1. Introduction
Viva Costa del Sol respects your privacy and is committed to protecting your personal data. This policy explains how we collect, use, and safeguard your information, in compliance with the General Data Protection Regulation (GDPR).
2. Data Collection
We collect personal information such as your name, contact details, payment information, and any other details provided during the booking process. We also gather information from cookies and analytics tools when you use our website.
3. Legal Basis for Processing
The processing of your personal data is based on:
- Consent: For sending promotional emails or newsletters.
- Contract: To manage your booking and provide our services.
- Legal Obligation: To comply with applicable laws, such as invoicing regulations.
4. Purpose of Data Collection
Your personal data is used for the following purposes:
- Booking Management: To manage reservations, payments, and communications.
- Customer Support: To address inquiries and provide support.
- Marketing: To send you promotional materials, only if you have opted-in.
- Analytics: To improve our services and website functionality.
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Booking Data: Retained for 5 years after the booking date for tax and accounting purposes.
- Marketing Data: Retained until you withdraw your consent.
- Cookies and Analytics Data: Retained as specified in our cookie policy.
6. Sharing Your Data
Your personal information may be shared with third-party service providers for booking management and payment processing, such as:
- WordPress (website management)
- Stripe (payment processing)
- Google Analytics (website analytics)
We ensure that these third parties comply with GDPR and only use your data as necessary to provide their services.
7. User Rights
You have the right to:
- Access your data and receive a copy of it.
- Rectify incorrect or incomplete data.
- Erase your data under certain conditions.
- Restrict or Object to processing.
- Withdraw Consent at any time if the processing is based on consent.
To exercise these rights, please contact us at contact@vivacostadelsol.org.
8. Consent Withdrawal
If you provided consent for processing, you may withdraw it at any time by contacting us at contact@vivacostadelsol.org or by clicking the unsubscribe link in any marketing email.
9. Data Security
We have implemented appropriate technical and organizational measures to protect your data from unauthorized access, alteration, or disclosure. Access to your personal information is restricted to authorized personnel only.
10. Minors
Our services are not intended for individuals under the age of 18. We do not knowingly collect data from minors. If we discover that we have collected personal data from a minor, we will take steps to delete it as soon as possible.
11. Cookies
Our website uses cookies to enhance user experience. For more information, please refer to our Cookie Policy.
12. Changes to This Policy
We may update this privacy policy from time to time. If changes are made, we will notify you via email or through a prominent notice on our website.
13. Contact Information
For questions or concerns about your privacy, please contact us at: contact@vivacostadelsol.org
14. Dispute Resolution
If you have any concerns about our use of your personal data, you may also contact your local data protection authority.
What personal data we collect and why we collect it
Comments
When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
Media
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
Contact forms
When you use our Contact forms, we collect certain information, provided by you.
- Examples of Personal Information collected: name, billing address, shipping address, entire or partial payment information (including credit card numbers, Paypal, etc), email address, and phone number.
- Purpose of collection: to provide support, products or services to you to fulfill our contract, to process your payment information, and provide you with invoices and/or order confirmations, communicate with you, screen our orders for potential risk or fraud, and when in line with the preferences you have shared with us.
- Source of collection: collected from you.
- Disclosure for a business purpose: shared with our processor WordPress.
Cookies
If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
Analytics
We use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For example:
- We use Google Analytics to help us understand how our customers use the Site. You can read more about how Google uses your Personal Information here: https://policies.google.com/privacy?hl=en. You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.
- We use Facebook for promotional services. We share information about your use of the Site, your purchases, and your interaction with our ads on other websites with our advertising partners. We collect and share some of this information directly with our advertising partners, and in some cases through the use of cookies or other similar technologies (which you may consent to, depending on your location).
- For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page at http://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.
You can opt out of targeted advertising by:
FACEBOOK – https://www.facebook.com/settings/?tab=ads
GOOGLE – https://www.google.com/settings/ads/anonymous
Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: http://optout.aboutads.info/.
Who we share your data with
We use your personal Information to provide our services to you, which includes: offering products for sale, processing payments, shipping and fulfillment of your order, and keeping you up to date on new products, services, and offers.
