Privacy Notice
Galadari Hotels (Lanka) PLC
Introduction
We are committed to protect and respect your right to privacy. This Privacy Notice (“Notice”) governs the collection and use of personal data by Galadari Hotels (Lanka) PLC. This Notice is applicable to Galadari Brothers Co. LLC (parent company) as well as Galadari Hotels (Lanka) PLC’s other subsidiaries that may also collect and process your personal data, either as controllers or processors. This Notice describes how and why we use any personal data you provide to us, as well as information we might obtain from other sources.
Your personal data may be used for any of the purposes specified in this Notice, or for additional purposes that we notify you of when your personal data is being collected.
In this Notice, references to “our,” “us,” or “we” refer to Galadari Hotels (Lanka) PLC.
Any references to “you” or “your” refers to the relevant individual who is the subject of the personal data.
Who are we?
Galadari Hotels (Lanka) PLC is the data controller for the purposes of any applicable data protection laws.
Definitions covered in this Notice
When we refer to “processing” your “personal data” in this Notice, we qualify this as any action done with or in connection with your personal data (this includes gathering, storing, and deleting such personal data). Any information that can be used to locate or (in)directly identify you is considered as “personal data”. Examples of personal data are: birth date, age, gender, nationality, passport, marital status, signature, country of residence, place of birth, photo, family details, voice recordings, religion, spoken languages, emergency contact information, insurance information, driver’s license number.
We process different categories of personal data further described below.
- Contact Details
Contact details is personal data that helps us to contact you, such as your address, email address and phone number.
- Identification Data
Identification Data is personal data that helps us identify you, such as your name, title, copy of your passport, NIC Number, driver’s license, proof of utility bills etc.
- Sensitive personal data
This category of personal data is considered as sensitive by law. Examples of sensitive personal data are your health data or your biometric data or a copy of your photo.
- Web Data
Web data is personal data collected via our websites such as cookies, user activity records, IP addresses, social media profiles, and information about your interactions on our websites.
- Geolocation Data
Geolocation data is personal data such as the location of your device.
- Financial Data
Financial data is personal data such as your bank and card information, bank statements and your salary details.
For what purposes do we process your personal data?
Description of Processing |
Category of Personal Data |
Legal Basis |
We process your personal data when we offer our products and services such as accommodation options, recreational opportunities, event spaces for conferences, business meetings, and other private gatherings, food and beverages, as well as food delivery services. |
Contact Details, Identification Data, and Financial Data |
Consent, Performance of Contract |
We process your personal data so we can monitor the quality of our products and services to you, to conduct surveys, obtain feedback and manage and progress complaints as necessary. |
Contact Details |
Consent |
We process your personal data for marketing and analytical purposes, including managing our loyalty programs and customizing offers for you. |
Contact Details, Identification Data, Web Data, and Financial Data |
Consent
|
We process your personal data to fulfil our legal obligations and to investigate or defend legal claims. |
Contact Details, Identification Data, Sensitive Personal Data, Web Data, and Financial Data |
Legal obligation |
We process your personal data for accounting, administration, and auditing purposes related to our business operations. |
Contact Details, Identification Data, and Financial Data |
Performance of Contract |
We process your personal data to protect and secure our IT systems or for backup and archiving purposes or to prevent a potential data breach. |
Contact Details, Identification Data, Sensitive Personal Data, Web Data, and Financial Data |
Consent |
We process your personal data to safeguard the safety and security of all customers and employees in our buildings or properties either owned or rented. |
Identification Data and Sensitive Personal Data |
Protection of the interest of the data subject |
Retention of Personal Data
We only retain your personal data for as long as necessary to carry out the purposes indicated in this Notice. After this period, we will securely delete your personal data, unless we are obligated to retain your personal data to comply with a legal or regulatory requirement or to deal with any potential disputes.
If we no longer need to keep your personal data, we will delete it from our systems and records and/or take steps to properly anonymize it so that you cannot be identified from it.
