PRIVACY POLICY
1. INFORMATION FOR USERS
HOTELES ONE 2020, S.A., as Data Controller, hereby informs you that, in accordance with Regulation (EU) 2016/679 of 27 April (GDPR) and Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), it will process your personal data as described in this Privacy Policy.
This Privacy Policy describes how users’ personal data are collected, the purposes for which they are processed, the recipients of the data, the rights available to users and the security measures adopted to ensure their protection.
2. DATA CONTROLLER CONTACT DETAILS
| Company name | HOTELES ONE 2020, S.A. (hereinafter “HOTELES ONE 2020”) |
|---|---|
| Tax ID (CIF) | B43967074 |
| Registered office | C/ Joan Fuster núm. 15, Polígono Industrial Mas de les Ànimes, 43206 Reus (Tarragona) |
| Website | www.hotelsone2020.com |
| Email address | [email protected] |
| Privacy | [email protected] |
3. PRINCIPLES GOVERNING DATA PROCESSING
HOTELES ONE 2020 applies the principles established in Article 5 of the GDPR to all personal data processing activities:
• Lawfulness, fairness and transparency: data are collected on a valid legal basis and the data subject is informed in a clear and accessible manner.
• Purpose limitation: data are used exclusively for the purposes for which they were collected.
• Data minimisation: only the data strictly necessary to achieve the stated purpose are processed.
• Accuracy: the necessary measures are taken to keep data up to date and to rectify any inaccuracies.
• Storage limitation: data are retained only for as long as necessary for the purpose of the processing or to comply with legal obligations.
• Integrity and confidentiality: appropriate technical and organisational measures are applied to ensure the security of the data against unauthorised access, loss or destruction.
• Accountability: the Data Controller is able to demonstrate compliance with all the principles set out above.
4. PERSONAL DATA PROCESSING ACTIVITIES
The personal data processing activities carried out by HOTELES ONE 2020 are detailed below:
4.1 Website users
Data Controller
| Identity | HOTELS ONE 2020, S.A.U – Tax ID (CIF): B43967074 |
|---|---|
| Postal address | C/ Joan Fuster núm. 15, Polígono Industrial Mas de les Ànimes, 43206 Reus (Tarragona) |
| Email address | [email protected] |
| Privacy | [email protected] |
Purpose of processing
To process requests for information, bookings and enquiries received through the contact forms on the HOTELES ONE 2020 website and to respond to any request submitted by the user through the contact channels made available to them.
Retention period
The data will be retained for the time necessary to deal with the request and, once it has been handled, for the applicable limitation periods relating to any liabilities that may arise from it, in accordance with current legislation.
Legal basis for processing
Taking steps at the request of the data subject prior to entering into a contract (Art. 6(1)(b) GDPR) and, where applicable, the legitimate interest of the Data Controller in responding to enquiries received (Art. 6(1)(f) GDPR).
Recipients
The data may be disclosed to data processors providing technological support services (web hosting, CRM systems and booking management platforms), provided that they offer sufficient guarantees of compliance with data protection regulations. No disclosures to third parties are envisaged, except where required by law.
Rights of the data subject
The data subject may exercise the rights of access, rectification, erasure, restriction, portability and objection to the processing of their data, under the terms set out in Articles 15 to 21 of the GDPR. See Section 6 of this Policy for information on how to exercise these rights.
4.3 Commercial communications and newsletter
Data Controller
| Identity | HOTELS ONE 2020, S.A.U – Tax ID (CIF): B43967074 |
|---|---|
| Postal address | C/ Joan Fuster núm. 15, Polígono Industrial Mas de les Ànimes, 43206 Reus (Tarragona) |
| Email address | [email protected] |
| Privacy | [email protected] |
Purpose of processing
To send commercial and informational communications by electronic means regarding activities, exhibitions, events, news and services related to HOTELES ONE 2020 to individuals who have requested a subscription or who, as customers, have a pre-existing relationship with the Data Controller.
Retention period
The data will be retained until the data subject exercises their right to erasure or withdraws the consent previously given.
Legal bases for processing
• The explicit consent of the data subject for the sending of commercial communications where there is no prior contractual relationship (Art. 6(1)(a) GDPR and Art. 21 LSSICE).
• The legitimate interest of the Data Controller in maintaining the commercial relationship with existing customers, provided that the rights and freedoms of the data subject do not prevail (Art. 6(1)(f) GDPR), in accordance with the exception provided for in Art. 21.2 LSSICE.
Recipients
Email distribution and subscriber management platforms acting as data processors. No disclosures to third parties are envisaged.
Right to unsubscribe
The data subject may withdraw their consent or object to receiving commercial communications at any time, free of charge and in a simple manner, by using the unsubscribe link included in each communication or by contacting [email protected].
Rights of the data subject
The data subject may exercise the rights of access, rectification, erasure, restriction, portability and objection to processing, under the terms set out in Section 6 of this Policy.
4.4 Video surveillance
Data Controller
| Identity | HOTELS ONE 2020, S.A.U – Tax ID (CIF): B43967074 |
|---|---|
| Postal address | C/ GUERAU DE LIOST, 9 43206 REUS |
| Email address | [email protected] |
| Privacy | [email protected] |
Purpose of processing
To ensure the security of HOTELES ONE 2020’s facilities, property and the people accessing them through a video surveillance camera system. The premises display information signs regarding the existence of the system, in compliance with Article 22 of the LOPDGDD and Instruction 1/2006 of the Spanish Data Protection Agency (AEPD).
Retention period
The images captured will be automatically deleted within a maximum period of one month, unless they contain evidence of a possible criminal or administrative offence, in which case they will be retained for the time necessary to make them available to the competent authorities.
Legal basis for processing
The legitimate interest of the Data Controller in ensuring the security of people and facilities (Art. 6(1)(f) GDPR) and, where applicable, compliance with a legal obligation (Art. 6(1)(c) GDPR).
Recipients
State security forces and bodies and, where applicable, courts and tribunals, where an unlawful act has been detected or where disclosure is required by a judicial or administrative decision. No other disclosures are envisaged.
Rights of the data subject
The data subject may exercise the rights of access, rectification, erasure, restriction and objection under the terms set out in Section 6 of this Policy. The right to data portability does not apply to video surveillance images captured in areas open to the public.
5. INTERNATIONAL DATA TRANSFERS
As a general rule, HOTELES ONE 2020 does not carry out international transfers of personal data outside the European Economic Area (EEA). Should any data processor be located outside the EEA, the engagement of such processor will be carried out in accordance with the safeguards provided for in Chapter V of the GDPR (European Commission adequacy decision, Standard Contractual Clauses or other approved mechanisms).
6. RIGHTS OF DATA SUBJECTS
In accordance with Articles 15 to 22 of the GDPR, any individual may exercise the following rights before HOTELES ONE 2020:
| Right of access (Art. 15 GDPR) | To obtain confirmation as to whether personal data concerning them are being processed and, if so, to access such data. |
|---|---|
| Right to rectification (Art. 16 GDPR) | To request the correction of inaccurate data or the completion of incomplete data. |
| Right to erasure (Art. 17 GDPR) | To request the deletion of data where, among other circumstances, they are no longer necessary for the purpose for which they were collected. |
| Right to restriction of processing (Art. 18 GDPR) | To request that processing be restricted, for example while the accuracy of the data is being verified. |
| Right to data portability (Art. 20 GDPR) | To receive the data in a structured, machine-readable format and transmit them to another controller where the processing is based on consent or a contract. |
| Right to object (Art. 21 GDPR) | To object to processing, particularly where it is based on the legitimate interests of the Data Controller or where the data are processed for direct marketing purposes. |
| Right to withdraw consent | To withdraw consent at any time, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal. |
How to exercise your rights
By sending a written request to HOTELES ONE 2020, S.A / C/ Joan Fuster núm. 15, Polígono Industrial Mas de les Ànimes, 43206 Reus (Tarragona), enclosing a photocopy of your Spanish National Identity Document (DNI) or an equivalent identification document.
Alternatively, by email to [email protected], signed with a recognised electronic signature or accompanied by a copy of the identification document.
The Data Controller will respond to the request within a maximum period of one month from receipt (Art. 12 GDPR), which may be extended by a further two months in cases of complexity or a high number of requests.
Complaint to the Supervisory Authority
If the data subject considers that the processing of their personal data does not comply with current legislation or that their rights have not been properly addressed, they have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), the competent supervisory authority:
• Website: www.aepd.es
• Postal address: C/ Jorge Juan, 6, 28001 Madrid
• Telephone: 901 100 099
7. DATA SECURITY
HOTELES ONE 2020 has adopted the necessary technical and organisational measures to ensure the security of personal data and to prevent their destruction, loss, alteration or unauthorised access, in accordance with Article 32 of the GDPR and the state of the art.
The payment gateways used for ticket purchases are PCI-DSS certified. HOTELES ONE 2020 does not store bank card details under any circumstances.
8. COOKIES
The website https://hotelsone2020.com/en/ may use cookies and similar technologies to improve the user experience. Detailed information about the types of cookies used, their purpose and the available management options can be found in the Cookie Policy available on the Data Controller’s website.
9. UPDATES TO THIS POLICY
HOTELES ONE 2020 reserves the right to amend this Privacy Policy in order to adapt it to legislative or case-law developments, recommendations issued by the Spanish Data Protection Agency (AEPD), or changes in business practices. In the event of substantial amendments, the Data Controller will inform data subjects through the appropriate channels. Users are advised to periodically review the version published at https://hotelsone2020.com/en/.