PRIVACY – DETAILED INFORMATION
The only legally binding and valid version of this Privacy Policy is the original Spanish version, which is available at: https://ecompliancegrc.com/privacy_policies/6984836d4241a6001fef556d
The Privacy Policy forms part of the General Terms and Conditions governing this Website.
Who is responsible for processing your data?
AMO HOLIDAY, S.L. – BENALMÁDENA PALACE
Tax ID (CIF): B91086272
Address: Camino de Gilabert s/n, Postcode 29650, Benalmádena Costa.
Telephone: +34 952 964 958
Email: direccion@amo-hotels.com
You may contact us by any means to communicate with us.
We reserve the right to modify or adapt this Privacy Policy at any time. We recommend that you review it periodically. If you have registered and access your account or profile, you will be informed of any changes.
+ WEBSITE OR EMAIL CONTACTS
What data do we collect through the Website?
We may process your IP address, the operating system or browser you use, and even the duration of your visit, anonymously. If you provide us with your details through the contact form, you will be identified so that we can contact you if necessary.
For what purposes will we process your personal data?
- To answer your queries, requests or enquiries.
- To manage the requested service, respond to your request or process your enquiry.
- To provide information by electronic means relating to your request.
- To send commercial information or information about events by electronic means, with your express authorisation.
- To carry out analyses and improvements to the Website, our products and our services, and to improve our commercial strategy.
What is the legal basis for processing your data?
Acceptance and consent of the data subject: where it is necessary to complete a form and click the submit button in order to make a request, doing so necessarily implies that you have been informed and have expressly given your consent to the content of the clause attached to that form or to the acceptance of this Privacy Policy.
We remind you that you may withdraw your consent at any time.
All our forms identify mandatory fields with the symbol (*). If you do not complete those fields or do not tick the checkbox accepting the Privacy Policy, the information cannot be sent.
The wording is usually as follows:
"□ I am over 14 years of age and I have read and accept the Privacy Policy."
+ NEWSLETTER CONTACTS
What data do we collect through the newsletter?
The Website allows you to subscribe to the Newsletter by providing your email address, to which it will be sent. We will only store your email address in our database and will send you periodic emails until you unsubscribe or we stop sending emails.
The Newsletter may contain a web beacon, which statistically confirms whether you have opened it, at what time and how many times. This enables us to analyse the best sending times and what interests you. We will not obtain personal information about you other than your email address. Furthermore, the mailing application is based in the USA, and there may be an international transfer of data to servers located in that country. You will always have the option to unsubscribe from any communication.
For what purposes will we process your personal data?
- To manage the requested service.
- To provide information by electronic means relating to your request.
- To send commercial information or information about events by electronic means, provided that express authorisation has been given.
- To analyse and improve our mailings in order to improve our commercial strategy.
What is the legal basis for processing your data?
Acceptance and consent of the data subject: when you subscribe, you must tick the relevant checkbox and click the submit button. By doing so, you necessarily acknowledge that you have been informed and have expressly consented to receiving the Newsletter.
We remind you that you may withdraw your consent at any time.
If you do not tick the checkbox accepting the Privacy Policy, the information cannot be sent.
The wording is usually as follows:
"□ I am over 14 years of age and I have read and accept the Privacy Policy."
+ CUSTOMERS – GUESTS
For what purposes will we process your personal data?
- To formalise your reservation in person, through our website or through our app, in order to combat the coronavirus and save you time during Check-in.
- To manage and collect payment for your stay at the hotel and to manage and improve quality.
- To provide information by electronic means relating to your request.
- Loyalty programmes and the sending of commercial information according to your profile. We keep the date of birth or anniversary of certain recurring guests in order to surprise them as a Hotel loyalty measure.
- Commercial information or information about events by electronic means, provided that express authorisation has been given.
- To manage the administrative, communication and logistics services carried out by the Controller.
- To carry out the corresponding transactions. Billing and declaration of the appropriate taxes. Control and debt recovery procedures. Exercise of the legal actions to which we are entitled.
- Management of the entertainment service, including the processing of special categories of children's data when provided by their parents for medical reasons, in order to safeguard the health and well-being of the child. Monitoring allergies and other issues that must be taken into account during activities.
