Personal Data Protection Policy

LAST REVISED ON OCTOBER 6, 2026

1. Foreword

Let's set the framework

Because respect for your privacy and your Personal Data is essential to us and justifies the trust you place in us, Louvre Hotels Group undertakes to process your Personal Data in compliance with the General Data Protection Regulation (EU Regulation 2016/679 of 27 April 2016), (hereinafter the "GDPR") and the French Data Protection Act (Law No. 78-17 of 6 January 1978 as amended relating to information technology, to files and freedoms) and has implemented this Personal Data Protection Policy (hereinafter the "Policy") which, in a transparent approach, aims to inform you about:

  • The Data Controller of your Personal Data;
  • The way in which your Personal Data is collected and processed;
  • The recipients to whom your personal data is transmitted;
  • Your rights regarding the use of your Personal Data;
  • Our reciprocal commitments to the protection of Personal Data

Capitalized terms not defined in the sections below will be defined in Section 16.
This Policy applies to all persons whose Personal Data may be processed by Louvre Hotels Group in the context of its activities, and in particular:
Customers include any natural person who has made a reservation via the Site, staying or having stayed in an establishment, whether or not they have a Customer Account, whether or not they are a member of the loyalty program, as well as any person who has made a complaint, left a review or participated in a satisfaction survey, a competition or a marketing operation;
Prospects include any natural person who has not necessarily stayed in an establishment, but who has shown an interest in the Services offered, in particular by initiating an unfinalized reservation, creating a Customer Account or joining the loyalty program, a request for information, subscribing to a newsletter;
Users, includes any person browsing the Sites, whether they are a customer or not, and whose Personal Data is collected in particular through cookies and other trackers;
Accompanying persons, include in particular persons accompanying a Client during a stay, and certain Data of whom may be communicated in the context of a reservation or the provision of the Services;
Persons contacting customer service or the reservation center, whether for a request for information, a reservation request on behalf of a third party, assistance, a report or any other communication, including in the absence of a contractual relationship;
Persons exercising their rights pursuant to the Applicable Regulations, in particular the rights of access, rectification, erasure, opposition, limitation or portability, as well as, where applicable, persons providing proof of identity in this context.
For the purposes of the policy, all of these persons are referred to interchangeably as the "Data Subjects".

2. General Principles

I promise you'll understand

In accordance with the provisions of Article 5 of the GDPR, the collection and Processing of your Personal Data comply with the following principles:
Lawfulness, fairness and transparency: the collection and Processing of your Personal Data may only be based on a previously defined legal basis (performance of a contract, legal obligation, consent, legitimate interest, preservation of vital interests, public interest);
Limited purposes: the collection and Processing of your Personal Data is carried out to meet one or more previously defined purposes;
Minimization of data collection and processing: only Personal Data that is strictly necessary for the proper execution of the purposes pursued is collected;
Data retention is limited in time: the Data Controller is obliged to define retention periods for the Personal Data processed. It must only be kept for as long as necessary to achieve the purpose or within the limits of the regulatory obligations imposed on the Data Controller;
Integrity and confidentiality of the data collected and processed: the Data Controller undertakes to guarantee the integrity and confidentiality of the Personal Data collected.

3. Data Controller

Who is responsible for the data?

In the context of the management of bookings and interactions with Data Subjects, the Processing of Personal Data is implemented by several entities acting at different levels, each in its capacity as Data Controller within the meaning of Article 47 of the GDPR, for the Processing that it determines and implements autonomously.

3.1 Louvre Hotels Group

The Processing of Personal Data related to the management and operation of the Sites, tools and services shared within its network, is carried out by LOUVRE HOTELS GROUP, a simplified joint-stock company with a capital of €117,624,016, registered with the Nanterre Trade and Companies Register under number 309 071 942, whose registered office is located at Tour Voltaire, 1 Place des Degrés, 92800 Puteaux, France, as Data Controller (hereinafter "Louvre Hotels Group", "we" or "us").
This means that we control how your Personal Data is processed and decide on the purposes of that Processing. This also means that we give specific instructions to our Sub-processors, who may process your Personal Data on our behalf.
In accordance with Article 32 of the GDPR, we implement appropriate technical and organizational measures to ensure the protection of your Personal Data.

3.2 Hotels in the network

The hotels in the Louvre Hotels Group network are legally autonomous and independent entities. This is why, when you book or stay in one of these Hotels, your Personal Data is processed by both Louvre Hotels Group and the Hotel concerned by your stay, each acting as Data Controller pursuing its own purposes.
The Hotels in the network are therefore required to comply with the principles of protection of your Personal Data in accordance with the Applicable Regulations, and to ensure the management of your rights when you exercise them.

