, aiming at the continuous improvement of our internal procedures and the provision of services with excellence.II. DEFINITIONS

For a better understanding of this document, the following terms are considered in this Privacy Policy:

Processing agents:Are natural or legal persons who perform personal data processing. They can be the controller and the operator.
Anonymization:Use of technical means through which data loses the possibility of association, directly or indirectly, with an individual.
National Data Protection Authority (ANPD):Public administration body responsible for watching over, implementing, and enforcing the LGPD across the national territory.
Database:Structured set of personal data, established in one or more locations, in electronic or physical support.
Consent:Free, informed, and unequivocal manifestation by which the data subject agrees to the processing of their personal data for a determined purpose.
Controller:Natural or legal person, of public or private law, to whom decisions regarding the processing of personal data are incumbent.
Anonymized Data:Data related to a data subject who cannot be identified, considering the use of reasonable technical means available at the time of its processing.
Sensitive Personal Data:Personal data regarding racial or ethnic origin, religious conviction, political opinion, affiliation with a union or organization of a religious, philosophical, or political nature, data related to health or sexual life, genetic or biometric data, when linked to a natural person.
Personal Data:Information related to a natural person that makes them identified or identifiable.
Data Protection Officer (DPO):Person appointed by the controller and operator to act as a communication channel between the controller, the data subjects, and the National Data Protection Authority (ANPD).
LGPD:Brazilian General Data Protection Law (Law No. 13.709/18).
Operator:Natural or legal person, of public or private law, who performs the processing of personal data on behalf of the controller.
Data Subject:Natural person to whom the personal data that are the object of processing refer.
International Data Transfer:Transfer of personal data to a foreign country or international organization of which the country is a member.
Processing:Any operation performed with personal data, such as collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, archiving, storage, elimination, evaluation, or control of information, modification, communication, transfer, diffusion, or extraction.
Shared Use of Data:Communication, diffusion, international transfer, interconnection of personal data, or shared processing of personal databases by public bodies and entities in the fulfillment of their legal competencies, or between these and private entities, reciprocally, with specific authorization, for one or more processing modalities permitted by these public entities, or between private entities.

III. TO WHOM THIS POLICY APPLIES

(i) Guests/clients, visitors, and employees of HOTEL BEIRA MAR clients;

(ii) Suppliers and partners of HOTEL BEIRA MAR, in connection with the supply of goods or services to the hotel; and

(iii) Users of the website https://www.hotelbeiramar.com.br/ (“Site”).IV. REGULATORY FRAMEWORK

This Privacy Policy was drafted in accordance with Federal Law No. 12.965 of April 23, 2014 (Civil Rights Framework for the Internet) and Federal Law No. 13.709 of August 14, 2018 (General Data Protection Law).

HOTEL BEIRA MAR commits to complying with the rules foreseen in the General Data Protection Law (LGPD) and to respecting the principles set forth in Art. 6 of said norm:

i. Purpose: processing for legitimate, specific, explicit, and informed purposes to the data subject, with no possibility of subsequent processing in a manner incompatible with these purposes;

ii. Adequacy: compatibility of the processing with the purposes informed to the data subject, according to the context of the processing;

iii. Necessity: limitation of the processing to the minimum necessary for the realization of its purposes, covering pertinent, proportional, and non-excessive data in relation to the purposes of the data processing;

iv. Free access: guarantee to data subjects of facilitated and free consultation on the form and duration of the processing, as well as the integrity of their personal data;

v. Data quality: guarantee to data subjects of accuracy, clarity, relevance, and updating of the data, according to the need and for the fulfillment of the purpose of its processing;

vi. Transparency: guarantee to data subjects of clear, precise, and easily accessible information about the realization of the processing and the respective processing agents, observed commercial and industrial secrets;

vii. Security: use of technical and administrative measures capable of protecting personal data from unauthorized access and accidental or illicit situations of destruction, loss, alteration, communication, or diffusion;

viii. Prevention: adoption of measures to prevent the occurrence of damages due to the processing of personal data;

ix. Non-discrimination: impossibility of performing processing for illicit or abusive discriminatory purposes;

x. Accountability and rendering of accounts: demonstration by the agent of the adoption of effective measures capable of proving the observance and compliance with personal data protection rules, including the effectiveness of these measures.V. CONTROLLER

HOTEL BEIRA MAR acts as a data controller when it provides accommodation services, hires suppliers and service providers, and interacts with commercial partners to support the operation, as well as interacts with third parties who process personal data on its behalf.

