The Ritz Club and The Ritz Club London.com (“We” or “us”) are committed to safeguarding the privacy of personal and sensitive personal data and are bound to comply with the UK Data Protection Act 1998 and EU General Data Protection Regulation (GDPR), along with similar and applicable laws in other countries around the world. This Privacy Notice forms part of our obligation to be open and fair with all individuals whose personal and sensitive personal data we process, to provide details around how we process such personal data and what we do with it.
We process the personal data of our customers such as names, contact details and email addresses, amongst other things. Processing of this data implies collecting, storing, using, disclosing or disposing of individuals’ personal data.
Existing or prospective customers who use our products and services, or websites, may be provided with further privacy notices which may be contained in a separate supplemental notice. These additional privacy notices shall supplement this Privacy Notice.
This Privacy Notice relates to the processing of personal data by us. Unless otherwise stated, all references to “we” or “our” shall imply all the Ritz Club and its associated companies that process personal or sensitive personal data.
None of the lists, or examples provided in this Privacy Notice, are intended to be exhaustive or fully representative of every individual.
The scope of this Privacy Notice covers customers (existing and prospective) personal data in respect of the following: -
· Collecting Personal Data
· Using Personal Data
· Disclosing Personal Data
· Retaining Personal Data
· Securing Personal Data
· International Data Transfers
· Subject Access Requests
· Updates / Amendments
· Third Party Websites
· Opt-in / Opt-out for marketing
· Our Details
COLLECTING PERSONAL DATA
We may collect and store the following kinds of personal data: -
a) Information about your computer and about your visits to the Ritz Club website, including your IP address, geographical location, browser type and version.
b) Information that you provide to us for the purpose of subscribing to our marketing communications.
c) Information that you provide to us when using any of the products and services, or that is generated during the course of using those solutions and services.
d) Information that you post on our social media platforms.
e) Information contained in, or relating to, any communication that you send to us through our website, email or in writing.
f) Information that you provide as part of us performing money laundering, financial and credit checks, as well as for fraud and crime prevention and detection purposes.
g) Information related to the security and access of our premises, systems and applications.
h) Information to help us comply with our legal and regulatory obligations, including reporting to and being audited by regulators and external auditors.
i) Information to help us comply with court orders and to exercise and defend our legal rights.
j) Any other personal information that may be sent to us and which we use for legitimate business purposes.
Before you disclose to us the personal data of another person, you must obtain that person's consent to both the disclosure and the processing of that personal data in accordance with this Privacy Notice.
USING PERSONAL DATA
We may use your personal information to:
a) Administer, personalise and secure our website.
b) Enable your use of any product or service that we may provide through our website.
c) Supply you with our product and services.
d) Send invoices and payment reminders to you or collect payments from you.
e) Send you marketing communications.
f) Deal with enquiries and complaints.
g) Perform money laundering, financial and credit checks.
h) Ensure appropriate access to premises, systems and applications.
i) Comply with our legal and regulatory obligations.
DISCLOSING PERSONAL DATA
We only disclose your personal data in the ways set out in this Privacy Notice or subject to any agreements in place between us. The following circumstances may apply:
a) Across our different lines of business, as part of a need to know, as part of improving our existing products and services or as part of providing new solutions and services.
b) To third parties who process personal data on our behalf, such as systems providers.
c) To third parties who process personal data on their own behalf but provide us, or you, with a service on behalf of us.
d) To third parties with whom information is shared for money laundering checks, credit risk reduction and other fraud and crime prevention purposes.
e) To any prospective buyer in the event we sell any part of our business, or its assets, or if substantially all of our assets are acquired by a third party.
f) To any regulator, external auditor or applicable body or court where we are required to do so by law or regulation or as part of any investigation.
g) To any central or local government department and other statutory or public bodies, such as the HMRC.
We do not sell, rent or trade any of your personal data.
We will not, without your consent, disclose or supply your personal data to any third party for the purpose of their or any other third party's direct marketing.
