Book Now 📞 +44 (0)20 7723 5157
Privacy Policy – Tudor Court Hotel Paddington

Privacy Policy

Tudor Court Hotel Paddington

A Trading Name of CDKG Limited — Company Registration No. 07941515 | Registered in England & Wales | VAT No. 510 4563 83

Effective Date: 1 January 2025  •  Version 2.0


Our Commitment to Your Privacy

At Tudor Court Hotel Paddington, we believe that the privacy of our Guests, website visitors and business contacts is a matter of the utmost importance. We are committed to handling all personal information entrusted to us with the greatest care, transparency and respect.

This Privacy Policy explains who we are, what personal data we collect about You, why we collect it, how we use it, with whom we share it, and what rights You have in relation to it. We encourage You to read this Policy carefully. If You have any questions, our team is always pleased to assist.



1. Data Controller

The data controller responsible for the personal data described in this Privacy Policy is:

Legal NameCDKG Limited
Trading AsTudor Court Hotel Paddington
Company No.07941515
RegisteredEngland and Wales
Registered Address10–12 Norfolk Square, London, W2 1RS, United Kingdom
VAT No.510 4563 83

References to “the Hotel,” “We,” “Us” and “Our” throughout this Policy are to CDKG Limited trading as Tudor Court Hotel Paddington in its capacity as data controller. References to “You” and “Your” are to any individual whose personal data we process, including Guests, prospective Guests, website visitors and enquirers.

Back to Top ↑

2. Legal Framework

We process all personal data in compliance with the following legislation and associated statutory instruments, as applicable:

  • the UK General Data Protection Regulation (“UK GDPR”), as retained in English law by virtue of section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019;
  • the Data Protection Act 2018 (“DPA 2018”);
  • the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), as amended;
  • the Network and Information Systems (NIS) Regulations 2018, where applicable to our IT infrastructure;
  • all other applicable UK legislation governing data protection, privacy, electronic communications and cybersecurity from time to time in force.

Where we rely on your consent as a lawful basis, you may withdraw that consent at any time without detriment to your existing rights. Withdrawal of consent will not affect the lawfulness of any processing carried out prior to withdrawal.

Back to Top ↑

3. How to Contact Us

For all data protection enquiries, requests to exercise your rights, or to raise a concern about how we handle your personal data, please contact us through any of the following channels:

Reception (in person)Tudor Court Hotel Paddington, 10–12 Norfolk Square, London, W2 1RS
WebsiteVia the contact form at www.tudorcourthotel.co.uk
Emailreservations@tudorcourthotel.co.uk

We aim to respond to all valid data protection requests within one calendar month of receipt, in accordance with Article 12 UK GDPR. Where a request is complex or we receive a high volume of requests, we may extend this period by a further two months, in which case we will notify You of the extension and the reasons for it within one month of receiving the initial request.

Back to Top ↑

4. Personal Data We Collect

We collect and process different categories of personal data depending on your relationship with us. The following sets out the categories of personal data we may hold about You:

4.1   Identification and Contact Data

Data You provide directly when making an enquiry, placing a reservation or checking in to the Hotel, including:

  • full name and title;
  • postal address, email address and telephone number;
  • nationality and passport or national identity card details (as required by the Immigration Act 1971 and associated regulations for the registration of overseas nationals);
  • vehicle registration details (where parking facilities are used);
  • any special requests or preferences communicated by You.

4.2   Booking and Reservation Data

Information relating to your booking and stay with us, including:

  • reservation dates, room type and rate;
  • details of accompanying guests (including names and, where applicable, ages of children);
  • dietary requirements or accessibility needs voluntarily disclosed by You;
  • records of any complaints, incidents or correspondence during Your stay.

4.3   Payment and Financial Data

Payment information necessary to process transactions, including:

  • payment card type and last four digits (for authorisation and audit purposes);
  • billing address associated with the payment method;
  • transaction records and receipts.
Please note: We do not store full payment card numbers, CVV codes or PIN details. All payment transactions are processed by certified, secure third-party payment processors in accordance with Payment Card Industry Data Security Standard (PCI DSS) requirements.

4.4   Technical and Usage Data

When You visit our website, we may automatically collect certain technical information, including:

  • IP address and approximate geographic location derived therefrom;
  • browser type, version and operating system;
  • device identifiers and screen resolution;
  • pages visited, time and duration of visit, referring URL;
  • cookie identifiers and session data (see Section 11 for further details).

