Privacy Policy
This legal text provides you with details of how we collect and process your personal data through the use of our website http://www.tobosohotels.com, including any information you may provide to us through the site when you provide your data through the form enabled for that purpose, make a booking, or register for our newsletter.
By providing us with your data, we inform you that our services are not possible for those persons whom the regulations prevent from giving consent, therefore when you submit the forms to us, you guarantee that you have sufficient capacity to give consent.
Below, we inform you about the data protection policy of: Tejera 2020, S.L
1. Data Controller.
Contact details of the controller:
Tejera 2020, S.L, with Tax ID (CIF): B92431873 and registered office at: Calle Cristo Número, 12 29700 Vélez Málaga, Málaga and telephone: 952527474. Email: rgpd@tobosohotels.com
Registered in the Commercial Registry of Málaga, on 6 June 2003, Volume 3285, Book 2198, Folio 40, Section 8, Sheet MA 62682, Entry 1st.
Tejera 2020, S.L is the controller of your data. (Hereinafter we or our).
2. What data do we collect?
The General Data Protection Regulation defines personal data as any information about an identified or identifiable natural person, i.e. any information capable of identifying a person. This would not include anonymous data, nor percentages.
The personal data that may be collected directly from the data subject will be treated confidentially and will be incorporated into the corresponding processing activities, owned by Tejera 2020, S.L.
On our Website we may process certain types of personal data, which may include:
- Identity data: name and surname.
- Personal characteristics data: date of birth.
- Contact data: email and telephone.
- Technical data: login data, Internet protocol addresses, browser type and version, time zone setting and location, operating system, browser plug-in types and versions, and any other technology on the devices you use to access our website.
- Profile data: password.
- Usage data: information about how you use our website, products and services.
- Marketing and communications data: preferences for receiving marketing communications from us and preferred means of communication.
We do not collect any data relating to special categories of personal data (those that reveal your ethnic or racial origin, political opinions, religious or philosophical beliefs, trade union membership and information about your health, genetic or biometric data).
In the event that we are required to collect personal data by law or under the terms of the contract between us and you refuse to provide it to us, we may not be able to perform that contract or provide the service, and you must notify us in advance.
3. How do we collect your personal data?
The means we use to collect personal data are:
Through the form on our website, through our contact email, by telephone or postal mail, when:
- You request information about our products
- You contract the provision of our services
- You subscribe to one of our services or publications
- You send your comments
To ensure the quality of our portal, we reserve the right to refuse any registration request or to suspend or cancel a previously accepted registration if we consider that it does not meet these requirements or any other law or regulation. If this occurs, we will try to explain the reasons for our decision, but we cannot commit to doing so in all cases.
Through technology or automated interactions: on our site we may automatically collect technical data about your equipment, browsing actions and usage patterns. This data is collected through cookies or similar technologies. If you would like more information, you can consult our cookie policy here
Through third parties:
- Google: analytical data or search data. Outside the European Union.
4. Purpose and lawfulness of the use of your data.
The most common uses of your personal data are:
- For the formalisation of a contract between Tejera 2020, S.L and you.
- When you give your consent to the processing of your data.
- When we need them to comply with a legal or regulatory obligation.
- When necessary for our legitimate interest or that of a third party.
The User may revoke the consent given at any time by sending an email to rgpd@tobosohotels.com or by consulting the section on exercising rights below.
Below, we attach a table in which you can consult the ways in which we will use your personal data and the lawfulness of its use, as well as knowing what type of personal data we will process. We may process some personal data for an additional legal reason, so if you need details about this you can send an email to rgpd@tobosohotels.com
|
Form |
Purpose |
Type of data |
Lawfulness of processing |
|
Contact |
The purpose is the management of contacts and requests for information received via the website |
Name Telephone |
Consent of the data subject (art. 6.1.a GDPR) Pre-contractual measures (art. 6.1.b GDPR) Processing is necessary for the purposes of the legitimate interests pursued by the controller (art. 6.1.f GDPR) |
|
Newsletter |
The purpose is the management of the data provided for sending information about our services and promotions |
Name |
Consent of the data subject (art. 6.1.a GDPR) Pre-contractual measures (art. 6.1.b GDPR) Processing is necessary for the purposes of the legitimate interests pursued by the controller (art. 6.1.f GDPR) |
|
Log in |
The purpose is the management of data provided when accessing the private area |
Password |
Consent of the data subject (art. 6.1.a GDPR) Processing is necessary for compliance with a legal obligation to which the controller is subject (art. 6.1.c GDPR) Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (art. 6.1.b GDPR) Processing is necessary for the purposes of the legitimate interests pursued by the controller (art. 6.1.f GDPR) |
|
Register |
The purpose is the management of data provided upon registration |
Name Surname Date of birth Password |
Consent of the data subject (art. 6.1.a GDPR) Pre-contractual measures (art. 6.1.b GDPR) Processing is necessary for the purposes of the legitimate interests pursued by the controller (art. 6.1.f GDPR) |
|
Bookings |
The purpose is the management of bookings |
Name Surname Telephone |
Consent of the data subject (art. 6.1.a GDPR) Processing is necessary for compliance with a legal obligation to which the controller is subject (art. 6.1.c GDPR) Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (art. 6.1.b GDPR) Processing is necessary for the purposes of the legitimate interests pursued by the controller (art. 6.1.f GDPR) |
Commercial communications: you will only receive communications if
- You requested information or made a contract with us for a product or service.
