Privacy Statement Boutique Hotel The Roosevelt
Last updated: September 17, 2026
Boutique Hotel The Roosevelt attaches great importance to the protection of your personal data and your privacy. In this privacy statement, we explain which personal data we collect, for what purposes we use it, with whom we may share data, how long we retain it and what rights you have under the General Data Protection Regulation (GDPR).
1. Who is responsible for your personal data?
The controller responsible for processing your personal data is:
Boutique Hotel The Roosevelt
Nieuwe Burg 42
4331 AH Middelburg
The Netherlands
Chamber of Commerce no.: 61222283
E-mail: info@hoteltheroosevelt.com
Phone: +31 118 436360
Hereafter referred to as "Hotel The Roosevelt", "the hotel", "we" or "us".
2. What personal data do we process?
Which personal data we process depends on how you use our services.
We may process the following data, among others:
- first and last name;
- address, postal code and city;
- email address;
- telephone number;
- date of birth and nationality, insofar as necessary;
- booking details;
- check-in and check-out dates;
- information about fellow guests, insofar as necessary for the reservation;
- room and stay information;
- invoice and payment details;
- correspondence with the hotel;
- preferences you communicate to us regarding your stay;
- information about special requests;
- data necessary to comply with legal registration obligations;
- camera footage inside and around the hotel;
- IP address, browser data and other technical information when using our website;
- cookie data, depending on your cookie preferences;
- other personal data you provide to us directly.
We always try to limit the processing of personal data to what is necessary for the purpose in question.
3. Special personal data
We generally do not ask you for special personal data, such as medical information.
It may happen that you provide such information yourself, for example when you make a specific request regarding your stay due to an allergy, limitation or other circumstance.
We use such information solely insofar as this is necessary and legally permitted and handle this information with extra care.
4. For what purposes do we use your personal data?
We may process your personal data for, among others, the following purposes:
- processing and confirming reservations;
- preparing and executing your stay;
- checking guests in and out;
- providing hotel, catering and other services;
- processing changes or cancellations;
- processing payments and invoices;
- answering questions and requests;
- handling complaints;
- maintaining contact before, during and after a stay;
- improving our services and guest experience;
- managing and securing our website and IT systems;
- securing guests, staff and property;
- preventing and investigating fraud, theft or other misuse;
- carrying out our administration;
- complying with tax, administrative and other legal obligations;
- sending newsletters and commercial communications where legally permitted;
- analyzing and improving our website, depending on your cookie preferences.
5. On what legal bases do we process personal data?
We only process personal data when there is a valid legal basis under the GDPR.
Depending on the situation, we process personal data on the basis of:
Contract performance
When you book a room or use another service from us, we need certain personal data to perform the contract.
Legal obligation
We must process and retain certain data to comply with, for example, tax, administrative or other legal obligations.
Legitimate interest
In some cases, we process personal data because it is necessary for a legitimate interest of the hotel or a third party.
This may relate to, for example:
- security of the hotel;
- fraud prevention;
- protection of property;
- improvement of our services;
- business administration.
We always balance our interest against your privacy interests.
Toestemming
For certain processing, we request your consent in advance, for example for certain marketing or tracking cookies.
If the processing is based on consent, you can withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing before the moment you withdraw your consent.
6. Bookings through other parties
You can book a stay at Hotel The Roosevelt directly with us, but also possibly through an external booking website, travel organization, tour operator or other intermediary.
When you book through such a party, we receive the data necessary to process your reservation and carry out your stay.
These external parties are themselves responsible for how they collect and process personal data. For more information, you can consult their own privacy statement.
7. Who do we share personal data with?
We do not sell your personal data.
We may share personal data with external parties when this is necessary for our services or business operations.
These may include, for example:
- suppliers of hotel and reservation software;
- providers of online reservation systems;
- payment service providers;
- financial and administrative service providers;
- accountants and advisors;
- IT, software and hosting providers;
- website managers;
- marketing and communication service providers;
- security companies;
- booking platforms and travel organizations;
- insurers, where necessary;
- competent government authorities when we are legally required to provide data.
When a third party processes personal data on our behalf, we make agreements on privacy, security and confidentiality where necessary.
