Hotel San Juan de los Reyes' privacy policy

Hotel San Juan de los Reyes' privacy policy

Last review date: May 18, 2026

0.- Introduction

Thank you for visiting this website. We believe your privacy is important. For the website owner, your reading and interest in this section demonstrates your interest in the site. You should do this every time you visit new websites, especially if they are going to ask for personal data. Below, in this document, we explain what personal data we collect, on what basis, how long it will be stored, and aspects related to data protection regulations, in compliance with current legislation. We encourage you to carefully read these terms before providing your personal data. For children under 14, parental or guardian consent is required for the processing of their data. If you are under 14, you should not leave your data on this website unless your parents authorize it. Under no circumstances will data relating to the professional or financial situation, or the privacy of other family members, be collected from a minor without their consent. If you have any questions, please contact the data controller or, if applicable, the data protection officer via the email addresses provided. The data controller is committed to privacy and ensures best practices in the processing of your personal data.

In compliance with the provisions of data protection regulations (EU Regulation 2016/679 of 27 April 2016), Restoledo SL (hereinafter, "The Owner" or simply "The Owner" or "The Hotel"), owner of the website www.hotelsanjuandelosreyes.com (hereinafter, the "Website"), establishes the following Privacy Policy, which will govern the processing of personal data. This policy is understood, in any case, without prejudice to the provisions of the corresponding Legal Notice / General Terms and Conditions and the corresponding Cookie Policy.

1.- Data Controller

Data Controller: Restoledo SL

Address: Reyes Católicos 5, 45002, Toledo

Email: info@hotelsanjuandelosreyes.com

Telephone: 925283535

Data Protection Officer: info@legaltech.es

We strive to guarantee the privacy of users of this website. Please be advised that we will never request personal information unless it is truly necessary for the provision of services, we will never share it with third parties (except in specific cases where it is essential and based on legitimate situations that have been previously communicated to you), and we will never use your data for purposes unrelated to the contractual relationship. This entity adheres to the commitments of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights, Regulation (EU) 2016/679 of the European Parliament and of the Council, and Law 34/2002, of July 11, on Information Society Services and Electronic Commerce (LSSICE or LSSI), as well as any regulations that develop or supplement them.

This Data Controller guarantees the confidentiality of the personal data being processed and informs you that those who have access to your information are bound by professional secrecy. However, we cannot guarantee the impenetrability of this website or the complete absence of risks. To the extent that your privacy is deemed to have been compromised, this controller undertakes to inform you without undue delay of any personal data breach that is likely to pose a high risk to your rights and freedoms, in accordance with the General Data Protection Regulation.

Therefore, the data that may be requested from users of this Website through contact forms, those provided by the mere fact of accessing the Website (cookies), those related to possible comments on the different corporate pages of the social networks linked from this Website, the personal data that the user enters within the enabled sections or those provided by the other means or channels of communication enabled (for example, email) will be processed by the indicated data controller in compliance always with current legislation.

2. What obligations do I have when providing my data?

By providing us with your personal information through electronic channels, you declare that you are over 14 years of age and that all the information provided is true, accurate, complete, and up-to-date. To this end, you confirm that you are responsible for the accuracy of the information provided and that you will keep it properly updated to reflect your current situation. You will be liable for any false or inaccurate information you may provide, as well as for any direct or indirect damages that may arise.

3.- Why do we process your personal data?

When a user visits this website, they are providing personal information. This information may include personal data such as your IP address, name, physical address, email address, telephone number, and other information. The purposes for which we process your data will depend on the context or section in which it is requested.

Simply by visiting the Website, certain information is collected on the servers that provide hosting services. This information includes the IP address from which you access the Website. The purpose of processing this information is to facilitate your browsing experience. We may also collect certain information (cookies), which we will process according to our specific Cookie Policy, which you can consult.

If you provide us with your data through any of the available forms, the purpose will be that indicated on the corresponding form. For example, if you provide your data in contact forms, the purpose will be to respond to your inquiry. If you use the reservation form, the purpose will be to manage and, where applicable, confirm your reservation, as well as to comply with the legal obligations associated with this action. If you enter your data in the newsletter form, your email address will be added to our mailing list, and you may receive advertising through this channel. If you include data in the restaurant reservation form, your data may be processed for that purpose. If you include your data in the "Work with Us" section, we may process your identification data and CV information to manage staff vacancies and review your application.

