By means of this document, we as your personal data administrator – Madhouse s.r.o., with the registered office in Prague 1, Spalena 102/39, post code 110 00, Reg. No.: 242 03 585, registered in the Commercial Register maintained by the Municipal Court in Prague under the file code C 188348 – provide you the information about the processing of your personal data and your rights relating to the processing in question.
The data processing takes place within the scope of this activity:
- Realization of customers request of accommodation in our facilities
- Answer all legal obligations regarding visitors to an accommodation service provider (Domovni Kniha)
Purpose of the data processing:
To confirm and process your request of accommodation in our premises. Communicating with the customers in relation to their bookings (check-ins, check-outs, cancellations, no-shows, deposits for confirmations, payment of fees, payment of penalties, etc), replying to requests and questions sent to Madhouse s.r.o. by the customer, following up with customers for the purpose of evaluating their quality of stay. It is also a legal obligation to provide certain information to the foreign police for any visitor to an accommodation business (Domovni Kniha).
Description of the data processing purpose:
Your personal information is used to register your booking in our property management system, to email you some information prior to your stay in regards to you stay, to receive payment of a mandatory deposit or full amount if you chose an option that requires those steps, to receive payment of any penalties in case the customer didn’t respect our terms and conditions, to receive payment for all damages that the customer is responsible of during their stay, to follow up with the guest regarding the quality of their stay and to offer them to stay in touch with us through our social media or directly with us for future travel plans.
Your data will also be request upon check-in when you’ll be asked to fill the foreign police form (Domovni Kniha). This form is a legal requirement for all visitors at an accommodation provider.
Permission to process data:
We are entitled to the data processing by the consent to the processing of personal information you have given to us. If you have not given us your consent, we will not process your personal data for this reason and your request of booking was therefore dismissed.
The categories of personal information we process:
Identification data (name, surname, date of birth, nationality, passport number, visa numbers), contact details (email, phone number, permanent address), credit card details.
Data processing and archiving period:
10 years from the granting of the consent.
Categories of processors or recipients to whom we may provide personal information:
Other accommodation service provider if Madhouse s.r.o was a victim of your criminal wrongdoing and there is necessity to inform potential victims.
Your personal data may be provided on request to public authorities, in particular to the courts, the Police of the Czech Republic and other law enforcement agencies to the extent necessary and within the limits of the law.
Personal data source: Directly from you through our third-party partners such a online travel agent (OTA), our website booking engine (Cloudbeds), direct email from you to us or in person. You can find our third-party partners privacy policies and GDPR compliance policies by clicking on the following links:
Transmission of personal data to third countries or to multinational companies:
There will be no sharing of information with third countries or multinational companies. You can find more information regarding this matter in the annex related to article 13 of GDPR law.
Automated decision-making based on personal information:
It does not take place within the scope of this data processing.
CUSTOMERS’S RIGHTS IN REGARDS TO PERSONAL DATA SUBMITTED
At any given times, the customer has the following rights regarding the personal data they submit:
- Right to access the data submitted upon confirming the reservation (Article 15 of GDPR law)
- Right to rectification of the data (Article 16 of GDPR law)
- Right to request erasure of the data (Article 17 of GDPR law)
- Right to restrict the processing of the data (Article 18 of GDPR law)
- Notification obligation regarding rectification or erasure of personal data or restriction of processing (Article 19 of GDPR law)
- Right to data portability (Article 20 of GDPR law)
- Right to Object (Article 21 of GDPR law)
- Right to not be subject to Automated individual decision-making, including profiling (Article 22 of GDPR law)
Refer to “Article 13 paragraph 2 (a-f)” in annex of this document for more information.
Clients can request their right directly to Madhouse s.r.o. via e-mail or in person at the premise.
Address: Spalena 102/39, 110 00, Praha 1 Nove Mesto.
If the customer withdraws the right for further process of their personal data after confirming the request of services from Madhouse s.r.o. and their decisions respect the terms and conditions agreed when confirming the accommodation request, their reservations will be cancelled and information deleted based on the fact that Madhouse s.r.o. no longer has access to the information necessary to perform the service.
When confirming the request of reservation, the customer agrees the processing of personal data by Madhouse s.r.o. in order to perform the service requested by the reservation. At any time, the customer can execute their rights as long as their decision respects Madhouse s.r.o. terms and conditions involving penalties for cancellation or no-shows.
If there is an outstanding balance after agreement on the contract, Madhouse s.r.o. has the right to collect that amount at any time before deleting all data belonging to the customer.
IN CASE OF BREACH OF PERSONAL DATA
In the eventuality of a personal data breach is like to result in a high risk to the rights and freedoms of the customer, the controller will communicate with the person affected by this breach without any undue delay. The customer will be contacted via email by the management of Madhouse s.r.o.
