SALOMON SA RIERA SL (hereinafter the Entity) is committed to due diligence and compliance with Data Protection regulations.
The following provides detailed information on the confidentiality and personal data protection policy in compliance with the provisions of Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation or GDPR) and Article 11 of Organic Law 3/2018, on the Protection of Personal Data and Guarantee of Digital Rights (LOPD GDD).
Data of the Data Controller and contact details of the Data Protection Officer (DPO):
- Identity: SALOMON SA RIERA SL
- Address – C. P: Passeig de Gràcia, 98, 3º 1ª – 08008 Barcelona
- Telephone: 935 579 797
- Email: info@honestgranadahotel.com
- Contact details of the DPO: dpo@majestichotelgroup.com
- Data Protection Channel: www.corporate-line.com/cnormativo-hotelfincavictoria
Purposes of the treatment
The Entity will process the information provided by interested parties for the following purposes:
- Manage your visit and meeting at our facilities.
- Manage the provision and delivery of contracted hotel and tourism sector services, among others:
- Physical and online booking process.
- Check-in as a guest at Finca Victoria Hotel & Spa.
- Management and improvement of your stay.
- 24-hour reception service.
- Parking service.
- Catering service.
- Wi-Fi service.
- Booking of meeting rooms, conferences and events.
- Manage any type of request, reservation, suggestion or petition made to us by interested parties.
- Manage your registration in the club or loyalty program and offer you special benefits.
- Informative and commercial communications: processing of your data for the purpose of informing you about activities, articles of interest and general information related to our activity and the services contracted.
- Manage data provided by job applicants through the Curriculum Vitae (CV) or other means for the purpose of the selection and recruitment process.
- Ensure the security of offices, facilities and people through access controls, video surveillance systems and other access control/identification systems.
- Comply with the legal provisions that apply to the Entity and its activities in matters of health, equality and prevention of occupational risks.
- Manage and control the operation of the internal mechanisms, policies and protocols established by the Entity for the purposes of regulatory compliance and management of the reporting channels for this purpose.
- All those treatments that are applicable to us for the proper compliance with the regulations and official/sectoral requirements to which our activity is subject.
For the proper execution and management of your request and the purposes described above, the processing of your data for the corresponding purposes will be carried out in strict compliance with Data Protection regulations and the Policy detailed herein. You may exercise your rights at any time (see specific section).
Data retention criteria
- Management of services contracted with the Entity: Personal data provided in contracts, offers, and/or service proposals, as well as data from other individuals whose involvement is necessary, will be retained for the duration of the contracted services. Upon termination of the contracted service(s), personal data will be retained in cases where liabilities may arise with the Entity and/or in compliance with other applicable regulations or a law requiring their retention. Personal data will be maintained in a manner that allows for the identification and exercise of the rights of data subjects, and under the necessary technical, legal, and organizational measures to guarantee its confidentiality and integrity.
- Curriculum Vitae Management: The Entity, as a rule, keeps your Curriculum Vitae for a maximum period of one year; after this period, it will be automatically destroyed, in compliance with the principle of data quality.
- Management of Employment Contracts: personal data will be kept, in any case, for the duration of the employment relationship and, upon its termination, in cases where responsibilities may arise between the parties and when required by a law.
- Other: the rest of the data and information provided by the user by any means will be kept for as long as necessary to fulfill the purpose for which they were collected.
Legitimation
The legal basis that enables the Entity to process the personal data of users, clients, and potential clients is based on the following grounds:
- The consent of interested parties for the processing and management of any request for information or consultation about our services.
- The consent given by job applicants for selection and recruitment purposes.
- The framework for pre-reservation, provision and/or contracting of services with the Entity.
- The legitimate interest to send you informational, commercial and/or promotional offers related to the Entity’s activity and the services contracted through email or any other means.
- Compliance with legal obligations and internal regulatory compliance procedures.
- The legitimate interest in ensuring the safety of offices, facilities and people.
Recipients
The Entity, whenever necessary to achieve the purposes described above, will share personal data with the following third parties:
- Collaborating entities: when their participation is required within the framework of a contract and/or agreement for the provision of products and services established with our clients.
- Suppliers: Personal data may be communicated to different suppliers due to the provision of services by them that require access to and processing of personal data.
- Solicitors: if their intervention is required due to a judicial procedure.
- Public administrations or bodies in compliance with applicable regulations (labor, occupational risk prevention, tax, accounting, data protection, etc.).
