This Privacy Statement applies to the processing by Max Brown Hotels of your (our guests‘) personal data. Max Brown Hotels takes your privacy very seriously and treats all your personal data with great care. Max Brown Hotels acts in accordance with the applicable data protection legislation.
When you visit our websites (or subdomains) (the “Website”), make a reservation, contact us, purchase products from us or visit one of our hotels, we collect personal data from and about you. This Privacy Statement describes which personal data is collected and for which purposes this personal data is processed by Max Brown Hotels. It also states which rights you have under applicable data protection law.
Who processes your personal data?
Your personal data may be processed by or on behalf of:
A. all Max Brown Hotels entities operating under Sircle Collection, whether owned or licensed by Max Brown Hotels Operations B.V. and its wholly and partially owned affiliates (each hereinafter referred to as a: Max Brown Hotels; see the full list of our Max Brown Hotels, and the legal entities that operate these hotels here; and/or
– Max Brown Hotel Musem Square Amsterdam
– Max Brown Hotel Canal District Amsterdam
– Max Brown Hotel Midtown Düsseldorf
– Max Brown Hotel Ku’damm Berlin
– Max Brown Hotel 7th District Vienna
B. Sircle Collection B.V., a limited liability company registered under the laws of the Netherlands, having its statutory seat in Amsterdam, the Netherlands and its offices at Nieuwezijds Voorburgwal 271, 1012 RL Amsterdam, the Netherlands. Sircle Collection B.V. is registered with the Dutch Chamber of Commerce under registration number 34369785.
Which personal data do we process, and for what purposes do we process personal data?
Regardless of which hotel you stay in, your personal data will be stored in (i) centralized systems which are under the control of Sircle Collection and accessible for authorized staff of Max Brown Hotels, and (ii) local systems controlled solely by the relevant Max Brown Hotels. We want to get to know you, because that enables us to make your stay more pleasant, so you may one day decide to return to our hotels. We collect, store and process personal data at two different stages: (i) before you decide to stay in one of our hotels and (ii) when you stay or have stayed in one of our hotels.
i. Before you decide to stay in one of our hotels
ii. When you stay or have stayed in one of our hotels
When you make a reservation, you will have to provide us with your name, your (email) address, phone number, the dates you are staying with us and a credit card token or other payment information as applicable. We use this personal data to process the reservation, for billing purposes, and to allow us to communicate with you about your reservation. When you stay in one of our hotels, we will collect personal data about your preferences, use of our services, and location.
Overview of activities under stage (i) and (ii)
We may at each of the stages outlined above use your personal data. For your convenience, we have made an overview of activities that involve the processing of your personal data, and the corresponding legal basis/legal bases that allow/s us to process this data:
|1.||First of all, we store the personal data you provide to us in our systems for administrative purposes.||
|2.||Under several jurisdictions and/or local city regulations we are legally obliged to ask you to provide us with certain information when you arrive at a Max Brown Hotel. This may include information such as: birth date, nationality, place of residence, date of arrival and profession.||
|3.||We will have to verify your identity when you arrive at a Max Brown Hotel. We will use your passport or other identification document. We will not store a copy of your passport, unless to the extent permitted by law.||
|4.||We store information of your use of the systems in the guest room to ensure that they work correctly. This information is used by our 24/7 support team for preventative and reactive support purposes.||
|5.||We store your personal data in our database(s), also after your transaction has been completed and after you have stayed in one of our hotels, in order to comply with data retention obligations and to be able to contact you and welcome you again in the future.||
|6.||Since we operate internationally, it may be necessary to transfer personal data to a Max Brown Hotel or other recipient (such as franchisees, partners and third party service providers) in a country outside of the country where it was originally collected or outside of your country of residence or nationality. For many of our business purposes we use cloud based services. Therefore, for technical and organizational reasons, it may be necessary that your personal data is transferred to servers located in the US, or to servers located in countries outside of the European Economic Area (‚EEA‘).||
When we transfer the data to a country outside of the EEA that does not offer an adequate level of data protection, we will ensure compliance with applicable law by way of:
|7.||We process your booking, howsoever made (directly via our website or via a third party (online) travel agent.||
|8.||We create a general and simple profile of you on the basis of information disclosed by you via public sources on the internet. We will not use any sensitive personal data that we may collect or derive from your stay or from public sources on the internet.||
|9.||We offer and provide services and products you request from us or which we may think you are interested in, via email, telephone or other media. You can subscribe to our newsletter, which contains commercial offers and news of Max Brown Hotels and related third parties. We use the email address you provide to send the newsletter to. If you no longer wish to receive the newsletter, you can use the link provided in every newsletter to unsubscribe.||
|10.||We use credit card data or other payment data for invoicing purposes.||
|11.||If you would like to park in our parking garage we may collect your license plate number in order to provide you access to the parking garage.||
|12.||We collect (meta)data on your use of our Wi-Fi services for security and anti-piracy purposes (such as: IP address, your device’s MAC address, connections made, location, etc.). We do not process the content of traffic.||
|13.||We collect automatically generated information for statistical (research) purposes. This information tells us how well our services are functioning. This information may be provided to third parties, but only if permitted by law or if this information cannot be traced back to you.||
|14.||We track information on your purchases for future use in case you return to a Max Brown Hotel.||
|15.||We track and record your use of our, or our affiliates‘, (online) services, either through cookies or via other means. Cookies enable us and others to monitor your browsing behavior. Please read our Cookie Statement for further information on cookies.||
|16.||We engage in the advertising and marketing of our brand, company, affiliates, services and/or products both online and offline, possibly via third party service providers. For this, we use your contact details, information on your stay at a Max Brown Hotel and information collected through cookies.||
|17.||We endeavor to provide a high level of security of both the information we store as well as our facilities, (IT) systems and premises, by means of encryption, physical security measures, passwords, company procedures and policies and professional IT support. Personal data may be processed in this context by Max Brown Hotels and its vendors.||
|18.||We endeavor to prevent our services and facilities (hotels) from being used for illegal purposes, of any kind. Personal data may be processed in this context by Max Brown Hotels and its vendors, such as through CCTV surveillance.||
|We engage in activities required for compliance with legal obligations, third party claims or requests from public authorities, such as (i) the mandatory storage/containment of certain information because of a criminal investigation, (ii) requests from third parties for access to information (iii) any further instructions from third parties, such as supervisory authorities, that involve data processing.||
Right to revoke consent
If we process personal data on the basis of your consent, you have the legal right to revoke such consent at any time. We will then cease the relevant processing activity going forward.