Its qualification as a data controller is:

HOTELEIRA HBM LTDA

CNPJ: 11.337.762/0001-02

Address: Av. Beira Mar, 3130 – Meireles, Fortaleza – CE, ZIP Code: 60165-121

Phone: +55 (85) 4009-2017VI. RIGHTS OF THE PERSONAL DATA SUBJECT

The personal data subject has the following rights, conferred by the LGPD:

i. Right of confirmation and access (Art. 18, items I and II): right to obtain confirmation that personal data concerning them is or is not subject to processing, and if so, the right to access their personal data;

ii. Right of rectification (Art. 18, item III): right to request the correction of incomplete, inaccurate, or outdated data;

iii. Right to limitation of data processing (Art. 18, item IV): right to limit the processing of their personal data, being able to demand the elimination of unnecessary, excessive, or processed data in non-conformity with the provisions of the LGPD;

iv. Right of opposition (Art. 18, § 2): right to, at any time, object to data processing for reasons related to their particular situation, based on one of the hypotheses of waiver of consent or in case of non-compliance with the provisions of the LGPD;

v. Right to information (Art. 18, item VII): right to be informed about public and private entities with which the controller has performed shared use of data;

vi. Right to data portability (Art. 18, item V): right to perform the portability of data to another service or product provider, upon express request, in accordance with the regulations of the national authority, observed commercial and industrial secrets;

vii. Right not to be subject to automated decisions (Art. 20): right to request the review of decisions taken solely based on automated processing of personal data that affect their interests, including decisions intended to define their personal, consumption, and credit profile or aspects of their personality;

To exercise your rights, you may make your request via the electronic form available on our website and at this link: click hereVII. WHICH DATA IS PROCESSED

The use of certain service functionalities by the personal data subject will depend on the processing of the following personal data:

• Signature;

• Birth certificate;

• Bank details;

• Credit card details;

• Date of birth;

• E-mail address;

• Complete permanent address;

• Age;

• Image;

• Nationality;

• Place of birth;

• Full name;

• CPF registration number (for Brazilians);

• Telephone number;

• Passport (for foreigners);

• Profession;

• Next destination;

• ID card (RG);

• Sex;

• Telephone;

• Last origin.VIII. HOW DATA IS COLLECTED

The way your personal data is collected is indicated below:

DATA PROCESSEDMETHOD OF DATA COLLECTION
SignatureInformed by the guest/user
Bank detailsInformed by the guest/user
Credit card detailsInformed by the guest/user
Date of birthInformed by the guest/user
E-mail addressInformed by the guest/user
Complete permanent addressInformed by the guest/user
AgeInformed by the guest/user
ImageCaptured by the Hotel’s security cameras
NationalityInformed by the guest/user
Place of birthInformed by the guest/user
Full nameInformed by the guest/user
CPF registration number (Brazilians)Informed by the guest/user
Telephone numberInformed by the guest/user
PassportInformed by the guest/user
ProfessionInformed by the guest/user
Next destinationInformed by the guest/user
RGInformed by the guest/user
SexInformed by the guest/user
TelephoneInformed by the guest/user
Last originInformed by the guest/user

IX. WHAT PROCESSING IS PERFORMED AND FOR WHAT PURPOSE

The way your personal data is processed and the purpose are indicated below:

DATAPROCESSINGPURPOSELEGAL BASIS
SignatureAccess/StorageGuest/user identificationContract execution
Birth certificateAccess/StorageGuest identification/Regulatory requirementContract execution and compliance with legal and regulatory obligation
Bank detailsAccess/StorageService paymentContract execution
Credit card detailsAccess/StorageService paymentContract execution
Vehicle dataAccess/StorageGuest identificationContract execution
Date of birthAccess/StorageGuest/user identificationContract execution
E-mail addressAccess/StorageCommunication/ReservationsContract execution
Complete permanent addressAccess/StorageGuest/user identificationContract execution and compliance with legal and regulatory obligation
AgeAccess/StorageGuest/user identificationContract execution and compliance with legal and regulatory obligation
ImageAccess/StorageGuest/user/visitor security and facilitiesLegitimate interest of the Controller
NationalityAccess/StorageGuest/user identificationContract execution and compliance with legal and regulatory obligation
Place of birthAccess/StorageGuest/user identificationContract execution and compliance with legal and regulatory obligation
Full nameAccess/Storage/SharingGuest/user identification/Provision of amenitiesContract execution
CPF registration numberAccess/StorageGuest/user identificationContract execution and compliance with legal and regulatory obligation
Telephone numberAccess/StorageGuest/user identificationContract execution
PassportAccess/StorageGuest/user identificationContract execution and compliance with legal and regulatory obligation
ProfessionAccess/StorageGuest/user identificationContract execution
Next destinationAccess/StorageGuest/user identification/Regulatory requirementCompliance with legal and regulatory obligation
RGAccess/StorageGuest/user identificationContract execution
SexAccess/StorageGuest/user identificationContract execution
TelephoneAccess/StorageGuest/user identificationContract execution
Last originAccess/StorageGuest/user identification/Regulatory requirementCompliance with legal and regulatory obligation

X. PERSONAL DATA COLLECTED BY THIRD PARTIES

We may receive your personal data when you provide it to third parties for the purpose of making reservations at HOTEL BEIRA MAR. In this process, third parties use their own means to collect data concerning you and, by contract, allow us to also have access to this data so that our services can be provided.

