This privacy notice explains how personal data is collected and used in connection with Glasgow Grosvenor Hotel,
including when you visit the hotel, make or enquire about a booking, attend an event, use our website at
[www.gghotel.co.uk](https://www.gghotel.co.uk), contact us, or interact with us on social media.
For the purposes of UK data protection law, **Nicolâ€TMs Worsteds Limited** is the controller of your personal
data. Glasgow Grosvenor Hotel is managed by **7 Hospitality Management (UK) Limited**, which may process
personal data on the controllerâ€TMs behalf and, where applicable, for its own lawful purposes.
You can contact us about this notice or the use of your personal data at:
Email: [reservations@gghotel.co.uk](mailto:reservations@gghotel.co.uk)
*Identity and contact data*, such as your name, title, postal address, email address, telephone number, signature
*Booking and stay data*, such as arrival and departure dates, room and package selections, booking history,
loyalty or corporate-booking details, vehicle registration, and requests or preferences you choose to provide;
*Restaurant, event and function data*, including reservation details, attendee information, event requirements
*Payment and transaction data*, such as payment status, billing details and limited payment-card information.
Card payments are handled by payment providers and we do not ordinarily retain complete card-security codes;
*Special-category data* that you choose to provide where needed to meet accessibility, dietary, allergy, health or
*Communications data*, including enquiries, complaints, survey responses, competition entries, reviews and
- **Marketing data*, including your preferences, consent records and engagement with our communications;
- **Website and device data**, such as IP address, device and browser information, cookie identifiers, referring
pages, pages viewed, approximate location and interaction data; and
- **Security data*, which may include CCTV images, access records and incident reports.
Please do not provide another persona’s personal data unless you are authorised to do so and have made this
- directly from you, including through our website, booking journey, check-in process, telephone calls, emails,
- from someone booking or organising a stay, meal or event on your behalf;
- from booking platforms, travel agents, tour operators, corporate travel organisers, event organisers and other
- from payment, fraud-prevention and identity-verification providers;
- automatically through our website and permitted cookies or similar technologies; and
- from publicly available sources, regulators, law-enforcement bodies or insurers where appropriate.
UK data protection law requires us to have a lawful basis for each use of personal data. We use personal data as
| Handle enquiries and take steps requested before a booking or contract | Identity, contact, booking, event and
communications data | Taking steps before entering into a contract; legitimate interests in responding to
| Make, administer and fulfil room, restaurant, voucher and event bookings; provide requested services; take
payment; and communicate about a booking or stay | Identity, contact, booking, event, payment, transaction and
communications data | Performance of a contract; legitimate interests in operating our services |
| Record and meet accessibility, dietary, allergy, health, religious or similar requirements | Information you
provide about those requirements | Explicit consent where required; vital interests in an emergency; or another
| Manage customer service, complaints, refunds, disputes, insurance matters and legal claims | Identity, contact,
booking, payment, transaction, communications and security data | Performance of a contract; legal obligations;
legitimate interests in protecting our business and resolving disputes |
| Maintain safety and security, prevent and investigate crime or fraud, and protect guests, staff and property |
Identity, transaction, website, device and security data | Legitimate interests; legal obligations; establishment,
| Maintain business, financial, tax and regulatory records | Identity, contact, booking, payment and transaction
data | Legal obligations; legitimate interests in business administration |
| Improve our website, services and customer experience; measure performance; and produce aggregated
reporting | Booking, communications, marketing, website and device data | Legitimate interests where the
processing is necessary and proportionate; consent where required for cookies or similar technologies |
| Send newsletters, offers and other direct marketing, and measure engagement | Identity, contact, marketing,
website and device data | Consent where required; otherwise our legitimate interests where electronic-
| Run promotions, prize draws and competitions and contact winners | Identity, contact, entry and
communications data | Performance of the competition terms; legitimate interests in administering and
promoting the competition. Entry is not treated as consent to unrelated marketing |
| Comply with lawful requests and enforce our terms | Relevant data described above | Legal obligations;
legitimate interests; establishment, exercise or defence of legal claims |
Where we rely on legitimate interests, we consider whether the use is necessary and whether your rights and
interests override ours. You may contact us for more information about this assessment.
