Privacy Policy - Miramar Hotels

PRIVACY POLICY

Protection and Processing of Personal Data

About this Policy

Serafim Silva – Actividades Hoteleiras, S.A. recognises the importance of privacy and the protection of the personal data of its guests, customers, visitors, users of its services, applicants, suppliers, partners and other individuals with whom it interacts.

This Policy clearly explains who is responsible for processing, what data may be collected, the purposes for which they are used, with whom they may be shared, how long they are retained and how data subjects can exercise their rights.

For the purposes of this Policy, the designation “Miramar Group” refers to the services and establishments operated by Serafim Silva – Actividades Hoteleiras, S.A. as identified in this document. Other legally independent companies shall provide their own privacy information when acting as data controllers.

Table of Contents

  • 1. Data controller and scope
  • 2. Data protection principles
  • 3. Personal data processed
  • 4. Source of personal data
  • 5. Purposes and legal grounds
  • 6. Third-party and accompanying persons’ data
  • 7. Data of minors
  • 8. Data communication and access
  • 9. International transfers
  • 10. Retention periods
  • 11. Data subjects’ rights
  • 12. Automated decision-making and profiling
  • 13. Security of personal data
  • 14. Personal data breaches
  • 15. Cookies and similar technologies
  • 16. Changes to the Policy
  • 17. Contacts and complaints

1. Responsável pelo tratamento e âmbito

  • Data controller: Serafim Silva – Actividades Hoteleiras, S.A.
  • Company registration and legal entity number: 502856564
  • Registered office: Rua Abel da Silva – Pederneira, 2450-060 Nazaré, Portugal
  • Telephone: +351 262 590 000 (call to the national landline network)
  • General email: info@hotelmiramar.pt
  • Data Protection Officer: dpo@grupomiramar.pt

This Policy applies to Miramar Hotel Spa & Apartments, Hotel Miramar Sul, the website [[www.miramarnazarehotels.com](http://www.miramarnazarehotels.com)], the booking engine made available through the website, online forms, the newsletter, Clube Miramar, the voucher shop and other services operated by the company identified above.

2. Princípios de proteção de dados

The Miramar Group processes personal data in accordance with the following principles:

  • Lawfulness, fairness and transparency: data is processed based on a valid legal basis and in a manner that is clear and understandable to the data subject;
  • Purpose limitation: data is collected for specific, explicit and legitimate purposes;
  • Data minimisation: only adequate and necessary data is processed;
  • Accuracy: reasonable measures are taken to keep data accurate and up to date;
  • Storage limitation: data is not retained for longer than necessary;
  • Integrity and confidentiality: appropriate technical and organisational measures are implemented;
  • Accountability: relevant decisions and measures are documented and reviewed.

3. Personal Data Processed

Depending on the relationship established and the service used, the following data may be processed:

  • Identification data, such as name, date of birth, nationality, identification document or passport number and signature, where required;
  • Contact details, such as address, email and telephone number;
  • Booking and stay details, such as dates, establishment, room type, number of guests, preferences, special requests, contracted services, amount and booking reference;
  • Companion details, to the extent necessary for the booking, stay or compliance with legal obligations;
  • Billing and tax data, including tax identification number, billing address and payment information;
  • Professional and curriculum data, in recruitment processes or relationships with suppliers and partners;
  • Communications, information requests, complaints, reviews, survey responses and contact history;
  • Technical and usage data, such as IP address, device, browser, access logs, identifiers and cookie preferences;
  • Images collected by video surveillance systems, when installed and properly identified;
  • Information required to use Wi-Fi networks made available to guests;
  • Data included in internal reports, in accordance with the applicable policy and legislation.

Special requests may reveal health data, mobility information, allergies, food intolerances, religious beliefs or other special categories of data. These data will only be processed when necessary to respond to the request and when there is an appropriate legal basis, namely explicit consent, protection of vital interests or another condition provided for by law.

4. Source of Personal Data

Data may be obtained:

  • Directly from the data subject, in person, by telephone, email, forms or during the provision of services;
  • Through the website, booking engine, voucher shop, newsletter or Miramar Club;
  • Through booking platforms, travel agencies, tour operators, corporate clients or other authorised partners;
  • Through the person making a reservation on behalf of accompanying guests;
  • From devices and systems used during browsing, Wi-Fi access or use of the facilities;
  • From public sources or authorities, where there is a legal basis.

5. Finalidades e fundamentos jurídicos

Processing does not always depend on consent. Depending on the purpose, it may be based on the performance of a contract, pre-contractual steps, compliance with legal obligations, consent, the protection of vital interests or legitimate interests that have been duly assessed.

5.1 Reservations and accommodation
Purpose: Managing requests, reservations, changes, cancellations, check-in, stays, associated services and operational communications.
Data processed: Identification details, contact details, dates, occupancy, preferences, amount, payments, billing information, accompanying persons and special requests.
Legal basis: Performance of the contract and pre-contractual steps; compliance with legal obligations; explicit consent when sensitive data is provided without another applicable legal basis.

