LEGAL
Política de Privacidad
Last updated: 06-08-2026
1. Data Controller
In accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE), Royal Decree 933/2021, and other applicable Spanish and European legislation, the following information is provided regarding the processing of personal data.
Data Controller: Christopher Michael Caples
NIE: Y7865284B
Trade Name: El Dorado Beach Resort
Address: Calle Ribera Baja 14, 18690 Almuñécar (Granada), Spain
Email: info@doradobeachresort.com
Website: www.doradobeachresort.com
2. Purpose of Data Processing
El Dorado Beach Resort collects and processes personal data for the following purposes:
2.1 Reservation Management
Managing accommodation enquiries and reservations.
Processing booking requests, modifications, and cancellations.
Allocating accommodation and requested services.
Providing customer service before, during, and after a stay.
Communicating important reservation and operational information.
Managing complaints, refunds, disputes, and contractual claims.
2.2 Guest Registration and Legal Compliance
Verifying guest identities.
Collecting legally required guest information.
Maintaining mandatory traveller-registration records.
Complying with Spanish tourism and public-security requirements.
Reporting guest information to competent authorities where required by law.
Complying with tax, accounting, consumer-protection, and other legal obligations.
Where legally required information is not provided, El Dorado Beach Resort may be unable to complete registration, issue check-in instructions, or provide access to the accommodation.
2.3 Online Check-In and Identity Verification
Through Chekin and related service providers, El Dorado Beach Resort may process guest information for:
Online check-in.
Identity verification.
Collection and validation of identification information.
Digital signature of rental agreements and required documentation.
Collection of mandatory guest-registration information.
Security deposit management and payment authorizations.
Fraud prevention and transaction security.
Transmission of legally required information to competent authorities.
2.4 Payment Processing
Processing accommodation payments and charges for additional services.
Managing payment links, deposits, and security authorizations.
Fraud prevention and transaction security.
Processing refunds and chargebacks.
Maintaining billing, accounting, and tax records.
El Dorado Beach Resort does not ordinarily receive or store complete payment-card details when payments are processed directly by an authorized payment provider.
2.5 Guest Communications
Reservation confirmations.
Guest-registration requests and reminders.
Arrival and departure instructions.
Access and check-in information.
Parking and resort-service arrangements.
Customer support.
Lost-property communications.
Operational communications during and after a stay.
Communications through email, telephone, SMS, WhatsApp, and booking-platform messaging.
2.6 Marketing Communications
With the guest’s consent where required, El Dorado Beach Resort may send:
Newsletters.
Promotional offers.
Special packages.
Resort updates.
Competitions and promotional campaigns.
Customer satisfaction surveys.
Where permitted by applicable law, existing customers may also receive information concerning services similar to those previously purchased.
Guests may unsubscribe from marketing communications at any time by using the unsubscribe option provided or by contacting info@doradobeachresort.com.
2.7 Property Security
Protection of guests, visitors, staff, contractors, vehicles, and property.
Monitoring designated exterior and access areas through video-surveillance systems.
Preventing and investigating unauthorized access, fraud, vandalism, theft, damage, or other unlawful activity.
Investigating accidents, safety concerns, and security incidents.
Managing insurance claims and legal proceedings.
2.8 Live Camera Audio
Certain exterior security cameras include a microphone that permits an authorized person to hear live audio while actively viewing the relevant camera.
Live audio may be used only where reasonably necessary to:
Assess an active or suspected security incident.
Assess an immediate safety concern.
Communicate with or assist a person at an entrance or exterior access point.
Investigate suspicious activity taking place at that moment.
Protect persons or property from an immediate risk.
Audio is not recorded, stored, archived, or retained.
Live audio is not used for continuous listening, routine monitoring of conversations, marketing, profiling, entertainment, or employee-performance monitoring.
2.9 Website Operation
Website administration.
Processing reservation enquiries and booking forms.
Security monitoring.
Detection of malicious activity and technical errors.
Analytics and performance improvement.
Management of cookie and consent preferences.
Compliance with legal obligations.
Non-essential cookies and analytics technologies will only be used where permitted by applicable law and the user’s consent choices.
3. Categories of Personal Data
Depending on the services requested, El Dorado Beach Resort may process:
Identification Data
Full name.
Date and place of birth.
Nationality.
Passport number.
DNI.
NIE.
Identification-document information.
Signature data.
Relationship between guests where required for the registration of minors.
Contact Information
Postal address.
Country of residence.
Email address.
Telephone number.
Language and communication preferences.
Reservation Information
Reservation number and booking source.
Arrival and departure dates.
Number and identity of guests.
Accommodation selected.
Reservation preferences.
Parking and resort-service information.
Special requests.
Check-in, arrival, and access information.
Payment Information
Payment transaction data.
Amounts charged, authorized, or refunded.