Your rights
You have certain rights that you can exercise. Please send an email to dpo@galadaribrothers.com to exercise your rights. The following rights may be applicable to you, depending on the jurisdiction where your personal data is processed:
Data Privacy Right |
What does it mean? |
Right to access your data |
You have the right to request from us a summary or a copy of the personal data that we have on file about you. |
Right to have your data updated or deleted |
You have the right to request that we immediately amend any inaccurate or missing personal data we may have about you along with the right to request that your personal data be deleted if it is no longer needed or processing it is prohibited by law. |
Right to limit or stop data processing |
You have the right to limit how your personal data is processed in certain situations. |
Right to request transfer of personal data or data portability |
You have the right to obtain your personal data in an organized, machine-readable manner, or request to transfer it to a third party. |
Right to raise objections to data processing |
You have the right to raise an objection to the processing of your personal data. |
Right to revoke consent |
You have the right to revoke your consent at any point The legitimacy of processing done using your consent prior to its revocation will remain unaffected by the withdrawal of your consent. |
Right to file a complaint |
You have a right to file a complaint with the Emirates Data Office or the relevant supervisory authority in your country if you believe that we have not complied with the applicable data protection laws. |
It is important to note that the rights stated above are not absolute and that not every request can be fully granted. In certain cases, for instance where we are required to retain your personal data by contracts or the law, we might not be able to delete it or limit its processing.
With whom do we share your personal data?
We may share your personal data with:
- Our service providers, business partners, and affiliates
- Authorized third parties
- Other third parties required by law.
We regulate how and with whom we share your personal data. We may disclose your information for purposes such as payment processing, order fulfilment, product installation, customer service, marketing, financing, servicing or repair, and other similar operations.
Category of Recipient |
Purpose for Sharing |
Affiliates and subsidiaries |
To facilitate, operate, improve, or fulfil our services |
Service providers and business partners |
To facilitate, operate, improve, and fulfil our services to you on our behalf we may want to outsource certain functions. |
Financial institutions |
To verify your eligibility and process your service request based on your consent or our contract with you, |
Law enforcement and government authorities |
To ensure compliance with the relevant laws based on our legal obligations |
How do we secure your personal data?
We have adopted appropriate technological and operational security measures to protect your personal data against loss, abuse, alteration, or destruction. Only authorized people have access to personal data, and these individuals are contractually bound to keep it confidential. We require our suppliers and vendors to implement appropriate safeguards when they access or use personal data that we share with them.
Automated Decision Making/Profiling
Our artificial intelligence technologies may enable automated data processing in several fields. This is called “profiling”. If we make use of profiling, we will always obtain your consent. We will also conduct privacy impact assessments to implement appropriate measures to protect your rights.
When we make use of profiling, you have the right to object against it. This right can be invoked by using the contact details provided in the “Contact Us” section below.
Collection of personal data from children
Our services are intended for adults, and not directed to children. We do not intentionally gather or request personal data from children. If we collect personal data from children, we will obtain verified parental consent.
International data transfers
When processing your personal data, we might share it with third parties in other countries to the extent required to achieve the purposes stated in this Notice. Galadari Hotels (Lanka) PLC is part of Galadari Brothers Co. LLC. Your personal data may be shared within this group of companies, as well as with Galadari Brothers Co. LLC’s subsidiaries located in countries outside of the UAE. Such transfers shall be continually done in accordance with applicable data protection laws.
We transfer personal data from the United Kingdom and the European Economic Area (“EEA”) to organizations outside the EEA in accordance with the EU Standard Data Protection Clauses. For more information regarding transfers, please contact us at dpo@galadaribrothers.com.
Privacy Center
Our Privacy Center enables you to customize your consent preferences. By clicking on Privacy Center, you can manage the consent given to us.
Contact Us
If you have any questions or concerns about this Notice, please contact us at dpo@galadaribrothers.com.
Updates to the Notice
This Notice may be updated on a regular basis to reflect new developments. We reserve the right to update, add, or remove portions of this Notice at any time. You are also advised to revisit this Notice periodically for updates.
The most recent update to this Notice will be indicated below.
Date of Publication – 1st April 2024