კონფიდენციალურობის პოლიტიკა

Ensana-ს შესახებ

კონფიდენციალურობის პოლიტიკა

0

ზოგადი დებულებები

ბოლო განახლება: აპრილი 2025

ეს კონფიდენციალურობის პოლიტიკა განსაზღვრავს, თუ როგორ იყენებს და იცავს Ensana s.r.o. („Ensana“ ან „ჩვენ“) თქვენს პერსონალურ მონაცემებს. Ensana (ან Ensana ჯგუფის სხვა კომპანია, იხილეთ ქვემოთ მე-5 ნაწილი) არის იმ პერსონალური მონაცემების დამმუშავებელი, რომლებსაც სტუმრები ან პოტენციური სტუმრები გვაწვდიან ensanahotels.com ვებ-საიტის გამოყენებისას. ეს ასევე ეხება სხვა ჯგუფის პირთა პერსონალური მონაცემების დამუშავებას, როგორებიც არიან სტუმრები, რომლებიც ჩვენთან სხვადასხვა არხებით ამყარებენ კომუნიკაციას, ბიზნეს კონტაქტები და ჩვენი თანამშრომლები.

თავისი ბიზნეს საქმიანობის პროცესში, Ensana ითხოვს, მოიპოვებს და ამუშავებს სტუმრების, პოტენციური სტუმრების, ბიზნეს პარტნიორების, თანამშრომლებისა და სხვა პირების პერსონალურ მონაცემებს. ჩვენი მიზანია, უზრუნველვყოთ მომსახურების შესაბამისი დონე პერსონალური მონაცემების მინიმალური რაოდენობის დამუშავებით.

ეს კონფიდენციალურობის პოლიტიკა შეიცავს დეტალებს იმის შესახებ, თუ როგორ ვუზრუნველყოფთ პერსონალური მონაცემების დაცვას. წესების უმეტესობა, რომლებსაც ჩვენ ვიცავთ, ეფუძნება მონაცემთა დაცვის ზოგად რეგულაციას (GDPR). მიუხედავად ამისა, ჩვენ ვიცავთ მონაცემთა დაცვისა და კონფიდენციალურობის ყველა შესაბამის სამართლებრივ მოთხოვნას.

მიუხედავად იმისა, რომ Ensana ჯგუფი რამდენიმე ქვეყანაში ოპერირებს, ამ კონფიდენციალურობის პოლიტიკაში მოცემული ინფორმაცია ზოგადად ძალაშია და ვრცელდება მონაცემთა დამუშავებაზე თქვენი ადგილმდებარეობის მიუხედავად. გარდა ამისა, ქვემოთ მოცემული მე-3 ნაწილი შეიცავს ინფორმაციას პერსონალური მონაცემების დამუშავების სპეციფიკური პირობების შესახებ იმ ქვეყანაში, სადაც თქვენ იმყოფებით.

თუ გაქვთ რაიმე შეკითხვა ამ პოლიტიკის შინაარსთან დაკავშირებით, ან შენიშვნები და წინადადებები მისი გაუმჯობესების შესახებ, გთხოვთ, დაგვიკავშირდეთ: [email protected]

ამ პოლიტიკაში ორიენტირება შეგიძლიათ შემდეგ სარჩევში მოცემულ სხვადასხვა პუნქტზე დაწკაპუნებით.

1

ფიზიკური პირების სამართლებრივი უფლებები GDPR-ის მიხედვით

GDPR-ის მიხედვით, მონაცემთა სუბიექტებს აქვთ შემდეგი ინდივიდუალური უფლებები:

ა) გამჭვირვალე ინფორმაციის მიღების უფლება

ბ) საკუთარ მონაცემებზე წვდომის უფლება

გ) არაზუსტი მონაცემების შესწორების უფლება

დ) მონაცემების წაშლის უფლება („დავიწყების უფლება“) გარკვეულ გარემოებებში

ე) თანხმობის გამოხმობის უფლება

ვ) დამუშავების შეზღუდვის მოთხოვნის უფლება

ზ) დამუშავების გაპროტესტების უფლება

თ) ავტომატიზებულ გადაწყვეტილებებზე არდაქვემდებარების უფლება

ი) მონაცემთა გადატანის უფლება

კ) „ზედამხედველ ორგანოში“ საჩივრის შეტანის უფლება

ლ) დამმუშავებლის ან თანადამმუშავებლის წინააღმდეგ სასამართლო დაცვის ეფექტიანი საშუალების უფლება

ამ უფლებებთან დაკავშირებულ თქვენს მოთხოვნებს ვუპასუხებთ გაუმართლებელი დაყოვნების გარეშე, მაგრამ არაუგვიანეს ერთი თვისა, ხოლო რთული შემთხვევების გადაჭრას მაქსიმუმ სამი თვის ვადაში შევეცდებით. პასუხს გამოგიგზავნით ელექტრონული არხით ან თქვენ მიერ მოთხოვნილი ნებისმიერი სხვა საშუალებით. პირველი მოთხოვნის შესრულებისთვის საფასურს არ გადაგახდევინებთ, თუმცა ვიტოვებთ უფლებას, დავაწესოთ ადმინისტრაციული მოსაკრებელი წლის განმავლობაში განმეორებით გამოგზავნილი, ან აშკარად დაუსაბუთებელი და გადაჭარბებული მოთხოვნის დამუშავებისთვის.

მნიშვნელოვანია! თქვენი მოთხოვნის დასამუშავებლად ჩვენ დაგვჭირდება თქვენი პიროვნების იდენტიფიცირება.

თუ მივიჩნევთ, რომ თქვენს მოთხოვნაზე რეაგირება არ არის საჭირო, წერილობით შეგატყობინებთ ჩვენი გადაწყვეტილების მიზეზს, ისევე როგორც თქვენთვის ხელმისაწვდომი სამართლებრივი დაცვის საშუალებების შესახებ.

ამ უფლებების მიღმა, თუ თვლით, რომ Ensana არასათანადოდ მოიქცა თქვენს პერსონალურ მონაცემებთან ან მათ დაცვასთან დაკავშირებით, გთხოვთ დაგვიკავშირდეთ, რათა გამოვასწოროთ სიტუაცია და გავაუმჯობესოთ ჩვენი სტუმრებისთვის გაწეული მომსახურება. ოფიციალური საჩივრის გამოგზავნა შეგიძლიათ ელექტრონული ფოსტით ან ფოსტის მეშვეობით, 1.12 ნაწილში („Ensana-სთან დაკავშირება GDPR-ის საკითხებზე“) მითითებულ მისამართებზე.

1.1

Right to receive transparent information

We will provide all information required by the GDPR to you in a concise, transparent, intelligible and easily accessible form, using clear and plain language. We will provide the information in writing or by electronic means. If you request, we can also provide this information verbally.

We help you exercise your rights as set out in section 1 below.

You will find our email and postal addresses in section 1.12 “Contacting Ensana in relation to the GDPR” below. In the sections of chapter 2 dealing with certain activities, you will also find contact details for various individual requests.

1.2

Right of access to your own data

You have the right to request confirmation from Ensana as to whether we process personal data about you and, if so, to request access to the data and to the following information:

a)  Purpose of the processing 

b)  Categories of personal data concerned

c)  Recipients to whom we have disclosed or will disclose the personal data, in particular recipients in countries outside the EU

d)  The period for which the personal data will be stored

e)  The fact that you have the right to request us to rectify or erase your personal data or to restrict the processing of your personal data, or to object to such processing

f)  The fact that you have the right to lodge a complaint with the Supervisory Authority

g)  If the personal data are not collected directly from you, then the source of these data

h)  Whether there any automated decision-making is made based on the data and, if there is, understandable information regarding the logic used, as well as what significance such data processing has, and what the likely consequences of it are for you.

i)  Where we send your personal data to a country outside the EU, the appropriate safeguards we have in place to protect your rights.

1.3

Right to rectify inaccurate data

If we hold inaccurate or incomplete personal data on you, you may request the rectification of such data. After receiving your request, we will correct such personal data without undue delay.

1.4

Right to erasure (“right to be forgotten”)

You have the right to have us erase your personal data and to ask us to fulfil your request without undue delay if one of the following grounds for this applies:

a) Your personal data is no longer needed in connection with the original purposes of the data processing

b) You have withdrawn your consent and thus we no longer have a legal basis for processing the data

c) The lawfulness of the data processing is based on our legitimate interests, but you claim that there is no legitimate reason for the data processing that takes precedence over your interests, rights and freedoms

d) The purpose of the data processing is direct marketing, and you object to this

e) We have been unlawfully processing your data

f) Your data must be deleted in order to fulfil the legal obligation prescribed by EU or member-state law that applies to us

g) The lawfulness of the processing of the data by us is based on the consent given by the guardian of a child, and or i. you are the guardian and the child is still under the age of consent, or ii. you are the child and are now above the age of consent.  NB! We cannot erase your personal data if the data processing is necessary for the following reasons:

a) for exercising the right to freedom of expression and information;

b) fulfilment of a legal obligation that requires the processing of the personal data; 

c) on the basis of public interest in the field of public health; 

d) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in so far as the request is likely to render impossible or seriously impair the achievement of the objectives of such processing; or

e) for the establishment, exercise or defence of legal claims.

1.5

Right to withdraw consent

Where you have given us consent for any processing, you have the right to withdraw consent at any time. You can do this by sending a request to the email address given in the relevant subsection of section 2 below, which lists the different activities for which we manage personal data. Alternatively, you can write to us at the address in section 1.11 below.  

NB. The withdrawal of your consent does not affect the lawfulness of any processing we have already carried out.

1.6

Right to request restriction of processing

You can request that Ensana restrict the processing of your personal data if one of the following applies:

•  You contest the accuracy of the personal data

•  The data processing carried out by us is unlawful, but you do not agree to the erasure of the data and instead request the restriction of its use

•  We no longer need the data for the original purpose, but you require the data for the establishment, exercise or defence of legal claims

•  You object to our processing on the grounds that we state our legal basis as “our legitimate interests” but you claim that your “interests, rights and freedoms” override these.

If the data processing is restricted based on your objection, such personal data may only be processed with your consent, with the exception of storage, or: 

a)  for the establishment, exercise or defence of legal claims

b)  for the protection of the rights of another person, or 

c)  for reasons of important public interest of the EU or of a Member State.

Where we restrict processing, we shall inform you before we lift the restriction.

1.7

Right to object to processing

You have the right to object to our processing your personal data where:

•  Our basis of lawfulness for processing is “our legitimate interests” but you claim that your “interests, rights and freedoms” override these

•  We process your data for direct marketing purposes, including “profiling” to the extent that this is related to the direct marketing. (Profiling is automated decision-making in which characteristics related to the financial situation, personal preferences or place of residence are analysed or predicted.) Where you make such an objection we shall no longer process your data for such purposes.

1.8

Right not be subject to automated decisions

You have the right not to be subject to the scope of a decision based solely on automated data processing that would have legal effects on you or would affect you in some other, similarly significant manner.

However, this does not apply if: 

a) the decision is necessary in order to conclude or fulfil a contract between you and us, or

b) the automated process is made possible by EU or member-state law that also establishes appropriate measures to protect your rights and freedoms as well as your legitimate interests.

In case a), we must implement appropriate measures to protect your rights, freedoms and legitimate interests, including at least your right to request human intervention on our part, to express your point of view and to submit an objection to the decision.

1.9

Data portability

Pursuant to the GDPR, the data subject is entitled, under certain circumstances, to receive their personal data “in a structured, commonly used and machine-readable format”. The right includes having the personal data transmitted directly from one controller to another, where technically feasible.

If you request access to your personal data based on the above section 1.2, we will generally provide such data to you in a widely used electronic format, unless you specifically request that we send you the data in written (hard-copy) form.

1.10

Right to complain to a “Supervisory Authority”

If you believe that we have acted unfairly or unlawfully towards you pursuant to the GDPR, you can lodge a complaint with the data protection Supervisory Authority. You can find the name and contact information of the data protection authorities at the following link

1.11

Right to an effective judicial remedy against a controller or processor

If you believe that your rights under the GDPR have been infringed as a result of the processing of your personal data in a manner not compliant with the GDPR, you have the right to effective judicial remedy. 

Proceedings against the data controller or data processor must be initiated before the court of the EU Member State where the data controller or data processor operates. Such proceedings can also be initiated before the court of the EU Member State of your habitual residence.