If you provide us with personal data via email or other means (traditional or otherwise), we will generally process your data in relation to the management or inquiry you have made. In compliance with Law 34/2002, on Information Society Services and Electronic Commerce, the Data Controller will not send commercial communications without identifying them as such and without prior notification. For these purposes, any information sent to interested parties will not be considered a commercial communication provided that its purpose is to maintain the contractual relationship, respond to your request, or provide other information related to your request—if applicable—and that arises directly from this relationship.

If you provide us with information through any of the social media platforms maintained by this organization and linked to this website, and assuming the role of Data Controller for the data provided (for example, photos uploaded by us or third parties, comments made by the interested party regarding our publications, etc.), we will process the information exclusively in relation to your inquiry, request, or comment, and always within the social media platform and its context. Under no circumstances will this data be extracted unless we obtain your explicit consent. However, the use of these platforms is subject to your full acceptance of their terms and conditions, which implies the processing of your data under conditions different from those set forth here. The official profiles on the social media platforms linked from this website have been created to provide you with a better understanding of our activities and to create an alternative communication channel with those interested in our organization and the services we offer. However, we disclaim responsibility for the data processing carried out by the companies that manage these social media platforms.

If you use the "Work with us" section or any similar section on the Website where job offers may be published or applications submitted, we will process the personal data you provide to manage your participation in open selection processes, assess your professional profile, contact you regarding your application, send communications related to the selection process, and, where applicable, retain your curriculum vitae or professional documentation for the period strictly necessary to address the specific offer or future vacancies, provided there is a sufficient legal basis for doing so. The data processed may include identification data, contact information, academic and professional information, work experience, training, skills, data included in your curriculum vitae, and any other information that you voluntarily provide. It is recommended that you do not include specially protected information or information not necessary for the professional assessment, such as health data, ideology, religion, trade union membership, sexual orientation, or other data not relevant to the selection process. If you are not selected, your data will be deleted once the process is over, unless you have been expressly informed of its retention for future offers or your consent has been obtained where necessary.

Specifically, if you enter your email address in the field provided for subscribing to receive information or communications related to the hotel, we will process this data to manage your registration on the mailing list and send you information about the establishment, its services, facilities, news, offers, promotions, activities, events, restaurant, experiences, tour packages, or other communications related to hotel operations. The legal basis for this processing will be the consent given by the user by checking the corresponding box or by taking the affirmative action provided for this purpose, in accordance with Article 6.1.a) of the GDPR and Law 34/2002, on Information Society Services and Electronic Commerce. The user may withdraw their consent or unsubscribe at any time through the mechanism provided in each communication or by contacting the hotel using the contact methods indicated in this policy, without this affecting the lawfulness of the processing carried out previously. In no case will subscription to these communications be necessary to browse the Website or to contract the hotel's ordinary services, unless expressly indicated otherwise in a specific promotion or service.

If you use the gift certificate purchase or gifting functionality enabled on the Website, we will process the personal data you provide for the purpose of managing the request, purchase, issuance, delivery, validation, and, where applicable, redemption of the gift certificate, as well as to handle any communication related to this transaction. The data processed may include identifying and contact information of the person purchasing or requesting the gift certificate, such as name, surname, telephone number, and email address, as well as identifying and contact information of the recipient of the gift, when entered by the user, including name, surname, telephone number, and email address. We may also process information relating to the gift certificate amount, selected option, purchase date, transaction status, associated communications, and data strictly necessary to verify the service agreement. The legal basis for processing will be the performance of the contractual relationship or the application of pre-contractual measures requested by the data subject, pursuant to Article 6.1.b) of the GDPR, as well as compliance with applicable legal obligations regarding tax, accounting, consumer protection, invoicing, and handling of potential claims, pursuant to Article 6.1.c) of the GDPR. When the user provides data of a third party as the recipient of the gift certificate, they must ensure that the third party has sufficient legal grounds to provide such data and that the information provided is adequate, relevant, and limited to what is necessary for managing the gift. Specially protected data, sensitive information, or comments that are not necessary for issuing or managing the gift certificate should not be included.

