XIOR PRIVACY PRINCIPLES
Xior Group takes privacy seriously. The following principles underpin our approach to respecting your privacy:
- We value the trust that you place in us by giving us your personal data. We will always use your personal data in a way that is fair and worthy of that trust.
- We will provide clear information about how we use your personal data. We shall always be transparent with you about what information we collect, what we do with it, with whom we share it and who you should contact if you have any concerns.
- We will take all reasonable steps to protect your information from misuse and keep it secure.
- We will comply with all applicable data protection laws and regulations and we will co-operate with data protection authorities.
XIOR PRIVACY NOTICE
Last Updated: February 2023
This Privacy Notice explains the types of personal data we collect and how we use, disclose and protect that information.
What does this Privacy Notice apply to?
This Privacy Notice applies to personal data collected by Xior Group in connection with the services it offers. Find out more about Xior Group at http://www.uhub.eu/uhub-experience.
This includes personal data collected offline at our receptions, over the phone, through direct marketing campaigns, and online through our websites, applications and branded pages on third-party platforms and applications accessed or used through such websites or third-party platforms (“Xior Group Sites”).
This Privacy Notice also applies to Xior Group marketing content, including offers and advertisements for U.hub Group products and services, which we (or a service provider acting on our behalf) send to you on third-party websites, platforms and applications (“Third-Party Sites”) based on your site usage information. These Third-Party Sites generally have their own privacy notices and terms and conditions. We encourage you to read them before using those Third-Party Sites.
Identity and contact details of the controller
Xior Group is the controller of the personal data provided to or collected by Xior. See U.hub Group full details below:
- U.HUB BENFICA, a Portuguese company, with corporate name UHUB INVESTMENTS BENFICA, S.A., with registered offices in Lisbon, Campo Grande 28, 3º B, 1700-093 Lisboa, registered with the Commercial Registry Office of Lisbon under the number 503 046 574.
- U.HUB ASPRELA, a Portuguese company, with corporate name UHUB INVESTMENTS SAO JOAO, S.A., with registered offices in Lisbon, Campo Grande 28, 3º B, 1700-093 Lisboa, registered with the Commercial Registry Office of Lisbon under the number 515 634 476.
Both XIOR BENFICA and XIOR ASPRELA (hereinafter, jointly “We”, “Xior Group” or “the controller of the personal data”), are Correspondents for data. This means that we regulate and we are jointly responsible for processing and protecting personal data.
If you have any questions, comments or concerns about how we handle your personal data, then you may contact us by clicking the Get In Touch link at www.xior.pt (or by clicking here), by sending us an email to info@xior.pt or by calling us to our phone number +351 932 963 158
What personal data do we collect?
In this Privacy Notice, "personal data" means any information that can be used to identify, directly or indirectly, a specific individual.
You may be asked to provide your personal data when you are in contact with us. Xior Group companies may share this personal data with each other and use it in a manner consistent with this Privacy Notice. We may also combine it with other information to improve our services, content, and advertising.
You are not required to provide Xior Group the personal data that we request, but if you choose not to do so, we may not be able to provide you with our services, or with a high quality of service or respond to any queries you may have.
Ways in which we collect your personal data
We may collect personal data about you from different sources, including:
- Personal data you give us directly
- We collect data about how you use our services, such as the types of content you view or engage with, or the frequency and duration of your activities. We also collect personal data you provide us when you place a reservation, when you register on our client login area, when you register for services, when you make a comment or enquiry, sign up for a marketing newsletter or complete a survey. In doing so, we may ask for personal data, such as your name, nationality, gender, date of birth, address, email address, ID Number, VAT number, telephone number or credit card details.
- Personal data we collect automatically
- We also receive and store certain types of personal data whenever you interact with us online. For example, we use cookies and tracking technologies to obtain personal data when your web browser accesses our websites or advertisements and other content served by or on behalf of Xior Group on other websites. Your personal data is also collected when you search, buy, post, participate in a contest or questionnaire or communicate with our customer service teams. Examples of the types of personal data we collect include; IP address, device ID, location data, computer and connection information such as browser type and version, time zone setting, browser plug-in types and versions, operating system. During some of your internet browsing on U.hub Group Sites we may also use software tools to measure and collect session information, including page response times, download errors, length of visits to certain pages, page interaction information, and methods used to browse away from the page. We may also collect technical information to help us identify your device for fraud prevention and diagnostic purposes.