Deposit information.
Security authorization records.
Billing and invoice information.
Chargeback and fraud-prevention information.
Legal Registration Information
Information required by Spanish tourism and public-security regulations.
Guest-registration records.
Information required for transmission to competent authorities.
Communication Information
Email correspondence.
Booking-platform messages.
WhatsApp and SMS communications.
Customer-service records.
Complaints and incident reports.
Telephone calls are not recorded unless the caller is specifically informed before recording begins.
Vehicle Information
Vehicle registration details.
Vehicle descriptions where necessary.
Parking reservation and access information.
Information relating to parking incidents or damage.
Video Surveillance and Security Data
CCTV video recordings from monitored exterior areas.
Live video images viewed by authorized users.
Live audio heard while an authorized user is actively viewing a camera.
Images of identifiable persons and vehicles.
Date, time, and location of recorded activity.
Security and access-control incident records.
CCTV is not used for facial recognition, biometric identification, behavioural advertising, or commercial profiling.
Live audio is not recorded, stored, archived, or retained.
Website Data
IP address.
Browser information.
Device and operating-system information.
Cookie identifiers.
Website usage and analytics data.
Security and server logs.
Consent preferences.
4. Legal Basis for Processing
Personal data is processed based on:
4.1 Contract Performance
Processing necessary to respond to booking enquiries, manage reservations, provide accommodation services, arrange requested additional services, process payments, and fulfil contractual obligations.
4.2 Legal Obligations
Processing required by Spanish tourism, traveller-registration, public-security, tax, accounting, consumer-protection, and other applicable legislation.
4.3 Legitimate Interests
Property and personal security.
Prevention and investigation of fraud, theft, damage, and unauthorized access.
Limited live monitoring of active security and safety incidents.
Customer-service improvement.
Business and property administration.
Website and network security.
Resolution of complaints and disputes.
Establishment, exercise, or defence of legal claims.
Where processing is based on legitimate interests, El Dorado Beach Resort considers whether the processing is necessary and proportionate and balances those interests against the rights and freedoms of the individuals concerned.
4.4 Consent
Where required, personal data may be processed based on consent, including for marketing communications and non-essential website cookies.
Consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
5. Recipients and Data Partners
Personal data may be shared with or processed through:
Airbnb.
Booking.com.
Vrbo.
Lodgify.
Stripe.
Chekin.
Brevo.
WhatsApp and Meta Platforms.
Website hosting providers.
Domain, cloud-storage, and backup providers.
Website developers and technical-support providers.
Cybersecurity and spam-prevention providers.
Cookie-consent and analytics providers.
CCTV equipment, cloud, installation, and maintenance providers.
Banks and financial institutions.
Professional advisers, including legal, tax, and accounting consultants.
Insurance companies and claims handlers.
Authorized maintenance providers and contractors.
Public authorities, courts, and law-enforcement agencies where required or permitted by law.
Personal data is never sold or rented to third parties.
Third parties may act as data processors on the instructions of El Dorado Beach Resort or as independent data controllers where they determine their own purposes and legal responsibilities.
6. Lodgify Services
El Dorado Beach Resort utilizes Lodgify for services that may include:
Property and reservation management.
Booking-engine services.
Website and booking integrations.
Channel-management functions.
Reservation communications.
Payment-status and operational administration.
Lodgify may process guest names, contact details, reservation information, communications, payment status, and accommodation information.
Lodgify may act as a processor for services performed on the instructions of El Dorado Beach Resort and may act under its own legal responsibilities for certain additional processing.
7. Chekin Services
El Dorado Beach Resort utilizes Chekin to facilitate:
Online check-in.
Identity verification.
Collection and validation of identification information.
Digital execution of rental agreements.
Security deposit processing and payment authorizations.
Guest-registration compliance.
Transmission of legally required information to competent authorities.
Chekin may act as a processor on behalf of El Dorado Beach Resort and may have independent legal responsibilities for certain identity-verification, payment, registration, or regulatory functions.
Guests should also review the privacy information made available by Chekin.
8. Payment, Email, and Communication Providers
Stripe may process payment, billing, transaction, device, authentication, and fraud-prevention information.
Brevo may process names, email addresses, contact-list information, email-delivery information, marketing preferences, and unsubscribe records when used for operational or marketing communications.
WhatsApp and Meta Platforms may process telephone numbers, message content, communication metadata, and device information when a guest chooses to communicate through WhatsApp.
Use of WhatsApp is not mandatory. Guests may request communication by email instead.
These providers may process certain information under their own privacy policies and legal responsibilities.
9. International Data Transfers
Certain service providers or their subprocessors may process or access personal data outside the European Economic Area.
Where international transfers occur, appropriate safeguards will be used in accordance with GDPR requirements, which may include:
A European Commission adequacy decision.
