fbpx

PRIVACY

The website belonging to the Posada Terra Santa Boutique Hotel is the property of Luperon Investment S.L. and complies with the requirements established by Law 34/2002 of 11 July on Information Society Services and Electronic Commerce, and by the Royal Decree, Law 13/2012 of 30 March, as well as with the obligation to provide Information to the user established in Organic Law 15/1999 of 13 December on Protection of Personal Data.

 


PRIVACY POLICY – EXTENDED INFORMATION 

LAST AMENDED: 13/12/2019

The Privacy Policy forms part of the General Terms and Conditions governing the www.hiddenawayhotels.com website, together with the Cookies Policy and the Legal Notice.

HIDDEN AWAY HOTELS S.L. reserves the right to modify or amend this Privacy Policy at any time. We therefore recommend that you review it every time you access the website. In the case of users who have registered with the website and are logging in to their account or profile, at the time of log-in they will be informed in the event of substantial modifications having been made in terms of the processing of their personal data.

Who is responsible for the processing of your data?

The data that are collected or that you voluntarily supply to us via the website, whether in the course of browsing the website or that you provide to us in the contact forms, via email or over the phone, will be gathered and processed by the Entity Responsible for Processing, details of which are set out below:

HIDDEN AWAY HOTELS S.L. Spanish fiscal ID: B57676108

Address: C/ Venezuela, 4, 07014, Palma de Mallorca

Listed in the Mercantile Register of Palma de Mallorca, Volume 2433, Folio 106, Sheet 66229, inscription 1 dated 04 July 2013.

Contact at HIDDEN AWAY HOTELS S.L. for the protection of your personal data

C/ Venezuela, 4, 07014 Palma de Mallorca

Tel.: + 34 971 21 47 42

Email: info@hiddenawayhotels.com

If, for any reason, you wish to get in touch with us regarding any issue concerning your personal data or privacy (with our Data Protection Officer), you can do so via any of the means indicated above.

What data do we collect through the Website?

Simply by browsing the website, HIDDEN AWAY HOTELS S.L. will collect information relating to:

– IP address.

– Type of browser.

– Operating system.

– Length of time visiting or browsing the website.

Such information is stored using Google Analytics, and thus we refer you to the Google Privacy Policy, since it is the latter organisation that collects and processes the information concerned: http://www.google.com/intl/en/policies/privacy/

Similarly, the website includes the Google Maps utility, which can have access to your location, in the event that you allow this, with the goal of providing you with greater accuracy about the distance and/or routes to our premises. In this context, we refer you to the Privacy Policy relating to Google Maps, in order to find out the ways in which such data are used and processed: http://www.google.com/intl/en/policies/privacy/

The information that we process will not be related to a specific user and will be stored on our databases for the purpose of carrying out statistical analyses, improvements to the website, to our products and/or services and to help us improve our business strategy. The data will not be passed on to third parties.

User registration on the website/Form submission

In order to access certain services, such as booking, it is necessary for users to complete a form. To this end, a series of personal details will be requested in the registration form. These details are necessary and compulsory in order to complete the registration process. In the event of not completing the fields in question, the registration will not take place.

In this case, the browsing data will be linked to the user registration data, identifying the specific user who is browsing the website. It will thus be possible to customise the offer of products and/or service that in our judgement best suits the user.

The registration data of each user will be incorporated into the HIDDEN AWAY HOTELS S.L. databases, together with a record of the operations conducted by the user, and will be stored on such databases until such time as the registered user’s account is deleted. Once the account has been deleted, the information in question will be removed from our databases, storing any data relating to the transactions carried out separately for 10 years, without the information being accessed or altered, in order to comply with the legally-prevailing requirements. Data that is not linked to the transactions carried out will be retained unless consent is withdrawn, in which case they will be deleted immediately (always subject to the legal requirements).

The legal basis for the processing of your personal data is the execution of a contract between the parties.

In relation to the sending of messages and promotions by electronic means and responses to requests for information, the legal basis of the processing is the consent of the user.

The purposes of processing will be as follows:

a) Managing your access to the website.

b) Managing the purchase of the services offered to you via the website.

c) Keeping you informed about the handling and status of your requests, purchases and/or bookings.

d) Responding to your requests for information.

e) Managing all the utilities and/or services that the platform offers the user.

We hereby notify you that you may receive messages via email and/or by telephone for the purpose of informing you of possible issues, errors, problems and/or the status of your requests.

For the purpose of sending marketing messages, the explicit consent of the user will be requested at the time of registering. The user may withdraw the consent given by getting in touch with HIDDEN AWAY HOTELS S.L. via the channels set out above. In any event, each marketing communication will include the possibility of cancelling receipt of such messages, either by means of a link or an email address.

Newsletter subscription

The website enables users to subscribe to the HIDDEN AWAY HOTELS S.L. Newsletter. This requires that you provide us with an email address to which it can be sent.

