Eden's Garden logo

Privacy Policy

1) Who processes your data (controller)

The controller of personal data is Eden’s Grand Spa, s.r.o., registered office at Rybná 716/24, 110 00 Prague, Company ID: 19855621.

2) What data we process and why (purposes and legal bases)

We only process data necessary for the purposes listed below:

  • Reservation of services, provision of massage / wellness, gift vouchers and e-shop
    Identification and contact data (name, e-mail, telephone), reservation / order details, payment and billing data.
    Legal basis: performance of the contract (Art. 6/1 b GDPR) and legal obligation in the accounting and tax area (Art. 6/1 c GDPR).
  • Communication and responses to inquiries (contact form, phone, email)
    Name, email, phone, message content.
    Legal basis: legitimate interest in handling inquiries and providing quality support (Art. 6/1 f GDPR).
  • Online payments and their settlement
    Identification and payment details required to make and match the payment (see processors below – Comgate).
    Legal basis: performance of the contract (Art. 6/1 (b) and legal obligation (Art. 6/1 c). On our website and booking portal you will see “Online Payments – Payments – Comgate”. Eden’s Garden Grandior Spa
  • Marketing (e.g. sending newsletters, promotions), remarketing and web analytics
    Email, technical and analytical data (IP, cookie identifiers/online identifiers, web behavior data).
    Legal basis: consent (Art. 6/1 a) for email marketing and storage/non-essential cookies; legitimate interest (Art. 6/1 f) in basic traffic statistics in aggregate form. We inform you about specific cookies and consent options in the Cookie Policy.
  • Exercise of rights, resolution of complaints and legal claims
    Data necessary for the establishment, defense or exercise of claims.
    Legal basis: legitimate interest (Art. 6/1 f), or legal obligation (Art. 6/1 c).

3) Where we get the data from

Primarily directly from you when booking, ordering, paying, communicating or using our websites (including grandior.edensgarden.cz and eshop.edensgarden.cz).

4) Who helps us with the data (recipients/processors)

We use trusted partners who only process data according to our instructions:

  • Payment gateway: Comgate a.s., Gočárova třída 1754/48b, 500 02 Hradec Králové, ID: 27924505 – online payment.
  • Web hosting/IT administration, reservation system and e-shop (e.g. WordPress/WooCommerce and necessary add-ons), hosting and IT support providers; in practice also plugins facilitating GDPR regime (data export/deletion, retention settings, etc.).
  • Email services and communication tools: your email provider/SMTP.
  • Analytical and marketing tools: only if you give your consent in the cookie bar (see Cookie Policy).
    In the case of payment through employee benefits, we may – depending on the method of application – pass on the necessary data to the benefit provider in order to process the payment. (Eden’s Garden is listed as a partner in the Benefit Plus catalogue .)

The actual range of processors and technical solutions may change; however, we always take contractual and technical measures in accordance with the GDPR.

5) Transfers to third countries

If we use tools based outside the EU/EEA (typically some cloud or analytics services), the transfer only takes place if there is an appropriate transfer mechanism (notably the European Commission’s Standard Contractual Clause) and with additional measures. The specific tools and categories of cookies are described in the Cookie Policy.

6) Data retention

  • Reservation and performance of services: for the duration of the contractual relationship and subsequently for the period necessary to protect the rights (usually 3 years), accounting and tax documents for the period prescribed by law (usually 10 years).
  • Communication via forms/email: up to 12 months from the last interaction, unless it is related to a contract.
  • Consent-based marketing: until consent is withdrawn.
  • Cookies: according to the categories and time limits set out in the Cookie Policy.

7) Your rights

  • You have the right to access, rectification, erasure, restriction, portability, to object to processing (including objection to processing on legitimate interest and direct marketing) and the right to withdraw consent (if it is based on).
  • You also have the right to lodge a complaint with the supervisory authority: the Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7.

8) Security

We maintain appropriate technical and organisational measures (access control, transmission encryption, regular system updates, contracted processors) to protect your data against misuse, loss or unauthorised access.

9) Cookies and similar technologies

The website uses cookies and similar technologies. You can find the categories, durations and list of providers in the Cookie Policy and in the consent interface on the website, where you can change your choices at any time. The link to the Cookie Policy is in the footer of the website.

10) Automated decision making

We do not make decisions based solely on automated processing that would have legal effects on you or similarly significantly affect you.

11) How to exercise your rights / contact us

The fastest way is by email to info@edensgarden.cz. We process applications without undue delay, within 1 month at the latest; in complex cases we may extend the deadline by 2 months (we will inform you).

12) Policy changes

We may update this policy from time to time. The latest version is always available on our website.

 

Reservation

Book Now

Book conveniently from your mobile, tablet or computer.

Grandior Spa Reception

Come and meet us at the reception in the hotel lobby.

+420 734 739 973

Wherever you are, give us a call.

5295

Call us directly from your room at Grandior hotel.