Data Peace of Mind: De Zeeuwse Stromen Privacy — How We Safeguard Your Personal Information
Planning a getaway should feel relaxing — and so should the way your data is handled. This guide explains De Zeeuwse Stromen privacy practices in clear, practical terms so you know exactly how we protect your personal information, when we use it, and the rights you can exercise at any time.
Our promise at a glance
- No commercial sharing: Booking and guest data are used only internally and are not passed to third parties for commercial use.
- GDPR-first approach: We process personal data in line with the applicable data-protection law (GDPR/AVG), with transparency and purpose limitation at the core.
- Data minimisation and retention: We keep personal data no longer than necessary to deliver services; if you consent to email updates, we retain your address for that purpose.
- Trusted processors, clear contracts: We work with vetted service providers (e.g., hosting, CRM, privacy-friendly analytics) under Processor Agreements that restrict use strictly to providing our services.
- Security by design: We apply technical and organisational safeguards, including SSL encryption where appropriate, encrypted storage of sensitive information where possible, backups where reasonably feasible, and timely remediation of software vulnerabilities.
- Transparent rights: You have the rights to access, correct, erase, restrict, port, and object — with immediate stop for any direct marketing upon objection.
- Respectful safety measures: Camera surveillance protects guests and property, never in guest rooms, public toilets, or wellness facilities; footage is retained for a maximum of 7 days.
What we collect and why
Bookings and stays
When you book an overnight stay, event, restaurant table or meeting space, we process what’s needed to fulfil your reservation and provide service:
- First and last name
- Gender
- Confirmation that you are 18 or older
- Address and place of residence
- Telephone number and email address
- Payment details
- Arrival and departure dates
These data are used internally to deliver your booking. They are not shared with organisations for commercial purposes. If you provide your email address with permission to keep you informed of our services, we retain it for that specific purpose.
Business reservations
For business bookings, we additionally process:
- Company name
- Company address details
- Billing address
Preferences and accessibility
To tailor your stay, you may share details such as dietary requirements, accessibility needs or other preferences. We handle these carefully to meet your requests.
Job applications
If you apply for a role, you provide typical application data (e.g., name, contact details, education and work experience). These are used internally by authorised staff only. Retention is up to 4 weeks, extendable to a maximum of one year with your consent.
Camera surveillance
To protect guests and property, camera surveillance is active day and night on and around the premises. Clear stickers indicate monitored areas. Cameras are not used in hotel rooms, public toilets, or wellness facilities. Footage is viewed or shared with third parties (e.g., police) only for urgent reasons such as burglary or theft, and is kept for a maximum of 7 days.
Cookies and analytics
We use cookies to improve website performance and user experience. For analytics, we use privacy-friendly Google Analytics configured so no personal data is shared with Google. You can block or delete cookies via your browser; blocking all cookies may reduce site functionality.
Quick reference table
| Data category | What we collect | Why | Retention/control | Sharing |
|---|---|---|---|---|
| Bookings & stays | Identity, contact, 18+ confirmation, address, payment, stay dates | To confirm and deliver your reservation | Kept only as long as necessary; email may be retained if you consent to updates | Not shared for commercial use |
| Business reservations | Company and billing details | To invoice and manage business bookings | As above | Not shared for commercial use |
| Preferences | Dietary, accessibility, other needs | To tailor services to your needs | As needed to provide service | Not shared for commercial use |
| Job applications | CV data, contact details | To assess and manage applications | 4 weeks; up to 1 year with consent | Not shared with third parties |
| Camera surveillance | Video images (public areas) | Security of guests and property | Max 7 days | May share with police if urgently required |
| Cookies & analytics | Site usage via cookies | Performance and improvements | You can block/delete via your browser | Analytics configured to share no personal data with Google |
How we protect your data
We align security with industry good practice and continually improve safeguards to match risks:
- Encryption in transit: We use SSL where appropriate to protect transmissions of sensitive information or personal data.
- Encryption at rest where possible: We store sensitive information in encrypted form whenever possible.
- Backups: We make backups of personal data where reasonably possible.
- Vulnerability management: We address software vulnerabilities as soon as reasonably possible.