The notification of incident shall contain the following information (Reference to Article 33(3))
- Contact details of the data protection responsible or other contact point where more information can be obtained
- The possible consequences of the breach
- Measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible advert effects
Madhouse s.r.o. is not required to communicate any security incident in the following cases:
- The implemented technical and organisational protection measures were applied to the personal data affected by the breach. More precisely, if the measure implemented render the personal data unintelligible to any person who is not authorised to access it.
- If Subsequent measure were taken; ensuring that the risk to the rights and freedoms of the customers is no longer likely to materialise.
- If multiple people are affected, effort will be concentrated in a public communication, or similar manner, so that all customers are informed equally and at the same time.
Article 13 Paragraph 1 (a-f)
(a) the identity and the contact details of the controller and, where applicable, of the controller’s representative;
Madhouse s.r.o.; Rodrigo Medina Flores, +420 608 566 609, firstname.lastname@example.org
Madhouse s.r.o.; Kraig Andrew Cooper, +420 773 260 410, email@example.com
(b) the contact details of the data protection officer, where applicable;
(c) the purposes of the processing for which the personal data are intended as well as the legal basis for the processing;
The data collected is for legal purposes regarding the registration to foreign police (Domovni Kniha)
Also, in order to confirm a reservation, identification and contact details need to be collected to ensure the reservation, communicate with customer in relation to their reservation, etc.
Financial details such as credit card numbers are collected in order to fulfil payment you agreed on by reserving our services or for our own protection regarding damages inflicted by you to our property.
(d) where the processing is based on point (f) of Article 6(1), the legitimate interests pursued by the controller or by a third party;
The processing is based on legitimate interests pursued by Madhouse s.r.o. (controller).
(e) the recipients or categories of recipients of the personal data, if any;
The recipients of the personal data collected are Madhouse s.r.o. (controller) and the foreign police.
(f) where applicable, the fact that the controller intends to transfer personal data to a third country or international organisation and the existence or absence of an adequacy decision by the Commission, or in the case of transfers referred to in Article 46 or 47, or the second subparagraph of Article 49(1), reference to the appropriate or suitable safeguards and the means by which to obtain a copy of them or where they have been made available.
The controlled has no intention to transfer personal data to any other entity or controller.
The only case where data might be transferred is in the eventuality that controller has been a victim of the subject’s criminal wrongdoing and wants to warn potential victims.
Article 13 Paragraph 2 (a-f)
(a) the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period;
The period for which the personal data is stored for a maximum of 10 years for legal reason; in case of an audit or to use in court to prove the relationship.
(b) the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject or to object to processing as well as the right to data portability;
The owner of the personal data has the right to request access to all data stored to rectify, request the data to be deleted, to restrict the processing or to object to the processing or portability.
In the eventuality, the request imposed by the owner of the data, after being granted access, cannot allow the fulfilment of the contract for services, Madhouse s.r.o. reserves the right to cancel the reservation and delete all trace of personal data from the person in question.
(c) where the processing is based on point (a) of Article 6(1) or point (a) of Article 9(2), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
When confirming the request of reservation, the customer agrees the processing of personal data by Madhouse s.r.o. in order to perform the service requested by the reservation. At any time, the customer can withdraw the right to further process of their data as long as their decisions respect Madhouse s.r.o. terms and conditions involving penalties for cancellation or no-shows.
If the customer withdraws the right for further processing of their personal data after confirming the request of services from Madhouse s.r.o. and respects the terms and conditions agreed on when confirming the request of reservation, their reservations will be cancelled and subsequently deleted based on the fact that Madhouse s.r.o. no longer has access to the information necessary to perform the service.
(d) the right to lodge a complaint with a supervisory authority;
In case of unsatisfactory processing of their data, customers can contact a supervisory authority and place a complaint.
(e) whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether the data subject is obliged to provide the personal data and of the possible consequences of failure to provide such data;
Since the personal data is a requirement necessary to enter in a contract for accommodation service from Madhouse s.r.o., and to comply with the Czech laws regarding foreign police regulation (Domovni Kniha), the failure to provide such information will result in a refusal to confirm the request of booking accommodation at Madhouse s.r.o.
(f) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject. N/A
(a) within a reasonable period after obtaining the personal data, but at the latest within one month, having regard to the specific circumstances in which the personal data are processed;
The data is processed as soon as the reservation confirmation is sent to us by any third party Online Travel Agent (Hostelworld, etc), our website or given to us in person, by email, or by telephone.
(b) if the personal data are to be used for communication with the data subject, at the latest at the time of the first communication to that data subject; or
The data provided by customers will be used for communication with them in relation to their reservation or any request they ask Madhouse s.r.o.
(c) if a disclosure to another recipient is envisaged, at the latest when the personal data are first disclosed.
In case Madhouse s.r.o. is victim of a criminal wrongdoing committed by the customer, their information will be shared with authorities in order to depose a claim and will also be shared with other potential victims.