Version 1.0
Andrew Brownsword Hotels (‘ABH’) (referred to as “we”, “our” or “us”) is committed to protecting your personal data in accordance with applicable UK data protection law; The UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003 (‘PECR’) and the Data (Use and Access) Act 2025. This also includes (and is not limited to) other applicable laws such as the EU GDPR and e-Privacy Directive.
This privacy notice explains how we collect, use, secure and share your personal data, and what rights you have under data protection law.
This privacy notice also applies to other hotels that form part of our group:
Each hotel group member is a data controller. For certain activities such as reservations and bookings, each acts as a joint-data controller with ABH head office based in Bath.
We are registered with the Information Commissioner’s Office (ICO) under registration numbers:
Head Office:
4 Queens Square
Bath, Somerset
BA1 2HA
United Kingdom
Email: info@brownswordhotels.co.uk
Tel: +44 (0)1225 320470
Contact details for each hotel can be found on their respective websites.
Data Protection Officer (DPO):
Name: RA Data Protection Ltd
Email: ravi@radataprotection.com
Website: https://radataprotection.com
We process personal data under the following lawful bases:
Where we process special category data (e.g. health information for dietary purposes), we ensure a relevant lawful condition is identified.
We may process data from the following individuals:
We do not sell or rent personal data. However, we may share data with:
We also share data with authorities where required by law or to protect our legal rights.
Bookings can be made directly or via third parties (e.g. Booking.com). We only share limited information necessary to confirm bookings.
We do not market to children. We only collect the number and ages of children to ensure suitable accommodation and pricing.
For some activities (e.g. bookings, HR, finance), we act as joint controllers within the ABH group, ensuring lawful and secure data sharing.
Our hotels use CCTV for crime prevention, safety, and legal defence. Signs are displayed in relevant areas.
Calls may be recorded for training and monitoring and are deleted after the retention period.
Recruitment data is processed in accordance with our Recruitment Privacy Notice.
We only send marketing communications with consent. We use social media (e.g. Facebook, LinkedIn, X) to share news and promotions.
If data is transferred outside the UK, we ensure lawful transfer mechanisms are used (e.g. adequacy decisions, standard contractual clauses).
Please refer to our Cookie Notice for details on cookies used and consent management.
We are not responsible for external websites or their privacy practices. Please refer to their privacy notices.
We retain personal data only as long as necessary to meet legal, regulatory, and operational obligations, after which data is securely deleted or anonymised.
We implement appropriate security measures and limit access to authorised personnel only. Any incidents are investigated and, where required, reported.
We use accredited third-party providers to process payments securely. For more information, contact us.
You can exercise these rights by contacting us. ID verification may be required.
If you have concerns, please contact us. You can also complain to the ICO at https://ico.org.uk/make-a-complaint/.
We review and update this notice periodically. Please check back regularly for the latest version.