1. IDENTIFICATION
At VIBRA HOTELS, a commercial brand owned by HIPERION HOTEL GROUP, S.L., we pay the utmost attention and apply the greatest diligence to compliance with the applicable regulations on the processing of personal data and to the data protection rights of our guests and customers.
This Privacy Policy is intended to identify who is responsible for the processing of personal data, and to explain how we obtain, process and protect the personal data that you provide or that we collect through our website https://www.vibrahotels.com/es (the “Website”) by means of forms and/or cookies, so that you may decide freely, knowingly and voluntarily whether you want us to process them.
The use of cookies and other tracking technologies on the Website is governed by its Cookie Policy, available on the Website itself, where users can obtain detailed information about the cookies used, their purpose and how to configure or withdraw their consent.
If you wish to stay and/or complete the booking process through this Website at the following hotel establishments, the controller of your data processing is:
| IBIZA TOWN | PLAYA D'EN BOSSA | SAN ANTONIO | BAHIA DE SAN ANTONIO | CALA TARIDA | MALLORCA | SEVILLA |
| *Vibra Jabeque Dreams Apartments *Vibra Jabeque Soul Aparthotel *Vibra Lei Ibiza Hotel *Vibra Lux Mar Aparthotel *Vibra Maritimo Hotel *Vibra Panoramic Apartments *Vibra Tivoli Apartments *Vibra Tropical Garden Apartments *Vibra Vila Hotel | *Vibra Algarb Hotel *Vibra Bossa Flow Hotel *Vibra Isola Hotel *Vibra Mare Nostrum Hotel *Vibra Mogambo Aparthotel | *Vibra Calima Apartments *Vibra Central City Aparthotel *Vibra Del Mar Aparthotel *Vibra District Hotel *Vibra Marco Polo I Hotel *Vibra Marco Polo II Hotel *Vibra Sanan Aparthotel *Vibra Yamm Sunset Hotel *Vibra Yamm Urban | *Vibra Bay Aparthotel *Vibra Club Maritim Aparthotel *Vibra Monterrey Aparthotel *Vibra Riviera Apartments *Vibra Riviera Hotel *Vibra San Marino Aparthotel *Vibra San Remo Hotel *Vibra S’Estanyol Hotel | *Vibra Cala Tarida Hotel | *Vibra Beverly Playa Hotel *Vibra Palma Cactus Hotel | *Fenix by Vibra Hotel |
If you wish to stay and/or complete the booking process through this Website at the following hotel establishments, the controller of your data processing is:
| CIUDADELA - MENORCA |
| *Vibra Caleta Playa Apartments *Vibra Blanc Cottage Apartments *Vibra Blanc Palace Aparthotel |
If you have any queries about data protection or about how we process your data through this Website, you may contact our Data Protection Officer (DPO) at: dpo@vibrahotels.com, indicating “Data Protection Officer” in the reference and identifying yourself by a means that allows us to reasonably verify your identity.
2. INFORMATION AND CONSENT
By accepting this Privacy Policy, the user is clearly and simply informed of the processing that will be carried out in relation to the personal data provided through this “Website”, as well as the data arising from browsing and any other data that may be provided to us in the future. The legal basis for each processing activity is not always consent, but rather the basis that applies in each case as set out in section 6 of this Privacy Policy (performance of a contract, legitimate interest or consent, depending on the purpose concerned). Where the legal basis is consent, the user may freely and voluntarily decide whether to provide their personal data through the different forms available on this “Website”.
3. OBLIGATION TO PROVIDE DATA
The data requested in the Website forms are generally mandatory (unless the required field states otherwise) in order to fulfil the stated purposes. Therefore, if the data are not provided, or are not provided correctly, the corresponding requests cannot be dealt with, without prejudice to the fact that the user may freely view the content of the Website.
4. FOR WHAT PURPOSE WILL HIPERION HOTEL GROUP, S.L. PROCESS THE USER’S PERSONAL DATA?
The personal data provided through the Website will be processed by HIPERION HOTEL GROUP, S.L. or by VACANCES MENORCA, depending on the hotel establishment where you wish to stay, for the following purposes:
1- Data provided for making bookings, both through the “Website” and through the contact center (call center, email or chat) for individual bookings or for groups and rooms at the hotel establishment of your choice
2- Data provided for modifying and cancelling bookings:
3- Data provided in the abandoned-cart recovery form:
4- Data provided through the Newsletter form:
5- Data provided to register as a registered user on the “Website” in relation to HIPERION and VACANCES MENORCA establishments:
6- Data provided for the Club Vibra Programme:
8- Data provided for posts on Blogs owned by HIPERION:
5.. WHAT USER DATA WILL HIPERION HOTEL GROUP, S.L. PROCESS?