- Personal data we collect from other sources
- We collect personal data from other sources including our trusted partnerships with third-parties and where we operate Xior Group accounts on third-party platforms: for example, when you use the “like” functionality on Facebook or the +1 functionality on Google+. Additionally, we receive information about you and other visitors’ interactions with our advertising to measure whether our advertising is relevant and successful.
The purposes and legal basis for the processing
Xior Group will only collect, use or disclose your personal data where it is fair and lawful to do so. In most cases, we will ask for your consent explicitly. However, we may process your personal data without consent if we have another lawful reason to do so. Any such use shall be in accordance with the U.hub Privacy Principles set out above.
Your consent
When you register at a Xior Group Site you are consenting explicitly and freely, by opting in the check box, to Xior Group collecting, using and disclosing your personal data in accordance with this Privacy Notice.
You are consenting to the processing of your personal data described in this policy and which are not being processed based on other grounds described below, and in particular: (i) to contact you regarding products and services which may be of interest to you; and (ii) to improve our products and services and your experience on the Xior Group Sites; as described below in the section “How do we use your personal data?”.
We may ask you to provide additional consent if we need to use your personal data for purposes not covered by this Privacy Notice. You are not obliged to provide such consent but if you decide not to then your participation in certain activities may be restricted. If you provide additional consent, the terms of that consent shall prevail in the event of any conflict with the terms of this Privacy Notice.
You have the right to withdraw consent at any time, without prejudice to the processing that might have occurred in the meantime. If you wish to do so, please contact us as described above.
Children
Most of the Xior Group Sites’ functionalities are designed and intended for use by adults. Where a U.hub Group Site or a certain functionality may be used by a younger audience, we will obtain consent from a parent or guardian before we collect personal data where it is required by applicable laws and regulations (the age at which consent is necessary varies from country to country). If you are a child over the age where parental consent is required in your country, you should review the terms of this Privacy Notice with your parent or guardian to make sure you understand and accept them.
If we discover that we have collected information from a child without consent from a parent or guardian where such consent should have been obtained, we will delete that information as soon as practical.
We sometimes use your personal data to carry out age verification checks and enforce any age restrictions.
Performance of a contract in which you are a party, and to take steps at your request prior to entering into a contract
Certain personal data you will provide when you register on our client login area, when you register for services and when you buy a service from us, will be used to place bookings and manage and confirm reservations for our products and services, to send you reminder emails, to include in the Lodging Services Agreement for Temporary Housing and for billing and contract management purposes. The processing of this information for these purposes is not based on consent, but rather on the performance of a contract in which you are a party and to take steps, at your request, prior to entering the contract. This information is necessary in order to enter into the contract. If the information is not provided the contract cannot be executed.
Processing is necessary for compliance with a legal obligation to which the controller is subject
We may process your personal data if the processing is necessary for legal reasons, such as to comply with applicable laws and regulations, co-operate in any legal investigation and meet enforceable governmental requests.
Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child
In some cases, we rely on legitimate interest for processing your personal data. A legitimate interest could exist for example, when you sign up at a Xior Group Site and we use the personal data collected to conduct data analytics to improve our products or services. This ground will only be used where it is necessary to achieve a legitimate interest, for example to assist in the performance of a contract, or to optimize a service, and does not outweigh your rights as an individual. This legal basis will only be relied upon where there is no less intrusive way to process your personal data. We can assure you that if legitimate interest is used as a ground for processing your personal data, we will keep a record of this and you have the right to ask for this information.
What purpose do we use your personal data for?
We collect, process and disclose your personal data only for specific and limited purposes. For example, to process your payments, to assess and handle any complaints, to develop and improve our services, communication methods and the functionality of Xior Group Sites, to provide personalized communications and targeted advertising as well as service recommendations to you.
