EN FR

Privacy Policy

The company S.A. "PEARL RESORTS OF TAHITI" is committed to ensuring that the processing of your personal data collected via the website https://www.pearlresorts.com complies with Law No. 78-17 of 6 January 1978 (as amended) relating to information technology, data files and civil liberties, and with the General Data Protection Regulation (GDPR).

This Privacy Policy applies only to the website https://www.pearlresorts.com.

Third-party websites or mobile applications to which you may be redirected while using the website have their own policies. We therefore encourage you to review the legal notices and privacy policy of those websites.

This Privacy Policy explains our policies and practices regarding how we collect and use the personal data we gather on our digital platforms.

Definitions

Data Controller

The natural or legal person, public authority, agency or other body which, alone or jointly with others (joint controllers), determines the purposes and means of the processing of personal data.

General Data Protection Regulation

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the "GDPR"), together with any legislation and/or regulation implemented or created pursuant to the GDPR and online privacy legislation, or which amends, replaces, re-adopts or consolidates any of them, and all other applicable national laws relating to the processing of personal data and privacy protection (French Data Protection Act — "Loi Informatique & Libertés").

Processor

A natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller.

Recipient

A natural or legal person, public authority, agency or other body to which personal data is disclosed, whether a third party or not.

Third Party

A natural or legal person, public authority, agency or body other than the data subject, the controller, the processor, and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

Supervisory Authority

An independent public authority established by a Member State pursuant to Article 51 of the GDPR (the CNIL in France).

Personal Data

Any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Processing

Any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Standard Contractual Clauses

A set of standard contractual clauses for transfers, adopted by the European Commission for the international transfer of personal data.

Personal Data Breach

A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data transmitted, stored or otherwise processed.

Data controller

The data controller is the entity that determines the purposes and means of the processing of personal data.

The data controller is S.A. "PEARL RESORTS OF TAHITI", a simplified joint-stock company (société par actions simplifiée), whose registered office is located at 24 rue Paul Gauguin, Papeete, registered with the Papeete Trade and Companies Register under number TPI 96 115 B, and identified in the Territorial Business Register under number TAHITI 368 340.

In accordance with applicable regulations, in particular the General Data Protection Regulation adopted in Europe, we are committed to complying with its principles.

Lawfulness, fairness and transparency

Data minimisation

Storage limitation

Data security

The different processing activities of personal data

Purpose Legal basis for processing Categories of data processed Retention period Source
Management and improvement of website security (cookies) Consent / Legitimate interest Connection data: session number, IP address, browser type, operating system 13 months
Booking management Performance of a contract Identification data (including minors), booking details, email and phone contact details, card type, special requests which may contain sensitive data 3 years from the booking date / 10 years for accounting obligations and dispute management Website booking form
Newsletter management Consent Name, first name, country, email address Until consent is withdrawn via the unsubscribe link at the bottom of the email Newsletter sign-up form
Commercial prospecting Performance of a contract (pre-contractual step) Email address 3 years from last contact, or until unsubscription via the link included at the bottom of the email Business relationship
Social media interaction Legitimate interest Identification data and username Linked to the existence of the relevant social media page Social media platform concerned
Organisation of competitions Legitimate interest Depending on the type of competition: identification, contact details, username Linked to the competition rules Competition entry form, social media

Your personal data is retained and accessible by S.A. "PEARL RESORTS OF TAHITI" only for as long as necessary to fulfil the purpose for which it was collected, in accordance with applicable legal provisions.

Recipients

Your personal data collected on the website https://www.pearlresorts.com is confidential and is only disclosed internally to employees authorised to process it for the purposes described above, who are bound by confidentiality obligations. It may be shared with other entities within the group involved in the relationship. The CNIL or any other competent supervisory authority may also access it.

We may also disclose personal data to third parties acting on behalf of S.A. "PEARL RESORTS OF TAHITI". All such processing is based on our prior instructions set out in a contract that complies with the requirements of applicable law. These disclosures are made for various reasons, including:

These service providers undertake to respect confidentiality and are not authorised to use your personal data for any other purpose. We also verify that appropriate security measures are applied to protect your personal data.

Some of our hotels are members of the Relais & Châteaux Association. As a member of the "Reconnaissance Client" recognition programme, your personal data collected in connection with your stay will be transmitted to the Relais & Châteaux member establishments with which you make a booking.

We may also disclose your personal data to comply with our legal obligations, including providing information to regulatory bodies where required by law, notably to comply with our legal obligations regarding the prevention and combating of fraud, money laundering and terrorist financing.

Transfer of Data Outside the EU

Personal data may be processed outside the European Union. Where a country does not offer an adequate level of protection under the GDPR, S.A. "PEARL RESORTS OF TAHITI" will implement appropriate safeguards to ensure that such transfers comply with the European data protection regulation, in particular by putting in place Standard Contractual Clauses approved by the European Commission, as these are considered to provide an adequate level of protection.

Security Measures

S.A. "PEARL RESORTS OF TAHITI" has implemented technical and organisational security measures to protect your personal data against unauthorised access and use. We follow appropriate security procedures in the storage and disclosure of your personal data in order to prevent unauthorised access by third parties and to avoid accidental loss of your data. We restrict access to your personal data to individuals who genuinely need it for professional purposes. Individuals who access your data are bound by a duty of confidentiality towards S.A. "PEARL RESORTS OF TAHITI".

We have also implemented procedures to address any suspected data security breach. We will notify you, as well as the French Supervisory Authority, in the event of a suspected data security breach (data breach), where required to do so by law.

The website has a TLS ("Transport Layer Security") certificate to ensure that information and data transferred through the site are secure. A TLS certificate is designed to secure data exchanged between the user and the website.

Social Media

In order to share content or user opinions about our products or services, elements (buttons, plug-ins, etc.) related to social media or other websites have been integrated into the website. These elements allow social media platforms/websites to track the user's browsing activity, provided the user is logged in to the relevant social media platform on their browser.

The terms of use of information related to these elements are defined by the social media platform/website of which you are a member; we have no control over the actions carried out. We encourage you to review the privacy policies of these social media platforms/websites to understand how they use the data collected during your browsing and how to manage your account privacy settings.

Your Rights — GDPR and French Data Protection Law

You have, at any time, the right to access, rectify, restrict, erase, port and object to the processing of your personal data.

If you have any questions regarding our Privacy Policy or the processing of your data, or if you wish to exercise any of the rights listed above or withdraw your consent, you may contact the Data Protection Officer of S.A. "PEARL RESORTS OF TAHITI":

Please note that you may be asked to provide certain information (a copy of a legally recognised form of identification) for identification purposes in order to process your request and to protect you against fraudulent requests.

If you are not satisfied with our response, you have the right to file a complaint with the French Data Protection Authority (CNIL): https://www.cnil.fr/fr/plaintes

Notice to California Residents

Do Not Sell or Share My Personal Information — Our Commitment

We respect your privacy. In accordance with the CCPA (California Consumer Privacy Act), we inform you that we do not sell or share your personal information with third parties, including for targeted advertising purposes.

For any request relating to your personal data, please contact our Data Protection Officer: dpo@pearlresorts.com.

More

We use cookies to personalize content, provide social media features, and analyze our traffic. We also share information about your use of our site with our analytics partners. You can change your preferences at any time. For more information, please see our Privacy Policy and Cookie Policy.