Privacy Policy

Last updated: 18 July 2026

At Unisotel, we attach great importance to the protection of your personal data and your privacy. This privacy policy explains what data we collect when you use our booking website, for what purposes, on what legal bases, with whom it is shared, how long it is retained, and what your rights are.

It is drawn up in accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act of 6 January 1978 as amended (loi « Informatique et Libertés »).


1. Data controller

The Unisotel website is a commercial brand of the HONPO group. The controller of the data collected via the website is:

SAS HONPO, a simplified joint-stock company (société par actions simplifiée) with a share capital of EUR 52,800.00, registered with the Paris Trade and Companies Register (RCS) under number 521 436 238, whose registered office is located at 39 avenue Pierre 1er de Serbie, 75008 Paris.

  • Intra-Community VAT number: FR08 521436238
  • Legal representative: Vladimir ULLMANN-HAMON, President of SAS HONPO

The HONPO group companies that operate the hotels booked via the website (in particular FYL GOOD ECO, RCS Paris 914 277 504, and FYL GOOD ECO 2, RCS Paris 921 278 446) receive only the data strictly necessary for the management of your stay.

For any question relating to this policy or to your personal data, you may write to us at: privacy@unisotel.com.


2. Data Protection Officer (DPO)

No Data Protection Officer (DPO) has been appointed to date. Requests relating to personal data are handled directly by the data controller at privacy@unisotel.com.


3. Data we collect

We collect only the data necessary to provide our services. Depending on your use of the website, we may collect:

a) Account and identity data

  • Title (Mr, Mrs, Miss)
  • First name and surname
  • E-mail address (and e-mail address to be verified upon registration)
  • Telephone / mobile number
  • Password (stored in encrypted / hashed form via the authentication service, never in plain text)

b) Postal and billing details

  • Full postal address
  • Postcode, city, country

c) Booking data

  • Booking details (dates of stay, hotel, options, price)
  • Purpose of the stay (personal or professional)
  • Your booking history

d) Payment data

  • Amount, currency and order identifier, transmitted to our payment provider.
  • We do not store bank card numbers: card details are entered and processed directly by our payment provider (see Section 6).

e) Reviews and communications

  • Review ratings and comments about the hotels
  • Content of messages sent via the contact form
  • Newsletter subscription (e-mail address)

f) Technical and browsing data

  • IP address, pages visited, time spent, clicks and other analytics data
  • Cookie data and similar technologies (see Section 8)

We do not intend to collect sensitive data within the meaning of Article 9 of the GDPR. Please do not send us any such data via free-text forms (contact, reviews).


4. Purposes and legal bases

We process your data for the following purposes, each resting on a specific legal basis:

PurposeLegal basis
Creating and managing your account, authenticating youPerformance of pre-contractual measures / of the contract
Processing and confirming your bookings, managing your stayPerformance of the contract
Collecting payment and handling refundsPerformance of the contract
Sending you service e-mails (confirmation, modification, cancellation)Performance of the contract
Responding to your requests via the contact formLegitimate interest (responding to your enquiry)
Publishing and moderating customer reviewsLegitimate interest / consent given when submitting the review
Sending you the newsletter and marketing communicationsConsent (withdrawable at any time)
Placing audience-measurement and tracking cookies that are not strictly necessaryConsent
Ensuring the proper functioning and security of the website and preventing fraudLegitimate interest
Complying with our accounting, tax and legal obligationsLegal obligation

Withdrawing your consent (for marketing or cookies) does not affect the lawfulness of processing carried out before that withdrawal, nor processing based on another legal basis (for example, the performance of your booking).


5. Recipients and processors

Your data is accessible only to authorised persons within the HONPO / Unisotel group and is shared, strictly to the extent necessary, with the following service providers (processors within the meaning of the GDPR):

  • Payment provider — Lyra / Société Générale gateway (Sogecommerce): secure transaction processing. Receives in particular your e-mail address, the amount, the currency and the order identifier.
  • Firebase / Google: authentication service (management of your account and login) and storage of session data.
  • Google Cloud Storage (Google): hosting of hotel images.
  • Google Maps / Google Places (Google): display of maps on hotel pages and address autocompletion during registration.
  • Google Analytics and/or Ahrefs: audience measurement and traffic analysis, only if you have consented (see Section 8). These tools are activated only if the corresponding tracking identifiers are configured.
  • Hotel management system — Oracle Hospitality OPERA Cloud (Oracle): transmission, via our backend, of the booking information necessary for the hotel to manage your stay (name, dates, room, options). The service is hosted in the European Union.
  • Host / infrastructure of the Unisotel backend: hosting of the application and of the booking, profile, contact, review and newsletter APIs (see Section 11).

We may also disclose your data to administrative or judicial authorities where required by law.

We never sell your personal data.

Each processor acts on our instructions and is bound by a contract providing confidentiality and security guarantees in accordance with Article 28 of the GDPR.


