Personal data

PERSONAL DATA PROTECTION POLICY

Last updated: September 14, 2026 

The protection of your personal data is important to Germain Collection and to the establishment hosting you. This policy clearly explains what data is processed, for what purposes, for how long, with whom it may be shared, and how to exercise your rights. It is established in accordance with Regulation (EU) 2016/679 of April 27, 2016, known as the General Data Protection Regulation (GDPR), and Law No. 78-17 of January 6, 1978, as amended, known as the Data Protection Act. 

1. Scope 

This policy applies to the website www.hotel-saintchristophe.fr, interactions with Hôtel Saint-Christophe, and related services that collect personal data: requests for information, reservations, stays, dining, events, recruitment, and communications regarding your stay. 

It does not apply to third-party websites or services accessible via a link from our platforms. These third parties have their own privacy policies. 

2. Data Controller 

The data controller is Germain Collection, SAS, with its principal place of business located at BAT C LE PATIO DE L’ALTA, 365 CHEMIN DU CAMP DE SARLIER, 13400 AUBAGNE, registered under number 106841372. 

For general inquiries: contact@germaincollection.fr 

3. Personal Data Collected 

Depending on your relationship with us and the services you use, we may process the following categories of data: 

  • Identification information: last name, first name, title, and, when necessary, date of birth. 
  • Contact information: mailing address, email address, and phone number. 
  • Information regarding the reservation and stay: dates, number of guests, room, services booked, preferences, and special requests. 
  • Payment and billing information: information required for payment processing, billing, and transaction tracking. Full credit card details are processed by the relevant payment service provider using its own secure system. 
  • Customer relationship data: communications, requests, complaints, feedback, responses to satisfaction surveys, and service history. 
  • Data related to newsletters and marketing communications: email address, sign-up date, preferences indicated, history of mailings and interactions, unsubscription, and proof of consent when required. 
  • Photos and videos voluntarily submitted: content that you choose to send to us in connection with a request, feedback, event, or interaction with the institution. Any publication or reuse for communication purposes is subject to separate authorization when necessary. 
  • Browsing data: IP address, device and browser type, pages viewed, interactions with the site, and identifiers associated with cookies or other trackers. 
  • Video surveillance data: footage recorded in designated areas of the facility. 
  • Job application and human resources management data: resumes, cover letters, work history, qualifications, contact information, evaluation data, and, for employees, information necessary for the administrative management of the employment relationship. 

We take care to collect only data that is adequate, relevant, and necessary for the purposes described below. Required fields are indicated at the time of data collection. If you do not provide a required piece of information, we may be unable to process your request, complete your reservation, or provide the service in question. 

4. Data Source 

Data is primarily collected directly from you when you: 

  • Visit our website or fill out a form; 
  • make, change, or cancel a reservation; 
  • Contact the hotel by phone, email, WhatsApp, or at the front desk; 
  • use a service provided by the facility; 
  • take a survey or post a review; 
  • you sign up for a newsletter or request to receive our news and offers; 
  • you voluntarily send us a photograph or video; 
  • Submit an application or join our team. 

They may also be provided to us through the intermediary you chose to make your reservation, such as an online booking platform, a travel agency, a tour operator, a distribution partner, or a company that made the reservation on your behalf. The identity of the relevant intermediary can be provided to you upon request. 

5. Purposes and Legal Bases 

We process your data only for specific purposes and on an appropriate legal basis. 

Purpose 

Data Primarily Affected 

Legal Basis 

Respond to requests and process a reservation 

Identity, Contact Information, Request 

Pre-contractual measures taken at your request 

Manage reservations, stays, services, changes, and cancellations 

Identity, contact information, reservations, preferences 

Performance of the Contract 

Communicate via WhatsApp regarding arrival, confirmation, and useful information for your stay 

Name, phone number, reservation 

Performance of the contract or precontractual measures 

Process payments and manage billing 

Transactions, Billing, Reservations 

Performance of the Contract and Legal Accounting and Tax Obligations 

Respond to complaints and follow up on customer relationships 

Identity, contact information, communications, stay 

Performance of the Contract and Legitimate Interest in Monitoring and Defending Our Rights 