- Courts and Tribunals and State Security Forces: personal data will be communicated to these entities whenever officially requested. The personal data of guests and clients provided upon registration at the Hotel will be subject to documentary registration and reporting obligations, in compliance with the provisions of Article 25 of Organic Law 4/2015, of March 30, on the protection of public safety.
- Companies of the MAJESTIC GROUP with the following purposes: fiscal and accounting management of the Hotel, management of reservations, administration of websites, portals and social networks of the Hotel, technical direction of the advertising, marketing and promotion activities of the Hotel, including the sending of commercial communications, control and management of the Hotel’s debt, collaboration in the contracting of services and supplies necessary for the Hotel, collaboration in the search for candidates for vacant job offers, as well as all those activities in which there is collaboration and joint management of the Entities of the MAJESTIC GROUP.
Origin
Personal data is obtained directly from data subjects and our partners, as well as from online booking platforms. The categories of personal data they provide us are as follows:
- Identification and contact information.
- Postal or email addresses.
- Bank details.
- Data provided and/or consented to by the interested parties themselves, related to and necessary for the management and performance of the requested service.
Rights
Right of Access, Rectification, and Erasure: Data subjects have the right to obtain confirmation as to whether or not the Entity is processing personal data concerning them. Data subjects have the right to access their personal data, as well as to request the rectification of inaccurate data or to request its erasure when, among other reasons, the data is no longer necessary for the purposes for which it was collected.
Right to Restriction and Objection: In certain circumstances, data subjects may request the restriction of the processing of their data, in which case we will only retain it for the exercise or defense of legal claims. In certain circumstances and for reasons related to their particular situation, data subjects may object to the processing of their data. The Entity will cease processing the data in this case, except for compelling legitimate grounds, or for the exercise or defense of possible legal claims.
Right to withdraw consent: Data subjects have the right to withdraw their consent at any time, except in the case of personal data processing provided for in data protection regulations or necessary for the provision of the contracted service, which do not require such consent. However, this withdrawal has no retroactive effect, and therefore will not affect the lawfulness of processing based on previously given consent.
These rights may be exercised through our Data Protection Channel, whose access details are provided at the beginning of this Policy.
Security and Control Measures
General
In compliance with data protection regulations, the Entity will process personal data applying appropriate technical, legal, organizational, and security measures to guarantee the confidentiality and integrity of the information it manages, in accordance with current legislation. We would appreciate it if you would inform the Data Protection Officer, using the contact details/channel established in this Privacy Policy, of any security risks you suspect or become aware of that could compromise the integrity and confidentiality of personal data and/or confidential information, so that the necessary measures can be taken to prevent unauthorized processing, loss, destruction, or accidental damage.
Cybersecurity
As a specific and complementary measure to the above, the Entity applies cybersecurity measures to prevent and manage potential attacks and fraud by cybercriminals who threaten the privacy and protection of the data that our Entity processes and accesses in the course of its activities and operations. In this regard, we wish to warn you that in the event of potential risks arising from communications whose content and/or format raise doubts about their authenticity, we recommend disregarding them and contacting the Data Protection Officer using the contact information provided in this Privacy Policy. Furthermore, any request you receive from our Entity regarding changes to payment methods, requests for contact information or individuals, or requests for confidential (non-public) information, bank details, credit card details, and/or other official data, should not be acted upon without direct confirmation from our Entity through another alternative means. We appreciate and need your collaboration in communicating and reporting any notifications about this type of request and other possible situations of risk of cyberattacks in which our Entity may be used, as well as any possible security risk that you may be aware of.
Data Protection Channel
The Entity has implemented a Channel, demonstrating the highest commitment, rigor, and professionalism in security, experience, independence, and expertise in handling incoming communications. This Channel, which includes its use in the area of Data Protection, has been implemented through a web platform, developed and managed by an independent external expert, to provide and guarantee our aforementioned commitments.
Through this Channel, you can communicate and process the exercise of your Rights (see previous section) and report any indication or knowledge you may have of possible security breaches, cyberattacks, and/or possible non-compliance or irregularities regarding Data Protection regulations, this Entity Policy, and all aspects mentioned above concerning confidentiality and trade secrets. Access details for the Channel are provided at the beginning of this Policy.
Supervisory authority
In the event of any disagreement with the Entity regarding the processing of your data, you have the right to file a complaint with the relevant Data Protection Supervisory Authority. In Spain, this Authority is the Spanish Data Protection Agency ( www.aepd.es ).
Customer service and support
Interested parties may communicate any doubts to the Entity regarding the processing of their personal data or the interpretation of our Policy, by contacting the Data Protection Officer (DPO) at the address indicated at the beginning of this Policy.