1. Data provided for making bookings, both through the Website and through the contact center (call center, email or chat) for individual bookings or for groups and rooms:
2. Data provided for modifying and cancelling bookings:
3. Data provided in the abandoned-cart recovery form:
4. Data provided for sending the Newsletter:
5. Data provided to register as a registered user on the “Website”:
6. Data provided for the Club Vibra Programme:
7. Data provided in contact forms and on the website:
8. Data provided for posts on BLOGS owned by HIPERION:
If the user provides data relating to third parties, the user declares that they have obtained their consent and undertakes to provide them with the information contained in the Privacy Policy, holding HIPERION harmless from any liability in this regard. Nevertheless, HIPERION may carry out periodic checks to verify this fact, adopting the due diligence measures that may be appropriate in accordance with data protection regulations.
6. WHAT IS THE LEGAL BASIS FOR PROCESSING THE USER’S DATA?
The legal bases for processing your personal data are the following:
If consent for the processing of the publication of comments is withdrawn, the comment will be deleted from the Website by HIPERION. The consents obtained for the purposes mentioned are independent, so the user may withdraw only one of them without affecting the others. To withdraw such consent, the User may contact us at any time through the following channel: dpo@vibrahotels.com
7. CALL RECORDING
If the user contacts our telephone customer service or call center, we inform you that calls may be recorded. This processing will be carried out for the purpose of managing and following up on bookings and requests, guaranteeing service quality and having evidence of the actions carried out. The legal basis for the recording is the controller’s legitimate interest (Article 6.1.f GDPR), without prejudice to the fact that, when the recording is intended to formalise the booking, the legal basis will be the performance of a pre-contractual or contractual relationship (Article 6.1.b GDPR). Recordings will be kept for a maximum period of one (1) month from their recording, unless they are necessary to deal with a claim or comply with a legal obligation, in which case they will be duly blocked for the limitation period of any actions that may arise. At the beginning of each call, the user will be informed of the recording through a prior recorded notice.
8. HOW LONG WILL WE PROCESS YOUR PERSONAL DATA?
The personal data to which access is obtained will be processed and stored for as long as the contractual relationship remains in force or the purpose for which they were collected continues to exist. Thereafter, once the contractual relationship has ended or when the data are no longer relevant for the purposes for which they were collected, they will be duly blocked and kept available to the competent Public Administrations, Judges and Courts or the Public Prosecutor’s Office for the limitation period of any actions that may arise from the relationship maintained with the user and/or for the legally established retention periods. Subsequently, your data will be physically deleted once those periods have elapsed. By way of guidance, and without prejudice to the foregoing, personal data will be kept for the following periods:
(i) data processed for the management of bookings, including data collected through the call center, for the duration of the relationship and subsequently blocked for the legally applicable limitation periods (generally, up to six years in accordance with commercial regulations and the applicable tax and accounting periods);
(ii) data collected to comply with the legal obligations for the registration of travellers will be kept for the period required by the applicable regulations, currently three years from the end of the accommodation service, in accordance with Royal Decree 933/2021, without prejudice to any longer periods that may be required by law;
(iii) data processed on the basis of the user’s consent will be kept until the user withdraws such consent; and
(iv) call recordings will be kept for the period indicated in the section on call recording in this Privacy Policy. If the user has given consent for the processing purposes reported in section 4 of this Privacy Policy, their information will be kept for as long as the user does not withdraw the consent initially given.
9. WITH WHICH RECIPIENTS WILL THE USER’S DATA BE SHARED?
For the fulfilment of the purposes described in this Privacy Policy, the user’s personal data may be communicated to or made accessible to the following recipients or categories of recipients:
(i) service providers acting as processors on behalf of the controller, including Aircall (telephone and call center services), NeoBookings (booking management platform), Centribal (conversational assistant or chatbot), and Zendesk (customer service management), which process personal data only in accordance with our instructions and under the corresponding data processing agreement signed in accordance with Article 28 of the GDPR; and
(ii) Public Administrations, Judges and Courts and Law Enforcement Authorities, where there is a legal obligation. Outside these cases, your data will not be assigned or disclosed to third parties, except where there is a legal obligation or the user’s consent.