Third parties who collect data have the legal obligation to obtain the respective consents and authorizations that you—freely and unequivocally—wish to give for the processing of your personal data. The Hotel relies on the content and scope of these consents to provide appropriate treatment for your personal data.

Although we contractually require that the consents obtained by third parties be adequate and comply with applicable legislation—mainly meeting the stated processing purposes—we disclaim any liability resulting from any inadequacy of these consents.

In relation to personal data obtained through third parties, HOTEL BEIRA MAR’s commitment is limited, in principle, to providing you with the greatest possible transparency regarding how we access, store, and use them.XI. DATA SHARING

To serve exclusively the purposes established in this Policy, we may share your personal information with:

i. The company that provides development and support services for our website for the specific purpose of administering it and maintaining its quality and security;

ii. HOTEL BEIRA MAR service providers who provide information technology services, data hosting services, and e-mail delivery services;

iii. Other suppliers and/or third-party service providers or subcontractors that collect, process, and/or store your data for the execution of the contract in the most efficient manner or to comply with specific legal obligations to which we are subject, acting as processing agents;

iv. In an eventual merger, acquisition, or other corporate operation, the acquiring/merged party, the counterparty of the operation, and service providers or third parties acting in the negotiation or transaction; and

v. Governmental authorities, regulatory agencies, or other public authorities for which we have responsibility.

In this process, we adopt appropriate measures to ensure the security of personal information and prevent its loss, as well as unauthorized alteration, processing, or access. Specific contractual clauses and other legally acceptable transfer mechanisms are adjusted and implemented in our procedures for protecting information. Contact us if you want more information regarding the safeguards adopted by HOTEL BEIRA MAR.XII. DATA SECURITY

HOTEL BEIRA MAR commits to applying technical and organizational measures capable of protecting personal data from unauthorized access, alteration, communication, or diffusion, as well as from situations of destruction and loss.

For security assurance, solutions will be adopted that take into consideration: adequate techniques; application costs; the nature, scope, context, and purposes of processing, as well as risks to the rights and freedoms of the user.

However, we disclaim liability for exclusive fault of third parties, such as in the case of hacker or cracker attacks, or exclusive fault of the user, in which they transfer their data to a third party. HOTEL BEIRA MAR further commits to communicating to the user, within an adequate period, should any type of security breach of your personal data occur that may cause a high risk to your rights and personal freedoms.

A personal data breach is a security breach that causes, accidentally or illicitly, the destruction or loss of personal data, as well as the alteration, disclosure, or unauthorized access to this data transmitted, stored, or subject to any other type of processing.

Finally, we commit to treating your personal data with confidentiality, preserving its integrity and availability, within legal limits.XIII. INTERNATIONAL DATA TRANSFER

HOTEL BEIRA MAR may transfer your personal data internationally—beyond the borders of the national territory—on some occasions, for example, when we use products and services located in foreign territory. These transfers may also occur due to our Hotel’s suppliers and partners, who may provide services abroad.

HOTEL BEIRA MAR will maintain the treatment applied in Brazilian territory in the foreign territory, ensuring the use of the same protection tools, in accordance with the provisions of Art. 33 of the LGPD and other ANPD regulations.XIV. SUBSEQUENT DATA PROCESSING FOR OTHER PURPOSES

Information about your personal data may be used for continuous improvement of our services, for enhancing your experience as a guest/client/user, as well as for improving our interaction with suppliers and partners.

If you, the personal data subject, choose to delete your data, it may be anonymized. Anonymized data may be used in the future for generating statistics, in order to improve our service procedures.XV. HOW TO CONTACT US

In case of questions, comments, requests, or any other concern about how we use your personal information, please contact us via the following email: privacidade@hotelbeiramar.com.br.XVI. CHANGES TO THE PRIVACY POLICY

HOTEL BEIRA MAR reserves the right to modify this Policy at any time, especially to adapt it to legal provisions that may be published, the needs of our service, and new website functionalities.

This Privacy Policy may be updated due to eventual normative updates, which is why the user is invited to periodically consult this section.

Privacy Channel: privacidade@hotelbeiramar.com.br

Data Subject Request Form—–Would you like me to summarize this policy or extract specific information for you?