
Privacy Policy
Effective from May 25, 2018
Table of Contents
- Introduction
- What constitutes personal data and what does processing personal data entail?
- To whom does this policy apply?
- What does this policy cover?
- What does it mean to be a data controller?
- Nobis Hotel AB as the Data Controller
- Why are we permitted to process personal data?
- What personal data do we collect?
- CCTV Surveillance
- How long do we retain personal data?
- Our measures to protect your personal data
- When We Share Personal Data
- Your Rights
- Changes to This Policy
- Contact
1. Introduction
Thank you for choosing Nobis Hotel AB, and a special thank you for taking the time to carefully read this Privacy Policy. We wish to begin by providing a brief summary of why we have created this policy. Our fundamental goal is to clearly and comprehensibly
- explain the respective roles of You and Us in this context;
- explain how we use the information you share with us to enable us to deliver and continuously enhance Sweden's finest hotel experience;
- ensure that you understand what information we collect and what we do with it;
- demonstrate how we work to protect your rights and your privacy.
Our objective is that, after reviewing this policy, you will feel confident that your personal privacy is respected and that your personal data is handled appropriately. We therefore continuously strive to ensure that our processing of personal data fully complies with current legislation, particularly the new General Data Protection Regulation (GDPR), which has been in effect since May 25, 2018.
2. What Constitutes Personal Data and What Does Personal Data Processing Entail?
2.1 Personal data refers to any information that can be directly or indirectly linked to a living physical person, when combined with other data. A non-exhaustive list of examples of personal data includes:
- Name
- Personal Identification Number
- Credit Card Number
- Email Address
- IP address
- Images
2.2 The processing of personal data encompasses any operation performed on personal data, whether automated or not. This includes, but is not limited to, the following actions:
- Collection
- Registration
- Use
- Combination
- Transfer
- Deletion
3. To Whom Does This Policy Apply?
This Privacy Policy primarily applies to individuals who stay at our hotel and whose personal data we process (the “Data Subject”). Various sections of this Privacy Policy may also be relevant to you depending on your relationship with Nobis Hotel AB. In summary, this policy applies to individuals who
- are guests at our hotel
- dine at our restaurant
- organize Meetings or events in our venues
- visit our website or interact with us on social media
- communicate with us through other channels, such as our customer service
By accepting this Privacy Policy, you consent to Nobis Hotel AB processing your personal data in accordance with this Privacy Policy.
4. What does this policy apply to?
This Privacy Policy governs how Nobis Hotel AB collects and processes personal data to deliver and continuously develop our Services.
5. What does it mean to be a Data Controller?
A Data Controller is a natural or legal person or other body that determines the purpose and means of processing personal data. A company acts as a Data Controller with respect to personal data it holds on its own behalf concerning its employees, customers, suppliers, and others.
6. Nobis Hotel AB as Data Controller
Nobis Hotel AB (corporate registration number 556629-5639) is the Data Controller for the processing of your personal data within the scope of Nobis Hotel AB's Services and is responsible for ensuring that such processing complies with applicable legislation.
7. Why are we permitted to process personal data? 7.1 For personal data processing to be permissible, there must always be a basis in GDPR, known as a legal ground. Such legal grounds include, among others:
- consent from the Data Subject
- that the processing of personal data is necessary for the fulfillment of a contract with the data subject, for example, an agreement regarding the use of the Services
- to fulfill a legal obligation, for example, regarding the retention of data due to accounting requirements
- that, following a balancing of interests, it is determined that Nobis Hotel AB's interest in processing personal data outweighs the data subject's interest in its protection.
7.2 Nobis Hotel AB always processes your personal data in accordance with applicable legislation. Our primary basis for processing your personal data is that it is necessary to fulfill our agreement with you regarding the use of our services.
7.3 It may occur that the same personal data is processed both on the basis of fulfilling a contract, specifically with consent, or on the basis that the data is necessary to comply with other legal obligations. This means that even if you withdraw your consent and the processing based on that consent ceases, the personal data may still be retained by us for other purposes.
