Privacy Policy

Glasgow Grosvenor Hotel Privacy Notice
**Last updated: 14 September 2026**
1. Who we are

This privacy notice explains how personal data is collected and used in connection with Glasgow Grosvenor Hotel,

including when you visit the hotel, make or enquire about a booking, attend an event, use our website at

[www.gghotel.co.uk](https://www.gghotel.co.uk), contact us, or interact with us on social media.

For the purposes of UK data protection law, **Nicolâ€TMs Worsteds Limited** is the controller of your personal

data. Glasgow Grosvenor Hotel is managed by **7 Hospitality Management (UK) Limited**, which may process

personal data on the controllerâ€TMs behalf and, where applicable, for its own lawful purposes.

You can contact us about this notice or the use of your personal data at:

Glasgow Grosvenor Hotel
19 Grosvenor Terrace
Glasgow G12 0TA
United Kingdom

Email: [reservations@gghotel.co.uk](mailto:reservations@gghotel.co.uk)

Telephone: [+44 (0)141 339 8811](tel:+441413398811)
2. The personal data we collect
Depending on how you interact with us, we may collect:

*Identity and contact data*, such as your name, title, postal address, email address, telephone number, signature

and date of birth where relevant;

*Booking and stay data*, such as arrival and departure dates, room and package selections, booking history,

loyalty or corporate-booking details, vehicle registration, and requests or preferences you choose to provide;

*Restaurant, event and function data*, including reservation details, attendee information, event requirements

and correspondence;

*Payment and transaction data*, such as payment status, billing details and limited payment-card information.

Card payments are handled by payment providers and we do not ordinarily retain complete card-security codes;

*Special-category data* that you choose to provide where needed to meet accessibility, dietary, allergy, health or

religious requirements;

*Communications data*, including enquiries, complaints, survey responses, competition entries, reviews and

communications by email, telephone, post or social media;

- **Marketing data*, including your preferences, consent records and engagement with our communications;

- **Website and device data**, such as IP address, device and browser information, cookie identifiers, referring

pages, pages viewed, approximate location and interaction data; and

- **Security data*, which may include CCTV images, access records and incident reports.

Please do not provide another persona’s personal data unless you are authorised to do so and have made this

notice available to them.
3. How we obtain personal data
We collect personal data:

- directly from you, including through our website, booking journey, check-in process, telephone calls, emails,

forms, surveys, competitions and social-media interactions;

- from someone booking or organising a stay, meal or event on your behalf;

- from booking platforms, travel agents, tour operators, corporate travel organisers, event organisers and other

commercial partners;

- from payment, fraud-prevention and identity-verification providers;

- automatically through our website and permitted cookies or similar technologies; and

- from publicly available sources, regulators, law-enforcement bodies or insurers where appropriate.

4. How and why we use personal data

UK data protection law requires us to have a lawful basis for each use of personal data. We use personal data as

follows:
| Purpose | Typical personal data | Lawful basis |

| Handle enquiries and take steps requested before a booking or contract | Identity, contact, booking, event and

communications data | Taking steps before entering into a contract; legitimate interests in responding to

enquiries |

| Make, administer and fulfil room, restaurant, voucher and event bookings; provide requested services; take

payment; and communicate about a booking or stay | Identity, contact, booking, event, payment, transaction and

communications data | Performance of a contract; legitimate interests in operating our services |

| Record and meet accessibility, dietary, allergy, health, religious or similar requirements | Information you

provide about those requirements | Explicit consent where required; vital interests in an emergency; or another

condition permitted by law |

| Manage customer service, complaints, refunds, disputes, insurance matters and legal claims | Identity, contact,

booking, payment, transaction, communications and security data | Performance of a contract; legal obligations;

legitimate interests in protecting our business and resolving disputes |

| Maintain safety and security, prevent and investigate crime or fraud, and protect guests, staff and property |

Identity, transaction, website, device and security data | Legitimate interests; legal obligations; establishment,

exercise or defence of legal claims |

| Maintain business, financial, tax and regulatory records | Identity, contact, booking, payment and transaction

data | Legal obligations; legitimate interests in business administration |

| Improve our website, services and customer experience; measure performance; and produce aggregated

reporting | Booking, communications, marketing, website and device data | Legitimate interests where the

processing is necessary and proportionate; consent where required for cookies or similar technologies |

| Send newsletters, offers and other direct marketing, and measure engagement | Identity, contact, marketing,

website and device data | Consent where required; otherwise our legitimate interests where electronic-

marketing law permits |

| Run promotions, prize draws and competitions and contact winners | Identity, contact, entry and

communications data | Performance of the competition terms; legitimate interests in administering and

promoting the competition. Entry is not treated as consent to unrelated marketing |

| Comply with lawful requests and enforce our terms | Relevant data described above | Legal obligations;

legitimate interests; establishment, exercise or defence of legal claims |

Where we rely on legitimate interests, we consider whether the use is necessary and whether your rights and

interests override ours. You may contact us for more information about this assessment.

