Privacy Statement
Privacy Statement – Hotel Acropolis v240626
This Privacy Statement explains which personal data Hotel Acropolis collects, why we collect it, with whom we share it, how long we retain it, and what rights you have. It applies, among others, to guests, bookers, accompanying travellers, visitors, event clients, suppliers, job applicants, website visitors, and users of our Wi-Fi network.
-
Who are we?
Hotel Acropolis is operated by IG CONCEPT BV, with its registered office at Oostendestraat 341, 8820 Torhout, Belgium, VAT BE 0878.141.196. The hotel operation is located at Westendelaan 94, 8430 Middelkerke.
Unless explicitly stated otherwise, IG CONCEPT BV is the data controller responsible for the processing of personal data described in this Privacy Statement.
For questions regarding this Privacy Statement or the processing of your personal data, you may contact our privacy contact person: Carlo Vermeersch, via carlo@hotelacropolis.be or by post at the address above.
2. Which personal data do we process?
Depending on your relationship with us, we may process the following data:
identification and contact details, such as name, address, telephone number, email address, language, date of birth and nationality;
reservation and stay information, such as arrival and departure dates, room type, accompanying travellers, preferences, remarks and communications relating to your stay;
data required by law or in practice during registration, such as information from identity or travel documents, visa details and information required for tourist taxes;
billing and payment information, such as billing address, company details, payment method and payment references;
information relating to events, groups and business clients, such as participant lists, contact persons, agreements and catering or meeting room preferences;
special requests that you communicate yourself, for example allergies, mobility requirements or other information necessary to welcome you appropriately;
technical data when using our website and Wi-Fi, such as IP address and cookie information;
camera footage recorded in and around the hotel;
data relating to suppliers, applicants and employees necessary for professional relationships, recruitment and administration.
We generally receive this information directly from you or from the person making a reservation on your behalf. In some cases, we receive data through booking platforms, travel organisers, companies, event organisers, payment service providers, public sources or other parties involved in your reservation or in the delivery of our services.
3. Guests and reservations
For reservations and stays, we process contact details, address details, stay information, billing information, payment references and, where necessary, identity, nationality, travel document and visa information.
Bookingplanner may contain, among other things, name, address, telephone number, mobile number, email address, language, nationality, citizenship, date of birth, place of birth, gender, identification number, document type, country of issue, document validity, visa number, tourist tax information, marketing consent, insurance information and internal notes.
4. Why do we process your personal data?
Reservations and stays: to process your request and reservation, prepare your stay, manage check-in and check-out, room occupancy and guest preferences, handle practical requests or lost property, and provide hotel or event services.
Payments and administration: to process deposits, payment guarantees and payments, issue invoices, handle cancellations, no-shows, refunds or damages, maintain our accounting records and manage disputes.
Legal obligations.
Communication and service: to send practical messages, confirmations, information regarding your stay, responses to enquiries and complaint handling.
News and promotions: to send newsletters and promotional offers where permitted.
Improvement of our services: to compile general statistics, improve our website and services, and better understand guest satisfaction. Whenever possible, we use aggregated or anonymised data for these purposes.
Personnel and suppliers: to manage job applications, employment relationships, contracts, deliveries and professional contacts.
5. Legal bases
We only process personal data where there is a valid legal basis:
the performance of a contract or steps prior to entering into a contract (for example, a reservation);
a legal obligation, for example accounting obligations;
a legitimate interest, such as security, fraud prevention or complaint management. We always balance this interest against your privacy rights;
the establishment, exercise or defence of legal claims.
6. Website and cookies
Our website uses a cookie banner with necessary, functional, analytical and marketing cookies. Visitors can save their preferences and modify or withdraw their consent at any time.
For website analytics, we use Google Analytics 4 (GA4). According to confirmation from our website partner, full IP addresses are not stored within GA4 and are not made available to Hotel Acropolis. Google may temporarily process an IP address for technical communication purposes and to determine derived information such as geographical location. Reports do not contain full IP addresses or directly identifiable IP information.
The website also uses Google Tag Manager, Google Ads and Meta/Facebook Pixel for analytics, marketing and advertising purposes.
More information regarding cookies and tracking technologies can be found in the separate Cookie Policy of Hotel Acropolis.
7. Newsletter
We use Mailchimp for newsletters and promotional emails. We send these communications where you have given your consent or where this is legally permitted within the context of an existing customer relationship.
No automated campaigns for abandoned bookings or birthdays are used.
Recipients may unsubscribe from newsletters at any time.
8. CCTV surveillance
Cameras are installed in and around Hotel Acropolis, including on the car park, at entrances, reception, corridors, lifts, breakfast area, Arena and outdoor areas.
The footage is accessible only to authorised persons and is generally retained for 10 days. In the event of an incident, relevant footage may be retained for a longer period if necessary for investigation, evidence purposes or handling by the police, insurers or courts.
The footage is used exclusively for security and incident investigation purposes.
9. Wi-Fi
When using the guest Wi-Fi network, IP addresses, MAC addresses, connection logs and possibly email addresses may be processed.
The guest network is separated from our internal systems and client isolation is enabled.
10. Recipients and processors
Only employees and service providers who require access to data for their duties are granted access. They are required to handle the data confidentially and securely.
We work with, among others, Microsoft, Clew, Ubicum, Bookingplanner, Cubilis, Teamleader, Venice, Billit, Liantis, Mailchimp, Mollie, Axepta, Payconiq, Booking.com, Google, Meta, RoomRudder and Salto.
11. Retention periods
We do not retain your personal data longer than necessary for the purposes for which it was collected.
Billing, stay and reservation data are generally retained for ten years.
CCTV footage is generally retained for ten days unless it is required for the investigation or handling of an incident.
Newsletter data are retained until you unsubscribe.
Applicant data are generally retained for a maximum period of six months following the end of the recruitment process, unless consent has been obtained to retain the data for a longer period.
After the applicable retention period has expired, data are deleted or anonymised, unless longer retention is required for the handling of a dispute or compliance with a legal obligation.
12. How do we protect your data?
We take appropriate organisational and technical measures to protect personal data against loss, misuse, unauthorised access and unwanted alteration.
Examples include access restrictions, individual user accounts, network segmentation, secure systems, backups, agreements with service providers and confidentiality obligations for employees.
13. Your rights
Subject to the conditions set out in applicable data protection legislation, you may:
request information and access to the personal data we process about you;
request correction of inaccurate or incomplete data;
request deletion of data or restriction of processing in certain circumstances;
object to processing based on legitimate interests and to direct marketing;
receive the data you have provided in a structured, commonly used electronic format;
withdraw previously given consent. Such withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
You may send your request to info@hotelacropolis.be or by post to the address mentioned above.
Please clearly indicate which right you wish to exercise and which data your request concerns. We may request additional information where reasonably necessary to verify your identity.
We generally respond within one month. In the case of complex or numerous requests, this period may be extended as permitted by law.
14. Complaints
If you have a question or complaint regarding the processing of your personal data, please first contact us on +32 59 47 17 17.
You also have the right to lodge a complaint with the supervisory authority:
Data Protection Authority
Rue de la Presse 35 / Drukpersstraat 35
1000 Brussels
T: +32 (0)2 274 48 00
F: +32 (0)2 274 48 35