Privacy Policy

Introduction

This Privacy Policy has been developed taking into account the provisions of the applicable Organic Law on the Protection of Personal Data, as well as Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, hereinafter referred to as the GDPR.

The purpose of this Privacy Policy is to inform the data subjects whose personal data is being collected of the specific aspects relating to the processing of their data, including, among other matters, the purposes of the processing, the contact details for exercising their rights, the periods for which the information will be retained, and the security measures implemented.

Data Controller

For data protection purposes, HOTEL GREEN SUITES, SL shall be considered the Data Controller in relation to the files/processing activities identified in this policy, specifically in the section entitled Data Processing Activities.

The identification details of the owner of this website are set out below:

  • Data Controller: HOTEL GREEN SUITES, SL
  • Postal address: C/ ALBATROS 2 A, URBANIZACION CONDEQUINTO., 41500, ALCALA DE GUADAIRA, (SEVILLA), SPAIN.
  • Email address: DMARTINEZ@GREENSUITESHOTELES.COM

Data Protection Officer

The person appointed to perform the duties of Data Protection Officer at HOTEL GREEN SUITES, SL is FERNANDO LUIS CANO CASTAÑO, whose identification details are as follows:

Data Processing Activities

The personal data requested, where applicable, shall consist solely of the data that is strictly necessary to identify and respond to the request made by the data subject, hereinafter referred to as the data subject. Such information shall be processed fairly, lawfully and transparently in relation to the data subject. Furthermore, personal data shall be collected for specified, explicit and legitimate purposes and shall not be further processed in a manner incompatible with those purposes.

The data collected from each data subject shall be adequate, relevant and not excessive in relation to the purposes applicable in each case, and shall be kept up to date whenever necessary.

Prior to the collection of their data, the data subject shall be informed of the general matters regulated in this policy so that they may provide their express, specific and unambiguous consent to the processing of their data, in accordance with the following aspects.

Purposes of the Processing

The specific purposes for which each processing activity is carried out are set out in the information clauses included in each of the data collection channels (web forms, paper forms, voice recordings or signs and information notices).

However, the data subject’s personal data shall be processed exclusively for the purpose of providing an effective response and handling the requests submitted by the user, as specified alongside the option, service, form or data collection system used by the data subject.

Legal Basis

As a general rule, prior to processing personal data, HOTEL GREEN SUITES, SL obtains the express and unambiguous consent of the data subject by including informed consent clauses in the various information collection systems.

However, where the data subject’s consent is not required, the legal basis for the processing relied upon by HOTEL GREEN SUITES, SL shall be the existence of a law or specific regulation authorising or requiring the processing of the data subject’s personal data.

Recipients

As a general rule, HOTEL GREEN SUITES, SL does not transfer or disclose personal data to third parties, except where legally required. However, where such transfers or disclosures are necessary, the data subject shall be informed of them through the informed consent clauses contained in the various personal data collection channels.

Source of the Data

As a general rule, personal data is always collected directly from the data subject. However, in certain exceptional cases, data may be collected through third parties, entities or services other than the data subject. In such cases, this circumstance shall be communicated to the data subject through the informed consent clauses contained in the various information collection channels and within a reasonable period after the data has been obtained, and no later than one month thereafter.

Data Retention Periods

The information collected from the data subject shall be retained for as long as necessary to fulfil the purpose for which the personal data was collected. Once the purpose has been fulfilled, the data shall be deleted. Such deletion shall result in the data being blocked and retained solely at the disposal of Public Administrations, Judges and Courts, in order to address any potential liabilities arising from the processing, for the applicable statutory limitation period. Once this period has elapsed, the information shall be destroyed.

For information purposes, the following legal retention periods applicable to different types of information are set out below:

DOCUMENTPERIODLEGAL REFERENCE
Employment-related or Social Security documentation4 yearsArticle 21 of Royal Legislative Decree 5/2000 of 4 August, approving the consolidated text of the Law on Offences and Sanctions in the Social Order
Accounting and tax documentation for commercial purposes6 yearsArticle 30 of the Spanish Commercial Code
Accounting and tax documentation for tax purposes4 yearsArticles 66 to 70 of the Spanish General Tax Law
Building access control records1 monthInstruction 1/1996 of the Spanish Data Protection Agency (AEPD)
Video surveillance1 monthInstruction 1/2006 of the Spanish Data Protection Agency (AEPD)Organic Law 4/1997

Browsing Data

With regard to browsing data that may be processed through the website, where data subject to applicable regulations is collected, users are advised to consult the Cookie Policy published on our website.

Data Subjects’ Rights

Data protection regulations grant a number of rights to data subjects or data owners, including users of the website and users of HOTEL GREEN SUITES, SL’s social media profiles.

The rights available to data subjects are as follows:

  • Right of access: the right to obtain information as to whether their personal data is being processed, the purpose of the processing being carried out, the categories of data processed, the recipients or categories of recipients, the retention period and the source of such data.
  • Right to rectification: the right to obtain the rectification of inaccurate or incomplete personal data.
  • Right to erasure: the right to obtain the deletion of personal data in the following circumstances:
    • When the data is no longer necessary for the purpose for which it was collected.
    • When the data subject withdraws their consent.
    • When the data subject objects to the processing.
    • When the data must be deleted in compliance with a legal obligation.
    • When the data has been obtained in connection with an information society service pursuant to Article 8(1) of the European General Data Protection Regulation.
  • Right to object: the right to object to a specific processing activity based on the data subject’s consent.
  • Right to restriction of processing: the right to obtain restriction of the processing of personal data where any of the following circumstances apply:
    • When the data subject contests the accuracy of the personal data, for a period enabling the company to verify its accuracy.
    • When the processing is unlawful and the data subject objects to the deletion of the data.
    • When the company no longer needs the data for the purposes for which it was collected, but the data subject requires it for the establishment, exercise or defence of legal claims.
    • When the data subject has objected to the processing while it is being verified whether the company’s legitimate grounds override those of the data subject.
  • Right to data portability: the right to receive personal data in a structured, commonly used and machine-readable format and to transmit it to another Data Controller where:
    • The processing is based on consent.
    • The processing is carried out by automated means.
  • Right to lodge a complaint with the competent supervisory authority.

Data subjects may exercise the aforementioned rights by contacting HOTEL GREEN SUITES, SL in writing at the following email address: SEVILLA@GREENSUITESHOTELES.COM, indicating in the subject line the right they wish to exercise.

In this regard, HOTEL GREEN SUITES, SL shall process the request as soon as possible and in accordance with the deadlines established under applicable data protection legislation.

Security

The security measures adopted by HOTEL GREEN SUITES, SL are those required in accordance with Article 32 of the GDPR. In this regard, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, HOTEL GREEN SUITES, SL has implemented appropriate technical and organisational measures to ensure a level of security appropriate to the existing risk.

In any event, HOTEL GREEN SUITES, SL has implemented sufficient mechanisms to:

  • Pseudonymise and encrypt personal data, where applicable.
  • Ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
  • Restore the availability of and access to personal data promptly in the event of a physical or technical incident.
  • Regularly verify, assess and evaluate the effectiveness of the technical and organisational measures implemented to ensure the security of the processing.
Scroll to Top
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.