Privacy Policy

Updated: January 1, 2025.


Wish Group S/A


Headquarters: São Paulo


CNPJ: 07.687.928/0001-35


This Policy aims to demonstrate the Wish Group's commitment to safeguarding your privacy and protecting your Personal Data, establishing the rules for its Processing, as well as explaining your rights and how to exercise them, within the scope of the services and functionalities of the websites listed below (“Site”) and the application called Exclusive Guest (“Application”), in accordance with applicable laws, with transparency and clarity:


  • https://www.grupowish.com.br/
  • https://www.wishhotels.com.br/
  • https://www.prodigyhotels.com.br/
  • https://www.linxhotels.com.br/
  • https://www.marupiarahotel.com.br/
  • https://exclusiveguest.com/


Please read this Policy carefully and, if you still have any questions, feel free to contact us through the Customer Service Channels provided here.



Basic concepts


For a better understanding of this Policy, the following definitions should be considered:


  • Algorithm: a set of rules that provide a sequence of operations capable of solving a specific problem or performing a task;
  • Personal Data: This refers to data relating to a natural person that is capable of identifying them or making them identifiable. For example: name, email, ID number, personal preferences, IP address, geolocation;
  • Sensitive Personal Data: This includes any data concerning racial or ethnic origin, religious beliefs, political opinions, membership in a trade union or religious, philosophical or political organization, data concerning health or sex life, genetic or biometric data, when linked to a natural person;
  • Data Protection Officer (DPO): a person appointed by the Wish Group to act as a communication channel between us, the Data Subjects, and the National Data Protection Authority (ANPD);
  • Applicable legislation: all legislation concerning privacy and protection of Personal Data, especially Law No. 13.709/2018 (General Law on the Protection of Personal Data – LGPD);
  • Our environments: refers to the electronic addresses listed above in this Policy and their subdomains, as well as the application called Exclusive Guest (“Application”), in addition to the physical environments;
  • Policy: This is the Privacy and Personal Data Processing Policy;
  • Data Subject: This is you, the individual to whom the Personal Data refers, whether in the capacity of a consumer;
  • Processing: any operation performed with Personal Data, such as those relating to collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, archiving, storage, elimination, evaluation or control of information, modification, communication, transfer, dissemination or extraction.



SPECIAL NOTE FOR CHILDREN, ADOLESCENTS AND LEGAL GUARDIANS
  • If you are under 16 years of age, you should not register on our platforms;
  • Although we do not allow the registration of children and adolescents under the age of 16, parents or legal guardians must supervise the online activities of minors;
  • Activities involving teenagers aged 16 to 18 must be supervised by their parents or legal guardians.




SPECIAL NOTE FOR SENIORS

If you are over 60 years old, please be aware that we are conscious of the risks involved in processing your personal data and are committed to taking all appropriate measures to protect it. Furthermore, we are committed to processing it in the following way:


  • Clara;
  • Simple;
  • Accessible;
  • Suitable for your understanding.



Regarding the data we process


How we handle data. Data may be processed when you interact with our environments.

What did we discuss?
What are we trying to achieve?
REGISTRATION DATA
REGISTRATION DATA
REGISTRATION DATA
What did we discuss?
  • First and Last Name;
  • CPF/NIF;
  • RG;
  • Passport;
  • E-mail;
  • Date of birth;
  • POCKET;
  • Telephone;
  • Address (Street, City, State and Country);
  • Profession;
  • Destination of the trip;
  • Travel dates;
  • Plano do Exclusive Guest;
  • Number of Points.
What are we trying to achieve?
  • (I) Identify and authenticate you;
  • (II) Confirm hotel reservations made by you and activities related to the execution of the contract, as well as provide support to the guest;
  • (III) Contacting You;
  • (IV) To expand our relationship and keep you updated on news, content, updates and other events that we consider relevant;
  • (V) To enrich your experience with us and promote our products and services and promotion on social media and websites;
  • (VI) Issue Invoice;
  • (VII) Investigate complaints made through our Complaints Channel and take the necessary measures, as well as for audits of the Wish Group;
  • (VIII) Protecting You by performing fraud prevention, credit protection and associated risks, in addition to complying with legal and regulatory obligations;
  • (IX) Management of benefits for the Exclusive Guest plan;
  • (X) Regular Exercise of Rights.


Notify us of any changes to this Policy, if necessary and in cases of legitimate interest.




