PRIVACY – DETAILED INFORMATION

 

The only legally binding and valid version of this Privacy Policy is the original Spanish version, which is available at: https://ecompliancegrc.com/privacy_policies/6984836d4241a6001fef556d 

 

The Privacy Policy forms part of the General Terms and Conditions governing this Website.

 

Who is responsible for processing your data?

AMO HOLIDAY, S.L. – BENALMÁDENA PALACE

Tax ID (CIF): B91086272

Address: Camino de Gilabert s/n, Postcode 29650, Benalmádena Costa.

Telephone: +34 952 964 958

Email: direccion@amo-hotels.com

You may contact us by any means to communicate with us.

We reserve the right to modify or adapt this Privacy Policy at any time. We recommend that you review it periodically. If you have registered and access your account or profile, you will be informed of any changes.

 

+ WEBSITE OR EMAIL CONTACTS

What data do we collect through the Website?

We may process your IP address, the operating system or browser you use, and even the duration of your visit, anonymously. If you provide us with your details through the contact form, you will be identified so that we can contact you if necessary.

For what purposes will we process your personal data?

What is the legal basis for processing your data?

Acceptance and consent of the data subject: where it is necessary to complete a form and click the submit button in order to make a request, doing so necessarily implies that you have been informed and have expressly given your consent to the content of the clause attached to that form or to the acceptance of this Privacy Policy.

We remind you that you may withdraw your consent at any time.

All our forms identify mandatory fields with the symbol (*). If you do not complete those fields or do not tick the checkbox accepting the Privacy Policy, the information cannot be sent.

The wording is usually as follows:

"□ I am over 14 years of age and I have read and accept the Privacy Policy."

 

 

+ NEWSLETTER CONTACTS

What data do we collect through the newsletter?

The Website allows you to subscribe to the Newsletter by providing your email address, to which it will be sent. We will only store your email address in our database and will send you periodic emails until you unsubscribe or we stop sending emails.

The Newsletter may contain a web beacon, which statistically confirms whether you have opened it, at what time and how many times. This enables us to analyse the best sending times and what interests you. We will not obtain personal information about you other than your email address. Furthermore, the mailing application is based in the USA, and there may be an international transfer of data to servers located in that country. You will always have the option to unsubscribe from any communication.

For what purposes will we process your personal data?

What is the legal basis for processing your data?

Acceptance and consent of the data subject: when you subscribe, you must tick the relevant checkbox and click the submit button. By doing so, you necessarily acknowledge that you have been informed and have expressly consented to receiving the Newsletter.

We remind you that you may withdraw your consent at any time.

If you do not tick the checkbox accepting the Privacy Policy, the information cannot be sent.

The wording is usually as follows:

"□ I am over 14 years of age and I have read and accept the Privacy Policy."

 

 

+ CUSTOMERS – GUESTS

For what purposes will we process your personal data?

What is the legal basis for processing your data?

The legal basis is:

We remind you that you may withdraw your consent at any time.

 

 

+ SUPPLIERS

For what purposes will we process your personal data?

What is the legal basis for processing your data?

The legal basis is the acceptance of a contractual relationship or, failing that, your consent when contacting us or offering us your products through any channel.

 

 

+ SHAREHOLDERS

For what purposes will we process your personal data?

What is the legal basis for processing your data?

The legal basis is contractual, namely the acceptance of a contract for the purchase and sale of shares or similar, or participation in the incorporation of the company.

 

 

+ SOCIAL MEDIA CONTACTS

For what purposes will we process your personal data?

What is the legal basis for processing your data?

Acceptance of a contractual relationship within the relevant social network environment and in accordance with its Privacy Policies:

How long will we keep your personal data?

We can only consult or delete your data in a restricted manner because you have a specific profile. We will process your data for as long as you allow us by following us, being our friend or clicking "Like", "Follow" or similar buttons.

Any rectification of your data or restriction of information or publications must be made through your profile or user settings on the relevant social network.

 

 

+ VIDEO SURVEILLANCE

For what purposes will we process your personal data?

What is the legal basis for processing your data?

The unequivocal consent of the data subject when entering our premises after viewing the information sign indicating that the area is under video surveillance.