8. What personal data do we collect?
In this section of our policy, we aim to provide you with examples of how we handle personal data to ensure we continuously deliver exceptional experiences with a high level of service.
8.1 When you book a room at our hotel
When you Book a room at our hotel, whether the booking is made at the hotel reception, by phone, via email, or on https://www.nobishotel.se, we process the following information that you provide to us:
- Your name and contact information (phone number, email)
- Credit card number and other payment information
- Your name and contact information (phone number, email)
- Your name and contact information (phone number, email)
- Your name and contact information (phone number, email)
- Information regarding your query, feedback, or matter
8.1.1 We process your personal data to:
- To identify you in connection with your booking and stay at Nobis Hotel AB
- To charge you for the services and products you have purchased from us
- To contact you with information regarding your stay, for example, via email, SMS, and WhatsApp
- To compile statistics and conduct analyses to improve our Services, products, and offers
- To provide, maintain, test, improve, and develop our Services and the technical platform used to deliver them
- To ensure the security of our Services, detecting or preventing various forms of illegal use or any use that otherwise violates our terms and conditions
- To inform you about personalized and tailored offers, campaigns, and benefits from us and our partners, for example, via email and SMS
- To identify you in connection with your booking and restaurant experience at NOI
- To charge you for the services and products you have purchased from us
- To contact you with information regarding your stay, for example, via email, SMS, and WhatsApp
- To compile statistics and conduct analyses to improve our Services, products, and offers
- To provide, maintain, test, improve, and develop our Services and the technical platform used to deliver them
- To ensure the security of our Services, detecting or preventing various forms of illegal use or any use that otherwise violates our terms and conditions
- To inform you about personalized and tailored offers, campaigns, and benefits from us and our partners, for example, via email and SMS
- To identify you in connection with your booking and your experience at our hotel
- To charge you for the services and products you have purchased from us
- To contact you with information regarding your booking, for example, via email, SMS, and WhatsApp
- To compile statistics and conduct analyses to improve our Services, products, and offers
- To provide, maintain, test, improve, and develop our Services and the technical platform used to deliver them
- To ensure the security of our Services, detecting or preventing various forms of illegal use or any use that otherwise violates our terms and conditions
- To inform you about personalized and tailored offers, campaigns, and benefits from us and our partners, for example, via email, SMS, and WhatsApp
- To answer your questions and manage your inquiries, for instance, by resolving errors and addressing complaints
- To improve our Services and the information we communicate through our various channels
8.1.2 Legal Basis for Processing:
We process your personal data based on the fulfillment of our contractual obligations when we meet our commitments to you as a hotel guest (e.g., when managing services related to your hotel room and providing relevant offers). We also rely on a legitimate interest assessment when we have a justifiable reason to use data about your stays and purchases to compile statistics and to develop, improve, and ensure the security of our Services.
8.1.3 Storage Period:
We store your personal data during your hotel stay and for up to 3 months thereafter. To ensure traceability, we retain information about our communication with you for 12 months. Your hotel history is kept for up to 2 years, based on our legitimate interest in analyzing trends over time.
8.2 When you Book a table at NOI
When you Book a table to dine at our restaurant NOI, whether the booking is made directly at the restaurant, by phone, via email, or on https://www.nobishotel.se, we process the following information that you provide to us:
8.2.1 We process your personal data for the following purposes:
8.2.2 Legal Basis for Processing:
We process your personal data based on the fulfillment of our contractual obligations when we meet our commitments to you as a restaurant guest (e.g., when managing services related to your table booking and providing relevant offers). We also rely on a legitimate interest assessment when we have a justifiable reason to use data about your visits and purchases to compile statistics and to develop, improve, and ensure the security of our Services.
8.2.3 Storage Period:
We store your personal data for up to 3 months after your restaurant visit. To ensure traceability, we retain information about our communication with you for up to 12 months. Your visit history is kept for up to 2 years, based on our legitimate interest in analyzing trends over time.
