The Harper — www.theharper.co.uk
Last updated: 24 August 2026
1. Who we are
The website, www.theharper.co.uk, is operated by The Harper Limited, a company registered in England and Wales under company number 17021976, with its registered office at Aberystwyth Park Lodge Hotel, Parc Y Llyn, Aberystwyth, Ceredigion, SY23 3TL. We trade as “The Harper”, a hotel located at North Street, Langham, Norfolk, NR25 7DH.
We are the “data controller” of the personal data collected through this Website. This means we are responsible for deciding how and why your personal data is used, and for keeping it safe.
We are registered with the Information Commissioner’s Office (ICO) under registration number C2014717.
Contact for data protection matters:
- Email: manager@theharper.co.uk
- Post: The Harper, North Street, Langham, Norfolk, NR25 7DH
- Phone: 01328 805000
2. What this policy covers
This policy explains what personal data we collect from you when you use this Website, why we collect it, the legal grounds we rely on, who we share it with, how long we keep it, and the rights you have over it. It covers data collected digitally through the Website, including forms, booking systems, cookies and similar technologies.
It applies alongside our cookie information in section 7 and, where you make a booking or purchase, our Terms & Conditions (www.theharper.co.uk/terms-and-conditions).
This policy does not cover personal data we collect offline (for example, in person at the hotel or over the phone), except where stated — including our use of CCTV at the hotel, which is explained in section 8.
3. Personal data we collect through this Website
We collect personal data in the following ways.
3.1 Contact and enquiry forms
When you submit a contact, enquiry or feedback form, we collect: your name, email address, phone number, the type of enquiry you select (accommodation, dining, spa, weddings, events or other), your company name (where you choose to provide it), and the content of your message, plus any other information you choose to include.
3.2 Room bookings
When you book accommodation through our online booking engine we collect: your name, email address, phone number, postal address, arrival and departure dates, guest details (including the names of others in your party, where provided), payment card details, and any preferences or special requirements you tell us about (for example accessibility or dietary needs — see section 4 on special category data). Our booking engine is provided by Guestline, which processes this personal and payment data securely on our behalf. Payments are processed securely through Guestline; we do not store your full card details on this Website.
3.3 Table and event reservations
When you reserve a table or book an event through our online reservation system, we collect your name, email address, phone number, party size, the date and time of your reservation, and any dietary requirements, allergies, or special requests you provide. Our reservation system is provided by ResDiary, which processes this personal data and any payment or deposit details securely on our behalf.
3.4 Spa treatment bookings
When you book a spa treatment, we collect your name, email address, phone number, appointment details, and any health or well-being information you provide to ensure your treatment is delivered safely (see section 4 on special category data). Our spa booking system is provided by Trybe, which processes this personal data securely on our behalf.
3.5 Newsletter and marketing sign-up
When you sign up to our mailing list, we collect your name and email address. Our email marketing is managed through Mailchimp, which processes this data on our behalf. We record when and how you consented.
3.6 Technical and usage data (collected automatically)
When you visit the Website, we automatically collect certain technical data, including: your IP address, browser type and version, device type, operating system, referral source, pages viewed, time spent on pages, and how you navigate the Website. This is collected via cookies and similar technologies — see section 7.
4. Special category data
We do not intentionally collect special category (sensitive) personal data through this Website, except where you voluntarily provide it — for example, dietary requirements or allergy information that may reveal health or religious information, health information relevant to a spa treatment, or accessibility requirements when booking. Where you provide this, we use it only to accommodate your needs and rely on your explicit consent, which you may withdraw at any time.
