PRIVACY POLICY
Last Updated: 3rd May 2013
Orient-Express Hotels Ltd. respects the privacy of every individual who visits our hotels, trains, cruises or websites and protecting the privacy and personal data of our visitors is of the utmost importance to us. This policy establishes how we handle the information that (i) you provide to us when you stay or travel with us and (ii) we collect from you when you visit our websites.
You have the right as an individual to find out what information we hold about you and make corrections if necessary; you also have the right to ask us to not use the information for certain purposes. We will make all practical efforts to respect your wishes (subject to any overriding legal obligations).
In order to provide multiple access points to the services and products we offer, Orient-Express Hotels Ltd. operates directly, or through its affiliates or service providers, many websites, including www.orient-express.com, www.orient-expresstrains.com, www.orient-expresshotels.com, www.signatureboutique.com, www.orient-express.fr, www.orient-express.co.jp, www.orient-express.co.ru, http://www.orient-expresshotels.com.br, www.21club.com, www.perrycabin.com, www.charlestonplace.com, www.elencanto.com, www.maromahotel.com, www.lasamanna.com, www.casadesierranevada.com, www.peru-tour.com, www.copacabanapalace.com.br, www.hoteldascataratas.com, www.mira-park.com, www.machupicchu.orient-express.com, www.monasteriohotel.com, www.mesa18restaurant.com, www.mesa18restaurante.com, www.mesa18restaurante.com.pe, www.riosagrado.com, www.grand-hotel-europe.com www.ritz.es, www.ritzmadrid.com, www.hotellaresidencia.com, www.hotelsplendido.com, www.villasanmichele.com, www.hotelcaruso.com, www.hotelcipriani.com, www.hotelvillasantandrea.com, www.grandhoteltimeo.com, www.manoir.com, www.reidspalace.com, www.eagleislandcamp.com, www.khwairiverlodge.com, www.savuteelephantcamp.com, www.alouettebarge.com, www.amaryllisbarge.com, www.hirondellebarge.com, www.napoleonbarge.com, www.fleurdelysbarge.com, www.jimbaranpuribali.com, www.ubudhanginggardens.com, www.residencedangkor.com, www.residencephouvao.com, www.napasai.com, www.governorsresidence.com, www.roadtomandalay.net, www.vsoe.com, www.perurail.com, www.royalscotsman.com, www.mountnelson.co.za, www.orient-express-safaris.co.za, www.westcliff.co.za, www.romanticgetaways.orient-express.com, and www.afloatinfrance.com, www.hotel-du-palais.com, www.palacionazarenas.com, www.palacionazarenas.com.pe. Any one of these websites may ask for and collect personally identifiable information in order to enhance your experience and provide you with relevant information.
If you have any specific questions that are not covered in the FAQ section below, please contact:
Central Marketing
Orient-Express Services Limited
1st Floor Shackleton House
4 Battle Bridge Lane
London
SE1 2HP
+44 (0)20 3117 1300
email: privacy@orient-express.com
The terms of this privacy policy may be changed by Orient-Express Hotels Ltd. from time to time. Changes will be displayed on www.orient-express.com.
*in the context of this Privacy Policy, Orient-Express Hotels Ltd. includes Orient-Express Hotels Ltd. (based in Bermuda) (“OEHL”) and each of those companies where OEHL owns from time to time (directly or indirectly) at least 25% of the company and, in each case, (i) any assignees, transferees or replacements of any such companies from time to time and (ii) any properties, trains or cruises managed or operated from time to time by any such entities. References in this Policy to “we” “us” and “our” shall be construed accordingly.
Frequently Asked Questions
Q1. Why does the Orient-Express Hotels Ltd. collect information about me?
Q2. What information might be collected about me by the Orient-Express Hotels Ltd.?
Q3. What are cookies?
Q4. Which cookies does the Orient-Express Hotels Ltd. use?
Q5. How can I turn cookies off?
Q6. Do you disclose to or share with any third parties any of the personal information you hold about me?
Q7. Can I see or update the personal information you hold about me?
Q8. Where do you transfer, process and store information about me?
Q9. How long is personal information kept for?
Q10. What security arrangements are in place to protect my personal information?
