Privacy policy

Last updated: 21 August 2026

This policy describes the processing of personal data carried out on reydelacosta.es: what data is collected, for what purpose and on what legal basis, who the recipients are, how long it is retained and how to exercise the rights granted by the General Data Protection Regulation.

1. Who the controller is

Data controller
Ismael Oñoro Espliego · Spanish tax ID (NIF) 03127541R
Address
Calle Sotavento, Vera Playa, 04621 Almería (Spain)
Email
reydelacostavera@gmail.com
Phone
(+34) 624 32 07 18

2. Scope

This policy applies to the whole of reydelacosta.es. Most personal data is processed in the booking area, at reydelacosta.es/reservas, where bookings are requested and where, before arrival, the traveller register required by law is completed.

3. What we process and on what legal basis

3.1. Booking request

The following data is collected when a booking is requested:

  • Full name.
  • Email address.
  • Number of guests and dates of the stay.
  • An optional free-text message.

3.2. Traveller register

Spanish Royal Decree 933/2021 requires accommodation providers to register the details of every person staying, including minors. Fourteen days before arrival, the following is requested for each of them:

  • Full name.
  • Identity document type and number and, where the document type requires it, its support number. For guests under 18, only if they hold a document.
  • Date of birth.
  • Full postal address, including the country and, for addresses in Spain, the province and municipality.
  • Phone and email.

Gender, nationality and, where guests under 18 are travelling, their relationship to the responsible adult may be provided optionally.

Providing the data in the list above is mandatory: without it, check-in cannot be completed, as the registration obligation could not be met.

3.3. Purposes and legal bases

Purpose Legal basis
Managing the booking and the accommodation contract Performance of a contract to which you are a party
Completing the traveller register and submitting it to the authorities Legal obligation (Spanish Royal Decree 933/2021)
Processing the payment for the booking Performance of the contract

3.4. Processing that is not carried out

No commercial or advertising communications are sent, no profiles are built, user behaviour is not analysed, and no automated decisions with legal or similarly significant effects are taken. Data is neither sold nor shared with third parties for commercial purposes.

4. Recipients of the data

Recipient Data disclosed and purpose
Cecabank / Ibercaja
Payment gateway
Card details are entered within the bank's own environment and are not accessible to the controller. The booking reference, the amount and the dates are disclosed. The guest's name is not disclosed.
Spanish Ministry of the Interior
SES.Hospedajes platform
The traveller register data, in compliance with the legal obligation described in section 3.2.
Hostinger
Hosting provider
Provides hosting for the website. It acts as a processor under the agreement in place and does not process the data for its own purposes.

No data is disclosed to any other recipient, except where required by law.

5. Source of the data

As a rule, the data is provided by the data subject. Where the booking is made through Airbnb or Booking.com, the booking details are received from those platforms. From that point onwards, the processing is the one described in this policy.

6. Retention period

Booking data is retained for 36 months from the date of check-out. Once that period elapses it is anonymised automatically, so that it is no longer associated with an identifiable person. Archived copies of the communications relating to the booking are deleted at the same time.

The period reflects the obligation under Spanish Royal Decree 933/2021 to keep the traveller register for three years.

7. Rights of data subjects

You may exercise your rights of access, rectification, erasure, restriction of processing, objection and portability at any time by sending a request to reydelacostavera@gmail.com stating the right you wish to exercise. Requests are answered within the one-month period laid down in article 12.3 of the General Data Protection Regulation.

Limits on the right to erasure

While the retention period for the traveller register is running, the data contained in that register cannot be erased at the data subject's request, as it is subject to a legal obligation on the accommodation provider. Other data can be erased, and the register data is anonymised once the period ends.

If you consider that your request has not been dealt with properly, you may lodge a complaint with the Spanish Data Protection Agency: https://www.aepd.es.

8. Security measures

The following technical measures are in place:

  • Communications with the site are encrypted using HTTPS.
  • Card details are entered within the bank's environment and are not processed on the controller's systems.
  • Administrative access is protected by a password and by limits on login attempts.
  • Personal links sent to guests, such as the traveller register link, expire.

9. Processing outside the booking area

Across the rest of the site no cookies are set and there are no forms: the contact buttons open the device's email, phone or WhatsApp application and transmit nothing by themselves. Details are given in the cookie policy. With two exceptions:

  • Weather forecast. The location page requests weather data from the Open-Meteo service. That request sets no cookies and transmits no identifier, although, like any request on the internet, it discloses the IP address to the server answering it.
  • Server logs. The hosting provider generates technical logs (IP address, date and resource requested) necessary to provide the service and detect incidents.

10. Virtual assistant

Every page of the website includes a conversational virtual assistant. No processing takes place until the user writes a message.

  • Data processed. The text entered and the language of the conversation. Users are not asked to identify themselves. Personal data should not be entered into the assistant; the email address and phone number are provided for that purpose.
  • Purpose and legal basis. To answer questions about the apartment and its surroundings, on the basis of the controller's legitimate interest in responding to enquiries from prospective guests.
  • Retention. Conversations are not stored. The history remains only in the browser while the window is open and is discarded when it is closed. It is not saved to any database and is not linked to any booking.
  • Processors. The message is transmitted to Cloudflare, acting as a technical intermediary, and to Anthropic, which generates the reply. Both entities are established outside the European Economic Area, so this transmission constitutes an international transfer of data. Any processing these entities carry out on their own account is governed by their respective terms, available at cloudflare.com and anthropic.com.
  • Dictation feature. The microphone button uses the browser's own speech recognition feature. In some browsers this feature transmits the audio to the browser vendor's servers. The controller does not receive the audio, only the text transcribed by the browser. This can be avoided by typing the message instead of dictating it.

These transfers are covered by the Standard Contractual Clauses approved by the European Commission, incorporated into the data processing agreements of both providers. You may request a copy by writing to reydelacostavera@gmail.com.

11. Amendments to this policy

Any material change to the processing described here will be reflected on this page and in the update date shown at the top. Where a change affects a booking in progress, it will be notified by email.

Note. This document was drafted by the owner with technical assistance and has not been reviewed by a legal professional. Legal review is recommended.