Privacy statement Boutiquehotel STAATS (Haarlem)
Boutiquehotel STAATS respects your privacy. Period. In this statement, we explain which personal data we use, why we do so, and what choices and rights you have. We like to keep it clear — just like our service.
1) Who are we?
Boutiquehotel STAATS B.V.
Address: Ripperdastraat 13a
Phone: +31 (0)23 200 1234
Email: welcome@hotelstaats.nl
Chamber of Commerce: 59439874
2) What personal data do we process?
That depends on what you do on our site and during your stay. We may process, for example:
When making a reservation/staying
- Name, address details (if needed), phone number, email
- Reservation details (dates, room type, preferences)
- Payment details (note: we do not store full card details; this is handled via our payment partner)
- Special requests you provide (e.g., allergies — only if you share them)
If you contact us
- Data you fill in or email (name, email, phone, content of your message)
Newsletter/offers (if you sign up or have stayed with us)
- Email address, possibly name and preferences
Website usage
- IP address and technical data (e.g., via cookies/analytics), depending on your cookie choice
3) Why do we process that data? (purposes + legal bases)
We process personal data only if there is a valid reason (“legal basis”) for it.
A. To properly arrange your reservation and stay
Legal basis: performance of a contract (you book with us).
B. To have contact with you (questions, requests, service)
Legal basis: performance of a contract or legitimate interest (good service).
C. For administration and legal obligations
Think of invoicing and retention obligations.
Legal basis: legal obligation.
D. To improve our website (analytics)
Legal basis: consent (via cookie settings) or legitimate interest if it is privacy-friendly and limited — depending on your setup.
E. Marketing (newsletter, campaigns)
Legal basis: consent (newsletter subscription/marketing cookies/stay form and agreement).
4) Do we share data with others?
Sometimes — but only if necessary to help you well or because it is required.
Think of:
- Booking engine Mews
- PMS/hotel software Mews
- Payment provider: Stripe
- Email/newsletter software: Mailchimp
- IT hosting/website management
- Analytics/marketing partners: only if you give permission via cookies
With parties working on our behalf, we make agreements to protect your data.
5) Retention periods
We do not keep your data longer than necessary.
Guidelines (practical and customary):
- Reservation and stay data: as long as necessary for service, administration, and any follow-up questions
- Invoices and financial administration: 7 years (legal retention obligation)
- Newsletter data: until you unsubscribe
- Contact requests: as long as necessary to handle your question
If we cannot specify an exact period, we use clear criteria (such as “until handled” or “legal retention obligation”).
6) Cookies & similar techniques
For cookies, we refer you to our cookie policy and the cookie settings at the bottom of the website. There you choose what you do and do not agree with.
7) Your rights
Under the GDPR, you have rights regarding your personal data. You can contact us with your requests, and we will respond within the legal timeframes.
8) Filing a complaint
If we cannot resolve the issue with you, you can file a complaint with the Data Protection Authority.
9) Security
We take appropriate technical and organizational measures to secure your data. (Not sexy, but essential.)
10) Changes
We may adjust this privacy statement if something changes (e.g., new systems or services). The most recent version is always on our website.