PRIVACY POLICY – EXTENDED INFORMATION
LAST MODIFIED: 08/07/2026
The Privacy Policy is part of the General Conditions governing the Website www.hotelcappuccino.com together with the Cookie Policy and the Legal Notice.
HOTEL CAPPUCCINO SL reserves the right to modify or adapt this Privacy Policy at any time. Therefore, we recommend that you review it each time you access the Website. In the event that the user has registered on the website and accesses their account or profile, they will be informed if there have been substantial modifications regarding the processing of their personal data.
Who is responsible for processing your data?
The data collected or voluntarily provided through the Website, whether by browsing it, as well as all data you may provide through contact forms, email or telephone, will be collected and processed by the Data Controller, whose details are indicated below:
HOTEL CAPPUCCINO
Plaça de Cort, 07001, Palma de Mallorca, Balearic Islands.
HOTEL CAPPUCCINO S.L. Tax ID: B57992174
Address: C/San Miguel 53, 07002, Palma de Mallorca, Balearic Islands.
Phone: 871 037 437
DPO Contact: info@hotelcappuccino.com
Registered in the Commercial Registry of Palma de Mallorca, Volume 2681, Folio 50, Sheet PM-80042, Entry 1.
Contact at HOTEL CAPPUCCINO SL for the protection of your personal data
Phone: 871 037 437
Email: info@hotelcappuccino.com
If, for any reason, you wish to contact us regarding any matter related to the processing of your personal data or privacy (with our Data Protection Officer), you may do so through any of the means indicated above.
What data do we collect through the website?
Simply by browsing the Website, HOTEL CAPPUCCINO SL will collect information regarding:
- IP Address.
- Browser version.
- Operating system.
- Duration of the visit or browsing on the Website.
Such information is stored through Google Analytics, so we refer to Google's Privacy Policy, as they collect and process such information. http://www.google.com/intl/en/policies/privacy/
Similarly, the Website provides the Google Maps utility, which may have access to your location, if you allow it, in order to provide you with greater specificity about distance and/or directions to our locations. In this regard, we refer to the Privacy Policy used by Google Maps, in order to know the use and processing of such data http://www.google.com/intl/en/policies/privacy/
The information we handle will not be related to a specific user and will be stored in our databases, for the purpose of statistical analysis, improvements to the Website, our products and/or services, and will help us improve our commercial strategy. The data will not be communicated to third parties.
User registration on the website / Form submission
To access certain functions, such as contact, the user must fill out a form. To do so, a series of personal data is requested in the registration form. The data are necessary and mandatory to carry out such registration. If such fields are not provided, registration will not be completed.
In this case, browsing data will be associated with the user's registration data, identifying the specific user browsing the Website. This way, we can personalize the offer of products and/or services that, in our opinion, best suit the user.
The registration data of each user will be incorporated into the databases of HOTEL CAPPUCCINO SL, along with the history of operations carried out by them, and will be stored while the registered user account is not deleted. Once such account is deleted, this information will be separated from our databases, keeping data related to transactions carried out separate for 10 years, without accessing or altering them, in order to comply with legally applicable deadlines. Data not linked to transactions will be maintained unless consent is withdrawn, in which case they will be immediately deleted (always taking into account legal deadlines).
The legal basis for processing your personal data is the execution of a contract between the parties.
Regarding the sending of communications and promotions electronically and responding to information requests, the legitimacy of processing is the user's consent.
The purposes of processing will be the following:
a) Manage your access to the Website.
b) Keep you informed of the processing and status of your requests.
c) Manage all utilities and/or services offered by the platform to the user.
Thus, we inform you that you may receive communications via email and/or on your phone, in order to inform you of possible incidents, errors, problems and/or status of your requests.
For the sending of commercial communications, express consent will be requested from the user when registering. In this regard, the user may revoke the consent given, by contacting HOTEL CAPPUCCINO SL, using the means indicated above. In any case, in each commercial communication, you will be given the possibility to unsubscribe from receiving them, either through a link and/or email address.
Newsletter Sending
In the event that the Website allows the option to register for the Newsletter, it will be necessary for you to provide a series of personal data and an email address to which the information will be sent.
Such information will be stored in a database, in which it will remain registered until the interested party requests to unsubscribe or, where appropriate, HOTEL CAPPUCCINO SL ceases sending it.
The legal basis for processing this personal data is the express consent given by all interested parties who subscribe to this service by checking the box designated for this purpose.
Email data will only be processed and stored for the purpose of managing the Newsletter sending by users who request it.