Preventing Fraud and Ensuring System Security 

Transactions, Navigation, Technical Logs 

Legitimate interest in securing our services and transactions 

Measuring the effectiveness of our campaigns and running ads through Google Ads and Meta Ads 

Browsing and Advertising Identifiers 

Consent, when trackers are subject to consent 

Ensuring the safety of people and property through video surveillance 

Images 

Legitimate interest and, depending on the area, compliance with the obligations applicable to video surveillance systems 

Process Applications 

Personal Information, Contact Information, Work History, Qualifications 

Pre-Contractual Measures and Legitimate Interest in Organizing the Recruitment Process 

Managing the Employment Relationship 

Administrative and Professional Information 

Performance of the employment contract, legal obligations, and legitimate interest in internal management 

Send newsletters, updates, and promotional offers 

Email address, preferences, and interactions with mailings 

Consent; or, for similar customers and services, legitimate interest under the conditions permitted by Article L. 34-5 of the French Postal and Electronic Communications Code 

Measuring Website Traffic and Improving the Site Using Google Analytics 

Browsing, IP address, device, and tracker identifiers 

Consent When Trackers Are Not Strictly Necessary 

Processing the photos and videos you voluntarily submit 

Image, voice, and related content 

Processing your request or consent; separate authorization for any publication when necessary 

6. Recipients and Service Providers 

Data is accessible only to individuals who need it to perform their duties, within the limits of their authorization levels: hotel staff, authorized departments of Germain Collection, human resources, accounting, IT, management, and security, depending on the specific data processing activity. 

We do not sell or rent your personal data. However, it may be processed—on our behalf or as part of the requested service—by the following categories of service providers: 

  • Website hosting and maintenance; 
  • Reservation engine, hotel management software (PMS), booking platforms, and travel agencies; 
  • Payment service providers and banks; 
  • Messaging and operational communication, including WhatsApp; 
  • Audience measurement and advertising, including Google Analytics, Google Ads, and Meta Ads; 
  • Sending newsletters and managing unsubscriptions; 
  • Consulting firms, recruitment agencies, and IT maintenance providers; 
  • Administrative or judicial authorities, when required by law. 

When these service providers act as subcontractors, they are required to process data only in accordance with our instructions, to maintain its confidentiality, and to implement appropriate security measures. 

7. Retention Periods 

Data is retained for a period of time commensurate with the intended purpose and is then deleted, anonymized, or archived as required by law. The main retention periods are as follows: 

Category / Treatment 

Duration 

Reservations and Your Stay 

3 years from the end of the business relationship or the last active contact, subject to legal obligations and the protection of rights 

Newsletters and Sales Prospecting 

Until consent is withdrawn or an objection is raised, contact information may be retained for the duration of the business relationship and for up to 3 years after its termination or the last active contact, depending on the situation 

Invoices and Accounting Documents 

10 years from the end of the fiscal year 

Application Not Selected 

2 years from the last contact with the candidate 

Key Information in an Employee's File 

5 years after its removal, subject to the specific statutory retention periods applicable to certain documents 

CCTV footage 

A maximum of 30 days, provided that the data is not retrieved for the purposes of a proceeding 

Photos and videos voluntarily submitted 

For as long as necessary to process the request; in the event of authorized publication, for the period specified in the authorization or until it is revoked, when possible 

Cookie Preferences 

Generally, 6 months before a new choice is requested, unless there is a significant change in the purposes or service providers 

Data from Google Analytics, Google Ads, and Meta Ads 

Depending on the tracker and the service settings, the exact and up-to-date duration for each tracker is shown in the Axeptio module, which is available on the website 

8. Hosting and Transfers Outside the European Economic Area 

The data collected by the website is hosted by Publicom. The data required to manage reservations and stays is processed primarily using the Mews hotel management software. It may also be processed by the online booking platforms used by the establishment, as well as by its payment service providers. 

Certain services, including Google Analytics, Google Ads, Meta Ads, and WhatsApp, may involve the transfer of or access to certain data from the United States. These transfers are governed by the adequacy decision adopted by the European Commission under the EU–U.S. Data Privacy Framework, provided that the relevant recipient entity holds active certification. 