- If you provided us with your data, accepting the relevant box on our form.
- As long as you have not expressed your wish to stop receiving such communications.
We obtain your express consent before sending you any communication, and you may at any time request that we stop sending you communications at rgpd@tobosohotels.com
When you choose to stop receiving our communications, your personal data will continue to be stored as a result of the contract you have entered into with us, in order to comply with legal requirements.
Purpose: we will only use your data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason, notifying you beforehand so that you are informed of the legal reason for its processing, and provided that the purpose is compatible with the original purpose.
5. How long will we keep your data?
They will be kept for as long as necessary to fulfil the purpose for which they were collected and to determine any possible liabilities that may arise from that purpose and from the processing of the data. The provisions of the various regulations regarding the retention period shall apply, insofar as they are applicable to this processing.
Data of subscribers by email or form: from the moment the user subscribes until they unsubscribe.
6. Minors.
Tejera 2020, S.L does not authorise minors under 14 years of age to provide their personal data through the means provided on this website (completing web forms to request services, contact or by sending emails). Therefore, those persons who provide personal data using such means formally declare that they are over 14 years of age, and Tejera 2020, S.L is exempt from any liability for failure to comply with this requirement.
If your child under the established age limit has provided personal information to Tejera 2020, S.L, please contact us to request the exercise of their applicable rights.
In those cases where the services offered by Tejera 2020, S.L are intended for minors under 14 years of age, the means to obtain the authorisation of the parents or legal guardians of the minor will be provided.
7. Exercise of Data Protection Rights:
How to exercise these rights? Users may send a communication to the registered office of Tejera 2020, S.L or to the email address rgpd@tobosohotels.com, including in both cases a copy of their ID card or other similar identification document, to request the exercise of the following rights:
- Access to your personal data: you may ask Tejera 2020, S.L whether it is using your personal data.
- To request its rectification, if it is incorrect, or to exercise the right to be forgotten with respect to it.
- To request the restriction of processing, in which case they will only be kept by Tejera 2020, S.L for the exercise or defence of claims.
- To object to its processing: Tejera 2020, S.L will stop processing the data in the manner you indicate, unless for legitimate reasons or for the exercise or defence of possible claims, they must continue to be processed.
- To data portability: if you want your data to be processed by another firm, Tejera 2020, S.L will facilitate the portability of your data to the new controller.
You may use the models made available to you by the Spanish Data Protection Agency to exercise your previous rights: Here
To lodge a complaint with the AEPD: if you consider that there is a problem with the way Tejera 2020, S.L is processing your data, you may direct your complaints to the corresponding supervisory authority, which in Spain is the competent one: Spanish Data Protection Agency.
We will request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of the other rights mentioned above). This is a security measure to ensure that personal data is not disclosed to any person who is not entitled to receive it.
We will resolve all requests within the legal period of one month. However, it may take us more than one month if your request is particularly complex. In this case, we will notify you and keep you updated.
8. Data communication: provision of services.
In the performance of our work, we may need the help of third parties, who will only process the data to provide the contracted service, and with whom we have the corresponding measures to guarantee your rights:
- Service providers that provide systems and information technology administration services.
- Professional advisors including lawyers, auditors and insurers who provide banking, legal, insurance and accounting consultancy services.
All data processors to whom we transfer your data will respect the security of your personal data and will process it in accordance with the GDPR.
We only allow such processors to process your data for specified purposes and in accordance with our instructions. However, you may request from us, in compliance with transparency, a list of who these companies are that provide us with services; you may do so by emailing: rgpd@tobosohotels.com
9. Data Security.
We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised manner, modified or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know such data. They will only process your personal data in accordance with our instructions and will be subject to a duty of confidentiality.
We have implemented procedures to deal with any suspected breach of your personal data and will notify you and the Supervisory Authority in the event that this occurs, as regulated in the GDPR in its articles 33 and 34, a security breach.