1.12

Contacting Ensana in relation to the GDPR

In order to exercise the rights described above or in the case of a complaint addressed directly to Ensana or in the case of a general enquiry related to the GDPR or to data protection, the email address and correspondence address required for maintaining contact are as follows:

Email: [email protected]  

Address: GDPR - Ensana s.r.o.; CZ- Senovázne námestí 992/8, CZ-110 00 Prague 1, Czech Republic

We will forward your request to the relevant hotel operator, as described in this Policy.

2

მონაცემთა დამუშავება

წინამდებარე კონფიდენციალურობის პოლიტიკაზე თანდართული ცალკეული დოკუმენტი შეიცავს ევროკავშირის შიდა (intra-EU) მონაცემთა გადაცემისა და მონაცემთა დამმუშავებლების (კონტროლერების) სიას; მესამე ქვეყნებისთვის მონაცემთა გადაცემის შემთხვევები დამატებით ხაზგასმულია წინამდებარე კონფიდენციალურობის პოლიტიკაში.

გთხოვთ გაითვალისწინოთ, რომ ქვემოთ აღწერილ მონაცემთა დამუშავების გარკვეულ აქტივობებთან დაკავშირებით, „Ensana Group“-ის სუბიექტები და შესაბამისი „Ensana Hotels“-ის სასტუმროები, რომლებიც უზრუნველყოფენ განთავსებასა და მასთან დაკავშირებულ მომსახურებას, მოქმედებენ როგორც მონაცემთა ერთობლივი დამმუშავებლები (კონტროლერები). ეს კეთდება ჯგუფის ადმინისტრირების გასამარტივებლად და თქვენთვის უკეთესი მომსახურების მისაწოდებლად, რაც არანაირად არ ახდენს გავლენას თქვენს უფლებებსა და ჩვენს ვალდებულებებზე. „Ensana Group“-ის სუბიექტები და „Ensana Hotels“-ის სასტუმროები, როგორც ერთობლივი დამმუშავებლები, ყოველთვის მკაცრად იცავენ პერსონალურ მონაცემთა დაცვის უმაღლეს სტანდარტებს და მოქმედებენ წინამდებარე კონფიდენციალურობის პოლიტიკის შესაბამისად. „Ensana Group“-ის სუბიექტების შესახებ დამატებითი ინფორმაციისთვის, გთხოვთ, იხილოთ მე-3 ნაწილი.

სტუმარი ინფორმირებული უნდა იყოს იმის შესახებ, რომ ინტერნეტთან წვდომა არის ღია (Firewall/პროგრამული უსაფრთხოების ფარის გარეშე) და სასტუმრო რეკომენდაციას უწევს სტუმარს, დაიცვას თავისი ლეპტოპი ან პერსონალური კომპიუტერი პროგრამული უზრუნველყოფის Firewall-ით.

ინფორმაცია მონაცემთა დამუშავების დებულებების/აქტივობების შესახებ უნგრეთში მდებარე „Ensana“-ს სასტუმროების შემთხვევაში ხელმისაწვდომია...

შენიშვნა: ბოლო წინადადება ორიგინალშიც დაუსრულებელია, სავარაუდოდ, ტექსტში მას ბმული ან კონკრეტული მითითება მოსდევს.

here.

2.1

Booking

In the case of a room reservation made online, in person at the hotel or by telephone, we may request one or all of the following items of personal data:

  • Full name
  • Title
  • Arrival date
  • Departure data
  • Number of adults staying in one room
  • Type of room
  • Details of the credit or debit card used to secure the booking or needed for online payment (see section 2.10.)
  • In the case of a spa hotel, the desired treatment package
  • Email address
  • Address
  • Time of arrival
  • Notes – including, for example, any preferences
  • Purpose of the data processing:

    - The purpose of the data processing is to be able to identify the guest who made the booking, to provide the room to the right person on check-in, and to register the means of payment, in order to cover us in case the guest does not check into the hotel.  

    •       We use your email address in the following cases:

    if we need to notify you of a change affecting your booking;

    ii. three days before your planned arrival, to remind you of details such as the hotel address and check-in time; and

    iii. three days after your departure, to ask that you share your comments about your stay with us so that we can provide you and other guests with an even better service in the future. 

    •       We process the data on the invoice for the purpose of fulfilling the related legal obligation

    •       After your departure, we will keep the data for the purpose of asserting claims or managing complaints within the limitation period stipulated under civil law.

    Legal basis of the data processing:

    •       Specific rules may apply depending on the country in which your data will be processed (see section 3 for details). The standard period is between 5 and 10 years. Under no circumstances will we exceed the period necessary for the processing of your data.

    •       The legal basis of the data processing is that we need the data to fulfil a contract for room reservation. [GDPR Article 6(1)(b)]

    •       We process your name and your email address for up to the third day following the end of your stay in order that we can send you a post-stay email for the purpose of the “legitimate interests pursued by the controller, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject”. Our legitimate interests here are to maintain a high quality of service, and we believe that sending you the post-stay email does not affect your fundamental rights. [GDPR Article 6(1)(f)]

    •       We process the data on the invoice (name, address) based on our legal obligation. [GDPR Article 6(1)(c)]

    •       After your departure, we will retain the data based on our legitimate interest associated with the assertion of claims and the managing of complaints. [GDPR Article 6(1)(f)]

    If you do not give us the data requested, we will either be unable to reserve a room for you or be unable to contact you if there is a problem.

    Period of the data processing:

    Processor:

    For booking purposes, your personal data is processed by Virtual Zoom s.r.o. (registered office: Office center Zirkon, Sokolovská 131/86 - Karlín, 186 00 Praha 8), our data processor, who is responsible for the appropriate functioning of our CRM system and who is obliged to conduct the data processing activity in accordance with the terms of the contract between us and with the relevant statutory provisions.

    Your personal data will be processed by THN (The Hotels Network, S.L., NIF B-65542714, Calle Muntaner, 262, 3º-1ª, 08021 Barcelona, Spain) as a data processor, responsible for the proper functioning of the forms, and obliged to carry out its processing activities in accordance with the contractual terms existing between us, and with the applicable legal requirements.

    For the purpose of sending out pre-stay and post-stay information emails, your data may be transferred to our processor, Servi Smart Solutions Ltd, an Isreal company that operates the Duve guest platform. As part of this, your data may also be transferred to a third country, namely Israel. Israel ensures adequate protection of personal data in accordance with Commission Decision of 31 January 2011 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data by the State of Israel with regard to automated processing of personal data (which is the case here).

    Other processors may be used in the country in which the processing of your data will take place (see section 3 for details).

    Transfer of data outside the EU:

    When you make a booking on our website you are entering data into a software application run by Sceptre Hospitality Resources, a US company. Your personal data is therefore transferred to a third country (i.e. a country outside the EU). The adequacy of such data transfers is safeguarded through the application of the standard contractual clauses for international transfers. https://eur-lex.europa.eu/legal-content/HU/TXT/HTML/?uri=CELEX:32010D0087&from=en.

    If you wish to exercise any of your rights referred to in section 1 in relation to the data thus provided, or you wish to contact us for any other reason in connection with the above data processing, please let us know by sending an email to [email protected].

    2.2

    Hotel registration cards

    Scope of the data and legal basis of the data processing:

    Personal data that must be provided (i.e. the guest must provide these in order to be able to use the hotel services):

    •       In order to fulfil our legal obligations, we record and store various identification data of our guests such as name, date of birth, details of personal ID document. The scope of the data may vary depending on the country where your data is processed and we refer you to section 3 for further information. [GDPR Article 6(1)(c)]

    •       In order to provide the requested services, e.g. accommodation and/or spa services (in accordance with the contract), we also process the following data: contact details, loyalty programme reference number, mode of payment, credit/debit card details, room number, number of guests. [GDPR Article 6(1)(b)]

    •       On the basis of the Ensana’s legitimate interest associated with the improving of its services, for three days after you leave we process your name and email address in order to ask you for your opinion on our services and thus to improve them. [GDPR Article 6(1)(f)]

    •       We process the data on the invoice (name, address) based on our legal obligation. [GDPR Article 6(1)(c)]

    •       After your departure, we will retain the data based on our legitimate interest associated with the assertion of claims and the managing of complaints. [GDPR Article 6(1)(f)]

    Non-compulsory statistical data:

    •       For statistical purposes, the following data are processed separately from personal data: business trip, holiday.

    Most of the data is completed based on the booking and the rest at the time of check-in using an ID document reader. We ask you to please always check the accuracy of your data.

    Purpose of the data processing:

    •       Provision of hotel services, including maintaining contact with customers and improving the service.

    •       The purpose of recording and storing data specified by the relevant law is to ensure legal compliance.

    •       After your departure, we will keep the data for the purpose of asserting claims or managing complaints within the limitation period stipulated under civil law.

    Period of the data processing:

    •       After your departure, we will keep the data for the period of limitation stipulated under civil law.•       Further to that, specific rules apply depending on the country in which your data will be processed (see section 3 for details). The standard period is between 5 and 10 years. Under no circumstances will we exceed the period necessary for the processing of your data.

    If you wish to exercise any of your rights referred to in section 1 in relation to the data recorded during check-in, or you wish to contact us for any other reason in connection with data recorded during check-in, please let us know by sending an email to [email protected]

    2.3

    Spa, health services and physical therapy

    You can use the health services separately from the other services of the hotel. You can access the treatments offered by the hotel on the basis of the curative health package already requested or by selecting it on site. Before providing health-related services, an employee working in the separate section of the hotel that deals with this directs each guest to a doctor. At the doctor, you will receive a Treatment Record Card, which the doctor will fill in as follows:

    •         Data required for identification: name, social security number, date of birth, telephone number

    •         Past history: illnesses, medications, complaints, etc. The recording of health data is part of the medical treatment. The treating doctor decides which medical data needs to be recorded in accordance with the professional regulations.

    The guest then shows up for the given treatment with his/her Treatment Record Card, where the staff participating in the treatment only see the minimum information required for providing the care specified on the Treatment Record Card. The detailed data on the patient will only be seen by the doctor and his/her assistant.

    Purpose of the data processing:

    Promoting the protection, improvement and maintenance of your health.

    Legal basis of the data processing:

    •         with regard to the mandatory personal identification data for the use of healthcare services: The statutory requirement [GDPR Article 6(1)(c); GDPR Article 9(1)(h)];

    •         with regard to personal data that is not mandatory for the use of healthcare services, but deemed necessary by the doctor: Your consent [GDPR Article 6(1)(a); GDPR Article 9(1)(a)]; Consent can be withdrawn at any time in person at the doctor’s office or by email at [email protected]. Such withdrawal, however, shall not affect the lawfulness of any processing that preceded it.

    Period of the data processing:

    The rules may apply according to the country in which the processing of your data will take place (see section 3 for details).

    Data transfer:

    Health data will only be transferred at your request to another doctor or third party and your consent will be required in the event of a transfer to a doctor who has not treated you but still requires your data so recorded. Health data will not be passed to your GP unless you specifically prohibit this.

    In addition, specific rules may apply depending on the country in which your data will be processed (see section 3 for details).

    If you wish to exercise any of your rights referred to in section 1 in relation to the data recorded during the provision of health services, or you wish to contact us for any other reason in connection with data recorded during the provision of health services, please let us know by sending an email to [email protected].

    2.4

    Gym

    Purpose of the data processing:

    Provision of gym services and complaints management:

    •       the name, date of birth and photo are used for identification purposes;

    •       the data related to health and to your membership helps us provide you with a personalised service and avoid risks to your health;

    •       the other personal data (phone number, email address) is used for maintaining contact with you; providing these contact details is not compulsory, but it is necessary if you want us to be able to contact you.

    Non-compulsory statistical data:

    •       for statistical purposes, we treat the following data separately from personal data: e.g. where you heard about the club.

    Legal compliance:

    •       in the case of a private individual, the name and address.

    To speed up the purchase process, some data will be left to be completed at check-in. We ask you to please always check the accuracy of your data.

    Period of the data processing:

    •       We process your personal data for 1 year from the end of the year in which your gym membership expired or from the end of the year of your one-time entry to the gym, for the purpose of complaints management. If you withdraw your consent before the end of this period, your health data will be deleted as soon as you notify us of the withdrawal.

    For guests signing up to the newsletter or consenting to receive promotional materials, Ensana shall process the data listed above further, in accordance with the provisions under section 2.7 of this Policy.

    In addition, specific rules may apply depending on the country in which your data will be processed (see section 3 for details).