The EU–US Data Privacy Framework where applicable.
European Commission Standard Contractual Clauses.
Binding corporate rules.
Supplementary technical, contractual, or organizational safeguards.
Another lawful transfer mechanism recognized by the GDPR.
Further information about the safeguards applicable to a particular provider may be requested by contacting info@doradobeachresort.com.
10. Data Retention
Personal data will be retained only for as long as necessary to:
Fulfil contractual obligations.
Comply with legal requirements.
Maintain mandatory guest-registration records.
Meet tax and accounting requirements.
Resolve complaints and disputes.
Enforce agreements.
Establish, exercise, or defend legal claims.
Maintain appropriate security and fraud-prevention records.
Reservation and communication records may be retained for the duration of the relationship and afterwards for the applicable legal limitation periods.
Tax, accounting, invoice, and transaction records will be retained for the periods required by applicable legislation.
Mandatory traveller-registration records will be retained for the period required under Spanish law.
Marketing information will be retained until consent is withdrawn, the person objects, or continued retention is no longer justified. A limited suppression record may be retained to prevent further marketing after an opt-out.
When retention is no longer required, personal data will be securely deleted, destroyed, or anonymized.
11. Video Surveillance
For security purposes, El Dorado Beach Resort operates video-surveillance systems covering certain exterior and access areas, including:
Property entrances and exits.
Pedestrian and vehicle gates.
Parking areas.
Exterior access routes.
Exterior common areas.
Grounds and perimeter areas.
Access points to facilities where security monitoring is reasonably necessary.
No video-surveillance cameras are installed inside guest accommodations, bathrooms, toilets, bedrooms, changing areas, or other locations where individuals reasonably expect a high degree of privacy.
Camera coverage is intended to be limited to areas necessary for the protection of persons and property.
Where a camera may capture a limited part of a public or neighbouring area, the field of view will be restricted to the minimum reasonably necessary to protect the relevant entrance, exit, access point, or property boundary.
Appropriate video-surveillance notices are displayed at or before access to monitored areas.
11.1 Video Recording and Retention
CCTV records video images only.
Recorded video footage is retained for 30 days and is then automatically overwritten or deleted unless the footage must be preserved in connection with:
A security investigation.
An accident or safety incident.
Suspected unlawful activity.
Property damage.
An insurance claim.
A complaint or dispute.
A legal obligation.
Legal or judicial proceedings.
Where relevant footage is preserved, it may be retained for as long as reasonably necessary to investigate the matter or provide it to an insurer, legal adviser, court, law-enforcement body, or other competent authority.
11.2 Live Audio
Certain exterior cameras include a microphone that allows an authorized person to hear live audio only while actively viewing the relevant camera.
The audio function does not create an audio recording.
Audio is not stored, saved, archived, downloaded, or retained.
Live audio may only be accessed where reasonably necessary to assess an active security or safety concern, communicate with a person at an entrance, assist a guest or visitor, or respond to an immediate risk.
Authorized users must not use live audio for continuous listening or to monitor conversations unrelated to a legitimate security or operational purpose.
11.3 Access and Disclosure
Access to live camera feeds and recorded video is restricted to:
The Data Controller.
Persons specifically authorized by the Data Controller.
Authorized technicians where access is necessary for maintenance, repair, or technical support.
Professional advisers where access is necessary for an incident, insurance claim, or legal matter.
Competent authorities where disclosure is legally justified.
Video footage may be disclosed where necessary to:
Police or other law-enforcement authorities.
Courts and tribunals.
Insurance companies and claims handlers.
Legal advisers.
Other competent authorities.
CCTV images will not be published or made generally available unless a separate lawful basis exists and publication is necessary and proportionate.
Because audio is not recorded or retained, no audio recording is available for disclosure.
11.4 CCTV Security
El Dorado Beach Resort applies appropriate security measures to the CCTV system, which may include:
Password-protected accounts.
Restricted user access.
Multi-factor authentication where available.
Secure remote access.
Secure local or cloud storage.
Software and firmware updates.
Review of authorized users.
Confidentiality requirements.
Procedures for preserving incident footage.
Automatic deletion or overwriting after 30 days.
12. WhatsApp Communications
Guests may choose to communicate with El Dorado Beach Resort through WhatsApp.
WhatsApp may be used for:
Reservation assistance.
Guest-registration reminders.
Check-in instructions.
Arrival coordination.
Parking and resort-service arrangements.
Guest support.
Operational communications during and after a stay.
Promotional communications where a valid legal basis exists.
By choosing WhatsApp, guests acknowledge that communications may also be processed by WhatsApp, Meta Platforms, and their affiliated service providers under their own privacy policies.
Guests may use email instead of WhatsApp.
Guests may opt out of marketing communications at any time.