If we ask for information that is required by law or needed to enter into or perform a contract, we will explain this
where appropriate. If you do not provide it, we may be unable to process a booking or provide the requested
We may send you marketing where you have consented or where the law otherwise permits. Marketing consent
is optional and is not a condition of booking with us. We do not treat entry into a competition as consent to
You can stop marketing at any time by using the unsubscribe link in an email or contacting us. Withdrawing
consent does not affect processing carried out before withdrawal. We may retain a minimal suppression record so
Service messages about a booking, event, transaction or stay are not marketing, and you may still receive them
Our website uses cookies and similar technologies. Some are strictly necessary for the site, booking functions,
security or the choices you request. Where consent is required, analytics, advertising and other non-essential
technologies will not be used until you choose to allow them.
You can accept, reject or manage non-essential technologies through **Cookie settings** on our website and can
change your choice at any time. Blocking some technologies may affect website features. Please see the
information presented in the cookie-preference tool for current details of the technologies used, their providers,
Where necessary for the purposes above, we may share personal data with:
- 7 Hospitality Management (UK) Limited and personnel involved in operating the hotel;
- booking-engine, property-management, customer-management, website-hosting, IT, communications and
- payment processors, banks, accountants, auditors and insurers;
- online travel agents, booking platforms, travel agents, tour operators, event organisers and service partners
- marketing, analytics and advertising providers, subject to your choices and applicable law;
- professional advisers, prospective purchasers, investors or lenders in connection with a corporate transaction,
- courts, regulators, tax authorities, police, emergency services and other public bodies where disclosure is
Service providers acting on our behalf may use personal data only as instructed and must protect it appropriately.
We do not sell or rent personal data. We do not disclose it to third parties for their own unrelated marketing
Some third parties, such as online travel agents or social-media platforms, determine independently how they use
Some suppliers may process personal data outside the United Kingdom. Where UK law requires it, we use an
approved transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement or
the UK Addendum to the EU standard contractual clauses, together with supplementary safeguards where
appropriate. Contact us if you would like more information about safeguards relevant to your personal data.
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected,
including to meet legal, accounting, tax, safety and reporting requirements and to establish, exercise or defend
Retention periods vary according to the type of record and relevant circumstances. In setting them, we consider
the amount, nature and sensitivity of the data; the risk of harm from unauthorised use or disclosure; the
purposes of processing; whether those purposes can be achieved in another way; and applicable legal
requirements. We securely delete or anonymise personal data when it is no longer required. You may contact us
for information about the retention period applicable to a particular category of data.
We use appropriate technical and organisational measures designed to protect personal data from accidental or
unlawful destruction, loss, alteration, unauthorised disclosure or access. Access is limited to people and suppliers
who need the data for their work and are subject to appropriate duties of confidentiality. No internet or storage
Subject to applicable law and any relevant exemptions, you may have the right to:
- receive certain personal data in a portable format and transmit it to another organisation;
- object to processing based on legitimate interests and object at any time to direct marketing;
- withdraw consent at any time where processing relies on consent; and
- request safeguards in relation to a decision based solely on automated processing that has a legal or similarly
These rights are not absolute. We may need to verify your identity and may request information needed to
respond. We normally respond within one month, although the law permits an extension in some circumstances.
There is usually no fee, but a reasonable fee may be charged or a request refused where the law permits.
To exercise a right, contact us using the details in section 1.
Please contact us first if you have concerns so that we can try to resolve them.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data-protection
regulator. Current contact details and the complaints process are available at [ico.org.uk/make-a-
complaint](https://ico.org.uk/make-a-complaint/). You may also seek a remedy through the courts.
Our website and services are not directed at children acting independently. We may process information about
children where it is supplied by a parent, guardian or booking organiser and is needed to provide hotel or event
services. Please contact us if you believe a child has provided personal data to us without appropriate authority.
Our website may link to websites, booking services and social-media platforms operated by others. We do not
control their privacy practices. Please read their privacy notices before providing personal data.
We may update this notice to reflect changes in our practices, services or legal obligations. The latest version will
be posted on this page with its revision date. We will use an appropriate method to tell you about material