Thulhagiri Island Resort & Spa (“Thulhagiri”, “we”, “us”, “our”) respects your privacy, and is committed to protecting the privacy, confidentiality and security of the personal data you provide to us or that we collect about you when you use our website www.thulhagiri.com.mv or our mobile application and other online products and services (“Site”), when you contact guest services, or when you otherwise interact with us. We are aware of our responsibilities to protect your personal data, to keep it secure and comply with applicable privacy and data protection laws.
Thulhagiri Island Resort & Spa (a data protection officer (Email) firstname.lastname@example.org (Address) Thulhagiri Island, North Male’ Atoll, 20307, is responsible for using your personal data.
Types of Personal Data We Collect
Information you provide to us: we collect personal data (including where applicable sensitive personal data) you provide directly to us. This includes:
- your full name and contact information, passport and visa information;
- guest stay information, including the hotels where you have stayed, date of arrival and departure, goods and services purchased, special requests made, your service preferences, telephone numbers dialled and email, faxes, telephone and other messages received;
- your credit card, mobile payment and other payment details;
- your membership information, account details, profile or password details and any frequent flyer or travel partner programme affiliation;
- any information necessary to fulfill special requests (for example, leisure, travel and guest preferences);
your reviews, feedback and opinions about our hotels, resorts, programmes and services;
- information collected through the use of closed circuit television systems and other security systems;
- and any other personal data you choose to provide to us.
Information We Collect Automatically When You Use the Site: when you access or use the Site, we automatically collect personal data about you, including:
- Log Information: we may collect system log information about your use of the Site, including the type of browser you use, access times, pages viewed, your IP address and the page you visited before navigating to our Site.
- Device Information: we may collect information about the computer or mobile device you use to access our Site, including the hardware model, operating system and version, unique device identifiers (such as, IP address, IMEI number, the address of the device’s wireless network interface, or mobile phone number used by the device) and mobile network information.
- Location Information: we may collect information about the location of your device each time you access or use one of our mobile applications or otherwise consent to the collection of this information. You can turn off location services for a device at any time, but this may turn off some useful features.
- Information Collected by Cookies and Other Tracking Technologies: we and our service providers use various technologies to collect information, including cookies and web beacons. Cookies are small data files stored on your hard drive or in device memory that help us improve our Site and your experience, see which areas and features of our Site are popular and count visits. Web beacons are electronic images that may be used in our services or emails and help deliver cookies, count visits and understand usage and campaign effectiveness.
Information We Collect From Other Sources: we may also obtain personal data from our hotels and from our third party service providers (such as information relating to the credit of guests) and from public sources and combine that with information we collect through our Site where we believe that it is necessary to help manage our relationship with you.
How We Use Your Personal Data
We may use your personal data for the purposes set out below. For the performance of our agreement with you, in order to:
- process, confirm, provide and charge for hotel arrangements and restaurant reservations and our goods and services, and administer mobile (where applicable) and in person check in and check out;
- fulfill contractual obligations to you, anyone involved in the process of making your travel arrangements (e.g. travel agents, group travel organisers and your employer) and vendors (e.g. credit card companies, airline operators and other loyalty programmes);
- provide you with access to the content on our Site, and respond to your enquiries and requests for information and services;
- and administer, and disclose the winner of, contests and lucky draw competitions conducted by us or on our behalf.
For our legitimate commercial interests, in order to:
- understand how our products and services impact you, provide you with a better, more personalised level of service, and further develop our products and services, including linking or combining with information we get from others to do so;
- provide privileges, benefits and services to you, process applications for and administer membership programmes, verify and validate your ability to access and use certain products, services and information (such as Golden Circle and The Table member-only information), and administer Golden Circle and The Table membership, including as regards points and rewards redemption;
- monitor your use of our Site and your bookings, and conduct analysis of the use of our Site in order to operate, evaluate and improve our Site and our services, understand your preferences, display customised content to you on our Site which may be of interest to you and troubleshoot any problems;
- conduct market analysis, market research, customer satisfaction and quality assurance surveys to improve our hotels, resorts and services; and provide for the safety and security of guests.
To comply with legal obligations to which we are subject:
- meet legal and regulatory requirements and administer general record keeping. Use of information based on your consent:
- facilitate direct marketing, promotional and customer management purposes, including sending you promotional communications (including without limitation emails and push notifications) or special offers if you have consented to receive the same. Please see section “Direct Marketing” below;
- we may use special categories of data (e.g. health data). But we will only do so if we have received your consent thereto; and for any other purposes for which we have your consent.
- In order to register with our mobile application, make an online hotel reservation, enrol with the Golden Circle or The Table programmes or if you make an enquiry, you must provide us with the personal data marked with an asterisk or otherwise indicated as mandatory, otherwise we may not be able to process your request or comply with our legal obligations.