4.5   Data Received from Third Parties

We may receive personal data about You from the following third-party sources:

  • authorised online travel agents (OTAs) and booking platforms (such as Booking.com, Expedia and similar) through which You have placed a reservation;
  • global distribution systems (GDS) and travel management companies acting on your behalf;
  • payment service providers, in connection with payment authorisation and fraud screening;
  • government or law enforcement authorities, where we are under a legal obligation to receive or act upon such data.

4.6   CCTV and Security Data

Closed-circuit television (CCTV) systems operate in designated public and communal areas of the Hotel — including the reception, corridors, entrances and car park — for the purpose of maintaining the safety and security of our Guests, staff and property. CCTV recording is carried out on the basis of the Hotel’s legitimate interests in maintaining a safe and secure environment. CCTV footage is addressed further in Section 16.

4.7   Special Categories of Personal Data

We do not routinely seek to collect or process special categories of personal data as defined under Article 9 UK GDPR (including data relating to health, religious belief, biometrics or ethnicity). Where Guests voluntarily disclose such information — for example, dietary requirements or accessibility needs that may indicate a health condition — we will process such data solely to the extent necessary to provide the requested service, and will handle it with enhanced care and confidentiality. Where required, we will seek your explicit consent prior to processing.

Back to Top ↑

5. Purposes of Processing and Legal Bases

Under UK GDPR, we are required to identify a lawful basis for each purpose for which we process your personal data. The following sets out our processing purposes and the corresponding lawful bases on which we rely:

  • Processing and managing reservation and accommodation bookings
    Article 6(1)(b) UK GDPR — Performance of a contract
  • Communicating with Guests regarding bookings, stay and post-stay matters
    Article 6(1)(b) UK GDPR — Performance of a contract
  • Processing payments, refunds and managing financial records
    Article 6(1)(b) — Contract; Article 6(1)(c) — Legal obligation (accounting and tax legislation)
  • Compliance with the Immigration Act 1971 (registration of overseas nationals)
    Article 6(1)(c) UK GDPR — Legal obligation
  • Compliance with anti-money laundering obligations under the Money Laundering Regulations 2017
    Article 6(1)(c) UK GDPR — Legal obligation
  • Fraud prevention, identity verification and crime prevention
    Article 6(1)(f) UK GDPR — Legitimate interests of the Hotel
  • Maintaining the safety and security of Hotel premises (including CCTV)
    Article 6(1)(f) UK GDPR — Legitimate interests of the Hotel
  • Improving our services, website performance and Guest experience
    Article 6(1)(f) UK GDPR — Legitimate interests of the Hotel
  • Handling complaints, disputes and legal claims
    Article 6(1)(f) — Legitimate interests; Article 6(1)(c) — Legal obligation
  • Sending marketing and promotional communications
    Article 6(1)(f) — Legitimate interests (PECR soft opt-in, existing Guests); or Article 6(1)(a) — Consent

Where we rely on our legitimate interests as a lawful basis, we have conducted a Legitimate Interests Assessment (LIA) and are satisfied that our interests do not override your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests at any time; please refer to Section 10.

Back to Top ↑

6. Disclosure of Personal Data to Third Parties

We do not sell, rent or trade your personal data to any third party for their own commercial purposes. We may, however, share your data with the following categories of third parties, strictly as necessary and subject to appropriate safeguards:

6.1   Authorised Data Processors

We engage trusted third-party service providers who process personal data on our behalf and under our instructions, including:

  • property management system (PMS) and reservation platform providers;
  • payment processing and fraud detection service providers (operating under PCI DSS compliance);
  • IT infrastructure, cloud hosting and cybersecurity providers;
  • email communication and guest satisfaction survey providers.

All data processors are engaged under written data processing agreements that comply with Article 28 UK GDPR, ensuring they implement appropriate technical and organisational security measures and process data only on our documented instructions.

6.2   Booking Platforms and Travel Agents

Where your reservation was placed through an online travel agent, booking platform or travel management company, we may exchange necessary booking and guest data with that platform to the extent required to fulfil your reservation and manage any amendments or cancellations.

6.3   Legal and Regulatory Disclosures

We may disclose personal data to competent authorities, law enforcement agencies, regulatory bodies or courts where we are under a legal obligation or legal compulsion to do so, including under:

  • the Immigration Act 1971 (provision of guest registration information to the Home Office or police on request);
  • the Proceeds of Crime Act 2002 and Money Laundering Regulations 2017 (mandatory reporting obligations);
  • the Police Act 1997 and Crime and Courts Act 2013 (disclosure to law enforcement);
  • any court order, subpoena or similar legal process requiring disclosure.

