GDPR Policy

GDPR Compliance Policy

Effective Date: 2 January 2024

Resorts Philippines is committed to ensuring that your personal data is handled in compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679. This GDPR Compliance Policy outlines how we collect, use, protect, and manage personal data in accordance with GDPR requirements.

1. Data Controller and Data Processor

Resorts Philippines acts as both a Data Controller and Data Processor, depending on the circumstances. As a Data Controller, we determine the purposes and means of processing your personal data. As data processors, we process data on behalf of other organizations.

2. Lawful Basis for Data Processing

We process personal data based on one or more of the following lawful bases:

  • Consent: You have given clear consent for us to process your personal data for a specific purpose.
  • Contractual Necessity: Processing is necessary for the performance of a contract with you or to take steps to enter into a contract.
  • Legal Obligation: Processing is necessary for compliance with a legal obligation to which we are subject.
  • Legitimate Interests: Processing is necessary for our legitimate interests or those of a third party, except where such interests are overridden by your fundamental rights and freedoms.

3. Types of Data Collected

We collect and process the following types of personal data:

  • Personal Identification Information: Name, email address, phone number, and other contact details.
  • Financial Information: Payment information for purchases or bookings.
  • Technical Data: IP address, browser type, operating system, and other technical information from your use of the Site.
  • Usage Data: Information about how you use our Site and services.

4. Data Subject Rights

Under GDPR, you have the following rights regarding your personal data:

  • Right to Access: You have the right to request access to your personal data and obtain information about how we process it.
  • Right to Rectification: You have the right to request the correction of inaccurate or incomplete personal data.
  • Right to Erasure (“Right to be Forgotten”): You have the right to request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected or if you withdraw your consent.
  • Right to Restriction of Processing: You have the right to request the restriction of processing of your personal data under certain circumstances.
  • Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format and have the right to transmit that data to another controller.
  • Right to Object: You have the right to object to the processing of your personal data based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent: If we rely on your consent to process your personal data, you have the right to withdraw your consent at any time.

To exercise any of these rights, please contact us. We may need to verify your identity before processing your request.

5. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by applicable laws and regulations. When personal data is no longer needed, we will securely delete or anonymize it.

6. Data Transfers

We may transfer your personal data to countries outside the European Economic Area (EEA) for processing. In such cases, we ensure that appropriate safeguards are in place to protect your personal data in accordance with GDPR requirements, such as using Standard Contractual Clauses approved by the European Commission.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction. These measures include encryption, access controls, and regular security assessments.

8. Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay in accordance with GDPR requirements.

9. Third-Party Processors

We may engage third-party service providers to process personal data on our behalf. These processors are contractually obligated to comply with GDPR requirements and to protect your personal data.

10. Supervisory Authority

If you believe that our processing of your personal data violates GDPR, you have the right to lodge a complaint with a supervisory authority in the EU Member State where you reside, work, or where the alleged infringement occurred.

11. Changes to This Policy

We may update this GDPR Compliance Policy from time to time to reflect changes in our data processing practices or legal obligations. We will notify you of any significant changes by posting the updated policy on our Site.

12. Contact Us

If you have any questions about this GDPR Compliance Policy or how we handle your personal data, please contact us.

Thank you for trusting Resorts Philippines with your personal data. We are committed to protecting your privacy and ensuring that your data is handled in accordance with GDPR.