13. Children’s Data
Personal data relating to minors may be processed where necessary for:
Accommodation reservations.
Mandatory traveller registration.
Compliance with public-security obligations.
Verification of the relationship with an accompanying adult where required.
Protection of the safety of the minor.
Provision of the requested accommodation service.
Where consent is legally required, authorization from a parent or legal guardian will be obtained.
Processing required for mandatory guest registration does not depend on marketing consent.
14. Automated Decision-Making
El Dorado Beach Resort does not ordinarily make decisions producing legal or similarly significant effects based solely on automated processing.
Booking platforms, payment providers, identity-verification providers, and fraud-prevention providers may use automated systems for fraud, security, identity, payment, or risk checks under their own privacy policies and legal responsibilities.
15. Rights of Data Subjects
Individuals may exercise the following rights, subject to the conditions established by applicable law:
Right of access.
Right of rectification.
Right of erasure.
Right to restriction of processing.
Right to data portability.
Right to object.
Right to withdraw consent.
Right not to be subject solely to automated decision-making where applicable.
Right to lodge a complaint with a supervisory authority.
Requests may be submitted to:
Email: info@doradobeachresort.com
Postal Address:
Christopher Michael Caples
El Dorado Beach Resort
Calle Ribera Baja 14
18690 Almuñécar, Granada, Spain
The request should identify the person making it, specify the right being exercised, and provide sufficient information to locate the relevant records.
Additional information may be requested where reasonably necessary to verify the requester’s identity.
Requests will ordinarily be handled within the periods established by the GDPR.
The right to erasure does not require the deletion of information that must be retained to comply with a legal obligation or establish, exercise, or defend legal claims.
16. CCTV Access Requests
A person requesting access to CCTV images should provide sufficient information to identify the relevant footage, including where possible:
The date.
The approximate time.
The monitored location.
A description of the person or vehicle concerned.
Information necessary to verify identity.
The privacy rights of other identifiable individuals appearing in the footage must also be protected. Images may therefore be obscured, access may be restricted, or another appropriate method of access may be used.
A request cannot be fulfilled where the footage has already been automatically deleted after the 30-day retention period and was not preserved for an incident, claim, or legal obligation.
Because live audio is not recorded or retained, it is not possible to provide a copy of previously heard audio.
17. Security of Personal Data
El Dorado Beach Resort implements appropriate technical and organizational measures designed to protect personal data against:
Unauthorized access.
Unlawful disclosure.
Accidental loss.
Alteration.
Destruction.
Misuse.
Loss of availability.
Measures may include access controls, strong passwords, multi-factor authentication where available, secure service providers, software updates, backups, confidentiality requirements, data-processing agreements, and incident-response procedures.
No electronic transmission or storage system can be guaranteed to be completely secure. El Dorado Beach Resort will nevertheless apply safeguards proportionate to the nature and risks of the processing.
18. Personal Data Breaches
Where a personal-data breach occurs, El Dorado Beach Resort will assess the nature and potential consequences of the incident.
Where required by the GDPR, the breach will be reported to the Agencia Española de Protección de Datos within the applicable legal period.
Affected individuals will also be informed where the breach is likely to result in a high risk to their rights and freedoms, unless a legal exception applies.
19. Third-Party Websites
The website may contain links, booking tools, maps, payment functions, social-media features, or other services operated by third parties.
Those third parties may process personal data under their own privacy and cookie policies.
El Dorado Beach Resort is not responsible for processing independently carried out by third-party websites or service providers.
Users should review the relevant third party’s privacy information before submitting personal information through its services.
20. Complaints
Individuals who believe their personal data has been processed unlawfully may file a complaint with:
Agencia Española de Protección de Datos (AEPD)
Website: www.aepd.es
Individuals may contact El Dorado Beach Resort first so that the matter can be investigated, but doing so is not required before filing a complaint with the AEPD.
21. Changes to This Privacy Policy
El Dorado Beach Resort reserves the right to modify this Privacy Policy to reflect:
Legal or regulatory changes.
Operational or technological changes.
Changes to service providers.
Changes to reservation, payment, communication, or security systems.
Changes to CCTV coverage or live-audio functionality.
New services or business practices.
The most current version will always be available at www.doradobeachresort.com.
Where a change affects processing based on consent, any additional consent required by law will be requested separately.
22. Privacy Information and Consent
This Privacy Policy is provided to explain how and why personal data is processed.
Reading or receiving this Privacy Policy does not, by itself, constitute consent to all processing activities described in it.
Where consent is the appropriate legal basis, including for certain marketing communications or non-essential website cookies, consent will be requested separately through a clear affirmative action.
Reservation management, payment processing, mandatory guest registration, necessary operational communications, and proportionate property-security processing may be based on contract, legal obligation, or legitimate interests and do not depend on marketing consent.