Privacy policy
This policy explains how we process your personal data in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on personal data protection and digital rights (LOPDGDD).
Data controller
- Controller: Aráiz Cuevas Romayol Arq. Ing. SL (trading as Blaustrand)
- Tax ID (CIF): B32315798
- Address: C/ Paseo nº 33, 6°B, 32003 Ourense (Spain)
- Contact: info@blaustrand.es
What data we process, why and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Managing and charging your booking and contacting you before, during and after your stay | Name, email, phone, dates, number of guests and language | Performance of the booking contract (art. 6.1.b GDPR) |
| Identifying you with your Google account to book, view and cancel your bookings in “My bookings” | Name, email and Google account identifier | Performance of the booking contract (art. 6.1.b GDPR) |
| Issuing the invoice and meeting accounting and tax obligations | Name, booking details and amount and, if you provide them, tax ID and address | Legal obligation (art. 6.1.c GDPR; Spanish General Tax Law 58/2003 and Commercial Code) |
| Guest registration and reporting to the Spanish Ministry of the Interior | For each guest: first name and surnames, sex, type and number of ID document, document support number, nationality, date of birth, address, phone or email and, for minors, relationship with the responsible adult; for the booking: dates, number of guests and payment method | Legal obligation (art. 6.1.c GDPR; Organic Law 4/2015 on public safety and Royal Decree 933/2021) |
| Answering your enquiries | The data you send us by email | Your request and our legitimate interest in answering it (art. 6.1.b and 6.1.f GDPR) |
| Keeping the website secure and making backups | IP address and technical logs; database backup | Legitimate interest in protecting the service and security obligation (art. 6.1.f and 32 GDPR) |
The fields marked as required in the forms are needed to make the booking. Guest registration data is required by law: if it is not provided, we cannot accommodate you.
Minors’ data is provided by their parent or guardian. We do not make automated decisions or create profiles.
Payments: card payments are made on the bank’s secure payment gateway (Redsys). Blaustrand never sees or stores your card details; it only receives the payment result.
Recipients
- Spanish Ministry of the Interior (State Security Forces), through the SES.HOSPEDAJES platform: guest registration data, as required by law.
- Spanish Tax Agency and other authorities, where required by law.
- The bank and Redsys, to process the payment.
- Providers that process data on our behalf (processors), under a contract in line with art. 28 GDPR: OVH (server hosting and email, in the European Union) and Google (Google sign-in through Firebase Authentication, and the owner’s email account, where booking notices and backups are received).
We do not sell your data or share it for advertising. The calendar synchronisation with Booking.com only exchanges booked dates, never guest data.
International transfers
Google LLC may process data in the United States. It participates in the EU-US Data Privacy Framework, which is covered by a European Commission adequacy decision (10 July 2023).
How long we keep data
- Unpaid bookings (payment not completed or expired): anonymised after 12 months.
- Bookings and invoices: for as long as the relationship lasts and then for the legal periods (4 years under tax law and 6 years under commercial law).
- Guest registration: 3 years after the end of the stay, as required by Royal Decree 933/2021; then deleted.
- Enquiry emails: as long as needed to answer them and at most 1 year.
- Backups: at most 3 months.
Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to info@blaustrand.es. Where necessary to verify your identity, we will ask you to prove it. We will reply within one month. Some data cannot be erased before the legal retention periods end.
If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or with the supervisory authority of your country of residence.
Security
We apply appropriate technical and organisational measures: encrypted connection (HTTPS), access to the management panel restricted to authorised people, servers in the European Union and backups.