We collect, process and disclose your personal data for the following purposes:
- To process your payments, if you purchase our services or make a reservation, to provide you with your reservation status, deal with your enquiries and requests, and assess and handle any complaints;
- To place bookings and manage and confirm reservations for our services;
- To include in the Lodging Services Agreement for Temporary Housing;
- For billing and contract management purposes;
- For the purposes of promotions that you have entered;
- To process and answer your inquiries or to contact you to answer your questions and/or requests;
- To develop and improve our services, communication methods and the functionality of Xior Group Sites;
- To communicate information to you and to manage your registration and/or subscription to our newsletter or other communications;
- To authenticate the identity of individuals contacting us by telephone, electronic means or otherwise;
- For internal training and quality assurance purposes;
- To analyze the effectiveness of our advertisements and promotions;
- To personalize your website experience, as well as to evaluate (anonymously and in the aggregate) statistics on website activity, such as what time you visited it, whether you’ve visited it before and what site referred you to it;
- To help speed up your future activities and experience on the Xior Group Sites. For example, a site can recognize that you have provided your personal data and will not request the same information a second time;
- To include your reviews on Xior Group Sites, if you post a review;
- To understand and assess the interests, wants, and changing needs of consumers, to improve our website, our current products and services, and/or developing new products and services;
- To provide personalized services, communications and targeted advertising as well as service recommendations to you; and
- To suggest products or services (including those of relevant third-parties) which we think may be of interest to you (you can opt out of receiving communications from us at any time and any direct marketing communications that we send to you will provide the information and means necessary to opt out)
When we collect and use your personal data for purposes mentioned above or for other purposes, we will inform you before or at the time of collection.
Where appropriate, we will ask for your consent to process the personal data. Where you have given consent for processing activities, you have the right to withdraw your consent at any time.
Recipients (or categories of recipients) of the personal data
Xior Group shares your personal data internally and with selected third-parties. For example, we share your personal data with third-party service providers and in case of business transfers or legal disclosure.
Xior Group shares your personal data in the following circumstances:
- Third-party service providers. In order to carry out your requests, respond to your inquiries, fulfil your reservations, or make various other features or services available to you through our websites we share your personal data with third-party service providers that perform functions on our behalf, such as companies that: host or operate Xior Group Sites, process credit card payments, provide accounting services, analyze data, provide customer service, postal or delivery services, and sponsors or other third-parties that participate in or administer our promotions. They have access to personal data needed to perform their functions but may not use it for other purposes. Further, they must process this personal data in accordance with this Privacy Notice and as permitted by applicable data protection laws and regulations.
- Business transfers. Your personal data will be used by us or shared with Xior Group for internal reasons, primarily for business and operational purposes. As we continue to develop our business, we may sell or purchase assets, subsidiaries or business units. In such transactions, your personal data generally is one of the transferred business assets but remains subject to the promises made in any pre-existing Privacy Notice (unless, of course, you consent otherwise). If another entity acquires us, our businesses or substantially all or part of our assets, or assets related to U.hub Group Sites, your personal data will be disclosed to such entity as part of the due diligence process and will be transferred to such entity as one of the transferred assets. Also, if any bankruptcy or reorganization proceeding is brought by or against us, all such personal data will be considered an asset of ours and as such it is possible they will be sold or transferred to third-parties.
- Legal disclosure. We may transfer and disclose your personal data to third-parties:
- To comply with a legal obligation;
- When we believe in good faith that an applicable law requires it;
- At the request of governmental authorities conducting an investigation;
- To verify or enforce our “Terms and conditions”, “Lodging Services Agreement” or other applicable policies;
- To detect and protect against fraud, or any technical or security vulnerabilities;
- To respond to an emergency; or otherwise
- To protect the rights, property, safety, or security of third-parties, visitors to Xior Group websites, Xior Group or the public.
International Data Transfers
Xior Group shares personal data internally or with third-parties for purposes described in this Privacy Notice.
Xior Group will only send personal data collected within the European Economic Area (EEA) to foreign countries in circumstances such as:
- To follow your instructions;
- To comply with a legal duty; or
- To work with our agents and advisers who we use to help run our business and services.
If we do transfer personal data to outside of the EEA, Xior Group will make sure that it is protected in the same way as if it was being used in the EEA. We’ll use one of the following safeguards:
- Transfer to a non-EEA Country whose privacy legislation ensures an adequate level of protection of personal data to the EEA one;
- Put in place a contract with the foreign third-party that means they must protect personal data to the same standards as the EEA; or
- Transfer personal data to organizations that are part of specific agreements on cross-border data transfers with the European Union (e.g., Privacy Shield, a framework that sets privacy standards for data sent between the United States and the European countries).
