Status: July 2026
This Privacy Policy explains how personal data is processed when you visit test.villalarnia.eu, contact us, make a direct booking, pay for accommodation or stay at Villa Larnia. It is based on the EU General Data Protection Regulation (GDPR), Spanish Organic Law 3/2018 and the applicable Spanish rules for information-society services and guest registration.
1. Controller
Helmut Franz Weiss
Villa Larnia
Via dei Manzanos 20
38360 El Sauzal, Tenerife
Canary Islands, Spain
NIE/NIF: Y5950653S
Tourist-accommodation registration identifier: ESHFTU00003802000001729000200000000000A-38-4-00075095
Email: info@villalarnia.eu
Telephone: +34 650 741 990
Website: https://test.villalarnia.eu
No data protection officer is required to be appointed for the present scope of processing. Privacy enquiries may be sent directly to the contact details above.
2. Data sources and categories
We generally obtain data from you, from a person making a booking for your group, from the booking engine used on this website, or from a booking platform through which you chose to book. Depending on the interaction, this may include:
- identity and guest-registration data, including name, nationality, date of birth, sex where required by law, identity-document details and signature;
- contact and booking data, including postal address, email, telephone number, arrival and departure dates, number of guests, messages and preferences;
- contract and payment data, including price, invoices, payment status and transaction references; full card details are processed by the selected payment provider and are not stored by Villa Larnia;
- technical data, including IP address, date and time, requested page, browser/device information, referrer, cookie identifiers and security logs;
- communications and any information you voluntarily provide.
If another person books for you, that person must ensure that they are authorised to provide your data and that you receive this Privacy Policy.
3. Purposes and legal bases
3.1 Website delivery, hosting and security
Technical connection and log data are processed to deliver the website, ensure stability, detect misuse and protect our systems. The legal basis is our legitimate interest in operating a secure and functional website (Article 6(1)(f) GDPR). The website is hosted within the SiteGround group. The contractually responsible SiteGround company acts as a processor for hosting data. Details are available in SiteGround’s Privacy Policy.
3.2 Enquiries, bookings and performance of the accommodation contract
We process contact, booking and stay data to answer pre-contractual enquiries, administer reservations, communicate with guests, provide the accommodation, handle changes or cancellations and enforce or defend contractual claims. The legal basis is Article 6(1)(b) GDPR and, for legitimate claims and business administration, Article 6(1)(f) GDPR.
3.3 Beds24 booking engine
The direct-booking interface is provided by Beds24 GmbH, c/o EDGE Workspaces Grand Central Berlin, Invalidenstraße 65, 10557 Berlin, Germany. When you open or use the booking interface, Beds24 processes the booking and technical data needed to display availability and complete your reservation. Beds24 acts as our processor for booking data under a data-processing agreement; for any processing it independently determines, its own privacy information applies. The legal basis for booking processing is Article 6(1)(b) GDPR. Technically necessary connection data is processed under Article 6(1)(f) GDPR. See the Beds24 Privacy Policy.
3.4 Payments through Stripe or PayPal
If you select an online payment option, the information required to process and secure the payment is transmitted directly to the selected provider:
- Stripe: Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. See Stripe’s Privacy Policy.
- PayPal: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. See PayPal’s Privacy Statement.
The legal basis for transmitting payment information is performance of the contract (Article 6(1)(b) GDPR). Payment providers may process data for fraud prevention, regulatory compliance and their own legal obligations under their respective privacy notices.
3.5 Statutory guest registration and reporting
Spanish law requires accommodation providers to collect specified guest and booking data, maintain a guest register and transmit required information to the competent authorities through the official SES.HOSPEDAJES system. Processing is necessary to comply with a legal obligation under Article 6(1)(c) GDPR, in particular Royal Decree 933/2021 and related legislation. Required registration data cannot be omitted where the law applies; without it, accommodation may not lawfully be provided. The local guest register is retained for three years from the relevant entry. The competent authorities determine their own subsequent processing and retention.
3.6 Accounting, tax duties and legal claims
Invoices, payment records and relevant contract data are processed to comply with Spanish commercial and tax obligations (Article 6(1)(c) GDPR) and to establish, exercise or defend legal claims (Article 6(1)(f) GDPR).
3.7 WhatsApp and other communications
If you choose to contact us through WhatsApp, your telephone number, profile information made available by you, message content and technical metadata are processed by WhatsApp Ireland Limited/Meta in accordance with its own terms. The legal basis on our side is Article 6(1)(b) GDPR for booking-related communication or Article 6(1)(f) GDPR for efficiently answering other enquiries. WhatsApp may process data outside the EEA; please use email if you do not wish to use this channel. See WhatsApp’s Privacy Policy.
