Types of Personal Data We Collect
Information you provide to us: we collect personal data (including where applicable sensitive personal data) you provide directly to us. This includes:
- your full name, gender, date of birth and contact information (e.g. country of residence, physical address, email address and phone number), passport and visa information;
- guest stay information, including the hotels where you have stayed, date of arrival and departure, goods and services purchased, special requests made, your service preferences, telephone numbers dialled and email, faxes, telephone and other messages received;
- your credit card, mobile payment and other payment details;
- your membership information, account details, profile or password details and any frequent flyer or travel partner programme affiliation;
- any information necessary to fulfill special requests (for example, leisure, travel and guest preferences);
- your reviews, feedback, opinions and interactions you have with us about our hotels, resorts, and services;
- information collected through the use of closed circuit television (“CCTV”) systems and other security systems; and
- any other personal data you choose to provide to us (e.g. health data, social media information).
Information We Collect Automatically When You Use the Site: when you access or use the Site, we automatically collect personal data about you, including:
- Log Information: we may collect system log information about your use of the Site, including the type of browser you use, access times, pages viewed, your IP address and the page you visited before navigating to our Site.
- Device Information: we may collect information about the computer or mobile device you use to access our Site, including the hardware model, operating system and version, unique device identifiers (such as, IP address, IMEI number, the address of the device’s wireless network interface, or mobile phone number used by the device) and mobile network information.
- Location Information: we may collect information about the location of your device each time you access or use one of our mobile applications or otherwise consent to the collection of this information. You can turn off location services for a device at any time, but this may turn off some useful features.
- Information Collected by Cookies and Other Tracking Technologies: we and our service providers use various technologies to collect information, including cookies and web beacons. Cookies are small data files stored on your hard drive or in device memory that help us improve our Site and your experience, see which areas and features of our Site are popular and count visits. Web beacons are electronic images that may be used in our services or emails and help deliver cookies, count visits and understand usage and campaign effectiveness.
How We Collect, Use and Disclose Your Personal Data
Subject to the requirements of applicable law, we may collect, use and disclose your personal data for the purposes set out below. For the performance of our agreement with you, in order to:
- process, confirm, provide and charge for hotel arrangements, restaurant and spa reservations and our goods and services, and administer mobile (where applicable) and in person check in and check out;
- fulfill contractual obligations to you, anyone involved in the process of making your travel arrangements (e.g. travel agents, group travel organisers and your employer) and vendors (e.g. credit card companies, airline operators and other loyalty programmes);
- provide you with access to the content on our Site, and respond to your enquiries and requests for information and services; and
- administer, and disclose the winner of, contests and lucky draw competitions conducted by us or on our behalf.
For our legitimate commercial interests, in order to:
- understand how our products and services impact you, provide you with a better, more personalised level of service, and further develop our products and services, including linking or combining with information we get from others to do so;
- provide privileges, benefits and services to you, process applications for and administer membership programmes, verify and validate your ability to access and use certain products, services, facilities and information;
- monitor your use of our Site and your bookings, and conduct analysis of the use of our Site in order to operate, evaluate and improve our Site and our services, understand your preferences, display customised content to you on our Site which may be of interest to you and troubleshoot any problems;
- conduct market analysis, market research, customer satisfaction and quality assurance surveys to improve our hotels, resorts, membership programme and services; and
- manage and provide for the safety and security of guests, premises and services (including but not limited to handling any incidents, accidents or claims made by guests or customers, conducting investigations and/or audits, carrying out CCTV surveillance and conducting security clearances).
For compliance with legal obligations to which we are subject, in order to:
- meet legal and regulatory requirements and administer general record keeping;
- prevent, detect and investigate crime and analyse and manage commercial risks; and
- conduct investigations.
Use of information based on your consent:
- to facilitate direct marketing, promotional and customer management purposes, including sending you promotional communications (including without limitation emails, SMS / MMS and push notifications) or special offers if you have consented to receive the same. Please see section “Direct Marketing” below;
- to use special categories of data (e.g. health data, biometric data, disability data, sensitive data from official identification documents if any, sexual behavior, religion, race, cult, and philosophical belief) only if we have received your explicit consent thereto for such activities separately; and
- for any other purposes for which we have obtained your consent, in accordance with the requirements of applicable law.