6. Payment

Online payments are processed by our provider Lyra, via the secure Société Générale (Sogecommerce) gateway. The payment form is provided and secured by this provider.

Your bank card details are transmitted to and processed directly by the payment provider in an environment compliant with payment card industry security standards. Unisotel receives only the transaction status and the information necessary to track the order (amount, currency, order identifier, e-mail address).


7. Data transfers outside the European Union

Some of our providers, in particular Google / Firebase, may process or host data outside the European Union (for example in the United States).

In such cases, these transfers are governed by appropriate safeguards within the meaning of Articles 44 et seq. of the GDPR: standard contractual clauses adopted by the European Commission and/or certification under the EU–US Data Privacy Framework, depending on the provider concerned (Google LLC is in particular certified under the Data Privacy Framework).


8. Cookies and trackers

The website uses cookies and similar technologies. We distinguish:

a) Strictly necessary cookies (placed without consent, essential to the service):

  • __Host_fid: authentication cookie (secure session token), placed via Firebase Auth. Purpose: keeping you logged in to your account.

b) Third-party functional cookies (necessary for certain features you activate):

  • Google Maps / Google Places: display of maps and address autocompletion.

c) Audience-measurement and tracking cookies (placed only with your consent):

  • Google Analytics (gtag): statistical measurement and analysis of browsing behaviour.
  • Ahrefs Analytics: traffic and SEO analysis.

To date, audience-measurement cookies (Google Analytics, Ahrefs) are not activated on the website: only the strictly necessary cookies and the third-party functional trackers described above may be placed. Should cookies subject to consent be activated, a consent-collection mechanism compliant with the recommendations of the French Data Protection Authority (CNIL) would first be put in place, allowing you to accept or refuse them category by category. You may also configure your browser to block some or all cookies; refusing non-essential cookies does not prevent you from using the website.

For more details, see our Cookie Policy.

Cookie retention period: strictly necessary cookies have a lifetime limited to the session or to the validity period of the authentication token; if audience-measurement cookies were activated, their lifetime would not exceed 13 months, in accordance with the recommendations of the CNIL.


9. Retention periods

We keep your data only for as long as necessary for the purposes described, and then delete or anonymise it:

  • Account data: for the lifetime of the account, then 3 years from the last activity or from the deletion of the account.
  • Booking and payment data: for the duration of the contractual relationship, then kept in intermediate archiving for 10 years pursuant to legal accounting and tax obligations.
  • Marketing / newsletter data: until you withdraw your consent and at the latest 3 years from your last contact with us.
  • Customer reviews: for as long as the review is published on the website; if withdrawn or deleted, limited archiving for 1 year.
  • Contact form messages: for the time needed to handle the request, then limited archiving for 1 year.
  • Cookies and analytics data: see Section 8 (session cookies; a maximum of 13 months for any audience-measurement cookies, 25 months for the associated data).
  • Data relating to the handling of rights requests: 5 years from the closure of the request.

Upon expiry of these periods, your data is deleted or irreversibly anonymised.


10. Your rights

In accordance with the GDPR and the French Data Protection Act (loi « Informatique et Libertés »), you have the following rights over your data:

  • Right of access: obtain confirmation that your data is being processed and receive a copy of it.
  • Right to rectification: have inaccurate or incomplete data corrected.
  • Right to erasure ("right to be forgotten"), under the conditions provided for by law.
  • Right to restriction of processing.
  • Right to object to processing based on legitimate interest, and at any time to commercial prospecting.
  • Right to data portability (for processing based on consent or on the contract).
  • Right to withdraw your consent at any time, for processing that depends on it (marketing, non-essential cookies).
  • Right to give instructions regarding the fate of your data after your death.

To exercise these rights, write to us at privacy@unisotel.com or by post to: SAS HONPO — Personal Data, 39 avenue Pierre 1er de Serbie, 75008 Paris. We may ask you for proof of identity if there is reasonable doubt about your identity. We respond within one month, extendable by two months for complex requests.

If you consider that your rights are not being respected, you may lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés, the French Data Protection Authority), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr.


11. Hosting

The website and its backend are hosted on the Upsun / Platform.sh infrastructure, operated by Platform.sh SAS, 22 rue de Palestro, 75002 Paris, France (RCS Paris 521 496 059). The data is hosted in a region located within the European Union.


12. Data security

We implement appropriate technical and organisational measures to protect your data against unauthorised access, alteration, disclosure or destruction: password encryption, secure connections (HTTPS), secure authentication cookies (httpOnly and Secure attributes in production), access rights management and the use of reputable service providers.


13. Changes to this policy

This policy may be amended at any time, in particular to reflect legal, regulatory or technical developments. Any update is published on this page with a new revision date. We invite you to consult it regularly.


For any question or concern about your personal data or this policy, you may contact us at: privacy@unisotel.com.