Data Controller

ControllerAZUL-ALAVA SL
Tax IDB01244714
AddressPlaza América, 4, Vitoria-Gasteiz (01005), Araba/Álava, Spain
Privacy Contactprivacidad@calpemar.com

Personal Data We Collect

CalpeMar only collects data strictly necessary for the provision of its services:

– Identification data: name, surname, DNI/NIE/Passport of all occupants (mandatory by RD 933/2021).

– Contact data: email address, phone number.

– Payment data: processed entirely by secure payment gateways (Stripe / Redsys). CalpeMar does not store credit card data.

– Browsing data: IP address, browser type, pages visited (via technical and analytical cookies, as detailed in the Cookie Policy).

– Communications: content of messages sent via the contact form or by email.

Purpose and Legal Basis for Processing

Booking ManagementExecution of the vacation rental contract (Art. 6.1.b GDPR).
Traveler RegistrationCompliance with legal obligation — RD 933/2021 (Art. 6.1.c GDPR).
Commercial CommunicationsExpress consent of the data subject (Art. 6.1.a GDPR). Revocable at any time.
Website Service ImprovementLegitimate interest of CalpeMar (Art. 6.1.f GDPR).
InvoicingCompliance with tax and accounting obligations (Art. 6.1.c GDPR).

Data Retention

Personal data will be retained for the time necessary for the provision of the service and, subsequently, for the applicable legal limitation periods:

– Booking and contract data: 5 years (limitation period for contractual actions).

– Tax and invoicing data: 6 years (General Tax Law).

– Traveler registration data: 3 years (RD 933/2021).

– Commercial communications data: until consent is withdrawn.

Data Transfer to Third Parties

CalpeMar does not sell, rent, or transfer personal data to third parties for commercial purposes. Data may be communicated to:

– State Security Forces and Corps: legal obligation derived from RD 933/2021.

– Tax Administration: in compliance with tax obligations.

– Technology service providers (processors): payment gateway, web platform, booking manager — all bound by a data processing agreement in accordance with Art. 28 GDPR.

International Transfers

In the event of using technology providers based outside the European Economic Area (EEA), CalpeMar guarantees that such transfers are carried out under adequate safeguards: European Commission Adequacy Decisions or Standard Contractual Clauses (SCCs).

Rights of Data Subjects

The data subject may exercise the following rights at any time, recognized by the GDPR and the LOPDGDD:

To exercise any of these rights, the data subject may contact:

Email: privacidad@calpemar.com

Postal address: AZUL-ALAVA SL, Plaza América, 4, Vitoria-Gasteiz (01005), Araba/Álava, Spain

A response will be provided within a maximum period of one month from the receipt of the request, extendable by two additional months in cases of particular complexity.

The data subject has the right to file a complaint with the Spanish Data Protection Agency (AEPD) — www.aepd.es — if they consider that the processing of their data does not comply with current regulations.

Data Security

CalpeMar applies appropriate technical and organizational measures to ensure a level of security adequate to the risk, including encryption of communications via HTTPS/TLS protocol, access control to systems, and security incident management procedures in accordance with Art. 33 GDPR.