In addition, we collect, use, and disclose your personal data for the following purposes depending on the nature of our relationship:
- If you are a guest at our hotel(s), or a guest to events organised at our hotel(s):
- providing customer service and support;
- creating and maintaining guest profiles in our system database;
- administering debt recovery and debt management; and/or
- any other purposes relating to any of the above;
- If you are a customer or guest at our spa, health club, restaurants or bars;
- indemnifying our hotel(s) from liability related to your use of the spa or health club or consumption of restaurant or bar food and drinks outside the restaurant or bar;
- preventing or suppressing a danger to your life, body or health, where you are incapable of giving consent by whatever reason; and/or
- any other purposes relating to any of the above.
- If you are an employee, officer or owner of an external service provider or vendor outsourced or prospected by Avangio Hotel:
- managing project tenders and quotations, processing orders or managing the supply of goods and services;
- processing payment of vendor invoices and bills;
- maintaining internal communications; and/or
- any other purposes relating to any of the above.
- If you are a guest at our hotel(s), or a guest to events organised at our hotel(s):
In order to register with our mobile application(s), make an online hotel reservation, enrol with the Avangio Hotel programmes or if you make an enquiry, you must provide us with the personal data marked with an asterisk or otherwise indicated as mandatory, otherwise we may not be able to process your request or comply with our legal obligations.
In addition to the above, except in limited instances where your consent is required, we may also collect, use, and disclose your personal data on the legal basis of (i) vital interest for the prevention or suppression of danger to a person’s life, body, or health; (ii) public interest for the performance of task carried out in the public interest or for exercising of official authorities or duties; and/or (iii) the necessity for an establishment and defenses of legal claims.
Disclosures of Your Personal Data
Subject to the provisions of any applicable law, we may share your personal data to the following entities and parties, for the purposes listed above (where applicable):
- between and among Avangio Hotel and a limited number of our affiliates as are relevant for the above purposes and to facilitate the operation of our business, but we shall only do so on a need to know basis;
- with the operator of the hotel or the hub of hotels which you book, stay or visit for the above purposes;
- with third-party payment processors, payment service providers, external banks, credit card companies, IT and marketing support service providers, insurance companies and other consultants, vendors and service providers who need access to such information to carry out work or provide services on our behalf or who help us provide the Site to you;
- vendors or third party service providers in connection with marketing promotions and services offered by Avangio Hotel (please also see the section below on “Direct Marketing”);
- with anyone involved in the process of making your travel arrangements (e.g. travel agents, group travel organisers, your employer, our partners, foreign embassies) in order to fulfill contractual obligations;
- with any law enforcement, courts, Government or regulatory bodies (in whatever jurisdiction), or otherwise in response to a request for information if we believe disclosure is in accordance with, or required by, any applicable law, regulation, court order or legal process;
- if we believe your actions are inconsistent with our user agreements or policies, or to protect the rights, property and safety of Avangio Hotel, our affiliates or others;
- any business partner, investor, assignee, or transferee (actual or prospective) in connection with, or during negotiations of, or to facilitate any business asset transactions (which may extend to any merger, sale of company assets, financing or acquisition of all or a portion of our business by another company, or any change of management of a hotel);
- with our advisors, which includes our accountants, auditors, lawyers, other professional advisors and business contacts for the purpose of assisting us to better manage, support or develop our business and comply with our legal and regulatory obligations;
- with any other party at your consent or at your direction or whom you authorise us to disclose your personal data to; and
- otherwise as permitted or required by applicable laws and regulations.
We may also disclose aggregate or de-identified data that is not personally identifiable with third parties, including our commercial and strategic partners.
Overseas Transfers of Your Personal Data
Your personal data will be transferred to, and stored at, locations in Malaysia in which you make reservations, stay or visit. It will also be accessed and processed by our personnel and the personnel of our partners, affiliates and third party service providers, who operate outside of Malaysia in which you make reservations, stay or visit. Your personal data will only be transferred to locations outside of Malaysia in which you make reservations, stay or visit where we are satisfied that adequate or comparable levels of protection are in place to protect personal data held in that jurisdiction or that appropriate safeguards are put in place (including standard data protection clauses for transfer from the EU to outside the EU and for access or transfers outside of Mainland China), or other derogations as allowed by laws and (where we are required to do so) with your consent.
From time to time, we would like to use your name, email address, mobile phone number, and other relevant contact information to send you either via emails, SMS / MMS messages, telephone calls, push notifications, post, or social media (e.g. WeChat and Facebook) information that we think may be of interest to you, including about our hotels, products and services, satisfaction surveys, events, offers and promotions, but we can only do so with your consent.