    If you wish to exercise any of your rights referred to in section 1 in relation to the data recorded for the purpose of the provision of this service, or you wish to contact us for any other reason, please let us know by sending an email to [email protected].

    2.5

    Guest questionnaire and review system

    Guest questionnaire and review system

    As part of the Ensana’s quality assurance process, guests can give their opinion on the services of Ensana hotels by means of an email or paper-based guest questionnaire, or with the help of the review system. When completing the questionnaire, you can specify the following personal data:

    •  Name

    •  Date of visit

    •  Room number

    •  Contact details (address, email address, phone number, home address)

    Giving the data is not compulsory; the purpose of the data is simply to allow us to accurately investigate possible complaints and to ensure we can respond to them.

    Ensana may also use the opinions received in this way, and any data specified in relation thereto that cannot be traced back to the given Guest or linked to the Guest’s name, for statistical purposes.

    If you provide your opinion in an anonymous way, we will not process any personal data. If you request feedback from us, our employee will contact you at one of the contact details provided (email, address, phone number) within 30 days at the latest.

    Purpose of the data processing:

    To maintain contact with the reviewer, and to manage complaints.

    Legal basis of the data processing:

    Your consent [GDPR Article 6(1)(a)]. Please note that if we do not receive your consent to the processing of your data or if you withdraw such consent, we will not be able to respond to your question. Withdrawal of consent does not affect the lawfulness of the data processing that preceded it.

    Period of the data processing:

    Messages and personal data received in this way will be deleted one year after the given request, question or complaint has been responded to.

    If you wish to exercise any of your rights referred to in section 1 in relation to the data thus provided, or you wish to contact us for any other reason in connection with the above data processing, please let us know by sending an email to [email protected].

    2.6

    Video surveillance system

    Cameras are used on the premises of the hotels in order to assure the safety of Guests and their personal belongings. Guests are reminded of the presence of these cameras through signs featuring a picture of a camera and an accompanying text.

    You can ask for more information about the data processing related to the video surveillance system from the front-desk staff at the hotel concerned. We will send you the Privacy Policy of such video surveillance systems at your request. Please send your request to the hotel’s general email address or postal address, or by email to [email protected].

    2.7

    Newsletter and special offers

    For the purpose of sending you newsletters and special offers (via email, SMS, and other appropriate channels), we process your name, phone number, email address and occasionally, your home address. In connection with the sending the newsletters and special offers, you have the option to set the topics and the region that you would like to receive newsletters or special offer on. We also store your language settings.

    Purpose of the data processing:

    To provide you with information on the latest promotions and on news items.

    Legal basis of the data processing:

    Your consent [GDPR Article 6(1)(a)]. Kindly note that if you do not consent to the processing of your data, we will not be able to send you a newsletter or special offer.

    Period of the data processing:

    We only send you our newsletter and special offers for as long as you request it. If you no longer wish to receive our newsletter or special offers, you can unsubscribe at any time either by using the dedicated link at the end of each newsletter or commercial communication or by notifying us at [email protected]. Withdrawal does not affect the lawfulness of the data processing that preceded it.

    Data transfer:

    Data is transferred to Ensana group companies that operate hotels functioning under the Ensana brand. Please note that Ensana s.r.o., CP Regents Park Two Ltd, Slovenské liečebné kúpele Piešťany, a.s., SC Balneoclimaterica SA, Borovete I AD and Léčebné lázně Mariánské Lázně a.s. may each be specified as senders of the newsletter or special offer. Data is transferred to Facebook (Meta Platforms Ireland Limited (Serpentine Avenue, Block J, Dublin 4, Ireland) for the purposes of “lookalike marketing”. In this context, using the name and email address, Facebook displays our ad to people with a similar profile. More information: https://www.facebook.com/business/help/164749007013531?id=401668390442328

    Processor:

    Your personal data is processed by Virtual Zoom s.r.o. (registered office: Office center Zirkon, Sokolovská 131/86 - Karlín, 186 00 Praha 8), our data processor, who is

    responsible for the appropriate functioning of our CRM system and who is obliged to conduct the data processing activity in accordance with the terms of the contract between us and with the relevant statutory provisions.

    Your personal data will be processed by THN (The Hotels Network, S.L., NIF B-65542714, Calle Muntaner, 262, 3º-1ª, 08021 Barcelona, Spain) as a data processor, responsible for the proper functioning of the forms, and obliged to carry out its processing activities in accordance with the contractual terms existing between us, and with the applicable legal requirements.

    Furthermore, your personal data may be made available to agencies engaged in marketing mailings that we authorize for this purpose (e.g., email or SMS mailings).

    If you wish to exercise any of your rights referred to in section 1 in relation to the data thus provided, or you wish to contact us for any other reason in connection with the above data processing, please let us know by sending an email to [email protected].

    2.8

    Loyalty Programme (Ensana Life)

    Ensana offers its own loyalty program.

    Ensana Life rewards the guest’s loyalty with discounts and other benefits based on nights spent at Ensana hotels.

    Further information here: https://ensanahotels.com/ge/membership/terms-and-conditions

    Danubius Friends is the new loyalty program of Danubius Hotels, which does not apply to Ensana hotels. More information is available here.

    The Company’s Corporate Programme is an exclusive service provided to the hotels’ corporate partners – juridical persons (companies) – with the purpose of providing loyalty discounts to these partners.

    Within the loyalty programmes, the company mainly processes the following personal data:

    In the case of natural persons (private individuals):

    •  Name

    •  Gender

    •  Postal address

    •  Address

    •  Phone number

    •  Email address

    •  Date of birth (minors under eighteen years of age may not participate in the programme)

    Personal data processed in the case of juridical persons (companies):

    •  Name of contact person

    •  Postal address

    •  Phone number

    •  Email address

    In addition, information related to fulfilling the conditions of the loyalty programme (points earned, number of nights, use of discounts and benefits or other information relevant to the programme concerned), and the number, validity and password of your loyalty card.

    Purpose of the data processing:

    To provide discounts to the participants. Sending notifications about the discounts.

    Legal basis of the data processing:

    Your consent [GDPR Article 6(1)(a)]. You can withdraw your consent at any time and request the deletion of your data by email sent to [email protected] or [email protected], or by letter sent to: Danubius Hotels Zrt. 1051 Budapest, Szent István tér 11., on the understanding that this shall not affect the lawfulness of any processing preceding it. Please note that without giving your consent you may not participate in the Loyalty Programme.

    Period of the data processing:

    •         The processing of the personal data provided shall last as long as the person concerned participates in the given programme. 

    •         The membership status of natural/juridical persons in the Corporate Programme will become inactive after 2 (two) years from the date of the last hotel service used.

    •         The company stores the necessary personal data of the member for the period specified in the relevant tax and accounting regulations, and deletes them after that period.

    Joint data processing:

    Kindly note that for the sake of the interoperability of the hotels, Ensana s.r.o., CP Regents Park Two Ltd, Slovenské liečebné kúpele Piešťany, a.s., SC Balneoclimaterica SA, Borovete I AD and Mariánské Lázně a.s. are joint data controllers for the loyalty programme. You will find more information on the hotels in section 5. The joint data controllers shall act in all respects in accordance with the provisions of this Policy when processing data.

    Participation in the programmes may occasionally require the provision of further personal data, in which case the Company may request the given data and inform the data subject about the purpose, manner and duration of the data processing.

    If you wish to exercise any of your rights referred to in section 1 in relation to the data thus provided, or you wish to contact us for any other reason in connection with the above data processing, please let us know by sending an email to [email protected].

    2.9

    Credit/debit card details

    In the case of room booking and online payment, we request the following credit/debit card details:

    • Name on the card

    • Card number

    • Expiry date

    • CVC (only in the case of payment)

    • Address

    • Email address

    • IP address

    Purpose of the data processing:

    To secure the payment or the booking, and to be able to charge the total price of the booking or a part of it, depending on the conditions of the booking.

    Legal basis of the data processing:

    Fulfilment of the contract concluded for the purpose of room booking as a service. [GDPR Article 6(1)(b)] Giving the data is compulsory; it is a precondition for the provision of the service.

    Period of the data processing:

    The debit/credit card details are encrypted; release of this data is only possible for the purpose of the transaction, and only to the person authorised in relation thereto. After the guest has left the hotel, the data can no longer be released, and access to the data is no longer possible. The data will be deleted after 8 years. 

    Processor or data processor:

    The service is provided by Adyen N.V. (registered office: Adyen N.V.; Simon Carmiggeltstraat 6-50, 1011 DJ in Amsterdam, the Netherlands.) as data processor.

    If you wish to exercise any of your rights referred to in section 1 in relation to the data thus provided, or you wish to contact us for any other reason, please let us know by sending an email to [email protected].

    2.10

    Social media platforms (e.g. Facebook, Instagram)

    Ensana and the hotels, restaurants and fitness clubs operated by Ensana can also be contacted individually via the social media platforms Facebook and Instagram. By hitting the “like” and “follow” button on the given page, Facebook users can subscribe to the news published on newsfeed; by hitting the “dislike” button they can unsubscribe to it, and by adjusting the newsfeed settings, they can hide the news they do not wish to follow from the newsfeed. Ensana is able to access its “followers’” profiles; however, it does not record or process them in its own internal system. On YouTube, you can follow and unfollow using the ‘subscribe/unsubscribe’ button.

    Purpose of the data processing:

    Sharing the contents on the websites of Ensana and of the hotels, restaurants and fitness clubs, etc. operated by Ensana; sharing other news and offers, maintaining contact. Via the Facebook pages, you can book a room, participate in prize draws and find out about our latest promotions.

    Legal basis of the data processing:

    Your consent [GDPR Article 6(1)(a)], which can be withdrawn at any time by unsubscribing. The withdrawal of consent does not affect the lawful processing that preceded it. In the case of withdrawal, you will not receive notifications on your newsfeed; our news will no longer appear on your newsfeed, though you will still be able to access the Ensana’s newsfeed, since our website is public.

    Period of the data processing:

    The data processing lasts until you unsubscribe.

    Facebook and Instagram are separate data controllers, independent of us. You can find information about the data processing of the site from the data protection guidelines and regulations on the Facebook website, at the following links:

    •  https://www.facebook.com/policies/cookies/

    •  https://www.facebook.com/about/privacy/update

    You can find information on Instagram’s data processing at the following link:

    •  help.instagram.com

    YouTube: https://www.youtube.com/intl/ALL_en/howyoutubeworks/user-settings/privacy/

    In the event of a room reservation, the system automatically redirects the guest to the Ensana’s website. The data processing takes place in accordance with the provisions of section 2.1.

    If you wish to exercise any of your rights referred to in section 1 in relation to the data thus recorded, or you wish to contact us for any other reason, please let us know by sending an email to [email protected].

    2.11

    Web store

    Hotel restaurant coupons and programme tickets, daily tickets for the use of various fitness and spa services, as well as passes and day spa programmes may also be purchased in the form of vouchers via the online system (web store), by filling out the online order form, for which the following data will be required:

    •  Family name

    •  Given name

    •  Email address

    •  Billing data (name, country, postcode, city, street, house number)

    In addition to the above, Ensana processes the date and time of purchase, the name and price of the service, the total amount of the purchase and the IP address of the customer.

    Purpose of the data processing:

    Maintaining contact with the customers, the provision of service, the processing of the purchase and the fulfilment of the relevant accounting obligations. The purpose of retaining the data after the purchase is to enforce any claims and manage any complaints.

    Legal basis of the data processing:

    •         Fulfilment of the contract and an compliance with legal obligations. Giving the data is compulsory; it is a precondition for the purchase. [GDPR Article 6(1)(b) and (c)]

    •         The legal basis of retaining the data after the purchase is our legitimate interest associated with the purpose of the processing, i.e. asserting claims and managing complaints. [GDPR Article 6(1)(f)]

    Period of the data processing:

    •       The personal data will be kept for 5 years after the service has been provided.

    •       Specific rules may apply depending on the country in which your data will be processed (see section 3 for details). The standard period is between 5 and 10 years. Under no circumstances will we exceed the period necessary for the processing of your data.

    For online card payments, you will be automatically redirected to the website of the following data controller:

    OTP Bank Nyrt. (Registered office: 1051 Budapest, Nádor Street 16.; registration number: 01-10-041585; web: www.otpbank.hu)

    If you wish to exercise any of your rights referred to in section 1 in relation to the data thus provided, or you wish to contact us for any other reason in connection with the above data processing, please let us know by sending an email to [email protected].