If you use the booking platform integrated into the Website, we will process the personal data you provide to manage your availability request, process, confirm, modify, or cancel your booking, as well as to properly provide the contracted accommodation service and handle any necessary communications related to that booking. The data processed may include the booking holder's identification and contact information, details of the stay, check-in and check-out dates, number of guests, preferences communicated by the user, comments entered on the form, billing information, and, where applicable, bank card details provided solely to guarantee the booking, ensure your stay, verify the validity of the payment method, and apply the terms and conditions for cancellation, no-shows, or modifications of the booking when applicable. When the booking is processed through an integrated technology platform or external booking engine provider, that provider may act as the data processor or, where applicable, as an independent controller for certain services, in accordance with its own terms and conditions, and the corresponding contractual and technical safeguards must be applied.

If you use the platform enabled to make reservations at La Fábrica de Harinas restaurant or to purchase products, menus, vouchers, gastronomic experiences, or services related to the restaurant, we will process the personal data you provide for the purpose of managing the request, processing, confirmation, modification, or cancellation of the reservation, as well as, where applicable, managing the purchase, issuance, validation, payment, and redemption of the contracted product or service. The data processed may include the user's identification and contact information, such as name, surname, email address, and telephone number; details related to the reservation or service requested, date, time, number of diners, comments entered by the user, selected product or experience, amount, transaction status, proof of purchase, and any other information necessary to properly manage the reservation or contract. In the case of online payment, this may be made through the methods enabled at any given time, including bank card or Google Pay, and may involve a secure external payment gateway. The hotel/restaurant will not store complete bank card details nor have full access to the financial information used to authorize the transaction. Access will be limited to receiving payment confirmation, the transaction status, and the information strictly necessary to manage the reservation, purchase, issue, refund, or corresponding claim. The CoverManager technology platform may act as the data processor for reservation management, online purchase, availability, associated communications, and technical support services, processing personal data on behalf of the hotel/restaurant and following its documented instructions, in accordance with the corresponding data processing agreement provided for in Article 28 of the GDPR. This is without prejudice to the fact that certain payment providers may act in accordance with their own terms and responsibilities regarding payment authorization and processing.

4. How long will you keep them?

As a general rule, data stored by this data controller will be deleted as soon as it is no longer needed for the purposes for which it was stored and there is no legal obligation to retain it. However, if user data is not deleted because it is required for other legally permitted purposes, its processing will be restricted to very specific purposes. This means that the data will be blocked and will not be processed for other purposes. For example, this applies to user data that must be retained for commercial or tax reasons.

It depends on the data processing carried out:

-The data related to the cookies existing on this Website have a retention period indicated in the Cookies Policy itself.

The data you provide through the means made available on this Website (forms, email) will be kept for as long as your relationship with us lasts, or until you withdraw your consent. Afterwards, we will retain the data as required by law, with the minimum retention period depending on the specific relationship or transaction. For example, we will retain billing data for 6 years due to tax and accounting obligations. There is also the 5-year statute of limitations established by Article 1964 of the Spanish Civil Code (personal actions without a specific limitation period). In the case of a room reservation, hotel check-in records will be kept for 3 years and made available to law enforcement agencies.

-The data included on social media linked through this Website will be kept by us until the interested party withdraws their consent. However, the responsible entities may retain this data according to other processing policies for which we are not responsible in any way.

The data provided through the "Work with us" section or by submitting a curriculum vitae will be kept for the time necessary to manage the corresponding selection process. If the candidate is not selected, the data may be kept for a maximum of 12 months from its receipt or from the end of the selection process, in order to consider future vacancies that may match their professional profile, unless the interested party requests its deletion or objects to its processing beforehand. After this period, the data will be securely deleted, unless there is a legal obligation to retain it or it is necessary to keep it blocked to address any potential liabilities arising from the selection process.

-Data processed for managing subscriptions to newsletters, marketing communications, or hotel-related information will be retained as long as the subscriber maintains an active subscription and does not withdraw their consent, unsubscribe, or object to receiving such communications. If the subscriber unsubscribes, the data will no longer be used for this purpose, although it may be kept blocked for the period necessary to demonstrate compliance with applicable legal obligations, address potential liabilities, or prevent the sending of further unsolicited communications.

Data related to the purchase, issuance, management, and redemption of gift certificates will be retained for the time necessary to process the transaction, enable its use or validation, address any issues, inquiries, or complaints related to the service, and comply with applicable legal obligations. Subsequently, the data may be kept blocked for the legally required periods for tax, accounting, consumer, billing, and liability purposes related to the service contract.