Other service providers or subcontractors may process certain data outside the European Economic Area. In such cases, transfers are governed by an adequacy decision issued by the European Commission or, in the absence thereof, by the European Commission’s standard contractual clauses, supplemented, where necessary, by additional safeguards. 

The data processing agreement proposed by Mews provides, among other things, for the application of the European Commission’s standard contractual clauses when a transfer subject to specific safeguards is carried out.  

For more information about the countries involved and the applicable safeguards, please contact our Data Protection Officer at the following address: contact@germaincollection.fr 

9. Security and Privacy 

We implement appropriate physical, technical, and organizational measures to protect data from destruction, loss, alteration, disclosure, or unauthorized access. These measures include, among other things, access control, secure access, system backups, and oversight of service providers. 

Online payments are processed using secure solutions that comply with applicable industry standards. In particular, payment service providers implement the security requirements of the PCI DSS standard when it applies to the processing of credit card data. Germain Collection does not directly store complete credit card information. Despite these precautions, no system can guarantee absolute security; therefore, we regularly adapt our measures to address identified risks. 

10. Cookies and Other Trackers 

A cookie or other tracker is a file or identifier that may be stored on your device or read from it when you visit the website. It may, in particular, enable the technical operation of the website, remember your preferences, measure website traffic, analyze browsing behavior, or measure and personalize advertising campaigns. 

In accordance with Article 82 of the French Data Protection Act, cookies that are not strictly necessary for the operation of the website or for a specifically requested service are placed or read only after you have given your consent. Refusing these cookies does not prevent you from accessing the website’s essential features, but may limit certain personalization, analytics, or advertising functions. 

This site uses the following categories of trackers: 

Up-to-date details about the cookies and other trackers used on the website—including their names, providers, purposes, and duration—are available at any time in the Axeptio module. This list supplements the information provided in this policy. 

During your first visit, you can accept all non-essential cookies, reject them, or customize your selection by purpose. The buttons for accepting and rejecting are presented with comparable simplicity. You can then modify or withdraw your consent at any time via the Axeptio module available on the website. Your selection is generally retained for 6 months before you are asked to make a new choice, unless there is a significant change in the purposes or service providers. 

You can also delete cookies from your browser settings. However, this setting does not replace the consent process organized by Axeptio for the relevant trackers.

Category or service 

Operation and Purpose 

Applicable Rule and Duration 

Strictly Necessary Cookies 

Ensure operation, security, reservation, and the storage of essential settings. 

No consent required when they are strictly necessary. Session-based or strictly necessary duration, as detailed in Axeptio. 

Google Analytics 

Measures traffic, page views, user journeys, and website performance in order to improve the site. 

Prior consent. Cookies and exact durations are listed in Axeptio based on the site's settings. 

Google Ads 

Measures conversions and campaign effectiveness and can enable remarketing or the display of targeted ads. 

Prior consent. Cookies and exact durations are specified in Axeptio. 

Meta Ads 

Measures conversions, builds advertising audiences, and can serve tailored ads on Meta services. 

Prior consent. Cookies and exact durations are specified in Axeptio. 

11. Video Surveillance 

To ensure the safety of people and property, Hôtel Saint-Christophe uses a video surveillance system in areas marked with a pictogram and a sign providing specific information. 

Areas affected: reception area, restaurant, hallway, common areas. 

The footage may be viewed only by the school principal, the technical supervisor, and, in the event of an incident, by the relevant authorities. It is retained for 30 days. When retrieved for the purposes of a proceeding, it may be retained for the duration of that proceeding. 

12. Recruitment and Personnel Management 

12.1 Candidates 

The information provided during the application process is used to review the candidate’s profile, schedule interviews, assess suitability for the position, and follow up on the recruitment process. This information is accessible to HR teams and the relevant operational managers, as well as to authorized service providers when their involvement is necessary. 

If an application is not selected, the data may be retained for two years from the date of the last contact in order to offer other opportunities, provided that the applicant is informed and, when necessary, gives their consent. 