    2.12

    Prices subject to registration

    Prices subject to registration

    Booking at certain prices that offer an extra discount (e.g. Direct Discount) is subject to registration. The direct booking discount applies to many public deals, however, it cannot be combined with other coupons or percent (e.g. Ensana Life) discounts.

    During registration, it is compulsory to provide your email address and possibly your name. By registering for the discounted price, you consent to us sending newsletters to the email address that you provide. You may naturally unsubscribe from the newsletter at any time.

    Purpose of the data processing:

    Provision of information about discounts and special offers.

    Legal grounds for the data processing:

    Your voluntary consent. You may withdraw your consent at any time, but this will not affect the legitimate data processing that occurred before the withdrawal of consent. Please note that if you do not consent to the processing of the data, we will not be able to keep you informed about our special offers. {GDPR 6. article (1)(a)}

    Period of the data processing:

    Until withdrawal of the consent.

    If you wish to exercise any of your rights described in section 1 in relation to the data thus provided, or if you would like to contact us for any other reason regarding the data processing described above, please let us know by sending an email to [email protected].

    If you subscribe via Facebook, the operator of the Facebook and Instagram pages (Meta Platforms Ireland Limited, seat: Serpentine Avenue, Block J, Dublin 4, Ireland; https://www.facebook.com/privacy/explanation; https://www.facebook.com/help/instagram/155833707900388/) provides the Controller the opportunity to display advertisements and use the page analytics function. The page analytics function displays aggregated data designed to help the Data Controller understand how visitors interact with the given page and its advertisements and to draw conclusions for a more efficient operation. No personal data are included in statistical analyses. The processing of data for advertising and statistical purposes on these pages is carried out jointly by the Data Controller and Meta Platforms Ireland Limited (Serpentine Avenue, Block J, Dublin 4, Ireland). The details of the joint data processing agreement can be found in the data processing appendix of the Facebook Page Analytics function. The appendix is available on the following link: https://www.facebook.com/legal/terms/page_controller_addendum

    Specific rules may apply depending on the country in which your data will be processed (see section 3 for details).

    2.13

    Contact

    You can contact us (e.g. to ask for a quote) at any of our contact details (email, Facebook, phone, post or through the forms designed for this purpose).

    Purpose of the data processing:

    Maintaining contact with the requester, answering and resolving the question/request.

    Legal basis of the data processing:

    Since it is you who is contacting us, the legal basis for data processing is your consent [GDPR Article 6(1)(a)]. You can withdraw your consent at any time, but in this case we will not be able to respond to your request. Withdrawal does not affect the lawfulness of the data processing that preceded it.

    Please note that the data fields on the various forms were created based on our experience, and involve requesting the minimum of data that we need to answer the request concerned. Mandatory fields are marked with a red asterisk.

    Period of the data processing:

    Messages and personal data received in this way will be deleted one year after the given request, question or complaint has been responded to. However, if, due to the nature of the correspondence, it is necessary for tax or accounting reasons, or perhaps for the purpose of protecting the rights and interests of Enana or the requester, it will be archived and stored for the necessary time, which we assess individually in each case.

    Processor:

    Your personal data will be processed by THN (The Hotels Network, S.L., NIF B-65542714, Calle Muntaner, 262, 3º-1ª, 08021 Barcelona, Spain) as a data processor, responsible for the proper functioning of the forms, and obliged to carry out its processing activities in accordance with the contractual terms existing between us, and with the applicable legal requirements.

    Data transfer:

    An enquiry related to a particular hotel is forwarded to the relevant Ensana group member operating the respective hotel.

    2.14

    Complaint management record

    During the management of a consumer complaint, if you do not agree with the way the complaint has been handled, or if it is not possible to investigate the complaint promptly, the respective company is obliged to draft, without delay, a report on the complaint and, if it has been able to formulate one, its position regarding it.

    The report must contain the following data:

    •  The consumer’s name and address

    •  The place, time and mode of submitting the complaint

    •  A detailed description of the consumer’s complaint, a list of receipts, documents and other items of evidence provided by the consumer

    •  A statement by the respective company on its position regarding the consumer’s complaint, if a prompt investigation of the complaint is possible

    •  The signature of the person who took down the report and – except for verbal complaints made over the phone or by email – the signature of the consumer

    •  The place and time the report was taken down

    •  In the case of a verbal complaint made over the phone or by email, the unique reference number of the complaint

    Purpose of the data processing:

    Investigation of the complaint and maintaining contact with the complainant.

    Legal basis of the data processing:

    Fulfilling a legal obligation in accordance with the relevant consumer protection regulations to deal with customer complaints or claims.[GDPR Article 6(1)(c)]

    Period of the data processing:

    Three years from the time that the report was taken down.

    If you wish to exercise any of your rights referred to in section 1 in relation to the data thus recorded, or you wish to contact us for any other reason, please let us know by sending an email to [email protected].

    2.15

    Maintaining contact with business clients

    Maintaining contact with business clients

    Like most companies, Ensana maintains a business relationship with certain employees of other organisations, whose names, job position and contact details we store.

    Purpose of the data processing:

    In all cases, such data storage is carried out with the consent of the person concerned, so that our companies can communicate for the purpose of co-operation.

    Legal basis of the data processing:

    The legal basis of our data processing activity is our legitimate interest associated with the performance of the contract or with maintaining contact between the companies [GDPR Article 6(1)(f)].

    Period of the data processing:

    We check the contact information of our business contacts at least once a year and remove those that are no longer up-to-date from the system.

    We apply the same procedure when processing the personal data of press contacts.

    2.16

    Customers’ book (complaints book)

    Purpose of the data processing:

    Providing a customers’ book is a legal obligation.

    Legal basis of the data processing:

    Fulfilment of a legal obligation. Retention is necessary due to the consumer protection laws. Providing the data is a precondition for being able to respond. [GDPR Article 6(1)(c)].

    Period of the data processing:

    Entries are kept for 3 years.

    If you wish to exercise any of your rights referred to in section 1 in relation to the data thus recorded, or you wish to contact us for any other reason, please let us know by sending an email to [email protected].

    2.17

    Wi-Fi

    If you use wireless internet in our hotels, we must record the following data:

    • date and start and end time of use,

    • source IP address, source MAC address, target IP address (+ target port)

    Purpose of the data processing:

    The purpose of the data processing is to ensure the availability of services while you are using Wi-Fi, to monitor your departure, to handle complaints and to detect fraud or abuse.

    Legal basis of the data processing:

    The legal basis for processing the data is “performance of a contract”, given that achieving Wi-Fi is one of the services provided by our hotel [Article 6(1)(b) GDPR]. However, after your departure, the legal basis is the legitimate interest of the controller related to the handling of complaints and the detection of fraud or abuse [Article 6(1)(f) GDPR]. The provision of your data is a necessary condition for the use of the services.

    Period of the data processing:

    The data will be kept for 1 year.

    Specific rules may apply depending on the country in which your data will be processed (see section 3 for details).

    If you wish to exercise any of your rights referred to in section 1 in relation to the data thus recorded, or you wish to contact us for any other reason, please let us know by sending an email to [email protected].

    2.18

    Prize draws, competitions

    Ensana itself, or in cooperation with another member of the Ensana group or an external company, occasionally organises prize draws or competitions. Entrants can enter prize draws or competitions via paper or online registration (on the Ensana Hotels website or Facebook page), where the following details will usually be requested:

    - Name

    - Address

    - Telephone number

    - Email address

    In certain circumstances, it will not be necessary to provide this data (e.g. in the case of a prize draw on Facebook) or, on the contrary, it will be required; thus, the scope of the data may vary.

    Purpose of data processing:

    Organising prize draws, competitions, keeping in touch so that the company can hand over the prize to the winner.

    Legal basis for data processing:

    Processing necessary for the performance of the terms of the competition or your consent [Article 6(1)(a) GDPR]. You can withdraw your consent at any time by sending an email to [email protected] or by sending a letter to the above address. Withdrawal of consent will not affect processing prior to withdrawal of consent.

    Your consent is required to enter any prize draw or competition.

    Retention period of personal data:

    The processing of data will be carried out until the end of the prize draw/contest, within 30 days from the date of the event, data processed in this context will be deleted (with the exception of data on the winner(s) and alternate winner(s)). Data on the winner(s) and alternate winner(s) will be retained by the company for a period of 10 years in accordance with the provisions of the applicable tax and accounting regulations, and will be deleted after this period.

    Information on data transfer and data processors and details of data processing that differ from the information set out in this Privacy Policy will always be provided during the competition or prize draw.

    If you wish to exercise any of your rights referred to in section 1 in relation to the data thus recorded, or you wish to contact us for any other reason, please let us know by sending an email to [email protected].

    2.19

    Danubius Gift Card, Ensana Value Voucher

    Both the Danubius Gift Card and the Ensana Gift Card are vouchers/gift cards that can currently be spent on services offered by Ensana and Danubius hotels.

    The Danubius Gift Card is a gift card designed primarily for visitors to Danubius hotels and can no longer be purchased or used at Ensana hotels.

    The Ensana Gift Card is a new voucher offered to customers of Ensana hotels that offers a wide range of personalisation options (in terms of value, layout, personalised messages, etc.).

    Scope of data:

    When purchasing a Danubius Gift Card or an Ensana Value Voucher (voucher), you will be asked to provide the following personal data:

    In the case of a personal purchase:

    - Name

    - Billing name and address

    In the case of an online order via the company's official website:

    - Name

    - Email address

    - Phone number

    - Billing name and address

    - Delivery address and name & other information regarding the gift card or voucher (e.g. dedication, format of the voucher, etc.).

    More information can be found at Danubius’ and Ensana’s websites.

    Purpose of data processing:

    To manage the contract for the delivery of gift cards or vouchers, cheques and for invoicing.

    Legal basis for data processing:

    Performance of the contract concluded for the delivery of the gift card or voucher. The provision of this data is necessary for the provision of the service [Article 6(1)(b) GDPR].

    Retention period:

    The personal data collected in this way will be retained for period stipulated by the provisions of the applicable tax and accounting regulations (usually 10 years).

    Processor:

    Your personal data will be processed by Virtual Zoom s.r.o., our data processor, which is responsible for the operation of the relevant booking system and which is bound by a data processing contract in accordance with applicable law.

    If you wish to exercise any of your rights referred to in section 1 in relation to the data thus recorded, or you wish to contact us for any other reason, please let us know by sending an email to [email protected].

    3

    მონაცემთა დამუშავების დებულებები / აქტივობები უნგრეთსა და ჩეხეთის რესპუბლიკაში მდებარე „Ensana“-ს სასტუმროების შემთხვევაში.

    3.1

    მონაცემთა დამუშავების დებულებები / აქტივობები უნგრეთსა და ჩეხეთის რესპუბლიკაში მდებარე „Ensana“-ს სასტუმროების შემთხვევაში.

    ი, ტექსტის სრული და იურიდიულად გამართული თარგმანი. შევინარჩუნე ჩეხური კანონების ზუსტი დასახელებები, მუხლები და ვადები, რაც დოკუმენტის ამ ნაწილში ყველაზე კრიტიკული და მნიშვნელოვანია:

    გთხოვთ გაითვალისწინოთ ქვემოთ მოყვანილი სპეციალური წესები, თუ თქვენი პერსონალური მონაცემების დამუშავება რეგულირდება ჩეხეთის კანონმდებლობით (კერძოდ, თუ ხართ ჩეხეთის რესპუბლიკაში მდებარე სასტუმროს სტუმარი):

    საკონტაქტო ინფორმაცია:

    • ელ-ფოსტა: [email protected]
    • საკორესპონდენციო მისამართი: Ensana s.r.o., Senovážné náměstí 992/8, 110 00 Praha 1
    • მარიანსკე ლაზნეში (Mariánské Lázně) განთავსებასთან დაკავშირებული კითხვების შემთხვევაში, ასევე შეგიძლიათ პირდაპირ დაუკავშირდეთ: Léčebné lázně Mariánské Lázně a.s. Masarykova 22, 353 29 – Mariánské Lázně, Czech Republic

    საზედამხედველო ორგანო:

    • პერსონალურ მონაცემთა დაცვის ოფისი (Office for Personal Data Protection) Pplk. Sochora 727/27, 170 00 Prague, Holešovice, Czech Republic ტელეფონი: +420 234 665 111 ელ-ფოსტა: [email protected]ვებგვერდი: www.uoou.cz

    სასამართლო დაცვის ეფექტური საშუალების უფლება:

    ჩეხეთის რესპუბლიკაში სარჩელის განხილვა შედის რაიონული სასამართლოების იურისდიქციაში. მონაცემთა სუბიექტის არჩევანით, სარჩელი შეიძლება აღიძრას მონაცემთა სუბიექტის მუდმივი საცხოვრებელი მისამართის მიხედვით არსებულ რაიონულ სასამართლოში. GDPR-ის დებულებების გარდა, გამოიყენება სამოქალაქო კოდექსის, სამოქალაქო საპროცესო კოდექსის, ისევე როგორც სასამართლო წარმოებასთან დაკავშირებული სხვა სამართლებრივი აქტების დებულებები.