For sending the Newsletter, express consent will be requested from the user when registering by checking the box designated for this purpose. In this regard, the user may revoke the consent given, by contacting HOTEL CAPPUCCINO SL, using the means indicated above. In any case, in each communication, you will be given the possibility to unsubscribe from receiving them, either through a link and/or email address.
_________________________________________________________________________________________________
If you belong to any of the following groups, please consult the dropdown information:
+ WEBSITE OR EMAIL CONTACTS
For what purposes will we process your personal data?
Answer your queries, requests or petitions.
Manage the requested service, answer your request, or process your petition.
Information by electronic means, regarding your request.
Commercial or event information by electronic means, provided there is express authorization.
What is the legitimacy for processing your data?
The acceptance and consent of the interested party: In cases where it is necessary to fill out a form and click the submit button to make a request, doing so will necessarily imply that you have been informed and have expressly given your consent to the content of the clause attached to said form or acceptance of the privacy policy.
All our forms have a checkbox with the following formula, in order to send the information: "□ I have read and accept the Privacy Policy."
+ CLIENTS
For what purposes will we process your personal data?
Preparation of the budget and follow-up through communications between both parties.
Information by electronic means, regarding your request.
Commercial or event information by electronic means, provided there is express authorization.
Manage administrative, communications and logistics services carried out by the Controller.
Carry out corresponding transactions.
Billing and declaration of appropriate taxes.
Control and collection management.
What is the legitimacy for processing your data?
The legal basis is your consent and the execution of a contract.
Recipients and providers
In general, personal data will not be communicated to third parties, except for legal obligation (for example, to the Tax Agency, financial entities or Security Forces when required by applicable regulations).
However, for the adequate provision of services offered on this website and within the framework of the contractual relationship with clients, certain providers acting as Data Processors may have access to the data, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR). Among them, and by way of example:
Google Analytics (web analytics service). May involve international transfers to the United States under the guarantees mentioned.
WhatsApp Business (messaging channel for communication with clients and users). The use of this service implies the application of the privacy policies of Meta Platforms, Inc., and may involve international data transfers.
In all cases, these providers act following our instructions, do not process data for their own purposes and are contractually bound through a data processing agreement in accordance with Article 28 GDPR and Organic Law 3/2018, of December 5, on Personal Data Protection and guarantee of digital rights (LOPDGDD).
+ GUESTS
For what purposes will we process your personal data?
Manage your reservation, including prior processing, confirmation, modification or cancellation.
Provide accommodation services and associated services (check-in, stay, complementary services, guest service, etc.).
Necessary communications during your stay, including those related to your reservation, special requests or incidents.
Compliance with legal obligations for traveler registration, in accordance with applicable regulations on public safety.
Administrative, accounting and tax management, including billing and tax filing.
Process charges and transactions corresponding to contracted services.
Satisfaction surveys and service quality monitoring.
Sending commercial or promotional information, provided there is express authorization from you.
Internal control, audit, fraud prevention and collection management, when applicable.
What is the legitimacy for processing your data?
The legal bases that legitimize processing are:
The execution of a contract, to manage the reservation, stay and associated services.
Compliance with legal obligations, especially those derived from traveler registration regulations, tax and accounting.
Your consent, when necessary for sending commercial communications or for certain optional processing.
Recipients and providers
In general, your personal data will not be communicated to third parties, except:
Legal obligation, for example:
– State Security Forces (traveler registration), Tax Agency, financial entities for payment management, courts and tribunals, when appropriate.
+ SUPPLIERS
For what purposes will we process your personal data?
Information by electronic means, regarding your request.
Commercial or event information by electronic means, provided there is express authorization.
Manage administrative, communications and logistics services carried out by the Controller.
Billing.
Carry out corresponding transactions.
Billing and declaration of appropriate taxes.
Control and collection management.
What is the legitimacy for processing your data?
The legal basis is the acceptance of a contractual relationship, or failing that, your consent when contacting us or offering us your products through any means.
Declaration of appropriate taxes.
What is the legitimacy for processing your data?
The legal basis is contractual, the acceptance of a contract either for share purchase or similar, or participation in the incorporation of the company.
+ LOYALTY CARD USERS (IF APPLICABLE)
For what purposes will we process your personal data?
Manage your registration and participation in the loyalty program (if applicable), including the creation and maintenance of your user account.
Apply the advantages, special conditions, discounts and preferential rates associated with the loyalty program.
Manage the accumulation and redemption of points or benefits, according to program conditions.
