Privacy notice

Tartu Hotell greatly values the privacy of every guest. Here we explain what data we collect, why we collect it and what we do with it.
Tartu Hotell is a 118-room hotel in the centre of Tartu. We offer comfortable accommodation in the heart of the city: the bus station is directly opposite the hotel, while the AHHAA Science Centre, Aura Water Centre, the Old Town, the Vanemuine theatre and concert hall and several shopping centres are a short walk away.
We apply the necessary technical, physical and organisational security measures to protect your personal data against loss, destruction and unauthorised access.
If you have any questions about the information in this privacy notice, please contact us at sales@tartuhotell.ee.
We collect the following data about you:
- Personal data, such as your first and last name, date of birth/personal identification code.
- Contact details, such as your home address, telephone number and email address.
- Visitor card data: information about a guest of an accommodation establishment required under the Tourism Act, such as citizenship; the name, date of birth and citizenship of a spouse or minor staying with the guest; the period during which accommodation services are provided; and so on.
- Credit card details, such as the card number, cardholder’s name and expiry date.
- Security camera recordings, if you visit our accommodation establishment or other premises equipped, for security purposes, with video or other electronic or digital monitoring systems or devices.
- Information about personal preferences, such as preferences regarding floor, room, check-in and check-out times and other choices that make your stay at the hotel more pleasant.
As a rule, we receive data directly from you when you make a booking or enquiry through our website, by telephone or email, or when you purchase services in person at our premises.
Your data is also provided to us by travel operators, booking operators and other accommodation intermediaries from whom you have ordered accommodation and/or other services with us.
We use your data to provide the accommodation and/or other services you have ordered, to fulfil obligations imposed on us by the laws governing our activities and for general business purposes, including:
- Personal data: we need this information to verify your identity, which is important for ensuring that the service is provided to the person who actually ordered it.
- Contact details: we need this information to contact you. We primarily contact you by telephone or email, but in certain cases we may also need to use your home address (for example, if we cannot reach you through other means of communication).
- Visitor card data: we are required to request this information under the Tourism Act. Its purpose includes preventing risks such as illegal immigration.
- Credit card details: we need this information if, under the accommodation agreement, we are entitled to charge a certain amount to your credit card as payment for services you have ordered or reimbursement of expenses incurred.
- Information about personal preferences: if we ask for this information or you choose to disclose it to us, we use it to provide a better service tailored to your wishes and interests.
If you do not provide the visitor card data, we cannot provide you with accommodation services.
Collecting data is necessary to ensure that services are provided smoothly, your stay is successful and your guest experience is positive. After providing the service, Hotell Tartu OÜ may send notifications to your email address to request feedback, inform you about forgotten items or resolve problems that arose during your stay.
We rely on various legal bases when processing your data:
- The need to establish a contractual relationship with you or perform a contract concluded with you.
- Your consent – when we rely on your consent to process personal data, please note that you have the right to withdraw your consent at any time.
- The need to comply with legal obligations imposed on us (for example, completing and retaining the visitor card for 2 years).
- The need to pursue our legitimate interests, including managing the company and carrying out general business activities, and detecting violations of law and fraud.
- The need to protect your vital interests or those of another person (for example, by disclosing your data to emergency medical personnel in the event of an accident).
- Any other basis permitted by law.
We do not share data entrusted to us by you except in the limited cases described below and where doing so is necessary to achieve the purposes set out in this privacy notice:
- Our subsidiaries and affiliates: we may share your personal data with our subsidiaries or affiliates, all of which are located in the European Union.
- Service providers: like many other companies, we may commission data-processing services from trusted third-party providers, such as IT and consultancy service providers.
- Public authorities and government agencies: we may share data with authorities where required by law or where sharing is necessary to protect our rights.
- Professional advisers and others: we may share your data with professional advisers such as auditors, lawyers, accountants and other providers of advisory services.
- Third parties in connection with corporate transactions: from time to time, we may share your data with third parties as part of a corporate transaction, such as the sale of the company or part of it to another company. This also includes a restructuring, establishment of a joint venture, merger or another transfer of company assets or shares.
If we share your data with the parties listed above, we ensure that your data is protected by a data-processing agreement between us and that party.
We do not store or transfer your personal data outside the European Economic Area or to countries for which no adequacy decision has been adopted under Article 25(6) of Directive 95/46/EC or Article 45(1) of its successor, Regulation (EU) 2016/679.
We retain your data for as long as necessary to fulfil the various purposes of data processing.
The company applies the following criteria when retaining personal data:
- For as long as the personal data needs to be retained in order to provide our services.
- If a person has a customer account or customer card with the company, we retain personal data throughout the active period of the account/card or for as long as it is needed to provide services to the person.
- If the company has a legal, contractual or similar obligation to retain personal data, for as long as necessary to fulfil that obligation.
- After the contractual relationship ends, we retain certain data for as long as the person (data subject) or the company itself has the right to make contractual claims against the other party.
For example, we retain visitor card data for 2 years after the card is completed, as required by the Tourism Act. We retain credit card details only until the accommodation agreement between us has been duly performed.
If you have consented to receive direct-marketing materials from us, we retain your contact details until you withdraw that consent.
As a data subject, you have the following rights:
- Right of access – you have the right to know what data is retained about you and how it is processed.
- Right to rectification – you have the right to request correction of your personal data if it is inaccurate.
- Right to erasure (“right to be forgotten”) – in certain circumstances, you have the right to request that we erase your personal data (for example, if we no longer need it or you withdraw the consent you gave us for processing it).
- Right to restriction of processing – in certain circumstances, you have the right to prohibit or restrict the processing of your personal data for a period of time (for example, if you have objected to the processing).
- Right to object – depending on the specific circumstances, you have the right to object to the processing of your personal data where it is based on our legitimate interests or the public interest. You may object to the processing of personal data for direct-marketing purposes at any time.
- Right to data portability – you have the right to request that data you have provided to us be transferred to you in a machine-readable format. You may also ask for the data to be transferred directly to another controller, but only where technically feasible. This right applies only to data that we process on the basis of your consent or to perform a contract with you.
We do our best to address your requests and wishes promptly and free of charge, except where doing so would involve disproportionate cost. If you are not satisfied with our response, you may lodge a complaint with the Estonian Data Protection Inspectorate.