1. Who we are
Gracechurch Hotel Operator Limited ("we", "us", "our") is the data controller for the personal data described in this policy. We operate The Gracechurch, a boutique hotel in the City of London, and the website gracechurchhotel.co.uk. We are a private limited company registered in England & Wales under Company Number 06010154, with our registered office at C/O TMF Group, 13th Floor, One Angel Court, London, United Kingdom, EC2R 7HJ.
2. The personal data we collect
Depending on how you interact with us, we may collect and process the following categories of personal data:
- Identity and contact data — name, email address, postal address and telephone number, provided when you make an enquiry, reservation or booking.
- Booking and stay data — arrival and departure dates, room preferences, dietary requirements you choose to share, and records of your stay and the services you use.
- Payment data — payment card details required to secure or settle a booking. Card data is processed by our payment provider; we do not retain full card numbers ourselves.
- Correspondence data — the content of emails, forms and other messages you send us, and our replies.
- Technical data — IP address, browser type and version, device type, and pages visited on our website, collected through server logs and cookies (see our Cookie Policy).
- Corporate account data — for business customers, the name, role and contact details of account contacts and authorised bookers.
3. How we use your data and our lawful bases
We process personal data only where we have a lawful basis under the UK GDPR and the Data Protection Act 2018:
| Purpose | Categories of data | Lawful basis |
|---|---|---|
| To take, manage and fulfil reservations and stays | Identity, contact, booking, payment data | Performance of a contract (or steps prior to a contract) |
| To respond to enquiries and correspondence | Identity, contact, correspondence data | Legitimate interests in responding to you; contract where the enquiry leads to a booking |
| To manage corporate rate agreements and group bookings | Corporate account, booking data | Performance of a contract; legitimate interests |
| To meet legal, tax and accounting obligations | Identity, booking, payment data | Legal obligation |
| To keep our website secure and improve it | Technical data | Legitimate interests in security and improvement; consent for non-essential cookies |
| To send marketing you have asked to receive | Identity, contact data | Consent (which you may withdraw at any time) |
4. Cookies
Our website uses a small number of cookies and similar technologies. Full details of the categories we use, the specific cookies, their purposes and durations, and how to manage or withdraw your consent are set out in our Cookie Policy.
5. Who we share your data with
We do not sell personal data. We share it only with:
- Service providers acting as processors — including our payment processing provider, IT and hosting providers, and professional advisers, each bound by written data-processing terms.
- Our company secretarial and registered office provider — TMF Group, which provides registered office and corporate administration services to Gracechurch Hotel Operator Limited.
- Authorities where required by law — regulators, law enforcement or courts, where we are legally obliged to disclose.
6. International transfers
We keep the personal data we hold within the United Kingdom wherever possible. Where a service provider processes data outside the UK, we ensure the transfer is protected by an adequacy regulation or by appropriate safeguards, such as the UK's International Data Transfer Agreement or the UK addendum to EU standard contractual clauses.
7. How long we keep your data
- Enquiries that do not lead to a booking — up to 24 months from our last correspondence.
- Booking, stay and invoice records — up to 7 years from the end of the financial year in which the stay took place, to meet tax and accounting obligations.
- Marketing consent records — until you withdraw consent, plus a short period to evidence the withdrawal.
- Website technical and cookie data — as set out per cookie in our Cookie Policy.
8. Your rights
Under the UK GDPR you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — ask us to delete your data where there is no good reason for us to keep it.
- Restriction — ask us to pause processing in certain circumstances.
- Portability — receive data you provided to us in a structured, commonly used, machine-readable format.
- Objection — object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent — where we rely on consent, withdraw it at any time without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, email info@gracechurchhotel.co.uk or write to us at our registered office. We respond within one month. You will not usually have to pay a fee.
9. Automated decision-making
We do not make decisions about you based solely on automated processing, including profiling, that produce legal or similarly significant effects.
10. Security
We apply appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, and limiting access to those who need it for their work.
11. Complaints
If you are unhappy with how we handle your personal data, please contact us first at info@gracechurchhotel.co.uk and we will do our best to resolve the matter. You also have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
ico.org.uk
12. Changes to this policy
We may update this policy from time to time. The version published on gracechurchhotel.co.uk is the version in force, and the date of the latest revision appears at the top of this page.