Data related to availability requests, reservations made through the booking platform integrated into the Website, modifications, cancellations, contracted stays, or communications associated with the provision of accommodation services will be kept for the time necessary to manage the reservation, provide the contracted service, address customer requests, apply cancellation or no-show policies, resolve incidents, and comply with applicable legal obligations. Data necessary for billing, accounting, tax obligations, consumer protection, or handling potential complaints may be kept for the legally required periods and will subsequently be blocked when appropriate. In particular, data related to the documentary registration of travelers will be kept in accordance with the regulations applicable to accommodation establishments and made available to law enforcement agencies when legally required. If bank card details are provided to guarantee the reservation or ensure the stay, such data will only be kept for the time necessary to verify the reservation, apply the contracted conditions, manage possible legitimate charges arising from cancellation, non-show, modification or services actually contracted, and attend to associated responsibilities, avoiding in any case its unnecessary or indefinite storage.

Data related to requests for organizing group lunches or dinners, inquiries about availability, quotes, group bookings, or waiting list management will be kept for the time necessary to process the request, manage availability, maintain communication with the interested party, organize the requested event or booking, and resolve any issues arising from this process. If placed on a waiting list, the data will be kept for the time necessary to manage the list and contact the interested party if availability becomes available, and will be deleted when it is no longer needed for this purpose. If a booking, contract, or service provision is ultimately formalized, the data may be kept for the legally required periods for tax, accounting, consumer, billing, and liability purposes. When the interested party has consented to receiving informational or commercial communications, their data will be kept as long as they maintain an active subscription and do not withdraw their consent, unsubscribe, or object to receiving such communications.

5. Why are we allowed to process your personal data?

Because there is a legal basis for processing your data, as established by data protection regulations. In other words, the regulations allow us to process your personal data. It depends on the specific data processing activity:

-The existence of one or more legal obligations that require us to process the data. For example, the aforementioned tax obligation in relation to issued invoices or the obligation derived from the retention of check-in data in hotel establishments (Organic Law 4/2015, of March 30, on the Protection of Public Safety and Royal Decree 933/2021, of October 26, which establishes the documentary registration and information obligations of natural or legal persons who carry out accommodation and motor vehicle rental activities).

-You have given us consent to process your data under the terms set out, by ticking the corresponding acceptance box.

-There is a legitimate interest in the processing. For example, if the interested party provides us with their data in relation to an entrusted task, we will process it because we understand that we have to give a full response to it.

-The execution of the contractual relationship, in accordance with Article 6.1.b) of the GDPR.

-The sending of commercial communications about similar products or services may be carried out, where appropriate, in accordance with the provisions of Article 21.2 of Law 34/2002, on Information Society Services and Electronic Commerce, provided that there is a prior contractual relationship, the products or services are similar to those initially contracted, and the recipient is offered the possibility of objecting or unsubscribing easily and free of charge in each communication. Outside of these cases, the sending of commercial communications will require the prior consent of the interested party.

6. Are we going to give them to someone?

Whenever we subcontract to third parties for the provision of our services, we will take appropriate legal precautions, as well as suitable technical and organizational measures to ensure the protection of personal data in accordance with the relevant legal regulations.

In addition to the Data Controller listed above, data may be processed by other entities depending on the nature of the data processing:

-Certain companies responsible for the cookies that are stored on your computer simply by visiting this Website may have information associated with your IP address, browsing habits, etc., as described in the corresponding Cookie Policy.

-The data may be processed by technology providers involved in the operation of the Website, booking engine, forms, newsletter, availability management, electronic communications, web hosting, technical maintenance, or tools integrated into the page, including, where applicable, providers that develop, host, or maintain the web platform or booking system. These providers will act, where appropriate, as data processors, accessing the data only to provide the contracted service, following documented instructions from the hotel and in accordance with the corresponding data processing agreement provided for in Article 28 of the GDPR.

-By legal obligation, the Spanish Tax Agency may also request information of tax relevance from us, and we are obligated to provide it. The same applies to state security forces and agencies in the performance of their assigned duties.