The Controller's legitimate interest.

 

 

+ JOB APPLICANTS

For what purposes will we process your personal data?

What is the legal basis for processing your data?

The legal basis is your unequivocal consent, given when you provide us with your CV and receive and sign the information relating to the processing activities that we will carry out.

 

 

+ WHISTLEBLOWING CHANNEL

For what purposes will we process your personal data?

What is the legal basis for processing your data?

 

+ PREVENTION OF CORONAVIRUS CONTAGION

For what purposes will we process your personal data?

What is the legal basis for processing your data?

It is a legal obligation arising from Occupational Risk Prevention regulations.

There is also a Public Interest in protecting the vital interests of individuals and in controlling epidemics and their spread.

 

Do we include personal data of third parties?

No. As a general rule, we only process data provided by the data subjects themselves. The only occasion on which you may include third-party data on our platform is when you complete the details of the guests staying in the room, for legal reasons.

If you provide us with third-party data, you must first inform those persons and obtain their consent. Otherwise, you release us from any liability arising from failure to comply with this requirement.

 

What about data relating to minors?

We process data relating to minors when they stay with their parents, just as we do for any other guest. We also process their data in connection with the entertainment service.

 

Will we communicate with you by electronic means?

Communications will only be sent in order to manage your request, provided that this is one of the contact methods you have given us.

If we send commercial communications, these will always have been previously and expressly authorised by you.

What security measures do we apply?

You can rest assured: we have adopted an optimum level of protection for the Personal Data we process and have implemented all the technical means and measures available to us, in accordance with the current state of technology, to prevent the loss, misuse, alteration, unauthorised access to, or theft of Personal Data.

 

To whom will your data be disclosed?

Your data will not be disclosed to third parties except where there is a legal or contractual obligation.

Specifically, your data will be disclosed to the Spanish Tax Agency (Agencia Estatal de Administración Tributaria) and to banks and financial institutions for the collection of payment for the service provided or product purchased, as well as to the processors necessary for the performance of the agreement.

If you access the portal by logging in with your Facebook or Google account, or subsequently link your access to our portal with those accounts, we will link the data from those platforms in order to manage your authentication. The data shared will be those displayed on your screen.

If you use the "Nearby Restaurants" option within the application, we may disclose your contact details to our partner restaurants, with whom we have agreements and special prices, so that you may benefit from them.

If you make a purchase or payment and choose to use an application, website, platform, bank card or any other online service, your data will be transferred to that platform or processed within its environment, always applying the highest security standards.

When instructed by us, our website development and maintenance company or hosting provider may access our website. They have signed a service agreement requiring them to maintain the same level of confidentiality and privacy as we do.

We use applications that may involve an International Transfer of Data to the United States. Such transfers will only take place to entities that have demonstrated compliance and have committed, through Standard Contractual Clauses (SCCs), to maintaining a level of protection and guarantees in accordance with the requirements of the applicable European data protection legislation, such as the General Data Protection Regulation, or where there is another legal basis permitting the international transfer.

When you book a non-refundable reservation, we provide you with cancellation insurance supplied by a third party. Therefore, you authorise us to transfer your personal data to FLEXMYROOM INSURETECH, S.L., registered in Benidorm (03503 – Alicante), Calle Gerona 13, Local CA 18, Tax Identification Number (CIF) B42687616, solely for the purpose of protecting your reservation by enabling you to benefit from the insurance services and products offered.

Only the data strictly necessary to activate the insurance will be transferred (name and surname, identity document number, postal address and contact details), in our mutual interest.

This entity will erase your personal data once the service has ended and the legally required retention periods have expired.

You may exercise your rights of access, rectification, erasure, restriction of processing, data portability, objection to processing and the right not to be subject to automated decisions directly with that entity by contacting:

datos@flexmyroom.com

 

What rights do you have?

You have the right:

If any of your personal data changes, we would appreciate it if you would inform us so that we can keep it up to date.

 

Would you like a form to exercise your rights?

We have forms available for the exercise of your rights. You may request them by email or, if you prefer, you may use the forms prepared by the Spanish Data Protection Agency or by third parties.