    იმ ძირითადი საკანონმდებლო აქტების სია, სადაც დამუშავების სამართლებრივ საფუძველს წარმოადგენს ჩვენი კანონისმიერი ვალდებულებების შესრულება:

    თქვენს ჯავშანთან (სექცია 2.1.) და განთავსებასთან (სექცია 2.2.) დაკავშირებით, ან ხელშეკრულების დადებასა და საგადასახადო დოკუმენტების გამოწერასთან დაკავშირებით (ასევე სექციები 2.4, 2.11.), ჩვენ ვალდებულნი ვართ დავამუშაოთ თქვენი პერსონალური მონაცემები, კერძოდ, შემდეგი აქტებით გათვალისწინებული ვალდებულებების შესასრულებლად:

    • კანონი № 563/1991 კრებულში (Coll.), „ბუღალტრული აღრიცხვის შესახებ“ და საგადასახადო რეგულაციები, კერძოდ, კანონი № 235/2004 კრებულში „დამატებული ღირებულების გადასახადის შესახებ“ — ბუღალტრული აღრიცხვისა და საგადასახადო დოკუმენტების გამოწერის მიზნით;
    • კანონი № 326/1999 კრებულში, „უცხოელთა ცხოვრების შესახებ“ — კერძოდ, საცხოვრებელი სახლის რეესტრის წარმოებისა და პირთა განთავსების შესახებ შეტყობინების მიზნით;
    • კანონი № 565/1990 კრებულში, „ადგილობრივი გადასახადების შესახებ“ — კერძოდ, სტუმართა რეესტრის წარმოების მიზნით.

    ჯანდაცვის მომსახურების გაწევასთან დაკავშირებით (სექცია 2.3.), ჩვენ ვალდებულნი ვართ დავამუშაოთ თქვენი პერსონალური მონაცემები, კერძოდ, შემდეგი აქტით გათვალისწინებული ვალდებულებების შესასრულებლად:

    • კანონი № 372/2011 კრებულში, „ჯანდაცვის მომსახურების გაწევის შესახებ“ — კერძოდ, ჯანდაცვის მომსახურების ჯეროვნად გაწევისა და სამედიცინო ჩანაწერების წარმოების მიზნით.

    ხელშეკრულებების შესრულებასა და მომხმარებელთა უფლებების დაცვის უზრუნველყოფასთან დაკავშირებულ საკითხებში (სექციები 2.1, 2.11, 2.14, 2.16), ჩვენ ვალდებულნი ვართ დავამუშაოთ თქვენი პერსონალური მონაცემები, კერძოდ, შემდეგი აქტებით გათვალისწინებული ვალდებულებების შესასრულებლად:

    • კანონი № 89/2012 კრებულში, „სამოქალაქო კოდექსი“;
    • კანონი № 634/1992 კრებულში, „მომხმარებელთა უფლებების დაცვის შესახებ“.

    მონაცემთა შენახვის/დამუშავების ვადები ზემოაღნიშნული სამართლებრივი ვალდებულებების შესრულებისას:

    • თუ ჩვენ ვალდებულნი ვართ შევინახოთ თქვენი მონაცემები სტუმრების კანონისმიერი აღრიცხვის მიზნით (კანონები № 565/1990 და № 326/1999), ვალდებულნი ვართ შევინახოთ თქვენი მონაცემები ბოლო რეგისტრაციიდან 6 წლის განმავლობაში.
    • თუ ინფორმაცია წარმოადგენს საგადასახადო დოკუმენტების აუცილებელ ნაწილს, კანონით ვალდებულნი ვართ შევინახოთ ეს მონაცემები კალენდარული წლის დასრულებიდან 10 წლის განმავლობაში (კანონის № 235/2004 შესაბამისად). სხვა ბუღალტრული დოკუმენტების შემთხვევაში (კანონი № 563/1991), ვალდებულნი ვართ შევინახოთ ისინი 5 წლის ვადით.
    • სამედიცინო ჩანაწერებს ვინახავთ 10 წლის განმავლობაში ან ჯანდაცვის სამინისტროს № 444/2024 განკარგულებით (სამედიცინო ჩანაწერების შესახებ, შეტანილი ცვლილებებით) განსაზღვრული ნებისმიერი სხვა ვადით.
    • მომხმარებელთა უფლებების დაცვის ვალდებულების შემთხვევაში, ჩვენ ვინახავთ თქვენს მონაცემებს ხანდაზმულობის ვადის განმავლობაში (ზოგადი ხანდაზმულობის ვადა შეადგენს 3 წელს).

    მონაცემთა გადაცემა ზემოაღნიშნული სამართლებრივი ვალდებულებების შესრულებისას:

    • იმ შემთხვევაში, თუ თქვენ ხართ უცხოელი ჩეხეთის რესპუბლიკაში, თქვენი პერსონალური მონაცემები გადაეცემა უცხოელთა პოლიციას (foreign police) № 326/1999 კანონით გათვალისწინებული ვალდებულებების შესასრულებლად.
    • სამედიცინო ჩანაწერებიდან მონაცემების ნებისმიერი გაცნობა (კონსულტაცია) და გადაცემა შესაძლებელია მხოლოდ № 372/2011 კანონის პირობების შესაბამისად, მაგალითად, 65-ე მუხლისა და სამედიცინო ჩანაწერების შემოწმების წესების დაცვით.
    3.2

    მონაცემთა დამუშავების დებულებები / აქტივობები უნგრეთში მდებარე „Ensana“-ს სასტუმროების შემთხვევაში

    ინფორმაცია მონაცემთა დამუშავების დებულებების / აქტივობების შესახებ უნგრეთში მდებარე „Ensana“-ს სასტუმროების შემთხვევაში ხელმისაწვდომია.here.

    4

    ავტომატურად ჩაწერილი მონაცემები, ქუქი-ფაილები და კოდები

    დეტალური ინფორმაცია მოცემულია ქვემოთ:

    4.1

    ავტომატურად ჩაწერილი მონაცემები

    მონაცემთა მოცულობა: როდესაც ჩვენს ვებგვერდს ხსნით რომელიმე მოწყობილობით (მაგალითად, ლეპტოპით ან პერსონალური კომპიუტერით, სმარტფონით ან პლანშეტით), ამ მოწყობილობის გარკვეული მონაცემები ავტომატურად ჩაიწერება. ავტომატურად ჩაწერილ მონაცემებში შედის: თქვენი მოწყობილობის IP მისამართი, ჩვენს ვებგვერდზე თქვენი ვიზიტის თარიღი და დრო, ბრაუზერის ტიპი, ასევე თქვენი ინტერნეტ პროვაიდერის დომენის სახელი და მისამართი. ჩაწერილი მონაცემები ავტომატურად აღირიცხება ვებგვერდის სერვერის მიერ, თქვენი თანხმობის ან რაიმე მიზნობრივი მოქმედების გარეშე. სისტემა იყენებს ჩაწერილ მონაცემებს სტატისტიკური მონაცემების ავტომატურად გენერირებისთვის. ეს მონაცემები არ შეიძლება ასოცირებულ/დაკავშირებულ იქნეს სხვა პერსონალურ მონაცემებთან, გარდა იმ შემთხვევებისა, როდესაც ამგვარი კავშირი კანონით არის გათვალისწინებული. ეს მონაცემები გამოყენებული იქნება ექსკლუზიურად აგრეგირებული (შეჯამებული) და დამუშავებული ფორმით, შეცდომების გამოსასწორებლად, ჩვენი მომსახურების ხარისხის გასაუმჯობესებლად და სტატისტიკური მიზნებისთვის.

    მონაცემთა დამუშავების მიზანი: საინფორმაციო (აიტი) სისტემის ტექნიკური განვითარება, მომსახურების მონიტორინგი და სტატისტიკური მონაცემების გენერირება. თაღლითური და სხვა დანაშაულებრივი ქმედებების შემთხვევაში, ეს მონაცემები ასევე შეიძლება გამოყენებულ იქნეს — მომხმარებლის ინტერნეტ პროვაიდერთან და სამართალდამცავ ორგანოებთან თანამშრომლობით — ამგვარი თაღლითური საქმიანობის წყაროს დასადგენად.

    მონაცემთა დამუშავების სამართლებრივი საფუძველი: ხელშეკრულების შესრულების აუცილებლობა (მოთხოვნილი მომსახურების გაწევა) და საინფორმაციო საზოგადოების გარკვეული მომსახურებების მიწოდებასთან დაკავშირებული სამართლებრივი ვალდებულებების შესრულება.

    მონაცემთა დამუშავების ვადა: ჩვენი ვებგვერდის გახსნიდან 30 დღე.

    4.2

    ქუქი-ფაილები და მსგავსი ტექნოლოგიები

    ქუქი-ფაილები (Cookies)

    ეს ვებგვერდი იყენებს ქუქი-ფაილებს.

    ქუქი-ფაილები ვებგვერდებს მომხმარებლებისთვის უფრო მოსახერხებელსა და ეფექტურს ხდის. ქუქი-ფაილი არის მცირე ზომის ტექსტური ფაილი, რომელიც გამოიყენება ინფორმაციის შესანახად. როდესაც სტუმრობთ ვებგვერდს, ამ ვებგვერდს შეუძლია განათავსოს ქუქი-ფაილი თქვენს კომპიუტერში. თუ მოგვიანებით კვლავ ეწვევით ამავე გვერდს, მას შეუძლია წაიკითხოს ქუქი-ფაილში შენახული ინფორმაცია და გაიგოს, მაგალითად, ნამყოფი ხართ თუ არა აქ ადრე და ვებგვერდის რომელი სექციები გაინტერესებთ განსაკუთრებით.

    ქუქი-ფაილების პარამეტრების შეცვლა

    ვებ-ბრაუზერის პარამეტრები განსაზღვრავს, თუ როგორ ეპყრობა ბრაუზერი ქუქი-ფაილებს და რომელი მათგანია ნებადართული ან აკრძალული. ამ პარამეტრების შეცვლა შესაძლებელია. ის, თუ როგორ და სად ხდება ამ ცვლილებების შეტანა, დამოკიდებულია კონკრეტულ ბრაუზერზე. ქუქი-ფაილების პარამეტრების შეცვლის შესახებ მეტის გასაგებად გამოიყენეთ თქვენი ბრაუზერის ფუნქცია „დახმარება“ (Help).

    გაითვალისწინეთ, რომ ქუქი-ფაილების გამოყენების შეზღუდვამ შესაძლოა გამოიწვიოს ის, რომ ამ ვებგვერდის ყველა ფუნქცია სრულყოფილად ვერ იმუშავებს.

    ჩვენს ვებგვერდზე არსებული ქუქი-ფაილების, თითოეული კატეგორიის პარამეტრების შეცვლისა და თანხმობის მიცემის/გაუქმების შესახებ დამატებითი ინფორმაციისთვის, გთხოვთ, იხილოთ ქუქი-ფაილების პანელი (cookie bar). ეს პანელი ჩნდება ვებგვერდზე თქვენი პირველი ვიზიტისას, ასევე მისი ნახვა შესაძლებელია ეკრანის ქვედა მარცხენა კუთხეში არსებულ მომჭერის (clip) ხატულაზე დაწკაპუნებით.

    ქუქი-ფაილები ჩვენს ვებგვერდზე

    ჩვენი ვებგვერდი იყენებს შემდეგ პროვაიდერებს:

    • ჩვენი ვებგვერდი: ქუქი-ფაილების გამოყენებაზე თქვენი თანხმობის შესანახად.
    • Google: Google-ის ვებ-სტატისტიკის პროგრამა Google Analytics-თან დაკავშირებული მომხმარებლის მონაცემების შესანახად. დამატებითი ინფორმაციისთვის ეწვიეთ Google Analytics-ს.
    • Facebook: Facebook Pixel-თან დაკავშირებული მომხმარებლის მონაცემების შესანახად. დამატებითი ინფორმაციისთვის ეწვიეთ Facebook Developer-ს და გაეცანით ინფორმაციას Facebook-ის ქუქი-ფაილების შესახებ.
    • Microsoft Clarity: Microsoft Clarity-სთან დაკავშირებული მომხმარებლის მონაცემების შესანახად. დეტალებისთვის გაეცანით Microsoft Clarity-ს ინფორმაციას ქუქი-ფაილების შესახებ.