Make informative communications related to your membership in the program (updates, changes in conditions, point reminders, etc.).
Send personalized commercial communications, promotions and exclusive offers for program members, provided you have given express consent.
Analyze habits and preferences, in an aggregated manner and always within legality, to improve program quality and better personalize the advantages offered.
Prevent fraud and ensure program security, as well as conduct internal audits when necessary.
What is the legitimacy for processing your data?
The legal bases that legitimize processing are:
Your consent, given when registering in the loyalty program and accepting its conditions.
The execution of the contractual relationship, necessary to manage your participation in the program, apply advantages and maintain your loyalty account.
The legitimate interest of the hotel, in ensuring program security and preventing fraud, always within the limits of Article 6.1.f) of the GDPR.
+ SOCIAL MEDIA CONTACTS
For what purposes will we process your personal data?
Answer your queries, requests or petitions.
Manage the requested service, answer your request, or process your petition.
Relate with you and create a community of followers.
What is the legitimacy for processing your data?
The acceptance of a contractual relationship in the environment of the corresponding social network, and in accordance with their Privacy policies:
Instagram: https://es-la.facebook.com/help/instagram/155833707900388;
Facebook: http://www.facebook.com/policy.php?ref=pf
Whatsapp: https://www.whatsapp.com/legal/#privacy-policy
How long will we keep personal data?
We can only consult or delete your data in a restricted manner by having a specific profile. We will process them as long as you allow us by following us, being friends or clicking "like", "follow" or similar buttons.
Any rectification of your data or restriction of information or publications must be done through the configuration of your profile or user in the social network itself.
+ VIDEO SURVEILLANCE
For what purposes will we process your personal data?
Video surveillance of our facilities.
Control of our employees.
Occasionally they may be transferred to courts and tribunals for the exercise of legitimate actions.
What is the legitimacy for processing your data?
The legal basis for processing is the legitimate interest of the controller, in accordance with Article 6.1.f of the GDPR and Article 22 of the Organic Law on Data Protection and Guarantee of Digital Rights (LOPDGDD).
+ JOB APPLICANTS
For what purposes will we process your personal data?
Organization of selection processes for hiring employees.
Schedule job interviews and evaluate your candidacy.
If you have given us your consent, we may transfer it to collaborating or related entities, with the sole purpose of helping you find employment.
What is the legitimacy for processing your data?
The legal basis is your unequivocal consent, by delivering your CV and receiving and signing information related to the processing we will carry out.
How long will we keep personal data?
The curriculum will be stored for a period of one year, after which, if we have not contacted you, it will be deleted.
+ HR
For what purposes will we process your personal data?
Manage the employment relationship, including the creation and maintenance of your employee file.
Carry out all administrative, tax, accounting and Social Security procedures necessary to comply with our obligations as an employer, in accordance with labor regulations, occupational risk prevention, tax and accounting.
Manage payroll payments and other remuneration through the corresponding financial entity.
Manage time tracking, through working time recording systems such as card, personal code, platform or employee portal, or any other system enabled by the company.
Manage collective insurance, social benefits or pension plans in which staff may be included.
Manage staff training, both subsidized and non-subsidized, as well as mandatory actions regarding occupational risk prevention.
Manage incidents, permits, absences, sanctions and any action derived from the employment relationship.
Ensure internal regulatory compliance, internal audit controls and fraud prevention actions, to the extent permitted by law.
What is the legitimacy for processing your data?
The legal bases that allow processing are:
The execution of the employment contract and the application of pre-contractual measures (Art. 6.1.b) GDPR).
Compliance with legal obligations applicable to the employer in labor matters, Social Security, occupational risk prevention, taxation and accounting (Art. 6.1.c) GDPR).
The worker's consent, only for those treatments not covered by the employment relationship or legal obligation (for example, certain voluntary benefits or optional training actions).
The legitimate interest of the employer, in cases such as internal controls, audits or fraud prevention, always within the limits of Art. 6.1.f) GDPR.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Do we include personal data of third parties?
No, as a general rule we only process data provided by the data subjects. If you provide us with third-party data, you must previously inform and request consent from said persons, otherwise you exempt us from any responsibility for non-compliance with this requirement.
What about minors' data?
We do not process data from minors under 14 years of age, therefore, refrain from providing it if you are not of that age.
Will we make communications by electronic means?
They will only be made to manage your request, if it is one of the contact means you have provided us.
If we make commercial communications, they will have been previously and expressly authorized by you.