3.3 No co-responsibility

Louvre Hotels Group and the Hotels in the network do not act as Joint Data Controllers within the meaning of Article 26 of the GDPR. Each of these entities intervenes autonomously and independently, for Processing Purposes pursuing distinct purposes, and assumes sole responsibility for the compliance of the Processing it implements with regard to the Applicable Regulations on the Protection of Personal Data.
Data Subjects may exercise their rights with Louvre Hotels Group (see Article 12) for the Processing described in Article 7 of this Policy
Directly to the Hotel of the network concerned about the Processing carried out by the latter in its capacity as Data Controller.

4. What personal data do we collect?

What do we know about you?

4.1 Personal Data collected directly from you

During your browsing, your booking and, where applicable, at different times during your stay, certain Personal Data may be collected. They can concern you directly or the people who accompany you. This Data is grouped by type below:

  • Identity data (such as your title, surname, first names, date of birth, nationality, customer ID, etc.);
  • Contact data (such as your email address, postal address, landline and/or mobile phone number, etc.);;
  • Data relating to payment methods (in particular information relating to your credit card to guarantee your reservation or make payment);
  • Data mentioned on official identity documents in the context of a legal application (such as those mentioned on national identity cards, passports, etc.);
  • Data relating to your preferences (such as the type of rooms and beds, location of the room, presence of pets, parking, etc.);
  • Data relating to your stays (such as date, place, services booked, etc.);
  • Data relating to children (accompanying you that you may send to us);
  • Data relating to the monitoring of the commercial relationship (such as requests for documentation, Service or subscription subscribed, your opinions and comments, etc.);
  • Traffic data (such as the IP address of your device, connection logs, login, etc.);
  • Geolocation data (only with your consent) with the "around me" destination function to suggest Hotels near your location.
On the other hand, we may collect Personal Data through the recording of your telephone conversations when you contact customer service or when you make a reservation with our reservation center for training or probationary purposes.

4.2 Personal Data from Cookies and other trackers

We use cookies and similar technologies to power, protect, improve, and understand how you use the Sites.
The following data may be collected automatically through the use of the Sites:
Technical data relating to your device and its operating system (IP address, internet connection, browser type, information about the Device used); Data collected using cookies: For more information, see the Cookie Policy.
The User can manage his or her cookie choices at any time thanks to the "Manage cookies" tab accessible at the footer of our Sites or directly from the cookie banner when he or she first browses each of our Sites.

4.3 Personal Data collected indirectly from online sites other than our Sites

We may collect your Personal Data from some of our partners who record your booking from their own websites and may, depending on the case, collect or not collect the price of the booking.
These partners include online hotel comparison sites or search engines such as Booking.com, Expedia, Google Hotels Ads, TripAdvisor or Trivago, etc. They collect and transmit to us the Personal Data necessary for your booking.
These partners collect certain information on their own behalf and in their own databases, which we do not have access to. For these Processings, our partners process the Personal Data that you provide to them as a Data Controller. Therefore, we invite you to consult their privacy/personal data protection policies to understand how and why they process your Personal Data and to be able to exercise your rights with them.

5. When do we collect your personal data?

Yes, we collect data, but as little as possible

Personal Data may be collected on various occasions, in particular in the context of:

  • Hotel Activity:
    • When booking, checking in and paying for a stay directly from our Sites or through our partners;
    • When managing Services offered as part of your stay;
    • When you contact customer service;
    • When you create a Customer Account;
    • When you log in to your Customer Account and use our Sites;
    • When you fill in online forms on our Sites;
    • When you leave a review on our Sites or on third-party partner sites regarding a booking;
    • When you interact with our content on social media;
    • When you make requests, complaints and/or in the event of a dispute regarding your booking
  • Participation in marketing operations:
    • When you respond to satisfaction surveys;
    • When you participate in competitions or prize draws;
    • When you subscribe to the newsletter.
  • Browsing our Site through cookies and other trackers

6. On what legal grounds do we collect your personal data?

We have obligations

We process your Personal Data based on the following legal bases, in accordance with the Applicable Regulations:
To fulfil our obligations under a pre-contract or contract with you (e.g. when you make a booking with us or create a Customer Account, etc.);
To comply with a legal obligation (for example, we need to retain your transaction information to comply with our tax and financial reporting obligations);
Where it is in our legitimate interests to process your Personal Data (e.g. to evaluate and improve our organisation, fight fraud, respond to complaints, etc.);
Based on your consent (e.g., when you choose to subscribe to our newsletters).

