This privacy policy is in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council, of the 27th of April, 2016, concerning the protection of natural persons with regard to the processing of personal data and free movement of these data (RGPD), to Organic Law 3/2018, of the 5th of December, Protection of Personal Data and digital rights guarantee (LOPDGDD), as well as in what is not contrary to the regulations indicated, to the Law Organic 15/1999, Protection of Personal Data (LOPD) and its development regulations, and/or those that could replace or update in the future.

Our organisation is committed to the privacy of your personal data. The personal data provided are necessary to provide our services and are processed in a lawful, fair and transparent way, ensuring adequate security of them, including protection against unauthorised or illegal processing and against loss, destruction or accidental damage through the application of technical and organisational measures.

In this document we want to offer you, in a transparent and loyal way, all the necessary information related to the processing of your personal data that this organisation makes.

I.- RESPONSIBLE FOR THE PROCESSING

 

IDENTITY: HOTEL NOGUERA MAR, S.L.

C.I.F./N.I.E./PASSPORT.: B54011457

ADDRESS: C/ LLAC MAJOR, 3, 03700 DENIA (ALICANTE)

TELEPHONE: 966475650

E-MAIL: info@nogueramarhotel.com

II.- RECIPIENTS OF THE PERSONAL DATA

 

  1. The personal data provided shall not be subject to any transfer unless it is stated specifically in the specific
  2. Optionally, for the contracting of computing cloud services and/or services for the sending of emails, as well as related services, the personal data can be:

–           Transferred to businesses for digital services located within the European Economic Area (EEA) or,

–            Transferred to businesses for digital services located outside the EEA under the protection of the Privacy Shield as they count on means of protection sufficient to guarantee the security of personal data. More information available following this link: https://www.privacyshield.gov/welcome

  1. Optionally, to administrations and other organisations when they are required in compliance with legal

III.- LEGAL BASIS FOR PROCESSING YOUR PERSONAL DATA

 

In each case of processing of personal data collected concerning yourself, we will inform you of the legal basis that legitimises the processing of your personal data.

IV.-  RIGHTS RIGHT TO ACCESS

The right to obtain confirmation of whether or not we are proccessing personal data concerning you, or not, and, in such case, right of access to personal data and the following information: the purposes of the processing, the categories of personal data in question, the recipients or the categories of recipients to whom the data were communicated or will be communicated. personal, period of conservation or the criteria used to determine this term, the existence of the right to request from the responsible the rectification or suppression of personal data or the limitation of the processing of personal data relative to the interested party or to oppose such processing, the right to present a claim before the Spanish Agency for Data Protection (AEPD), the existence, where appropriate, of automated decisions, including the preparation of profiles, when data is transferred to third countries the right to be informed of the appropriate guarantees applied.

RIGHT TO RECTIFICATION

 

You have the right to request the rectification of your personal data if these are innaccurate, including the right to complete data that is incomplete. We must bear in mind that by providing personal data by any means, guarantees that they are true and accurate and agrees to notify us of any change or modification thereof. Therefore, any damage caused due to a communication of erroneous, inaccurate or incomplete information in the forms of the web, will be the exclusive responsibility of the interested party.

RIGHT TO SUPPRESSION

 

It is the right to request the suppression of your personal data when, among other assumptions, they are no longer necessary for the purpose for which they were collected, or they are being processed differently or you withdraw the consent. It must be borne in mind that the suppression will not proceed when the processing of personal data is necessary, among other assumptions, for compliance with legal obligations or for the formulation, exercise or defense of claims.

RIGHT TO LIMITATION

 

You have the right to request that we limit our processing of your personal data, which means that in certain cases you can ask us to temporarily suspend the processing of your personal data or that we keep them beyond the necessary time when you may need it.

RIGHT TO WITHDRAW CONSENT

 

It is the right to withdraw the consent you have provided by checking “I have read and accept the privacy policy” at any time and as specified in the corresponding section “Exercise of rights” or in the specific processing of commercial communications or Newsletter. It must be borne in mind that this right will not be effective if, among other cases, the processing of personal data is necessary for the fulfillment of a legal obligation, the execution and maintenance of a contractual relationship, or for the formulation, exercise or the defense of claims. Likewise, the withdrawal of consent will not have retroactive effects, it will not affect the legality of the processing based on the consent prior to its withdrawal.

RIGHT TO PORTABILITY

 

It is the right to receive the personal data that concern you and that you have given us, in a structured format, of common use and mechanical reading, and to transmit them to another

responsible, as long as: the processing is based on your consent and is carried out by automated or computerized media.

RIGHT TO OPPOSITION

 

You have the right to oppose the processing of your personal data on the basis of our own legitimate interest. We will not continue processing the personal data unless we can show compelling legitimate motive for this which overrules your interests, rights and liberties, either for the formulation, the exercising or defence of grievances.

RIGHT TO FILE A CLAIM WITH A CONTROL AUTHORITY

 

If you suspect that we are processing your personal data incorrectly, you can contact us or you also have the right to file a claim with the Spanish Data Protection Agency (AEPD):

https://www.agpd.es/portalwebAGPD/index-ides-idphp.php

EXERCISING OF THESES RIGHTS

 

You can exercise your rights by letter to the postal address indicated above or by e-mail info@nogueramarhotel.com, attaching, in both cases, a copy of your NIF/NIE/Passport or similar document.

