Purpose/Activity | Lawful basis for processing including basis of legitimate interest | Retention period |
---|---|---|
Meeting our obligations to our customers. | Performance of a contract with you. Necessary to comply with a legal obligation. Necessary for our legitimate interest in running our business and providing you with requested products and services. | 10 years from the booking in accordance with legal obligations. |
Managing the reservation of rooms and accommodation requests, in particular the creation and storage of legal documents in compliance with accounting standards. | ||
Managing your stay at the hotel:
| Performance of a contract with you. Necessary for our legitimate interest in running our business and providing you with requested products and services. | For the duration of your stay. |
Managing our relationship with customers before, during and after your stay:
| Performance of our contract with you and for the management of your membership in the loyalty program. Necessary for our legitimate interests in promoting and improving our services. Processing based on your consent for direct marketing purposes. | 3 years from the last date on which you have interacted with us in any way, if you are not a member of the loyalty programme. 6 years from the last date on which you have interacted with us in any way, if you are a member of the loyalty programme. |
Improving our hotel service by:
| Performance of contract with you in relation to the management of your membership in the loyalty program. Necessary for our legitimate interests in promoting our services, performing direct marketing activities (taking into account your commercial relationship with AccorGroup) and improving our services. | 3 years from the last date on which you have interacted with us in any way, if you are not a member of the loyalty program. 6 years from the last date on which you have interacted with us in any way, if you are a member of the loyalty program. |
Use a trusted third party to cross-check, analyse and combine your collected data at the time of booking or at the time of your stay, in order to determine your interests and develop your customer profile and to allow us to send you personalized offers. | Necessary for our legitimate interests in promoting our services, performing direct marketing activities (taking into account your commercial relationship with one of the AccorGroup’s entities)) and improving our services. | 3 years from the last date on which you have interacted with us in any way, if you are not a member of the loyalty program. 6 years from the last date on which you have interacted with us in any way, if you are a member of the loyalty program. |
Improving Accor SA services, in particular:
| Performance of contract with you (for the management of your membership in the loyalty program) Necessary for our legitimate interests in promoting our services, performing direct marketing activities (taking into account your commercial relationship with one of the AccorGroup’s entities)) and improving our services. | 3 years from the last date on which you have interacted with us in any way, if you are not a member of the loyalty program. 6 years from the last date on which you have interacted with us in any way, if you are a member of the loyalty program. 6 years from the date of closure of your file in case of a claim or a complaint. |
Securing and enhancing your use of Accor SA websites, applications and services by:
| Necessary for our legitimate interests in running our business, provision of administration and IT services and network security to prevent fraud | 13 months from the collection of the information. |
Internal management of lists of customers having behaved inappropriately during their stay at the hotel (aggressive and anti-social behaviour, non-compliance with safety regulations, theft, damage and vandalism or payment incidents). | Necessary for our legitimate interests in running our business and to prevent fraud and the abuse of our property and staff. | Up to 122 days from the recording of an event. |
Securing payments by determining the associated level of fraud risk. As part of this analysis, Accor SA and hotels may use the AccorGroup risk prevention service provider to refine their analysis. Depending on the results of the investigations carried out, AccorGroup may take security measures, in particular AccorGroup may request the use of a different booking channel or for the use of an alternative payment method. These measures will have the effect of suspending the execution of the booking or, if the result of the analysis does not guarantee the safety of the order, of cancelling it. Fraudulent use of a means of payment leading to payment default may result in the entry of data in the AccorGroup incident file, which may lead AccorGroup to block future payments or carry out additional checks. | Necessary for our legitimate interests in running our business and to prevent fraud. | 90 days to our database to allow for analysis and controls and then 2 years in a separated database used for improving the system. In case of recording in the incident file, 2 years from recording or until regularization of the situation if earlier. |
Securing properties and persons and preventing non-payments. For these reasons, some hotels have a feature that allow them to include in the category of "ineffective" customers, any customer whose behaviour has been inappropriate in the following ways: aggression and rudeness, non-compliance with the hotel contract, failure to observe safety rules, theft, damage and vandalism, or payment issues. The status of “ineffective” may cause the hotel where this listing originated to refuse a customer's reservation when he/she returns to the same hotel. | Necessary for our legitimate interests in running our business, securing properties and persons and preventing non-payments. | 122 days from registration. |
Using services to search for persons staying in AccorGroup hotels in the event of serious events affecting the hotel in question (natural disasters, terrorist attacks, etc.). | Protection of the vital interests of the guests. | For the duration of the event. |
