Privacy Policies
Last revision:
09 de julho de 2025
This Enotel Hotels & Resorts Website Privacy Policy (the “Privacy Policy”) aims to explain to you what personal data we collect and what we do with it based on your interactions with us through our website (which includes the navigable pages, applications, and other resources found on it), because we know how important your privacy and the protection of your personal data are to you. This Privacy and Data Protection Policy applies to all collaborators and employees of Enotel Hotels & Resorts; to third parties, whether individuals or legal entities, acting on behalf of or under the guidance of the organization in activities involving the processing of personal data; to external processing agents (controllers or processors) who maintain any contractual or institutional relationship with Enotel; as well as to personal data subjects whose information is collected, processed, stored, or shared within the scope of the institution's activities, ensuring compliance with Law No. 13,709/2018 – General Personal Data Protection Law (LGPD) and the preservation of data subjects' rights.
Therefore, we ask you to carefully read the information contained in this document, which explains how we process and protect your personal data, as well as the ways in which you can exercise your rights in compliance with current legislation, particularly the LGPD. We are committed to processing your personal data, including sensitive data, responsibly, transparently, and securely, ensuring your privacy and the realization of your rights as a data subject. We emphasize that the terms used in this Policy follow the definitions set out in Article 5 of the LGPD. If you have any questions regarding the Privacy Policy, please contact our Data Protection Officer, the law firm Hissa & Galamba Advogados, contact Dr. Carmina Hissa via email at dpo@enotel.com.br.
It will be a pleasure to assist you!
Acceptance of this policy will occur when you use our website or our services, as this will indicate your awareness and agreement with how we will use your personal data.
Commitment to Privacy and Personal Data Protection
Within the scope of processing personal data, we reaffirm our commitment to protecting the privacy of data subjects by adopting continuous measures to ensure compliance with current legislation. In this regard, we highlight the following principles that guide our practices:
- Ensuring that all data processing occurs lawfully, supported by an appropriate legal basis, whether for legitimate interest, data subject consent, or another legal hypothesis.
- Restricting data processing to specific, previously informed purposes, ensuring its use is compatible with the purposes stated at the time of collection.
- Adopting mechanisms that promote the accuracy, updating, and completeness of the data provided by the subjects.
- Observing the principle of minimization, requesting only the data strictly necessary to fulfill the informed purposes.
- Defining and respecting retention periods compatible with the purposes of the processing, ensuring the appropriate limitation of the storage period.
- Implementing technical and administrative measures capable of ensuring the integrity, confidentiality, and security of the processed information.
What you will find in our Privacy Policy?
To facilitate your reading, this Privacy Policy is divided into the following sections:
- What personal information do we collect?
- What are the restricted activities and Guest Privacy?
- What do we use the collected personal information for?
- What are the purposes of using personal data?
- Who do we share personal data with?
- Will there be International Data Transfers?
- How long do we keep personal information?
- How is your data protected?
- What are the data subjects' rights?
- Who is our Data Protection Officer?
- Regarding the possibility of altering the Privacy Policy.
Before we proceed, it is important that you know some fundamental concepts to better understand this document:
- Personal Data:
All information that allows someone to identify you or contact you, including but not limited to your name, CPF, address, phone number, email address, an identification number, location data, an online identifier, among others.
- Sensitive Personal Data:
Personal data related to racial or ethnic origin, religious conviction, political opinion, union affiliation, or religious, philosophical, or political organization affiliation, data regarding health or sex life, genetic or biometric data, when linked to you.
- Processing of Personal Data:
Any operation performed with personal data, such as collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, archiving, storage, elimination, evaluation or control of information, modification, communication, transfer, diffusion, or extraction.
- Data Subject:
The natural person to whom the personal data or sensitive personal data undergoing processing refer. Here, the data subject is you!
- Processing Agents:
Those responsible for processing personal data as established in Law No. 13,709/2018: the Controller, who makes decisions regarding data processing; and the Processor, who performs the processing on behalf of the Controller.
- Data Protection Officer (DPO):
The person appointed by Enotel Hotels & Resorts to act as a communication channel between the hotel, data subjects, and the ANPD (National Data Protection Authority).
- National Data Protection Authority (ANPD): The body responsible for enforcing and monitoring compliance with Law No. 13,709/2018.
1. What personal information do we collect?
We may collect, directly or indirectly, the following categories of personal data, depending on your interaction with the site and services:
- General Data:
Full name, nationality, ID documents (CPF, RG, Passport), mother's name, birth date, age, gender, marital status, addresses, phone numbers, email, IP address, lodging preferences, health information for emergencies/accessibility, and biometric data.
- Financial Data:
Banking information used for billing and credit, such as agency and account numbers, credit card numbers, payment slips, and financial history (amounts paid/due, payment methods, debt agreements).
- Loyalty Program (Enotel Club) Data:
Member registration data, member number, status, point balances, redemption history, and reward preferences.
- Registration and Navigation Data:
Automatically collected via cookies, including IP addresses and information regarding your interaction with the website's content to improve your browsing experience. Further details are available in the Cookie Policy at
https://www.enotel.com/pt.
- Event Contents:
Video, image, or voice recordings and personal information of participants from in-person or online meetings, which may be published on the company's website or social media.
- Surveillance Images/Videos:
CCTV recordings collected to ensure the safety of guests, employees, and property.