    სერვერის ლოგ-ფაილები (Server Log Files)

    ტექნიკური მონიტორინგისა და უსაფრთხოების გაზრდის მიზნით, ეს ვებგვერდი სერვერის ლოგ-ფაილში ამუშავებს შემდეგ პერსონალურ მონაცემებს. ეს დამუშავება ეფუძნება პასუხისმგებელი პირის/კომპანიის უპირატესი ინტერესის პრინციპს (ტექნიკური უსაფრთხოების ზომები):

    • IP მისამართი
    • გვერდი, საიდანაც მოხდა ფაილზე წვდომა („referrer URL“)
    • ფაილის დასახელება
    • ფაილზე წვდომის თარიღი და დრო („დროის შტამპი“)
    • გადაცემული მონაცემების მოცულობა
    • წვდომის სტატუსი (ფაილი გადაიგზავნა, ფაილი ვერ მოიძებნა და ა.შ.)
    • გამოყენებული ვებ-ბრაუზერის ტიპი (მაგ. Mozilla Firefox, Google Chrome, Microsoft Internet Explorer, Microsoft Edge, Apple Safari, Opera და ა.შ.)

    ეს მონაცემები პერსონალიზებული ფორმით ინახება მხოლოდ დროებით, 7 დღის ვადით. ამის შემდეგ ლოგ-ფაილები იშლება.

    Google Analytics

    ეს ვებგვერდი იყენებს Google Analytics-ს, ვებ-ანალიტიკის სერვისს, რომელსაც მართავს Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; „Google“). Google Analytics ეფუძნება უპირატესი ლეგიტიმური ინტერესის სამართლებრივ პრინციპს (ვებგვერდის გამოყენების ანალიზი). ამ მიზნით, ჩვენ დავდეთ ხელშეკრულება Google-თან მონაცემთა სახელშეკრულებო დამუშავების შესახებ.

    ჩვენს ვებგვერდზე თქვენი ვიზიტისას, პროგრამული უზრუნველყოფა ამყარებს კავშირს Google-ის სერვერებთან და მონაცემები იგზავნება ამ სერვერებზე, რომელთაგან ზოგიერთი მდებარეობს აშშ-ში. Google Analytics ასევე იყენებს ქუქი-ფაილებს ვებგვერდის მომხმარებლის შესახებ ინფორმაციის შესანახად და იმის გასაანალიზებლად, თუ როგორ იყენებენ ვიზიტორები ამ გვერდს.

    ეს ვებგვერდი იყენებს ფუნქციას „IP ანონიმიზაციის გააქტიურება“. ეს ნიშნავს, რომ ევროკავშირის წევრ ქვეყნებსა და ევროპული ეკონომიკური ზონის ქვეყნებში თქვენი IP მისამართი შემოკლდება. მხოლოდ გამონაკლის შემთხვევებში მოხდება სრული IP მისამართის გაგზავნა Google-ის სერვერზე აშშ-ში და მისი იქ შემოკლება.

    Google-ის თანახმად, ეს მონაცემები გამოიყენება ვებგვერდის გამოყენების გასაანალიზებლად, ვებგვერდის აქტივობის შესახებ რეპორტების შესადგენად და ვებგვერდისა და ინტერნეტის გამოყენებასთან დაკავშირებული დამატებითი სერვისების მისაწოდებლად.

    Google-მა შესაძლოა ეს ინფორმაცია გადასცეს მესამე პირებსაც, თუ ეს კანონით არის მოთხოვნილი, ან თუ მესამე პირს დავალებული აქვს მონაცემთა დამუშავება Google-ის სახელით.

    Google Analytics-ის მიერ მონაცემთა გამოყენების შესახებ დეტალური ინფორმაციისთვის, გთხოვთ, გაეცნოთ Google-ისა და Google Analytics-ის მონაცემთა დაცვის დეკლარაციას.

    Google Analytics Remarketing (რემარკეტინგი)

    ჩვენი ვებგვერდები იყენებენ Google Analytics Remarketing-ის ფუნქციებს Google AdWords-ისა და DoubleClick-ის სხვადასხვა მოწყობილობებს შორის (cross-device) თავსებადობის შესაძლებლობებთან კომბინაციაში. ამ სერვისს გვაწვდის Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland).

    ეს ფუნქცია საშუალებას იძლევა, Google Analytics Remarketing-ით შექმნილი სარეკლამო მარკეტინგის სამიზნე აუდიტორიები დაუკავშირდეს Google AdWords-ისა და Google DoubleClick-ის cross-device შესაძლებლობებს. ეს იძლევა საშუალებას, თქვენს პერსონალურ ინტერესებზე დაფუძნებული რეკლამა, რომელიც იდენტიფიცირებულია ერთი მოწყობილობიდან (მაგ. მობილური ტელეფონიდან) თქვენი წინა აქტივობისა და ინტერნეტში ნავიგაციის ქცევის საფუძველზე, გამოჩნდეს სხვა მოწყობილობებზეც (როგორიცაა პლანშეტი ან კომპიუტერი).

    თქვენი თანხმობის მიცემის შემდეგ, Google ამ მიზნით დაუკავშირებს თქვენი ვებ-გვერდებისა და აპლიკაციების ბრაუზინგის ისტორიას თქვენს Google ანგარიშს. ამგვარად, ნებისმიერ მოწყობილობას, სადაც შეხვალთ თქვენი Google ანგარიშით, შეუძლია გამოიყენოს იგივე პერსონალიზებული სარეკლამო შეტყობინებები.

    ამ ფუნქციის მხარდასაჭერად, Google Analytics აგროვებს მომხმარებელთა Google-ის მიერ ავტორიზებულ ID-ებს, რომლებიც დროებით უკავშირდება ჩვენს Google Analytics-ის მონაცემებს, რათა განისაზღვროს და შეიქმნას აუდიტორიები მოწყობილობებს შორის რეკლამის პოპულარიზაციისთვის.

    თქვენ შეგიძლიათ სამუდამოდ უარი თქვათ მოწყობილობებს შორის რემარკეტინგზე/ტარგეტირებაზე თქვენს Google ანგარიშში პერსონალიზებული რეკლამის გამორთვით; მიჰყევით ამ ბმულს.

    თქვენს Google ანგარიშში შეგროვებული მონაცემების აგრეგაცია ეფუძნება მხოლოდ თქვენს თანხმობას, რომელიც შეგიძლიათ მისცეთ ან გაუუქმოთ Google-ს GDPR-ის მე-6 მუხლის (1)(a) პუნქტის შესაბამისად. იმ მონაცემთა შეგროვების ოპერაციებისთვის, რომლებიც არ არის გაერთიანებული თქვენს Google ანგარიშში (მაგალითად, იმიტომ, რომ არ გაქვთ Google ანგარიში ან უარი თქვით გაერთიანებაზე), მონაცემთა შეგროვება ეფუძნება GDPR-ის მე-6 მუხლის (1)(f) პუნქტს. ვებგვერდის ოპერატორს აქვს ლეგიტიმური ინტერესი, გააანალიზოს ანონიმური მომხმარებლის ქცევა სარეკლამო მიზნებისთვის.

    დამატებითი ინფორმაციისთვის გაეცანით Google-ის კონფიდენციალურობის პოლიტიკას.

    Google Analytics-ის დეაქტივაცია

    • შესაძლებელია არ მისცეთ ჩვენს ვებგვერდს თქვენი მომხმარებლის მონაცემების შეგროვების უფლება თქვენს ვებ-ბრაუზერში ფუნქციის „Do Not Track“ (არ მიადევნო თვალი) გააქტიურებით. ამ შემთხვევაში თქვენი ბრაუზერი გაუგზავნის „Do Not Track“ სიგნალს ყველა ვებგვერდს, მათ შორის ჩვენსას.
    • თქვენ შეგიძლიათ ყველანაირ ვებგვერდს აუკრძალოთ თქვენი მონაცემების შეგროვება შემდეგი გაფართოების ჩამოტვირთვით და თქვენს კომპიუტერში დაინსტალირებით: ბრაუზერის გაფართოების ჩამოტვირთვა.
    • თქვენ შეგიძლიათ აუკრძალოთ მხოლოდ ჩვენს ვებგვერდს თქვენი მონაცემების შეგროვება Google Analytics-ის საშუალებით შემდეგ ბმულზე დაწკაპუნებით. ეს თქვენს კომპიუტერში განათავსებს უარის თქმის (opt-out) ქუქი-ფაილს, რომელიც ხელს შეუშლის თქვენი მონაცემების შეგროვებას ამ ვებგვერდზე ხელახლა სტუმრობისას. Google Analytics-ის დეაქტივაცია.

    Google Analytics Google Signals

    ჩვენ გავააქტიურეთ Google signals Google Analytics-ში. ეს ანახლებს Google Analytics-ის არსებულ ფუნქციებს (სარეკლამო რეპორტები, რემარკეტინგი, მოწყობილობებს შორის რეპორტები, ასევე ინტერესებისა და დემოგრაფიული რეპორტები), რათა მოგვაწოდოს თქვენი აგრეგირებული და ანონიმიზებული მონაცემები, იმ პირობით, თუ თქვენს Google ანგარიშში ჩართული გაქვთ პერსონალიზებული რეკლამები.

    ამ ფუნქციის განსაკუთრებულობა იმაში მდგომარეობს, რომ ის წარმოადგენს მოწყობილობებს შორის თრექინგს (cross-device tracking). ეს ნიშნავს, რომ თქვენი მონაცემების გაანალიზება შესაძლებელია სხვადასხვა მოწყობილობაზე. Google signals-ის ჩართვით, მონაცემები გროვდება და უკავშირდება Google ანგარიშს. ამგვარად, Google-ს შეუძლია ამოიცნოს, მაგალითად, თუ თქვენ ნახულობთ ჩვენს ვებგვერდს სმარტფონით, ხოლო ჯავშანს მოგვიანებით აკეთებთ ლეპტოპიდან. Google signals-ის გააქტიურების წყალობით, ჩვენ შეგვიძლია გავუშვათ cross-device რემარკეტინგული კამპანიები, რაც სხვაგვარად ამ ფორმით შეუძლებელი იქნებოდა. რემარკეტინგი ნიშნავს, რომ ჩვენ შეგვიძლია ჩვენი შეთავაზებები სხვა ვებგვერდებზეც გიჩვენოთ.

    Google Analytics-ში Google signals ასევე აგროვებს ვიზიტორთა სხვა მონაცემებს, როგორიცაა ადგილმდებარეობა, ძიების ისტორია, YouTube-ის ისტორია და მონაცემები ჩვენს ვებგვერდზე თქვენი მოქმედებების შესახებ. ეს გვაძლევს უკეთეს სარეკლამო რეპორტებს Google-ისგან და უფრო სასარგებლო ინფორმაციას თქვენი ინტერესებისა და დემოგრაფიის შესახებ. ეს მოიცავს თქვენს ასაკს, რა ენაზე საუბრობთ, სად ცხოვრობთ ან რა სქესის ხართ. გარდა ამისა, ემატება სოციალური კრიტერიუმებიც, როგორიცაა თქვენი პროფესია, ოჯახური მდგომარეობა ან შემოსავალი. ყველა ეს მახასიათებელი ეხმარება Google Analytics-ს ადამიანთა ჯგუფების ან სამიზნე აუდიტორიების განსაზღვრაში.

    ეს რეპორტები ასევე გვეხმარება უკეთ შევაფასოთ თქვენი ქცევა, სურვილები და ინტერესები. ეს საშუალებას გვძლევს მოვახდინოთ ჩვენი სერვისებისა და პროდუქტების ოპტიმიზაცია და თქვენზე მორგება. ნაგულისხმევი პარამეტრით, ამ მონაცემების ვადა გადის 26 თვის შემდეგ. გთხოვთ გაითვალისწინოთ, რომ მონაცემთა ეს შეგროვება ხდება მხოლოდ იმ შემთხვევაში, თუ თქვენს Google ანგარიშში ნებადართული გაქვთ პერსონალიზებული რეკლამა. ეს ყოველთვის არის აგრეგირებული და ანონიმური მონაცემები და არასდროს წარმოადგენს კონკრეტული ფიზიკური პირის მონაცემებს. თქვენს Google ანგარიშში თქვენ შეგიძლიათ მართოთ ეს მონაცემები ან წაშალოთ ისინი.

