Privacy Policy
Last Updated: 1st Jan 2025
Welcome to KAYA Zurich Apartments (“KAYA,” “we,” “us,” or “our”). We value your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, process, disclose, and safeguard your information when you visit https://www.kayazurich.com (the “Site”) and when you book and stay in our serviced apartments. This Privacy Policy also describes your rights regarding your personal data.
By accessing our Site or using our Services, you acknowledge you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree with the terms herein, please discontinue your use of our Site and Services.
1. Definitions
- “Personal Data”: Any information relating to an identified or identifiable individual, such as name, email, phone number, IP address, or financial details.
- “Processing”: Any operation performed on Personal Data, whether or not by automated means, including collection, storage, use, disclosure, or erasure.
- “Services”: The services provided by KAYA Zurich Apartments, including our website, online booking, and accommodation offerings.
2. Legal Framework and Scope
-
Swiss Law
- KAYA operates under Swiss law, including the Swiss Federal Data Protection Act (FADP). We strive to comply with its rules and regulations regarding the protection and handling of Personal Data.
-
GDPR (EU General Data Protection Regulation)
- If you are located in the European Union (EU), we also endeavor to comply with the GDPR regarding the Processing of your Personal Data. This ensures that you have the same rights, regardless of your location.
-
Applicability
- This Privacy Policy applies to the Personal Data collected by us when you visit our Site, interact with our social media channels, or use our Services (e.g., booking an apartment).
3. Data Controller
For the purposes of the Swiss FADP and GDPR, the Data Controller is:
KAYA Zurich Apartments
Website: https://www.kayazurich.com
Email: contact@kayazurich.com
4. Types of Personal Data We Collect
We may collect and process various types of Personal Data, including but not limited to:
-
Identification Information
- Full name, date of birth, nationality, ID/passport details.
-
Contact Information
- Email address, phone number, postal address.
-
Booking and Reservation Information
- Dates of stay, room type, special requests, number of guests, and payment details.
-
Financial Data
- Credit/debit card information, billing address, transaction history.
-
Usage Data
- Details about how you use our Site, including IP address, browser type, operating system, geographic location (country/city), referring URLs, pages visited, and time spent on those pages.
-
Communication Data
- Emails, phone calls, or live chat logs, including any personal information shared in your messages or calls to our support or reservations team.
-
Cookies and Similar Technologies
- Information collected automatically through cookies, web beacons, or other tracking technologies to analyze Site usage and enhance your user experience. (See Section 10 for more details.)
-
Special Categories of Personal Data
- In limited circumstances, we may collect information related to specific preferences or requirements, such as dietary restrictions (which may reveal religious or health information) or accessibility needs. Where required by law, we will seek your explicit consent to process this data.
5. How We Collect Your Personal Data
-
Direct Interactions
- When you provide your information through our online booking form, during check-in, or via email or telephone.
-
Third-Party Booking Platforms
- When you make a reservation through third-party booking websites or travel agencies (e.g., Booking.com, Airbnb, Expedia), we may receive your Personal Data from them.
-
Automated Technologies
- As you interact with our Site, we automatically collect certain data (Usage Data, Cookies) through browser interactions.
-
In-Person
- We may collect additional Personal Data when you check into our apartments (passport details, ID verification, etc.) or when you use on-site facilities and services.
6. Purposes and Legal Bases for Processing
We process your Personal Data for the following purposes and in accordance with the following legal bases under Swiss law and (where applicable) GDPR:
-
To Provide and Manage Our Services
- Purpose: Process bookings, manage check-ins and check-outs, facilitate payment, and organize your stay.
- Legal Basis: Performance of a contract (GDPR Art. 6(1)(b)) and legitimate interests.
-
Customer Support and Communication
- Purpose: Respond to inquiries, send booking confirmations, address issues, and provide customer service.
- Legal Basis: Performance of a contract (GDPR Art. 6(1)(b)) or legitimate interests.
-
Legal and Regulatory Compliance
- Purpose: Comply with Swiss immigration law, accounting, tax regulations, and other mandatory legal obligations.
- Legal Basis: Compliance with a legal obligation (GDPR Art. 6(1)(c)).
-
Marketing and Promotions
- Purpose: Send newsletters, promotional materials, or offers related to our Services (provided you have not opted out).
- Legal Basis: Consent (GDPR Art. 6(1)(a)) or legitimate interests (GDPR Art. 6(1)(f)) where applicable.
-
Analytics and Service Improvement
- Purpose: Evaluate user engagement, improve Site functionality, and develop new features or services.
- Legal Basis: Legitimate interests (GDPR Art. 6(1)(f)).
-
Security and Fraud Prevention
- Purpose: Detect and prevent fraudulent bookings, abusive usage, or any malicious activity.
- Legal Basis: Legitimate interests (GDPR Art. 6(1)(f)).
-
Special Categories (If Applicable)
- Purpose: Accommodate specific requests (e.g., health, dietary needs) that may reveal sensitive data.
- Legal Basis: Explicit consent (GDPR Art. 9(2)(a)).
7. How We Share Your Personal Data
We only share your Personal Data when necessary and for the purposes outlined below:
-
Service Providers
- We may share your Personal Data with trusted third-party vendors who assist us in delivering our Services, such as payment processors, website hosting providers, and IT support. These vendors are contractually required to process Personal Data only in accordance with our instructions and to ensure appropriate security measures.
