Contact Information: Name, physical residential address, email address, phone number.
Booking Information: Arrival and departure dates, room preferences, payment information.
Identification: Government-issued identification information, including passport, national identity card, or driver's licence details, as applicable. Guests are required to provide valid identification during check-in. We may collect information contained in the identification document, including document type, document number, nationality, date of birth, and other information necessary to verify the guest's identity and comply with applicable legal requirements.
Identity Verification Photograph: As part of our check-in and identity verification process, guests are required to provide a photograph of their face. The verification photograph is used to confirm the identity of the person checking in, reduce the risk of identity fraud or the use of stolen personal information, protect our property, and assist us in identifying the responsible guest in the event of damage, non-payment, fraud, or other misuse of our accommodation services.
Special Requests: Dietary restrictions, accessibility requirements, or other preferences.
Usage Data: Information about your interactions with our website, including IP address, browser type, pages viewed, and the duration of your visit.
Cookies: We use cookies and similar technologies to enhance your browsing experience and analyze website traffic. You can manage your cookie preferences through your browser settings.
Processing Reservations: To facilitate your bookings and manage your stay.
Guest Services: To provide personalized services and respond to your requests and inquiries.
Payment Processing: To process payments and prevent fraudulent transactions.
Guest Registration and Identity Verification: To comply with legal requirements applicable to accommodation providers, verify the identity of guests, maintain required guest registration information, and prevent persons from checking in using false, stolen, or unauthorised identity information.
Property Protection and Damage Claims: To protect LUX Hotel, our apartments and other property against damage, theft, fraud, misuse, and non-payment, and where necessary to identify the responsible guest, document an incident, issue or pursue a payment claim, recover losses, or establish, exercise, or defend legal claims.
Marketing Communications: With your consent, to send promotional offers, newsletters, and updates.
Legal Obligations: To comply with applicable laws and regulations.
compliance with legal obligations under Article 6(1)(c) of the GDPR, including mandatory guest registration and identity verification requirements;
performance of a contract under Article 6(1)(b) of the GDPR where processing is necessary to manage your reservation, stay, payments, and related services;
our legitimate interests under Article 6(1)(f) of the GDPR, including preventing identity fraud, preventing misuse of our accommodation services, protecting our property, investigating damage or non-payment, establishing the identity of responsible persons, recovering amounts owed to us, and establishing, exercising, or defending legal claims;
your consent where consent is required, including for certain marketing communications.
Service Providers: We may engage trusted third-party service providers to assist us in delivering our services, such as payment processors, property management and identity verification service providers, including Mews, IT support, and marketing agencies. Such providers process personal information only for authorised purposes and subject to applicable contractual and data protection requirements.
Legal Compliance: We may disclose your information to comply with legal obligations, protect our rights, or respond to lawful requests from authorities.
Prevention of Fraud and Legal Claims: Where necessary and legally permitted, relevant personal information may be disclosed to law enforcement authorities, courts, legal advisers, debt collection providers, insurers, payment providers, or other appropriate parties for the prevention or investigation of fraud, recovery of unpaid amounts or damages, or establishment, exercise, or defence of legal claims.
Business Transfers: In the event of a merger, acquisition, or sale of our assets, your information may be transferred to the acquiring entity.
Consent: Where processing or sharing is based on your consent, we will obtain the required consent before such processing or sharing takes place. Certain disclosures do not require consent where another lawful basis applies, for example where disclosure is necessary to comply with the law or pursue a legitimate interest permitted under applicable data protection legislation.
request access to personal information we hold about you;
request correction of inaccurate or incomplete personal information;
request deletion of personal information where there is no lawful basis for its continued retention;
request restriction of processing in certain circumstances;
object to processing based on our legitimate interests;
request data portability where applicable;
withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal;
lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).