Privacy Policy
1. IDENTIFICATION
At VIBRA HOTELS, a trading brand owned by HIPERION HOTEL GROUP, S.L., we pay the greatest attention and care to complying with applicable data protection regulations, and to the data protection rights of our guests and customers.
This Privacy Policy is intended to identify who is responsible for processing personal data, and to explain how we obtain, process and protect the personal data you provide or that we collect through our website https://www.vibrahotels.com/es (the “Website”) via forms and/or cookies, so that you can freely, knowingly and voluntarily decide whether you wish us to process it.
The use of cookies and other tracking technologies on the Website is governed by its Cookie Policy, available on the Website itself, where users can obtain detailed information about the cookies used, their purpose and how to configure or withdraw their consent.
Should you wish to stay and/or complete the booking process through this Website at the following hotel establishments, the data controller is:
| IBIZA TOWN | PLAYA D'EN BOSSA | SAN ANTONIO | BAHIA DE SAN ANTONIO | CALA TARIDA | MALLORCA | SEVILLE |
| *Apartamentos Vibra Jabeque Dreams *Aparthotel Vibra Jabeque Soul *Hotel Vibra Lei Ibiza *Aparthotel Vibra Lux Mar *Hotel Vibra Maritimo * Apartmentos Vibra Panoramic *Apartamentos Vibra Tivoli *Apartamentos Vibra Tropical Garden *Hotel Vibra Vila Hotel | *Hotel Vibra Algarb *Hotel Vibra Bossa Flow *Hotel Vibra Isola *Hotel Vibra Mare Nostrum *Aparthotel Vibra Mogambo | *Apartamentos Vibra Calima *Aparthotel Vibra Central City *Aparthotel Vibra Del Mar *Hotel Vibra District *Hotel Vibra Marco Polo I *Hotel Vibra Marco Polo II *Aparthotel Vibra Sanan *Hotel Vibra Yamm Sunset *Hotel Vibra Yamm Urban | *Aparthotel Vibra Bay *Aparthotel Vibra Club Maritim *Aparthotel Vibra Monterrey *Apartamentos Vibra Riviera *Hotel Vibra Riviera *Aparthotel Vibra San Marino *Hotel Vibra San Remo *Hotel Vibra S’Estanyol | *Hotel Vibra Cala Tarida | *Hotel Vibra Beverly Playa *Hotel Vibra Palma Cactus | *Hotel Fenix by Vibra |
- Identity: HIPERION HOTEL GROUP, S.L. (hereinafter, “HIPERION”)
- Tax ID: B-86213378
- Registered office: C/ ZURBARÁN, 30, 1º, 28010 MADRID
Should you wish to stay and/or complete the booking process through this Website at the following hotel establishments, the data controller is:
| CIUDADELA - MENORCA |
| *Apartamentos Vibra Caleta Playa *Apartamentos Vibra Blanc Cottage *Aparthotel Vibra Blanc Palace |
- Identity: VACANCES MENORCA RESORT S.L. (hereinafter, “VACANCES MENORCA”)
- Tax ID: B-07694342
- Registered office: C/ DES SIGNE LLEO, 07760 SA CALETA - MENORCA
If you have any query about data protection, or about how we process your data through this Website, you can contact our Data Protection Officer (DPO): you can reach our DPO by email at: dpo@vibrahotels.com. Please state “Data Protection Officer” in the subject line, and identify yourself by a means that reasonably allows us to verify your identity.
2. INFORMATION AND CONSENT
By accepting this Privacy Policy, the user is clearly and simply informed of how the personal data they provide through this “Website” will be processed, as well as data derived from their browsing and any other data they may provide in future. The legal basis for each processing activity is not always consent, but rather whichever basis applies in each case as set out in section 6 of this Privacy Policy (performance of a contract, legitimate interest or consent, depending on the purpose concerned). Where the legal basis is consent, the user may freely and voluntarily decide whether to provide their personal data through the various forms available on this “Website”.
3. OBLIGATION TO PROVIDE DATA
The data requested in the Website's forms is generally mandatory (unless otherwise stated in the relevant field) in order to fulfil the stated purposes.
Therefore, if this data is not provided, or is provided incorrectly, we may be unable to process your request, without prejudice to your ability to freely view the content of the Website.