7. For what purposes and for how long do we keep your personal data?

We would like to explain to you

The table below lists the purposes for which we process your Personal Data, the legal basis for each Processing and the associated retention periods.

Purpose of the processing Legal Basis Retention period
Booking management [Booking, modifying, cancelling] Execution of pre-contractual or contractual measures (for the entire duration of the business relationship for the proper performance of the contract)
Legitimate interest (after the business relationship for evidentiary purposes)
Duration of the business relationship, then:
Booking without creating a Customer Account: 3 years from the end of the commercial relationship (end date of the stay, date of no-show, date of cancellation of a booking)
Booking with Customer Account: 3 years of continuous inactivity on the Customer Account
Electronic sales prospecting [Clients] Data Subject Consent (B2C) or Legitimate Interest (B2B) Until the withdrawal of consent or 3 years from the end of the commercial relationship (end date of the stay, date of the no-show, in the cancellation of a reservation or end of use of the Customer Account)
Electronic Commercial Prospecting [Prospects] Data Subject Consent (B2C) or Legitimate Interest (B2B) Until the withdrawal of consent or 3 years from the last contact from the prospect (click on a link in the body of a prospecting email for example)
Carrying out satisfaction surveys Legitimate interest of the company in post-stay surveys to improve the quality of its services
Consent for non-stay-related satisfaction surveys
Duration necessary to achieve the purpose of the survey or until the right to object is exercised or consent is withdrawn
Marketing operations, competitions Legitimate interest of the company in promoting its brands or services Until the end of the marketing operation and then until the withdrawal of consent or 3 years from the last contact of the people with the company
Claims Management Legal obligations (for the duration of the business relationship for the proper performance of the contract)
Legitimate interest (after the business relationship for evidentiary purposes or in the event of litigation)
Until the end of the operations related to the analysis and processing of the claim and then 3 years from the date of closure of the file
Exercising the Rights of Data Subjects Legal obligations (under the GDPR) Until the completion of the operations related to the execution of the request for rights, then:
For all rights except the right to object: 1 year from the date of the request to exercise the right
For the right to object: 6 years from the date of the request to exercise the right
With regard to supporting documents (in the event of legitimate doubt as to the identity of the applicant): these are deleted once the Data Subject's request has been granted, except in the event of litigation
Payment by credit card Execution of pre-contractual or contractual measures (for payment of booked services)
Consent of the Data Subject for the storage of data to facilitate the continuation of subsequent online transactions, for example
Cryptogram: during the completion of the transaction only
Transaction: duration of the transaction until actual payment, plus the withdrawal periods in force
Then 13 months in intermediate archiving (or 15 months for deferred debit payment cards), from the date of the transaction, for evidentiary purposes and which can only be used in the event of disputes
Booking with a Customer Account: until the Customer withdraws their consent; when the expiry date of the bank card has passed; upon closure of the Client Account or after three years of inactivity of the Client Account
Browsing Websites and Applications via Cookies and Other Trackers Legitimate interest in cookies that are strictly necessary for the proper functioning of the Sites.
Consent for other cookies (marketing, audience measurement, etc.)
The lifespan of cookies is 13 months from the date of deposit on the user's terminal (computer or mobile phone) or until the withdrawal of consent for cookies other than for functional purposes.
The user's choice of cookies is kept for 6 months and the application logs are kept for 1 year.
Carrying out sales analyses and statistics Legitimate interest of the company to be able to analyse its results and improve its offers and services Time required to achieve the objective of the analyses and compilation of the statistics
Recording of telephone conversations Legitimate interest of the company for training and evidentiary purposes Reservation: time required for the reservation to be processed and then 90 days from the date of the call
Customer service: time needed to process the request and then 30% of calls are kept for a maximum of 30 days from the date of the call
Litigation Management Legitimate interest of the company in the defence of its interests
Legal obligation (Article 77-1-1 of the French Code of Criminal Procedure)
The data is kept for 1 year from the date of termination of all remedies
Until the end of the operations related to the execution of the request and then 1 year from the date of sending the elements to the authorities
Bookkeeping (such as invoices) Legal obligation (Article L123-22 of the French Commercial Code) These documents are secured in a specific archiving database and cannot be subject to the right of erasure for a period of 10 years from the date of their issue


For any further information on the purposes or retention periods, you can refer to the "CNIL Repository - Processing implemented for the purpose of managing commercial activities" or contact the Data Controller (see Article 12)
For Processing based on legitimate interest, a prior balancing analysis is carried out in order to verify that the interests of the Data Controller do not disproportionately infringe the fundamental rights and freedoms of the Data Subjects.

