The Gwbert Hotel and Flat Rock Restaurant & Bar

Flatrock Group Privacy Notice

Last Updated: August 2026

1. About This Privacy Notice

Flatrock Group respects your privacy and is committed to protecting your personal data.

This Privacy Notice explains how we collect, use and protect your personal information when you interact with us, including when you:
• stay at one of our hotels or holiday properties;
• visit our restaurants, bars or spa facilities;
• make a booking or enquiry;
• purchase products, services or gift vouchers;
• attend an event, wedding or function;
• use our websites;
• apply for employment; or
• contact us.

Flatrock Group operates:
• The Cliff Hotel & Spa
• The Gwbert Hotel & Flatrock Bar & Restaurant
• The Harbourmaster
• The Black Lion Hotel
• The Grosvenor
• The Angel Hotel
• Gwbert Holidays

We process your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and other applicable data protection laws.

2. Who We Are

Flatrock Group is the data controller responsible for your personal data.

Correspondence Address:
Flatrock Group
The Cliff Hotel & Spa
Gwbert
Cardigan
SA43 1PP

If you have questions about this Privacy Notice or wish to exercise your data protection rights, please contact us:

Email: customerservices@flatrockgroup.co.uk

3. Information We Collect

The information we collect depends on how you interact with us.

Information You Provide

This may include:
• your name and contact details;
• booking and reservation information;
• arrival and departure dates;
• payment and transaction details;
• gift voucher purchases;
• preferences and special requests;
• dietary requirements and allergies;
• accessibility requirements;
• feedback and survey responses;
• marketing preferences;
• information provided when applying for employment.

Information Collected Automatically

When you use our websites or digital services, we may collect technical information such as:
• IP address;
• browser type;
• device information;
• operating system;
• pages visited;
• website usage information;
• cookie information where applicable.

Information From Third Parties

We may receive information from trusted third parties, including:
• booking platforms;
• travel agents;
• payment providers;
• reservation systems;
• recruitment agencies;
• event organisers;
• corporate customers arranging bookings on your behalf.

4. How We Use Your Information

We use your personal data to:
• manage bookings and enquiries;
• provide accommodation, dining, spa and holiday services;
• process payments and refunds;
• communicate with you about your bookings;
• provide customer support;
• manage events and functions;
• improve our services;
• administer gift vouchers and loyalty schemes;
• send marketing communications where permitted;
• maintain website security and functionality;
• protect guests, visitors, employees and property;
• comply with legal obligations;
• manage recruitment and employment.

5. Our Legal Reasons for Using Your Information

Under UK GDPR, we must have a lawful basis for processing your personal data.

Depending on the circumstances, we rely on:

Contract

Where we need your information to provide services you have requested, such as accommodation, restaurant bookings or spa treatments.

Legal obligation

Where we must process information to comply with laws, regulations or official requirements.

Legitimate interests

Where processing is necessary for our business interests, such as improving services, maintaining security, preventing fraud and managing our operations. We ensure these interests do not override your rights.

Consent

Where you have given permission for a specific use of your information, such as receiving marketing communications. You can withdraw consent at any time.

Vital interests

Where processing is necessary to protect someone’s life or safety in an emergency.

6. Special Category Personal Data

Some information requires additional protection under UK GDPR.

This may include:
• health information;
• disability information;
• dietary information where it reveals health or religious information;
• information about accessibility requirements;
• certain employment-related information.

We only process this type of information where permitted by law and where appropriate safeguards are in place.

Examples include:
• providing services safely;
• accommodating accessibility requirements;
• managing allergies or medical considerations;
• meeting employment or health and safety obligations.

We do not use special category personal data for marketing purposes.

7. Marketing Communications

We may send you information about:
• accommodation offers;
• restaurants and dining experiences;
• spa treatments;
• events;
• gift vouchers;
• seasonal promotions;
• news and updates.

We only send marketing communications where permitted by law.

You can stop receiving marketing communications at any time by:
• clicking the unsubscribe link in our emails; or
• contacting us directly.

Choosing not to receive marketing will not affect your ability to use our services.

8. Cookies and Website Tracking

Our websites use cookies and similar technologies.

Cookies help us:
• operate our websites;
• keep them secure;
• remember preferences;
• understand how visitors use our websites;
• improve our services.

We only use non-essential cookies, such as analytics or marketing cookies, where you have provided consent.

You can manage your cookie preferences through our cookie settings or your browser controls.

Further information is available in our Cookie Policy.

9. Sharing Your Information

We do not sell, rent or trade your personal information.

We may share information with trusted organisations where necessary, including:
• booking and reservation providers;
• payment processors;
• IT and website providers;
• email marketing providers;
• professional advisers;
• payroll and HR providers;
• law enforcement or regulators where legally required.

Where third parties process information on our behalf, we require them to protect your data appropriately.

10. International Transfers

Some suppliers may process information outside the UK.

Where this happens, we ensure appropriate safeguards are in place so that your personal data receives protection equivalent to UK data protection standards.

11. How Long We Keep Your Information

We keep personal data only for as long as necessary.

Retention periods depend on the type of information and why we use it.

Examples include:
• booking and customer records: generally 6 years;
• financial records: generally 6 years;
• CCTV footage: generally 30 days;
• unsuccessful recruitment records: generally 6 months.

Some information may be retained longer where required by law or where needed for legal claims.

12. Keeping Your Information Secure

We use appropriate technical and organisational measures to protect your personal data.

These include:
• restricting access to authorised people;
• staff confidentiality requirements;
• security training;
• secure systems and backups;
• appropriate supplier checks;
• secure payment processing arrangements.

Although we take reasonable steps to protect your information, no online system can be guaranteed to be completely secure.

13. CCTV

We operate CCTV at certain locations to help protect:
• guests;
• visitors;
• employees;
• property and facilities.

CCTV may be used for:
• security;
• crime prevention;
• investigating incidents;
• health and safety purposes.

CCTV footage is normally retained for 30 days unless it is required for an ongoing matter.

CCTV is not used for marketing purposes.

14. Your Data Protection Rights

Under UK GDPR, you may have the right to:
• access your personal data;
• correct inaccurate information;
• request deletion of your information;
• restrict how we use your information;
• object to certain processing;
• request transfer of your information where applicable;
• withdraw consent where processing is based on consent.

To exercise your rights, contact:

Email: customerservices@flatrockgroup.co.uk

Post:
Data Protection Enquiries
Flatrock Group
The Cliff Hotel & Spa
Gwbert
Cardigan
SA43 1PP

We may ask you to verify your identity before responding.

15. Complaints

If you have concerns about how we use your personal data, please contact us first so that we can investigate.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK regulator for data protection.

Further information is available from the ICO website.

16. Changes to This Privacy Notice

We may update this Privacy Notice from time to time to reflect changes to our services, technology, legal requirements or privacy practices.

Any updated version will be published on our websites with a revised update date.

Contact Us

Flatrock Group
The Cliff Hotel & Spa
Gwbert
Cardigan
SA43 1PP

Email: customerservices@flatrockgroup.co.uk