Privacy Policy
What data Royal Blue collects, what it uses, who shares them with among the three countries in which it operates, and how you exercise your rights.
This policy explains what personal data Royal Blue Resorts Hotels collects, why it collects them, with whom it shares them, and what you can ask for at any time. It goes for the website royalblueresortshotels.com, for the service by WhatsApp, by e-mail and telephone, and for the houses we operate in Brazil, Italy and the United States.
1Who's the controller?
Royal Blue Resorts Hotels is the name we operate by. The controller of the personal data processed on the website, in the service and in the houses is [Social Reason], registered in CNPJ under the no [CNPJ], based in [SEE ENDER].
The house has properties, teams, and contracts in three countries — Brazil, Italy, and the United States. This defines the law applicable to each treatment: the General Data Protection Act (Law 13.709/2018) is our starting point; the General Data Protection Regulation of the European Union (Regulation (EU) 2016/679) applies to what we do in Italy and what we offer guests in the European Union; the US state laws apply to residents of the United States, to the extent that their requirements concern.
The person responsible for the processing of personal data (PDO) is [ENCARREGADO/DPO], which you find in [E-MAIL OF PRIVACY].
2What data we collect and how
We collect what is necessary to answer, host, sell a property or administer the property of a owner. Almost everything comes from you, when you write to us at WhatsApp, write to the house email or call one of our phones — today the site has no form or registration area.
- Requests for information and reservations — name, email, phone, destination, dates of entry and exit, number of guests and what you choose to write in the conversation with the concierge.
- Stay details — names of guests and where the country's law requires the registration of guests, identification documents; special requests, including restrictions and food preferences, which may reveal sensitive data.
- Requests for real estate for sale — the data necessary for the advice and knowledge checks of the client (KYC) required by the counterparty, bank and professionals who instruct the operation.
- Owners and partners — contact details, property data and what the management contract and transfer of values require, including banking and tax data.
- Site technical data — IP address, device type, browser, pages viewed and cookies.
- WhatsApp, e-mail and phone — the number or address you write from, the date of the conversation, and the content of what was handled.
The site has no registration, account, area logged in or cart. When payment is made, card data is collected and processed directly by the payment processor — we do not keep card numbers on our systems.
We do not buy contact lists and do not enrich data from third party sources.
3What we use and on what legal basis
Each purpose has a legal basis of LGPD Article 7 — and, when GDPR applies, the equivalent basis of its Article 6.
- Responding to a request for information, setting up a budget, checking availability and confirming a reservation — execution of contract and preliminary contract procedures.
- Host: prepare the house, climb the team, organize transfers, chef and the services requested — execution of contract.
- Register guests before the authorities, where the law of the country requires — compliance with legal or regulatory obligation.
- Issue tax documents, book books and keep records — compliance with legal obligation.
- To assist in the purchase and sale of real estate, including in customer knowledge checks and prevention of money laundering required by those involved — compliance with legal obligation and performance of contract.
- Administer the property of a owner, account and transfer values — performance of contract.
- Maintain site security, prevent fraud and abuse, and register attendance to maintain the standard of service — legitimate interest.
- Meet special requests involving health, allergy or food restriction — specific and seconded consent, as this is sensitive data.
- Measure the audience of the site with analytics cookies, if and when they are activated, and send communications you have requested to receive — consent, revocable at any time.
- Defend our rights in legal, administrative or arbitral proceedings — regular exercise of rights.
When the basis is legitimate interest, we weigh our interest against their rights and freedoms before dealing with the facts, and we limit treatment to what is necessary. You can object at any time and ask for the explanation of this evaluation by [E-MAIL OF PRIVACY].
We do not make automated decisions that have legal effects or significantly affect their interests. We don't profile guests or credit scores.
4Sensitive data and data from children
Some requests reveal sensitive data: an allergy, a food restriction due to health or religion, a need for accessibility in the house. We only process this data when you inform them that the stay will work, based on your specific consent, and we only share it with those who need to execute the order — the chef, the housekeeper, the house staff.
You don't have to tell us a diagnosis. Just say what cannot be served, or what the house needs to have. We'll keep that data for the duration of your stay and, if you ask us to save it for the next one, just as long as you authorize.