Q11. Do you have a policy for protecting the privacy of children using your websites?
Q12. Do Orient-Express Hotels Ltd. websites link to other websites?
Q13. Are there any additional privacy provisions for non-UK websites?
Answers:
Q1. Why does the Orient-Express Hotels Ltd. collect information about me?
A. We collect information to:
• help us create content that is relevant to our visitors;
• make improvements to our websites and ensure that content on our websites is presented in the most effective manner for you and computer;
• provide you with information, products or services that you request from us or which we feel may interest you (where you have consented to be contacted for such purposes);
• assess and help us understand general trends and patterns relating to our business;
• provide for the safety and security of our guests and visitors;
• manage general record keeping;
• enable us to compile anonymous, aggregated statistics that allow us to understand how users use our websites and to help us improve the structure of our websites;
• enable you to make reservations and payments (whether for stays, travel, gift certificates purchases or otherwise) on-line; and
• meet any legal and/or regulatory requirements.
Back to top
Q2. What information might be collected about me by the Orient-Express Hotels Ltd.?
A. Visitors to Websites:
In general, you can browse any Orient-Express Hotels Ltd. website without disclosing any personally identifiable information about yourself. If you visit an Orient-Express Hotels Ltd. Website to read or download information, we collect and store only the following information that is automatically recognised (via cookies). What are cookies?
• Date and time;
• Originating IP address;
• Domain name;
• Type of browser and operating system used (if provided by the browser);
• URL of the referring page (if provided by the browser);
• Object requested;
• Completion status of the request.
In addition, we will collect and process the information you provide to us in connection with the following:
• filling in a form on any of our websites
• subscribing to receive a service from us (for example, a newsletter)
• requesting promotional (or other) information from us
• participating in a survey, competition or prize draw
• contributing content to us (for display on an Orient-Express Hotels Ltd. blog, Travellers' Lounge site or similar)
Our Hotel, Train and Cruise Guests:
We may collect and process information about you as a result of your stay/travel with us, including:
• the information you provide in a registration card (which may include your name, gender, home and work contact details, business title, date and place of birth, nationality and passport and visa information);
• the information we receive about you from any third parties you have booked your arrangements with us through (including but not limited to travel agents and tour operators);
• members of the Orient-Express Hotels Ltd. at which you have been a guest and information about those stays (which may include arrival/departure dates, goods and services purchased during those stays, food allergies, special requests made and room preferences and details of payments made to us);
Back to top
Q3. What are cookies?
A. A “cookie” is an element of data that a website can send to your browser which may then be stored on your system.
We use cookies to gather anonymous information about the visitors to our websites (as they enable us to improve our websites and deliver a better and more personalised service). Why does the Orient-Express Hotels Ltd. collect information about me?
We do not associate the information in a website visitor’s cookie with any other personal information about that visitor.
Further information about cookies and how they work is available at www.allaboutcookies.org
Q4. Which cookies does the Orient-Express Hotels Ltd. use?
The main cookies we use on our Orient-Express Hotels Ltd. websites are:
| Cookie Name
| Function
|
|---|---|
| ARPT
| Ensures that the user stays on the same server throughout their visit, ensuring consistent functionality throughout a visit. This cookie is destroyed at the end of the user’s visit
|
| JSESSIONID
| Ensures that the user’s session is maintained and works in conjunction with ARRPT to ensure consistent functionality throughout a visit. This cookie is destroyed at the end of the user’s visit
|
| sifrFetch
| Allows use of flash to improve display of text (if the user's browser supports it). This cookie is destroyed at the end of the user’s visit
|
| user_countrycode
lounge_user_countrycode user_lang_pref | These three cookies allow us to keep track of the users' geographic location and language preferences in order to display them relevant targeted and localised content as applicable.
|
| user_campaign
user_creative user_placement internal_user_campaign internal_user_creative internal_user_placement | These six cookies allow us to identify which of our marketing campaigns or internal promotions a user has come from as well as measure their effectiveness
|
| user_id
lounge_user_id | These two cookie allows us to identify the user and customise their experience as appropriate as well as helping with form entry and the like by pre-populating fields containing name and address information.
