\n\t\t\t\t\t\t\t\t\t
In the event that the website allows subscription to the Newsletter or registration for the \u201cHidden Rewards\u201d loyalty programme, it will be necessary for the user to provide the personal data required in the corresponding form, including at least a valid e-mail address.<\/p>
\u00a0<\/p>
Signing up for the Newsletter and the Hidden Rewards programme will be done independently, and it is not obligatory to accept the sending of commercial communications in order to form part of the loyalty programme.<\/p>
For the sending of commercial communications, the user's express consent will be required by ticking the corresponding box. Additionally, a double opt-in system will be implemented, whereby the user must confirm their subscription via a link sent to their email address.<\/p>
The legal basis for the processing shall be:<\/p>
- The user's consent to receive commercial communications.<\/p>
- The execution of a contract or the application of pre-contractual measures, in connection with the management of the Hidden Rewards programme<\/p>
Personal data will be processed for the following purposes:<\/p>
- Manage Newsletter subscription<\/p>
- Send commercial communications, promotions and news<\/p>
- Manage the registration, participation and benefits associated with the Hidden Rewards programme.<\/p>
- Where appropriate, personalise the offers and benefits of the programme, only when the user has given his consent to do so.<\/p>
In the event of processing based on profiling (e.g. personalisation of offers on the basis of consumption habits or preferences), this will only be carried out on the basis of the user's consent.<\/p>
The data will be kept as long as the user does not request cancellation of the service, does not cancel their participation in the programme or does not withdraw their consent. Once the relationship has ended, the data will be deleted or blocked in accordance with the legally established deadlines.<\/p>
The data may be processed by email marketing service providers and technology platforms associated with the loyalty programme, who will act as data processors under appropriate contractual safeguards. In case of international transfers, appropriate safeguards will apply in accordance with the GDPR.<\/p>
Users may withdraw their consent at any time, as well as unsubscribe from the Newsletter or the Hidden Rewards programme through the link provided in each communication or through the channels indicated in this Privacy Policy.<\/p>
Commercial communications may be carried out centrally by the HIDDEN HOTELS group, using customer management tools (CRM), and may include information from different establishments of the group, always in accordance with the consent given by the user.<\/p>
__________________________________________________________________________________________________<\/p>
If you are one of the following groups, please see the information below:<\/p>
\u00a0<\/strong><\/p>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 + CONTACTS FROM THE WEB OR EMAIL<\/strong><\/p>For what purposes will we process your personal data?<\/strong><\/p>- Attend and respond to your queries, requests or petitions.<\/li>
- Manage the requested service or information.<\/li>
- Maintain communications related to your application, including by electronic means.<\/li>
- To send you commercial communications or information about events, only if you have expressly authorised this.<\/li><\/ul>
What is the legitimacy for the processing of your data?<\/strong><\/p>The legal basis for the processing of your data is:<\/p>
- The application of pre-contractual measures or the performance of a contract, where your request relates to the procurement of services.<\/li>
- The legitimate interest of the data controller, to deal with general enquiries and to maintain the relationship derived from your request.<\/li>
- The consent of the data subject, in relation to the sending of commercial communications.<\/li><\/ul>
In those cases in which the processing is based on consent, this will be obtained by ticking the corresponding box, which will not be pre-ticked in any case.<\/p>
All forms shall have a check box with the following formula:<\/p>
\u201cI have read and accept the Privacy Policy\u201d.\u201d<\/p>
By filling in and sending the form, the user declares that he\/she has been informed about the processing of his\/her data in accordance with this Privacy Policy.<\/p>
How long will we keep personal data?<\/strong><\/p>The personal data provided through contact forms or by sending e-mails will be kept for the time necessary to deal with and manage the request made.<\/p>
Once the management of the consultation has been completed, the data may be duly blocked for the duration of the statute of limitations for possible legal liabilities.<\/p>
In the event that the user has authorised the sending of commercial communications, their data will be retained until said consent is withdrawn.<\/p>
\u00a0<\/p>
\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 + CUSTOMERS<\/strong> \/ HOSPITALITY<\/strong><\/p>For what purposes will we process your personal data?<\/strong><\/p>Your personal data will be processed in order to manage the contractual relationship derived from the reservation and stay in the establishments of the HIDDEN HOTELS group.<\/p>
Specific purposes include:<\/p>