We would also like to share (for gain) such data with the operator of the hotel or hub of hotels in which you stay or visit and with selected third party entities, so that they may send you information, news updates, special events, offers and promotions as regards their products and services, including travel, transportation, retail, food and beverage, hotel accommodation, credit cards, financial and investment services, real estate, entertainment, publications, fashion and jewellery, leisure and sports, health and wellness, non-profit and charitable activities, telecommunications, social networking, media and public relations, but we will not share your personal data with such third parties or use your personal data for direct marketing without your consent.
You may, in accordance with applicable law, choose not to receive marketing communications or opt-out from receiving marketing communications at any time, free of charge, by following the unsubscribe instructions contained in the marketing communications or contacting Avangio Hotel in accordance with the section “Your Rights and Contact Us” below. If you opt out of these communications, we may still send you non-promotional communications, such as those about your reservation, unless we are prohibited from doing so by applicable laws.
Retention of Personal Data
Our Commitment to Data Security
We have in place reasonable technical and organisational measures to prevent unauthorised or accidental access, processing, erasure, loss or use of your personal data and to keep your personal data confidential. These measures are subject to ongoing review and monitoring. To protect your personal data, we also require our third party service providers to take reasonable precautions to keep your personal data confidential and to prevent unauthorised or accidental access, processing, erasure, loss or use of personal data, and to act at all times in compliance with applicable data protection laws.
We cannot guarantee that our Site will function faultless and without any interruptions. We shall not be liable for damages that may result from the use of electronic means of communication, including, but not limited to, damages resulting from the failure or delay in delivery of electronic communications, interception or manipulation of electronic communications by third parties or by computer programs used for electronic communications and transmission of viruses.
We recommend that where applicable, you change your passwords often, use a combination of letters and numbers, and ensure that you use a secure browser. If applicable, you undertake to keep your username and password secure and confidential and shall not disclose or permit it to be disclosed to any unauthorised person, and to inform us as soon as reasonably practicable if you know or suspect that someone else knows your username and password or believe the confidentiality of your username and password has been lost, stolen or compromised in any way or that actual or possible unauthorised transactions have taken place. We are not liable for any damages resulting from any security breaches, on unauthorised and/or fraudulent use of your username and password.
Children,Minors, Quasi-Incompetent Persons, and Incompetent Persons
Except where required by local laws, we do not knowingly collect personal data from minors, quasi-incompetent persons, and incompetent persons. If you are a minor, quasi-incompetent persons, and incompetent persons, you may only use our Site and services with the permission of your parent, or guardian, or curator.
If you are in the EU, our online services are not directed at children under the age of 13. If you believe we have collected information about a child under the age of 13, please contact us so that we may take appropriate steps to delete such information. If you are at least 13 but under the age of 16, please get the consent of your parent or legal guardian before giving us any personal data about yourself.
If you are in the People’s Republic of China, our online services are not directed at children under the age of 14. If you are under the age of 14, please get the consent of your parent or legal guardian before giving us any personal data about yourself.
If you are in Thailand, our online services are not directed at children under the age of 20. If you believe we have collected information about a child under the age of 20, please contact us so that we may take appropriate steps to delete such information. If you are under the age of 20 and other legal exceptions cannot be relied on, please get the consent of your parent or legal guardian before giving us any personal data about yourself.
Third Party Sites
Your Rights and Contact Us
Subject to applicable law, you may be entitled to access, make/ raise objection to processing, rectify, erase (including deletion of your membership account), limit the use or transfer the personal data we hold of you, exercise the right to data portability, or lodge a complaint to a competent authority. Whenever reasonably possible and required, we will strive to grant these rights within one (1) month or within a reasonable time or as required by applicable local data protection law (e.g. within 15 working days in the People’s Republic of China). You may also withdraw your consent to receiving direct marketing communications, or more generally to our processing of your personal data if based on your consent, at any time. You may also be entitled to appeal and object to important decisions which were made based solely on automated decision-making. You may in certain circumstances ask us to cancel your membership account or delete your personal data, in which case, to the extent permissible by applicable law, we will take reasonable steps to delete or de-identify your personal data. Please note that we may not be able to continue providing services to you if you entirely withdraw your consent or ask us to delete your personal data entirely, and this may also result in the termination of any agreements with Avangio Hotel.