|
In addition, the following are the main third party cookies we use (which are each subject to their own privacy and cookie policies):
| Third Party Cookie | Function |
|---|---|
| Google Analytics
| Monitors usage of site (using non-personally identifiable data). Privacy policy available at www.google.com/intl/en/analytics/privacyoverview.html |
| Facebook Like Button
| Allows users to choose to show Orient-Express Hotels Ltd.websites on their Facebook site. Privacy policy available at www.facebook.com/about/privacy/ |
| Google +1 Button
| Allows users to choose to show Orient-Express Hotels Ltd. websites on their Google + account. Privacy policy available at www.google.com/intl/en/+/policy/+1button.html |
| DoubleClick Advertising
and Google Adwords | Allows the Orient-Express Hotels Ltd. to monitor (using non-personally identifiable data) the number and type of relevant searches made for it on Google. Privacy policy available at www.google.com/intl/en/privacy/ads/ |
| Yahoo Advertising and Campaign Tags
| Allows the Orient-Express Hotels Ltd. to monitor (using non-personally identifiable data) the number and type of relevant searches made for it on Yahoo. Privacy policy available at info.yahoo.com/privacy/us/yahoo/details.html |
| Yandex
| Allows users to search for Orient-Express Hotels Ltd. websites in the Russian language. Privacy policy available at company.yandex.ru/legal/en/confidential/ |
| Quantcast
| Quantcast enable the direct-measurement of traffic and audience characteristics, using non-persoanlly identifiable data. Privacy policy available at http://www.quantcast.com/privacy |
| Google Remarketing Tags
| Orient-Express Hotels Ltd. are using remarketing to advertise online. This means that third-party vendors, including Google, will show ads on sites across the Internet. Google will use cookies to serve ads based on past visits to this website. You can opt-out of Google's use of cookies by visiting the Ads Preferences Manager, or through the Network Advertising Initiative opt-out page. |
Unless you have adjusted your browser setting so that it will refuse cookies (Q5 How can I turn cookies off?), our system will issue cookies when you log on to any of our websites.
Q5. How can I turn cookies off?
You can set your internet browser to notify you when you receive a cookie, giving you the chance to decide whether or not to accept it. Please note however that if you choose to reject cookies, you may be unable to access certain parts of our websites.
Back to top
Q6. Do you disclose to or share with any third parties any of the personal information you hold about me?
We may disclose or share your information within the Orient-Express Hotels Ltd. and, in the following circumstances, with third parties:
• where we outsource certain functions of our business to third parties such as agents, service providers and/or suppliers who assist us in either providing a product or service to you or with quality assurance or the hosting of databases, such third parties may have access to your information. Where this is the case, we oblige those third parties to process the information only in accordance with our strict instructions, to adopt technical and organisational security measures to protect your information and not to disclose your information to others;
• if we are under a duty to disclose or share your information in order to comply with any legal obligation, or in order to enforce or apply our Terms of Use or to protect (i) the rights or property and/or (ii) the personal safety of (in each case) us, our staff, guests and visitors;
• to meet any legal and/or regulatory requirements;
• in the event that we sell (or propose to sell) any Orient-Express Hotels Ltd. business or assets, we may disclose your information to the prospective buyer.
We will usually inform you (before collecting your information) if we intend to use your information (or disclose it to a third party) for marketing purposes (for more about marketing, see Q7. Can I see or update the personal information you hold about me?)
Back to top
Q7. Can I see or update the personal information you hold about me?
A. You can ask us whether we are keeping personal information about you and you can ask to receive a copy of that personal information.
Before sending you any personal data, we will ask you to provide proof of your identity. If you are not able to provide proof of your identity, we reserve the right to refuse to send you any personal data.
We will respond as quickly as we can to your requests for details of personal information we hold about you.
To contact is with any questions, comments, corrections, requests regarding this Policy or to exercise your right at any time to update, delete or access the information we hold about you, please contact us at:
Central Marketing
Orient-Express Services Limited
1st Floor Shackleton House
4 Battle Bridge Lane
London
SE1 2HP
+44 (0)20 3117 1300
email: privacy@orient-express.com
You have the right to ask us not to process your personal information for marketing purposes by (i) checking the applicable box(es) on the registration form we use to collect information from guests to our properties or (ii) by clicking the unsubscribe link displayed in any of our marketing e-mails and in the Orient-Express Hotels Ltd. website on-line e-mail preference centre.