-In case of reservation, and in relation to guest registration: competent authorities in compliance with the provisions of Organic Law 4/2015, of March 30, on the Protection of Citizen Security and Royal Decree 933/2021, of October 26, which establishes the documentary registration and information obligations of natural or legal persons who carry out accommodation and motor vehicle rental activities

Data related to restaurant reservations, online purchases of products, menus, vouchers, or dining experiences may be processed by CoverManager, in its capacity as technology provider and data processor, for the management of reservations, availability, communications, online purchases, issuance of receipts, transaction validation, and technical support for the platform. Likewise, when the user makes a payment by bank card, Google Pay, or another enabled electronic payment method, external payment service providers or gateways may be involved, processing the data necessary to authorize and process the transaction in accordance with their own terms, security measures, and responsibilities.

This Data Controller follows strict criteria for selecting service providers in order to comply with its data protection obligations and undertakes to sign the corresponding data processing contract with them, through which it will impose obligations related to the implementation of appropriate technical and organizational measures, process personal data for the agreed purposes and only following documented instructions, and delete or return the data to this controller once the provision of services has ended.

7. What rights do I have?

Everyone has the right to obtain confirmation as to whether or not this entity is processing personal data concerning them. Data subjects have the right to access their personal data, as well as to request the rectification of inaccurate data or, where appropriate, to request its erasure when, among other reasons, the data is no longer necessary for the purposes for which it was collected. In certain circumstances, data subjects may request the restriction of the processing of their data, in which case we will only retain it for the exercise or defense of legal claims. In other circumstances and for reasons related to their particular situation, data subjects may object to the processing of their data. In those cases where you have given us your consent, we further inform you that you have the right to withdraw it at any time, without this affecting the lawfulness of the processing based on the consent prior to its withdrawal. If you request it, this entity will cease processing the data, except for compelling legitimate grounds, or for the exercise or defense of possible legal claims. You may also request that your data be processed by another entity, and this entity will facilitate the portability of your data to the new controller. To this end, specific forms have been prepared (which are available to you and which you may request) so that you can exercise your rights of access, rectification, erasure, restriction of processing, objection to processing, objection to automated individual decision-making, including profiling, and data portability. In any case, if you believe that these rights have not been adequately addressed by us, we inform you that you may file a complaint with the supervisory authority (Spanish Data Protection Agency, Jorge Juan 6, 28001, Madrid, or via its website https://sedeagpd.gob.es).

If you prefer, you can contact us by mail at the address shown in the header, or by email at the email address provided, including a document proving your identity and requesting to exercise the rights mentioned above.

8. Whether the information we request is mandatory or optional. Accuracy of the information

By checking the corresponding boxes and entering data in the fields, the user expressly, freely, and unequivocally accepts that their data is necessary for the Data Controller to process their request. The user guarantees that the personal data provided is truthful and accurate and is responsible for communicating any changes to it. The Data Controller is exempt from any liability if the user enters false data. All data requested through the website is mandatory, as it is the minimum required to contact the user. If all the data is not provided, we cannot guarantee that the information and services provided will be fully tailored to the user's needs.

9. Principles we will apply when processing your personal data

The processing of the User's personal data will be subject to the following principles set out in Article 5 of the General Data Protection Regulation:

Principle of lawfulness, fairness and transparency: the User's consent will be required at all times after providing completely transparent information about the purposes for which personal data is collected.

Principle of purpose limitation: personal data will be collected for specific, explicit and legitimate purposes.

10. Special reference to social networks

The Owner maintains several pages and/or profiles on various social media platforms, linked through this Website. The Owner is not responsible for content published by third parties on these social media platforms. The use and processing of data by third parties on these social media platforms will be subject to general or specific terms and conditions that differ from these. The Owner recommends that you carefully read and understand these terms and conditions.

This website may include links to the hotel's corporate profiles on social media, particularly Facebook and Instagram. These social media platforms are operated, for users within the European Economic Area, by Meta Platforms Ireland Limited, located at Merrion Road, Dublin 4, D04 X2K5, Ireland, a company within the Meta group. Using these links may require the user to leave this website and access platforms owned by Meta. Therefore, the processing of data within Facebook or Instagram will be subject to their respective terms of use, privacy policies, and the user's privacy settings. Meta explains in its privacy policy how it collects, uses, shares, stores, and transfers information from users of its services.

The purpose of the hotel's presence on these social networks is to inform about its services, facilities, rooms, restaurant, events, promotions, activities, news, images of the establishment, tourist content or information related to hotel activity, as well as to provide a complementary communication channel with clients, potential guests, followers or interested people.

