The Personal Data Protection Policy Document describes the process of processing personal data by “Merebashvili Estate” LLC and the guarantees for the protection of the rights of the data subject during the processing process.
The terms used in this document have the meaning defined by the Law of Georgia “On Personal Data Protection”.
“Merebashvili Estate” LLC respects the legislation of Georgia and international standards in the field of human rights protection. Protecting the confidentiality of our guests, employees, and persons in contractual relations with us is particularly important to us. Accordingly, we apply all necessary organizational and technical security measures to protect your personal data.
1. Legislation Underlying the Personal Data Protection Policy Document
- 1.1. Legislation of Georgia: Your personal data are processed in accordance with the Law of Georgia “On Personal Data Protection”.
- 1.2. International Standards: Your rights are protected in accordance with the legislation of Georgia and the European General Data Protection Regulation (GDPR).
- 1.3. Regulatory Recommendations: We take into account the recommendations of the Personal Data Protection Service of Georgia in order to protect your rights with the best standard.
- 1.4. Right to Request Information: You have the right, based on the above-mentioned regulations, to request information about our processing of your personal data.
- 1.5. Responsibilities and Time Limits: We are ready to provide you with the information you request at the earliest opportunity and within the time limits established by the legislation of Georgia.
2. Person Responsible for the Processing of Personal Data
- Company Name: LLC “Merebashvili Estate” (hereinafter referred to as “we”)
- Identification Number: 432553186
- Address: Georgia, Kaspi, V. Gorgasali Street, N 29
- Telephone Number: +995 510100444
- E-mail: Info@merebashvili.com
3. Compliance with Data Processing Principles
We adhere to the following principles in the data processing process:
- 3.1. Principle of Lawfulness and Fairness: We process your personal data only in accordance with the rules and grounds established by law. We ensure proper protection of your rights in compliance with the principle of equality (non-discrimination).
- 3.2. Principle of Transparency: The data processing process is transparent to you, as the data subject. You can contact us at any time and receive information about the processing of your personal data in accordance with the procedure and within the time limits established by the legislation of Georgia.
- 3.3. Principle of Purpose Limitation: We process personal data only for the specific purpose for which they were obtained. We request your consent again to use data obtained with your consent for another purpose.
- 3.4. Data Minimization Principle: We process data only to the extent necessary to achieve the purpose, taking into account the proportionality of the purpose and the volume of data.
- 3.5. Data Accuracy Principle: We ensure that the personal data stored with us are accurate and truthful. We immediately correct or delete inaccurate data, both upon your request and in the event of our discovery of an error.
- 3.6. Time Limitation Principle: We store data only for the period necessary to achieve the purpose. We pre-determine a specific period for the storage of personal data or indicate the criteria for determining the period.
- 3.7. Data Security Principle: In order to protect the security of data, we take such technical and organizational measures when processing data that adequately ensure the protection of data, including against unauthorized or unlawful processing, accidental loss, destruction, and/or damage.
4. Purposes of Processing Personal Data
We process personal data for the following specific purposes:
- 4.1. To provide the offered products and services;
- 4.2. To carry out automatic payment procedures;
- 4.3. To conclude a contract or transaction;
- 4.4. For special offers and marketing purposes for customers;
- 4.5. To hold events on the territory of the hotel;
- 4.6. For analytical and statistical purposes, to understand how our customers interact with our website;
- 4.7. To conduct various studies in order to improve products and services, and to study how customers use our products and services;
- 4.8. To develop and manage our brands, products, and services;
- 4.9. To improve the quality of service and take into account the wishes/preferences of the customer;
- 4.10. To protect security and property;
- 4.11. To respond appropriately to violations of the hotel rules.
5. Sources and Methods of Obtaining Personal Data
- 5.1. Hotel Visitors:
- When the data subject makes a hotel reservation online, through the contact center, or when purchasing services on site. Information about accompanying persons is collected in the same way, with their consent.
- When paying for services online.
- From partner websites (e.g. Booking.com), through which reservations are made for our hotel rooms, based on agreements concluded with them.
- 5.2. Members Registered on Our Website:
- When registering on the hotel website, we obtain data directly from the data subject, who enters the data himself/herself and confirms consent to the processing of personal data by checking the appropriate box.
- 5.3. Visitors to Our Website:
- When visiting our website, we obtain information in accordance with the Cookies Policy.
- 5.4. Members of the Loyalty Program:
- The data subject, who becomes a member of the loyalty program, enters the data himself/herself on the website and agrees to join the loyalty program.
- 5.5. Persons in Employment Relationships:
- In order to make a decision on employment and to conclude an employment contract, we obtain personal data directly from data subjects, as well as from their recommenders.
- 5.6. Participants in Events Held at the Hotel:
- In case of using the hotel’s conference space within the framework of a contract, the participating party may provide us with information about the persons participating in the event (names and surnames) for the purpose of granting entry access.
