PRIVACY POLICY
Introduction
We have a high level of commitment to the privacy of individuals, so the protection of personal data is important to us.
We process data in accordance with the provisions of EU Regulation 2016/679 General Data Protection Regulation, Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights and other current regulations in this regard.
This Privacy Policy has been reviewed in June 2026 to comply with the information and transparency duties of the website itself and of the controller in general, to provide any type of interested party, and not only website users, with the general terms of the controller in this matter. There may be variations until its next review.
Who is the controller of your data?
Controller: HOTELES DE MURCIA S.A.
Tax ID (NIF/CIF): A30163547
Address: ALAMEDA RAFAEL MÉNDEZ Nº 34. 30800 LORCA (MURCIA)
Email: info@hotelesdemurcia.com
This Privacy Policy has been reviewed in June 2026 to comply with the information and transparency duties of the website itself and of the controller in general, to provide any type of interested party, and not only website users, with the general terms of the controller in this matter. There may be variations until its next review.
What is the origin and type of data we process?
The origin of the information we process may be any of the following categories:
- Forms on paper, electronic or digital media.
- Communication and messaging systems: email and messaging applications, telephone, etc.
- Other lawful sources and origins of information.
The different categories of data that we may process depending on the type of data subject (user, customer, supplier, employee, etc.) and the nature of the controller’s activity and the different data processing operations are:
- Identification data, for example: name and surname, image.
- Identification codes or keys, for example: username, employee code.
- Postal or electronic contact addresses, for example: telephone, email, social media profile.
- Personal and professional characteristics data, for example: age, date of birth, qualifications, professional experience, CV.
- Economic, financial and insurance data; for example: bank details, credit card, etc.
- Economic and non-economic payroll data and other employment-related information; for example: job position, payslip document, etc.
- Transaction data, for example: goods and services supplied and received.
- Special category data, for example: health, trade union membership, racial origin.
- Other data and information necessary or implicit in the development of our activities, services and purpose.
MANDATORY OR OPTIONAL NATURE OF THE INFORMATION PROVIDED BY THE DATA SUBJECT.The data subject, by ticking the corresponding boxes and entering data in the fields marked as mandatory (for example, with an asterisk) in the contact form or presented in download forms, expressly and freely and unequivocally accepts that their data are necessary to respond to their request by the controller, it being voluntary to include data in the remaining fields.The data subject guarantees that the personal data provided to the controller are truthful and undertakes to communicate any changes to them. The data requested through the website, marked as mandatory, are necessary for the provision of an optimal service to the data subject. In the event that not all data is provided, it is not guaranteed that the information and services provided will be fully tailored to their needs.
For what purpose do we process your personal data?
In general, the data is processed to successfully carry out the actions implicit in the normal development and management of the controller’s activity. Although we can specify different purposes of processing depending on the possible existing categories of data subjects:
- Customers and potential customers: management and maintenance of commercial, pre-contractual and contractual relationships; internal administration; economic management; advertising and marketing, customer service.
- Collaborators, creditors and suppliers: management and maintenance of commercial relationships, internal administration and economic management.
- Employees: management, development and maintenance of the employment relationship, human resources management, communications, training activities, occupational risk prevention, working time recording and other purposes derived from legal obligations and the development of employment relationships.
- Candidates: management of CVs received, management of job offers and recruitment.
- Website and social media users: user assistance and management of communications between the parties.
- Visitors: visitor assistance and access control to facilities.
- The information existing on any other category of data subjects processed by the controller will be carried out within the framework of its activity, strict compliance with the applicable rules and under the general criteria of this Privacy Policy.
Other general purposes that the controller may implement are:
- Preparation of a commercial profile, with the aim of improving your experience by personalising offers and communications. No individualised decisions will be made based on this profile and action will be taken on the basis of legitimate interest.
- Video surveillance, for the security of goods and people, as well as the corresponding labour control based on legitimate interest.
- Telephone switchboard, in order to record communications for security, guarantee and quality of service, based on legitimate interest.
- Financial management and control of monetary obligations. In the case of debtors with certain, due and enforceable outstanding payments, the controller may communicate this circumstance to credit solvency files, debtor files, and debt management or collection services, among others, based on legitimate interest.
- Communications: development and execution of communications through the available contact data and means (email, instant messaging, etc.) with internal (employees) and external (customers, potential customers, collaborators, suppliers, etc.) categories of data subjects. The purposes of such communications may be informative, organisational, commercial and advertising, as applicable, based on informed consent and the legitimate interest of the controller.
- Other purposes derived from the nature of the controller, motivated by the normal development and exercise of its activity, from a valid legitimising basis.
How long will we keep your data?
In general, personal data will be kept at least as long as there is a relationship with the data subject, as long as their deletion is not requested, as long as liabilities may arise or as long as there is any legal provision for retention.
With regard to the data of candidates and job applicants, they will be deleted immediately when they are no longer of interest to the controller.
The data controller has in its data protection plan an inventory of retention periods that it observes to manage the different applicable retention periods.
The deletion of data will in all cases be carried out ensuring its confidentiality.
What is the legal basis for the processing of your data?
The controller observes and applies the different existing legitimising bases that apply to each purpose of processing. These are:
- Informed consent of the data subject.
- Pre-contractual or contractual commitments.
- Legitimate interest of the controller.
