HOTEL ALISEI

Privacy Policies

How we collect, protect and process your personal data.

Ready to Experience Paradise?

Book directly through our official engine to secure the best rates, exclusive perks, and flexible cancellation policies.

Book Online Now

Data Controller & General Commitment

Hotel Alisei, operated by Enjoyce, S.R.L., located at Calle Francisco Alberto Caamaño Deñó, Las Terrenas, Samaná, Dominican Republic, is committed to safeguarding the privacy and personal data of our guests, website visitors, and service users. This Privacy Policy governs our data processing practices across our websites (aliseihotelspa.com, m.aliseihotelspa.com), our direct reservation engine, pre-arrival online check-in portal, and on-property guest services at our hotel, spa, and El Loro Restaurant.

Dominican Republic Legal Framework (Law 172-13 & Law 310-14)

In accordance with Organic Law No. 172-13 for the Protection of Personal Data in the Dominican Republic, Hotel Alisei guarantees the integral protection of personal data stored in our archives, registries, and digital processing systems. We uphold the constitutional right to personal honor, privacy, and intimacy guaranteed under Article 44 of the Constitution of the Dominican Republic.

Under Law No. 310-14 regulating unsolicited commercial electronic messages (Anti-SPAM), we strictly prohibit unsolicited emails. Commercial newsletters or promotional notices are sent exclusively to users who have provided prior affirmative consent (opt-in), which may be revoked at any time.

European Union GDPR Compliance (Regulation EU 2016/679)

For visitors, guests, and customers located in the European Union (EU) or European Economic Area (EEA), we process personal data in strict compliance with the General Data Protection Regulation (GDPR).

Legal Bases for Processing (Article 6 GDPR)

  • Performance of Contract (Art. 6(1)(b)): Processing room bookings, managing room allocations, executing online check-in, providing spa therapies, and fulfilling dining requests.
  • Legal Obligation (Art. 6(1)(c)): Mandatory guest registration and identity reporting under Dominican tourism and security laws, as well as tax and accounting record-keeping.
  • Legitimate Interests (Art. 6(1)(f)): Maintaining network and digital security, preventing fraud, optimizing website functionality, and evaluating service satisfaction.
  • Explicit Consent (Art. 6(1)(a)): Delivering email marketing communications, newsletters, and activating non-essential statistical or advertising tracking technologies.

Your Rights as an EU Data Subject

Under Chapter III of the GDPR, EU residents benefit from enforceable rights regarding their personal data:

  • Right of Access (Art. 15): Obtain confirmation of whether your data is processed and receive a copy of your records.
  • Right to Rectification (Art. 16): Request correction of inaccurate, incomplete, or outdated personal information.
  • Right to Erasure / "Right to be Forgotten" (Art. 17): Request deletion of your personal data when no longer required for statutory or contractual purposes.
  • Right to Restriction of Processing (Art. 18): Limit the scope of data processing during verification or dispute resolution.
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21): Object to processing based on legitimate interests or direct marketing at any time.
  • Right to Withdraw Consent (Art. 7(3)): Withdraw consent previously granted without affecting the legality of prior processing.
  • Right to Lodge a Complaint: Lodge a complaint with a supervisory authority in your EU Member State if you believe your rights have been violated.

US State Privacy Rights (California CCPA/CPRA, VCDPA, CPA, CTDPA)

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CPRA), and related comprehensive state privacy laws (including Virginia VCDPA, Colorado CPA, and Connecticut CTDPA), we provide the following disclosures to United States residents:

Notice at Collection: Categories of Personal Information

  • Identifiers: Name, physical mailing address, email address, telephone number, passport/ID number (collected securely for mandatory guest check-in), and unique online identifiers (IP address, client IDs).
  • Commercial Information: Reservation history, room category booked, spa services reserved, dining preferences, and payment authorization tokens.
  • Internet & Network Activity: Device information, operating system, browser type, interaction with booking flows, time spent on pages, and referring URLs.
  • Geolocation Data: Imprecise geographic location derived from IP address for localized language and currency display.

"Do Not Sell or Share My Personal Information"

Hotel Alisei does NOT sell personal information for monetary consideration. We do not disclose your name, contact information, or sensitive records to third-party data brokers.

To the extent that third-party analytics and digital advertising cookies qualify as "sharing" or "targeted advertising" under California or multi-state privacy legislation, consumers retain the absolute right to opt out at any time through our on-site Cookie Choices & Do Not Sell control panel.

Global Privacy Control (GPC) & Restricted Data Processing (RDP)

Our website implements automated detection of Global Privacy Control (GPC) signals emitted by modern browsers (navigator.globalPrivacyControl === true). When a GPC signal is recognized:

  • Targeted advertising, personalized tracking, and data sharing are immediately disabled.
  • Google Tag (GA4) is automatically instructed to operate under Restricted Data Processing (RDP) mode (gtag('set', 'restricted_data_processing', true)), acting strictly as a confidential service provider.
  • Google Consent Mode v2 denies advertising and user profiling storage by default.

Cookie Policy & Tracking Technologies

We deploy cookies, local storage, and similar technologies to ensure seamless navigation, preserve booking sessions, and analyze aggregate usage.

  • Strictly Necessary Cookies: Essential for website routing, session security, language preferences, and interaction with our booking engine. These cookies cannot be switched off.
  • Analytics & Measurement Cookies: Powered by Google Tag / Google Analytics 4 (G-4J5EGP8E60), these measure aggregated website traffic and booking intent conversions. They operate only upon user consent or under Restricted Data Processing.
  • Marketing & Social Pixels: Enable relevant communication for visitors who have opted in. Always disabled by default until explicit consent is given.

You can modify or withdraw your cookie consent at any time by clicking the "Cookie Choices & Do Not Sell" link located in our website footer.

Online Check-in & Guest Pre-Arrival Data

When utilizing our online check-in service (checking-online.html), guests voluntarily submit pre-arrival data (including full names, passport/national ID numbers, nationality, arrival times, and vehicle plates). This data is strictly utilized to expedite check-in, assign accommodations, and satisfy official Dominican civil registry standards. Physical identification documents must still be presented upon arrival at reception.

Payment Processing Security & PCI-DSS

Hotel Alisei adheres strictly to DevSecOps and digital security standards. We never store full credit card numbers, expiration dates, or CVV/CVC security codes on our local web servers or databases. All online reservation transactions are encrypted using Transport Layer Security (TLS 1.3) and redirected to certified PCI-DSS compliant payment processors (e-GDS / Cardnet).

Digital Security & Data Protection (DevSecOps)

We implement comprehensive technical and organizational safeguards, including HTTP Content Security Policy (CSP), HSTS encryption, strict database access controls, server-level firewalls, and regular vulnerability audits to prevent unauthorized access, tampering, or disclosure of your personal data.

Exercising Your Privacy Rights & Contact

To exercise your rights of access, rectification, erasure, portability, objection, or opt-out under Dominican Law 172-13, the GDPR, or US state privacy statutes, please email our Data Protection team at:

[email protected]

Please specify "DATA PROTECTION / PRIVACY REQUEST" in the subject line and include reasonable proof of identity. Requests are verified and processed free of charge within statutory timelines (typically within 30 days).

Last Revised: September 2026

Hotel Alisei Administration & Data Compliance