Conforming to any applicable legislation (for example, storing of accounting documents), including:
| Necessary to comply with a legal obligation. | As stipulated in the respective country’s legislation. |
Purpose/Activity | Lawful basis for processing |
---|---|
Use a trusted third party to cross-check, analyze and combine your collected data at the time of booking or at the time of your stay, in order to determine your interests and develop your customer profile and to allow us to send you personalized offers. | Consent |
Securing and enhancing your use of Accor SA websites, applications and services by:
| The conclusion or performance of a contract to which you are a contracting party |
Internal management of lists of customers having behaved inappropriately during their stay at the hotel (aggressive and anti-social behavior, non-compliance with safety regulations, theft, damage and vandalism or payment incidents). | The conclusion or performance of a contract to which you are a contracting party |
Securing payments by determining the associated level of fraud risk. As part of this analysis, Accor SA and hotels may use the AccorGroup risk prevention service provider to refine their analysis. Depending on the results of the investigations carried out, AccorGroup may take security measures, in particular AccorGroup may request the use of a different booking channel or for the use of an alternative payment method. These measures will have the effect of suspending the execution of the booking or, if the result of the analysis does not guarantee the safety of the order, of cancelling it. Fraudulent use of a means of payment leading to payment default may result in the entry of data in the AccorGroup incident file, which may lead AccorGroup to block future payments or carry out additional checks. | The conclusion or performance of a contract to which you are a contracting party |
Securing properties and persons and preventing non-payments. For these reasons, some hotels have a feature that allow them to include in the category of "ineffective" customers, any customer whose behavior has been inappropriate in the following ways: aggression and rudeness, non-compliance with the hotel contract, failure to observe safety rules, theft, damage and vandalism, or payment issues. The status of "ineffective" may cause the hotel where this listing originated to refuse a customer's reservation when he/she returns to the same hotel. | The conclusion or performance of a contract to which you are a contracting party |
Using services to search for persons staying in AccorGroup hotels in the event of serious events affecting the hotel in question (natural disasters, terrorist attacks, etc.). | Responding to a public health emergency, or for protecting the life, health or property safety of a natural person in the case of an emergency; |
Name of system permissions | Description | Purposes | Applicable platforms |
android.permission.ACCESS_NETWORK_STATE | View network status | Allows an application to view the status of all networks. | Android |
android.permission.INTERNET | Full internet access | Allows an application to create network sockets. | Android |
android.permission.WAKE_LOCK | Prevent phone from sleeping | Allows an application to prevent the phone from going to sleep. | Android |
android.permission.ACCESS_WIFI_STATE | View Wi-Fi status | Allows an application to view the information about the status of Wi-Fi. | Android |
com.google.android.c2dm.permission.RECEIVE | C2DM permissions | Permission for cloud to device messaging. | Android |
android.permission.RECEIVE_BOOT_COMPLETED | Automatically start at boot | Allows an application to start itself as soon as the System has finished booting. | Android |
android.permission.FOREGROUND_SERVICE | Allows a regular application to use service.startforeground | Allows a regular application to use service.startforeground. | Android |
com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE | Get APP installation information for notification pushing | To get information about the origin of the installation of the APP by the user in order for the push notification system to reach Google servers and push the notification on the right device. | Android |
android.permission.VIBRATE | Control device vibration | Allows the application to control device vibration. | Android |
com.accor.appli.hybrid.inhouse.batch.permission.INTERNAL_BROADCAST | Push notifications | To request user authorization to send him/her push notifications | Android |
android.permission.READ_EXTERNAL_STORAGE | Read external storage contents | Allows an application to read external storage. Necessary to install the application on a device without internal memory. | Android |
android.permission.WRITE_EXTERNAL_STORAGE | Read/modify/delete external storage contents | Allows an application to write to external storage. Necessary to install the application on a device without internal memory. | Android |
android.permission.READ_PHONE_STATE | Read phone state and identity | Allows the application to access the phone features of the device. Feature to call Accor customer Help Center in the app. | Android |
android.permission.BLUETOOTH | Create Bluetooth Connections | Allows applications to connect to paired Bluetooth devices. Necessary to have the Accor Hotel Keyless functionality (keyless door lock). | Android |
android.permission.BLUETOOTH_ADMIN | Bluetooth Administration | Allows applications to discover and pair Bluetooth devices. Necessary to have the Accor Hotel Keyless functionality (keyless door lock). | Android |
android.permission.ACCESS_FINE_LOCATION | Fine (GPS) location | Access fine location sources, such as the GPS on the phone, where available. Necessary for the geolocation hotel search feature (find a hotel around me). | Android |
android.permission.ACCESS_COARSE_LOCATION | Coarse (networkbased) location | Access coarse location sources, such as the mobile network database, to determine an approximate phone location, where available. Necessary to define the language to be displayed in the application. | Android |
