Privacy policy

The Old School Room

This notice describes how we process your personal data if you book at ‘The Old School Room’ Nottingham.

The controller is ‘The Old School Room’The correspondence address for The Old School Room is, Unit 1 Quayside Court, Colwick Quays Business Park, Road No. 2, Colwick, Nottingham, NG4 2SR, United Kingdom. 

You have the right to object to some of the processing which The Old School Room carries out. More information about your rights and how to exercise these is set out in the section headed “Your rights” below. 

This notice applies to: 

And anyone contacting, visiting or using our: 

Summary of the purposes for processing your personal data and the legal basis for doing so: 

We keep your data to enable us to fulfil our contract with you or to provide services, where required by law, to respond to a question or complaint, to obey rules about keeping records, to uphold or protect contractual or legal rights or where it is in your or another party’s vital interests or our legitimate interests. Where we process personal data on the basis of your consent, we will retain it for as long as required for the specified purpose. We also keep your data in line with any statutory limitation periods and for tax, legal or regulatory purposes. 

Your rights 

o request access, rectify, and erase your personal data;
o object to processing for any purpose where we rely on our legitimate interests as the legal basis;
o restrict processing; and
o supply or transfer your personal data in a portable format. 

Where you exercise any of your rights, we will process your personal data to comply with your request in accordance with our legal obligations. 

• Where we use automated decision-making, you have the right to human intervention, to add a statement, and to have the decision reviewed. 

You have the right to lodge a complaint with the data protection supervisory authority of the country in which you are resident, work or in which your complaint arises. For the contact details of the Information Commissioner in the UK see www.ico.org.uk.

We may provide additional information during the booking and check-in process and at other points at which we collect your personal data. 

If you wish to exercise your rights, please contact us at info@heritagemewsnottingham.co.uk or write to us at our correspondence address.

Personal information we collect 

We collect personal information when you book with us or request or use our services. This includes, using our websites or apps, or corresponding with us. We may also receive personal data about you from another source. This includes: 

Third parties, including where we are joint controllers, that we receive personal data from may include: 

How do we use your information, and what is the legal basis for this use? 

• To fulfil a contract, or take steps linked to a contract. This is relevant when you want to make a reservation with us; or receive other products and services from us and includes: 

o making, amending or administering your room booking; o providing products and services requested by you;
o verifying your identity;
o processing payments; 
o communicating with you;
o providing customer services, including managing complaints; and 
o alerting you by text, email or phone in the event of an unplanned incident, as a result of which we have to make alternative arrangements under our contract (or where we believe it is in your vital interests). 

If the information we request is not provided, we may not be able to enter into or comply with a contract or our legal obligations. 

• In our legitimate interests regarding the conduct of our business, in particular: 

Ensuring customer satisfaction, maintaining goodwill and dispute resolution 

o we provide technical support and investigate and process any complaints about our website or our products or services, and to maintain appropriate records for internal administrative purposes. We reserve the right to request evidence to support any claims or complaints. 

To protect our business and prevent fraud 

o monitor, test and control the performance and security of our systems, networks, processes and premises to prevent and detect fraud and protect our business; 

o if you provide a credit or debit card as payment, we use third parties to check the validity of your bank account or card details to prevent fraud. 

For business performance and improvement 

o monitor and record CCTV, call centre communications, including incoming and outgoing calls and emails for staff training, quality improvement purposes and establishing facts; and 
o analyse transactions to enable us to improve our services and products and plan for our business. 

Safety & Security of our Guests and Employees 

o to protect premises and for security purposes including information recorded from CCTV; 
o to monitor hygiene;
o to obtain statements from witnesses to accidents and other incidents; and
o for the detection and prevention of crime. 

Developing and Marketing Products and Services 

o for raising brand awareness;
o to understand you better as a customer by analysing your transactions and other information you provide to us or which we learn through your interactions with us; 
o for marketing (including creating profiles), competitions and promotions by post, email, text and push notification where permitted to do so by law (for an alternative lawful basis, see consent below); 
o we may use your data to provide personalised promotional offers to you; 
o we may also use your data to provide you with personalised promotional offers on selected partner websites (for example, you might see an advertisement for our products on a partner site such as Facebook and Google); 
o we also may share some of your information with marketing service and ad technology providers and digital marketing networks, such as Facebook, Google, Adobe and Rocket Fuel, to present advertisements that might interest you. 

For example we may transfer information about you to such providers so that they may recognize your devices and deliver interest-based content and advertisements to you. 

The information may include your name, email, device ID, or other identifier in encrypted form. The providers may process the information in hashed form. These providers may collect additional information from you, such as your IP address and information about your browser or operating system; may combine information about you with information from other companies in data sharing cooperatives in which we participate; and may place or recognize their own unique cookie on your browser. These cookies may contain demographic or other data in de-identified form; 

o for monitoring the use of our websites, apps and Facebook Pages in order to improve their performance, understand how people are engaging with them and optimise our media spend; 
o we use personal data of some individuals to invite them to provide feedback or take part in market research; and 
o for developing corporate business and applying rates. 

Legal and Regulatory purposes 

o in connection with legal claims, compliance, regulatory and investigative purposes as necessary (including disclosure of such information in connection with claims, legal process or litigation); 
o to comply with health and safety legislation, including accounting for the number of individuals on our premises and logging accidents; 
o to prevent, investigate and/or report suspected fraud, terrorism, security incidents or other crime, in accordance with applicable law; and 
o to anonymise personal data when we no longer need to process it.