3.8 Google Fonts and externally loaded resources
The website uses fonts supplied by Google. Depending on the consent settings and technical configuration, font files may be retrieved from Google servers. In that event, your IP address, browser information and the requested resource are transmitted to Google Ireland Limited and possibly other Google group companies. Where legally required, the legal basis is your consent under Article 6(1)(a) GDPR and Section 25 of the German TDDDG only insofar as that law applies; for visitors in Spain, the applicable consent requirement follows Article 22.2 LSSI-CE. You may withdraw consent at any time through the available consent settings or by deleting the relevant cookies. See Google’s Privacy Policy.
3.9 Cookies and similar technologies
Strictly necessary cookies and local-storage functions may be used to provide requested functions, maintain security and remember essential settings. Their legal basis is Article 6(1)(f) GDPR and the exemption for technically necessary storage/access under Article 22.2 LSSI-CE. Optional analytics, marketing or external-media technologies are used only after consent where required (Article 6(1)(a) GDPR and Article 22.2 LSSI-CE). Consent may be refused without affecting essential website functions and may be withdrawn as easily as it was given. Cookie settings can be changed through the consent interface, where displayed, and cookies can also be deleted in the browser.
4. Recipients
Personal data is disclosed only where necessary to:
- hosting, website, IT-support and booking-system processors;
- payment providers, banks and accounting/tax advisers;
- competent police, security, tourism, tax, judicial or other public authorities where legally required;
- professional advisers and insurers where needed for legal claims;
- booking platforms or communication providers chosen by you.
Processors receive only the data needed for their services and are contractually bound in accordance with Article 28 GDPR where applicable. Data is not sold.
5. Transfers outside the European Economic Area
Some providers, particularly Google, Meta/WhatsApp, Stripe, PayPal or their subcontractors, may process data in countries outside the EEA. Where the GDPR requires safeguards, transfers are based on an EU adequacy decision, the EU-US Data Privacy Framework for certified recipients, EU Standard Contractual Clauses together with supplementary measures, or another lawful transfer mechanism. The exact mechanism may depend on the provider and recipient. Further details are available in the linked provider notices or from us on request.
6. Retention periods
- Guest register: three years from the relevant entry, as required by Royal Decree 933/2021.
- Booking and contract records: for the duration of the stay and thereafter while contractual claims may be brought or defended.
- Accounting and commercial documents: for the applicable statutory periods, generally up to six years under Spanish commercial rules; tax-relevant records are retained for the applicable tax limitation period, generally four years, unless a longer period is required.
- Unsuccessful enquiries: normally up to twelve months after the last communication, unless earlier deletion is requested or longer retention is necessary for a claim.
- Website security logs: normally up to ninety days, unless an incident requires longer evidence preservation.
- Consent records: for as long as necessary to demonstrate valid consent and until related claims are time-barred.
When a period ends, data is deleted or anonymised unless continued storage is required or permitted by law.
7. Mandatory information
Data marked as required during booking is necessary to enter into or perform the accommodation contract or to comply with statutory registration duties. If it is not provided, we may be unable to accept the booking, process payment or provide accommodation. Other information is voluntary.
8. Children
Direct bookings may be made only by adults with legal capacity. Data concerning accompanying minors is processed only to administer the stay and fulfil statutory guest-registration duties. We do not knowingly use children’s data for direct marketing.
9. Automated decision-making
Villa Larnia does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you. Payment providers may use automated fraud-prevention checks under their own privacy notices.
10. Your rights
Subject to the statutory conditions, you have the right to request access, rectification, erasure, restriction of processing and data portability, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time with future effect. Withdrawal does not affect the lawfulness of processing before withdrawal.
To exercise a right, email info@villalarnia.eu or write to the controller’s postal address. We may request information needed to verify your identity. You also have the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, Spain, www.aepd.es, or with another competent supervisory authority under Article 77 GDPR.
11. Security
We use appropriate technical and organisational measures proportionate to the risk, including encrypted transmission where supported, access controls, data minimisation and appropriate processor arrangements. No online transmission or storage system can be guaranteed to be completely secure.
12. Changes to this Privacy Policy
We may update this Policy when processing activities, providers or legal requirements change. The current version and status date are published on this page. Material changes affecting an existing consent will be addressed as required by law.
