Reset Password

Cancellation Policy

02.09.2021 by adminkaio

GDPR Privacy Policy

Last Updated: [DATE]

1. Who We Are

Data Controller: [FULL NAME OF PROPERTY OWNER]
Property Name: [PROPERTY NAME/VILLA NAME]
Address: [FULL ADDRESS OF PROPERTY IN SPAIN]
Tax ID/NIE: [SPANISH TAX IDENTIFICATION NUMBER]
Contact Email: [EMAIL ADDRESS]
Contact Phone: [+34 PHONE NUMBER]
Data Protection Officer (if applicable): [DPO CONTACT DETAILS OR «NOT APPOINTED»]

We are the owner of [PROPERTY NAME], a holiday accommodation property located in Spain. When you submit an inquiry or booking request through our website forms, you are providing your personal data directly to us as the data controller under applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD).

2. What Data We Collect

When you use our booking or contact forms, we collect the following personal information:

Essential Information:

  • Full name(s) of all guests
  • Email address
  • Phone number
  • Nationality
  • Passport or ID number details (for all guests)
  • Date of birth (for all guests)
  • Travel dates (arrival and departure)
  • Number of guests (adults, children, infants)

Additional Information (if provided):

  • Special dietary requirements
  • Health conditions or mobility needs
  • Purpose of stay (holiday, business, etc.)
  • Marketing preferences
  • Feedback and comments

Automatically Collected Data:

  • IP address
  • Browser type and version
  • Device information
  • Pages visited on our website
  • Time spent on our website
  • Referral source

3. Why We Process Your Data (Legal Basis)

We process your personal data for the following lawful purposes:

3.1. Legal Compliance (Article 6(1)(c) GDPR)

  • Tourist Registration: Spanish law (Order 194/2015) requires property owners to register all guests with local authorities (Policía Nacional/Guardia Civil) within 24 hours of arrival. This includes submitting full names, nationality, passport/ID numbers, and dates of stay.
  • Tax Compliance: We are required to maintain records of all rentals for Spanish tax authorities.

3.2. Contract Performance (Article 6(1)(b) GDPR)

  • To manage your booking request and confirm your reservation
  • To communicate with you regarding your stay
  • To provide you with access instructions and property information
  • To process payments and security deposits

3.3. Legitimate Interests (Article 6(1)(f) GDPR)

  • To ensure the security of our property and guests
  • For internal record keeping and accounting purposes
  • To prevent fraud and abuse of our booking system
  • To improve our services and guest experience

3.4. Consent (Article 6(1)(a) GDPR)

  • For marketing communications (if you opt-in)
  • For cookie usage beyond strictly necessary ones
  • For photography during your stay (if applicable)

4. Data Sharing

We only share your personal data when necessary and with appropriate safeguards:

4.1. Mandatory Sharing (Legal Requirement)

  • Local Police Authorities: We are legally required to share guest registration data (full names, nationality, passport/ID numbers, dates of stay) with Spanish police authorities within 24 hours of arrival.
  • Tax Authorities: We may need to share booking information with Spanish tax authorities upon request.

4.2. Service Providers (With Your Consent or as Necessary)

  • Payment Processors: If you pay online, we share payment details with our payment processor solely for transaction purposes. We use [PAYMENT PROCESSOR NAME] which complies with PCI DSS standards.
  • Local Representatives: We may share your contact details and arrival information with our local representative who will meet you for check-in and check-out.
  • Cleaning/Maintenance Service Providers: We may share your stay dates with service providers who prepare the property for your arrival.

4.3. International Transfers

Your data may be transferred outside the European Economic Area (EEA) when sharing with international payment processors. We ensure adequate safeguards are in place through Standard Contractual Clauses (SCCs) approved by the European Commission.