If we already have your contact details, or if you exercise your rights through a communication channel that we have previously used with you, or if identification was not required in order to provide you with the service, we will not ask you to provide your identity document.

If we do not have your contact details, if we have not previously communicated with you, or if we have doubts about whether you are actually the data subject, the forms must be signed using an electronic signature or accompanied by a copy of your identity document or another valid identification document. We will always endeavour to minimise the amount of data requested.

If someone is acting on your behalf, you must provide us with a copy of their identity document or ensure that they sign using their electronic signature.

The forms may be submitted in person, sent by post or by email to the Controller at the address indicated at the beginning of this document.

 

How long will we take to respond to your request to exercise your rights?

It depends on the right exercised, but no later than one month from receipt of your request, or two months if the request is particularly complex and we notify you that additional time is required.

 

Do we use cookies?

If we use cookies other than those that are strictly necessary, you may consult our Cookie Policy by following the corresponding link available from the home page of our website.

 

How long will we retain your personal data?

Your personal data will be retained for as long as you maintain a relationship with us.

Once the relationship has ended, the personal data processed for each purpose will be retained for the legally established retention periods, including the period during which a Judge or Court may require them in accordance with the applicable limitation periods.

The processed data will be retained until the aforementioned legal retention periods expire where there is a legal obligation to retain them, or, where no such legal period exists, until the data subject requests their erasure or withdraws the consent previously granted.

We will retain all information and communications relating to your purchase or to the provision of our services for the duration of the guarantees applicable to the products or services, in order to deal with any possible claims.

For each processing activity or category of data, we specify the corresponding retention period in the following table.


RETENTION PERIODS

File

Document

Retention

Customers

Invoices

10 years

Customers

Forms and vouchers

15 years

Customers

Contracts

5 years

Human Resources

Payrolls, TC1, TC2, etc.

10 years

Human Resources

CVs

Until the end of the recruitment process and one additional year with your consent

Human Resources

Severance compensation documents

4 years

Human Resources

Employment contracts

4 years

Human Resources

Temporary workers' records

4 years

Human Resources

Working time records

4 years

Human Resources

Employee personnel file

Up to 5 years after termination of employment

Marketing

Databases or website visitors

For the duration of the processing

Suppliers

Invoices

10 years

Suppliers

Contracts

5 years

Access control and video surveillance

Visitor register

30 days

Access control and video surveillance

Video recordings

30 days blocked / 3 years until destruction

Accounting

Accounting books and records

6 years

Accounting

Shareholders' agreements, board resolutions, articles of association, minutes, board regulations and delegated committees

6 years

Accounting

Financial statements and audit reports

6 years

Accounting

Records and documents relating to grants

6 years

Tax

Company tax administration and tax obligations

10 years

Tax

Dividend payments and withholding tax administration

10 years

Tax

Transfer pricing documentation

18 years

Tax

Intra-group pricing agreements

8 years

Health & Safety

Employees' medical records

5 years

Environment

Information on chemical or hazardous substances

10 years

Environment

Environmental permits

For the duration of the activity

Environment

Environmental permits after closure

3 years after closure / 10 years for criminal limitation periods

Environment

Recycling and waste disposal records

3 years

Environment

Cleaning grants – supporting documents

4 years

Environment

Accident reports

5 years

Insurance

Insurance policies

6 years (general rule)

Insurance

Property damage claims

2 years

Insurance

Personal injury claims

5 years

Insurance

Life insurance

10 years

Purchases

VAT records of supplies of goods and services, intra-Community acquisitions, imports and exports

5 years

Legal

Intellectual and Industrial Property documents

5 years

Legal

Contracts and agreements

5 years

Legal

Permits, licences and certificates

6 years after expiry / 10 years for criminal limitation periods

Legal

Confidentiality and non-compete agreements

For the entire duration of the obligation or confidentiality commitment

Data Protection

Personal data processing activities different from those notified to the Spanish Data Protection Agency

3 years

Data Protection

Employees' personal data stored on networks, computers, communication equipment, access control systems and internal management systems

5 years

Traveller Records

Traveller data communicated to the Police

3 years