 • Where you give us consent: 

o we will send you emails, texts and push notifications (including newsletters) in relation to products and services provided by us (for an alternative lawful basis see “legitimate interests” above), or by our named affiliates and carefully selected partners; 
o when you use our websites or apps, we place cookies and use similar technologies on your computer, mobile or other device and we use such technologies such as pixel tags and web beacons in marketing emails and communications;
o we may use credit checks.
o to participate in competitions we run and, if you win, to use your information for promotional purposes; 
o we will process health information, such as dietary, accessibility, and allergy information you or a party on your behalf provides to us (we may also be able to do this where it is in your vital interests); 
o when you make a donation to a charity, we will process your payment for this purpose; and 
o on other occasions where we ask you for consent, we will use the personal data for the purpose which we explain at that time. You have the right to withdraw consent at any time. 

• For purposes which are required by law: 

o to record the identity and nationality of overseas guests (excluding the Republic of Ireland and Commonwealth citizens) on check-in. These guests will be asked to complete a registration form and provide their identity card/passport details, to comply with the Immigration (Hotel Records) Order 1972, as amended. Acceptable forms of identification are: a passport, driving licence, ID card or police warrant card. 
o UK;
o in response to requests by government, law enforcement authorities, or intelligence services and court orders; 
o if required to comply with health and safety legislation to which we are subject; 
o we may be required to share information with other licensees in accordance with local licensing requirements; and o responding to a rights request under data protection legislation.

 • To protect your vital interests or those of another person: 

o disclosing your personal data to the emergency services where we believe it is necessary to protect your vital interests or the vital interest of another person; and 
o where you (or a person acting on your behalf) provide us with dietary or other personal health data such as allergies. 

Other recipients that we disclose, transfer or share your personal data with: 

Service Providers 

For some activities Premier Inn uses third party service providers including where we are joint controllers. Your personal data will be disclosed to such organisations where this is necessary to provide a service to you, or where it is in our legitimate interests. For example, we use third parties to: 

o administer bookings;
o provide Wi-Fi;
o provide parking facilities (e.g. for NCP);
o undertake customer feedback surveys;
o provide analytics;
o send promotional offers;
o provide personalised advertisements;
o provide insurance;
o provide IT development, support, maintenance and hosting, including the provision of applications and website hosting;
o process payments to enable you to pay by credit or debit card; o provide credit checks and fraud checks; and
o provide CCTV systems and maintenance. 

Other parties 

Personal data may be shared with regulators, government authorities and/or law enforcement officials for the prevention or detection of crime, if required by law or if required for a legal or contractual claim or regulatory purposes. We disclose your personal data to payment providers, technology providers, insurers, and other specialist professional and technical advisers, to manage your bookings, arrange payments, and provide services. With your consent, we will also disclose your personal data to Ombudsman services and Citizens’ Advice. 

Restructure and sale 

In the event that the business is sold or integrated with another business, your details may be disclosed to our advisers and any prospective purchaser’s adviser and will be passed to the new owners of the business. 

International transfers 

Sometimes we may need to send or store your data outside of the European Economic Area (the EU plus Iceland, Lichtenstein and Norway) (‘EEA’). For example, to follow your instructions, comply with a legal duty or to work with or receive services from our service providers who we use to help run your accounts and our services. 

If we do transfer information outside of the EEA, we will make sure that it is protected by using one of these safeguards:

For some of our service providers in the US, we rely on Privacy Shield. For example the party who helps us with our customer feedback surveys. We rely on contractual measures for a small number of our suppliers who have or use offices outside the EEA and who have restricted access to some data to provide us with IT services including development, testing, support and maintenance. For further details on the mechanisms used please contact info@heritagemews.co.uk 

What rights do I have? 

Withdrawing consent or otherwise objecting to direct marketing 

Sometimes we may need to send or store your data outside of the European Economic Area (the EU plus Iceland, Lichtenstein and Norway) (‘EEA’). For example, to follow your instructions, comply with a legal duty or to work with or receive services from our service providers who we use to help run your accounts and our services. 

If we do transfer information outside of the EEA, we will make sure that it is protected by using one of these safeguards:

Wherever we rely on your consent, you will always be able to withdraw that consent. We will continue to process your personal data for other purposes on a different lawful basis (other than consent) where that applies. 

In some cases, we are able to send you direct marketing without your consent, where we rely on our legitimate interests. You have an absolute right to opt-out of direct marketing, and any profiling we carry out for direct marketing, at any time. You can do this by clicking on the 'unsubscribe' link located in the footer of every marketing email or text. 

Where you have a relationship with another organisation, such as a social media platform like Facebook, we may ask them to send marketing to you. If you object to receiving marketing from us we will stop marketing to you. However, please contact the organisation directly if you want to object or withdraw your consent to such organisation marketing to you. 

Other qualified rights 

These rights may be limited, for example if fulfilling your request would reveal personal data about another person or you ask us to erase information which we are required by law to keep. Where you object to us processing personal information we may have a compelling justification for processing it. Relevant exemptions are also included within the data protection laws that apply in the UK. We will inform you of relevant exemptions we rely upon when responding to any request you make. 

To exercise any of these rights, you can get in touch with us using the details set out below. If you have concerns, you have the right to complain to the data protection supervisory authority of the EU Member State in which you are resident, work or in which your complaint arises. In the UK, the supervisory authority is the Information Commissioner. Details of all EU supervisory authorities can be found at: 

http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=612080

Copyright Hawkes web Design