- Budgeting and monitoring of budgets.<\/li>
- The management of the booking, including pre-booking, confirmation, modification or cancellation.<\/li>
- The provision of accommodation and associated services during the stay.<\/li>
- The management of communications necessary for the correct provision of the service (confirmations, reminders, incidents or relevant information about the stay), including by electronic means.<\/li>
- Administrative, accounting and tax management derived from the services provided.<\/li>
- The carrying out of economic transactions, collections, payments and, where appropriate, guarantees or pre-authorisations.<\/li>
- Compliance with the legal obligations applicable to the hotel sector, in particular those relating to the registration of travellers and public safety regulations.<\/li>
- The management of internal controls, audits, complaint handling, fraud prevention and recovery of outstanding amounts.<\/li>
- Conducting satisfaction surveys and service quality evaluations.<\/li>
- The sending of commercial communications, promotions or offers related to HIDDEN HOTELS, only with the express authorisation of the user.<\/li>
- Likewise, the data may be used centrally by the HIDDEN HOTELS group to send commercial communications, provided that the user has given his or her express consent.<\/li><\/ul>
What is the legitimacy for the processing of your data?<\/strong><\/p>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The legal basis for the processing of your personal data is:<\/p>
- The execution of a contract or the implementation of pre-contractual measures, for the management of quotations, reservations, accommodation and associated services.<\/li>
- Compliance with legal obligations in relation to tax, accounting, public safety and applicable sectorial regulations.<\/li>
- The legitimate interest of the data controller, for the management of complaints, fraud prevention, debt collection and improvement of the quality of service, including the carrying out of satisfaction surveys.<\/li>
- The consent of the data subject, in relation to the sending of commercial communications.<\/li><\/ul>
The communications necessary for the management of the reservation or provision of the service will not be considered as commercial communications, as they are based on the execution of the contract.<\/p>
How long will we keep personal data?<\/strong><\/p>The personal data will be kept for the time necessary for the management of the contractual relationship arising from the reservation and stay in the establishments of the HIDDEN HOTELS group.<\/p>
In particular:<\/p>
- Data related to reservations and accommodation services: during the contractual relationship and, subsequently, during the periods required by the applicable regulations, in particular the regulations on the registration of travellers, as well as tax and accounting obligations.<\/li>
- Data associated with invoicing and payments: during the legally required tax and accounting periods.<\/li>
- Data used for fraud prevention, claims or recoveries: for the time necessary for the management of such actions and the applicable statute of limitations.<\/li>
- Data used for satisfaction surveys: for the time necessary to assess the quality of service, applying minimisation criteria.<\/li><\/ul>
In the event that the user has authorised the sending of commercial communications, their data will be retained until said consent is withdrawn.<\/p>
Once the aforementioned periods have expired, the data will be deleted or, where appropriate, blocked during the periods of limitation of possible legal liabilities, in accordance with the applicable regulations.<\/p>
\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 + SUPPLIERS.<\/strong><\/p>For what purposes will we process your personal data?<\/strong><\/p>We will process the personal data of suppliers and collaborators in order to properly manage the commercial or professional relationship that links them with the different companies of the HIDDEN HOTELS group.<\/p>
\u00a0Specific purposes include:<\/p>
- To maintain communications relating to requests, proposals, offers or exchanges of information necessary for the provision of services.<\/li>
- To send you information by electronic means related to your request or to the existing contractual relationship.<\/li>
- Send commercial or event information only when expressly authorised to do so.<\/li>
- Manage the administrative, communication and logistical services necessary for the contracting, provision and control of the services or products supplied.<\/li>
- Carry out the relevant economic transactions, including payments, receipts and reconciliations.<\/li>
- Manage invoicing, accounting and compliance with applicable fiscal or tax obligations.<\/li>
- To carry out control procedures, internal audit, quality verification, fraud prevention or recovery of amounts due, when necessary for the proper execution of the contractual relationship.<\/li><\/ul>
What is the legitimacy for the processing of your data?<\/strong><\/p>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The legal basis for the processing of supplier data is the performance of a contract or the implementation of pre-contractual measures in connection with the provision of services or supply of products. In the absence of a contractual relationship, the legitimation may derive from the data subject's consent when contacting us by any means. Certain processing linked to tax, accounting or legal obligations is based on compliance with legal obligations. Commercial communications will only be sent when there is express consent.<\/p>
