PRIVACY POLICY
YOUR PRIVACY (Kenya)
Introduction
At Palacina the Residence & The Suites, Nairobi, we are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and protect your personal information in compliance with Kenya’s Data Protection Act, 2019 and relevant regulations.
Data Controller
Palacina The Residence & The Suites, Nairobi (the "Hotel", "we", "us") is the data controller responsible for processing personal data collected through this website and other interactions.
Information We Collect
We may collect personal data including:
- Contact details (name, address, phone, email)
- Booking information
- Website usage data
- Preferences and communications
We collect this data only where you voluntarily provide it via online forms, bookings, newsletters, customer service enquiries, surveys, or similar.
Legal Basis for Processing
We process personal data only:
- with your voluntary and informed consent;
- to perform a contract (e.g., booking services);
- to comply with legal obligations;
- or to protect our legitimate interests.
Consent
By providing personal data, you give clear, informed consent for its use for specific purposes. You may withdraw consent at any time by contacting us.
Use of Cookies & Tracking Technologies
We use cookies and similar technologies to improve your browsing experience. Before placing non-essential cookies, we will obtain your explicit consent. You can manage or refuse cookies via your browser settings or our consent tool.
How We Use Your Personal Data
We use your data to:
- deliver services you request (e.g., reservations, newsletters);
- improve our website and services;
- send administrative or marketing communications only if you have opted-in.
You can unsubscribe or opt-out of marketing at any time via the unsubscribe link or by contacting us.
Sharing & Transfers of Your Data
We do not sell personal data to third parties. We may share data with:
- third parties who provide services (e.g., booking systems), subject to strict confidentiality and security commitments;
- law enforcement or regulatory authorities when required by law.
Where personal data is transferred outside Kenya, we will ensure adequate safeguards or obtain consent.
Data Security
We implement reasonable security measures (encryption, access controls) to protect personal data against loss, unauthorized access, alteration, or destruction.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected or to comply with legal obligations. After that, data will be securely deleted or anonymised.
Your Rights
Under Kenya's Data Protection Act, you have the right to:
- access your personal data;
- correct inaccurate data;
- request deletion ("right to be forgotten");
- withdraw consent;
- object to processing;
- complain to the Office of the Data Protection Commissioner.
Data Protection Officer (DPO)
If applicable, you may contact our DPO at:
[Insert email/phone]
Changes to This Policy
We may update this policy; changes will be posted here with an updated effective date.
Contact Us
For privacy questions or exercise of rights, contact:
info@palacina.com and +254 733 777 173
OUR RESPONSIBILITIES UNDER UK & EU GDPR
Data Controller
For the purposes of UK and EU data protection law, the data controller is:
Palacina The Residence & The Suites, Nairobi
Email: manager@palacina.com
Telephone: +254-733-777-173
Lawful Basis for Processing
We collect and process your personal data only where we have a lawful basis to do so, including:
- Contractual necessity – to provide accommodation, reservations, billing and guest services.
- Consent – for marketing communications such as newsletters or promotional offers.
- Legal obligation – where required by law (e.g. tax or regulatory compliance).
- Legitimate interests – including internal analytics, fraud prevention, service improvement and security.
Types of Personal Data We Collect
This may include:
- Name, contact details
- Booking and payment information
- Communication records
- Website usage data
- Preferences and special requests
We do not knowingly collect special category data unless required for guest services (e.g. accessibility needs).
Your Rights Under UK & EU GDPR
If you are located in the UK or EU, you have the right to:
- Be informed about how your data is used
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing
- Object to processing
- Data portability
- Not be subject to automated decision-making
To exercise any of these rights, contact us at:
We will respond within 30 days as required by law.
Withdrawing Consent
Where we rely on your consent, you may withdraw it at any time by:
- Using unsubscribe links in emails
- Contacting us directly
Withdrawal does not affect processing already carried out lawfully.
Data Retention
We retain personal data only for as long as necessary for:
- Service delivery
- Legal compliance
- Accounting and regulatory obligations
Typical retention periods:
- Booking records: up to 7 years
- Marketing data: until consent is withdrawn
- Enquiry data: up to 24 months
Data is then securely deleted or anonymised.
International Data Transfers
Where your data is transferred outside the UK or EU, we ensure appropriate safeguards, including:
- UK International Data Transfer Agreement (IDTA)
- EU Standard Contractual Clauses (SCCs)
- Transfers to countries with adequacy decisions
We do not rely on generic "GDPR compliance" claims.
Data Security
We implement appropriate technical and organizational measures including:
- Encryption
- Access controls
- Secure servers
- Staff confidentiality obligations
Right to Lodge a Complaint
You have the right to complain to a supervisory authority:
UK:
Information Commissioner's Office (ICO)
EU:
Your local data protection authority in your country of residence.
Third Parties
We may share data with trusted service providers (e.g. booking platforms, payment processors) who act as data processors under contract and confidentiality.
We never sell personal data.
Automated Decision Making
We do not carry out automated decision-making or profiling that produces legal or significant effects.
Updates
We may update this notice from time to time. The latest version will always be available on our website.
CHANGE IN PRIVACY POLICY
As we plan to ensure our privacy policy remains current, this policy is subject to change. We may modify this policy at any time, in our sole discretion and all modifications will be effective immediately upon our posting of the modifications on this website. Please return periodically to review our privacy policy.
If you have any questions or concerns at any time about our privacy policy or the use of your personal information, please contact us call us and we will respond within 48 hours.
Contact Details: