Privacy Policy

PRIVACY POLICY

1. DATA CONTROLLER

In accordance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 on Personal Data Protection and the Guarantee of Digital Rights (LOPDGDD), you are hereby informed that the data controller responsible for the processing of personal data collected through this website is:
 
Trade Name: HOSTAL DON CARLOS
Legal Owner: Hostal Don Carlos C.B.
Tax Identification Number (NIF): E16599300
Registered Address: Calle Malgrats, 22, 07160 Peguera, Mallorca (Balearic Islands), Spain
Email Address: salvatore@hostaldoncarlos.com
Telephone: +34 690 02 94 83
Website: https://doncarlospeguera.com/

2. PERSONAL DATA WE COLLECT

We may collect the following categories of personal data:

 

Identification Data

 

  • Full name.
  • Email address.
  • Telephone number.

 

Enquiry and Booking Data

 

  • Information provided through website forms.
  • Content of messages sent by users.
  • Data required to manage availability requests or reservations.

 

Browsing Data

 

  • IP address.
  • Device type.
  • Browser information.
  • Statistical and website usage data.

3. PURPOSES OF PROCESSING

Personal data may be processed for the following purposes:

 

Responding to Enquiries and Requests

 

To manage information requests submitted through website forms, email or telephone.
 

Booking and Accommodation Management

 

To manage availability, reservations, communications related to guests’ stays, and the provision of requested accommodation services.
 

Compliance with Legal Obligations

 

To comply with administrative, tax, accounting, security and any other legal obligations applicable to the hospitality business.
 

Website Security

 

To prevent unauthorised access, fraud, security incidents, and misuse of the website.
 

Statistics and Service Improvement

 

To analyse website usage in order to improve the browsing experience, always in accordance with the applicable cookie settings and user consents.

4. LEGAL BASIS FOR PROCESSING

Personal data is processed on one or more of the legal grounds established in Article 6 of the GDPR:

 

Consent of the Data Subject

 

Where users voluntarily provide information through forms or expressly authorise specific processing activities.
 

Performance of a Contract or Pre-Contractual Measures

 

Where processing is necessary to manage reservation requests or to provide accommodation services.
 

Compliance with Legal Obligations

 

Where processing is required to comply with legal obligations applicable to the data controller.
 

Legitimate Interest

 

To ensure website security, prevent fraud and improve the services offered, provided that such interests do not override the rights and freedoms of the data subject.

5. DATA RETENTION PERIOD

Personal data will be retained:

 

  • For as long as a contractual or commercial relationship exists.
  • For the time necessary to respond to enquiries received.
  • For the periods required by tax, accounting and administrative regulations.
  • Until consent is withdrawn where processing is based on consent.
 
Once the applicable retention periods have expired, the data will be blocked where legally required and subsequently securely deleted.

6. DATA RECIPIENTS

As a general rule, personal data will not be disclosed to third parties unless required by law.

However, certain authorised recipients may have access to personal data, including:
 
  • Technology and web hosting providers.
  • IT maintenance service providers.
  • Service providers involved in the management of the establishment.
  • Public authorities and competent bodies where required by law.
 
All service providers processing personal data on behalf of the data controller shall act as data processors in accordance with Article 28 of the GDPR.

7. INTERNATIONAL DATA TRANSFERS

As a general rule, no international transfers of personal data are carried out.

 
However, certain technology providers used by the website may store or process information outside the European Economic Area (EEA).
 
In such cases, appropriate safeguards required by the GDPR will be implemented, including Standard Contractual Clauses approved by the European Commission or any other legally recognised transfer mechanism.

8. DATA SUBJECT RIGHTS

Users may exercise the following rights:
 
  • Right of access.
  • Right to rectification.
  • Right to erasure.
  • Right to object.
  • Right to restriction of processing.
  • Right to data portability.
  • Right to withdraw consent at any time.
 
To exercise these rights, a request may be sent to:
salvatore@hostaldoncarlos.com
 
The request should specify the right being exercised and proof of identity may be required where necessary.

9. COMPLAINTS TO THE SUPERVISORY AUTHORITY

If you believe that the processing of your personal data infringes applicable data protection legislation, you may lodge a complaint with the competent supervisory authority:
Spanish Data Protection Agency (AEPD)
C/ Jorge Juan, 6
28001 Madrid
Spain
https://www.aepd.es

10. SECURITY MEASURES

HOSTAL DON CARLOS implements appropriate technical and organisational measures to protect personal data against:

 

  • Accidental loss;
  • Destruction;
  • Unauthorised access;
  • Alteration;
  • Unlawful disclosure.
 
The measures implemented are reviewed periodically in accordance with the state of the art, technological developments and the risks associated with the processing activities.

11. CHILDREN'S DATA

The services provided through this website are not directed at children under the age of 14.

 

If a minor provides personal data without the authorisation of their legal representatives, such representatives may request its deletion by contacting the data controller.

12. CHANGES TO THIS PRIVACY POLICY

HOSTAL DON CARLOS may amend this Privacy Policy whenever necessary to adapt it to legislative changes, guidance issued by supervisory authorities, or modifications to the services offered.
 
The current version shall always be the one published on this website.