Children and adolescents are frequent guests. Their data arrive by the adult in charge of the reservation and are treated in their best interest, in the form of LGPD article 14, limited to what is necessary to safely host them. The website is not aimed at minors, does not ask children to send data on their own and does not offer information society services directly to children under 16 in the European Union. If we know we've received data from a child without proper authorization, we'll eliminate the record.
5Who we share with
We don't sell personal data, we share the minimum with those who need the information to do the job.
- Local house teams — property manager, housekeeper, caretaker, in Brazil, Italy, and the United States.
- Contracted providers for your stay — chef, cleaning, transfers, guides, event providers. They receive the name, dates and order; nothing more.
- Payment processors and financial institutions, to collect, reconcile and pass on values.
- Legal, accounting and financial advice in the purchase and sale operations and management of property of owners.
- Suppliers of technology hosting the website and the communication tools we use as operators.
- Public authorities, when the law requires — guest registration, tax obligations, prevention of money laundering, competent authority order.
Operators process data on our own and according to our instructions, under contract with confidentiality, security and elimination obligations at the end of the relationship. You can ask for the relationship of the entities with which we share your data.
6International data transfer
The house operates in three countries, and so the data circulates among them. A reservation made in Brazil for a villa in Tuscany is read by the Italian team. A request on a property in Florida is instructed by professionals in the United States. The central administration is in Brazil.
Under the LGPD, we transfer data out of Brazil when the transfer is necessary for the execution of the contract with you, for the fulfilment of legal obligation, for the regular exercise of rights, or for the support of standard contractual clauses approved by the National Data Protection Authority — and, when none of these hypotheses applies, through your specific and seconded consent.
Under GDPR, transfers from the European Union to Brazil and the United States are made on the basis of the standard contractual clauses adopted by the European Commission, together with the assessment of the specific case and the additional technical and contractual measures it indicates. We do not support an adequacy decision that does not exist for the country of destination.
You can request a copy of the safeguards applicable to the transfer of your data by [E-MAIL PRIVACY].
7How long do we keep it?
We keep each given for the time of its purpose, and then for the time limit that the law imposes or for the time limit that we may still need it to defend a right.
- Request for information that does not become a reservation — up to 24 months after the last contact, to resume the conversation if you return.
- Reservation and stay details — during the stay and the limitation periods of the contract obligations.
- Guest registration required by authority — the deadline set by the law of the country where the house is located.
- Tax and accounting documents — by the deadlines of each country's tax legislation.
- Data on purchase and sale transactions and customer knowledge checks — by the time limits of the money laundering legislation applicable to the operation, which are longer.
- Administrative contracts with owners — during the contract and for subsequent legal periods.
- Site access records — six months, in the form of article 15 of the Internet Civil Mark.
- Data processed based on consent — until you revoke it, unless another legal basis requires custody.
Once the deadline has expired, the data is deleted or anonymized in such a way that they can no longer be associated with you.
8How we protect
The measures are proportional to what we keep, and most of them are discipline, not technology.
- Limited access to those who need the data to work, reviewed when someone enters or leaves the team.
- Traffic of the encrypted website in transit (HTTPS) and storage in services with access control.
- Contracts with confidentiality and data protection clause with local teams, providers and operators.
- No card numbers stored by us.
- Procedure for incident response, with record of the occurrence and risk assessment.
If security incident occurs with relevant risk to your rights, we communicate to ANPD and you, in the form of LGPD art. 48; when GDPR applies, the competent control authority is notified within 72 hours.
No system is entirely safe. If you notice anything strange in a message that seems to come from us — a payment request for another channel, for example — confirm by the phones posted on the site before responding.
10Your rights under LGPD
LGPD Article 18 gives you, at any time and upon request, the following rights to your data.
- Confirmation of treatment.
- Access to data.
- Correction of incomplete, inaccurate or outdated data.
- Anonymization, blocking or deletion of unnecessary, excessive or processed data in breach of the law.
- Data portability to another service provider or product, by express request, observed business and industrial secrets.
- Elimination of data processed on the basis of consent, except for the custody hypotheses provided for in Article 16 of the law.
- Information about the public and private entities with which we share your data.
- Information on the possibility of not providing consent and the consequences of refusal.