6.4   Business Transfers

In the event of a sale, acquisition, merger, restructuring or insolvency involving the Hotel or CDKG Limited, personal data held by us may constitute part of the transferred or assessed assets. We will take all reasonable steps to ensure that any such transfer is conducted in compliance with UK GDPR and that the receiving party agrees to treat your personal data consistently with this Privacy Policy.

Back to Top ↑

7. International Transfers of Personal Data

The Hotel is based in the United Kingdom and, in the ordinary course of our operations, we aim to process and store all personal data within the UK or the European Economic Area (EEA). Where it becomes necessary to transfer personal data to a country outside the UK (a “Restricted Transfer”), we will do so only where one of the following safeguards is in place, as required by Chapter V UK GDPR:

  • an adequacy decision issued by the UK Secretary of State confirming that the destination country provides an adequate level of data protection;
  • the use of International Data Transfer Agreements (IDTAs), being the UK’s equivalent of the EU Standard Contractual Clauses, as approved by the Information Commissioner;
  • binding corporate rules approved by the Information Commissioner, where applicable;
  • any other safeguard or derogation permitted under Article 46 or Article 49 UK GDPR.

You may request further information about the specific safeguards applied to any international transfer of your personal data by contacting us using the details in Section 3.

Back to Top ↑

8. Data Retention

We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, and for such additional periods as may be required to comply with applicable legal obligations, resolve disputes and enforce our agreements. Our retention periods are set by reference to applicable legal requirements and operational necessity, and are reviewed regularly.

Our principal retention periods are as follows:

  • Guest reservation and stay records
    7 years from the date of departure (Companies Act 2006 / HMRC requirements for accounting and tax records)
  • Guest registration records for overseas nationals
    12 months from the date of departure (Immigration (Hotel Records) Order 1972)
  • Payment transaction records
    7 years from the date of the transaction (accounting, tax and audit obligations)
  • Complaint and dispute correspondence
    6 years from the date of resolution (Limitation Act 1980 — contractual claims limitation period)
  • CCTV footage
    Up to 31 days from the date of recording, unless required for an active investigation or legal proceedings
  • Marketing consent records
    Until consent is withdrawn, plus 2 years thereafter (evidence of consent)
  • Website analytics and cookie data
    Up to 26 months from the date of collection (ICO guidance on analytics cookies)

Upon expiry of the applicable retention period, personal data will be securely deleted, anonymised or destroyed in accordance with our internal data retention and disposal procedures.

Please note: The retention periods listed above are general guidelines. Specific circumstances, such as ongoing legal proceedings or regulatory investigations, may require us to retain data for longer periods.

Back to Top ↑

9. Data Security

We take the security of your personal data seriously and implement a range of appropriate technical and organisational security measures to protect your data against unauthorised access, disclosure, alteration, loss or destruction. These measures include, but are not limited to:

  • encryption of personal data in transit and, where appropriate, at rest;
  • access controls and role-based permissions limiting access to personal data to authorised personnel only;
  • staff training and awareness on data protection responsibilities;
  • regular review and testing of our security systems and procedures;
  • PCI DSS-compliant payment processing;
  • physical security measures at our premises.

Notwithstanding the above measures, no method of electronic transmission or storage is entirely secure. We cannot guarantee the absolute security of your personal data. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach, in accordance with Article 33 UK GDPR, and will communicate with affected individuals as required under Article 34 UK GDPR.

Back to Top ↑

10. Your Rights Under UK GDPR

As a data subject, you have the following rights in relation to your personal data under the UK GDPR and the Data Protection Act 2018. We will respond to all valid requests within one calendar month, free of charge, unless a request is manifestly unfounded or excessive:

Right of Access (Article 15) You have the right to request confirmation of whether we process personal data about You, and if so, to receive a copy of that data together with supplementary information about how we use it (a “Subject Access Request” or “SAR”).
Right to Rectification (Article 16) You have the right to request that we correct any inaccurate personal data we hold about You, or complete any incomplete data.
Right to Erasure (Article 17) You have the right to request the deletion of your personal data in certain circumstances, for example where the data is no longer necessary for the purpose for which it was collected, or where you withdraw consent and there is no other lawful basis for processing.
Right to Restriction of Processing (Article 18) You have the right to request that we restrict the processing of your personal data in certain circumstances, for example while the accuracy of the data is contested or while an objection to processing is being considered.
Right to Data Portability (Article 20) Where processing is based on your consent or on a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used and machine-readable format, and to have that data transmitted directly to another controller where technically feasible.
Right to Object (Article 21) You have the right to object at any time to the processing of your personal data where that processing is based on our legitimate interests. Where you object to processing for direct marketing purposes, we will cease processing without delay.
Right to Withdraw Consent (Article 7) Where we rely on your consent as the lawful basis for processing, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Right Not to be Subject to Automated Decision-Making (Article 22) We do not engage in automated decision-making, including profiling, that produces legal or similarly significant effects in relation to You. If this position changes, we will notify You and seek your consent or apply another lawful basis as required.

To exercise any of the above rights, please contact us using the details set out in Section 3. We may need to verify your identity before processing a request.

Please note: You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s independent supervisory authority for data protection, at any time. The ICO can be contacted at: www.ico.org.uk  •  Telephone: 0303 123 1113  •  Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
Back to Top ↑

11. Cookies and Similar Technologies

Our website uses cookies and similar tracking technologies in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR) and applicable guidance from the Information Commissioner’s Office (ICO). A cookie is a small text file placed on your device when you visit our website.

We use the following categories of cookies:

Strictly Necessary Cookies These cookies are essential for the website to function and cannot be disabled. They enable core functionality such as session management, security and accessibility features. No consent is required for these cookies.
Analytics and Performance Cookies These cookies allow us to measure and analyse how visitors interact with our website (for example, pages visited, time on site and error messages encountered). The information collected is aggregated and anonymised. Your consent is required before we place these cookies.
Functionality Cookies These cookies enable enhanced features and personalisation, such as remembering your language preference or room type. Your consent is required before we place these cookies.
Marketing and Targeting Cookies These cookies may be set by us or our advertising partners to build a profile of your interests and deliver relevant advertisements. Your consent is required before we place these cookies.

We will present a cookie consent banner upon your first visit to our website, through which you may accept, reject or manage your cookie preferences by category. You may also manage or withdraw your consent at any time by adjusting the cookie settings on our website or through your browser settings.

For full details of the cookies we use, their purposes, their lifespans and the parties who set them, please refer to our Cookie Policy, available on our website.

Back to Top ↑

12. Marketing Communications

We may send you marketing communications about our services, promotions and special offers where:

  • you are an existing Guest and have made a reservation with us, and we are marketing similar services to those reserved, in accordance with the “soft opt-in” rule under Regulation 22 PECR; or
  • you have provided your express consent to receive marketing communications from us.

Where we contact you for marketing purposes by electronic means (email or SMS), we will always:

  • clearly identify ourselves as the sender;
  • provide a clear, simple and free means for you to opt out of future marketing communications;
  • honour any opt-out request promptly and without detriment.

You may opt out of marketing communications at any time by clicking the “unsubscribe” link in any marketing email, by contacting us via the details in Section 3, or by updating your preferences on our website.

Please note: Opting out of marketing communications will not affect the delivery of essential transactional or service communications relating to your booking or stay.
Back to Top ↑

13. Third-Party Websites and Links

Our website may contain hyperlinks to third-party websites, social media platforms and other online resources operated independently of the Hotel. We have no control over, and accept no responsibility or liability for, the privacy practices, content or data processing activities of any such third-party website.

We strongly encourage You to review the privacy policy of any third-party website before providing any personal data. Access to any linked third-party website is entirely at your own risk.

Back to Top ↑

14. Children and Minors

Our Services are not directed at, and we do not knowingly collect or process personal data from, individuals under the age of 18 (“children” or “minors”). Where a reservation includes minors, the booking is made by and under the responsibility of an adult Guest.

If You believe that we have inadvertently collected personal data from a child under the age of 18 without appropriate parental or guardian consent, please contact us immediately using the details in Section 3 and we will take prompt steps to delete such data.

Back to Top ↑

15. Automated Decision-Making and Profiling

We do not engage in any form of automated decision-making, including profiling, that produces legal effects or similarly significant effects in relation to You, as described in Article 22 UK GDPR.

We may use aggregated, anonymised data for statistical analysis and service improvement purposes. Such data does not identify individual Guests and is not subject to the restrictions applicable to personal data under UK GDPR.