    Facebook Pixel

    ეს ვებგვერდი იყენებს Facebook Pixel-ს, ვებ-ანალიტიკის სერვისს, რომელსაც მართავს Facebook Ireland Limited (4 Grand Canal Square, Dublin 2, Ireland; „Facebook“) უპირატესი ლეგიტიმური ინტერესის სამართლებრივი პრინციპის საფუძველზე (ვებგვერდის გამოყენების ანალიზი). ჩვენ დავდეთ ხელშეკრულება Facebook-თან მონაცემთა სახელშეკრულებო დამუშავების შესახებ. ზოგიერთ შემთხვევაში მონაცემები გადაიცემა აშშ-ში. მონაცემთა ეს გადაცემა აშშ-ში ხორციელდება Privacy Shield-ის (კონფიდენციალურობის ფარის) საფუძველზე.

    ჩვენს ვებგვერდზე სტუმრობისას, პროგრამული უზრუნველყოფა ამყარებს კავშირს Facebook-ის სერვერებთან და აგზავნის მონაცემებს ამ სერვერებზე, რომელთაგან ზოგიერთი მდებარეობს აშშ-ში. Facebook Pixel ასევე იყენებს ქუქი-ფაილებს ვებგვერდის მომხმარებლის შესახებ ინფორმაციის შესანახად და იმის გასაანალიზებლად, თუ როგორ იყენებს მომხმარებელი ვებგვერდს.

    Facebook-ის თანახმად, ეს მონაცემები გამოიყენება ვებგვერდის გამოყენების გასაანალიზებლად, ვებგვერდის აქტივობის შესახებ რეპორტების შესადგენად და ვებგვერდისა და ინტერნეტის გამოყენებასთან დაკავშირებული დამატებითი სერვისების მისაწოდებლად.

    Facebook-მა შესაძლოა ეს ინფორმაცია გადასცეს მესამე პირებსაც, თუ ეს კანონით არის მოთხოვნილი, ან თუ მესამე პირს დავალებული აქვს მონაცემთა დამუშავება Facebook-ის სახელით.

    ჩვენ ვიყენებთ Facebook Custom Audience-ს, ისევე როგორც Facebook-ის მიერ შემოთავაზებულ სხვა ინსტრუმენტებს ისეთ ვებგვერდებზე რეკლამირებისთვის, როგორიცაა Facebook. ამის გასაკეთებლად, ჩვენ ვუზიარებთ თქვენს მონაცემებს ისეთ პროვაიდერებს, როგორიცაა Facebook, და ვიყენებთ ქუქი-ფაილებსა და მსგავს ტექნოლოგიებს ჩვენს ვებგვერდზე, რათა გავაანალიზოთ, რამდენად ეფექტურია ჩვენი რეკლამები ამ მესამე მხარის პლატფორმებზე.

    Facebook-ის მიერ მონაცემთა გამოყენების შესახებ დეტალური ინფორმაციისთვის, გთხოვთ, გაეცნოთ Facebook-ის მონაცემთა დაცვის დეკლარაციას.

    Facebook Pixel-ის დეაქტივაცია

    • შესაძლებელია არ მისცეთ ჩვენს ვებგვერდს თქვენი მომხმარებლის მონაცემების შეგროვების უფლება თქვენს ვებ-ბრაუზერში ფუნქციის „Do Not Track“ გააქტიურებით. ამ შემთხვევაში თქვენი ბრაუზერი გაუგზავნის „Do Not Track“ სიგნალს ყველა ვებგვერდს, მათ შორის ჩვენსას.
    • თქვენ შეგიძლიათ აუკრძალოთ ამ ვებგვერდს თქვენი მონაცემების შეგროვება Facebook Pixel-ის საშუალებით შემდეგ ბმულზე დაწკაპუნებით. ეს თქვენს კომპიუტერში განათავსებს უარის თქმის (opt-out) ქუქი-ფაილს, რომელიც ხელს შეუშლის თქვენი მონაცემების შეგროვებას ამ ვებგვერდზე ხელახლა სტუმრობისას. Facebook Pixel-ის დეაქტივაცია.

    გაზიარების ღილაკები („Share“-Buttons)

    ჩვენი ვებგვერდის ზოგიერთ გვერდს აქვს ღილაკები, რომლებიც მომხმარებლებს საშუალებას აძლევს გააზიარონ კონტენტი სოციალური მედიის პლატფორმებზე, როგორიცაა Facebook, Google Plus, Instagram, LinkedIn, Pinterest, Tumblr, Twitter, XING და YouTube.

    ეს ღილაკები შექმნილია პერსონალური მონაცემების დასაცავად. სკრიპტი (კომპიუტერული პროგრამა), რომელიც ამ ღილაკების მიღმა დგას, არ აგროვებს და არ ამუშავებს პერსონალურ მონაცემებს. დეტალური ინფორმაცია ამ ღილაკების ფუნქციონირების შესახებ ხელმისაწვდომია Heise Verlag-ისგან — კომპანიისგან, რომელიც გამოსცემს IT ჟურნალს c’t და ასევე პასუხისმგებელია ამ ღილაკების შემუშავებაზე.

    ვებგვერდის ვიზიტორებს, რომლებსაც სურთ ჩვენი ვებგვერდის გაზიარება, შეუძლიათ დააწკაპუნონ ერთ-ერთ ამ ღილაკზე. ისინი გადამისამართდებიან შესაბამისი სოციალური მედიის პლატფორმის „გაზიარების“ გვერდზე. მხოლოდ იქ ჩაიტვირთება ის სკრიპტები, რომლებიც საჭიროა ვებგვერდის კონტენტის გასაზიარებლად. ინფორმაციის ამგვარ გაზიარებაზე ვრცელდება შესაბამისი სოციალური მედიის პლატფორმის წესები და პირობები, ისევე როგორც მონაცემთა დაცვის დებულებები. დამატებითი ინფორმაციისთვის ეწვიეთ Facebook, Google Plus, Instagram, Linkedin, Pinterest, Tumblr, Twitter, XING და Youtube-ს.

    Microsoft Clarity

    ჩვენ ვთანამშრომლობთ Microsoft Clarity-სთან, რათა ქცევითი მეტრიკის, სითბური რუკებისა (heatmaps) და სესიების გამეორების (session replay) საშუალებით დავაფიქსიროთ, თუ როგორ იყენებთ და ურთიერთქმედებთ ჩვენს ვებგვერდთან, ჩვენი სერვისების გაუმჯობესების მიზნით. ვებგვერდის გამოყენების მონაცემები ფიქსირდება პირველი და მესამე მხარის ქუქი-ფაილების და სხვა თრექინგ-ტექნოლოგიების გამოყენებით, სერვისების პოპულარობისა და ონლაინ აქტივობის დასადგენად. გარდა ამისა, ჩვენ ვიყენებთ ამ ინფორმაციას საიტის ოპტიმიზაციის, თაღლითობის აღკვეთისა და უსაფრთხოების მიზნებისთვის. დამატებითი ინფორმაციისთვის იმის შესახებ, თუ როგორ აგროვებს და იყენებს Microsoft თქვენს მონაცემებს, ეწვიეთ Microsoft-ის კონფიდენციალურობის განცხადებას.

    როგორც აღინიშნა, Microsoft Clarity-ის ნორმალური ფუნქციონირება მოითხოვს, რომ ჩვენ დავაყენოთ ქუქი-ფაილები თქვენს ვებ-ბრაუზერში. შესაბამისი ქუქი-ფაილები Microsoft-ს უგზავნის თქვენს შესახებ არაპერსონალიზებულ (ანონიმურ) ინფორმაციას. Microsoft Clarity-ის ქუქი-ფაილების სრული სიის სანახავად, გთხოვთ, იხილოთ ქუქი-ფაილების პანელი ჩვენს ვებგვერდზე.

    მონაცემთა ერთობლივი დამუშავება: დამუშავებულ მონაცემებთან დაკავშირებით, „Ensana s.r.o.“, „CP Regents Park Two Ltd.“, „Slovenske liecebne kupele Piešťany, a.s.“, „SC Balneoclimaterica SA“ და „Léčebné lázně Mariánské Lázně a.s.“ მოქმედებენ როგორც მონაცემთა ერთობლივი დამმუშავებლები (კონტროლერები). დამატებითი ინფორმაციისთვის, გთხოვთ, იხილოთ მე-5 ნაწილი.

    მონაცემთა დამუშავებისას ერთობლივი დამმუშავებლები (კონტროლერები) მოქმედებენ წინამდებარე პოლიტიკის შესაბამისად.

    4.3

    ვებ-ბმულები

    ჩვენი ვებგვერდი შესაძლოა შეიცავდეს ვებ-ბმულებს იმ საიტებზე, რომლებსაც კომპანია არ მართავს და არ ოპერირებს და რომლებიც ჩვენს საიტზე განთავსებულია მომხმარებლებისთვის ინფორმაციის მიწოდების მიზნით. კომპანია გავლენას ვერ ახდენს თავისი პარტნიორი კომპანიების მიერ მართული ვებგვერდების შინაარსსა და უსაფრთხოებაზე, შესაბამისად, მასზე პასუხისმგებლობა არ ეკისრება. გთხოვთ, გაეცნოთ მათ კონფიდენციალურობის პოლიტიკას, სანამ ამგვარ ვებგვერდებზე რაიმე სახის ინფორმაციას მიაწვდით

    5

    სამართლებრივი ხასიათის ინფორმაცია (საკონტაქტო რეკვიზიტების ჩათვლით)

    როგორც მის მიერ გამოყენებული პერსონალური მონაცემების დამმუშავებელი (კონტროლერი), „Ensana“ ვალდებულია, მონაცემთა დაცვის ზოგადი რეგულაციის (GDPR) შესაბამისად, გამოაქვეყნოს ინფორმაცია თავისი ოფიციალური დასახელების, საკონტაქტო რეკვიზიტებისა და სხვა მონაცემების შესახებ. ეს სექცია შეიცავს GDPR-ით მოთხოვნილ ყველა ინფორმაციას, ისევე როგორც დამატებით იურიდიულ ცნობებს.

    უპირველეს ყოვლისა, გვსურს შეგატყობინოთ, რომ საქმიანობის მეტი გამჭვირვალობის უზრუნველსაყოფად, „Ensana ჯგუფის“ სასტუმროები ორ დივიზიონად არის დაყოფილი:

    • ქალაქის დივიზიონი (City division) — მართავს ქალაქებში მდებარე სასტუმროებს (City hotels; იხილეთ ქვეპარაგრაფი 5.1.)
    • სპა დივიზიონი (SPA division) — მართავს გამაჯანსაღებელ, სპა და ველნეს სასტუმროებს (Ensana group; იხილეთ ქვეპარაგრაფი 5.2.).

    ქალაქის დივიზიონს მართავს უნგრული კომპანია „Danubius Hotels Zrt.“, ხოლო სპა დივიზიონს — ჩეხური კომპანია „Ensana s.r.o.“. ორივე კომპანია, „Danubius Hotels Zrt.“ და „Ensana s.r.o.“, ერთობლივად მართავენ ქვემოთ ჩამოთვლილ სასტუმროებს, რისთვისაც, თითოეული კონკრეტული შემთხვევის მიხედვით, ხდება პერსონალური მონაცემების გაზიარება და დამუშავება ამ კომპანიების მიერ, როგორც დამოუკიდებელი ან ერთობლივი დამმუშავებლების (კონტროლერების) მიერ. ქალაქის დივიზიონში მონაცემთა დაცვაზე პასუხისმგებელი პირი, დოქტორი ჰელგა სტანო (Dr. Helga Sztanó), ასევე პასუხისმგებელია მონაცემთა დაცვაზე სპა დივიზიონშიც.

