Privacy Policy

The Caerwylan Hotel, Criccieth

This Privacy Policy explains how The Caerwylan Hotel (“we”, “us”, “our”) collects, uses, stores and protects your personal data when you use our website, contact us, make a hotel or restaurant booking, or use our services.

We are committed to protecting your privacy and handling your personal information responsibly in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Data Controller

The Caerwylan Hotel is the Data Controller responsible for your personal information.

If you have any questions regarding this Privacy Policy or how your information is handled, please contact us using the details at the end of this policy.

Information We Collect

Depending on the services you use, we may collect and process the following information:

  • Name and title
  • Postal address
  • Email address
  • Telephone number
  • Hotel and restaurant booking details
  • Number of guests within your booking
  • Special requests
  • Dietary requirements and allergy information
  • Accessibility requirements where voluntarily provided
  • Payment references and transaction information
  • Vehicle registration details (where required for parking)
  • Marketing preferences
  • Website usage information collected through cookies and analytics
  • IP address, browser type and device information

We only collect information that is necessary for providing our services or where required by law.

How We Collect Your Information

We collect personal information when you:

  • Interact with us on social media where information is voluntarily provided.
  • Make a hotel reservation.
  • Make a restaurant reservation.
  • Contact us by telephone, email or through our website.
  • Complete an enquiry form.
  • Purchase gift vouchers or other services.
  • Subscribe to receive marketing communications.
  • Visit our website.
How We Use Your Information

We use your information to:

  • Manage hotel and restaurant reservations.
  • Confirm, amend or cancel bookings.
  • Process payments securely.
  • Contact you before, during and after your stay.
  • Respond to enquiries.
  • Provide customer service.
  • Meet legal and regulatory obligations.
  • Prevent fraud.
  • Improve our services and website.
  • Send marketing communications where you have given consent.

Our lawful basis for processing includes:

  • Consent (for marketing communications).
  • Performance of a contract.
  • Compliance with legal obligations.
  • Legitimate business interests.
Payment Processing

Hotel reservations are managed using FreeOnline, our Property Management and Booking System.

Restaurant reservations and food and beverage transactions are managed using Tabology EPOS.

Online card payments are securely processed through Dojo.

The Caerwylan Hotel does not store your complete debit or credit card details.

Payment information is encrypted and processed using PCI DSS compliant payment systems.

Card Vault

When you make an online reservation, your payment card details are securely stored within the FreeOnline Card Vault.

The Card Vault allows authorised members of our team to securely process payments relating to your reservation, including deposits, outstanding balances, cancellation charges (where permitted under our Terms & Conditions) and any agreed charges during or after your stay.

The Caerwylan Hotel does not store or have access to your complete payment card details. Card information is securely tokenised and managed in accordance with PCI DSS security standards.

Marketing Communications

We will only send marketing communications where you have chosen to opt in.

Our marketing emails are designed to be occasional and relevant, typically no more than a few times each year, and may include:

  • Seasonal offers
  • Hotel news
  • Restaurant events
  • Christmas and special event information
  • Exclusive promotions

You may unsubscribe at any time by using the unsubscribe link within our emails or by contacting us directly.

Sharing Your Information

We never sell your personal information.

Where necessary, your information may be shared with trusted third parties who assist us in operating our business, including:

  • FreeOnline (hotel reservations)
  • Tabology EPOS (restaurant and payment management)
  • Dojo (secure payment processing)
  • Website hosting providers
  • WordPress service providers
  • Google Analytics
  • IT support providers
  • Professional advisers where legally required
  • Law enforcement or regulatory authorities where required by law

All third parties are required to process your information securely and in accordance with UK data protection legislation.

Data Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected.

Retention periods may be determined by:

  • Legal obligations
  • Financial record keeping
  • Tax legislation
  • Insurance requirements
  • Legitimate business interests

Once information is no longer required it is securely deleted or anonymised.

Data Controller

The Caerwylan Hotel is the Data Controller responsible for your personal information.

If you have any questions regarding this Privacy Policy or how your information is handled, please contact us using the details at the end of this policy.

Data Security

We take the security of your information seriously.

Appropriate physical, organisational and technical safeguards are in place to protect your personal information against unauthorised access, disclosure, alteration or destruction.

Our website uses SSL encryption.

Payment card information is securely processed by our payment provider and is not retained by The Caerwylan Hotel beyond what is necessary to administer your booking.

Your Rights

Under UK GDPR you have the right to:

  • Request access to your personal information.
  • Request correction of inaccurate information.
  • Request deletion of your information where applicable.
  • Restrict or object to processing in certain circumstances.
  • Withdraw consent where processing is based on consent.
  • Request transfer of your information to another provider where applicable.
  • Lodge a complaint with the Information Commissioner’s Office (ICO).

We encourage you to contact us first so we have the opportunity to resolve any concerns.

Cookies & Website Analytics

Our website uses cookies to improve functionality, enhance your browsing experience and understand how visitors use our website.

We currently use cookies for:

  • Essential website functionality
  • Website security
  • Remembering cookie preferences
  • Google Analytics
  • Booking functionality provided through FreeOnline

Further information is available within our Cookie Policy.

Third-Party Websites

Our website may contain links to external websites including booking providers and social media platforms.

We are not responsible for the privacy practices or content of these websites and encourage you to read their own privacy policies.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in legislation, technology or our business practices.

The latest version will always be published on this website.

Contact Details

The Caerwylan Hotel
Beach Bank
Criccieth
Gwynedd
LL52 0HW

Telephone: 01766 522547

Email: reception@caerwylan.co.uk /  tonnau@caerwylan.co.uk

Website: www.caerwylan.co.uk /  www.tonnaurestaurant.com