- Physical and electronic protections: Measures are in place to reduce risks of unauthorised access, loss or misuse.
- Processor diligence: Our authorised processors (e.g., software providers, hosting, CRM, privacy-friendly analytics) are bound by Processor Agreements and may not use your data for advertising.
When we may share data
- With processors (service providers): To run secure, reliable systems we work with categories such as software developers/suppliers, hosting providers, storage/database management, research agencies and analytical software (including privacy-friendly Google Analytics configured so no personal data is shared with Google), and relationship-management software. These processors act under contract and only for the Service.
- With your consent: If you opt in to a specific partner service or offer, we may share only the data necessary (e.g., name or contact details) so the partner can provide that service or contact you.
- Legal obligations and safety: We may share data where permitted or required by law, to comply with lawful requests from authorities, respond to claims, or protect the rights, property or safety of our guests, employees, users or the public. We will promptly notify you of government requests related to your data unless the law prohibits us from doing so.
- Business transitions: Personal data may be disclosed or transferred in connection with a merger or sale of (part of) the company.
Your privacy rights — simple answers
Can I see what data you hold about me?
Yes. You can request access to your personal data. We will confirm whether we process your data and provide a copy, explain purposes, categories, recipients, expected storage duration, and your further rights. We may ask you to verify your identity (e.g., with a copy of an ID) to protect your privacy.Can I correct or update my details?
Yes. If data are inaccurate or incomplete, you can request correction or supplementation. We will motivate our response and notify relevant recipients of any corrections.Can I ask you to delete my data?
Yes, in situations such as when data are no longer needed for their original purpose, you withdraw consent and no other legal basis applies, processing is unlawful, or we must erase data to comply with a legal obligation.Can I restrict processing?
Yes. You can request restriction, for example while a correction request is pending, if you contest lawful processing, or if you object to further processing.Can I get a copy of my data or have you send it to another provider?
Yes. If you provided data in a structured, commonly used digital format and we process it based on consent or a contract, you may request a copy or ask us to transfer it to another service provider.Can I object to processing — especially for marketing?
Yes. You may object at any time. If we process your personal data for direct marketing, we will immediately stop upon objection.How do I raise a complaint?
You can follow the official procedure of the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): https://autoriteitpersoonsgegevens.nl/
Accountability and identity
- Data controller: We act as the data controller for personal data we process in connection with our services and website.
- Company registration: Hotel‑Congress Centre De Zeeuwse Stromen is registered with the Chamber of Commerce (KvK Middelburg) under number 220 55586; VAT number NL 8135.36.029.B.01.
Privacy within responsible hospitality
Our approach to privacy sits alongside broader commitments to responsible operations. In our published CSR Declaration, we commit to: continuously expanding CSR knowledge, informing guests and suppliers about responsible practices, limiting negative social and environmental impacts, donating to social causes, and prioritising sustainable, locally sourced products. In daily operations, our Green Policy reinforces mindful choices — and in data handling, that translates to collecting only what we need, keeping it only as long as necessary, and giving you clear control.
Practical takeaways for guests
- Share only what helps us serve you: Dietary or accessibility details ensure we meet your needs during your stay.
- Set your cookie preferences: Use your browser or our cookie controls to manage analytics and other non‑essential cookies.
- Keep communications clear: If you want to receive updates from us, provide consent with your email; you can withdraw it anytime.
- Use your rights: Access, correct, erase, restrict or port your data; object to marketing and we will stop immediately.
- Know where cameras are — and aren’t: Surveillance supports safety in public areas only; never in rooms, public toilets, or wellness facilities.
- Be cautious with third‑party sites: If you follow links from our website, review those sites’ privacy practices before sharing personal information.
Conclusion: Book with confidence
De Zeeuwse Stromen privacy is built on a simple promise: collect only what’s necessary, protect it with robust safeguards, never sell it for commercial use, and put your rights first. If you have questions or wish to exercise a privacy right, contact our team. Ready for a carefree coastal escape? Book your stay with confidence — your data and your downtime are both in safe hands.
Tip for further reading on our site:
- Privacy Statement (full details and procedures)
- CSR Declaration (our broader responsibility commitments)
- Green Policy (how we translate values into daily practice)