V.- SECURITY MEASURES

The responsible person implements appropriate technical and organisational measures to ensure the confidentiality, integrity and availability of the data.

VI.- PERSONAL DATA PROCESSING.

– GENERAL PROVISIONS

Personal data requested in each of the specific processing operations are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed, thereby complying with the principle of data minimisation.

Personal data requested in each of the specific processing operations are strictly necessary, and refusal to provide them would mean that the requested service could not be provided.

The communication of personal data provided for in each of the specific processing operations is in some cases necessary for the performance and maintenance of a contract and in other cases for compliance with a legal obligation applicable to the responsible party.

– BASIC PROCESSING

CONTACT FORM

Personal data provided in the contact form will be used solely to respond to queries or requests for information and to manage the relationship arising from the query.

The legal basis that legitimises the processing of personal data is the express consent given by ticking ‘I have read and accept the privacy policy’.

Data will not be transferred to third parties, except where legally required or when necessary for the proper provision of the service.

Personal data will be kept for a period of two years from the moment it ceases to be processed, without prejudice to the exercise of your rights as a data subject, unless there is a contractual or legal relationship that requires it to be kept for longer.

BOOKING FORM

Personal data will be processed to manage online reservations, your payments, any complaint or claim about the services provided, identify and validate your legal age to contract, as well as for and, where appropriate, the formulation, exercise or defense of claims

The legal basis that legitimates the processing of personal data is the express consent when marking “I have read and accept the privacy policy”.

As a necessary contractual requirement, personal data will be passed on to third party companies for the provision of consultancy services to the responsible party. In compliance with legal obligations, personal data will be disclosed to official bodies necessary for the proper fulfilment of the order. In addition, and in some cases, they may also be disclosed to online payment service providers.

Personal data will be kept as long as the consent is not withdrawn, unless they should be kept for the maintenance of the relationship between the parties or during the years necessary for compliance with legal obligations.

COMMERCIAL COMMUNICATIONS OR NEWSLETTER FORM

Personal data collected in the context of subscribing to the newsletter will be processed to send information, news, promotions or related content, manage subscriptions, preferences and user cancellations, through various means such as WhatsApp, email, telephone or SMS. It should be noted that this type of data processing may involve analysing the profile of the data subject in order to determine their preferences and thus be able to send them information that is more suited to their interests.

The legal basis that legitimises the processing of personal data is the express consent given in advance by ticking ‘I have read and accept the privacy policy’.

Data is obtained directly from the data subject via the newsletter subscription form or direct contact by email or telephone.

No data is obtained from third parties without express consent.

You can request to unsubscribe from this type of processing, depending on the means used, as follows:

Data will not be transferred to third parties, except where legally required. However, certain service providers acting as data processors, such as web hosting services, newsletter delivery tools and IT support, may have access to your data, always under a contract that guarantees confidentiality and compliance with current regulations. If WhatsApp is used, as a necessary contractual requirement, personal data will be transferred to WhatsApp Ireland Limited, which is located within the EEA.

International data transfers are made by GOOGLE, LLC. when using the GMAIL email application. Data processors: IT services.

Personal data provided for subscription to our newsletter will be kept for as long as the user maintains their subscription. In the event of cancellation or revocation of consent, your data will be deleted unless there are legal obligations that require its retention.

DIGITAL ASSISTANT – “CHATBOT” or “ONLINE CHAT”

In the event that this website uses online chat software, provided as a self-service tool to offer users an adequate and quick response to common questions and to improve consumer service for the benefit of users visiting the website, the following data will be processed during the conversation with the “chatbot”: the IP address and other personal data entered in the chatbot conversation function.

The collected data will not be used to personally identify the website visitor and will not be combined with personal data about the pseudonymous user, unless personal data are voluntarily provided when using the online chat.

The legal basis for this processing is established in Article 6(1)(f) of the GDPR.

ONLINE CHECK-IN

The data provided through the booking software and the digital check-in process include identification data, an image of the identity document, contact details, and booking information. The purpose of processing this data is to manage the reservation, carry out the digital check-in process by verifying the guest’s identity through capturing an image of the identity document, comply with the legal obligations applicable to the establishment—especially those relating to guest identification and communication of data to the competent authorities when legally required—and ensure the security of the facilities and individuals.

The legal basis that legitimizes the processing is the data subject’s consent by clicking “I have read and accept the privacy policy.” The processing of personal data is also based on the performance of a contract or the application of pre-contractual measures, compliance with legal obligations applicable to the controller, and the legitimate interest of the controller in ensuring security and preventing fraud.

The data will be retained only for the strictly necessary period to fulfill the purpose for which they were collected: the image of the identity document used for check-in will be automatically deleted at the time of the guest’s departure. The remaining personal data will be retained for the legally established periods or for as long as legal liabilities may arise. Once these periods have expired, the data will be securely deleted.

Personal data will not be disclosed to third parties, except where required by law or when necessary to fulfill the described purpose (e.g., competent authorities).

Where technological service providers act as data processors, it will be ensured that they provide the security measures and guarantees required by current regulations.

Data will not be transferred to third countries unless required by the service provider used and provided that appropriate safeguards exist.

The data controller applies appropriate technical and organizational measures to ensure the security of personal data and to prevent loss, alteration, unauthorized access, or disclosure, including encryption and access control to the system.