Legal
Privacy Policy
Last updated: [TODO — date]
This is a template, not legal advice. Every field marked [TODO] must be completed, and the finished text should be reviewed by a lawyer qualified in Spanish and EU data-protection law before the site goes live. Spanish law (LOPDGDD) requires this notice to also be available in Spanish; you will likely want a Dutch version too, to match the site.
1. Who we are
The data controller is Paseo de Salamera S.L., operator of Hotel S'Alamera, Paseo de S'Alamera, Santa Eulalia del Río, Ibiza, Spain.
[TODO] Add company registration number (CIF/NIF), full registered address, and a contact email for privacy enquiries. If you have appointed a Data Protection Officer, add their contact details here.
2. What we collect
When you register your interest through this website, we collect:
- Your email address
- The language version of the site you used
- The date and time of your registration, and a record of your consent
We do not ask for your name, address, phone number, or payment details on this site.
[TODO] If you add analytics, a booking engine, a chat widget, or any cookies beyond what is strictly necessary, they must be described here and gated behind a consent banner. At present this site sets no cookies and runs no analytics — if that stays true, say so plainly.
3. Why we use it, and on what legal basis
We use your email address solely to notify you about the opening of Hotel S'Alamera and to offer priority reservations and pre-opening rates. The legal basis is your consent under Article 6(1)(a) GDPR, given by ticking the box on the registration form.
You may withdraw your consent at any time; every message we send will include an unsubscribe link. Withdrawing consent does not affect the lawfulness of processing carried out beforehand.
4. Who we share it with
Your email address is stored and processed by the service that receives our registration form and by our email delivery provider, both acting as data processors on our instructions.
[TODO] Name the actual providers (for example the form endpoint service and the mailing platform), state whether either transfers data outside the EEA, and if so identify the safeguard relied upon — normally the European Commission's Standard Contractual Clauses. Choosing EU-hosted providers avoids this section entirely.
We do not sell your data, and we do not share it with third parties for their own marketing.
5. How long we keep it
[TODO] State a concrete retention period. A common approach for a pre-opening list: keep registrations until 12 months after the hotel opens, or until consent is withdrawn, whichever comes first — then delete.
6. Your rights
Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable format. To exercise any of these, contact us at the address in section 1.
If you believe we have handled your data improperly, you may lodge a complaint with the Spanish data protection authority, the Agencia Española de Protección de Datos.
7. Security
We apply appropriate technical and organisational measures to protect your data. The site is served over HTTPS and access to the registration list is limited to staff who need it.
[TODO] Confirm this is accurate once hosting and the form endpoint are in place.
8. Changes to this policy
We may update this policy as the project develops. The current version will always be published on this page with its revision date.