How long will we keep personal data?<\/strong><\/p>The personal data of suppliers and collaborators will be kept for the time necessary to manage the existing contractual or professional relationship.<\/p>
- In particular:<\/li>
- Identification and contact data: for the duration of the contractual or commercial relationship.<\/li>
- Data related to invoicing, payments and accounting: during the legally required tax and accounting deadlines.<\/li>
- Data used for administrative management, audits, internal control or fraud prevention: for the time necessary for these purposes and the applicable limitation periods.<\/li><\/ul>
\u00a0<\/p>
In the event that a contractual relationship is not formalised, the data will be kept for the time necessary to process the request or proposal and will subsequently be deleted, unless there is a legal obligation to keep them.<\/p>
In the event that the provider has authorised the sending of commercial communications, your data will be retained until such time as you withdraw this consent.<\/p>
Once the aforementioned periods have expired, the data will be deleted or, where appropriate, blocked during the periods of limitation of possible legal liabilities, in accordance with the applicable regulations.<\/p>
\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 + SOCIAL MEDIA CONTACTS<\/strong><\/p>For what purposes will we process your personal data?<\/strong><\/p>When you interact with us through our official social media accounts, the personal data you provide or that is visible on your profile will be processed for the following purposes:<\/p>
- Attend and respond to your queries, requests or petitions.<\/li>
- Manage the relationship with you as a user of the social network.<\/li>
- Interact with you and energise the community of followers.<\/li>
- To analyse user interaction and participation for statistical purposes and to improve our services.<\/li><\/ul>
What is the legitimacy for the processing of your data?<\/strong><\/p>The legal basis for the processing is:<\/p>
- The legitimate interest of the data controller in managing its presence on social networks and attending to the users who interact with its profiles.<\/li>
- The execution of the relationship established with the user within the social network itself, in accordance with its terms of use.<\/li><\/ul>
In any case, the processing is carried out in accordance with the privacy policies of the corresponding social network. HIDDEN HOTELS and the social network platform may act as co-responsible for the processing in relation to certain processing (for example, page usage statistics), in accordance with the provisions of each platform.<\/p>
How long will we keep personal data?<\/strong><\/p>The personal data will be processed for as long as the user maintains a relationship with the HIDDEN HOTELS profile on the social network (for example, by following or interacting with it).<\/p>
However, HIDDEN HOTELS has no direct control over the conservation of the data on the platform, so the effective deletion of the data will depend on the user's privacy settings and the policies of the corresponding social network.<\/p>
In any case, HIDDEN HOTELS may delete or stop processing data that is inappropriate or excessive in the context of the interaction with your profiles.<\/p>
\u00a0<\/p>
\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 + VIDEO SURVEILLANCE<\/strong><\/p>For what purposes will we process your personal data?<\/strong><\/p>The images captured through the video surveillance systems installed in our facilities will be processed in order to guarantee the security of people, goods and facilities.<\/p>
Likewise, in the field of employment, they may be used to monitor compliance with employment obligations, within the limits established by the regulations in force and respecting the rights of workers in all cases.<\/p>
The images may be made available to the Security Forces and Corps, as well as to courts and tribunals, when necessary for the investigation of facts or the exercise of legal actions.<\/p>
What is the legitimacy for the processing of your data?<\/strong><\/p>The legal basis for the processing is the legitimate interest of the controller, in accordance with Article 6.1.f) of the GDPR, in conjunction with Article 22 of Organic Law 3\/2018.<\/p>
In the case of labour inspection, the treatment is additionally covered by the provisions of Article 20.3 of the Workers' Statute.<\/p>
How long will we keep personal data?<\/strong><\/p>The images will be kept for a maximum period of 30 days from their capture.<\/p>
However, they may be kept for a longer period when necessary to prove the commission of acts against the integrity of persons, property or installations, or when they are to be provided in the context of police or judicial proceedings.<\/p>
In such cases, the images will be blocked and made available to the competent authorities, in accordance with the applicable regulations.<\/p>
\u00a0<\/p>