-
Law Enforcement and Regulatory Bodies
- If required by law, court order, or legal process, we may disclose your Personal Data to relevant authorities. This could include compliance with tax authorities, local police, immigration offices, or courts.
-
Third-Party Booking Platforms
- If you initially booked through a third-party platform, we may provide updates (e.g., confirmation of stay, changes to reservation) to that platform as necessary.
-
Business Transfers
- In the event of a merger, acquisition, or sale of all or a portion of KAYA’s assets, your Personal Data may be transferred to the acquiring entity subject to legal restrictions.
-
Consent
- We will share your Personal Data with third parties when we have obtained your explicit consent to do so for a specific purpose not covered by this Privacy Policy.
8. International Data Transfers
-
Within the EU/EEA
- If your Personal Data is transferred to a country within the EU/EEA, it will be protected by GDPR-compliant safeguards.
-
Outside the EU/EEA
- If we transfer your Personal Data to countries outside of Switzerland or the EU/EEA, we will ensure that the transfer is in compliance with data protection laws and subject to appropriate safeguards (such as standard contractual clauses approved by the European Commission).
-
Your Rights in Data Transfers
- You may request a copy of or reference to the safeguards we use to transfer Personal Data outside the EU/EEA by contacting us at contact@kayazurich.com.
9. Data Retention
-
Retention Period
- We store Personal Data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy or to comply with legal obligations (e.g., accounting or tax requirements). For instance, Swiss law may mandate the retention of certain financial records for a minimum period.
-
Deletion and Anonymization
- When we no longer need your Personal Data for the specified purposes, we will securely delete or anonymize it. Anonymized data may be retained for statistical and analytical purposes.
10. Cookies and Similar Technologies
-
What Are Cookies?
- Cookies are small text files placed on your device’s hard drive by a web server when you visit certain websites. They help websites function more efficiently, remember user preferences, and provide usage analytics.
-
Types of Cookies We Use
- Essential Cookies: Necessary for the Site’s operation, such as enabling secure log-ins or remembering your booking details.
- Analytics Cookies: Collect aggregated information to help us understand how users interact with our Site (e.g., pages visited, time spent).
- Functional Cookies: Remember your preferences (e.g., language, currency) to enhance your experience.
- Advertising Cookies (if applicable): Used to deliver relevant ads or track campaign performance.
-
Cookie Management
- You can manage or disable cookies through your browser settings. Note that disabling certain cookies may affect the functionality of the Site.
-
Third-Party Tracking
- Some third-party service providers (e.g., Google Analytics) may place their own cookies on your device. These providers have their own privacy policies and cookie management practices.
11. Your Data Protection Rights
If the GDPR applies to you or under certain Swiss data protection principles, you may have the following rights:
-
Right to Access
- You can request details of the Personal Data we hold about you and how we process it.
-
Right to Rectification
- You have the right to request that we correct any inaccuracies in your Personal Data.
-
Right to Erasure (“Right to be Forgotten”)
- You can ask us to delete your Personal Data in certain circumstances (e.g., if it is no longer needed for the purposes it was collected).
-
Right to Restrict Processing
- You can request that we temporarily or permanently stop Processing all or some of your Personal Data.
-
Right to Object
- You can object at any time, on grounds relating to your particular situation, to the Processing of your Personal Data for direct marketing or legitimate interests.
-
Right to Data Portability
- You have the right to request a copy of your Personal Data in a structured, commonly used, machine-readable format, and to transfer it to another controller, where technically feasible.
-
Right to Withdraw Consent
- If we are processing your Personal Data based on your consent, you can withdraw your consent at any time. This does not affect the lawfulness of any Processing carried out prior to withdrawal.
-
Filing a Complaint
- If you believe your rights under Swiss law or GDPR have been violated, you can file a complaint with the Swiss Federal Data Protection and Information Commissioner or your local supervisory authority in the EU/EEA.
To exercise any of these rights, please contact us at contact@kayazurich.com. We may need to verify your identity before fulfilling your request.
12. Security Measures
-
Technical Measures
- We implement industry-standard security protocols such as encryption (TLS/SSL), firewalls, and secure server infrastructures to protect your Personal Data against unauthorized access or disclosure.
-
Organizational Measures
- Our staff undergo regular training on data protection requirements. Access to Personal Data is restricted to personnel who need it for their duties.
-
Incident Response
- In the event of a data breach, we will notify affected individuals and the appropriate supervisory authority within the legal timeframes, as required by law.
13. Children’s Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect Personal Data from minors. If you believe we have inadvertently collected data from a minor, please contact us at contact@kayazurich.com, and we will promptly delete such information.
14. Third-Party Links
The Site may contain links to third-party websites or resources. This Privacy Policy does not apply to those external websites or services, and we are not responsible for their content or privacy practices. We encourage you to review the privacy policies of any third-party sites you visit.
15. Changes to This Privacy Policy
- Updates
- We may update this Privacy Policy from time to time to reflect changes in our operations, legal requirements, or industry best practices.
- Notification
- Any significant changes will be posted on our Site with an updated “Last Updated” date. We may also notify you via email if required by law or if the changes materially affect your rights.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
KAYA Zurich Apartments
Website: https://www.kayazurich.com
Email: contact@kayazurich.com