8.3 When you Book our Meeting and Event Venues
When you Book any of our excellent Meeting or event venues, whether the booking is made at the hotel reception, by phone, via email, or on https://www.nobishotel.se, we process the following information that you provide to us:
8.3.1 We process your personal data to:
8.3.2 Legal basis for processing:
We process your personal data based on the fulfillment of a contract when we meet our obligations to you as a visitor (e.g., when administering services related to your meeting or event booking and providing relevant offers), and based on a legitimate interest assessment when we have a legitimate interest in using data about your stays and purchases to compile statistics and to develop, improve, and ensure the security of our Services.
8.3.3 Storage period:
We store your personal data for up to 3 months after your visit. To ensure traceability, we store information about our communication with you for 12 months. Your visit history is stored for up to 2 years, based on our legitimate interest in analyzing trends over time.
8.4 When you communicate with us
You can choose to communicate with us in several ways, including through our social media accounts or with our customer service via phone or email.
When you book and communicate with us, we process the following information that you provide to us:
8.4.1 We process your personal data to:
8.4.2 Legal basis for processing:
We process your personal data based on our and your legitimate interest in handling the matter (legitimate interest assessment).
8.4.3 Storage period:
To ensure traceability, we store information about our communication with you for 12 months.
8.5 When you use our Wi-Fi or visit our website
When you connect to our Wi-Fi, we are the data controller for the processing that occurs to connect you to the Internet, but not for subsequent processing or for the content of your communication via Wi-Fi. When you connect to our Wi-Fi, we process:
- Your IP address and MAC address
When you visit our website, we process:
- Information about how you interact with and use our website, for example, when booking a hotel room.
- Information about your visits to our website, collected through cookies. For more information on how we use cookies, please see https://www.nobishotel.se/cook...
8.5.1 We process your personal data to:
- Provide our digital services
- Provide you with support when you experience various technical problems
- Maintain, test, and improve our digital services
- Detect and prevent security attacks, such as virus attacks
8.5.2 Legal basis for processing:
We process your personal data based on the fulfillment of a contract when providing Wi-Fi, and based on a legitimate interest assessment for our legitimate interests in maintaining, testing, and improving our digital services.
8.5.3 Storage Period:
We store your personal data for 3 months after you have used our digital channels and for 6 months from the date you connected to our Wi-Fi.
9. Camera Surveillance
We employ camera surveillance in certain areas with high foot traffic, such as the reception, entrances, and stairwells. The purpose of this surveillance is to prevent and investigate crimes and to mitigate the effects of any accidents. The cameras are in place to enhance safety and security for guests, staff, and operations, and are used exclusively for these purposes.
Following a balancing of interests, we have determined that the interest in preventing and investigating crimes outweighs individuals' interest in protecting their personal integrity (General Data Protection Regulation Article 6.1 f).
Material from camera surveillance is confidential and is only released to the Police for criminal investigations. The camera equipment and material are protected by robust physical and technical safeguards, and only a limited number of individuals have access to this material. In accordance with the principle of storage minimization, the material is deleted after 30 days.
If you have questions regarding camera surveillance, please contact our hotel manager Guadalupe Banegas at +46 (0)8 614 10 17, guadalupe@nobishotel.com
You also have the right to lodge a complaint with the Swedish Data Protection Authority (Datainspektionen): www.datainspektionen.se
10. How long do we store personal data?
Your personal data is stored only for the period necessary to fulfill the purposes for which the data was collected, in accordance with this Privacy Policy. Nobis Hotel AB may store the data for a longer period if required to comply with legal obligations or to protect Nobis Hotel AB's legal interests, for example, if there is an ongoing legal process.
11. Our Measures to Protect Your Personal Data
11.1 At Nobis Hotel AB, we have ensured that appropriate technical and organizational measures have been implemented to protect your personal data against loss, misuse, and unauthorized access, among other things.
