Hotel Mirador del Compás
Privacy policy
Last updated: 06/10/2026
1. Data controller
- Owner: Hotel Mirador del Compás SL
- Tax ID: ESA12345674
- Address: Calle del Compás, 12, 29400 Ronda, Spain
- Email: reservas@miradordelcompas.example
- Phone: +34 952 000 000
- Tourism registry no.: H/MA/01234
2. What data we process and why
- Bookings and stay: name, contact details, dates, preferences and payments, to manage the booking, the stay and invoicing. Legal basis: performance of the contract.
- Guest register: the identity document details and the other data required by Royal Decree 933/2021, which are reported to the Spanish Ministry of the Interior (SES.HOSPEDAJES). Legal basis: legal obligation.
- Booking communications: confirmation, pre-arrival reminder and thank-you message after the stay. Legal basis: performance of the contract and legitimate interest.
- Restaurant table booking, if you make one. Legal basis: performance of the contract.
We do not use the data for automated decisions or profiling.
3. How long we keep them
Booking and invoicing data, for the period required by tax and commercial law. Guest register data, for the three years set by Royal Decree 933/2021; after that they are anonymised.
4. Who receives them
- Law enforcement authorities, due to the guest register obligation.
- Payment institutions, to charge or guarantee the booking. Card details are processed directly by the institution: the hotel does not store them.
- Technology providers acting as data processors (hosting of the website and management system, email), under contract and with safeguards.
- If you book through an agency or a booking portal, that intermediary also processes your data under its own policy.
5. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to reservas@miradordelcompas.example or at reception. If you consider they have not been addressed, you can complain to the Spanish Data Protection Agency (www.aepd.es).
6. Security
We apply appropriate technical and organisational measures: role-based access, encrypted communications and backups.