This policy primarily concerns the public website and commercial relationships with HotelGEX. The processing of guest data carried out by each hotel through the platform is additionally governed by the relevant agreement and, where applicable, by the data processing agreement with that hotel.
1. Data controller
The entity that owns and provides the HotelGEX service is the controller responsible for the processing activities described. You can contact us at hello@hotelgex.es or through Contact. The controller’s identification, tax, registration and address details must appear in the Legal Notice.
2. Data we may process
Depending on your interaction, we may process your first name, last name, company, job title, email address, telephone number, information provided in forms or communications, data relating to demos, trials and contracting, commercial preferences, interaction history, and technical data necessary for security, operation and abuse prevention.
When a business contact comes from sources other than the data subject themselves, we will provide information in accordance with applicable regulations and document the source and corresponding legal basis.
3. Purposes and legal bases
When processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before its withdrawal.
4. Artificial Intelligence
HotelGEX incorporates AI to assist with analysis, content, recommendations and automation. Data entered in forms or conversations may be processed by technology providers necessary for the requested functionality, subject to the applicable contractual and security safeguards.
Visitors will not be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect them without the required legal basis and safeguards. When a specific functionality involves profiling or relevant automated decisions, additional information will be provided.
5. Recipients and processors
Providers necessary to operate HotelGEX — hosting, infrastructure, email, support, security, consent-based analytics or AI — may process data as processors or sub-processors, where applicable. HotelGEX does not sell personal data. Data may be disclosed where required by law, in response to a request from an authority, or to establish, exercise or defend claims.
6. International transfers
If a provider processes information outside the European Economic Area, the applicable valid mechanism will be used, such as an adequacy decision or standard contractual clauses, together with any necessary additional safeguards.
7. Retention
Data will be retained for as long as necessary for the relevant purpose and subsequently for the periods required to comply with legal obligations or address liabilities. Commercial contacts will be reviewed periodically; minimum information may be retained to respect an objection or opt-out.
8. Rights
You may request access, rectification, erasure, objection, restriction and data portability where applicable, as well as withdraw your consent, by writing to hello@hotelgex.es. If you believe that the processing does not comply with applicable regulations, you may lodge a complaint with the Spanish Data Protection Agency.
9. Security
We apply technical and organisational measures appropriate to the risk, including access controls, tenant segregation, credential management, event logging and business continuity measures.
10. Minors
The HotelGEX website and commercial services are aimed at professionals and businesses and are not designed for direct contracting by minors.
11. Changes
We may update this policy due to regulatory or technological changes or changes to our processing activities. The page will indicate the date of the current version.