Such information will be stored on a HIDDEN AWAY HOTELS S.L. database, where it will remain until such time as the subscriber wishes to end the subscription or, if applicable, HIDDEN AWAY HOTELS S.L. stops issuing the Newsletter.

The legal basis for the processing of such personal data is the explicit consent provided by all those interested in subscribing to this service when they tick the box provided for that purpose.

The data collected from the emails will only be processed and stored for the purposes of sending the Newsletter to those users who request it.

For the purposes of sending the Newsletter, the explicit consent of the user will be requested at the time of subscribing, by ticking the box provided to this end. In this regard, users may withdraw the consent provided by getting in touch with HIDDEN AWAY HOTELS S.L. using any of the channels indicated above. In any event, included with each Newsletter will be the opportunity to unsubscribe, whether via a link or an email address.

If you belong to one of the following categories, consult the dropdown information:

+ WEBSITE AND EMAIL CONTACTS 

For what purposes do we process your personal data?

  • Answering your queries, requests and questions.
  • Managing the service requested, answering your query or processing your request.
  • Information by electronic means relating to your request.
  • Marketing and event information by electronic means, provided explicit authorisation exists.

What is the legal basis for the processing of your data?

The acceptance and consent of the interested party: In those cases where in order to make a request it is necessary to complete a form and click a button to send, doing this will necessarily entail that you have been informed and that you have expressly provided your consent to the content of the clause appended to the form or the acceptance of the privacy policy.

All our forms are accompanied by a checkbox with the following wording, in order for the information to be sent: “□ I have read and accept the Privacy policy.”

+ CUSTOMERS

For what purposes do we process your personal data?

  • Drawing up quotes and subsequently following them up via messages between both parties.
  • Information by electronic means relating to your request.
  • Marketing and event information by electronic means, provided explicit authorisation exists.
  • Managing the administrative, communications and logistical services carried out by the responsible entity.
  • Carrying out any transactions that arise.
  • Billing and the declaration of relevant taxes.
  • Management of monitoring and reimbursement.

What is the legal basis for the processing of your data?

The legal basis is your consent and fulfilment of a contract.


+ SUPPLIERS.

For what purposes do we process your personal data?

  • Information by electronic means relating to your request.
  • Marketing and event information by electronic means, provided explicit authorisation exists.
  • Managing the administrative, communications and logistical services carried out by the responsible entity.
  • Billing.
  • Carrying out any transactions that arise.
  • Billing and the declaration of relevant taxes.
  • Management of monitoring and reimbursement.

What is the legal basis for the processing of your data?

The legal basis is the acceptance of a contractual relationship, or in its absence your consent upon contacting us and offering us your products by some channel or other.

+ SOCIAL MEDIA CONTACTS

For what purposes do we process your personal data?

  • Answering your queries, requests and questions.
  • Managing the service requested, answering your query or processing your request.
  • Building relationships with you and creating a community of followers.

What is the legal basis for the processing of your data?

The acceptance of a contractual relationship in the context of the social media network concerned, and in accordance with its privacy policies:

Facebook: http://www.facebook.com/policy.php?ref=pf

Instagram: https://help.instagram.com/155833707900388

Twitter: http://twitter.com/privacy

LinkedIn: http://www.linkedin.com/legal/privacy-policy?trk=hb_ft_priv

Pinterest: https://about.pinterest.com/es/privacy-policy

WhatsApp: https://www.whatsapp.com/legal/#privacy-policy

How long are we going to keep the personal data?

We can only consult or deregister your data in a restricted way by having a specific profile. We will process the data for as long as you continue following us, friending us or clicking “like”, “follow” and similar buttons.

You will need to carry out any amendment to your data or restriction of information or publications using the profile or user settings in the social media account.

+ VIDEO SURVEILLANCE

For what purposes do we process your personal data?

  • Video surveillance of our facilities.
  • Monitoring our employees.
  • The data may occasionally be handed over to courts and tribunals to enable due process to be carried out.

What is the legal basis for the processing of your data?

The clear consent of the interested party on entering our premises after seeing the sign informing them of the video surveillance area.

+ EMPLOYMENT APPLICANTS

For what purposes do we process your personal data?

  • Organisation of recruitment processes for the hiring of staff.
  • Arranging job interviews and evaluating your candidacy.
  • If you have given us your consent, we may pass your data on to partners or related entities, with the sole objective of helping you find work.

What is the legal basis for the processing of your data?

The legal basis is your clear consent, having sent us your CV and received and signed information relating to the processing that we intend to carry out.

How long are we going to keep the personal data?

The CV will be stored for a period of one year, after which, in the event that we have not contacted you, it will be deleted.

+ HR

For what purposes do we process your personal data?

  • Management of the employment relationship and the employee’s record.
  • Undertaking all the administrative, fiscal and accounting operations needed to comply with our contractual commitments, obligations in terms of employment regulations, Social Security, health and safety, taxation and accountancy.
  • Managing the payment of salaries through a financial entity.
  • Monitoring of working hours through an access control system using fingerprints/card (if applicable).
  • Management of the entity’s collective insurance / pension plan.
  • Carrying out training programmes, whether paid-for or otherwise.

