PRIVACY NOTICE FOR CALIFORNIA RESIDENTS
[Last Updated: May 30, 2024]
Fattal Hotels Ltd., together with its subsidiaries and affiliated companies and the hotels in the Fattal group (collectively “Fattal”, “Company”, “we” or “us”) is devoted to making sure that your privacy rights are respected, and personal data is collected and used in accordance with the current and applicable privacy and data protection law. The California Consumer Privacy Act of 2018 (“CCPA”), as amended by the California Privacy Rights Act of 2020 (“CPRA”), together with any other California privacy laws, and this CCPA Notice apply to Visitors and Customers of our Site who are California residents (“consumers” or “you”).
This CCPA Notice is an integral part of our Privacy Policy, and thus, definitions used herein shall have the same meaning as defined in the Privacy Policy. Any terms defined in the CCPA and CPRA have the same meaning when used in this CCPA Privacy Notice.
This CCPA Notice is relevant for residents of California, to the extent the CCPA may apply on our Site, and pertains to Personal Information that we collect both directly and indirectly in our role as a Business during the use or provision of our Services through our Site.
PART I: A COMPREHENSIVE DESCRIPTION OF THE INFORMATION PRACTICES:
(1) Categories Of Personal Information
We collect Personal Information which is defined under the CCPA as any information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, household or device, all as detailed in the table below.
Personal Information does not include: publicly available information that is lawfully made available from government records, that a consumer has otherwise made available to the public; De-identified or aggregated consumer information; Information excluded from the CCPA’s or CPRA’s scope, such as: Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPPA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data; Personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FRCA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA) and the Driver’s Privacy Protection Act of 1994.
Please see below a table detailing the categories of Personal Information that we collect as a Business (and has collected within the last 12 months):
CATEGORY | EXAMPLES OF PERSONAL INFORMATION | COLLECTED |
A. Identifiers. | A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers. | Yes – online identifier, IP address, real name, account name, email address – with respect to Customers and Visitors. Additional data pertaining to Customers making a reservation – passport number. |
B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).
|
A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories. |
Yes – Name and telephone number if provided by you. Passport number for Customers. |
C. Protected classification characteristics under California or federal law.
|
Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information). | No |
D. Commercial information. | Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. | Yes – with respect to customers – Records of Services purchased, obtained, or considered. |
E. Biometric information. | Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data. | No |
F. Internet or other similar network activity. | Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement. | Yes – information on your interaction with our Site or other digital assets and Services, or advertisements included therein. |
G. Geolocation data. | Physical location, approximate location derived from IP address or movements. | Yes – approximate location from IP address when accessing the Site. |
H. Sensory data. | Audio, electronic, visual, thermal, olfactory, or similar information. | No |
I. Professional or employment-related information.
|
Current or past job history or performance evaluations. | No |
J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)). | Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records. | No |
K. Inferences drawn from other personal information. | Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. | No |
L. Sensitive personal information.
|
Government-issued identifying numbers, financial account details, genetic data, precise geolocation, race or ethnicity, religious or philosophical beliefs, union membership, mail, email, text messages, biometric data, health data, and sexual orientation or sex life. | No |
(2) Disclosures Of Personal Information for a Business Purpose
We may disclose your Personal Information to a contractor or service provider for our business purposes. When we disclose Personal Information for a business purpose, we enter into a contract that describes the purpose and requires the recipient to both keep that Personal Information confidential and not use it for any purpose except fulfilling the contract. In the preceding twelve (12) months, we disclosed the following categories of Personal Information for a business purpose:
BUSINESS PURPOSE | CATEGORY OF RECIPIENT | CATEGORY (CORRESPONDING WITH THE TABLE ABOVE) | |
Storage, hosting. | Cloud computing and storage vendors. |
Category A Category B Category D Category F Category G |
1 |
Subject to a law requirement, such as tax authorities. | Government entities/Law enforcement. | 2 | |
Operating the Site and Services | Operating systems | 3 | |
Providing analytic data on the use of our Site and Services. | Data analysis providers. |
Category A Category D Category F Category G |
4 |
Marketing which is not cross-contextual, ad delivery. | Marketing & promotions providers, CRM providers, social networks, advertising networks. | Category A
Category B Category D Category F Category G |
6 |
Debugging, security, fraud prevention. | Security service providers. | Category A
Category F
|
7 |
Customer and technical support. | Customer support providers. Affiliated companies. | Category A
Category B Category D Category F Category G |
9 |
(3) How We Collect Personal Information
We collect the categories of Personal Information detailed above, in the following ways:
• Directly from you: For example, from forms you complete, when you contact us, make a reservation, etc.;
• Directly and indirectly from activity on our Site: For example, directly from you when you inquire about our Site, or indirectly, we collect your usage data automatically from measurement tools;
• Indirectly from you: We track your activities across the internet related to engagement with our campaigns, for example, when you view or interact with certain content, web page or ad.