4. FOR WHAT PURPOSES WILL HIPERION HOTEL GROUP, S.L. PROCESS THE USER'S PERSONAL DATA?
The personal data provided through the Website will be processed by HIPERION HOTEL GROUP, S.L. or by VACANCES MENORCA, depending on the hotel establishment where you wish to stay, for the following purposes:
1- Data provided to make bookings, whether through the “Website” or the contact centre (call centre, email or chat) for individual or group bookings and rooms at the hotel establishment of your choice
- Managing the bookings requested by the user at the chosen hotel establishment;
- Sending confirmation or documentation of the booking made by the user at the chosen hotel establishment;
- Where consent has been given for this purpose, sending commercial communications solely on behalf of HIPERION
- Carrying out analysis of the use of the Website and checking users' preferences and behaviour regarding our hotel services.
2- Data provided to modify and cancel bookings:
- Managing requests to modify or cancel a booking made by the user.
- Sending a reply to the request submitted regarding the cancellation or modification of a booking.
- Carrying out analysis of the use of the “Website” and checking users' preferences and behaviour.
3- Data provided in the cart recovery form:
- Sending a reminder of a booking not completed by the user or, where applicable, of searches for hotel services on our “Website” carried out by the user.
- Carrying out analysis of the use of the Website and checking users' preferences and behaviour.
4- Data provided through the Newsletter form:
- Managing user requests for contact and information through the channels provided for this purpose on the “Website” linked to the data controller's establishments;
- Managing the request submitted;
- Carrying out analysis of the use of the Website and checking users' preferences and behaviour;
- Managing subscription to and/or unsubscription from the Newsletter, carried out through the channel provided on the “Website” linked to HIPERION's Newsletter programme;
5- Data provided to register as a registered user on the “Website” linked to HIPERION and VACANCES MENORCA establishments:
- Managing your registration or cancellation request within the option chosen by the user;
- Verifying that the user meets the requirements to register within the option selected, whenever HIPERION considers it appropriate;
- Handling and responding to any requests for information and/or complaints made by the user;
- Finding promotions suited to the needs selected by the user;
- Sending personalised commercial communications on behalf of HIPERION;
- Carrying out analysis of the use of the Website and checking users' preferences and behaviour;
6- Data provided for the Club Vibra Programme:
- Managing the loyalty programme and processing your registration request, assigning your member number, access codes to your private online area, and allowing you to accumulate and redeem your points.
- Tailoring the loyalty programme's services to the Member's preferences and tastes, and measuring their satisfaction with the service provided at our hotels. This purpose may include sending quality surveys and adapting and personalising the services provided by HIPERION.
- Sending communications relating to your account, including, among others, points balance, your card category, notifications and any other communication that keeps you informed of your account status.
- Sending personalised commercial communications by email or equivalent means about offers and services related to the Programme, unless you object to such processing.
7- Data provided in the contact forms and on the website:
- Managing user requests for contact and information through the channels provided for this purpose on the “Website;”
- Managing the request submitted
- Carrying out analysis of the use of the Website and checking users' preferences and behaviour.
8- Data provided for posts on Blogs owned by HIPERION;
- Managing the publication of your comments on the Website.
- Managing subscription to and/or unsubscription from the blog Newsletter at the user's request
- Carrying out analysis of the use of the Website and checking users' preferences and behaviour.
- Where necessary, monitoring the content of user comments and, where applicable, removing those whose content does not comply with the conditions applicable to this Website, at HIPERION's discretion.
5. WHAT USER DATA WILL HIPERION HOTEL GROUP, S.L. PROCESS?
1- Data provided to make bookings, whether through the Website or the contact centre (call centre, email or chat) for individual or group bookings and rooms:
- Identification data: first name, surname, nationality.
- Contact data: email address, phone number.
- Data on transactions of goods and services: products and services purchased or in which you show interest during your stay at the hotel establishment.
- Stay preferences.
- Financial data, credit or debit card, financial and insurance data.
- Other data: data provided by the data subjects themselves in open fields or through the call made
- Browsing data.
2- Data provided to modify and cancel bookings:
- Identification data: first name, surname, address, nationality.
- Contact data: email address, phone number.
- Data on transactions of goods and services
- Financial and insurance data.
- Other data: data provided by the data subjects themselves in the open fields of the forms available on the Website or in attached documents.
- Browsing data.
3- Data provided in the cart recovery form:
- Contact data: address and email.
4- Data provided to send the Newsletter:
- Identification data: first name, surname, address, nationality.
- Contact data: country of residence, email address.
- Personal characteristics data: language.
5- Data provided to register as a registered user on the “Website;
- Identification data: first name, surname, address and nationality
- Contact data: email address, phone number.