- Incident assistance services relating to your stay at our establishment, in accordance with our quality policies.
- To verify the validity of the card or carry out its bank pre-authorisation, guarantee the reservation by making the corresponding charge, collect payment in accordance with the reservation and cancellation conditions, as well as payment for the costs of the stay, even after the stay has ended.
- To guarantee payment of all expenses arising from the stay, even after check-out.
- Voluntary quality surveys to improve our services.
- To provide free travel cancellation insurance for guests with a non-refundable reservation.
What is the legal basis for processing your data?
The legal basis is:
- Performance of the contract in order to provide our services.
- Compliance with the Controller's legal obligations.
- Consent of the data subject.
- Legitimate interest in protecting public health in general, and the health of our guests in particular.
We remind you that you may withdraw your consent at any time.
+ SUPPLIERS
For what purposes will we process your personal data?
- To provide information by electronic means relating to your request.
- To send commercial information or information about events by electronic means, provided that express authorisation has been given.
- To manage the administrative, communication and logistics services carried out by the Controller.
- To carry out the corresponding transactions. Billing and declaration of the appropriate taxes. Control and debt recovery procedures.
What is the legal basis for processing your data?
The legal basis is the acceptance of a contractual relationship or, failing that, your consent when contacting us or offering us your products through any channel.
+ SHAREHOLDERS
For what purposes will we process your personal data?
- Organisation of the actions necessary to achieve the company's corporate purposes.
- Internal management and legal compliance.
- Convening shareholders' meetings.
- Carrying out the corresponding transactions.
- Declaration of the appropriate taxes.
What is the legal basis for processing your data?
The legal basis is contractual, namely the acceptance of a contract for the purchase and sale of shares or similar, or participation in the incorporation of the company.
+ SOCIAL MEDIA CONTACTS
For what purposes will we process your personal data?
- To answer your queries, requests or enquiries.
- To manage the requested service, respond to your request or process your enquiry.
- To interact with you and create a community of followers.
What is the legal basis for processing your data?
Acceptance of a contractual relationship within the relevant social network environment and in accordance with its Privacy Policies:
How long will we keep your personal data?
We can only consult or delete your data in a restricted manner because you have a specific profile. We will process your data for as long as you allow us by following us, being our friend or clicking "Like", "Follow" or similar buttons.
Any rectification of your data or restriction of information or publications must be made through your profile or user settings on the relevant social network.
+ VIDEO SURVEILLANCE
For what purposes will we process your personal data?
- Video surveillance of our facilities.
- Monitoring of our employees.
- Monitoring of service quality.
- On certain occasions, the recordings may be disclosed to Courts and Tribunals for the exercise of legitimate legal actions.
What is the legal basis for processing your data?
The unequivocal consent of the data subject when entering our premises after viewing the information sign indicating that the area is under video surveillance.
The Controller's legitimate interest.
+ JOB APPLICANTS
For what purposes will we process your personal data?
- To organise recruitment processes for the hiring of employees.
- To invite you to job interviews and assess your application.
- If you have given us your consent, we may keep your CV for future recruitment processes.
- If you have given us your consent, we may disclose it to collaborating or affiliated companies for the sole purpose of helping you find employment.
- We may send your data to other hotels if you authorise us to do so.
What is the legal basis for processing your data?
The legal basis is your unequivocal consent, given when you provide us with your CV and receive and sign the information relating to the processing activities that we will carry out.
+ WHISTLEBLOWING CHANNEL
For what purposes will we process your personal data?
- Internal detection of possible criminal and administrative offences affecting the legal entity and compliance with the Company's Code of Conduct and Compliance Policies.
- Management of reports. The whistleblower's data may be processed anonymously.
What is the legal basis for processing your data?
- Public interest mission or exercise of official authority.
- Compliance with a legal obligation.
+ PREVENTION OF CORONAVIRUS CONTAGION
For what purposes will we process your personal data?
- Protection of customers and employees.
- Temperature measurement for virus containment purposes. Only the temperature will be viewed, and there will never be any negative consequences for users.
What is the legal basis for processing your data?
It is a legal obligation arising from Occupational Risk Prevention regulations.
