We respect your privacy and collect as little data as possible. This policy explains what personal data is processed when you visit charming-hotels-madeira.com or contact us, why, and what rights you have. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR), the Norwegian Personal Data Act, which incorporates the GDPR, and the Law of Ukraine “On Personal Data Protection”.
1. Data controller
The controller responsible for processing personal data through this website is:
Karyna Senyshyn46A Honore de Balzac Street
Kyiv, 02000
Ukraine
Email: [email protected]
For all data protection questions and requests, please write to [email protected].
2. Scope of this policy
This policy covers the website charming-hotels-madeira.com and the enquiries you send to the email addresses published on it. When you stay at the resort, additional information on processing for guest registration, payment and legal obligations at the hotel will be provided to you at check-in.
3. What data we process
3.1 Data you send us by email
If you contact us using one of the email links on this website, the booking bar or the contact form, your own email program opens and you send the message yourself. We then receive the data you choose to include, typically:
- your name and email address;
- the content of your message, such as travel dates, number of guests, room type, event details or questions;
- any other information you decide to share, for example a phone number or dietary requirements.
Please do not send us special categories of data, such as health information, unless it is needed for your stay (for example an allergy) and you are happy for us to use it for that purpose.
3.2 Technical server logs
When you visit the website, the hosting provider automatically records technical information in server log files: your IP address, the date and time of the request, the page or file requested, the HTTP status code, the amount of data transferred, the referring page and your browser type and version. This information is needed to deliver the website securely and is not combined with other data sources.
4. What we do not do
- We do not set cookies and do not use localStorage, sessionStorage or similar technologies. See our Cookie Policy.
- We do not use analytics, tracking pixels, advertising networks or social media plug-ins.
- We do not load fonts, scripts, maps or videos from third parties; everything is served from our own domain.
- We do not create profiles and do not make decisions based solely on automated processing, including profiling.
- We do not sell, rent or trade personal data.
5. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Answering booking enquiries and preparing an offer or reservation | Contact details, message content, travel dates | Art. 6(1)(b) GDPR: steps taken at your request before entering into a contract |
| Answering general, dining, event, casino and privacy enquiries | Contact details, message content | Art. 6(1)(b) GDPR where the enquiry relates to a contract; otherwise Art. 6(1)(f) GDPR: our legitimate interest in responding to people who contact us |
| Operating the website securely and defending against attacks | Server log data | Art. 6(1)(f) GDPR: our legitimate interest in the security and stability of the website |
| Keeping records required by law, for example accounting records for confirmed bookings | Booking and invoicing data | Art. 6(1)(c) GDPR: compliance with a legal obligation |
Under the Law of Ukraine “On Personal Data Protection”, the corresponding grounds are the conclusion and performance of a transaction at your request, the legitimate interest of the controller and the fulfilment of obligations established by law.
6. How the contact form and booking bar work
The contact form and the booking bar on this website do not send any data to our server or to any third party. When you press the button, a small script running in your browser checks your entries and builds an email with your details. Your own email program then opens, and the message is only transmitted when you press “send” in that program. Until then, no data leaves your device.
7. Recipients of your data
Your data is only shared where this is necessary for the purposes above:
- Hosting provider, which stores and delivers the website and keeps the server logs;
- Email provider, which receives and stores the emails you send us;
- the resort team responsible for your enquiry (reservations, dining, events or casino);
- other processors, such as IT support, who act only on our instructions under a contract in line with Art. 28 GDPR;
- public authorities, only where we are legally required to disclose data.
8. International transfers
The data controller is based in Ukraine, and the resort is located in Norway, which is part of the European Economic Area (EEA). Personal data may therefore be transferred between the EEA and Ukraine. As there is currently no adequacy decision of the European Commission for Ukraine, we protect such transfers with appropriate safeguards, in particular the Standard Contractual Clauses adopted by the European Commission, together with additional technical and organisational measures where needed. Wherever possible, we choose hosting and email providers that store data within the EEA. You can request a copy of the safeguards used by writing to [email protected].
9. How long we keep data
- Enquiries that do not lead to a booking: up to 24 months after our last contact with you, so that we can refer back to your request, and then deleted.
- Server logs: up to 30 days, unless a specific log entry is needed for longer to investigate a security incident.
- Booking records: for as long as required by applicable accounting, tax and guest registration laws. In Norway, accounting documentation is generally kept for five years.
10. Your rights
Subject to the conditions set out in the law, you have the right to:
- access the personal data we hold about you (Art. 15 GDPR);
- rectification of inaccurate or incomplete data (Art. 16 GDPR);
- erasure of your data (Art. 17 GDPR);
- restriction of processing (Art. 18 GDPR);
- data portability, receiving your data in a structured, commonly used format (Art. 20 GDPR);
- object to processing based on our legitimate interests (Art. 21 GDPR);
- withdraw your consent at any time, where processing is based on consent, without affecting the lawfulness of processing before the withdrawal (Art. 7(3) GDPR).
Article 8 of the Law of Ukraine “On Personal Data Protection” grants you comparable rights, including the right to know the sources of collection and the purpose of processing, to access your data, to object to its processing and to demand its correction or destruction.
11. How to exercise your rights
Send your request to [email protected]. We will reply without undue delay and in any case within one month. In complex cases this period can be extended by two further months, and we will tell you if that happens. If we have reasonable doubts about your identity, we may ask for information to confirm it. Exercising your rights is free of charge.
12. Right to lodge a complaint
If you believe that our processing of your personal data breaches the law, you have the right to complain to a supervisory authority, in particular:
- Datatilsynet, the Norwegian Data Protection Authority;
- the data protection supervisory authority of the EU/EEA country where you live or work, or where the alleged breach took place;
- the Ukrainian Parliament Commissioner for Human Rights, who supervises compliance with personal data protection law in Ukraine.
We would appreciate the chance to address your concern first, so please feel free to contact us beforehand.
13. Security
The website is delivered only over encrypted HTTPS connections and uses a strict Content Security Policy that prevents third-party content from being loaded. Access to enquiry emails is limited to the staff who need it, protected by strong passwords and multi-factor authentication where available. No method of transmission over the internet is completely secure, but we review our measures regularly.
14. Children
The casino and bar content of this website is not aimed at people under 18. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe that a child has sent us personal data, please contact us and we will delete it.
15. Changes to this policy
We may update this policy when our services or the law change. The current version is always available on this page, with the date of the last update shown at the top. If we make significant changes, for example by introducing any new type of processing, we will show a clear notice on the website.
16. Contact
For privacy questions, please contact:
Karyna Senyshyn46A Honore de Balzac Street
Kyiv, 02000
Ukraine
Email: [email protected]