When the user interacts with the hotel's profiles on Facebook or Instagram, for example by following the page, clicking "like", commenting on posts, sending private messages, sharing content, tagging the hotel or performing any other interaction allowed by the platform, the hotel may process the data visible or communicated by the user within the social network in order to manage said interaction, answer queries, attend to requests for information, manage communications, moderate comments, maintain the relationship with its followers and disseminate information related to its hotel services.

The data processed may include, depending on the user's privacy settings and the interaction performed, username or alias, profile identifier, public profile picture, comments, messages, reactions, shared content, mentions, tags, voluntarily provided contact information, and any other information the user communicates through the platform. The hotel will not extract this data from the social network for its own processing activities unless there is a valid legal basis for doing so, it is necessary to fulfill a specific user request, or the user has been previously informed where applicable.

Please note that if a user accesses Facebook or Instagram while logged into their account, Meta may associate that browsing or interaction with their user profile, as well as process technical information, usage data, identifiers, cookies, IP address, device information, activity within and outside of its services, and other data in accordance with its own policies. This processing is carried out by Meta as an independent data controller, and the hotel has no control over its purposes, means, or scope.

The legal basis for the processing carried out by the hotel will generally be its legitimate interest in maintaining a professional presence on social media, promoting its hotel services, responding to inquiries, and managing its digital community, in accordance with Article 6.1.f) of the GDPR. When the user submits a specific request related to a reservation, service contract, stay, event, or pre-contractual inquiry, the legal basis may be the application of pre-contractual measures or the performance of the contractual relationship, in accordance with Article 6.1.b) of the GDPR. Where applicable, for direct commercial communications outside the social media environment, consent will be requested when required.

Facebook or Instagram should not be used to send particularly sensitive or confidential information, such as copies of ID cards, passports, or other identification documents, full bank details, credit card numbers, health information, specially protected information, documentation relating to minors, complex claims, financial statements, or any other information that requires a more secure or formal channel. For this type of communication, the channels specifically provided by the hotel should be used.

The use of Facebook and Instagram may involve international data transfers outside the European Economic Area. According to information published by Meta, for certain categories of data received from the EEA or Switzerland, Meta Platforms, Inc. declares its adherence to the EU-U.S. Data Privacy Framework, without prejudice to the use of other legally valid safeguards, such as Standard Contractual Clauses or other mechanisms provided for in applicable regulations.

The hotel is not responsible for the processing of personal data by Meta, Facebook, Instagram, or other entities within their group, as these are independent operators of their own platforms. The inclusion of links to the hotel's social media profiles is solely for the purpose of facilitating voluntary access to these channels for the user. It is the user's responsibility to decide whether to interact with the hotel through these social networks or use other alternative means of contact made available to them.

This Website may incorporate a link, button or direct access to the WhatsApp instant messaging platform, in order to provide users, clients or potential guests with an alternative channel of contact with the hotel for general inquiries, requests for information on availability, rates, establishment services, schedules, location, reservations, ordinary reservation modifications or other issues related to the provision of hotel services.

The service provider for users in the European Economic Area is WhatsApp Ireland Limited, a company within the Meta group. Using this link may require the user to leave this website and access a WhatsApp-owned environment, and therefore, any data processing within that platform will be subject to its own terms of service and privacy policy.

By using this channel, WhatsApp may process personal data such as phone number, username or alias, profile picture, device information, IP address, information about application usage, communication metadata, date and time of contact, as well as any data that the user voluntarily includes in the message. Although WhatsApp states that communications are transmitted end-to-end encrypted, this does not prevent the platform from processing certain technical, account, security, usage, or metadata necessary for providing the service.

This channel is provided solely for routine hotel-related communications. WhatsApp should not be used to send particularly sensitive or confidential information, such as complete identification documents, copies of ID cards, passports, or other official documents, full bank details, credit card numbers, financial statements, health information, information about minors beyond what is strictly necessary for the booking, information about special accommodation needs, complex complaints, or any other information that, by its nature, requires a more secure, formal, or private channel. For these types of communications, please use the channels specifically provided by the hotel.

The use of WhatsApp may involve international data transfers outside the European Economic Area, especially when Meta group entities located in third countries are involved. Such transfers will be carried out, where applicable, in accordance with the safeguards provided for in applicable regulations, including adequacy decisions, Standard Contractual Clauses, or other legally valid mechanisms.