There is also a Public Interest in protecting the vital interests of individuals and in controlling epidemics and their spread.
Do we include personal data of third parties?
No. As a general rule, we only process data provided by the data subjects themselves. The only occasion on which you may include third-party data on our platform is when you complete the details of the guests staying in the room, for legal reasons.
If you provide us with third-party data, you must first inform those persons and obtain their consent. Otherwise, you release us from any liability arising from failure to comply with this requirement.
What about data relating to minors?
We process data relating to minors when they stay with their parents, just as we do for any other guest. We also process their data in connection with the entertainment service.
Will we communicate with you by electronic means?
Communications will only be sent in order to manage your request, provided that this is one of the contact methods you have given us.
If we send commercial communications, these will always have been previously and expressly authorised by you.
What security measures do we apply?
You can rest assured: we have adopted an optimum level of protection for the Personal Data we process and have implemented all the technical means and measures available to us, in accordance with the current state of technology, to prevent the loss, misuse, alteration, unauthorised access to, or theft of Personal Data.
To whom will your data be disclosed?
Your data will not be disclosed to third parties except where there is a legal or contractual obligation.
Specifically, your data will be disclosed to the Spanish Tax Agency (Agencia Estatal de Administración Tributaria) and to banks and financial institutions for the collection of payment for the service provided or product purchased, as well as to the processors necessary for the performance of the agreement.
If you access the portal by logging in with your Facebook or Google account, or subsequently link your access to our portal with those accounts, we will link the data from those platforms in order to manage your authentication. The data shared will be those displayed on your screen.
If you use the "Nearby Restaurants" option within the application, we may disclose your contact details to our partner restaurants, with whom we have agreements and special prices, so that you may benefit from them.
If you make a purchase or payment and choose to use an application, website, platform, bank card or any other online service, your data will be transferred to that platform or processed within its environment, always applying the highest security standards.
When instructed by us, our website development and maintenance company or hosting provider may access our website. They have signed a service agreement requiring them to maintain the same level of confidentiality and privacy as we do.
We use applications that may involve an International Transfer of Data to the United States. Such transfers will only take place to entities that have demonstrated compliance and have committed, through Standard Contractual Clauses (SCCs), to maintaining a level of protection and guarantees in accordance with the requirements of the applicable European data protection legislation, such as the General Data Protection Regulation, or where there is another legal basis permitting the international transfer.
When you book a non-refundable reservation, we provide you with cancellation insurance supplied by a third party. Therefore, you authorise us to transfer your personal data to FLEXMYROOM INSURETECH, S.L., registered in Benidorm (03503 – Alicante), Calle Gerona 13, Local CA 18, Tax Identification Number (CIF) B42687616, solely for the purpose of protecting your reservation by enabling you to benefit from the insurance services and products offered.
Only the data strictly necessary to activate the insurance will be transferred (name and surname, identity document number, postal address and contact details), in our mutual interest.
This entity will erase your personal data once the service has ended and the legally required retention periods have expired.
You may exercise your rights of access, rectification, erasure, restriction of processing, data portability, objection to processing and the right not to be subject to automated decisions directly with that entity by contacting:
datos@flexmyroom.com
What rights do you have?
You have the right:
- To know whether or not we are processing your personal data.
- To access your personal data.
- To request the rectification of your data if it is inaccurate.
- To request the erasure of your data if it is no longer necessary for the purposes for which it was collected or if you withdraw the consent previously given.
- To request the restriction of the processing of your data in certain circumstances, in which case we will only retain it in accordance with the applicable legislation.
- To data portability, whereby your data will be provided to you in a structured, commonly used and machine-readable format. If you prefer, we can send it directly to the new controller you designate. This right only applies in certain cases.
- To lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos) if you believe that we have not processed your request correctly.
- To withdraw your consent for any processing based on consent at any time.
If any of your personal data changes, we would appreciate it if you would inform us so that we can keep it up to date.
Would you like a form to exercise your rights?
We have forms available for the exercise of your rights. You may request them by email or, if you prefer, you may use the forms prepared by the Spanish Data Protection Agency or by third parties.
If we already have your contact details, or if you exercise your rights through a communication channel that we have previously used with you, or if identification was not required in order to provide you with the service, we will not ask you to provide your identity document.