Back to Top ↑

16. CCTV Surveillance

Tudor Court Hotel Paddington operates closed-circuit television (CCTV) surveillance systems in the following areas of the Hotel premises: the main reception, public corridors, entrances and exits, the car park and other communal external areas. CCTV is not operated in private guest rooms, bathrooms or changing facilities.

CCTV surveillance is conducted on the basis of the Hotel’s legitimate interests under Article 6(1)(f) UK GDPR, specifically the prevention, detection and investigation of crime; the protection of the safety of Guests, staff and property; and compliance with our duty of care obligations.

CCTV footage is retained for a period of up to thirty-one (31) days from the date of recording. Footage may be retained for a longer period where it is required in connection with an active investigation, insurance claim, legal proceedings or a specific request from a law enforcement or regulatory authority. Upon expiry of the relevant retention period, footage is permanently and securely deleted.

Access to CCTV footage is restricted to authorised Hotel management and security personnel, and will be disclosed to law enforcement or regulatory authorities only where required by law or a court order. The Hotel’s CCTV operation is conducted in accordance with the Information Commissioner’s Office CCTV Code of Practice.

Please note: Notices advising of CCTV operation are displayed at all camera locations on the Hotel premises, in compliance with the transparency obligations under UK GDPR.
Back to Top ↑

17. Legal Compliance — Guest Registration Records

The Hotel is subject to statutory obligations to collect and retain certain information about Guests. In particular, under the Immigration (Hotel Records) Order 1972 (made pursuant to the Immigration Act 1971), we are required to:

  • record the full name and nationality of all Guests aged 16 or over at the time of check-in;
  • for Guests who are not British, Irish or Commonwealth citizens, also record their passport or travel document number, the place of issue of that document, and their next destination;
  • retain these records for a minimum period of twelve (12) months from the date of the relevant stay;
  • make such records available to a police constable or immigration officer on request.

Compliance with these obligations is carried out on the lawful basis of legal obligation under Article 6(1)(c) UK GDPR. The data collected for this purpose is used solely to the extent required to comply with applicable immigration legislation and is not shared with any other third party unless required by law.

Back to Top ↑

18. Data Accuracy

We take reasonable steps to ensure that personal data we hold is accurate, complete and, where necessary, kept up to date. The accuracy of certain personal data we hold depends on the information You or a third party (such as a booking platform) provides to us.

We encourage You to inform us promptly of any changes to your personal data, or of any inaccuracies in the information we hold about You, by contacting us using the details in Section 3. You may also exercise your right to rectification as described in Section 10.

Back to Top ↑

19. Changes to This Privacy Policy

We reserve the right to review, update or amend this Privacy Policy at any time to reflect changes in our data processing practices, applicable legislation, regulatory guidance or for any other legitimate reason. The date of the most recent revision is indicated at the top of this Policy.

Where a change to this Policy is material, we will take reasonable steps to bring it to your attention — for example, by displaying a prominent notice on our website or by contacting You directly where we hold a current email address for You and the change affects your personal data.

Your continued use of the Hotel’s website or Services following any update to this Policy constitutes your acknowledgement of the revised Policy. We encourage You to review this Policy periodically to stay informed of how we protect your personal data.

Back to Top ↑

20. Governing Law and Supervisory Authority

This Privacy Policy is governed by and shall be construed in accordance with the laws of England and Wales. Any dispute arising out of or in connection with this Policy or our data processing activities shall be subject to the exclusive jurisdiction of the courts of England and Wales, save where you have the right as a Consumer to bring proceedings in the courts of your country of residence.

The supervisory authority responsible for overseeing compliance with data protection law in the United Kingdom is the Information Commissioner’s Office (ICO):

Websitewww.ico.org.uk
Telephone0303 123 1113
PostInformation Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

If you are dissatisfied with our response to any data protection concern, you have the right to lodge a complaint with the ICO at any time, free of charge. We would, however, appreciate the opportunity to address any concern directly before a complaint is made to the ICO, and encourage You to contact us in the first instance.

Back to Top ↑

Tudor Court Hotel Paddington — A Trading Name of CDKG Limited — Company No. 07941515 — Registered in England & Wales

10–12 Norfolk Square, London, W2 1RS  •  www.tudorcourthotel.co.uk  •  reservations@tudorcourthotel.co.uk

© 2025 CDKG Limited. All rights reserved. — Privacy Policy last reviewed: January 2025 — Version 2.0

Write a review