- 5.7. Direct Marketing:
- Personal data is obtained from the data subject for direct marketing only on the basis of his/her written consent, in accordance with the procedure established by the Law of Georgia “On Personal Data Protection” and with guarantees of protection of rights in accordance with section 6 of this document.
- 5.8. Persons Within the Perimeter of the Hotel:
- For the purpose of security and property protection, video monitoring is carried out in the building and on its external perimeter. A warning sign is prominently displayed. Employees are additionally warned in writing. Detailed rules can be found in the document: “Standard Operating Procedure on Video Monitoring”.
- 5.9. Restaurant Customers / Catering Services Users:
- We obtain information about restaurant customers/data subjects when they make a reservation (physically, by phone, or using a booking application) and when making a payment.
6. Processing of Personal Data for Direct Marketing
For the purpose of direct marketing, personal data shall be processed only on the basis of the informed, written consent of the data subject through a special form.
Before giving consent, the data subject shall be provided with the following information:
- 6.1. Identity of the person responsible for the processing of personal data;
- 6.2. List of personal data processed for direct marketing in case of consent;
- 6.3. Specific purposes of data processing;
- 6.4. Form of receiving notifications/information from the company;
- 6.5. Guarantees for the protection of personal data and rights of the data subject;
- 6.6. Period of processing of personal data;
- 6.7. Withdrawal of consent and withdrawal mechanisms;
- 6.8. Possible consequences of withdrawal of consent.
7. Rights of the Data Subject
We protect the rights of the personal data subject guaranteed by the Georgian Law on Personal Data Protection and the European General Data Protection Regulation (GDPR), including:
- 7.1. Right to Receive Information About Data Processing:
Upon request, no later than 10 days, we will provide information about: processed data, basis and purpose, source, storage period (or criteria to determine it), and legal guarantees for data transfer to third parties. - 7.2. Right to Be Informed About Incidents:
In the event of a data security breach (incident) likely to cause significant damage or threat, we will inform the data subject immediately about the circumstances, likely/actual damage, mitigation measures, and contact details of the Data Protection Officer. - 7.3. Right to Access and Obtain a Copy:
The data subject may request copies of processed personal data free of charge. Reasonable fees may apply if provision in a different format requires additional resources. - 7.4. Right to Rectification, Updating, and Completion:
The data subject has the right to request correction, updating, or completion of inaccurate/incomplete data. All data recipients will be notified of such rectifications. - 7.5. Right to Erasure, Deletion, or Destruction:
Requests must be fulfilled no later than 10 days. Deletion may be refused only in exceptional cases established by Georgian legislation. - 7.6. Right to Block Data:
Data will be blocked if accuracy is disputed, processing is unlawful, data is needed for a legal claim, deletion request is under review, or storage is necessary for evidence. - 7.7. Right to Withdraw Consent:
The data subject has the right to withdraw consent at any time without justification. Processing must cease and data be deleted within 10 working days of request.
8. Protection of Personal Data of Minors
We process personal data of minors in accordance with the Law on Personal Data Protection, based on the consent of a parent or legal representative, taking into account the best interests of the minor.
9. Data Security Measures
- 9.1. We apply all necessary technical and organizational security measures to protect personal data against unauthorized or unlawful access, accidental loss, damage, disclosure, or destruction.
- 9.2. After the processing purpose expires, we regularly delete/destroy personal data or store it in an anonymized/depersonalized form for analytical and statistical purposes.
- 9.3. Affiliated companies and authorized third parties are bound by contract to protect personal data according to the same standards.
- 9.4. Detailed security descriptions are available in internal documents: “Description of Measures Taken to Secure Personal Data” and “Standard Operating Procedure for Video Monitoring”.
10. Transfer of Data to Third Parties
Processed personal data is not transferred to third parties except in the following cases:
- 10.1. Affiliated Companies:
Interconnected entities (under common ownership, management, or control) based on agreements containing confidentiality and data protection guarantees. - 10.2. Technical Service Providers:
Companies that carry out technical sending of notifications/information under contract (only phone number or email address is transferred).
11. Cookies Policy
- 11.1. Definition: “Cookies” are small text files stored on your computer or mobile device when visiting a website, helping us improve efficiency and manage user navigation.
- 11.2. Confidentiality: We do not store addresses, passwords, credit/debit card information, or other sensitive personal data in cookie files.
- 11.3. Analytical Tools:
We use Google Analytics and Facebook Pixel services to obtain statistical data (search content, pages visited, city/country, time spent, operating system, age, gender, interests, device language, etc.). This information is processed solely for statistical purposes and does not allow personal identification. - 11.4. Consent: Collection of cookie information is subject to your consent upon visiting our website.
12. Document Updates
This policy document is subject to periodic updates as necessary according to legal or operational requirements.
13. Contact Information
- Telephone Number: +995 510100444
- E-mail: Info@merebashvili.com
