Privacy Policy
Identification of the Controller
- Identity: HOTELBEDS SPAIN, S.L.U. (hereinafter, “Hotelbeds entity” or the “Controller”), which belongs to the Hotelbeds Group.
- Tax No. (NIF): B-28916765
- Address: Camí de Son Fangos n.º 100, Complejo Mirall Balear, Torre A, 5.º piso, 6A-7A, 07007, Palma de Mallorca (Spain)
- Data Protection Officer (DPO): dataprotection@hotelbeds.com
What is the purpose of the processing of your data, and what is its legitimate basis?
The personal data provided by users (hereinafter, “You” or the “User”) through the various forms made available on the website https://www.bkms-system.net/hotelbedsgroup (hereinafter, the "Website") will be processed for the following purposes:
- To manage whistleblowing claims, Governance-Risk-Compliance enquiries and/or Compliance advice.
- To provide communication updates (when required) with users logging whistle blowing claims (based on the user decision to identify him/herself.
The legitimate basis for these purposes is the legitimate interest to comply with legal obligations defined for Whistle blowing activities.
The data requested on the forms appearing on the Website are generally mandatory (unless otherwise specified in the required field) in order to comply with the established purposes. Therefore, if such data is not provided or is not correctly provided, the said purposes may not be fulfilled. This is without prejudice to the fact that the content of the Website will still be freely visible to You.
The use of the helpline is entirely voluntary. Please note that we can only receive and examine reports if you confirm that you have read and understood this information about Data Protection and agreed to the processing of all personal data entered by you in accordance with the present Data Protection information.
What User data will be processed by the Controller?
The Controller will process the following categories of User data:
- Identification details: your name, surname(s), or alias you decide to provide.
If You, the User, provide third-party data, You are doing this as part of your claim / communication for the whistle blowing notification, releasing the Controller from any liability in this regard. Notwithstanding the foregoing, the Controller may carry out periodic checks to confirm the whistle blower regulation supports the processing purpose, taking any due diligence measures that may be appropriate, in accordance with the data protection legislation.
Anyone over the age of 16 can navigate through the Website. However, filing and whistle blowing claim is only open to over-18s. This means that You are expressly forbidden if You are under 18.
With which recipients will User data be shared?
User data may be disclosed:
- To the Controller’s partner organisations Companies in the group to which the Hotelbeds Group belongs.
- Legal counsel services required to support whistleblowing claims that may require local support.
- Public bodies pursuant to legal obligations.
If the disclosure of data to such third-party companies involves an international transfer of data, the Controller shall take the necessary steps in accordance with the data protection legislation to ensure that the said third parties process the data with all appropriate guarantees.
Retention of Data
The personal data will be retained for the applicable legal limitation periods, unless otherwise stated. In such case, the data will be processed for the purpose of proving compliance with our legal and/or contractual obligations. We will retain personal information for as long as may be necessary or permitted in accordance with the purposes for which it was obtained.
Security Measures
The Controller will at all times process your data in full confidentiality and in accordance with the mandatory duty of secrecy in relation thereto, as provided in the applicable legislation, adopting all necessary technical and organisational measures for that purpose, in both physical and logical environments, guaranteeing the security of the data and preventing its loss, alteration or unauthorised access or processing by internal staff or any other third parties, taking into account the state of the art, the nature of the data stored and the risks to which such data is exposed. Similarly, your information is stored in a secure environment and may only be accessed by authorised staff.
In relation to this, You are hereby informed that the Controller’s systems include encryption protocols in the communication of information transmitted by the Website. When the Website is contacted, it must be processed in accordance with the Secure Socket Layer (SSL) security parameters.
However, as no communications made over the Internet can be guaranteed to be 100% secure, we cannot fully guarantee that the information provided will remain secure at all times.
Exercise of Rights
You may write to the Controller at the address provided in the heading of this Policy, or send an e-mail to the address dataprotection@hotelbeds.com, attaching a photocopy of your identity document, at any time and free of charge, for the following purposes:
- To revoke the consents granted.
- To access your personal data.
- To rectify inaccurate or incomplete data.
- To request the erasure of your data when - among other reasons - such data is no longer necessary for the purposes for which it was collected.
- To request the limitation of processing of your data when any of the conditions set forth in the data protection legislation are fulfilled.
- To request the portability of your data.
Compliance with the CCPA
If You are a subject affected by California State law in relation to the processing of your personal data, You will find more information about the ability to prevent the sale of your personal data in this link (Do Not Sell My Data).
You may also contact the DPO at the address dataprotection@hotelbeds.com, and You have the right to file a complaint relating to the protection of your personal data with the Spanish Data Protection Agency (AEPD) at the address Calle de Jorge Juan, 6, 28001 Madrid (Spain) (www.aepd.com), if You, the data subject, consider that the Controller has infringed your rights as recognised in the applicable data protection legislation.
Last updated on: May 31st, 2023