Storage period
We will keep your personal data for as long as we need it for the purpose it is being processed for. For example, where you make a reservation online with us or register for services we will keep the data related to your reservation or services requested, so we can perform the specific contract you have entered and after that, we will keep the personal data for a period which enables us to handle or respond to any complaints, queries or concerns relating to the services.
Your data may also be retained so that we can continue to improve your experience with us and to ensure that you receive any promotions or discounts which are due to you.
We retain the identifiable data we collect directly for targeting purposes for as little time as possible, after which we employ measures to permanently delete it.
We will actively review the personal data we hold and delete it securely, or in some cases anonymize it, when there is no longer a legal, business or consumer need for it to be retained.
Safeguarding your personal data
Xior Group takes the security of your personal data very seriously. We take every effort to protect your personal data from misuse, interference, loss, unauthorized access, modification or disclosure.
Our measures include implementing appropriate access controls, investing in Information Security Capabilities to protect the IT environments we leverage, and ensuring we encrypt, pseudonymize and anonymize personal data wherever possible.
Access to your personal data is only permitted among our employees and agents on a need-to-know basis and subject to strict contractual confidentiality obligations when processed by third-parties.
Your privacy rights and who to contact
Your rights in relation to your personal data and how it is processed. You can exercise these rights at any point. We have provided an overview of these rights below together with what this entails for you. You can exercise your rights by contacting us by clicking the Get In Touch link at www.uhub.eu (or by clicking here) or by sending us an email to info@xior.pt.
- The right to be informed. You have the right to be provided with clear, transparent and easily understandable information about how we use your personal data and your rights. Therefore, we’re providing you with the information in this Notice.
- The right to access and rectification. You have the right to access, correct or update your personal data at any time. We understand the importance of this and should you want to exercise your rights, please contact us.
- The right to data portability. The personal data you have provided us with is portable. This means it can be moved, copied or transmitted electronically under certain circumstances.
- The right to be forgotten. Under certain circumstances, you have right to request that we delete your data. If you wish to delete the personal data we hold about you, please let us know and we will take reasonable steps to respond to your request in accordance with legal requirements. If the personal data we collect is no longer needed for any purposes and we are not required by law to retain it, we will do what we can to delete, destroy or permanently de-identify it.
- The right to restrict processing. Under certain circumstances, you have the right to restrict the processing of your personal data.
- The right to object. Under certain circumstances, you have the right to object to certain types of processing, including processing for direct marketing (i.e., receiving emails from us notifying you or being contacted with varying potential opportunities).
- The right to lodge a complaint with a Supervisory Authority. You have the right to lodge a complaint directly with a Supervisory Authority about how we process your personal data. In Portugal the Supervisory Authority is “Comissão Nacional de Protecção de Dados”.
- The right to withdraw consent. If you have given your consent to anything we do with your personal data (i.e., we rely on consent as a legal basis for processing your personal data), you have the right to withdraw your consent at any time (although if you do so, it does not mean that anything we have done with your personal data with your consent up to that point is unlawful). You can withdraw your consent to the processing of your personal data at any time by contacting us with the details provided below.
- Rights related to automated decision-making. You have the right not to be subject to a decision which is based solely on automated processing and which produces legal or other significant effects on you. In particular, you have the right:
- to obtain human intervention;
- to express your point of view;
- to obtain an explanation of the decision reached after an assessment; and
- to challenge such a decision.
Further information and advice about your rights can be obtained from the data protection Regulator.
Changes to our Privacy Notice
We will update this Privacy Notice when necessary to reflect client and user feedback and changes in our services. When we post changes to this statement, we will revise the “last updated” date at the top of this Notice. If the changes are significant, we will provide a more prominent notice (including, for certain services, email notification of Privacy Notice changes). We will also keep prior versions of this Privacy Notice in an archive for your review.
We will not reduce your rights under this Privacy Notice without your consent.
Other Xior Group privacy notices
In addition to this Privacy Notice, there may be specific campaigns or promotions which will be governed by additional privacy terms or policies. We encourage you to read these additional terms or policies before participating in any such campaigns or promotions as you will be required to comply with them if you participate. Any additional privacy terms or policies will be made prominently available to you.