Last updated: 14 August 2026
Belloise Hospitality Limited, trading as Number Nine Hotel ("Number Nine", "we", "us", "our") respects your privacy and is committed to protecting your personal data. This policy explains how we collect, use, share and protect your information when you book or stay with us, visit our website, message us, or pass through our premises, and it describes the rights you have under the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. Because Number Nine is a fully automated, self check-in property, some of the processing described below (electronic door access and entrance cameras, for example) is central to how we let you into the building safely, so we have set it out in full.
1. Who we are
Belloise Hospitality Limited, trading as Number Nine Hotel, a company registered in Ireland under company number 818175, is the data controller for the personal data described in this policy. We have not appointed a statutory Data Protection Officer, as we are not required to, but we have a named point of contact for all privacy matters. You can reach us at:
- Email: [email protected]
- Post: Data Protection, Number Nine Hotel, 9 Merchants Quay, Waterford, X91 ENF7, Ireland
2. The personal data we collect
We collect the following categories of personal data:
- Identity and contact data: your name, date of birth, nationality, passport or identification document type and number, email address, phone number and postal address.
- Booking data: your dates of stay, the room booked, number of guests, guest roster, special requests and signed rental agreements.
- Payment data: the last four digits of the card used, the card brand and a secure payment token. We never store full card numbers or security codes; these are handled entirely by our payment processor.
- Identification documents: a scan or photograph of the primary guest's passport or ID, required under Irish accommodation legislation.
- Signature and verification data: an electronic signature image together with the date, time and IP address at which the rental agreement was accepted.
- Access data: the electronic door codes issued to you and the associated lock activity for the front door and your room during your stay, used to provide keyless entry.
- Image data: CCTV footage captured by cameras at the building's entrances and common areas, as described in section 6.
- Communications data: the emails, WhatsApp messages, phone calls, chat messages and other correspondence you exchange with us, including through the guest portal.
- Special category data: where you choose to share it, information about accessibility requirements, mobility needs, allergies or dietary requirements, so that we can accommodate you. This is covered in section 5.
- Technical data: your IP address, browser and device information, cookie identifiers and pages visited, as described in the Cookies section below.
3. Where we collect your data from
We collect personal data:
- Directly from you: when you make a booking, complete online check-in, sign a rental agreement, message us or otherwise interact with us.
- From booking channels: when you book through a third-party platform such as Airbnb or Booking.com, we receive your booking and contact details from that platform. Those platforms are separate controllers and their own privacy policies also apply to you.
- Automatically: through cookies and similar technologies on our website, through our building's entrance cameras, and through the electronic locks when door access is used.
4. How we use your data and our legal basis
We only process personal data where we have a lawful basis under GDPR Article 6:
- Performance of a contract (Art. 6(1)(b)): to take a reservation, complete check-in, issue your door access, manage your stay, take payment and respond to requests relating to your booking.
- Legal obligation (Art. 6(1)(c)): to collect and retain guest identification records under Irish accommodation law, and to keep financial records required by tax and accounting legislation.
- Legitimate interests (Art. 6(1)(f)): to secure our premises and website through CCTV and access controls, prevent and detect fraud, keep records of correspondence, understand and improve our services, and invite feedback after your stay. Where we rely on legitimate interests we balance them against your rights and freedoms, and you may object at any time.
- Consent (Art. 6(1)(a)): for optional activities such as marketing emails and non-essential cookies. You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
5. Special category data (accessibility, dietary and health information)
We do not seek out sensitive personal data. If you volunteer information about an accessibility or mobility requirement, an allergy or a dietary requirement so that we can make your stay comfortable, we treat this as special category data under GDPR Article 9. We process it only with your explicit consent, or where it is necessary to protect your vital interests, and we use it solely to accommodate the need you have told us about. You can ask us to delete it at any time.
6. CCTV and security cameras
Because Number Nine is unstaffed, we operate CCTV cameras to keep the building and our guests secure and to support safe, self check-in. Cameras cover the exterior entrance, the reception and entry areas, internal corridors and landings, and the laundry area. There are no cameras inside guest rooms or bathrooms. Some cameras include a video doorbell and two-way audio at the front entrance so we can assist arriving guests remotely.
We process this footage on the basis of our legitimate interests in the safety and security of guests, staff and property, and in enabling remote check-in. Footage is stored securely, retained for a limited period (ordinarily around 30 days) and then automatically overwritten, unless it is needed to investigate a specific incident. We may share relevant footage with An Garda Síochána or our insurers where there is a lawful basis to do so. You have the right to request access to footage in which you appear; please contact us using the details in section 1.
7. Electronic access and door codes
Entry to the building and to your room is by electronic lock. When you book, we issue you time-limited door codes and, where offered, the ability to open your door from your guidebook. The locks record when access codes are used. We process this access data to provide you with keyless entry (performance of our contract with you) and to keep the building secure (our legitimate interests). Access codes expire at the end of your stay, and associated access logs are kept only for a short period afterwards for security and dispute-resolution purposes.
8. Guest messaging and our use of AI
You can reach our team by email, WhatsApp and phone, and we use these channels to answer questions, share check-in details and offer local suggestions. Messages you send through WhatsApp are delivered using the WhatsApp Business Platform provided by Meta, which processes message content and your phone number in order to deliver the service.
We use artificial intelligence tools, including third-party large language models, to help our team draft and suggest replies to guest messages and to power features such as our trip planner. These tools act on our instructions under data processing terms. A member of our team remains responsible for guest communications, and we do not use AI to make decisions about you that are based solely on automated processing and that produce legal or similarly significant effects. See also section 15.