Back to top
Q8. Where do you transfer, process and store information about me?
A. The information that we collect from you may be transferred to and stored in the USA or another destination outside the European Economic Area (“EEA”). It may also be processed by staff operating outside the EEA who work for us or for one of our agents, service providers or suppliers. Such staff may be engaged in, amongst other things, the fulfilment of your order or in providing a service to you, the processing of your payment details and/or the provisions of support services.
By submitting your information to us, you agree to this transfer, storing and processing. Orient-Express Hotels Ltd. will take all commercially reasonable steps necessary to ensure that your information is treated securely and in accordance with this Policy.
Back to top
Q9. How long is personal information kept for?
A. Orient-Express Hotels Ltd. holds information for as long as we believe it will help us to achieve our aims of understanding how we can better serve you. Subject to any legislation which might, from time to time, oblige us to store the information for a certain period of time, we will respect your wishes to correct inaccurate information or delete information. How do I correct personal information you hold about me?
Back to top
Q10. What security arrangements are in place to protect my personal information?
A. We intend to protect the quality and integrity of your personal information. Orient-Express Hotels Ltd. stores personal information in a secure environment protected by a combination of physical and technical measures. We will continue to enhance our security procedures, as new technology becomes available. There is no general public access to visitor’s personal information.
The personal information you give to us when making a payment on-line to us in encrypted before you conduct your transaction, using appropriate secure technology. However please note that:
• transmission of information via the internet is not completely secure and although we will endeavour to protect your information, we cannot guarantee the security of your information transmitted to one of our websites; any transmission is therefore at your own risk. Once we have received your information, we will use procedures and security features to try to prevent unauthorised access;
• you are responsible for keeping any password you have to access certain parts of any of our websites confidential and we ask you not to share a password with anyone.
Back to top
Q11. Do you have a policy for protecting the privacy of children using your websites?
A. The Orient-Express Hotels Ltd. websites are not aimed at children. We never collect or maintain information from those visitors to our websites who we actually know are under the age of 14 without first obtaining verifiable consent from a parent or legal guardian. Upon written request (with supporting proof of identity), parents (or legal guardians) may ask to review their child’s information or request that it be deleted.
Back to top
Q12. Do Orient-Express Hotels Ltd. Websites link to Other Websites?
Our websites may, from time to time, contain links to and from the websites of our partner networks, advertisers, social media sites and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal information to these websites.
Back to top
Q13. Are there any additional privacy provisions for non-UK websites?
A. Yes, for www.ritzmadrid.com and www.ritz.es, in addition to the Orient-Express Hotels Ltd. Privacy Policy, please note that for the purposes of the Spanish Data Protection Act (LO 15/1999 of 13 December), personal information gained from visitors to those websites is provided to:
Hotel Ritz Madrid S.A.
Plaza de la Lealtad
5-28014 Madrid
CIF A28011286
e-mail: lopd@ritz.es
Registered in the Mercantile record of Madrid 20-08-1908, to the volume the 55th, I foliate aheet 2345, inscription 1.
