Privacy Policy

Last updated: 02 September 2025

This Privacy Policy explains how Narayan Hotels & Resorts ("we", "our", "us") collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

1. Data controller

The data controller responsible for your personal data under applicable German and European data protection laws is:

Narayan Hotels & Resorts GmbH
📍 Hauptstraße 34, 34265 Hamburg, Germany
📧 privacy@narayanhotels.com

2. Data we collect

  • Booking information: Name, contact details, payment details, and stay preferences.
  • Account details: If you register with us, we may store your login data and preferences.
  • Technical data: IP address, browser type, device information, cookies, and analytics data.
  • Communication data: Inquiries via email, phone, or contact forms.

3. Purpose of processing

We process your personal data for the following purposes:

  • To manage bookings, payments, and customer support.
  • To provide personalized offers and services during your stay.
  • To comply with German legal obligations (e.g., retention of invoices, guest registration under local law).
  • For marketing activities, only if you have given consent.

4. Legal basis

  • Article 6(1)(b) GDPR: Processing necessary for the performance of a contract (e.g., hotel booking).
  • Article 6(1)(c) GDPR: Processing to comply with legal obligations under German law.
  • Article 6(1)(f) GDPR: Legitimate interest in improving services and ensuring IT security.
  • Article 6(1)(a) GDPR: Processing based on your consent (e.g., newsletters, marketing cookies).

5. Data sharing

We only share your data with trusted third parties when necessary:

  • Payment providers (for secure transactions).
  • IT and hosting service providers located in the EU.
  • Public authorities, where required by German law (e.g., guest registration).

We never sell your data to third parties.

6. International transfers

If your data is transferred outside the European Economic Area (EEA), we ensure adequate safeguards are in place, such as EU Standard Contractual Clauses, to protect your data.

7. Retention period

We store personal data only as long as necessary:
- Booking and billing data: up to 10 years (as required by German tax law).
- Marketing data: until you withdraw your consent.
- Technical and analytical data: up to 12 months.

8. Your rights under GDPR

As a data subject under GDPR and German data protection law, you have the right to:

  • Access your personal data (Art. 15 GDPR).
  • Request rectification of inaccurate data (Art. 16 GDPR).
  • Request deletion of your data ("right to be forgotten", Art. 17 GDPR).
  • Restrict or object to processing (Art. 18 & 21 GDPR).
  • Data portability (Art. 20 GDPR).
  • Lodge a complaint with the German supervisory authority:
    Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI).

9. Security

We use technical and organizational measures to protect your data against unauthorized access, alteration, or loss, in compliance with German IT security standards.

10. Updates

We may update this Privacy Policy to reflect changes in law, technology, or our services. Updates will always be published here with a new “Last updated” date.

11. Contact

For any privacy-related inquiries, please contact us:
📧 help@narayanresort.com
📍 Hauptstraße 34, 34265 Hamburg, Germany
☎️ +49 40 5820 9113