← Back to home

Data protection

GDPR & data-protection information

Concierge Comptoir, LLC · Informative overview · Not a certification of compliance · Effective date: · Last updated:

This page summarises GDPR-oriented rights and points to official EU materials. It does not claim that Concierge Comptoir, LLC is GDPR certified or fully compliant. Product-specific practices are described in the Privacy Notice.

1. Purpose of this page

Concierge Comptoir, LLC (a United States limited liability company formed in New Jersey; info@conciergecomptoir.com; 650 E. Palisades Ave, Englewood Cliffs, NJ 07632, USA) processes different kinds of personal data depending on whether you browse the marketing site, use a hotel guest link, sign in to the protected demo, or operate a hotel/admin account.

In particular, hotel guest processing involves limited stay-specific personal data that Concierge Comptoir receives to provide the service—not the hotel’s complete PMS record, and not anonymous data. Details are set out in the Privacy Notice.

2. When the GDPR may apply

The EU General Data Protection Regulation (Regulation (EU) 2016/679) protects natural persons regarding processing of personal data and the free movement of such data. It applies in the EU/EEA and can also apply to organisations outside the EU when offering goods or services to people in the EU or monitoring their behaviour, subject to the Regulation’s territorial scope.

Concierge Comptoir, LLC is established in the United States. Whether and how the GDPR (or UK GDPR / other local laws) applies to a particular processing activity depends on facts such as targeting and the roles of Concierge Comptoir versus each hotel. This page is informative and does not decide territorial scope or replace legal review for a specific activity.

3. Rights individuals may have

Where the GDPR applies, individuals typically have rights including (summarised; see the official text for exact conditions and exceptions):

  • Right to be informed — clear information about how personal data is used (Articles 13–14).
  • Right of access — confirmation of processing and a copy of personal data (Article 15).
  • Right to rectification — correction of inaccurate data (Article 16).
  • Right to erasure — “right to be forgotten” in defined cases (Article 17).
  • Right to restriction of processing (Article 18).
  • Right to data portability where applicable (Article 20).
  • Right to object to certain processing, including direct marketing where relevant (Article 21).
  • Rights related to automated decision-making including profiling, where Article 22 applies.
  • Right to withdraw consent where processing is based on consent, without affecting prior lawful processing.
  • Right to lodge a complaint with a supervisory authority.

The European Commission summarises that organisations must provide information such as identity of the controller, purposes, lawful basis, recipients, retention, and rights, in concise and plain language.

4. How to exercise rights with Concierge Comptoir

  1. Email info@conciergecomptoir.com and describe your request.
  2. State your relationship to the service (marketing enquiry, hotel guest, demo user, hotel staff, etc.) and the right you wish to exercise.
  3. We may ask for information reasonably needed to verify identity and locate records. Account requests should come from the verified account email. Do not send passwords or authentication codes by email.
  4. Hotel guests: contact the hotel about reservation and stay-related information. The hotel will handle the request and coordinate with Concierge Comptoir if records held in our service are involved.

Postal correspondence may be sent to Concierge Comptoir, LLC, 650 E. Palisades Ave, Englewood Cliffs, NJ 07632, USA.

Response timelines under the GDPR are generally one month, with limited extensions for complex requests. Hotel guest requests should be directed to the hotel; account holders may contact Concierge Comptoir at the address above.

5. Guest service and data

Concierge Comptoir provides cosmetic skincare recommendations using the guest’s selected skin preferences and hotel-location weather. The hotel retains its full reservation and PMS records and fulfills any products the guest selects. Concierge Comptoir sends the hotel only the selected products and stay context needed to match the request, and only after the guest explicitly chooses products for fulfillment. The selected products and stay context are emailed to the hotel's stored spa notification address(es); a separate hotel-staff report is also available. The system does not send hotel webhooks. Guest data processed for this service is limited and stay-specific; it is not anonymous.

Where the GDPR applies and the characterisation fits, Concierge Comptoir intends to rely on Article 6(1)(b) for guest-requested recommendations. Article 6(1)(b) alone is insufficient if an answer is classified as health data under Article 9. The questionnaire may collect an optional adult age band (not date of birth or exact age) and includes an option labeled “Redness / Rosacea.” Answers are used only for cosmetic recommendations, not diagnosis or medical care; Concierge Comptoir does not claim that this option is automatically outside Article 9. For questionnaire wording, providers, retention, and how to make a request, see the Privacy Notice.

6. Official sources

Prefer primary EU and government materials over secondary blogs:

Related pages: Privacy Notice · Legal Notice · Home