B - Privacy Policy for Italy
This privacy Policy ("Privacy Policy") has been drafted according to the Recommendation n. 2/2001 dated May 17, 2001 issued by Article 29 Data Protection Working Party (Minimum requirements for the collection of data on-line within the European Union). The Privacy Policy also represents the information statement to the data subjects that is due under Art. 13 of the “Privacy Code” (Legislative Decree June 30, 2003 n. 196 and further amendments and integrations). The Privacy Policy identifies who is the data controller that manages the data collected through the Site (as below defined), specifies what personal information is collected, the data processing purposes and conditions, the extent of the communication of user’s data to third parties, the data security measures adopted to protect data and how user may enforce the privacy rights acknowledged by the Privacy Code. The Privacy Policy is provided by the following data controllers (collectively, the "Controller") and for the websites below listed (collectively, the "Site"):
For the web sites www.hotelcaruso.com and www.hotelcaruso.it the Controller is Hotel Caruso S.r.l., offices at P.zza San Giovanni del Toro 2, 84010 Ravello (SA) - Italy and data Processor is Mr. Franco Girasoli, domiciled at the premises of the above Controller;
For the web sites www.hotelcipriani.com and www.hotelcipriani.it the Controller is Hotel Cipriani S.r.l., offices at sola Giudecca 10, 30123 Venezia (VE) - Italy and data Processor is Mr. Giampaolo Ottazzi, domiciled at the premises of the above Controller;
For the web site www.hotelsplendido.com the Controller is Hotel Splendido & Splendido Mare S.r.l., offices at Salita Baratta 16, 16034 Portofino (GE) - Italy and data Processor is Mr. Ermes De Megni, domiciled at the premises of the above Controller;
For the web site www.villasanmichele.com the Controller is Villa San Michele S.r.l., offices at Via Doccia 4, 50014 Fiesole (FI) - Italy and data Processor is Mr. Marco Novella, domiciled at the premises of the above Controller;
For the web site www.villasantandrea.com the Controller is Villa Sant’Andrea S.r.l., offices at Via Nazionale 137, 98039 Taormina (ME) - Italy and data Processor is Mr. Giovanni Nastasi, domiciled at the premises of the above Controller;
For the web site www.grandhoteltimeo.com the Controller is Grand Hotel Timeo / Orient-Express Esercizi S.r.l., offices at Via Teatro Greco 59, 98039 Taormina (ME) - Italy and data Processor is Mr. Luca Finardi, domiciled at the premises of the above Controller.
The nature and kind of data processed
If user visits the Site usually no personal data will be collected or processed, since the data processing is limited to the so named surfing data, which are data whose transmission to the Site is necessary to allow the functioning of the information systems that manage the Site and more generally the use of Internet communications protocols. Surfing data are for example: the computer’s IP addresses or domain names used to visit the Site together with other parameters on the relevant operating system. Controller collects these data and other data such as the number of visits and the time spent on the Site only for statistical purposes and in anonymous form to monitor the correct functioning of the Site and improve its functionalities. By their nature, surfing data may allow the identification of user by association with other information owned by third parties; Controller does not collect surfing data to associate them with other user’s information or to identify users. Surfing data are deleted immediately after the processing in anonymous form; Controller may use said data to assess possible responsibilities for information crimes against the Site or realized through the Site. With this exception, Controller keeps surfing data only temporarily and according to applicable legislation.
Controller collects and processes personal data voluntarily provided by user upon interaction with the Site functionalities and request of the services offered by the Site, for example when user makes a booking or requests information. As permitted by the Privacy Code, Controller may also process user’s personal data obtained from third parties in the course of its business activity. With the user’s consent, Controller may further process user’s personal data for marketing purposes, notably to send via email or newsletter information and material on special initiatives, promotions and events of Controller, including possible invitations.
We may collect user's name and contact details such as street address, telephone number and e-mail. When personal data are collected on the Site a specific informative statement will be displayed according to Art. 13 of the Privacy Code. User’s consent is requested when necessary under the Privacy Code.
Place where personal data are stored
Personal data are stored and processed through an electronic system owned by Controller and managed by Controller or by third parties providing technical services to Controller. Data are processed only by specifically authorized staff, including staff in charge of performing non-routine maintenance operations.
Cookies
Cookies are small data files stored on the hard disk of the user’s computer. The Site deploys cookies for the limited purposes specified below. Controller uses cookies that cannot be used to run programs or download viruses on the user’s computer, and they do not allow any kind of control of the user’s computer. We do not use cookies to access information on the user’s computer, to store information therein or to monitor user’s activities. The foregoing applies to user’s computer and any other kind of device used to connect to the Site. The so called ‘session cookies’ are stored temporarily and deleted when user closes the browser. The Site may contain links to other sites. We do not have any access or control of cookies, web bacons and other user tracking technologies used on third parties’ web sites that user may access from the Site, of the availability and of any content or material contained in, or obtained through, any such sites, and of the relevant conditions of data processing, and hereby we expressly disclaim any relevant liability. User should verify the privacy policy of third parties’ web sites accessed from the Site to be informed of the data processing conditions, since this Privacy Policy only applies to the Site as defined above. Most web browsers automatically accept cookies, but user can usually change the web browser to disable this function. The section “Help” of the toolbar available in most browsers explains how to avoid receipt of cookies by browser, web bacons and other technologies employed to track users, how to obtain from the browser notice of receipt of the referenced technologies or how to disable them completely. Disabling cookies may limit the possibility to use the Site and may prevent user from fully benefiting from the Site functionalities and services.