12.2 Employees 

Employee data is used for the administrative, contractual, and operational management of the employment relationship, payroll, training, safety, work organization, and compliance with legal obligations. The main data in the file is retained for the duration of the employment relationship and then, in accordance with the internal policy provided, for five years after the employee’s departure, subject to the specific statutory retention periods applicable to each document. 

13. Electronic Communications 

13.1 WhatsApp 

The phone number may be used via WhatsApp only for communications necessary for the preparation and smooth running of the stay: confirmation, arrival information, responses to inquiries, and practical information. It is not used after the stay to send marketing messages. 

However, using WhatsApp involves the service provider. We ask that you refrain from sending sensitive data or payment information through this channel. You may request to continue the conversation through another contact method offered by the hotel. 

13.2 Newsletters and Marketing Communications 

When you subscribe to our newsletter, we use your email address and, where applicable, your preferences to send you news, offers, and information about Germain Collection’s properties and services. For prospective customers, these communications are based on your prior consent, in accordance with Article L. 34-5 of the French Postal and Electronic Communications Code. In cases permitted by this law, offers for similar services may be sent to customers, provided they have been informed and can easily opt out. 

You may withdraw your consent or object to these communications at any time, including by using the unsubscribe link included in each message. Withdrawing your consent does not affect the lawfulness of any processing carried out prior to that time. 

14. Your Rights 

Under the conditions set forth in the regulations, you may exercise the following rights: 

  • the right to access your data and obtain a copy of it; 
  • the right to have inaccurate or incomplete data corrected; 
  • the right to erasure, when the conditions are met; 
  • right to restriction of processing; 
  • the right to object to processing based on our legitimate interests and the absolute right to object to commercial solicitation; 
  • the right to data portability, when the processing is based on consent or a contract and is carried out by automated means; 
  • the right to withdraw your consent at any time, without affecting the processing that took place prior to that; 
  • the right to set guidelines regarding what happens to your data after your death. 

These rights are not absolute: certain requests may be restricted when a legal obligation, a compelling legitimate interest, or the establishment, exercise, or defense of legal rights requires the retention or processing of certain data. 

15. Exercising Your Rights and Contacting Us 

You may exercise the rights described in the previous section by contacting, at your discretion, either the relevant institution directly or Germain Collection’s data protection officer. 

15.1 Contact the institution 

For inquiries regarding your reservation, your stay, updating your contact information, or any other matter directly related to your relationship with the hotel, please contact: 

Name of the establishment: Hôtel Saint-Christophe 

Email address: bonjour@hotel-saintchristophe.fr 

Mailing Address: 2 Av. Victor Hugo, 13100 Aix-en-Provence 

The organization will be able to process your request directly if it has the necessary information and expertise. If the request specifically concerns the exercise of your rights regarding personal data or requires special consideration, it may be forwarded to Germain Collection’s Data Protection Officer. 

15.2 Contact Germain Collection Directly 

You may also contact Germain Collection’s Data Protection Officer directly with any questions regarding the processing of your personal data or to exercise your rights: 

Email address: contact@germaincollection.fr 

Mailing Address: P.O. Box C, LE PATIO DE L’ALTA, 365 Chemin du Camp de Sarlier, 13400 Aubagne 

It is not mandatory to first contact the organization. You may contact the DPO directly, particularly if your request involves multiple organizations, presents a specific challenge, or concerns how your personal data is used. 

15.3 Processing Your Request 

Whether your request is addressed to the institution or directly to the DPO, it will be processed in accordance with the terms and within the timeframes set forth in the regulations. 

To protect your data, proof of identity may be requested only when necessary to verify your identity, particularly in cases of reasonable doubt. 

We will respond as soon as possible and, in principle, within one month of receiving your request. This timeframe may be extended under the conditions set forth in the regulations when the request is complex or when multiple requests are received. In such cases, you will be notified of the extension and the reasons for it. 

16. Complaint to the CNIL 

If, after contacting us, you believe that your rights have not been respected, you may file a complaint with the National Commission for Information Technology and Civil Liberties (CNIL): www.cnil.fr. 

17. Policy Change 

This policy may be amended to reflect changes in our services, practices, or regulations. The current version is posted on this page and includes the date of the last update. In the event of a significant change, additional information may be provided to you through an appropriate channel.