(4) Use Of Personal Information
We may use, or disclose the Personal Information we collect for one or more of the following business purposes:
• To fulfill or meet the reason you provided Personal Information. For example, if you make a reservation, we will use your Personal Information to prepare your staying with us, validate your booking, etc..;
• For security and fraud detection purposes, monitoring and to maintain the safety, security, and integrity of our Site;
• To improve our Services, which includes but not limited to, analyze which types of ads should be provided as part of the Site; marketing our Services; analyzing our Services and your use of the Site;
• To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations;
• As described to you when collecting your Personal Information or as otherwise set forth in the Privacy Policy.
We will not collect additional categories of Personal Information or use the Personal Information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
(5) Sale Of Personal Information
In the preceding twelve (12) months, we do not “sell” information as most people would commonly understand that term, we do not, and will not, disclose your Personal Information in direct exchange for money or some other form of actual payment. We may “share” Personal Information for “interest-based advertising” or “cross-context behavioral advertising”. The CCPA defines “sharing” as “communicating orally, in writing, or by electronic or other means, a consumer’s Personal Information” to “a third party for cross-context behavioral advertising, whether or not for money or other valuable consideration”. In other words, we may share your Personal Information with a third party to help serve personalized content or ads that may be more relevant to your interests, and to perform other advertising-related services such as enabling our partners to serve such personalized content.
In the preceding twelve (12) months, we “sell” or “share” the following categories of Personal Information for a business purpose:
PURPOSE OF SALE OR SHARE | CATEGORY RECIPIENT | CATEGORY (CORRESPONDING WITH THE TABLE ABOVE) |
Sale/Share for cross-context behavioral advertising. | Ad-network and advertising partners. | category A
Category F Category G
|
(6) Data Retention
In general, we retain the Personal Information we collect for as long as it remains necessary for the purposes set forth above, all under the applicable regulation, or until you express your preference to optout, where applicable.
The retention periods are determined according to the following criteria:
• For as long as it remains necessary in order to achieve the purpose for which the Personal Information was initially processed. For example, if you contacted us, we would retain your contact information at least until we address your inquiry.
• To comply with our regulatory obligations. For example, transactional data will usually be retained for seven years as of termination of engagement (or even more under certain circumstances) for compliance with our bookkeeping obligations purposes.
• To resolve a claim, we might have a dispute with you, including any legal proceeding between us, until such dispute is resolved, and following, if we find it necessary, in accordance with applicable statutory limitation periods.
Please note that except as required by applicable law, we will not be obligated to retain your data for any particular period, and we may delete it for any reason and at any time, without providing you with prior notice of our intention to do so.
(7) Amendments
As required under the CCPA, we will update this Privacy Notice every 12 months. The last revision date will be reflected in the “Last Modified” heading located at the header of the Privacy Notice.
(8) Children Under Age 16
We do not knowingly collect information from children under the age of 16 that reside in California, unless such data is provided voluntarily by the Customer in its capacity as their legal guardian.
PART II: EXPLANATION OF YOUR RIGHTS UNDER THE CCPA AND HOW TO EXERCISE THEM
(1) Users’ Rights
If you are a California resident, you may exercise certain privacy rights related to your Personal Information. You may exercise these rights free of charge except as otherwise permitted under applicable law.