What security measures do we apply?
The Data Controller declares that it has adopted the necessary technical and organizational measures to guarantee a level of security appropriate to the risk, in compliance with the provisions of Article 32 of the GDPR and the LOPDGDD.
In particular, among other measures, the following are applied:
Encryption of communications and data in transit through secure protocols (TLS/SSL).
Access control based on personal and non-transferable credentials, with the principle of least privilege.
Data segregation by client and project, avoiding unauthorized cross-access.
Access and operation logging and monitoring, with periodic reviews to detect improper access or incidents.
Encrypted backups, with recovery and periodic verification procedures.
Confidentiality policies signed by persons with access to information.
Regular updating and patching of systems and services used.
Periodic security reviews and audits, including internal verification tests and, where appropriate, data protection impact assessments (DPIA) when the type of processing so requires.
These measures are periodically reviewed and adapted to the state of the art, the nature of the data processed and the risks detected.
To what extent will decision-making be automated?
HOTEL CAPPUCCINO SL does not use fully automated decision-making processes to establish, develop or terminate a contractual relationship with the user. If we use such processes in a particular case, we will keep you informed and communicate your rights in this regard if required by law.
Will profiling take place?
In order to offer you products and/or services according to your interests and improve your user experience, we may create a "commercial profile" based on the information provided. However, no automated decisions will be made based on said profile.
To which recipients will your data be communicated?
Your data will not be transferred to third parties, except for legal obligation. Specifically, they will be communicated to the State Tax Administration Agency and to banks and financial entities for the collection of the service provided or product acquired, as well as to the data processors necessary for the execution of the agreement.
In case of purchase or payment, if you choose any application, website, platform, bank card, or any other online service, your data will be transferred to that platform or processed in its environment, always with maximum security.
In the event that you have given us your consent for the processing of your name and images and other information, related to the activity of HOTEL CAPPUCCINO SL, it will be disseminated on different social networks and website.
International transfers.
In general, the Controller ensures that personal data is stored and processed within the European Economic Area (EEA). However, for the adequate provision of the services described in this policy, it may be necessary to use technology providers located outside the EEA.
In such cases, appropriate safeguards provided for in Chapter V of the GDPR will always be applied, ensuring a level of protection equivalent to the European one. Among the mechanisms applied are:
Adequacy decisions of the European Commission, such as the EU-U.S. Data Privacy Framework, when the provider is adhered to said system.
Standard Contractual Clauses (SCCs) approved by the European Commission, complemented with transfer impact assessments and, where appropriate, additional security measures.
In particular, it is reported that certain services used (e.g. Zcal, AI model providers such as OpenAI, or Google Analytics) may involve transfers to the United States. Such transfers are made under the guarantees indicated.
Likewise, in case of using cloud storage systems or shared folders (e.g., Dropbox, Google Drive, Microsoft OneDrive, Amazon Web Services, Apple iCloud, HubSpot or other similar providers), the above mechanisms will be applied to guarantee an adequate level of protection in accordance with the provisions of the GDPR.
What Rights do you have?
To know if we are processing your data or not.
To access your personal data.
To request the rectification of your data if it is inaccurate.
To request the deletion of your data if it is no longer necessary for the purposes for which it was collected or if you withdraw the consent granted.
To request the limitation of the processing of your data, in some cases, in which case we will only keep them in accordance with current regulations.
To port your data, which will be provided in a structured, commonly used or machine-readable format. If you prefer, we can send it to the new controller you designate. Only valid in certain cases.
To file a complaint with the Spanish Data Protection Agency, if you believe we have not served you correctly.
To revoke consent for any processing for which you have consented, at any time.
If you modify any data, we would appreciate it if you let us know to keep them updated.
Do you want a form for exercising Rights?
We have forms for exercising your rights, ask us by email or if you prefer, you can use those prepared by the Spanish Data Protection Agency or third parties.
These forms must be electronically signed or accompanied by a photocopy of the ID.
If someone represents you, you must attach a copy of their ID, or have them sign with their electronic signature.
Forms may be presented in person, sent by letter or by email to the address of the Controller at the beginning of this text.
You have the right to file a complaint with the Spanish Data Protection Agency, in the event that you consider that the request for your rights has not been adequately addressed.
The maximum period to resolve is one month, counting from the effective receipt of your request by us.
You have the right to revoke at any time the consent for any of the processing for which you have granted it.
Do we process cookies?
If we use other types of cookies other than necessary ones, you can consult the cookie policy at the corresponding link from the beginning of our website.