- User and/or account holder identification codes or keys.
- Employment detail data: profession, sector.
6- Data provided for the Club Vibra Programme:
- Identification data: first name, surname, tax identification number, signature, address and nationality.
- Personal characteristics data: date of birth and gender.
- Contact data: email, phone number
- User and/or account holder identification codes or keys.
- Transactions of goods and services. Products and services purchased or in which you show interest.
- Accommodation preferences
- Browsing data
7- Data provided in the contact forms and on the website:
- Identification data: first name, surname, address, nationality.
- Contact data: email address, phone number.
- Data on transactions of goods and services
- Other data: data provided by the data subjects themselves in the open fields of the forms available on the Website or in attached documents.
- Browsing data.
8- Data provided for posts on BLOGs owned by HIPERION:
- Identification data: first name, surname, address, nationality.
- Contact data: country of residence, email address.
- Browsing data. If the user provides third-party data, they confirm that they have that person's consent and undertake to pass on the information contained in the Privacy Policy to them, releasing HIPERION from any liability in this regard. Nonetheless, HIPERION may carry out periodic checks to confirm this, taking whatever due diligence measures are appropriate under data protection regulations.
6. WHAT IS THE LEGAL BASIS FOR PROCESSING THE USER'S DATA?The legal basis for processing your personal data will be as follows:
1. For making bookings, whether through the Website or the contact centre (call centre, email or chat) for individual or group bookings and rooms: performance of the contract between the parties. For carrying out analysis of the use of the website, the legitimate interest of the data controller.
2. For modifying and/or cancelling your booking: performance of the contract between the parties. For carrying out analysis of the use of the website, the legitimate interest of the data controller.
3. For sending the cart recovery reminder: the consent given by the user. For carrying out analysis of the use of the website, the legitimate interest of the data controller.
4. For sending the Newsletter: the consent given by the user.
5. For managing registration as a registered user: the consent requested and, in cases of verifying the user's compliance with conditions, as well as for carrying out analysis of the use of the website, the legitimate interest of the data controller. However, if you withdraw your consent, which you may do at any time, this will not affect the lawfulness of processing carried out prior to that withdrawal.
6. For the Club Vibra form: the consent requested from you, which is the basis for sending commercial communications, and which you may withdraw at any time. However, if you withdraw your consent, this will not affect the lawfulness of processing carried out prior to that withdrawal. For carrying out analysis of the use of the website, the legitimate interest of the data controller.
7. For sending the contact and website forms: the consent given by the user. For carrying out analysis of the use of the website, the legitimate interest of the data controller.
For managing and publishing comments or posts submitted by users on HIPERION's BLOGs: the consent given by the user and, in cases involving analysis of the use of the Website, checking users' preferences and behaviour, as well as monitoring the content of comments, the legitimate interest of the data controller. If you withdraw your consent to the publication of comments, it will be removed by HIPERION from the Website. The consents obtained for the purposes mentioned are independent of each other, so the user may revoke just one of them without affecting the others. To revoke such consent, the User may contact us at any time through the following channels: dpo@vibrahotels.com
7. CALL RECORDING
If the user contacts our telephone customer service or call centre, please note that calls may be recorded. This processing is carried out in order to manage and follow up bookings and requests, as well as to ensure service quality and to have evidence of the actions carried out. The legal basis for the recording is the legitimate interest of the data controller (Article 6.1.f of the GDPR), without prejudice to the fact that, where the recording is intended to formalise the booking, the legal basis will be the performance of a pre-contractual or contractual relationship (Article 6.1.b of the GDPR). Recordings will be kept for a maximum period of one (1) month from the date they are made, unless they are necessary to deal with a claim or to comply with a legal obligation, in which case they will be duly retained, blocked, for the
limitation period of any actions that may arise. At the start of each call, the user will be informed that the call is being recorded via an automated notice.
8. FOR HOW LONG WILL WE PROCESS YOUR PERSONAL DATA?
Personal data accessed will be processed and retained for as long as the contractual relationship or the purpose for which it was collected remains in place. After that, once the contractual relationship has ended or the data is no longer relevant to the purposes for which it was collected, it will be retained, duly blocked, to be made available to the competent Public Authorities, Courts and Tribunals or the Public Prosecutor's Office for the limitation period of any actions that may arise from the relationship with the user and/or the legally established retention periods. The data will then be permanently deleted once these periods have elapsed.