+ JOB SEEKERS<\/strong><\/p>For what purposes will we process your personal data?<\/strong><\/p>We will process the personal data included in your CV or provided during the selection process for the following purposes:<\/p>
- To organise and manage current or future selection processes for the recruitment of personnel in the different companies of the HIDDEN HOTELS group.<\/li>
- Evaluate your application and assess whether your profile matches the position offered.<\/li>
- Contact you to arrange interviews or tests related to the selection process.<\/li>
- In the event that you give us your express consent, we may communicate your application to other companies in the group or to collaborating entities, exclusively with the aim of facilitating your incorporation into the labour market.<\/li><\/ul>
What is the legitimacy for the processing of your data?<\/strong><\/p>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The legal basis for the processing of your personal data is the consent you give by submitting your CV or participating in selection processes. Certain data may also be processed for the purposes of pre-contractual measures in connection with the possible conclusion of an employment contract.<\/p>
How long will we keep personal data?<\/strong><\/p>CVs will be kept for a maximum period of one year from receipt. After this period, and if no recruitment process has been initiated with you, the data will be securely deleted, unless you have expressly authorised their retention for a further period or there is an active recruitment process that requires them to be kept for a longer period.<\/p>
\u00a0<\/p>
\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 + HR<\/strong><\/p>For what purposes will we process your personal data?<\/strong><\/p>We will process employees' personal data for the purpose of properly managing the employment relationship and the employee's file. This includes:<\/p>
- The administrative, labour and contractual management derived from the employment relationship.<\/li>
- Carrying out all the administrative, tax, accounting and social security procedures necessary to comply with legal and contractual obligations.<\/li>
- The management of the payment of salaries, remuneration and social benefits through the corresponding financial institution.<\/li>
- The management of time and attendance and time recording by means of the authorised systems (card, personal code, platform, employee portal or biometric system, only when legally and technically appropriate).<\/li>
- The management of group insurance, additional coverage or pension plans in which the employee may be included.<\/li>
- The management of staff training, whether compulsory training, subsidised or non-reimbursed training.<\/li>
- The management of the necessary actions in terms of occupational risk prevention, health surveillance and regulatory compliance.<\/li>
- The management of incidents, leave, absences, disciplinary sanctions or any other action derived from the employment relationship.<\/li>
- The performance of internal audits, quality controls or internal procedures necessary to ensure the proper functioning of the human resources area and the group.<\/li><\/ul>
\u00a0<\/p>
What is the legitimacy for the processing of your data?<\/strong><\/p>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The legal bases legitimising the processing are:<\/p>
- The execution of the employment contract and the application of pre-contractual measures in the framework of the employment relationship (Art. 6.1.b) GDPR).<\/li>
- Compliance with legal obligations applicable to the employer, including those derived from labour, social security, occupational risk prevention, tax and accounting regulations (art. 6.1.c) GDPR).<\/li>
- The employee's consent only for those processing operations that are not covered by the employment relationship or a legal obligation, such as certain voluntary training actions or optional social benefits (art. 6.1.a) GDPR).<\/li>
- The legitimate interest of the employer, in cases such as internal controls, audits or actions necessary for the prevention of fraud or the proper functioning of the organisation (art. 6.1.f) RGPD), always within the limits provided for in the regulations.<\/li><\/ul>
How long will we keep personal data?<\/strong><\/p>The personal data of employees will be kept for the time necessary to manage the employment relationship and, once the employment relationship has ended, for the legally required periods. In particular:<\/p>
- Data derived from the employment relationship, payslips, contributions and associated documentation: during the term of the contract and, subsequently, during the periods established by labour, Social Security, tax and accounting regulations.
- Data related to occupational risk prevention and health surveillance: during the periods required by the specific applicable regulations.
- Data linked to time control and recording of working hours: during the legally established period.
- Data relating to training, disciplinary files or internal evaluations: for the time necessary for the purpose for which they were collected and the applicable limitation periods.<\/p>
Once the aforementioned periods have expired, the data will be deleted or, where appropriate, blocked during the periods of limitation of possible legal liabilities, in accordance with the applicable regulations.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t