If we ask for information that is required by law or needed to enter into or perform a contract, we will explain this

where appropriate. If you do not provide it, we may be unable to process a booking or provide the requested

service.
5. Marketing

We may send you marketing where you have consented or where the law otherwise permits. Marketing consent

is optional and is not a condition of booking with us. We do not treat entry into a competition as consent to

receive unrelated marketing.

You can stop marketing at any time by using the unsubscribe link in an email or contacting us. Withdrawing

consent does not affect processing carried out before withdrawal. We may retain a minimal suppression record so

that we can respect your opt-out.

Service messages about a booking, event, transaction or stay are not marketing, and you may still receive them

when necessary.
6. Cookies and similar technologies

Our website uses cookies and similar technologies. Some are strictly necessary for the site, booking functions,

security or the choices you request. Where consent is required, analytics, advertising and other non-essential

technologies will not be used until you choose to allow them.

You can accept, reject or manage non-essential technologies through **Cookie settings** on our website and can

change your choice at any time. Blocking some technologies may affect website features. Please see the

information presented in the cookie-preference tool for current details of the technologies used, their providers,

purposes and durations.
7. Who we share personal data with

Where necessary for the purposes above, we may share personal data with:

- 7 Hospitality Management (UK) Limited and personnel involved in operating the hotel;

- booking-engine, property-management, customer-management, website-hosting, IT, communications and

support providers;

- payment processors, banks, accountants, auditors and insurers;

- online travel agents, booking platforms, travel agents, tour operators, event organisers and service partners

involved in fulfilling your booking;

- marketing, analytics and advertising providers, subject to your choices and applicable law;

- professional advisers, prospective purchasers, investors or lenders in connection with a corporate transaction,

subject to appropriate confidentiality safeguards; and

- courts, regulators, tax authorities, police, emergency services and other public bodies where disclosure is

required or permitted by law.

Service providers acting on our behalf may use personal data only as instructed and must protect it appropriately.

We do not sell or rent personal data. We do not disclose it to third parties for their own unrelated marketing

without your consent.

Some third parties, such as online travel agents or social-media platforms, determine independently how they use

personal data. Their own privacy notices also apply.
8. International transfers

Some suppliers may process personal data outside the United Kingdom. Where UK law requires it, we use an

approved transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement or

the UK Addendum to the EU standard contractual clauses, together with supplementary safeguards where

appropriate. Contact us if you would like more information about safeguards relevant to your personal data.

9. How long we keep personal data

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected,

including to meet legal, accounting, tax, safety and reporting requirements and to establish, exercise or defend

legal claims.

Retention periods vary according to the type of record and relevant circumstances. In setting them, we consider

the amount, nature and sensitivity of the data; the risk of harm from unauthorised use or disclosure; the

purposes of processing; whether those purposes can be achieved in another way; and applicable legal

requirements. We securely delete or anonymise personal data when it is no longer required. You may contact us

for information about the retention period applicable to a particular category of data.

10. Security

We use appropriate technical and organisational measures designed to protect personal data from accidental or

unlawful destruction, loss, alteration, unauthorised disclosure or access. Access is limited to people and suppliers

who need the data for their work and are subject to appropriate duties of confidentiality. No internet or storage

system is completely secure.
11. Your rights

Subject to applicable law and any relevant exemptions, you may have the right to:

- be informed about how your personal data is used;
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request erasure of personal data;
- request restriction of processing;

- receive certain personal data in a portable format and transmit it to another organisation;

- object to processing based on legitimate interests and object at any time to direct marketing;

- withdraw consent at any time where processing relies on consent; and

- request safeguards in relation to a decision based solely on automated processing that has a legal or similarly

significant effect.

These rights are not absolute. We may need to verify your identity and may request information needed to

respond. We normally respond within one month, although the law permits an extension in some circumstances.

There is usually no fee, but a reasonable fee may be charged or a request refused where the law permits.

To exercise a right, contact us using the details in section 1.

12. Complaints

Please contact us first if you have concerns so that we can try to resolve them.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data-protection

regulator. Current contact details and the complaints process are available at [ico.org.uk/make-a-

complaint](https://ico.org.uk/make-a-complaint/). You may also seek a remedy through the courts.

13. Children

Our website and services are not directed at children acting independently. We may process information about

children where it is supplied by a parent, guardian or booking organiser and is needed to provide hotel or event

services. Please contact us if you believe a child has provided personal data to us without appropriate authority.

14. Third-party websites and social media

Our website may link to websites, booking services and social-media platforms operated by others. We do not

control their privacy practices. Please read their privacy notices before providing personal data.

15. Changes to this notice

We may update this notice to reflect changes in our practices, services or legal obligations. The latest version will

be posted on this page with its revision date. We will use an appropriate method to tell you about material

changes where required.