8. With whom may be share your personal data?

You don't pass them on to just anyone

The Personal Data that we collect may be transmitted, to ensure the various purposes and to improve your stay

  • Authorized personnel of Louvre Hotels Group;
  • Authorized staff of the hotels in the network;
  • Authorized persons with our service providers who are subcontractors of Louvre Hotels Group and in particular the service providers in charge:
  • To perform certain Services;
  • To help us manage bookings and deal with any complaints;
  • Customer service
To ensure the Processing and security of your payment data when making a booking;
To help us carry out advertising campaigns, marketing content, competitions and to analyze their effectiveness;
To provide hosting and maintenance services, software and applications and to support our databases.
To companies with whom we have commercial agreements for the purpose of providing you with bundled or personalized offerings;
To any relevant regulatory, statutory, governmental or other authority, agency or body and industry regulator, if required by law or in connection with an investigation and in accordance with local regulations;
To auditors, lawyers or other advisors in the course of their services.

9. How do we protect your personal data?

The security of your Personal Data is taken seriously

The Personal Data that we collect may be transmitted, to ensure the various purposes and to improve your stay

We implement appropriate technical and organizational measures to protect your Personal Data against accidental or unlawful destruction, loss, alteration, dissemination or unauthorized access to such Data.
In particular, we operate data systems and networks protected by industry-standard security measures and we use specific protocols on unsecured networks to protect the transmission of your Data. In addition, access to your Data is limited to authorized persons.
While we strive to always protect our Sites, systems and operations, we do not control all risks associated with the operation of the Internet and draw your attention to the existence of possible risks inherent in its operation and use.
When we need to share your Personal Data in the context of the performance of certain Services, we take all necessary measures to ensure that the third-party recipients have put in place appropriate technical and organizational measures to protect your Personal Data.

10. How is the transfer of your personal data outside the EEA managed?

Even outside Europe, we take care of your Personal Data

In the course of performing our Services, we may transfer your Personal Data to recipients, in particular the Hotels in the network that may be located outside the European Economic Area (EEA), in countries that may have a different framework for the protection of Personal Data.
In the event of a transfer of Personal Data outside the EEA, we undertake to comply with the requirements of the Applicable Regulations and to put in place the appropriate safeguards necessary for such transfer.

11. Use of Artificial Intelligence (AI) solutions

AI also has rules

Some Personal Data Processing may be carried out by automated Processing or algorithmic tools, including technologies incorporating artificial intelligence, whose sole purpose is to provide assistance in the analysis or production of content, according to predefined rules.
These tools are not intended to produce decisions with legal or significant effects about the Data Subjects.
No individual decision is taken on the sole basis of automated processing, and any decision remains based on human assessment.
These technologies may be provided by third-party providers. In this context, we ensure that these service providers provide sufficient guarantees for the protection of Personal Data, in particular regarding security, confidentiality, limitation of purposes and the absence of reuse of data for their own purposes.

12. What are your rights and how can you exercise them?

You have all the cards in your hand

You have the right to access, rectify, delete, limit, oppose and have the right to portability. You can also request at any time to stop receiving marketing communications from us.
In accordance with the provisions of Article 85 of the French Data Protection Act, you also have the right to define with us directives relating to the retention, deletion and communication of your Personal Data after your death.
If you wish to exercise your rights, you can contact our Data Protection Officer (DPO): 

By e-mail: dpo@louvre-hotels.com

By mail to the following address:
LOUVRE HOTELS GROUP - DPO
Tour Voltaire, 1 place des degrés
92800 PUTEAUX
FRANCE

You can exercise these rights at any time and free of charge, except in the case of manifestly unfounded or excessive requests (in particular due to their repetitive nature). In this exceptional case, we reserve the right, in accordance with the Applicable Regulations, to request payment of reasonable fees or to refuse your request.
Following your request to exercise your right, a response will then be sent to you within one (1) month of receipt of the request, which may be extended by two (2) months depending on the complexity of your request.
If you do not respond within the deadline or are incomplete, you also have the right to lodge a complaint with the competent supervisory authority (in France, the Commission Nationale de l'Informatique et des Libertés, or "CNIL" www.cnil.fr ).
You can also exercise your rights with regard to your Personal Data processed by a Hotel in its capacity as Data Controller. We invite you to exercise your rights directly with the Hotel concerned and to consult its "data protection policy" if necessary

13. What are your commitments?

And yes, you also have obligations

13.1 Accuracy of Personal Data

You declare that you, as a User of the Site or as a Data Subject, are informed of the importance of the accuracy of the Personal Data concerning you.
You also undertake to provide only accurate Personal Data during your exchanges, contracts with us, requests for Service(s), throughout the duration of your use of the Site and to update them, if necessary.