5. Data Retention Periods

We retain your personal data only for as long as necessary:

  • Guest Registration Data: 3 years (as required by Spanish law)
  • Booking Records & Financial Information: 5 years (for tax purposes under Spanish law)
  • Passport/ID Copies: Deleted within 1 month after your departure, unless required longer by authorities
  • Marketing Preferences: Until you withdraw consent
  • Website Analytics Data: 26 months (Google Analytics anonymized data)
  • Security Camera Footage (if applicable): 72 hours, unless needed for investigation

6. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right to Access: Obtain confirmation of whether we process your data and access to that data
  • Right to Rectification: Correct inaccurate or incomplete personal data
  • Right to Erasure («Right to be Forgotten»): Request deletion of your data when no longer necessary
  • Right to Restriction of Processing: Limit how we use your data in certain circumstances
  • Right to Data Portability: Receive your data in a structured, commonly used format
  • Right to Object: Object to processing based on legitimate interests or for direct marketing
  • Right to Withdraw Consent: Withdraw consent for processing where consent was the legal basis
  • Right to Lodge a Complaint: File a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos – AEPD)

To exercise these rights, contact us using the details in Section 1. We will respond within one month. We may request proof of identity before processing your request.

7. Security Measures

We implement appropriate technical and organizational measures to protect your personal data:

  • Encryption: All data transmitted through our website is encrypted using SSL/TLS
  • Access Controls: Only authorized personnel have access to your data
  • Secure Storage: Physical and digital security measures for data storage
  • Regular Updates: Security patches and updates for all systems
  • Staff Training: Regular training on data protection for all staff handling personal data
  • Breach Notification: We will notify you and relevant authorities within 72 hours of any data breach that poses a risk to your rights

8. Cookies and Tracking Technologies

Our website uses cookies and similar technologies:

8.1. Essential Cookies

  • Purpose: Enable basic website functionality and security
  • Retention: Session to 1 year
  • Examples: Login cookies, security cookies, load balancing cookies

8.2. Analytics Cookies

  • Purpose: Analyze website usage and improve user experience
  • Provider: Google Analytics (with IP anonymization enabled)
  • Retention: 26 months
  • Opt-out: Available through browser settings or Google’s opt-out tool

8.3. Marketing Cookies

  • Purpose: Show relevant advertisements and measure campaign effectiveness
  • Retention: 13 months
  • Opt-out: Available through cookie consent banner and browser settings

You can manage your cookie preferences through our cookie consent banner that appears on your first visit. You can also configure your browser to reject cookies, though this may limit website functionality.

9. Special Categories of Data

We may process special categories of data (sensitive data) only when necessary and with appropriate safeguards:

  • Health Information: Only collected when necessary for accessibility requirements or emergency situations
  • Biometric Data: Not collected unless necessary for security purposes with explicit consent
  • Religious/Philosophical Beliefs: Not collected unless relevant to dietary requirements

10. Children’s Data

Our services are not intended for children under 16 years of age. We do not knowingly collect personal data from children without parental consent. If you believe we have inadvertently collected data from a child, please contact us immediately so we can delete it.

11. Data Protection Impact Assessment

We have conducted a Data Protection Impact Assessment (DPIA) for our processing activities, particularly regarding:

  • Guest registration data sharing with police authorities
  • International transfers of payment data
  • Security camera usage (if applicable)
  • Large-scale processing of guest data

12. Changes to This Policy

We may update this Privacy Policy from time to time. The updated version will be posted on our website with the «Last Updated» date. We encourage you to review this policy periodically. Significant changes will be communicated via email if we have your contact details.

13. Contact Us

If you have any questions about this Privacy Policy, your data protection rights, or wish to exercise any of your rights, please contact us:

Data Controller: [FULL NAME OF PROPERTY OWNER]
Email: [EMAIL ADDRESS]
Phone: [+34 PHONE NUMBER]
Postal Address: [FULL ADDRESS IN SPAIN]

Spanish Data Protection Agency (AEPD):
C/ Jorge Juan, 6
28001 Madrid, Spain
www.aepd.es
(+34) 901 100 099

14. Registration with Spanish Data Protection Agency

Our data processing activities are registered with the Spanish Data Protection Agency (AEPD) under registration number: [AEPD REGISTRATION NUMBER].

15. Tourism Legal Requirements

In accordance with Spanish tourism regulations (Decree 194/2015), we are registered as a tourist accommodation with registration number: [TOURIST ACCOMMODATION REGISTRATION NUMBER].

All guest data collected for police registration purposes is processed exclusively for compliance with Spanish law and is not used for any other purpose without your explicit consent.

This Privacy Policy is provided in both English and Spanish. In case of any discrepancy between the versions, the Spanish version shall prevail for legal purposes in Spain.