8. Processing outside the European Economic Area
Some suppliers of software, IT, communication or marketing services may process personal data outside the European Economic Area (EEA).
When personal data is transferred to a country outside the EEA, we ensure that a valid legal basis exists for this and that appropriate safeguards are applied in accordance with the GDPR.
This can take place, for example, on the basis of an adequacy decision by the European Commission or by using approved standard contractual clauses.
9. How long do we retain your personal data?
We do not retain personal data longer than necessary for the purpose for which it was collected.
Some data must be retained by us under applicable laws and regulations for a certain period, for example data that form part of our financial administration.
For other data, we determine the retention period based on:
- the purpose of processing;
- the nature of the data;
- legal retention obligations;
- possible claims or disputes;
- our legitimate business interests.
When personal data is no longer necessary, it is deleted or anonymized.
10. Camera surveillance
Security cameras may be present in and around Hotel The Roosevelt.
Camera surveillance aims, among other things, to:
- the safety of guests and staff;
- protection of property;
- prevent and investigate incidents;
- prevent and investigate theft, fraud and vandalism.
Camera footage is only reviewed when there is a reason to do so and is only accessible to authorized persons.
We do not retain camera footage longer than necessary, unless an incident requires certain footage to be retained longer or when we are legally required to do so.
11. Website and cookies
Our website uses cookies and similar techniques.
Cookies can be used, among other things, to:
- ensure the website functions properly;
- remember preferences;
- analyze website usage;
- improve the website and our services;
- conduct marketing activities, insofar as permission is required and obtained.
For non-essential cookies, we request your prior consent where legally required.
More information is available in our Cookie Policy.
12. Direct marketing and newsletters
When you have subscribed to our newsletter or when we send you commercial communications in another legally permitted way, we may use your contact details to inform you about offers, packages, news and services from Hotel The Roosevelt.
You can unsubscribe at any time via the unsubscribe option in the relevant message or by contacting us at info@hoteltheroosevelt.com.
13. Security of personal data
We take appropriate technical and organizational security measures to protect personal data against:
- loss;
- theft;
- unauthorized access;
- unauthorized modification;
- unauthorized disclosure;
- misuse.
Access to personal data is limited as much as possible to employees and service providers who need this data for their work.
14. Your privacy rights
Under the GDPR, you have, depending on the circumstances, various rights with respect to your personal data.
You can, among other things, request:
- access to the personal data we process about you;
- correction of incorrect or incomplete personal data;
- deletion of personal data;
- restriction of processing;
- transfer of certain personal data to yourself or another organization;
- objection to processing based on a legitimate interest;
- objection to direct marketing;
- withdrawal of previously given consent.
You can submit a request to:
We may ask you to provide additional information when necessary to verify your identity and prevent personal data from being disclosed to the wrong person.
We will process your request in accordance with the timelines and conditions of the GDPR.
15. Automated decision-making
Hotel The Roosevelt does not, in principle, make decisions that are based solely on automated processing and have significant legal or similar consequences for you.
Should this change in the future, we will inform you in accordance with applicable privacy legislation.
16. Privacy of minors
Our website and services are not specifically aimed at minors.
Personal data of minors may be processed when necessary in connection with a reservation or stay, for example when a family with children stays at the hotel.
We process such data only when necessary and legally permitted.
17. Links to other websites
Our website may contain links to websites of external parties.
Hotel The Roosevelt is not responsible for how these external websites process personal data. We advise you to read the privacy statement of the relevant party before providing personal data.
18. Filing a complaint
Do you have a question or complaint about how we handle your personal data? Please contact us first at:
We will try to address your question or complaint as carefully as possible.
You also have the right to lodge a complaint with the Dutch supervisory authority:
Data Protection Authority
For more information, visit the Data Protection Authority website.
19. Changes to this privacy statement
We may modify this privacy statement when our service delivery, business operations, systems used, or applicable laws and regulations change.
The most current version is published on our website.
We advise you to consult this privacy statement from time to time.
20. Contact
Do you have questions about this privacy statement or about the processing of your personal data? Please contact us:
Boutique Hotel The Roosevelt
Nieuwe Burg 42
4331 AH Middelburg
The Netherlands
E-mail: info@hoteltheroosevelt.com
Phone: +31 118 436360
Chamber of Commerce no.: 61222283