Right of access to your information
If you want to know what personal data we have collected or process about you, you may request us to provide a copy of your personal data by sending an email to firstname.lastname@example.org. We will ask you to identify yourself. We will not provide you with a copy of your personal data to the extent that the rights and freedoms of others are or may be adversely affected.
Right to rectification and erasure of data, and restriction of processing
If you believe that our processing of your personal data is incorrect, inaccurate, unlawful, excessive, incomplete, no longer relevant, or if you think that your data is stored longer than necessary, you may ask us to change or remove such personal data or restrict such processing activity, by sending an email to email@example.com.
Right to data portability
You have the right to receive your personal data, which you have provided to us, in a structured, commonly used and machine-readable format, in accordance with section 20 of the General Data Protection Regulation.
Right to object
You have the legal right to object, on grounds relating to your particular personal situation, at any time to processing of your personal data which is based on the legal basis of either point (e) or (f) of section 6(1) of the General Data Protection Regulation (i.e. the performance of a task carried out in the public interest; the purposes of our, or a third party’s, legitimate interests) including profiling based on those provisions [see the Schedule under clause 4 of this Privacy Statement]. We will only cease the processing if so required under section 21(1) of the General Data Protection Regulation. Furthermore, you have the right to object at any time to our processing of your personal data for direct marketing purposes by either (i) opting out by using the option we provide in the relevant direct marketing message (e.g. an email newsletter), or (ii) by sending an email to firstname.lastname@example.org. For the sake of clarity: without prejudice to the foregoing we are at all times entitled to send you messages that do not constitute direct marketing.
General information relevant for all requests and queries
You must exercise your rights, as explained in this clause, in accordance with applicable law, in particular section 15, 16, 17, 18, 20 and 21 of the General Data Protection Regulation, if and when it applies. We will solely review your request or query in light of our obligations under applicable mandatory data protection law. Nothing in this Privacy Statement is intended to provide you with rights beyond or in addition to your rights as a data subject under applicable mandatory data protection law.
We will use reasonable endeavors to respond to your request or query within one month. We are entitled to extend this term by another two months if the complexity of the situation so requires. If your request is manifestly unfounded or excessive we may either (i) charge you a fee, or (ii) refuse to process your request. With respect to access requests we may also charge you for extra copies. If we decide not to honor your request or answer your query, we will explain our reasons for doing so in our reply.
Protection and storage of your data
We have used and will continue to use reasonable endeavors to protect your personal data against loss, alteration or any form of unlawful use. Where possible, your personal data will be encrypted and stored on a virtual private server that is secured by means of state of the art protection measures. A strictly limited amount of people have access to your personal data. We will retain your personal data for the period necessary to fulfill the purposes outlined in this Privacy Statement, generally 2 years, unless a longer retention period is required or permitted by law (which is typically the case in the context of our obligations under tax law).
A cookie is a simple small file that is sent with pages from this website (and/or Flash applications] and is saved through your browser onto your computer’s hard drive. The information stored in the cookie can be sent back to our servers during a subsequent visit to our site.
Inspection, correction or removal of details
You have the right to ask to inspect, correct or remove your details. See our contact page about this. In order to prevent misuse we may ask you to provide appropriate identification. If this concerns inspection of personal details linked to a cookie, you should send a copy of the cookie in question.
Only you can delete cookies, as they are stored on your computer. Consult your browsers user manual for this.
Supervisory authority and applicable law
With respect to the processing of your personal data, Max Brown Hotels Operations is the ‚main establishment‘ of the Sircle Collection. This means that the data protection authority of the Netherlands (Autoriteit Persoonsgegevens) shall have jurisdiction with respect to the cross-border processing of your personal data in which Max Brown Hotels Operations is involved. Notwithstanding the foregoing you shall be entitled to lodge a complaint with the competent supervisory authority in the territory of a Max Brown Hotel.
The processing of your personal data by Max Brown Hotels Operations and the relevant Max Brown Hotels Hotel(s) shall be subject to the laws of the Netherlands, including the General Data Protection Regulation, when it applies from 25 May 2018 onwards. The applicability of the laws of the Netherlands and General Data Protection Regulation shall be without prejudice to any provisions that may apply to a particular processing activity under local mandatory data protection law.
In case you have any questions in relation to this Privacy Statement, you may send an email to email@example.com.
We have done our best to make sure that this Privacy Statement explains the way in which we process your personal data, and rights you have in relation thereto. We may change this Privacy Statement from time to time to make sure it is still up to date. To make sure you consult the most recent version of our Privacy Statement, please check the Privacy Statement published on our Website.
Last update: 17 February 2020.