9. Marketing and guest reviews
If you opt in, we may send you occasional emails about Number Nine, offers and news. Every marketing email includes an unsubscribe link, and you can opt out at any time by using it or by emailing us. We do not need your consent to send you transactional messages about a booking you have made (for example confirmations, check-in details and receipts).
After your stay we may invite you to leave a review. Reviews you choose to publish, and any that you post on third-party platforms such as Airbnb, Booking.com or Google, may be displayed on our website and social media. We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.
10. Who we share your data with
We share personal data only with trusted providers who process it on our behalf under a written agreement, and only to the extent necessary to run our business. These include:
- Booking and website providers: our WordPress hosting and our booking and channel-management software (VikBooking and VikChannelManager).
- Booking channels: where you book or communicate through Airbnb, Booking.com or a similar platform, data is exchanged with that platform.
- Payment processor: card payments are processed securely by our payment provider (currently SumUp), which is a separate controller in respect of your payment data. We may use an alternative or additional regulated payment provider from time to time.
- Messaging providers: Meta Platforms Ireland, for WhatsApp messaging, and our telephony provider for calls.
- Email delivery provider: for transactional and, where you have opted in, marketing emails.
- Website performance and security providers: our content-delivery and security network (Cloudflare) and our website analytics provider, which help us keep the site fast, secure and reliable.
- Professional advisers: our accountants and tax advisers, where necessary to meet statutory obligations.
- Public authorities: where we are legally required to disclose information, for example to An Garda Síochána, the Revenue Commissioners, or the courts.
11. International transfers
Most of your data is processed within the European Economic Area (EEA). Some of our providers, such as those behind our messaging and website-performance tools, are based in or transfer data to countries outside the EEA, including the United States. Where this happens we rely on the safeguards recognised under GDPR, such as the European Commission's Standard Contractual Clauses, the EU-US Data Privacy Framework where the provider is certified, or an adequacy decision, so that your data continues to receive an equivalent level of protection. You can ask us for more detail about the safeguards that apply to a particular transfer.
12. How long we keep your data
We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting or reporting requirements:
- Booking and financial records: retained for the period required by Irish tax and accounting legislation, typically up to seven years after the end of the stay.
- Identification documents (passport or ID scans): securely deleted within 30 days of check-out, in line with our rental agreement.
- Signed rental agreements and signature verification data: retained for the duration of any potential limitation period for contractual claims, which is six years in Ireland.
- CCTV footage: retained for a limited period, ordinarily around 30 days, then automatically overwritten unless needed for a specific incident.
- Door access logs: retained for a short period after your stay for security and dispute resolution.
- Marketing preferences: retained until you withdraw consent or request erasure.
- Website analytics and cookie data: retained for no longer than 13 months.
When personal data is no longer needed we either delete it or anonymise it.
13. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you and request a copy.
- Rectify inaccurate or incomplete data.
- Erase your data (the "right to be forgotten") where there is no overriding legal basis for us to keep it.
- Restrict or object to processing in certain circumstances, including any processing we base on our legitimate interests.
- Data portability: receive the data you provided in a structured, commonly used, machine-readable format.
- Withdraw consent at any time, where processing is based on consent.
To exercise any of these rights please contact us at [email protected]. We will respond within one month, and this service is free of charge. We may ask you to verify your identity before we act on a request.
14. Is providing personal data a requirement?
Providing your identity, contact and payment information is a contractual requirement, and, in the case of identification documents, a legal requirement, in order to complete a booking and lawfully accommodate you. If you do not provide this information we will not be able to confirm your reservation or check you in. Sharing accessibility or dietary information is entirely optional.
15. Automated decision-making and profiling
We do not make decisions about you that are based solely on automated processing, including profiling, and that produce legal effects concerning you or similarly significantly affect you. As explained in section 8, we use AI tools to assist our team, but a person remains responsible for decisions that affect you.
16. Security
We use technical and organisational measures appropriate to the risk, including encrypted connections (HTTPS), access controls, pseudonymisation of payment data, secure storage of CCTV footage, and regular backups. No system can be guaranteed to be completely secure; if a personal data breach occurs we will notify the Data Protection Commission and, where required, affected individuals within the timeframes set by GDPR.
17. Cookies
Our website uses cookies and similar technologies. Some are strictly necessary for the site to function (for example session cookies and the cookie that holds a booking in progress); these do not require consent. Any non-essential cookies (functional, analytics or marketing) are set only after you give consent through our cookie banner, and you can change or withdraw your consent at any time using the Cookie settings link in the footer. For full details of the cookies we use and how to manage them, please see our Cookie Policy.
18. Children
Our services are not directed at children under 16, and children under that age should not use our website to provide personal data without the consent of a parent or guardian. Children may of course stay with us as part of a family booking made by an adult. If you believe a child has provided us with personal data without appropriate consent, please contact us and we will delete it.
19. Third-party links
Our website and messages may contain links to third-party websites, such as local attractions, maps or booking platforms. This policy does not cover those sites, and we are not responsible for their privacy practices. We encourage you to read the privacy policy of any website you visit.
20. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent change. Where changes are material we will notify you by email or through a prominent notice on the website before the changes take effect.
21. Contact us and how to complain
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at [email protected]. We take every concern seriously and will always try to resolve it with you directly first.
You also have the right to lodge a complaint with the Irish supervisory authority:
- Data Protection Commission
- 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
- Website: www.dataprotection.ie