DIGITAL IDENTIFICATION DATA
DIGITAL IDENTIFICATION DATA
What did we discuss?
  • IP Address, Logical Port, and Source;
  • Device (operating system version) Browser;
  • Geolocation;
  • Date and time records of each action you perform on the Site (Logs);
  • Which screens did you access? Session ID;
  • Cookies.
What are we trying to achieve?
  • (I) Identify and authenticate you;
  • (II) Comply with legal obligations for maintaining records (Logs) established by the Brazilian Civil Rights Framework for the Internet - Law 12.965/2014;
  • (III) Protecting you by performing fraud prevention, credit protection and associated risks, in addition to complying with legal and regulatory obligations;
  • (IV) Enhance the user experience;
  • (V) Access management when you use Wi-Fi on hotel premises.



PAYMENT DETAILS
PAYMENT DETAILS
What did we discuss?
  • Credit card number and security code.
What are we trying to achieve?
  • (I) To sell products and/or services on our Website or App;
  • (II) Sharing the Data with the third-party company responsible for processing the payment and regular exercise of rights in the event of disputes and payments;
  • (III) To protect you with regard to fraud prevention, credit protection and associated risks, as well as compliance with legal and regulatory obligations.



IDENTIFICATION DATA
IDENTIFICATION DATA
What did we discuss?
  • Full name;
  • Date of birth;
  • Age;
  • Apartment number;
  • Father's Name;
  • Mother's name;
  • Name of the person in charge;
  • Signature of the Responsible Party.
What are we trying to achieve?
  • (I) Kids Space Management



What did we discuss?
  • Photo/video
What are we trying to achieve?
  • (II) Identification, authentication, security through camera monitoring;


Algorithmic instruction: the resulting database will be used to instruct an algorithm to improve the browsing experience, and data such as access device characteristics, browser, IP address (with date and time), IP origin, click information, pages accessed, subsequent pages accessed after leaving the Pages, or any search term typed on the site or in reference to it, among others, may be collected automatically. For this collection, standard technologies such as cookies, pixel tags, beacons, and local shared objects may be used, which are employed to improve the User's browsing experience on the Pages, according to their habits and preferences.



Data Update and Accuracy. You are solely responsible for the accuracy, truthfulness, and updating of the data you provide to us. We are not obligated to process your data if there are reasons to believe that such processing may imply a violation of any applicable law, or if you are using our facilities for any illegal or illicit purposes.


Database. The database formed through the collection of Data is our property and is our responsibility, and its use, access, and sharing, when necessary, will be done within the limits and purposes described in this Policy.





We do not use any type of purely automated decision-making that affects your interests.



How we share the data


Data Sharing Hypotheses. The processed data and recorded activities (logs) may be shared:


  • (I) With our suppliers and business partners, with whom we have entered into contractual obligations regarding the security and protection of personal data. Suppliers include data hosting and server companies; security companies, such as the one responsible for managing the whistleblowing channel; and payment processing companies, responsible for processing payments for reservations made on the Website and App;
  • (II) With competent judicial, administrative or governmental authorities, whenever there is a legal determination, request, requisition or order to that effect;
  • (III) With the companies that make up the Economic Group to which the WISH GROUP belongs, always in compliance with the guidelines of this Policy;
  • (IV) With service providers or partner companies, to facilitate, provide or perform activities related to our environments;
  • (V) With marketing and advertising companies, to deliver promotions and information tailored to your profile;
  • (VI) Automatically, in the event of corporate transactions, such as merger, acquisition or incorporation of the WISH GROUP.


If you have any questions about who we share your Data with, please contact us through the Customer Service Channels provided at the end of this Policy.


Data Anonymization. For the purposes of market intelligence research, dissemination of information to the press, and advertising, the Data will be shared in an anonymized manner, so as not to allow for your identification.



How we protect your data and how you can protect yours too.


Security and Governance Practices. To safeguard your privacy and protect your Data, we have a governance program that includes rules of best practices, policies and internal procedures, which establish conditions for organization, training, educational actions and mechanisms for supervision and mitigation of risks related to the Processing of Personal Data.


Data Access, Proportionality, and Relevance. Internally, the processed Data is accessed only by duly authorized professionals, respecting the principles of proportionality, necessity, and relevance to the objectives of our business, in addition to the commitment to confidentiality and preservation of your privacy under the terms of this Policy. In the event of individual leaks or unauthorized access to your Personal Data, we may promote, provided that these represent relevant damage or risk to you and you agree, direct conciliation under the terms of Article 52, § 7, of the General Data Protection Law.


Password sharing. You are also responsible for keeping your Personal Data confidential and should always be aware that sharing passwords and access data violates this Policy and compromises the security of your Personal Data and the Website and Application.


Precautions You Should Take. It is very important that you take the necessary precautions against unauthorized access to your computer/smartphone, account, or password, and always remember to click "Log Out" when you finish browsing on a shared computer. The WISH GROUP never sends emails requesting confirmation of data or with attachments that can be executed (extensions: .exe, .com, etc.) or links for downloads. If you identify or become aware of a compromise of your data security, please contact our Data Protection Officer through the Customer Service channels provided at the end of this Policy.