Purposes and conditions of the personal data processing
In addition to the so-called surfing data, we may process the personal data voluntarily provided by user when user interacts with the Site functionalities and asks for our services. Controller will process user’s personal data for the following purposes: managing user's requests of bookings and information, managing user's questions, communication or feedback to Controller. User’s personal data will also be processed by Controller to comply with obligations imposed by laws, regulations and Community legislation and to establish or defend a legal claim of Controller. For the above purposes providing personal data is necessary and denial thereof would make it impossible for Controller to manage the user's requests of bookings and information.
With the user’s consent, Controller may also process user’s personal data for marketing purposes, notably to send via email or newsletter information and material on special initiatives, promotions and events of Controller, including possible invitations. User will always have the opportunity to refuse receiving promotional e-mails; in each communication it will be explained how to refuse receiving future promotional e-mails. Providing personal data for marketing purposes is optional and denial thereof would have no consequence.
Controller processes personal data mostly through electronic and automated means whose procedures and logics are defined according to the purposes herein specified. Data are kept only for the time that is necessary to fulfil the specific purposes that are sought from time to time.
Security and quality of personal data
Controller is committed to protect the security of user’s personal data and complies with security provisions set forth by applicable laws and regulations to prevent loss of data, unlawful or unfair use of data and unauthorized access to data, with specific but not limited reference to Annex B of the Privacy Code (Technical Specifications Concerning Minimum Security Measures). Moreover, information systems and software programs are configured by reducing to a minimum the use of personal and identification data, which are used only if necessary for specific purposes that are sought from time to time.
Extent of personal data communication and transfer abroad
User’s personal data will be shared according to this Privacy Policy and the information statement published on the Site in the sections where data are collected, always in compliance with the consent given by the user upon data collection, if required by the Privacy Code. User personal data will be accessible within the Controller organization on a need-to-know basis by its personnel as persons charged with data processing operations and by the Processor above mentioned. The updated list of Processors and of the subjects to which data may be communicated remains at user disposal free of charge upon request to applicable Controller and its Processor, as above listed. User personal data may be communicated to institutions, authorities, public entities, professionals, independent consultants, also in associate form, business partners of Controller, notably third parties to which we may revert to in relation to performance of business, professional and technical services functional to the managing of the Site and the processing purposes herein specified. Data may also be shared with other companies of the Group Orient Express based in Italy, only for managing of booking requests.
User’s personal data may also be communicated to third parties in case of mergers, acquisitions, and transfer of assets, products or other extraordinary operations. These third parties will be provided only with the information necessary to perform their respective functions; they agree to keep it confidential and secure and to comply with applicable law. User’s personal data may further be communicated to whoever is the legitimate addressee under applicable laws, thus for example in case of judicial processes, request by competent courts and authorities or other legal obligation, and if Controller in good faith holds the data communication as necessary to comply with obligations deriving from applicable legislation, to protect and defend the Site and the rights and property of Controller. The third parties receiving data will process them as Controllers, Processors or persons in charge of processing, as the case may be. Personal data are not transferred outside the European Union.
User’s rights
User is entitled at any moment to enforce the rights acknowledged under Art. 7 of the Privacy Code, including for example to obtain confirmation that user’s personal data exist or not, verify their content, origin, accuracy, ask for their integration, updating, amendment, deletion, transformation in anonymous form, block for breach of laws, oppose for legitimate reason the data processing. For any request on the personal data processing by Controller and to enforce privacy rights user may contact relevant Controller or its Processor, as applicable and above listed.
This Privacy Policy is subject to updating and amendment. The version published on the Site is the version currently in force. Changes to this Privacy Policy will be communicated by placing a notice on the Site that reads “Newly Revised Privacy Policy” or the like. Controller invites user to periodically review the Privacy Policy to be informed of any relevant change.
The Effective Date of this Privacy Policy is: May 3, 2013