    5.1

    Danubius-ის ქალაქის სასტუმროები (ქალაქის დივიზიონი)

    ქალაქის დივიზიონის მმართველი (წამყვანი) კომპანია:

    • დასახელება: Danubius Hotels Zrt.
    • იურიდიული მისამართი: 1051 Budapest, Szent István tér 11.
    • მარეგისტრირებელი სასამართლო: ბუდაპეშტის საქალაქო სასამართლო, როგორც სამეწარმეო რეესტრი (Metropolitan Court of Budapest as Court of Registration)
    • საიდენტიფიკაციო (სარეგისტრაციო) ნომერი: 01-10-041669
    • საგადასახადო ნომერი: 10594702-2-44
    • წარმომადგენელი: ბალაშ კოვაჩი (Balázs Kovács), გენერალური დირექტორი (CEO)
    • მონაცემთა დაცვაზე პასუხისმგებელი იურიდიული მრჩეველი (ასოცირებული პირი) ხელმისაწვდომია ნომერზე: +36-1-889-4172
    • ელ-ფოსტის მისამართი: [email protected]

    5.2

    Ensana-ს გამაჯანსაღებელი და სპა სასტუმროები (სპა დივიზიონი)

    სპა დივიზიონის მმართველი (წამყვანი) კომპანია:

    • კომპანიის დასახელება: Ensana s.r.o.
    • იურიდიული მისამართი: Senovážné náměstí 922/8, 110 00 Prague
    • მარეგისტრირებელი სასამართლოს დასახელება: პლზენის რეგიონული სასამართლო (Krajský soud v Plzni)
    • სარეგისტრაციო ნომერი: C 33301
    • საიდენტიფიკაციო კოდი (ID): 05456274

    „Danubius Hotels Zrt.“-ის გარდა, „Ensana s.r.o.“-ის მიერ ოპერირებადი სასტუმროების მფლობელებს წარმოადგენენ შემდეგი კომპანიები:

    „Ensana s.r.o.“-ის მართვაში არსებული კომპანიები:

  • კომპანიის დასახელება: CP Regents Park Two Ltd.
    • იურიდიული მისამართი: CP House, Otterspool Way, Watford WD25 7JP, UK (დიდი ბრიტანეთი)
    • სარეგისტრაციო ნომერი: 5307946
    • საგადასახადო ნომერი (TAX ID): GB 848957555
  • კომპანიის დასახელება: Slovenské liečebné kúpele Piešťany, a.s.
    • შემოკლებული დასახელება: SLKP, a.s.
    • იურიდიული მისამართი: Winterova 29, 921 29 Piešťany, Slovakia (სლოვაკეთი)
    • სარეგისტრაციო ნომერი: ტრნავას რეგიონული სასამართლოს სამეწარმეო რეესტრი, სექცია Sa, ჩანაწერი № 181/T (Obch. reg. KS Trnava, odd. Sa, vlozka č. 181/T)
    • ევროკავშირის საგადასახადო ნომერი (EU VAT): SK2020389668
  • კომპანიის დასახელება: SC Balneoclimaterica SA Sovata
    • იურიდიული მისამართი: Str. Trandafirilor nr. 99, Cod. 545500, Romania (რუმინეთი)
    • ევროკავშირის საგადასახადო ნომერი (EU VAT): RO1245068
    • სარეგისტრაციო ნომერი: J26/266/1991
  • კომპანიის დასახელება: Borovete I AD
    • იურიდიული მისამართი: 9000 Varna, Primorsky district, Sveti Konstantin i Elena resort, administrative building, Bulgaria (ბულგარეთი)
    • საიდენტიფიკაციო კოდი (ID): 204605689
  • კომპანიის დასახელება: Léčebné lázně Mariánské Lázně a.s.
    • იურიდიული მისამართი: Masarykova 22, 353 29 Mariánské Lázně, Czech Republic (ჩეხეთის რესპუბლიკა)
    • სარეგისტრაციო ნომერი: B 196
    • ევროკავშირის საგადასახადო ნომერი (EU VAT): CZ45359113
  • მონაცემთა ერთობლივ დამუშავებაში ჩართული სასტუმროები:

    Danubius Hotels Zrt. (უნგრეთი):

    • Ensana Thermal Margitsziget
    • Ensana Grand Margitsziget
    • Ensana Thermal Sárvár
    • Ensana Thermal Aqua
    • Ensana Thermal Hévíz

    Léčebné lázně Mariánské Lázně a.s. (ჩეხეთი):

    • Ensana Nové Lázně
    • Ensana Centrální Lázně
    • Ensana Hvězda
    • Ensana Pacifik
    • Ensana Butterfly
    • Ensana Vltava
    • Ensana Svoboda

    Slovenské liečebné kúpele Piešťany, a.s. (სლოვაკეთი):

    • Ensana Thermia Palace
    • Ensana Esplanade
    • Ensana Splendid
    • Ensana Vila Trajan
    • Ensana Jalta
    • Ensana Pro Patria
    • Ensana Smrdáky

    SC Balneoclimaterica SA Sovata (რუმინეთი):

    • Ensana Bradet
    • Ensana Sovata
    • Ensana Ursina

    Borovete I AD (ბულგარეთი):

    • Aquahouse

    6

    გამოყენებული ტერმინები და აბრევიატურები

    განმარტებების უმეტესობა აღებულია ევროკავშირის მონაცემთა დაცვის ზოგადი რეგულაციიდან (GDPR). ვინაიდან ეს სამართლებრივი დოკუმენტია, მისი შინაარსის მარტივად და მოკლედ გადმოცემა ყოველთვის შეუძლებელია. ჩვენი მიზანია მოგაწოდოთ ნათელი განმარტებები, რაც ტექსტის გაგებას გაამარტივებს; ეს ზოგჯერ გამორიცხავს სრული იურიდიული დეფინიციის მოწოდებას. „Ensana“-ს პოლიტიკის თანახმად, ჩვენ სრულად ვიცავთ GDPR-ის მოთხოვნებს და აქ მოცემული გამარტივებული განმარტებები არანაირად არ ლახავს თქვენს უფლებებს.

    ტერმინი ან აბრევიატურა | განმარტება

    დამმუშავებელი / მონაცემთა დამმუშავებელი (Controller or data controller): პირი, რომელიც დამოუკიდებლად ან სხვებთან ერთად განსაზღვრავს პერსონალურ მონაცემთა დამუშავების მიზნებსა და საშუალებებს და არეგულირებს ამ მონაცემების დამუშავების პროცესს.

    მონაცემთა სუბიექტი (Data subject): ევროკავშირის შიგნით ან მის ფარგლებს გარეთ მცხოვრები ფიზიკური პირი, რომელსაც აქვს ურთიერთობა ევროკავშირში მოქმედ ორგანიზაციასთან. ეს პირი ითვლება „მონაცემთა სუბიექტად“ და GDPR-ის ფარგლებში გააჩნია უფლებები საკუთარი მონაცემების დამუშავებასთან დაკავშირებით.

    EU: ევროკავშირი (The European Union).

    GDPR: ევროკავშირის მონაცემთა დაცვის ზოგადი რეგულაცია, რომელიც ძალაში შევიდა 2018 წლის 25 მაისს.

    პერსონალური მონაცემები (Personal data): ფიზიკურ პირთან დაკავშირებული ნებისმიერი ინფორმაცია, რომელიც იძლევა ამ პირის იდენტიფიცირების საშუალებას სხვადასხვა მეთოდით. ეს მონაცემები მოიცავს (მაგრამ არ შემოიფარგლება):

    • პირის სახელს, საიდენტიფიკაციო ნომერს, მისამართს, დედის სახელს დაბადებისას, ან
    • პირის ფიზიკური, ფიზიოლოგიური, გენეტიკური, ფსიქიკური, ეკონომიკური, კულტურული ან სოციალური იდენტობის მახასიათებელ ერთ ან რამდენიმე ფაქტორს.

    დამუშავება ან მონაცემთა დამუშავება (Processing or Data Processing): პერსონალურ მონაცემებზე ავტომატური ან არაავტომატური საშუალებებით შესრულებული ნებისმიერი მოქმედება ან მოქმედებათა ერთობლიობა, მათ შორის (მაგრამ არ შემოიფარგლება): შეგროვება, ჩაწერა, ორგანიზება, სტრუქტურირება, შენახვა, ადაპტაცია ან შეცვლა, ამოღება, გაცნობა, გამოყენება, გადაცემით გამჟღავნება, გავრცელება, კომბინირება, შეზღუდვა, წაშლა ან განადგურება.

    უფლებამოსილი პირი / მონაცემთა დამუშავებაზე პასუხისმგებელი პირი (Processor or data processor): პირი, რომელიც ამუშავებს პერსონალურ მონაცემებს მონაცემთა დამმუშავებლის (კონტროლერის) სახელით და დავალებით.

    პროფაილინგი (Profiling): მონაცემთა ავტომატური დამუშავება, რომელიც იყენებს პერსონალურ მონაცემებს პირის სამუშაო ეფექტურობის, ეკონომიკური მდგომარეობის, ჯანმრთელობის, პირადი პრეფერენციების, ინტერესების, საიმედოობის, ქცევის, ადგილმდებარეობის ან გადაადგილების გასაანალიზებლად ან პროგნოზირებისთვის.

    ფსევდონიმიზაცია (Pseudonymisation): პერსონალური მონაცემების კოდირება ან სხვაგვარად შენახვა, რაც უზრუნველყოფს იმას, რომ დამატებითი ინფორმაციის გამოყენების გარეშე მონაცემები ვერ დაუკავშირდეს კონკრეტულ მონაცემთა სუბიექტს. ეს დამატებითი ინფორმაცია უნდა ინახებოდეს ცალკე და დაცული უნდა იყოს არასანქცირებული გამოყენებისგან ტექნიკური და ორგანიზაციული ზომებით.

    განსაკუთრებული კატეგორიის პერსონალური მონაცემები (Sensitive categories of personal data):„განსაკუთრებული კატეგორიის“ (სენსიტიური) პერსონალური მონაცემების დამუშავებაზე მოქმედებს ძალიან მკაცრი შეზღუდვები. ესენია:

    • მონაცემები, რომლებიც ააშკარავებს რასობრივ ან ეთნიკურ კუთვნილებას, პოლიტიკურ შეხედულებებს, რელიგიურ ან ფილოსოფიურ მრწამსს, ან პროფესიული კავშირის წევრობას;
    • გენეტიკური ან ბიომეტრიული მონაცემების დამუშავება მხოლოდ ფიზიკური პირის უნიკალური იდენტიფიცირების მიზნით; მონაცემები ჯანმრთელობის მდგომარეობის, სექსუალური ცხოვრების ან სექსუალური ორიენტაციის შესახებ, ან
    • ნასამართლობასთან და სისხლისსამართლებრივ დარღვევებთან დაკავშირებული პერსონალური მონაცემები.

    საზედამხედველო ორგანო (Supervisory Authority): ევროკავშირის წევრი ქვეყნის მიერ შექმნილი დამოუკიდებელი საჯარო ორგანო, რომლის მიზანია GDPR-ის გამოყენების მონიტორინგი და, საჭიროების შემთხვევაში, ჩარევა ფიზიკურ პირთა უფლებების დასაცავად.

    მესამე ქვეყანა (Third country): ნებისმიერი ქვეყანა ევროკავშირის (EU) ფარგლებს გარეთ.

    მონაცემთა გადაცემა (Data transfer): პერსონალური მონაცემების გაგზავნა დამმუშავებლის (კონტროლერის) ან უფლებამოსილი პირის (პროცესორის) მიერ ევროკავშირის ფარგლებს გარეთ არსებული იურიდიული პირისთვის.

    • კითხვები

      Ensana-ს სასტუმროებსა თუ მომსახურებასთან დაკავშირებული ნებისმიერი კითხვის შემთხვევაში, გთხოვთ, მოგვმართოთ. ჩვენს ლოიალობის პროგრამასთან დაკავშირებულ კითხვებსა და პასუხებზე ინფორმაციის მისაღებად, გთხოვთ, დააჭიროთ აქ.

      დასვით კითხვა
    • ჯავშნები

      ისარგებლეთ ჩვენი საუკეთესო შეთავაზებებით აქ. თუ გსურთ გაწევრიანდეთ ლოიალობის პროგრამაში დამატებითი ფასდაკლებებისა და პრივილეგიების მისაღებად, ან უბრალოდ თვალი ადევნოთ სიახლეებს, დააჭირეთ აქ.

      დაჯავშნეთ ახლა
    • მოთხოვნები

      გამოგვიგზავნეთ თქვენი მოთხოვნა, რათა შევძლოთ თქვენზე მორგებული საუკეთესო შეთავაზების მომზადება. სიამოვნებით მოგაწვდით ნებისმიერ დამატებით ინფორმაციას, რომელიც ჩვენს ვებგვერდზე ვერ იპოვეთ.