The hotel will not be responsible for any subsequent processing carried out by WhatsApp, Meta, or other entities within its group as independent providers of their own services. The inclusion of this link on this website is solely for the purpose of facilitating a voluntary means of contact; it is up to the user to decide whether to use this platform or other alternative channels made available by the establishment.

11. Cookies and other aspects.

This website includes an SSL certificate. This is a security protocol that ensures your data travels securely and intact. We have implemented appropriate security measures following a thorough risk analysis. These measures include, in particular, the encrypted transmission of data between your browser and our server.

As a user, you are solely responsible for the truthfulness and accuracy of the data you submit on this website. The Owner Entity will not accept any liability in this regard, ensuring the accuracy, validity, and authenticity of the personal data provided.

The Owner reserves the right to modify this policy to adapt it to new legislation or case law, as well as industry practices. In such cases, the Owner will announce the changes on this page with reasonable notice before they take effect.

This Data Controller reserves the right to modify and/or update the data protection information when necessary for compliance with the General Data Protection Regulation (GDPR). If any changes are made, the updated text will be published on this page, where you can access the current policy. In each case, the relationship with users will be governed by the rules in effect at the time of access to the website. For all purposes, the document's validity can be verified in the header.

Regarding the cookies collected on this website, please refer to our Cookie Policy.

We use the Google reCAPTCHA service on certain forms on the Website to protect them against automated submissions, spam, unauthorized access, fraudulent use, or bot activity. This service allows us to verify, through a technical analysis of user interaction with the Website, whether the action was performed by a human or an automated system.

The service provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, without prejudice to the fact that, depending on the configuration of the service and Google's technical infrastructure, other entities of the Google group may be involved, including Google LLC, with registered office at 1600 Amphitheatre Parkway, Mountain View, California 94043, United States.

The use of Google reCAPTCHA may involve the processing of certain technical and browsing data, such as the IP address of the device used, browser and operating system information, date and time of access, page or form in which the service is integrated, browsing behavior, interactions with the form, mouse movements, clicks, time spent, device information, cookies or other technical identifiers, as well as, where applicable, information associated with a Google account if the user is authenticated in its services.

The purpose of this processing is to ensure the security of the Website, prevent misuse of forms, prevent the automated sending of unsolicited communications, and protect the technical integrity of the systems. The legal basis for this processing is the legitimate interest of the Data Controller in maintaining the security of its Website and preventing abuse or fraudulent activity, in accordance with Article 6.1.f) of the GDPR. However, when the use of the service involves the installation of cookies or similar technologies that are not strictly necessary, the provisions of the Cookie Policy will apply, and, where applicable, the user's consent will be obtained.

The use of Google reCAPTCHA may involve international data transfers, particularly when Google group entities located outside the European Economic Area are involved. In such cases, these transfers will be carried out based on the safeguards provided for in applicable regulations, including, where applicable, the Adequacy Decision relating to the EU-U.S. Data Privacy Framework, Standard Contractual Clauses approved by the European Commission, or other legally valid mechanisms.

You can find more information about how Google processes data in its Privacy Policy and in the specific information about its services, available at: https://policies.google.com/privacy

12. Safety information for safe navigation

Always use an up-to-date browser. Also, ensure your operating system is up-to-date. If applicable, check the apps and programs you use most frequently. Most modern browsers update automatically, either transparently to the user or through notifications that require approval. These updates are often avoided because they seem tedious, but they typically include patches that fix minor security vulnerabilities. We also recommend configuring your add-ons and extensions to update automatically. Furthermore, make sure you install these add-ons from trusted sources.

It is advisable to disable plugins such as Adobe Flash and Java for unfamiliar services and websites. Click-to-run mechanisms or the use of certain extensions can facilitate this task. It is also recommended to disable JavaScript when browsing unfamiliar websites.

It is advisable to review your browser's security and privacy settings. Browsers currently offer useful features such as: not accepting third-party cookies, blocking pop-ups, preventing password synchronization, disabling autofill, deleting temporary files and cookies when closing the browser, blocking geolocation, filtering ActiveX controls, and more.