13.2 Management of the Personal Data of minors

We do not knowingly collect or solicit Personal Data from minors and do not allow such minors to book a room in one of our Hotels on their own.
The collection of information about minors is limited, in the context of the booking, to their first name, last name, nationality and age, which can only be provided to us by their legal representative.
Please ensure that your children do not provide us with any Personal Data without your permission. In the event that such a transmission takes place, you can contact the data protection officer whose contact details are given in Article 12 so that this information can be deleted.

13.3 Free Fields

In general, failure to fill in the fields identified on the Sites by an asterisk (*) does not allow us to provide you with all or part of the Services we offer and the Site's features. Your requests may not be taken into account in an optimal way.
The other fields are optional and are intended to improve the quality of the Services offered to you.
When a form offers a free field, we ask you to indicate only strictly objective information that is essential to your request and never to provide sensitive data (such as password, credit card number, health data, etc.).

13.4 Sensitive Personal Data

We do not collect so-called sensitive Personal Data.
We remind you that data that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, as well as genetic and biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation are considered Sensitive Personal Data.
If you voluntarily provide us with sensitive Personal Data, including in connection with special requests in connection with your booking, you acknowledge that you have given us your explicit consent to process these special categories of Personal Data.

14. General and modification of our policy

Important to make updates

In the event that one of the clauses of this Policy is null and void, in particular due to a change in the Applicable Regulations or by a court decision, this shall in no way affect the validity of the other clauses of the Policy.
This Policy is governed by French law.
This Policy may be updated and posted on the Sites. The previous Policy will then be replaced by the new version. The latter will be made immediately enforceable against you. Use of the Site is subject to the Policy in effect at the time of use.
In order to stay informed of any such changes and updates, you are advised to regularly review the Site Policy. Information on updates may be provided, without this being an obligation, by posting a message on each Site or by sending an e-mail.

15. Radisson Rewards Loyalty program

Loyalty also matters

Louvre Hotels Group is a participating entity in the Radisson Rewards Loyalty Program set up by Radisson, acting as a Data Controller. In this context, Louvre Hotels Group acts as a subcontractor of the Personal Data that may be collected and processed for the purposes of your membership and participation in the said program. In addition, Hotel Guests have the opportunity to join the Radisson Rewards Loyalty Program in order to benefit from benefits within the Hotels under the conditions and limits specified in the Radisson Rewards Loyalty Program Terms and Conditions.
We invite you to consult the privacy policy for the Radisson Rewards Loyalty Program accessible via the following link: https://www.radissonhotels.com/en-us/privacy/radisson-rewards
For any questions relating to Data protection in this context, you can contact the Data Protection Officer of the Data Controller at the following address: DataProtection@radissonhotels.com.

16. Definitions

We promise, you'll understand us

"Customer Account": space made available to a Customer on the Site following his/her registration under the conditions set out in the T&Cs. This Customer Account is strictly personal, individual, non-assignable, and non-transferable to a third party. The Customer Account is accessible via the Customer's username and password.

"Personal Data" or "Data": sAccording to Article 4 of the GDPR, this is "any information relating to an identified or identifiable natural person; an "identifiable natural person" is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to his or her physical, physiological, genetic, mental, economic, cultural or social identity". For example, data allowing your identification such as title, surname, first name and email address are Personal Data.

"Hotels": any franchised entity or subsidiary that operates under one of the Louvre Hotels Group brands as well as partner establishments as defined in the Louvre Hotels Group General Terms and Conditions of Sale. Louvre Hotels Group's brands include: Hosho, Première Classe, Campanile, Kyriad, Kyriad Direct, Kyriad Eco, Golden Tulip, Royal Tulip, Tulip Hotels & Residences, Tulip Inn.

"Radisson Rewards Loyalty Program": means the loyalty program established and operated exclusively by Radisson.

"Applicable Regulation": this refers to all existing or future regulations and standards applicable to Data Subjects and Data Controllers (the regulations applicable to online platforms, the regulations relating to the protection of personal data, including the Data Protection Act and the GDPR, etc.).

"Data Controller": the data controller is the legal person (company, municipality, etc.) or natural person who determines the purposes and means of processing, i.e. the objective and the way in which it is carried out.

"Service(s)": refers to all the services offered to Customers via the Sites.

"Sites": any website or mobile application published by Louvre Hotels Group.

"Processing": processing of personal data is an operation, or set of operations, relating to personal data, regardless of the process used (collection, recording, organization, storage, adaptation, modification, extraction, consultation, use, communication by transmission or dissemination or any other form of making available, reconciliation).