NSCalendarsUsageDescription | Calendar | Add booking to calendar | iOS |
NSMicrophoneUsageDescription | Microphone | Voice Search feature | iOS |
NSLocationAlwaysUsageDescription | Location | Find hotels + taxi or chauffeur-driven car | iOS |
NSLocationWhenInUseUsageDescription | Location | Find hotels + taxi or chauffeur-driven car | iOS |
NSSpeechRecognitionUsageDescription | Speech recognition | Voice search feature | iOS |
NSUserTrackingUsageDescription | Tracking (IDFA/ATT) | Tracking. Necessary because of mandatory IDFA / ATT Apple’s rule. Consent is needed prior sending identifier to partners. | iOS |
Push notification | Push | iOS | |
Background app refresh | Allow the application to be refreshed in background. Can be turned off in iOS settings | iOS | |
NSBluetoothAlwaysUsageDescription | Bluetooth | Necessary to have the Accor Hotel Keyless functionality (keyless door lock) | iOS |
Share Profile (Nickname, Gender, region, Country, Image/Avatar) | Avoid to fill the same information in a form in Mini-Program | Weixin Mini-Program | |
Share Mobile number | Automatically fill in the mobile phone number, which is used to send SMS notifications such as room information. | Weixin Mini-Program | |
Share WeChat Chat feature | Activation of chat notification. | Weixin Mini-Program | |
Share WeChat Pay | Payment through WeChat. | Weixin Mini-Program | |
Share Geo fencing | Geo localization, necessary for the geolocation hotel search feature (find a hotel around me). | Weixin Mini-Program |
Number | Name of the SDK | SDK service provider | Purposes of processing personal information | Personal information collected via SDK | SDK service provider's privacy policy |
1 | Firebase | Google, Inc. | User tracking and engagement. | No personal information, only anonymous navigation data. | https://firebase.google.com/support/privacy |
2 | Firebase Crashlytics | Google, Inc. | User crash monitoring. | No personal information, only anonymous data about crash: device, OS version | https://firebase.google.com/support/privacy |
3 | Firebase Remote Config | Google, Inc. | Enable feature without submitting a new app on the store. | No personal information, only anonymous data: app version | https://firebase.google.com/support/privacy |
4 | Firebase Analytics | Google, Inc. | User tracking and engagement. | No personal information, only anonymous navigation data: screen view, click, time on each page | https://firebase.google.com/support/privacy |
5 | GoogleAnalytics | Google, Inc. | User tracking and engagement. | No personal information, only anonymous data | https://developers.google.com/analytics/ devguides/collection/protocol/policy |
6 | GoogleTagManager | Google, Inc. | Managing tracking plan in the app | No personal information, only anonymous data | https://marketingplatform.google.com/ about/analytics/tag-manager/use- policy/#:~:text=If%20You%20have% 203rd%20Party,responsible%20for%203 rd%20Party%20Tags.&text=to%20upload %20any%20data%20to,such%20information %20by%20Google%2C%20or |
7 | Branch | Branch Metrics, Inc. | Deeplink handling. | No personal data | https://branch.io/policies/privacy-policy/ |
8 | Batch | IMEDIAPP SA | User push notification management. | Device installation ID | https://batch.com/privacy-policy |
9 | BatchExtension | IMEDIAPP SA | Custom push notification | Device installation ID | https://batch.com/privacy-policy |
10 | Dynatrace | Dynatrace LLC | Application API call tracking, used for stats and API debugging. | Anonymous data, except PMID (user id). With this PMID we can show: -App version -User actions -User crashs -Device -OS version -IP Adress | https://www.dynatrace.com/company/ trust-center/privacy/ |
11 | One Trust | One Trust, LLC. | User consent management platform. | Cookie consent for one device / no user data | https://www.onetrust.com/privacy-notice/ |
12 | Alamofire | Open Source (https://github.com/Alamofire/Alamofire) | HTTP networking library for iOS | No personal information | NA |
13 | Apollo | MG Code EPE | Android Graph QL API client | No personal information | https://www.apollographql.com/ privacy-policy/ |
14 | Content Square | Content Square, Inc. | Web analytics feature | No personal information, only anonymous data | https://contentsquare.com/privacy-center/privacy-policy/ |
15 | Materiel Design | User Interface Design Tool | No personal information | NA | |
16 | Kingfisher | Open Source (https://github.com/onevcat/Kingfisher/) | Library for downloading and caching images from the web | No personal information | NA |
17 | FSCalendar | Open source (https://github.com/onevcat/Kingfisher/FSCalendar) | Library for downloading and caching images from the web | No personal information | NA |
18 | Threat Matrix | LexisNexis Risk Solutions Inc. | Security analytics. | No personal information | https://risk.lexisnexis.com/group/privacy-policy |
19 | Cardinal Commerce | Visa, Inc. | PSD2 Banking authorisation management. | No personal information | https://usa.visa.com/legal/ privacy-policy.html |
20 | Imperva | Imperva, Inc. | Bot detection / security | No personal information | https://www.imperva.com/trust-center/privacy-statement/ |
21 | Karhoo | Flit Technologies Ltd | Chauffeur driven car booking SDK. | No personal information | https://www.karhoo.com/ privacy-policy/ |
22 | Stay My Way | Stay My Way | Contactless door opening. | PMID / Reservation ID | NA |
23 | Debug Tool Kit | Open Source (https://github.com/dbukowski/DBDebugToolkit) | Access to debugging logs | No personal information, only anonymous data | NA |
24 | Nimble | Open Source (https://github.com/Quick/Nimble ) | express the expected outcomes of Swift or Objective-C expression | No personal information | NA |
25 | Meta, Inc. | User tracking, such as Firebase, for Facebook purposes | PMID (user identifier) | https://www.facebook.com/policy.php | |
26 | Baidu Maps | Baidu, Inc. | Mapping application for China. | No personal information | http://privacy.baidu.com/policy |
27 | Retrofit2 | Open source (https://square.github.io/retrofit/ ) | Android REST API client. | No personal information | NA |