How long will we keep your personal data?
Personal data will be kept as long as you remain linked to us.
Once you unlink, personal data processed for each purpose will be kept for the legally provided periods, including the period in which a judge or court may require them according to the statute of limitations for legal actions.
Processed data will be kept as long as the legal deadlines referred to above do not expire, if there is a legal obligation to maintain them, or if there is no such legal deadline, until the interested party requests their deletion or revokes the consent granted.
We will keep all information and communications related to your purchase or the provision of our service, while the guarantees of products or services last, to address possible claims.
In each treatment or data type, we provide you with a specific period, which you can consult in the following table:
| Data related to | Document | Retention |
|---|---|---|
| Clients and suppliers | By way of example and without limitation, some of the most significant documents are cited below. Invoices (issued by the company and charged against the company). Contracts between merchants (sale, commission, transport, service provision, etc.) Contracts with individuals. Real estate contracts (business premises leases, sale, exchange, etc.) Commercial correspondence Banking contracts and documentation (current accounts, deposits, leasing, renting, etc.) Expense notes. | Obligation to keep documentation minimum 6 years. It is advisable to keep it depending on the case of prescription of actions. Article 30 of the Commercial Code establishes that entrepreneurs will keep books, correspondence, documentation and receipts concerning their business, for six years from the last entry made in the books. However, this rule is limited to establishing a minimum period of time during which, in view of general interests, the merchant must keep the documents generated during the development of their activity. |
| Documents and records of tax significance | General Tax Law arts. 66 to 70 4 previous fiscal years VAT and other indirect tax declarations advisable to keep 10 years (EU harmonization) |
|
| Obligated subjects Money Laundering Prevention Law, documentation accrediting compliance with AML obligations | Law 10/2010 art. 25 10 years |
|
| Human Resources | Payroll, Contribution Settlement Receipt (former TC1), Worker Nominal Relationship (former TC2), etc. | General Social Security Law RDL 5/2000 Labor infractions: 3 years Social Security infractions: 5 years General labor documentation: 4 years (recommended 6 years) |
| Resumes | Until the end of the selection process, and up to 2 more years unless the interested party revokes consent or requests deletion | |
| Worker training | Art 5.2, Order TAS/2307/2007 4 years |
|
| Working Time Records | Art. 10 RDL 8/2019 and art. 34 ET modified by Law 4/2023 4 years |
|
| Severance pay documents. Contracts. Temporary worker data. |
RD 425/2005 section 3 Additional Provision 1 4 years Art. 30 of the Commercial Code establishes a minimum period of 6 years. Organic Law 7/2012 recommends keeping it for 10 years. |
|
| Employee file. | Up to 5 years after termination (Royal Legislative Decree 5/2000, of August 4, approving the consolidated text of the Law on Infractions and Sanctions in the Social Order). | |
| Documentation or computer records accrediting compliance with ORP regulations | RDL 5/2000 art. 4 5 years |
|
| Marketing | Databases or website visitors. | While processing lasts. |
| Access control and video surveillance | Visitor registry | Instruction 1/1996 AEPD Art. 22 LOPDGDD 30 days |
| Video surveillance Images/sounds captured by video surveillance systems will be cancelled within a maximum period of one month from their capture. Recordings will be destroyed within a maximum period of one month from their capture, unless they are related to criminal or serious or very serious administrative infractions in public safety matters, with an ongoing police investigation or with an open judicial or administrative procedure |
Instruction 1/2006 AEPD Art. 22 LOPDGDD 30 days |
|
| Accounting | Accounting books and documents. Annual accounts Partner and board of directors agreements, company bylaws, minutes, board of directors regulations and delegated committees. Financial statements, audit reports Records and documents related to subsidies |
Commercial Code art. 30: 6 years |
| Corporate Documentation | Deeds of incorporation of the company together with the bylaws, deeds of elevation of corporate agreements, of granting/renewal of powers, deed of purchase and sale of shares, deed of purchase and sale of assets, of shares, of dissolution/liquidation, etc.) Minute books of general shareholders' meetings and board of directors (commercial companies), regulatory share registry book, partner registry book, contracts registry book with the sole partner, other books. Other type of corporate documentation (private share purchase and sale contracts, participating loans, share pledges, etc.) |
It is recommended to keep them throughout the life of the company, from its incorporation until at least 6 years after its dissolution and liquidation. If the deeds incorporated rights or obligations for the company, it is recommended to adhere to the previously indicated prescription periods. Obligation to keep documentation minimum 6 years. From the last entry made in the Books. They must be kept throughout the life of the company from its incorporation until at least 6 years after its dissolution and liquidation. It is recommended to keep them throughout the life of the company, from its incorporation until at least 6 years after its dissolution and liquidation. |