DETAILS | CALIFORNIA PRIVACY RIGHTS |
The right to know what Personal Information the business has collected about the consumer, including the categories of Personal Information, the categories of sources from which the Personal Information is collected, the business or commercial purpose for collecting, selling, or sharing Personal Information, the categories of third parties to whom the business discloses Personal Information, and the specific pieces of Personal Information the business has collected about the consumer. | The right to know what Personal Information the business has collected. |
The right to delete Personal Information that the business has collected from the consumer, subject to certain exceptions. | Deletion rights. |
The right to correct inaccurate Personal Information that a business maintains about a consumer. | Correct inaccurate information |
You have the right to opt-out of the “sharing” of your Personal Information for “cross-contextual behavioral advertising”, often referred to as “interest-based advertising” or “targeted advertising”. | Opt-Out of sharing for cross-contextual behavioral advertising |
the right to opt-out of the sale or sharing of Personal Information by the business. | Opt-out from selling |
Under certain circumstances, If the business uses or discloses SPI, the right to limit the use or disclosure of SPI by the business. | Limit the Use or Disclosure of SPI |
In certain circumstances, you have the right to opt-out of the use of automated decision making in relation to your Personal Information. | Opt-out of the use of automated decision making |
The right not to receive discriminatory treatment by the business for the exercise of privacy rights conferred by the CCPA, including an employee’s, applicants, or independent contractor’s right not to be retaliated against for the exercise of their CCPA rights, denying a consumer goods or services, charging different prices or rates for goods or services, providing you a different level or quality of goods or services, etc. We may, however, charge different prices or rates, or provide a different level or quality of goods or services, if that difference is reasonably related to the value provided to us by your Personal Information. | Non-discrimination |
You may request to receive a copy of your Personal Information, including specific pieces of Personal Information, including, where applicable, to obtain a copy of the Personal Information you provided to us in a portable format. | Data portability
|
To learn more about your California privacy rights, please visit https://oag.ca.gov/privacy/privacy-laws.
(2) How Can You Exercise the Rights?
We provide option to opt out of Sharing for Cross-Contextual Behavioral Advertising or Selling Personal Information by using the following opt-out options:
• Use the “Do Not Sell or Share My Information” through the cookie setting tool available on our Site.
• To opt out from cross contextual ads you can further use these links:
– Network Advertising Initiative’s (“NAI”) HERE;
– Digital Advertising Alliance’s (“DAA”) HERE Or the European Interactive Digital Advertising Alliance (“EDAA”) HERE;
– California and Colorado resident and wish to opt-out from having your data used for interest-based advertising, you may exercise your right here: https://optout.privacyrights.info/.
• We also are able to affirmatively the Global Privacy Control preference.
Other rights may be exercised by contacting us by mail: info@fattal.co.il.
(3) Authorized Agents
“Authorized Agents” may submit opt out requests on a consumer’s behalf. If you have elected to use an authorized agent, or if you were an authorized agent who would like to submit requests on behalf of a consumer, the following procedures will be required prior to acceptance of any requests by an authorized agent on behalf of a California consumer. Usually, we will accept requests from qualified third parties on behalf of other consumers, regardless of either the consumer or the authorized agent’s state of residence, provided that the third party successfully completes the following qualification procedures:
• When a consumer uses an authorized agent to submit a request to know or a request to delete, a business may require that the consumer do the following:
– Provide the authorized agent signed permission to do so or power of attorney.
– Verify their own identity directly with the business.
– Directly confirm with the business that they provided the authorized agent permission to submit the request.
• A business may deny a request from an authorized agent that does not submit proof that they have been authorized by the consumer to act on their behalf.
(4) Notice Of Financial Incentive
We do not offer financial incentives to consumers for providing Personal Information.
PART III: OTHER CALIFORNIA OBLIGATIONS
(1) Direct Marketing Requests:
California Civil Code Section 1798.83 permits you, if you are a California resident, to request certain information regarding disclosure of Personal Information to third parties for their direct marketing purposes. To make such a request, please contact us by mail: info@fattal.co.il.
(2) Do Not Track Settings:
Cal. Bus. And Prof. Code Section 22575 also requires us to notify you how we deal with the “Do Not Track” settings in your browser. As of the effective date listed above, there is no commonly accepted response for Do Not Track signals initiated by browsers. Therefore, we so not respond to the Do Not Track settings. Do Not Track is a privacy preference you can set in your web browser to indicate that you do not want certain information about your web page visits tracked and collected across websites. For more details, including how to turn on Do Not Track, visit: www.donottrack.us.
CONTACT US:
● By Email – info@fattal.co.il
● By Mail –
o Fattal Hotels Ltd.
o registration number 510678816.
o Address: 94 Yigal Alon St., Tel-Aviv, Israel,
o Email: info@fattal.co.il
o Phone: +972-3-5110016/7