What is the legal basis for the processing of your data?

The legal basis for the processing of your data is the execution of your employment contract. Fulfilment of the legal obligations involved. The consent of the interested party.

– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –

Do we include the personal data of third parties?

No, as a general rule we only process the data provided to us by the owners of that data. If you provide us with the data of third parties, you will need to inform and request the consent of such people beforehand, otherwise you exempt us from any liability for non-compliance with this requirement.

And the data of legal minors? 

We do not process the data of those under 14, so if you have not attained this age please do not provide them.

Do we send messages by electronic means?

  • They will only be sent to deal with your request, if it is one of the contact methods you have provided us with.
  • If we send marketing messages, they will have been explicitly authorised by you beforehand.

What security measures do we apply?

You can rest assured: we have instituted the utmost level of protection for the personal data that we process, and we have installed all the technical means and measures at our disposal, in accordance with the state of technology, to prevent the loss, misuse, alteration, non-authorised access and theft of the personal data.

To what extent will decision-making be automated?

HIDDEN AWAY HOTELS S.L. does not use totally automated decision-making processes to enter into, develop or terminate a contractual relationship with users. In the event that we should use such processes in a specific case, we will keep you informed and notify you of your rights in this regard if stipulated by law.

Will profiles be created?

In order to be able to offer you products and/or services in accordance with your interests and improve your user experience, we may create a “business profile” on the basis of the information supplied. Automated decisions will not however be taken on the basis of such profiles.

Which recipients will your data be passed on to?

Your data will not be passed on to third parties, barring legal obligation. Specifically, they will be passed on to the Spanish tax authorities (Agencia Estatal de la Administración Tributaria) and to banks and financial entities in order to charge for the service rendered or product purchased, as well as those responsible for the processing needed for the execution of the agreement.

In the case of a purchase or payment, if you choose an application, website, platform, bank card or any other online service, your data will be passed on to such a platform or will be processed in its environment with the utmost security at all times.

In the event that you have given us your consent to process your name and images and other information, related to the activity of HIDDEN AWAY HOTELS S.L., they will be released on the various HIDDEN AWAY HOTELS S.L. social media accounts and website.

International transfers.

In the event of it being necessary to undertake international transfers of data by HIDDEN AWAY HOTELS S.L., these will only be made to entities under the auspices of the US-European Union Privacy Shield agreement (more information: https://www.privacyshield.gov/welcome), to entities that have shown that they comply with the level of protection and guarantees in accordance with the parameters and requirements set out in the prevailing regulations in the data protection field, such as EU regulations, or when legal authorisation exists to carry out an international transfer.

What rights do you have? 

  • To know whether we are processing your data or not.
  • To access your personal data.
  • To request the amendment of your data if they are incorrect.
  • To request the deletion of your data if they are no longer necessary for the purposes for which they were collected or if you withdraw the consent you gave us.
  • To request that the processing of your data be limited, in some respects, in which case we will only retain them in accordance with the prevailing regulations.
  • To transfer your data, which will be given to you in a structured, commonly-used and machine-readable format. If you prefer, they can be sent to a new responsible entity of your nomination. Only valid in specific cases.
  • To submit a complaint to the Spanish Data Protection Agency, if you believe you have not been properly dealt with.
  • To withdraw your consent to any processing that you may previously have granted, at any time.

If your details change, we would be grateful if you could let us know to keep your data up to date.

Would you like a form to exercise your rights?   

  • We have forms for exercising your rights; request them by email or, if you prefer, you can use those drawn up by the Spanish Data Protection Agency or third parties.
  • These forms need to be signed electronically or be accompanied by a photocopy of your ID.
  • If you are acting on behalf of someone else, you should attach a copy of their ID, or get them to sign with their electronic signature.
  • The forms can be submitted in person, sent to us by post or email at the address of the entity responsible at the head of this text.

You have the right to submit a complaint to the Spanish Data Protection Agency, if you believe that your assertion of rights has not been appropriately dealt with.

The maximum period for resolution on the part of HIDDEN AWAY HOTELS S.L. is one month, starting from our effective receipt of your request.

You have the right to withdraw your consent at any time for any of the processing operations that you have consented to.

Do we process cookies?

If we use other types of cookie that are unnecessary, you will be able to consult the cookies policy by clicking on the link provided on the homepage of the website.

How long are we going to retain your personal data?

  • Your personal data will be retained for as long as you maintain a connection with us.
  • Once you sever such connections, the personal data processed for each purpose will be retained for the periods laid down in law, including the time that a court or tribunal may require them in light of the periods of prescription for court proceedings.
  • The processed data shall be retained for as long as the aforementioned legal periods remain in force, in the event of there being a legal retention obligation, or in the absence of such a legal period, until such time as the interested party requests their deletion or withdraws the consent granted.
  • We will maintain all the information and messages relating to your purchases and the rendering of our services as long as the guarantees of the products or services remain in force, to deal with possible complaints.