10. INFORMATION ON INTERNATIONAL DATA TRANSFERS
As a general rule, your personal data will not be subject to international transfers outside the European Economic Area (EEA). However, the use of certain service providers or collaborating entities could involve access to or processing of personal data from third countries. In such cases, international transfers will only be carried out where there is a legal basis that legitimises them and in accordance with Articles 44 et seq. of Regulation (EU) 2016/679 (GDPR), applying, where necessary, the appropriate safeguards provided for by the regulations, such as adequacy decisions adopted by the European Commission or the signing of Standard Contractual Clauses, together with any supplementary measures that may be required. You may obtain additional information about any international transfers that may be carried out, the countries of destination and the safeguards applied by contacting our Data Protection Officer at dpo@vibrahotels.com.
11. INFORMATION ON THE PROCESSING OF THIRD-PARTY DATA
If the Holder provides the controller with third-party data at any time, they declare that they have obtained the consent of those third parties and undertake to provide them with the information contained in this clause, as well as to inform HIPERION or VACANCES MENORCA of any change or update relating to them.
12 - DATA SECURITY
The controller has adopted the necessary technical and organisational measures to guarantee the security of personal data and to prevent their alteration, loss, processing or unauthorised access, taking into account the state of the art, the nature of the data stored and the risks to which they are exposed, whether arising from human action or from the physical or natural environment. The Holder is responsible for keeping their user password strictly confidential and is responsible for access to our “Website” or private area, or for its use by the Holder or by any person using the password previously provided by the Holder, whether or not such access or use has been authorised by the Holder, or on the Holder’s behalf, even if that person is the Holder’s employee, relative or agent. You agree
(i) to inform us immediately of any unauthorised use of your password, your account or any other security breach and
(ii) to ensure that you close your account at the end of each session. The Holder is solely responsible for controlling the disclosure and use of their password, the access to and use of their account, and for informing us of their wish to terminate their account. In compliance with Articles 33 and 34 of the GDPR, if a personal data breach occurs that poses a risk to the rights and freedoms of users, the controller will notify the Spanish Data Protection Agency within a maximum period of 72 hours after becoming aware of it and, where the risk to their rights and freedoms is high, will also communicate it to the affected data subjects without undue delay.
13. VIDEO SURVEILLANCE
The hotel establishments have a video surveillance system using cameras installed in access areas and common spaces, the purpose of which is to guarantee the security of persons, facilities and property. The legal basis for this processing is the controller’s legitimate interest in protecting persons and property (Article 6.1.f GDPR) and, where applicable, compliance with a legal obligation. The existence of the cameras is announced by the corresponding information signs placed in a visible location in the video-surveilled areas. Images will be kept for a maximum period of one (1) month from their capture, unless they must be kept to prove the commission of acts that threaten the security of persons, property or facilities, in which case they will be made available to the competent authorities. No video surveillance is carried out in areas intended for rest or of a private nature, all in accordance with Article 22 of Organic Law 3/2018, of 5 December, on Personal Data Protection and the guarantee of digital rights.
14. RIGHTS OF DATA SUBJECTS IN RELATION TO THEIR DATA
You may exercise, at any time and free of charge, the rights indicated below by writing to the email address dpo@vibrahotels.com, indicating “Data Protection” in the subject and identifying yourself by a means that allows us to reasonably verify your identity, without it generally being necessary to provide a copy of your identity document. In particular, you may exercise the following rights:
a) Withdraw the consent granted for the processing and communication of your personal data.
b) Obtain information about whether or not your personal data are being processed.
c) Access your personal data.
d) Rectify inaccurate or incomplete data.
e) Request the deletion of your data when, among other reasons, the data are no longer necessary for the purposes for which they were collected.
f) Restrict the processing of data when any of the conditions provided for in data protection regulations are met.
g) In certain circumstances and on grounds relating to their particular situation, data subjects may object to the processing of their data.
h) Request the portability of your data. i) Lodge a complaint with the Spanish Data Protection Agency at the following address: Calle de Jorge Juan, 6, 28001 Madrid, when you consider that the controller has infringed the rights recognised to you by data protection regulations. The data subject may contact the Data Protection Officer of the Controller by email at: dpo@vibrahotels.com
15. GOOGLE ADVERTISING SERVICES
This site uses Google advertising services. For more information about how Google uses personal data when you visit websites or applications that use its services, you may consult Google’s Business Data Responsibility page.