| Tax | Management of the entity's administration, rights and obligations related to tax payment. Administration of dividend payments and tax withholdings. All documents justifying the tax action of the taxpayer (income and expense receipts), including both accounting and supporting documentation (contracts, invoices, receipts, delivery notes...) All types of tax declarations. |
Obligation to keep documentation: Minimum 4 years. Articles 66, 67 and 68, of the General Tax Law. The general prescription period for tax obligations is 4 years. Regarding tax declarations, the 4-year prescription period begins to count from the day on which the voluntary filing period for the tax ends. If there has been a subsequent action by the Administration (inspection, partial verification) or by the taxpayer (rectifying declaration, appeal) that has interrupted the prescription, a new 4-year period begins from that action. However, it is advisable to keep the tax documentation. Organic Law 7/2012 recommends keeping it for 10 years. Order EHA/962/2007 contemplates the possibility of destroying invoices received on paper if a certified digitization process has been previously carried out that obtains electronically signed digital copies. |
| Health and Safety | Medical Records. Worker Medical Records Health data of Spa clients (wellness treatments). |
Article 17.1 of Law 41/2002 of November 14, on patient autonomy and rights and obligations regarding information and clinical documentation 5 years |
| Insurance | Insurance policies | 6 years (general rule) 2 years (damages) 5 years (personal) 10 years (life) |
| Legal | Intellectual and Industrial Property Documents. Contracts and agreements. |
5 years |
| Permits, licenses, certificates | 6 years from the expiration date of the permit, license or certificate. 10 years (criminal prescription) |
|
| Confidentiality and non-compete agreements | Always the duration of the obligation or confidentiality | |
| Data protection regulations. Once the retention period has been met, the data must be blocked (art. 32 LOPDGDD) and kept only available to competent authorities during the prescription periods for responsibilities, after which they will be definitively deleted. |
Records and documents accrediting compliance with data protection regulations requirements (audits, reports, processor contracts, etc) | While data processing lasts and then for 3 years |
| Documentation accrediting that requests for exercise of data subject rights are addressed | For 3 years after the request |
|
| Logs / Access records to information systems | 2 years | |
| If processing is based on the data subject's consent, proof of consent | While data processing lasts and then for 3 years |
|
| Traffic data related to internet connections, emails and calls sent or received from landline telephony | User identifier, IP address (origin/destination), telephone number, IMSI and IMEI (origin/destination), date and time of communication (start/end), identification of the type of service or communication used (voice, data, SMS or MMS) | Article 5, of Law 25/2007, on data retention related to electronic communications and public communications networks. 1 year |
| Biometric data (fingerprint, facial recognition), if applicable, pursuant to guidelines published by the AEPD. Currently in Spain there is no legitimacy for its use, for access or labor control, except positive Impact Assessment). | Biometric data is recorded in the tool/software enabled for this purpose by the entity, in case of having carried out a positive Impact Assessment, within the current legal framework. | Complying with the principle of limitation of the retention period, personal data may be processed no longer than necessary for the purposes of processing, therefore, taking into account the provisions of article 34.9 of the ET, the company will keep records for four years and will remain available to workers, their legal representatives and the Labor and Social Security Inspection. It will be the user who notifies and initiates the definitive termination procedure. Building access control: 30 days, files to control access (Inst. 1/1996 AEPD) INACTIVE FINGERPRINTS: 6 MONTHS OF INACTIVITY. RECORDS: EMPLOYEES, 4 YEARS, NON-EMPLOYEES: 30 DAYS |
| Academic data, academic record, student identification data, attendance data, sanctions, psycho-pedagogical reports, continuous evaluation data and final results, scholarship and aid applications. | Academic file, personal data file of the educational center, academic record, reports and disciplinary records, evaluation records and report cards, scholarship application and resolution files | File and academic record: permanently. Reports and disciplinary records: 5 years. Evaluation records and report cards: permanently for records and 5 years for report cards. Scholarship application and resolution files: 6 years from resolution. |
| Guests | Traveler/guest entry registration (check-in). | 3 years (Organic Law 4/2015 on citizen security protection, Order INT/1922/2003 and RD 933/2021, of October 26 (documentation and information registration obligations of natural or legal persons engaged in accommodation activities). |