5.2 Billing, accounting and legal obligations
Purpose: Issuing invoices, maintaining accounting records, complying with tax, tourism, statistical, police or administrative obligations and responding to competent authorities.
Data processed: Identification details, tax identification number, billing address, reservation, stay details, amounts, payments and legally required documentation.
Legal basis: Compliance with legal obligations.

5.3 Payments and fraud prevention
Purpose: Processing payments, pre-authorisations, refunds, reservation guarantees, fraud prevention and transaction security.
Data processed: Identification details, booking reference, amount, payment method and status, and information strictly necessary for the transaction.
Legal basis: Performance of the contract, compliance with legal obligations and legitimate interest in fraud prevention and the protection of systems.

5.4 Customer service, requests and complaints
Purpose: Responding to contacts, information requests, complaints, incidents, support requests and communications related to the services.
Data processed: Identification details, contact details, content of the communication, related reservation or service and any documentation provided.
Legal basis: Pre-contractual steps, performance of the contract, compliance with legal obligations and legitimate interest in managing and improving the service.

5.5 Commercial communications and newsletter
Purpose: Sending news, offers, campaigns and promotional information by email or other authorised channels.
Data processed: Name, contact details, language, country, preferences and consent or objection history.
Legal basis: Consent; or, where legally permitted, legitimate interest regarding similar services, always ensuring a simple and free means of objection.

5.6 Clube Miramar and loyalty programmes
Purpose: Managing membership, benefits, preferences, communications and the use of associated advantages.
Data processed: Identification details, contact details, credentials, preferences, reservations and use of benefits.
Legal basis: Performance of the membership terms and consent for optional communications.

5.7 Reviews, surveys and quality assessment
Purpose: Assessing satisfaction, requesting feedback, analysing quality and improving services.
Data processed: Identification details and contact details, reservation information, responses, comments and reviews.
Legal basis: Legitimate interest in assessing and improving services; consent when required by the channel or purpose.

5.8 Website, cookies and advertising
Purpose: Ensuring the operation and security of the website, measuring usage and, subject to consent, analysing audiences and measuring or personalising campaigns.
Data processed: IP address, device, browser, identifiers, interactions, pages visited and consent preferences.
Legal basis: Legitimate interest and technical necessity for strictly necessary functionalities; consent for analytics, marketing or advertising cookies.

5.9 Recruitment
Purpose: Managing applications, assessing profiles, conducting interviews and selecting candidates.
Data processed: Identification details, contact details, CV, education, professional experience, availability and information provided during the process.
Legal basis: Pre-contractual steps; legitimate interest in managing recruitment; consent when CVs are retained for future opportunities.

5.10 Security, video surveillance and access control
Purpose: Protecting people, facilities, assets and systems, and preventing or investigating incidents.
Data processed: Images, date and time, location, access records, security events and technical information.
Legal basis: Legitimate interest in security; compliance with legal obligations; establishment, exercise or defence of legal claims.

5.11 Wi-Fi networks
Purpose: Providing Internet access, ensuring network security, preventing misuse and diagnosing failures.
Data processed: Technical identifiers, equipment, network addresses, connection date and duration, and security logs.
Legal basis: Provision of the service and legitimate interest in network security and management.

5.12 Suppliers and partners
Purpose: Managing business relationships, contracts, contacts, access, invoicing and regulatory compliance.
Data processed: Professional identification details, position, organisation, contact details, signature, contractual and billing information.
Legal basis: Performance of the contract, compliance with legal obligations and legitimate interest in managing the business relationship.

5.13 Whistleblowing channel
Purpose: Receiving, recording, analysing, investigating and following up on reports and adopting the measures required by law.
Data processed: Identification and contact details when provided, professional relationship, facts, individuals mentioned, documents and communications.
Legal basis: Compliance with legal obligations and, for additional matters, legitimate interest in preventing and detecting irregularities.

6. Third-Party and Accompanying Persons’ Data

Anyone providing data relating to accompanying persons or third parties must ensure that they have the appropriate authority to do so and, where applicable, that those individuals have been informed about the processing of their data. The Miramar Group will limit processing to what is necessary to manage the reservation, provide the services and comply with legal obligations.

7. Data of Minors

Data of minors is processed when necessary for reservations, accommodation, safety, billing or compliance with legal obligations. Such data must be provided by parents, legal representatives or a person authorised to make the reservation. Commercial communications are not directed at minors without an appropriate legal basis.