It is recommended to use the https protocol. This means that the information between your browser and the server will travel encrypted end-to-end. However, it is important to verify that certificates issued by “https” services handling sensitive information have been issued by a trusted entity. Any errors or alerts generated by the browser as a result of certificate validation (for example, self-signed certificates) should be carefully reviewed. Be suspicious if the beginning of the internet address is not “https”. And in any case, keep in mind that the padlock icon in the browser does not guarantee security: the padlock only serves to indicate that communication to the web server is encrypted and that they have paid for it, but it has nothing to do with whether the website is legitimate or a scam.

Take the time to configure the cookies for the website you are visiting. In principle, correctly configured cookies should allow you to disable them, and they should not load automatically (except for essential cookies) under any circumstances.

Protect your passwords; do not reveal them to third parties, either in writing or verbally. Change your passwords regularly and never respond to password requests received via email. Use combinations of numbers, letters, and symbols for your passwords. Do not store passwords by default through your browser and use more secure tools for password management (for example, password managers that implement a robust encryption system). If you choose to use your browser, it is important to use a master key to encrypt the credential repository.

-Consider using extensions or add-ons that implement functionalities not included in the browser. For example, those that improve privacy while browsing or that block, as much as possible, ads, banners, and certain tracking techniques used by third parties.

We recommend not trusting unknown Wi-Fi networks. When our connections fail, desperation leads us to search for and connect to Wi-Fi networks of dubious origin and legitimacy, presented as free. These fraudulent networks can compromise your devices, so you should avoid them.

-It is also important to log out when we have finished browsing, especially if we have done so through a public computer.

13. Control Authority

We trust we can resolve any questions or concerns you may have regarding your personal information. However, if you wish to file a complaint with the competent authority, you have the right to do so. In Spain, the highest authority for data protection is the Spanish Data Protection Agency (AEPD). Its website is accessible at https://www.aepd.es/es and its telephone number is +34 91 266 35 17.

14. Specifics regarding the Whistleblowing Channel

This Website may include a link to the internal information channel or whistleblowing channel enabled by the Owner Entity, managed through the Factorial platform. The purpose of this channel is to allow the reporting of potential irregularities, regulatory non-compliance, legal infringements, or conduct contrary to the entity's code of ethics or internal regulations, in compliance with applicable whistleblower protection laws. It also allows the reporting party to be kept informed regarding their report, to request additional information related to it, and to manage legal responsibilities. The personal data processed through this channel may include the whistleblower's identification and contact information, should they choose to identify themselves, data relating to the individuals affected by the report, the reported facts, supporting documentation, and any other information necessary for the processing, investigation, and resolution of the report received. The legal basis for processing will be compliance with a legal obligation applicable to the entity, specifically Law 2/2023 of February 20, regulating the protection of individuals who report regulatory infringements and combating corruption. Factorial may act as a technology provider or data processor, in accordance with the corresponding regulatory agreement, processing the data only following documented instructions from the Data Controller and applying the required security and confidentiality measures. The data will be processed confidentially and only by those authorized to manage the channel, and will be retained for the time necessary to decide whether to initiate an investigation and, subsequently, for the legally applicable periods, specifically a maximum of three months after notification of the irregularity. In any case, the internal information channel must be used in good faith and for legitimate purposes, avoiding manifestly false, abusive, or unrelated communications.

15. Specifics regarding the Gift Certificate

To the extent that the buyer provides personal data of a third party as the recipient of the gift voucher, such as name, surname, telephone number, email address, or other contact information, they declare under their own responsibility that such data is adequate, relevant, and limited to what is necessary for managing the gift, and that they have a sufficient legal basis for communicating it to the hotel. In particular, the user must have previously informed the recipient about the communication of their data to the hotel and, where applicable, have their consent or authorization to provide such data for the purpose of issuing, communicating, delivering, or allowing the redemption of the gift voucher. The user agrees not to enter specially protected data, sensitive information, health data, third-party bank details, identification documents, intimate comments, or any other information that is not strictly necessary for managing the gift voucher. The hotel will process the recipient's data only for the stated purpose, without using it to send its own marketing communications unless the recipient has given their specific consent or there is another valid legal basis.

16. Updates to this Privacy Policy

This data controller reserves the right to modify this privacy policy to adapt it to changing legal situations or in the event of modifications to our business activities or significant changes that affect the processing of personal data. However, this applies only to this privacy policy. Nevertheless, if user consent is required, changes will only be made with the user's authorization. Users are advised to regularly review the content of this Privacy Policy.

Give a stay