- Repeal of consent at any time and at no cost.
- Opposition to treatment based on one of the hypotheses of waiver of consent, when there is breach of the law.
- Review of decisions made solely on the basis of automated treatment — today we do not take any.
11Additional rights under GDPR for residents of the European Union
If you are in the European Union, or reserve one of our homes in Italy, the GDPR guarantees you, in addition to what is already above:
- Access to data and a copy of it (Art. 15).
- Rectification (art. 16) and erasure, the right to forgetfulness (art. 17).
- Limitation of treatment while discussing the accuracy or legitimacy of a data (art. 18).
- Portability in structured format, current use and automatic reading (art. 20).
- Opposition to treatment based on legitimate interest, and unconditional opposition to direct marketing communications (art. 21).
- Do not be subject to exclusively automated decision, including profile definition (art. 22).
- Withdraw consent at any time, without prejudice to what has already been dealt with before withdrawal.
You may lodge a complaint with the control authority of your country of residence, work or place of alleged infringement (art. 77). In Italy, it is the Guarantee per la protezione dei dati personali.
Our representative in the European Union, appointed under article 27 of the GDPR, is [RESEARCH IN the EU]. You can address him or directly to us.
12Note for residents in the United States and California
There is no single federal privacy law in the United States. Rights vary according to the state of residence — California, Virginia, Colorado, Connecticut, and others give, in general, the right to know what data are processed, to request copying, to correct, to erase, and to refuse certain uses. We comply with these requests to the extent that the law of their state applies to us, and we make no practical distinction between them: the procedure is the same as in section 13.
Residents of California, under the CCPA and the CPRA, have the right to know which categories of personal data we collect, where they come from, what they serve and who they are shared with; to ask for a copy of the data; to correct them; to ask for elimination; to limit the use and disclosure of sensitive personal information; and to not suffer discriminatory treatment by exercising any of these rights.
The house does not sell personal data and does not share it for behavioral advertising between contexts — neither in the last twelve months nor today. So there is no "Do Not Sell or Share My Personal Information" mechanism on the site: there is nothing to refuse. The categories of data we collect, the purposes and the recipients are in sections 2, 3 and 5.
Requests may be submitted by an authorised agent upon proof of authorisation. We may ask for information to confirm your identity before responding.
13How to exercise your rights and how long we respond
Write to [E-MAIL OF PRIVACY] by saying what you want and, if possible, to what stay, immobile or contact the request refers. We may ask for additional information to confirm who you are — not to create registration, just not to deliver data to the wrong person. WhatsApp, phone and e-mail from the house are for reservations and concierge; privacy requests we prefer to receive at the address above, in writing, to register the deadline.
- LGPD — Confirmation of the existence of processing and access to data in simplified format are answered immediately; the full declaration, within 15 days of the request. The other requests also answer in up to 15 days.
- GDPR — in up to one month, extended for another two months in complex or numerous requests, with notice to you within the first month.
- California — we confirm receipt in up to 10 business days and respond in up to 45 rundays, extendable for another 45 when needed, with warning.
The service is free. Clearly unfounded or repetitive applications may be refused or cost, always with justification. When the law forces us to keep a given — a tax record, a guest record, a KYC document — we explain why we cannot eliminate it and what we do with it until the deadline.
14Changes to this policy
This policy changes when changing our services, our suppliers or the law. The date of the last update is at the top of the page.
Relevant changes — a new purpose, a new recipient, a new international transfer — are warned prominently on the site and, to those who have a contract with us, by e-mail, before they take it seriously. When the change depends on your consent, we'll ask again. Previous versions are available on request by [E-MAIL OF PRIVACY].
15Contact and in charge
The person responsible for the processing of personal data shall be [SIGNED/DPO], who shall receive doubts, requests and complaints in [E-MAIL OF PRIVACY], or by letter addressed to [SEE DERDER], in the care of the Member.
In the European Union, our representative is [RESENTANT IN the EU].
If we do not come to an understanding, you can complain to the National Data Protection Authority (ANPD) in Brazil; to the control authority of your country, in the European Union — in Italy, the Guarantee per la protezione dei dati personali; and in California, California, the California Privacy Protection Agency or the State Attorney General. We prefer to resolve before that: write first for us.