5. Why we use your data and our legal grounds
UK data protection law requires us to have a lawful basis for using your personal data. The table below sets out our purposes and the corresponding lawful bases.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Responding to your enquiries | Contact/enquiry form data | Legitimate interests (responding to correspondence you initiate) |
| Processing and managing your room booking or table/event reservation | Booking/reservation data, payment data | Performance of a contract |
| Sending email marketing you have signed up to | Name, email, preferences | Consent |
| Sending email marketing to previous customers about similar products/services | Name, email, purchase history | Legitimate interests (the “soft opt-in” — you can opt out at any time) |
| Accommodating dietary, allergy or accessibility needs | Special category data you provide | Explicit consent |
| Website analytics and improvement | Technical and usage data | Consent (for non-essential cookies) / legitimate interests (essential operation) |
| Online advertising and measuring ad performance | Technical/usage data, hashed identifiers | Consent |
| Website security, fraud prevention and diagnostics | Technical data | Legitimate interests (keeping the Website secure) |
| CCTV at the hotel | CCTV images | Legitimate interests (the safety and security of guests, staff and property, and the prevention and detection of crime) |
| Complying with legal obligations (e.g. tax, accounting, licensing) | Transaction records | Legal obligation |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms and concluded they are not overridden. You can request a copy of our assessment using the contact details in section 1.
6. Marketing
We will only send you marketing communications by email where you have either (a) consented, or (b) previously made a purchase or booking with us and not opted out, in which case we may tell you about similar products and services (the “soft opt-in” permitted under UK e-privacy rules).
Every marketing email we send contains an unsubscribe link. You can also opt out at any time by contacting us at manager@theharper.co.uk. Opting out of marketing will not affect service communications we need to send you, such as booking confirmations.
We do not sell your personal data to third parties.
We may use your hashed email address to show you relevant advertising on platforms such as Meta and Google, and to create audiences of people with similar interests. We only do this where you have consented to advertising cookies. You can object at any time.
7. Cookies and similar technologies
This Website uses cookies and similar technologies. When you first visit, you will see a cookie banner that lets you accept or reject non-essential cookies. Essential cookies (needed for the Website to function, such as those supporting the booking process) do not require consent.
The categories we use are:
- Essential cookies — required for core functionality such as security, page navigation and the booking process.
- Analytics cookies — help us understand how visitors use the Website. We use Google Analytics 4, deployed via Google Tag Manager.
- Advertising cookies — used to deliver and measure relevant advertising. We use the Meta Pixel and Google Ads tags, deployed via Google Tag Manager.
- Functionality cookies — remember your choices and preferences.
You can change or withdraw your cookie preferences at any time by re-opening the cookie banner on the Website or through your browser settings. Further detail is set out in our Cookie Policy at www.theharper.co.uk/cookie-policy-uk.
8. CCTV at the hotel
For the safety and security of our guests, staff and property, and for the prevention and detection of crime, CCTV operates at The Harper 24 hours a day. Cameras cover public and operational areas of the hotel; they are never located in bedrooms, bathrooms, spa treatment rooms or changing areas.
CCTV images are held securely, accessible only to authorised members of staff, and are retained for 30 days before being automatically overwritten, unless footage is required for an ongoing incident, investigation or legal claim. Signage is displayed at the hotel where CCTV is in operation. We may share footage with the police or other authorities where required by law. Our lawful basis for CCTV is our legitimate interest in keeping people and property safe.
You have the right to request a copy of CCTV footage in which you appear, using the contact details in section 1.
9. Who we share your data with
We share personal data with trusted third parties who help us run the Website and our business. They act under contract, only on our instructions, and must keep your data secure. These include:
- Website hosting and development: our website platform (WordPress) and Greyhive Ltd, our marketing agency, who manage the Website and marketing on our behalf.
- Booking engine and property management: Guestline — processes booking, guest and payment data on our behalf.
- Table reservations: ResDiary — processes reservation, guest and payment/deposit data on our behalf.
- Spa bookings: Trybe — processes spa booking data on our behalf.
- Payment processing: payments for rooms and reservations are processed securely within Guestline and ResDiary, respectively.
- Email marketing: Mailchimp.