11.2 To technically ensure that personal data is processed securely and confidentially, we utilize digital networks protected by measures such as encryption, firewalls, and password protection. In the event of a breach, Nobis Hotel AB has established robust procedures for identification, damage minimization, and reporting. Furthermore, Nobis Hotel AB has developed an effective method to uphold the rights of the data subject, including the right to be forgotten.
11.3 To ensure a high level of knowledge regarding personal data processing, ongoing GDPR training is provided for both Nobis Hotel AB employees and consultants who are engaged by the company from time to time to perform assignments.
12. When do we share personal data?
12.1 Nobis Hotel AB will not sell, disclose, or disseminate personal data to third parties, except as specified in this Privacy Policy. Within the scope of the Services, personal data may be transferred to subcontractors and partners, for instance, if necessary for the execution and provision of the company's services. In instances where we choose to share personal data, we enter into a data processing agreement to ensure that the recipient processes this data in accordance with applicable legislation and that the recipient has implemented the necessary technical and organizational measures under GDPR to adequately protect the data subject's rights and freedoms.
12.2 Furthermore, we may disclose personal data if we are obligated to do so by applicable law, court order, or if such disclosure is otherwise necessary to cooperate with a legal investigation.
13. Your Rights
13.1 Nobis Hotel AB is responsible for ensuring that your personal data is processed in accordance with applicable legislation.
13.2 Nobis Hotel AB will, upon your request or on its own initiative, correct, de-identify, delete, or supplement data found to be inaccurate, incomplete, or misleading.
13.3 You have the right to request access to your personal data. This means you have the right to request an extract from the register detailing the processing we carry out concerning your personal data. You also have the right to receive a copy of the personal data being processed. Once per calendar year, you are entitled to receive, free of charge, an extract from the register via a written and signed application, specifying what personal data about you is registered, the purposes of the processing, and to which recipients the data has been or will be disclosed. You also have the right to receive information in the register extract about the anticipated period during which the data will be stored or the criteria used to determine this period.
13.4 You have the right to rectification of your personal data. Upon your request, we will correct any inaccurate or incomplete data we process about you as quickly as possible.
13.5 You have the right to erasure of your personal data. This means you have the right to request that your personal data be deleted if it is no longer necessary for the purpose for which it was collected. However, there may be legal requirements preventing us from immediately deleting your personal data, for example, due to applicable accounting and tax legislation.
13.6 You have the right to object to personal data processing carried out based on a balancing of interests. If you object to such processing, we will only continue the processing if there are legitimate grounds for it that outweigh your interests.
13.7 If you do not wish for your personal data to be processed for direct marketing, you always have the right to object to such processing by either unsubscribing directly in each specific email or by sending an email to gdpr@nobishotel.se. Once we have received your objection, we will cease processing your personal data for such marketing purposes. If you are not satisfied with how we handle your personal data, you also have the option to report our processing of your personal data to the Swedish Data Protection Authority (Datainspektionen). However, for smooth and efficient handling, we recommend that you first contact us so that we can assist you with any questions or concerns.
14. Changes to this Policy
Nobis Hotel AB reserves the right to revise this Privacy Policy from time to time. The date of the latest amendment is indicated at the end of the Privacy Policy. Should we make any changes to the Privacy Policy, we will publish these changes on the website. You are therefore advised to review this Privacy Policy regularly to be aware of any updates. If we amend the Privacy Policy in a manner that significantly differs from what was stated when your consent was initially collected, we will inform you of these changes and, if necessary, request your renewed consent to Nobis Hotel AB's personal data processing.
15. Contact
Nobis Hotel AB (organization number 556629-5639) is the data controller responsible for processing your personal data. If you require further information on how your personal data is handled, please contact us by sending a written, personally signed request to:
Nobis Hotel AB
Norrmalmstorg 2-4
111 57 Stockholm
In your letter, please provide your name, address, email, telephone number, and personal identification number, in addition to your inquiry. Please also enclose a copy of your identification. A response will be sent to your most recently registered residential address.