If we do not have your contact details, if we have not previously communicated with you, or if we have doubts about whether you are actually the data subject, the forms must be signed using an electronic signature or accompanied by a copy of your identity document or another valid identification document. We will always endeavour to minimise the amount of data requested.
If someone is acting on your behalf, you must provide us with a copy of their identity document or ensure that they sign using their electronic signature.
The forms may be submitted in person, sent by post or by email to the Controller at the address indicated at the beginning of this document.
How long will we take to respond to your request to exercise your rights?
It depends on the right exercised, but no later than one month from receipt of your request, or two months if the request is particularly complex and we notify you that additional time is required.
Do we use cookies?
If we use cookies other than those that are strictly necessary, you may consult our Cookie Policy by following the corresponding link available from the home page of our website.
How long will we retain your personal data?
Your personal data will be retained for as long as you maintain a relationship with us.
Once the relationship has ended, the personal data processed for each purpose will be retained for the legally established retention periods, including the period during which a Judge or Court may require them in accordance with the applicable limitation periods.
The processed data will be retained until the aforementioned legal retention periods expire where there is a legal obligation to retain them, or, where no such legal period exists, until the data subject requests their erasure or withdraws the consent previously granted.
We will retain all information and communications relating to your purchase or to the provision of our services for the duration of the guarantees applicable to the products or services, in order to deal with any possible claims.
For each processing activity or category of data, we specify the corresponding retention period in the following table.
RETENTION PERIODS
File | Document | Retention |
Customers | Invoices | 10 years |
Customers | Forms and vouchers | 15 years |
Customers | Contracts | 5 years |
Human Resources | Payrolls, TC1, TC2, etc. | 10 years |
Human Resources | CVs | Until the end of the recruitment process and one additional year with your consent |
Human Resources | Severance compensation documents | 4 years |
Human Resources | Employment contracts | 4 years |
Human Resources | Temporary workers' records | 4 years |
Human Resources | Working time records | 4 years |
Human Resources | Employee personnel file | Up to 5 years after termination of employment |
Marketing | Databases or website visitors | For the duration of the processing |
Suppliers | Invoices | 10 years |
Suppliers | Contracts | 5 years |
Access control and video surveillance | Visitor register | 30 days |
Access control and video surveillance | Video recordings | 30 days blocked / 3 years until destruction |
Accounting | Accounting books and records | 6 years |
Accounting | Shareholders' agreements, board resolutions, articles of association, minutes, board regulations and delegated committees | 6 years |
Accounting | Financial statements and audit reports | 6 years |
Accounting | Records and documents relating to grants | 6 years |
Tax | Company tax administration and tax obligations | 10 years |
Tax | Dividend payments and withholding tax administration | 10 years |
Tax | Transfer pricing documentation | 18 years |
Tax | Intra-group pricing agreements | 8 years |
Health & Safety | Employees' medical records | 5 years |
Environment | Information on chemical or hazardous substances | 10 years |
Environment | Environmental permits | For the duration of the activity |
Environment | Environmental permits after closure | 3 years after closure / 10 years for criminal limitation periods |
Environment | Recycling and waste disposal records | 3 years |
Environment | Cleaning grants – supporting documents | 4 years |
Environment | Accident reports | 5 years |
Insurance | Insurance policies | 6 years (general rule) |
Insurance | Property damage claims | 2 years |
Insurance | Personal injury claims | 5 years |
Insurance | Life insurance | 10 years |
Purchases | VAT records of supplies of goods and services, intra-Community acquisitions, imports and exports | 5 years |
Legal | Intellectual and Industrial Property documents | 5 years |
Legal | Contracts and agreements | 5 years |
Legal | Permits, licences and certificates | 6 years after expiry / 10 years for criminal limitation periods |
Legal | Confidentiality and non-compete agreements | For the entire duration of the obligation or confidentiality commitment |
Data Protection | Personal data processing activities different from those notified to the Spanish Data Protection Agency | 3 years |
Data Protection | Employees' personal data stored on networks, computers, communication equipment, access control systems and internal management systems | 5 years |
Traveller Records | Traveller data communicated to the Police | 3 years |
Kommentare