How long we retain your data
If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.
For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
What rights you have over your data
If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
Where we send your data
Visitor comments may be checked through an automated spam detection service.
Your contact information
When you visit the Site, we collect certain information about your device, your interaction with the Site, and information necessary to process your purchases. We may also collect additional information if you contact us for customer support. In this Privacy Policy, we refer to any information that can uniquely identify an individual (including the information below) as “Personal Information”. See the list below for more information about what Personal Information we collect and why.
Device information
- Examples of Personal Information collected: version of web browser, IP address, time zone, cookie information, what sites or products you view, search terms, and how you interact with the Site.
- Purpose of collection: to load the Site accurately for you, and to perform analytics on Site usage to optimize our Site.
- Source of collection: Collected automatically when you access our Site using cookies, log files, web beacons, tags, or pixels.
- Disclosure for a business purpose: shared with our processor WordPress.
Order information
- Examples of Personal Information collected: name, billing address, entire or partial payment information (including credit card numbers, Paypal, etc), email address, and phone number.
- Purpose of collection: to provide products or services to you to fulfill our contract, to process your payment information, arrange for shipping, and provide you with invoices and/or order confirmations, communicate with you, screen our orders for potential risk or fraud, and when in line with the preferences you have shared with us, provide you with information or advertising relating to our products or services.
- Source of collection: collected from you.
- Disclosure for a business purpose: shared with our processor WordPress.
Customer support information
- Examples of Personal Information collected: name, billing address, shipping address, entire or partial payment information (including credit card numbers, Paypal, etc), email address, and phone number.
- Purpose of collection: to provide customer support.
- Source of collection: collected from you.
- Disclosure for a business purpose: Delivery companies
Minors
The Site is not intended for individuals under the age of 18. We do not intentionally collect Personal Information from children. If you are the parent or guardian and believe your child has provided us with Personal Information, please contact us at the address below to request deletion.
Additional information
Lawful basis
Pursuant to the General Data Protection Regulation (“GDPR”), if you are a resident of the European Economic Area (“EEA”), we process your personal information under the following lawful bases:
- Your consent;
- The performance of the contract between you and the Site;
- Compliance with our legal obligations;
- To protect your vital interests;
- To perform a task carried out in the public interest;
- For our legitimate interests, which do not override your fundamental rights and freedoms.
Retention
When you place an order through the Site, we will retain your Personal Information for our records unless and until you ask us to erase this information. For more information on your right of erasure, please see the ‘Your rights’ section below.
Automatic decision-making
If you are a resident of the EEA, you have the right to object to processing based solely on automated decision-making (which includes profiling), when that decision-making has a legal effect on you or otherwise significantly affects yo.
We do not engage in fully automated decision-making that has a legal or otherwise significant effect using customer data.
Our processor WordPress uses limited automated decision-making to prevent fraud that does not have a legal or otherwise significant effect on you.
Services that include elements of automated decision-making include:
- Temporary denylist of IP addresses associated with repeated failed transactions. This denylist persists for a small number of hours.
- Temporary denylist of credit cards associated with denylisted IP addresses. This denylist persists for a small number of days.
- Selling Personal Information
- Our Site does not sell Personal Information, as defined by the California Consumer Privacy Act of 2018 (“CCPA”).
Your rights
GDPR
If you are a resident of the EEA, you have the right to access the Personal Information we hold about you, to port it to a new service, and to ask that your Personal Information be corrected, updated, or erased. If you would like to exercise these rights, please contact us through the contact information below.
Do Not Track
Please note that because there is no consistent industry understanding of how to respond to “Do Not Track” signals, we do not alter our data collection and usage practices when we detect such a signal from your browser.
Changes
We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons.
Contact
For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at contact@vivacostadelsol.org.
Last updated: 27/11/2020
If you are not satisfied with our response to your complaint, you have the right to lodge your complaint with the relevant data protection authority. You can contact your local data protection authority, or our supervisory authority here: Spanish Data Protection Agency.