Privacy Policy
Last updated: September 1, 2026
OpenYourHotel respects your privacy. This policy explains how we handle personal data when you visit our website, contact us, arrange a conversation or work with us.
1. Who is responsible for your personal data?
Ingmar Sloothaak, trading as OpenYourHotel, is the controller for the processing described in this policy.
Registered business address: Kuipersstraat 147 A8, 1073 ER Amsterdam, the Netherlands
Dutch Chamber of Commerce (KvK): 53129148
Email: info@openyourhotel.nl
Telephone: +31 (0)20 793 38 43
Website: https://www.openyourhotel.nl
2. What information do we collect?
Depending on your interaction with us, we may process:
Your name, role, organisation and business contact details.
Information you provide through a contact form, email, telephone conversation or appointment booking.
Meeting details, correspondence and relevant notes about your enquiry or engagement.
Contract, invoicing and payment information.
Technical information such as IP address, browser and device information, requested pages, timestamps and security logs.
Cookie preferences and, where enabled with the required consent, website usage information.
We usually receive information directly from you. Business contact details may also come from your organisation, a professional introduction or publicly available professional sources. Where required, we explain the source when we first contact you.
Please avoid including sensitive personal information or identifiable guest or employee records in a general enquiry. If an engagement requires such information, we agree an appropriate and secure process separately.
3. Why do we use your information?
PurposeLegal basisResponding to enquiries and arranging introductory conversationsSteps requested before entering a contract where you are the prospective contracting party; otherwise our legitimate interest in responding to business enquiriesPreparing proposals, delivering services and managing relationshipsPerformance of our contract with you, or our legitimate interest in managing an engagement with your organisationInvoicing, accounting and tax administrationContract performance and compliance with legal obligationsMaintaining website security, preventing misuse and handling disputesOur legitimate interests in protecting our business, website and legal rightsOptional analytics or marketing trackingYour consentSending optional promotional email updatesYour consent, unless a specific legal exception permits this; you can opt out at any time
Where we rely on legitimate interests, we assess whether those interests are outweighed by your rights and freedoms. You may object as explained below.
Providing contact details is not a statutory requirement, but we may be unable to respond, arrange a meeting or deliver services without relevant information. Fields marked as required on a form are needed to handle that request.
Sending an enquiry does not automatically subscribe you to promotional communications.
4. Who receives your information?
We share information only where necessary for the purposes described above, including with:
Squarespace for website hosting and relevant website functions.
Google for email, business collaboration and appointment scheduling, where used.
IT and administrative service providers supporting our business.
Accountants, professional advisers, insurers and payment service providers where relevant.
Public authorities where disclosure is legally required.
Providers acting on our instructions are subject to appropriate processing and confidentiality arrangements. Some recipients, such as professional advisers or external platforms, may act as independent controllers for their own processing.
We do not sell your personal data.
5. International transfers
Some providers may process personal data outside the European Economic Area. Where this occurs, we use a lawful transfer mechanism, such as an applicable European Commission adequacy decision or Standard Contractual Clauses, with additional safeguards where necessary.
[BEFORE PUBLICATION: identify the confirmed providers and relevant destination countries, and specify the transfer mechanism used for each. Confirm whether any EU–US Data Privacy Framework reliance applies to the relevant certified entity and service.]
You may contact us for information about applicable safeguards or to request a copy, subject to appropriate redaction of confidential information.
6. How long do we keep your information?
We retain personal data only for as long as needed for its purpose:
Enquiries that do not result in an engagement: normally up to 12 months after the last meaningful contact.
Client correspondence and project records: for the engagement and afterwards only as necessary for agreed follow-up, legal obligations or the establishment, exercise or defence of legal claims. We review these records and remove information that is no longer needed.
Accounting and tax records: normally seven years, or longer where a specific statutory obligation applies.
Promotional contact details: until you unsubscribe or the information is no longer relevant. We may retain minimal suppression information to honour your opt-out.
Cookie preferences and related identifiers: according to the durations shown in our cookie information.
Security logs: for a period proportionate to security needs, with longer retention only where necessary to investigate a specific incident.
Records needed for an active dispute or legal obligation may be retained longer. Retention periods apply to the relevant records, not automatically to every item of personal data in a project.
7. Your rights
Subject to the applicable legal conditions, you may request access, correction, deletion, restriction of processing or data portability. You may object to processing based on legitimate interests. You can object to direct marketing at any time.
Where processing relies on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before it was withdrawn.
Send requests to ingmar@openyourhotel.nl. We may request proportionate information to verify your identity. We respond without undue delay and normally within one month. If the law permits an extension of up to two further months, we explain the reason within the first month.
You may lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, at https://www.autoriteitpersoonsgegevens.nl, or with the competent supervisory authority in the EEA country where you live or work. You do not have to contact us first.
8. Security and automated decisions
We use appropriate technical and organisational measures to protect personal data, taking account of the nature of the information and the risks involved. No system can guarantee absolute security.
We do not use solely automated decision-making that produces legal or similarly significant effects on you.
9. Client data, cookies and external services
Where we process personal data solely on a client's instructions during an engagement, the client generally remains the controller. The applicable processing agreement and the client's privacy information govern that processing. This policy does not replace those arrangements.
Our Cookie Settings explain website cookies and your choices. When you follow an external link, including an appointment booking or social media link, the external provider's privacy information also applies to its processing.
10. Changes
We may update this policy to reflect changes in our services, processing or legal obligations. The latest version is published here. Where required, we provide additional notice of material changes.