RETAINING PERSONAL DATA
Personal data that we process, for any purpose or purposes, shall not be kept for longer than is necessary. The Ritz Club bases its record retention on any legal, regulatory or contractual obligations.
You have the right to request we erase your data, where we do not have any overriding legal, regulatory or contractual obligations for continued retention of such data.
SECURING PERSONAL DATA
Where the Ritz Club acts as the controller of personal data, it will ensure that necessary and adequate safeguards are in place to prevent unauthorised access, loss, misuse or alteration of your personal data.
We store all personal information on secure servers with relevant access and firewall controls.
Any personal data sent to us, either in writing or email, may be insecure in transit and we cannot guarantee its safe and secure delivery.
Your passwords must be kept confidential and not disclosed to a third party. The Ritz Club will not ask you to disclose your password.
INTERNATIONAL DATA TRANSFERS
Personal data that we collect, is stored in the UK and not outside the European Economic Area. Should we need to transfer personal outside of the UK or European Economic Area in the future, such personal data will be covered by binding corporate rules or contractual arrangements to ensure it is processed appropriately and securely.
When data is processed (or will be processed) outside of the UK or European Economic Area, we will notify you.
SUBJECT ACCESS REQUESTS
You may ask us to provide you with any personal data we hold about you as part of a Subject Access Request. The provision of such information will be subject to: -
a) The payment of a £10 fee up to the 24th of May 2018 and no fee from the 25th May 2018 and onwards; and
b) Appropriate evidence of your identity, such as a passport or driving licence.
In certain instances, where legal exemptions exist, we may withhold personal data that you request.
You have the right to rectification and may wish to contact us if the personal data that we hold about you needs to be corrected or updated.
You have the right to object to us processing your data, and the right to request we restrict the processing of your data however our ability to meet your request will be affected by any overarching legal, regulatory or contractual obligations.
You may instruct us at any time not to process your personal data for marketing and communications purposes by means of ‘opting-out’.
We do not perform any auto-profiling of individuals.
UPDATES / AMENDMENTS
In order to remain compliant with any legal and regulatory obligations, or as part of our evolving business practices, we may update this Privacy Notice from time to time by publishing a new version. In certain instances, we may notify you.
THIRD PARTY WEBSITES
We are not responsible for the practices employed by Third Party Websites linked to or from our Website nor the information or content contained therein. Often links to other websites are provided solely as reference points to information on topics that may be useful to the users of our Website. Please remember that when you use a link to go from our Website to a Third-Party Website, our Privacy Notice will no longer apply. Your browsing and interaction on any other Website, including Third Party Websites, which have a link on our Website, are subject to that Website's own Privacy Notice.
OPT IN / OPT OUT FOR MARKETING
You have the right, at any time, to ask us not to process your personal data for marketing purposes.
You can opt-out of receiving email communications simply by clicking the unsubscribe link, which is contained within marketing emails.
Please note it can take up to 7 days for a request to be fulfilled because of pre-planned or ongoing marketing activity.
DATA PROTECTION REGISTRATION
We are registered as a data controller with the UK Information Commissioner's Office and our data protection registration number is Z6392382.
THE RITZ HOTEL CASINO LTD (“The Ritz Club”) is registered in England and Wales under company number 3329884 and THE RITZ CLUB LONDON.COM Limited is registered in England and Wales under company number 9908292
The registered office is at 22 Arlington Street, London SW1A 1RD , United Kingdom.
You can contact us as follows: -
Telephone: +44 (0)207 499 1818
In Writing: Data Protection Officer
The Ritz Club or The Ritz Club London.com
22 Arlington Street
If you feel your rights have not been respected, or do not feel a situation was resolved satisfactorily, you have the right to raise a complaint with the UK Information Commissioner.
You can contact them as follows: -
Telephone: +44 (0)303 123 1113
In Writing: Information Commissioner's Office