Information Security. All credit card payment transactions are executed using SSL (secure socket layer) technology, ensuring that your Personal Data is not unlawfully disclosed. Furthermore, this technology aims to prevent information from being transmitted or accessed by third parties.


External links. When using the Site and Application, you may be directed, via link, to third-party platforms that may collect your information and have their own Data Processing Policy. It is your responsibility to read the Privacy Policies of such third-party platforms, and it is your responsibility to accept or reject them. We are not responsible for the Privacy Policies of third parties, nor for the content or services of any websites other than our own.


Processing by third parties under our guidance. We carefully evaluate our partners and service providers and enter into contractual obligations with them regarding confidentiality, information security, and data protection, with the goal of protecting you.


Email communication. To optimize and improve our communication, when we send you an email we may receive a notification when it is opened, provided this feature is available. It is important that you pay attention, as emails are only sent from the domains “@grupowish.com” or “@exclusiveguest.com”.



How we store your data and activity logs.


Storage location. The processed data and activity logs are stored in a secure and controlled environment, which may be on our servers located in Brazil, as well as in a cloud computing environment, which may require the transfer and/or processing of your data outside of Brazil. These transfers involve only companies that demonstrate compliance with applicable laws, maintaining a level of compliance similar to or more rigorous than that provided for in Brazilian legislation.


Data storage period. We store the Data only for as long as necessary to fulfill the purposes for which it was processed or to comply with any legal or regulatory obligations or to preserve rights.


Data Disposal. Once the retention period and legal requirements have expired, the Data will be deleted using secure disposal methods or used in an anonymized form for statistical purposes.


What are your rights and how can you exercise them?


Your basic rights. The Data belongs to you, and applicable legislation provides a series of rights related to it, which you may exercise by contacting our Data Protection Officer through the Customer Service Channel provided at the end of this Policy.


  • (VII) Confirmation and access: you may request confirmation of the existence of Processing and access to your Data, including by requesting copies of records we hold about you;
  • (VIII) Correction: you may request the correction of your Data that is incomplete, inaccurate or outdated;
  • (IX) Anonymization, blocking or deletion: you may request the anonymization of your Data, so that it can no longer be associated with you, the blocking of your Data, temporarily suspending the possibility of Processing for certain purposes, or the deletion of your Data;
  • (X) Portability: you may request that we provide your Data in a structured and interoperable format for the purpose of transferring it to a third party, respecting our intellectual property or trade secrets;
  • (XI) Information about sharing: you may request information about third parties with whom we share your Data, limiting this disclosure to information that does not violate our intellectual property or trade secrets;
  • (XII) Revocation of consent: you may choose to withdraw your consent for any purpose to which you have previously consented. This revocation will not affect the legality of any processing carried out previously. If you withdraw your consent for purposes fundamental to the proper functioning of our environments and services, these may become unavailable to you;
  • (XII) Objection: you may object to the Processing of your Data if you do not agree with any purpose;
  • (XIV) Review: In the case of decisions based exclusively on automated processing, you may request a review of the decision, indicating your interests that may have been affected.


Request. For your security, whenever you submit a request to exercise your rights, we may request additional information to verify your identity, in order to prevent fraud.


Failure to comply with requests. We may fail to comply with any request to exercise rights if doing so would violate our intellectual property or trade secrets, or when there is a legal or regulatory obligation to retain data. Furthermore, we may fail to comply with your request if we need to retain the data to enable our defense or that of third parties in disputes of any nature.


Responses to requests. We are committed to responding to all requests within a reasonable timeframe and always in accordance with applicable law.


Information about this policy


Changes to the content and updates. You acknowledge our right to change the content of this Policy at any time, as needed or intended. If significant updates are made to the Policy, you will be notified using the contact information you provide or through posts on our official profiles.


Inapplicability. If any point of this Policy is deemed inapplicable by a Data Authority or judicial body, the remaining conditions will remain in full force and effect.


Customer Service Channels. If you have any questions regarding the provisions of this Policy, including how to exercise your rights, you may contact our Data Protection Officer, who is available at the following addresses:


  • Responsible party: ESPALLARGAS, GONZALEZ, SAMPAIO – SOCIEDADE DE ADVOGADOS – ESG Advogados;
  • Representative appointed by EGS Advogados: Júlio Cesar Beltrão;
  • Deputy Responsible Party appointed by EGS Advogados: Bruna Komoni;
  • Mailing address: Av. Dra. Ruth Cardoso, 7815, Suites 901, 1001 and 1002, São Paulo – SP;
  • Contact email: lgpd@grupowish.com


Applicable law. This Policy shall be interpreted in accordance with Brazilian law, in the Portuguese language.


Update: 01/01/2025