- Drone Imagery:
Drones may be used in common areas for institutional, promotional, and security purposes, strictly observing legal norms (e.g., ANAC regulations and LGPD) and respecting privacy. Specific consent will be requested for identifiable images, except where legally justified.
- Partner/Candidate Data:
Information on corporate stakes, bank accounts, professions, and education for business partners, service providers, or job applicants.
- Automatically Collected Data:
Information related to the devices (desktop, mobile) used to access our site and Wi-Fi networks, gathered via cookies to improve service and user experience.
- Children and Adolescents:
The data of minors under 18 is processed for reservations and recreational activities, supervised by parents, prioritizing their best interests and requiring specific parental consent (LGPD art. 14). The hotel ensures the privacy, protection, and ethical use of this information. Our services are generally not directed at minors, except where legally permitted; non-compliant minor accounts will be blocked.
- Sensitive Data Processing: Handled with heightened attention under LGPD guidelines (including financial data), processed only with specific consent or when legally required (e.g., life protection, fraud prevention, health tutelage).
2. Restricted Activities and Guest Privacy
The privacy, comfort, and safety of our guests are of utmost importance. To ensure a peaceful environment, Enotel Hotels & Resorts establishes the following guidelines:
- Drone Use:
The use of drones is strictly prohibited in any area of the hotel facilities without prior and express authorization from the hotel administration for justified professional purposes.
- Other Activities:
Filming, photographing, or recording audio of other guests or restricted areas without explicit consent is prohibited. Activities causing disturbance to privacy or peace (e.g., loud music) are not permitted.
- Consequences: Non-compliance may result in requests to cease the activity, temporary equipment confiscation, and, in severe cases, removal from the hotel premises.
3. What do we use the collected personal information for?
As the Data Controller, we process your data for the following purposes:
- Providing Services:
Processing reservations, check-ins/outs, payments, special requests (conjugal rooms, diets), and providing emergency medical support.
- Communication:
Responding to your contacts, sending service updates, surveys, and personalized promotional offers.
- Loyalty Program:
Administering the Enotel Club, managing points, redemptions, exclusive promotions, and satisfaction surveys.
- Legal Compliance:
Fulfilling federal, state, municipal, and regulatory obligations.
- Legal Defense:
Exercising rights in judicial, administrative, or arbitral proceedings.
- Fraud Prevention & Credit Protection:
Verifying identities and consulting credit protection agencies for risk analysis.
- Consent: Data processed via consent can be revoked at any time by emailing dpo@enotel.com.br, understanding that this withdrawal may impact services and does not affect prior processing or public third-party posts.
Communications through any channel may be recorded for contact verification and auditing purposes.
4. How do we share personal information?
We may share your personal data minimally with third parties for the informed purposes:
- Technology service providers and online application suppliers.
- Enotel Club partners, airlines, credit card networks, transport companies, and booking platforms.
- Specialized clinics and laboratories.
- Medical emergencies and authorities (e.g., Fire Department, Police, sanitary authorities).
- Providers of website analysis, marketing, and online advertising.
- Financial institutions and payment providers.
- Other service providers (legal, accounting, auditing).
- Public authorities to comply with legal obligations or investigate fraud.
- Private third parties are contractually bound to use the data solely for specified obligations.
- Third-Party Sites: We are not responsible for the privacy practices of external links or social networks (e.g., WhatsApp). Always check their policies.
5. International Transfer
Data is stored on servers located in Brazil but may be transferred abroad for specific purposes, implementing adequate data protection measures aligned with the LGPD.
6. How long do we keep personal information?
We will retain your data for the period necessary to fulfill the described purposes, or as required by laws (e.g., Brazilian Civil Rights Framework for the Internet, tax obligations). Revoked consent requests will not imply the elimination of previously processed data if we are legally obligated or permitted to retain it. Enotel reserves the right to block or anonymize collected data.
7. How do we protect personal information?
We implement robust security controls, including physical and logical protection measures, encrypted communications, access management, and continuous privacy training. We contractually demand acceptable security levels from our partners and restrict data access to authorized, trained personnel under confidentiality obligations.
8. What are your data subject rights?
You can exercise the rights provided in the LGPD at any time by contacting dpo@enotel.com.br:
- Confirmation and Access:
Confirm data existence and request access.
- Correction:
Request correction of incomplete, inaccurate, or outdated data.
- Revocation of Consent:
Withdraw consent, understanding the potential direct or indirect impact on provided services.
- Deletion:
Request the elimination of data processed based on your consent.
- Portability:
Request data portability to another provider.
- Information on Sharing:
Be informed about how we share your data with public or private sectors.
- Opposition: Oppose processing if you believe it violates the LGPD.
You may also contact the ANPD or consumer defense agencies. We will evaluate your request after verifying your identity.
9. Data Protection Officer
If you wish to make suggestions, complaints, or exercise your rights, contact our DPO:
- Law Firm: Hissa & Galamba Advogados
- Contact:
Dra. Carmina Bezerra Hissa
- Email: dpo@enotel.com.br
10. Data Veracity
We will use your registered email for communication purposes, which is valid as documentary evidence. You commit to providing accurate data and are responsible for keeping it updated by emailing dpo@enotel.com.br.
11. Applicable Law
This document is governed by and must be interpreted according to Brazilian laws.
12. Privacy Policy Changes
This Policy may change over time to meet legal or business requirements. Please check it before visiting our site or contracting our services. The date of the last update is indicated herein.