8. Data Sharing and Access

Data may be accessed or disclosed, strictly to the extent necessary, to:

  • Authorised Miramar Group employees, subject to confidentiality obligations;
  • Technology, hosting, maintenance, cybersecurity, communications, hotel management and customer support providers;
  • Mirai and other suppliers associated with the website and booking engine;
  • Booking platforms, agencies, tour operators and partners involved in the reservation;
  • Payment service providers, banking institutions, insurers and fraud prevention entities;
  • Accountants, auditors, consultants, lawyers and other professional advisers;
  • Marketing, newsletter, analytics, advertising and survey providers, when authorised;
  • Tax, police, judicial, administrative, tourism authorities or other public entities, when legally required.

When a supplier processes data on behalf of the Miramar Group, it acts as a data processor and is subject to documented instructions, confidentiality obligations, security measures and all other obligations established under the applicable legislation.

9. International Transfers

Some technology providers may process data outside the European Economic Area. In such cases, the Miramar Group ensures the existence of an appropriate legal mechanism, such as an adequacy decision by the European Commission, standard contractual clauses, binding corporate rules or another safeguard recognised under the GDPR.

The data subject may request additional information about the applicable safeguards by contacting dpo@grupomiramar.pt.

10. Retention Periods

Data is retained only for the period necessary for the relevant purpose, without prejudice to legal retention periods and any retention required for the establishment, exercise or defence of legal claims.

Processing activity Retention criteria
Reservations and stays During the contractual relationship and thereafter for the applicable statutory limitation and liability periods.
Tax and accounting documentation For the applicable legal period, generally 10 years.
Marketing and newsletter Until consent is withdrawn or an objection is made, keeping only the record necessary to respect that choice.
Requests and complaints For the period necessary to respond and comply with applicable legal deadlines.
Recruitment During the recruitment process; for future opportunities, only for the period communicated and with an appropriate legal basis.
Video surveillance As a general rule, up to 30 days, unless retention is required for legal, administrative proceedings or investigations.
Whistleblowing channel For at least 5 years and, regardless of this period, throughout any pending legal or administrative proceedings.
Cookies According to the duration indicated in the Cookies Policy and preference management panel.
Security and Wi-Fi logs For the proportionate and necessary period required for security, diagnostics, prevention of misuse and compliance with obligations.

11. Data Subject Rights

Under the applicable legislation, data subjects may exercise the following rights:

  • Right of access to personal data and information about its processing;
  • Right to rectification of inaccurate or incomplete data;
  • Right to erasure, where the legal conditions are met;
  • Right to restriction of processing;
  • Right to data portability of the data provided, where applicable;
  • Right to object to processing based on legitimate interest and, at any time, to direct marketing;
  • Right to withdraw consent, without affecting the lawfulness of processing carried out prior to withdrawal;
  • Right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significant effects, except in cases permitted by law.

Requests may be submitted to [dpo@grupomiramar.pt](mailto:dpo@grupomiramar.pt) or by post to the registered office, addressed to the Data Protection Officer. Information necessary to verify identity may be requested. A response will generally be provided within one month, without prejudice to any legally permitted extension depending on the complexity or number of requests.

Rights are not absolute and may be limited where the law requires data retention, where the rights of third parties are involved, or where confidentiality of a report, fraud prevention, security, or the establishment, exercise or defence of legal claims is at stake.

12. Decisões automatizadas e definição de perfis

The Miramar Group does not intend to adopt solely automated decision-making processes that produce legal effects or significantly affect the data subject. Simple segmentation may be carried out to tailor communications or assess campaigns, always in accordance with the applicable legal basis and with the right to object to direct marketing.

13. Security of Personal Data

The Miramar Group adopts technical and organisational measures appropriate to the level of risk, which may include access controls, authentication, event logging, backups, network protection, encryption or pseudonymisation where appropriate, system updates, vulnerability management, confidentiality obligations, training, supplier assessments and incident response procedures.

Despite the measures adopted, no system is completely invulnerable. Data subjects should use official channels, protect their credentials and report any suspicious messages or behaviour.

14. Personal Data Breaches

In the event of a personal data breach, the Miramar Group will record, contain, investigate and assess the risk, adopt mitigation measures and, where legally required, notify the Portuguese Data Protection Authority (Comissão Nacional de Proteção de Dados) and inform the affected data subjects.

15. Cookies and Similar Technologies

The use of cookies is explained in the Cookies Policy. Preferences can be changed at any time through the “Cookie Settings” option available in the website footer.

16. Changes to this Policy

This Policy may be updated to reflect legal, technological or operational changes. The current version will be made available through the official Miramar Group channels, indicating the date of the latest update.

17. Contacts and Complaints

For questions, requests or to exercise your rights:

Data Protection Officer: [dpo@grupomiramar.pt](mailto:dpo@grupomiramar.pt)

Address: Rua Abel da Silva – Pederneira, 2450-060 Nazaré, Portugal

Telephone: +351 262 590 000

The data subject may also lodge a complaint with the Portuguese Data Protection Authority (Comissão Nacional de Proteção de Dados), without prejudice to any other administrative or judicial remedy available.