PRIVACY POLICY

Who We Are

Cevio Hotel Corporation (“Cevio”, “we”, “our”, or “us”) values and protects privacy and is committed to safeguarding personal data in accordance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012, its Implementing Rules and Regulations, and all relevant issuances of the National Privacy Commission (“NPC”).

This Privacy Policy explains how we collect, use, process, store, disclose, and protect your personal data when you access our website, create an account, make reservations, avail of hotel services, or otherwise interact with us.

Coverage

This Privacy Policy applies to personal and other data that we collect through our website, social media pages, email communications third party partners, and during your stay or visit at our hotel. It covers guests, prospective guests, website users, account holders, and all other individuals who interact with Cevio.

Acceptance of this Policy

By accessing our website, creating an account, making a reservation, submitting personal information, availing of our services, or otherwise interacting with Cevio, you acknowledge that you have read, understood, and agreed to this Privacy Policy.

Data We Collect

We collect, use, and keep personal information, and where applicable, sensitive personal information. This may include, but is not limited to, the following:

• Personal identification information - full name, birth date, gender, nationality, address, contact details;
• Government-issued identifiers - passport details and other government identification documents;
• Booking and accommodation details - room preferences, travel information, arrival/departure schedules, companions, special requests, and stay history;
• Payment and billing information - processed through accredited payment providers;
• Account credentials - for users who create website accounts;
• Health and dietary information– collected in connection with providing our food and beverage services and spa treatments;
• CCTV footage and security records – collected in common/public areas within hotel premises;
• Marketing data - preferences, survey responses, and promotional participation details;
• Sensitive personal information - where necessary, such as health information, disability accommodations or emergency-related details.

Purposes of Processing

We process personal data for lawful purposes including but not limited to: reservation management, hotel operations, guest verification, payment processing, security and fraud prevention, customer service, compliance with legal obligations, data analytics, website enhancement, marketing and promotional activities (with consent where required), and enforcement of hotel policies.

Legal Bases for Processing

The processing of personal data may be based on your consent, performance of a contract, compliance with legal obligations, protection of legitimate interests, establishment, exercise, or defense of legal claims, and other lawful criteria under applicable laws and regulations.

How Data is Collected

We collect personal data directly from you through website reservations, account creation, emails, phone calls, hotel check-in, customer support, and surveys. We also gather information through CCTV systems within hotel premises, as well as from third-party booking platforms, travel agents, and authorized representatives acting on your behalf.

Third-Party Sharing

Personal data may be shared, when necessary, with accredited payment processors, booking engines, travel platforms, IT service providers, cloud storage providers, insurers, legal advisers, regulators, and government agencies. All third parties are required to implement appropriate safeguards and maintain strict confidentiality obligations in accordance with applicable data protection laws.

CCTV and Security

CCTV systems may operate in common and public areas of the hotel to promote safety, maintain security, support incident investigation, prevent fraud, and protect property. CCTV is not installed in private areas where guests and employees have reasonable expectation of privacy.

Marketing Communications

Where permitted by law or with your consent, Cevio may send promotional messages, special offers, and service updates. Users may opt out of receiving such communications at any time through the provided unsubscribe mechanisms or by directly contacting us.

Data Retention and Disposal

Personal data shall be retained only for as long as necessary to fulfill contractual, legal, regulatory, accounting, tax, operational, safety, and other legitimate business purposes. Upon expiration of the applicable retention period, files shall be permanently deleted or records shall be securely disposed of to prevent unauthorized access, processing, or disclosure.

Data Security

Cevio implements all reasonable measures to protect personal data against unauthorized access, alteration, disclosure, misuse, or loss/destruction.
To ensure the integrity and security of personal information, we implement organizational, physical, and technical safeguards, including:

• Access controls and authentication systems
• Data encryption and secure storage
• Regular monitoring, audits, and risk assessments
• Employee training on data privacy and security

These measures are subject to periodic review and will be upgraded in line with technological advancements and evolving regulatory requirements.

Rights of Data Subjects

In accordance with the Data Privacy Act of 2012, data subjects are entitled to the following rights:

• Right to be informed - to know when and how personal data is collected, processed, or shared.
• Right to object - to refuse or withdraw consent to the processing of personal data, subject to legal and contractual limitations.
• Right to rectification - to request correction of inaccurate or incomplete personal data.
• Right to erasure or blocking - to request deletion or blocking of personal data under circumstances allowed by law.
• Right to lodge a complaint with the NPC - to file complaints with the National Privacy Commission (NPC) for any violation of data privacy rights.

Data Breach Notification

In the event of a personal data breach, Cevio shall:

• Conduct a Risk Assessment - Evaluate the nature, scope, and potential impact of the breach.
• Notify the National Privacy Commission and the affected data subject/s within the prescribed period, where required by law.
• Implement Corrective Measures – Take immediate steps to contain the incident and adopt safeguards to prevent recurrence.

Policy Updates

Cevio reserves the right to amend this Privacy Policy from time to time. Updates shall be posted on the official website and shall take effect immediately upon posting, unless otherwise stated.

Contact Information

Data Protection Officer – Cevio Hotel Corporation
206 Justice Romualdez St., Brgy. 25, Tacloban City, Leyte
Email: dpo@ceviohotels.com
Contact Number: 09175840408