Data Controller
| Controller | AZUL-ALAVA SL |
| Tax ID | B01244714 |
| Address | Plaza América, 4, Vitoria-Gasteiz (01005), Araba/Álava, Spain |
| Privacy Contact | privacidad@calpemar.com |
Personal Data We Collect
CalpeMar only collects data strictly necessary for the provision of its services:
– Identification data: name, surname, DNI/NIE/Passport of all occupants (mandatory by RD 933/2021).
– Contact data: email address, phone number.
– Payment data: processed entirely by secure payment gateways (Stripe / Redsys). CalpeMar does not store credit card data.
– Browsing data: IP address, browser type, pages visited (via technical and analytical cookies, as detailed in the Cookie Policy).
– Communications: content of messages sent via the contact form or by email.
Purpose and Legal Basis for Processing
| Booking Management | Execution of the vacation rental contract (Art. 6.1.b GDPR). |
| Traveler Registration | Compliance with legal obligation — RD 933/2021 (Art. 6.1.c GDPR). |
| Commercial Communications | Express consent of the data subject (Art. 6.1.a GDPR). Revocable at any time. |
| Website Service Improvement | Legitimate interest of CalpeMar (Art. 6.1.f GDPR). |
| Invoicing | Compliance with tax and accounting obligations (Art. 6.1.c GDPR). |
Data Retention
Personal data will be retained for the time necessary for the provision of the service and, subsequently, for the applicable legal limitation periods:
– Booking and contract data: 5 years (limitation period for contractual actions).
– Tax and invoicing data: 6 years (General Tax Law).
– Traveler registration data: 3 years (RD 933/2021).
– Commercial communications data: until consent is withdrawn.
Data Transfer to Third Parties
CalpeMar does not sell, rent, or transfer personal data to third parties for commercial purposes. Data may be communicated to:
– State Security Forces and Corps: legal obligation derived from RD 933/2021.
– Tax Administration: in compliance with tax obligations.
– Technology service providers (processors): payment gateway, web platform, booking manager — all bound by a data processing agreement in accordance with Art. 28 GDPR.
International Transfers
In the event of using technology providers based outside the European Economic Area (EEA), CalpeMar guarantees that such transfers are carried out under adequate safeguards: European Commission Adequacy Decisions or Standard Contractual Clauses (SCCs).
Rights of Data Subjects
The data subject may exercise the following rights at any time, recognized by the GDPR and the LOPDGDD:
- Right of access: to know what personal data we process.
- Right to rectification: to request the correction of inaccurate data.
- Right to erasure (“right to be forgotten”): to request the deletion of your data.
- Right to restriction of processing: to request the suspension of processing in certain circumstances.
- Right to data portability: to receive your data in a structured, commonly used format.
- Right to object: to object to the processing of your data based on legitimate interest.
- Right not to be subject to automated decisions: currently not applicable to CalpeMar’s services.
To exercise any of these rights, the data subject may contact:
Email: privacidad@calpemar.com
Postal address: AZUL-ALAVA SL, Plaza América, 4, Vitoria-Gasteiz (01005), Araba/Álava, Spain
A response will be provided within a maximum period of one month from the receipt of the request, extendable by two additional months in cases of particular complexity.
The data subject has the right to file a complaint with the Spanish Data Protection Agency (AEPD) — www.aepd.es — if they consider that the processing of their data does not comply with current regulations.
Data Security
CalpeMar applies appropriate technical and organizational measures to ensure a level of security adequate to the risk, including encryption of communications via HTTPS/TLS protocol, access control to systems, and security incident management procedures in accordance with Art. 33 GDPR.