Disclosures of Your Personal Data
We may share your personal data:
- between and among Thulhagiri and a limited number of our affiliates as are relevant for the above purposes and to facilitate the operation of our business, but we shall only do so on a need to know basis;
- with the operator of the hotel or the hub of hotels which you book, stay or visit for the above purposes;
with third-party payment processors, payment service providers, IT and marketing support service providers and other consultants, vendors and service providers who need access to such information to carry out work or provide services on our behalf or who help us to provide the Site to you;
- with anyone involved in the process of making your travel arrangements (e.g. travel agents, group travel organisers and your employer) in order to fulfill contractual obligations;
- with any law enforcement, courts, Government or regulatory bodies (in whatever jurisdiction), or otherwise in response to a request for information if we believe disclosure is in accordance with, or required by, any applicable law, regulation, court order or legal process;
- if we believe your actions are inconsistent with our user agreements or policies, or to protect the rights, property and safety of Thulhagiri, our affiliates or others;
- in connection with, or during negotiations of, any merger, sale of company assets, financing or acquisition of all or a portion of our business by another company, or any change of management of a hotel;
- with our advisors, which includes our accountants, auditors, lawyers, other professional advisors and business contacts for the purpose of assisting us to better manage, support or develop our business and comply with ourlegal and regulatory obligations;
- with any other party at your consent or at your direction; and otherwise as permitted or required by applicable laws and regulations.
We may also disclose aggregate or de-identified data that is not personally identifiable with third parties, including our commercial and strategic partners.
From time to time, we would like to use your name, email address, mobile phone number, and other relevant contact information to send you either via emails, SMS messages, telephone calls, push notifications, post, or social media (e.g. WeChat and Facebook) information that we think may be of interest to you, including about our hotels, products and services, news about our membership programmes (if you become a member of Golden Circle or The Table), satisfaction surveys, events, offers and promotions, but we can only do so with your consent.
We would also like to share (for gain) such data with the operator of the hotel or hub of hotels in which you stay or visit and with selected third party entities, so that they may send you information, news updates, special events, offers and promotions as regards their products and services, including travel, transportation, retail, food and beverage, hotel accommodation, credit cards, financial and investment services, real estate, entertainment, publications, fashion and jewellery, leisure and sports, health and wellness, non-profit and charitable activities, telecommunications, social networking, media and public relations, but we will not use your personal data for direct marketing without your consent.
You may opt-out from receiving marketing communications at any time, free of charge, by following the unsubscribe instructions contained in the marketing communications or contacting Thulhagiri in accordance with the section “Your Rights and Contact Us” below. If you opt out of these communications, we may still send you non-promotional communications, such as those about your reservation or Golden Circle programme members communications, unless we are prohibited from doing so by applicable laws.
Retention of Personal Data
Our Commitment to Data Security
We have in place reasonable technical and organizational measures to prevent unauthorized or accidental access, processing, erasure, loss or use of your personal data and to keep your personal data confidential. These measures are subject to ongoing review and monitoring. To protect your personal data, we also require our third party service providers to take reasonable precautions to keep your personal data confidential and to prevent unauthorized or accidental access, processing, erasure, loss or use of personal data, and to act at all times in compliance with applicable data protection laws.
We cannot guarantee that our Site will function faultless and without any interruptions. We shall not be liable for damages that may result from the use of electronic means of communication, including, but not limited to, damages resulting from the failure or delay in delivery of electronic communications, interception or manipulation of electronic communications by third parties or by computer programs used for electronic communications and transmission of viruses.
Children and Minors
Except where required by local laws, we do not knowingly collect personal data from minors. If you are a minor, you may only use our Site and services with the permission of your parent or guardian.
If you are in the EU, our online services are not directed at children under the age of 13. If you believe we have collected information about a child under the age of 13, please contact us so that we may take appropriate steps to delete such information. If you are at least 13 but under the age of 16, please get the consent of your parent or legal guardian before giving us any personal data about yourself.
Third Party Sites
Your Rights and Contact Us
You are entitled to the following rights: right of access to the personal data we hold about you, right of rectification, right to erasure, right to restrict data processing, right to object against profiling and your personal right to data portability. Whenever reasonably possible and required, we will strive to grant these rights within one (1) month. You may also withdraw your consent to receiving direct marketing communications, or more generally to our processing of your personal data, at any time, and you may in certain circumstances ask us to delete your personal data. However, we may not be able to continue providing services to you if you entirely withdraw your consent or ask us to delete your personal data entirely. To make these requests, or if you have any questions or complaints about how we handle your personal data, or would like us to update the data we maintain about you and your preferences, please contact our data protection officer by email at email@example.com or by post at Thulhagiri Island, North Male’ Atoll, 20307.
Last Updated: September 16, 2018