- Analytics: Google (Google Analytics 4 / Google Tag Manager).
- Advertising platforms: Meta and Google.
We may also disclose personal data where required by law, to professional advisers, in connection with a sale or restructuring of our business, or to protect our legal rights.
10. How long we keep your data
We keep personal data only as long as necessary for the purposes described in this policy, and then securely delete or anonymise it. Our standard retention periods are:
- Enquiry form submissions: 12 months after our last contact with you.
- Booking and transaction records: 7 years, to meet accounting and tax obligations.
- Marketing lists: until you unsubscribe.
- Analytics data: 26 months, per the analytics platform’s configured retention.
- CCTV footage: 30 days, unless required for an incident or legal claim.
11. International transfers
Some of our service providers — including Mailchimp, Meta and Google — may store or process personal data outside the UK, including in the United States. Where they do, we ensure appropriate safeguards are in place, such as the UK Extension to the EU–US Data Privacy Framework, UK adequacy regulations (“data bridges”), or the ICO’s International Data Transfer Agreement / Addendum, so that your data receives protection not materially lower than it would in the UK.
12. How we keep your data secure
We use appropriate technical and organisational measures to protect your personal data, including encryption in transit (HTTPS/SSL across the Website), access controls limiting who can view your data, and reputable, security-accredited service providers. All data we collect through any of our software systems — whether personal or financial — is accessible to authorised members of staff only via a two-factor authentication (2FA) process; this includes our booking and reservation systems, Guestline and ResDiary. While no online transmission is completely secure, we work to protect your data and require the same of our suppliers. If a data breach occurs that is likely to result in a risk to your rights, we will notify the ICO and, where required, affected individuals, in line with our legal obligations.
13. Your rights
Under UK data protection law, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your data in certain circumstances.
- Restriction — ask us to limit how we use your data in certain circumstances.
- Data portability — receive your data in a structured, machine-readable format.
- Object — object to processing based on legitimate interests, and to direct marketing at any time (an objection to direct marketing is absolute and we will always honour it).
- Withdraw consent — where we rely on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Rights relating to automated decision-making — we do not make solely automated decisions with legal or similarly significant effects about you through this Website.
To exercise any of these rights, contact us using the details in section 1. We will respond within one month (this may be extended for complex requests, in which case we will let you know). We may need to verify your identity first. These rights are free to exercise in most circumstances.
14. Complaints about how we handle your data
You have a legal right to complain to us if you believe we have not handled your personal data in line with data protection law, and we have a formal process for dealing with such complaints.
How to complain to us: You can submit a data protection complaint by email to manager@theharper.co.uk, or by post to The Harper, North Street, Langham, Norfolk, NR25 7DH.
What happens next: We will acknowledge your complaint within 30 days of receiving it, investigate it promptly and appropriately (led by our General Manager), keep you informed of progress, and tell you the outcome without undue delay.
Escalation: If you are not satisfied with our response, or at any time, you can complain to the UK’s supervisory authority, the Information Commissioner’s Office (ICO):
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · Helpline: 0303 123 1113 · ico.org.uk/make-a-complaint
We would, however, welcome the chance to resolve your concerns directly first.
15. Children
This Website is not directed at children, and we do not knowingly collect personal data from anyone under 18 through it. Where you provide details of children in your party as part of a booking, we use this only to manage your stay. If you believe a child has provided us with personal data, please contact us, and we will delete it.
16. Links to other websites
This Website may contain links to third-party websites (for example, social media platforms, review sites, or partner attractions). We are not responsible for the privacy practices of those sites — please check their own privacy policies.
17. Changes to this policy
We may update this policy from time to time. The latest version will always be published on this page with the “last updated” date shown at the top.
18. How to contact us
Questions about this policy or your personal data should be directed to:
The Harper Limited (trading as The Harper)
The Harper, North Street, Langham, Norfolk, NR25 7DH
manager@theharper.co.uk
01328 805000