- Applicable legal obligations.
- Other legally required legitimising bases.
To which recipients will your data be disclosed?
The data of data subjects will not be disclosed to any third party by default, except: a) auxiliary services, authorised data processors or other third parties implicitly necessary for the correct provision of goods and services; b) competent authorities and public administrations in the exercise of their functions; c) other legitimate interested parties and third parties provided for by law.
What are your rights when you provide and/or we process your data?
As a data subject, you may at any time request the exercise of any of the following rights that assist you in matters of data protection:
- Access to the personal data of the data subject to confirm whether or not data concerning them is being processed and to obtain more information about this processing.
- Rectification or Erasure of the personal data concerning the data subject when, among other reasons, they are inaccurate or are no longer necessary for the purposes for which they were collected.
- Restrict the processing of the personal data of the data subject in certain circumstances, in which case they will only be kept for the exercise or defence of claims, for the protection of the rights of another person or for reasons of public interest.
- Receive the personal data concerning them that they have previously provided to us, and in a structured format where possible. (Data portability).
- Object to the processing of their data in certain circumstances and for reasons related to their particular situation. The company will stop processing their data, except for compelling legitimate reasons, or the exercise or defence of possible claims.
- Withdraw consent, which may lead to the cancellation or termination of the existing business or contractual relationship, if any. Without prejudice to the processing carried out prior to the withdrawal of consent.
To do so, you only need to contact us via the email or postal address indicated at the beginning.Optionally, you may also contact our designated data protection officer, or the Data Protection Agency to learn more about your rights or to request the protection of these rights by the supervisory authority.
Data security
We adopt in our information system the necessary technical and organisational measures to guarantee an adequate level of confidentiality, integrity, availability and resilience of the data in order to protect the rights and freedoms of data subjects.
The controller complies with the provisions and principles described in the GDPR to process data lawfully, fairly and transparently in relation to the data subject, and adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
However, to the extent permitted by law, we assume no liability for damages or alterations that third parties may cause to our information system. Any security breach will be duly and immediately communicated to the competent authority and/or the State Security Forces and Bodies.
Sending communications or information
Our policy regarding the sending of information through telematic means (email, instant messaging, etc.) is limited to sending only communications that we consider of interest to our users and interested parties, in relation to the functions and activity of the company, or that you have consented to receive.
If you prefer not to receive these messages, we will offer you through these the possibility of exercising your right to cancel and waive the receipt of these messages, in accordance with the provisions of Title III, Article 22 of Law 34/2002 on Information Society Services and Electronic Commerce.
Social media
The controller may have a presence on social media through the corresponding profiles, with this section and any legal and privacy terms present on the website being applicable for the processing of data of users or interested parties who follow or in some way connect to said profiles.
The purposes of the controller’s use of these profiles are communication, commercial development, marketing and advertising, processing queries raised to the controller and user assistance, informing about actions, activities and events organised by the controller or in which it participates, and interacting through the official profiles.
The legitimising bases set out in section 6 above are complemented in this case because the user or interested party may have a profile on the same social network as the controller and has decided to join or connect with the controller’s profile, thus showing interest in the information published by the controller. Therefore, at the time of following the controller’s profiles, they give their consent for the processing of the data available in their profile.
The user may at any time access the policies and privacy terms of the corresponding social network, as well as configure the privacy features that may be carried out on their profile. The publications made by the user will be known to other users, so the user is the main responsible for their privacy.
Users who follow and/or participate in our profiles shall refrain:
- From publishing content or information contrary to the Laws, morality, and good faith. Any unlawful, annoying, inappropriate use or behaviour that may generate negative opinions in the profile or that violates the rights of individuals is not permitted.
- From behaving contrary to the principles of legality, honesty, responsibility, protection of human dignity, protection of minors, protection of public order, protection of private life, consumer protection and intellectual and industrial property rights.
The controller reserves the right to remove without prior notice any content that is considered inappropriate. Likewise, it is released from any liability in relation to the security measures corresponding to each platform, and the user must be aware of them together with the legal terms and conditions of use of the platform itself.
The controller shall be expressly exonerated from any liability that may arise from the use of social media by minors or persons with special needs. The controller’s social media does not knowingly collect any personal information from minors, therefore, if the user is a minor, they should not register, use the controller’s social media, or provide any personal information. Particularly in Spain, the processing of personal data of a minor may only be based from the age of 14. On the other hand, if any norm or regulation so requires, or if the user has special needs, the intervention of the holder of parental authority or guardianship, or of their legal representative, shall be required through a valid document proving such representation.
Employment and candidate management
Those interested in accessing job offers from the controller may provide their data and professional information to the controller through different channels, preferably through existing forms, email addresses, and existing means for this purpose, where applicable.
These data will be processed in accordance with the privacy terms set out herein for the purpose of managing applications for possible job offers, internships and training of the controlling entity and any subsidiary companies or companies belonging to the same business organisation, when they exist and are applicable.
The processing will be carried out on the basis of the informed consent of the data subject or another valid legitimising basis.
The data provided, if they are not of professional interest to the entity or once they are no longer necessary for the purposes for which they were collected, will be deleted ensuring their confidentiality and anonymisation.
Any data subject may withdraw their consent and exercise the rights that assist them in matters of privacy under the terms set out in this privacy policy.