As a general guide, and without prejudice to the above, personal data will be retained for the following periods:
(i) data processed for managing bookings, including data collected through the call centre, for the duration of the relationship and, subsequently, blocked for the legally applicable limitation periods (generally, up to six years under commercial regulations and any applicable tax and accounting periods);
(ii) data collected to comply with legal obligations regarding traveller registration will be retained for the period required by applicable regulations, currently three years from the end of the accommodation service, in accordance with Royal Decree 933/2021, without prejudice to any longer periods that may be legally required;
(iii) data processed on the basis of the user's consent will be retained until the user withdraws that consent; and
(iv) call recordings will be retained for the period indicated in the section relating to call recording in this Privacy Policy.
If the user has given consent for the processing purposes set out in section 4 of this Privacy Policy, their information will be retained for as long as the user does not withdraw the consent originally given.
9. WHO WILL THE USER'S DATA BE SHARED WITH?
In order to fulfil the purposes described in this Privacy Policy, the user's personal data may be communicated to or accessible by the following recipients or categories of recipients:
(i) service providers acting as data processors on behalf of the controller — including Aircall (telephony and call centre services) and NeoBookings (booking management platform), Centribal (conversational assistant or chatbot), and Zendesk (customer service management), who process personal data solely in accordance with our instructions and under the corresponding data processing agreement entered into in accordance with Article 28 of the GDPR; and
(ii) Public Authorities, Courts and Tribunals and Law Enforcement Agencies, where there is a legal obligation to do so. Outside these cases, your data will not be transferred or disclosed to third parties, except where legally required or with the user's consent.
10. INFORMATION ON INTERNATIONAL DATA TRANSFERS
As a general rule, your personal data will not be subject to international transfers outside the European Economic Area (EEA).
However, the use of certain service providers or partner entities may involve access to or processing of personal data from third countries. In such cases, international transfers will only be carried out where there is a legal basis authorising them and in accordance with Articles 44 et seq. of Regulation (EU) 2016/679 (GDPR), applying, where necessary, the appropriate safeguards provided for under the regulations, such as adequacy decisions adopted by the European Commission or the signing of the Standard Contractual Clauses, together with any supplementary measures that may be required.
You can obtain additional information about any international transfers carried out, the destination countries and the safeguards applied by contacting our Data Protection Officer at dpo@vibrahotels.com.
11. INFORMATION ON THE PROCESSING OF THIRD-PARTY DATA
If the Account Holder provides the data controller, at any time, with third-party data, they confirm that they have that person's consent and undertake to pass on the information contained in this clause to them, as well as to inform HIPERION or VACANCES MENORCA of any change or update relating to it.
12. DATA SECURITY
The data controller has adopted the technical and organisational measures necessary to guarantee the security of personal data and to prevent its alteration, loss, unauthorised processing or access, taking into account the
state of technology, the nature of the data stored and the risks to which it is exposed, whether arising from human action or the physical or natural environment. The Account Holder is responsible for keeping their user password strictly confidential, and is responsible for access to our “Website” or private area, or its use by themselves or by any person using the password they have previously provided, whether or not such access or use was authorised by them or on their behalf, and even if that person is their employee, relative or agent. You agree to
(i) notify us immediately of any unauthorised use of your password, your account, or any other security breach, and
(ii) ensure that you close your account at the end of each session.
The Account Holder is solely responsible for controlling the disclosure and use of their password, for access to and use of their account, and for informing us of their wish to close their account.
In compliance with Articles 33 and 34 of the GDPR, in the event of a personal data breach that poses a risk to users' rights and freedoms, the data controller will notify the Spanish Data Protection Agency within a maximum of 72 hours of becoming aware of it and, where the risk to their rights and freedoms is high, will also notify the affected data subjects without undue delay.
13. VIDEO SURVEILLANCE
The hotel establishments have a video surveillance system with cameras installed in access and common areas, aimed at ensuring the safety of people, facilities and property. The legal basis for this processing is the legitimate interest of the data controller in protecting people and property (Article 6.1.f of the GDPR) and, where applicable, compliance with a legal obligation. The presence of cameras is indicated by the relevant information signs placed in a visible location in the monitored areas. Footage will be retained for a maximum period of one (1) month from recording, unless it needs to be kept as evidence of acts against the safety of people, property or facilities, in which case it will be made available to the competent authorities. No video surveillance is carried out in areas intended for rest or of a private nature, all in accordance with the provisions of Article 22 of Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights.
14. RIGHTS OF DATA SUBJECTS REGARDING THEIR DATA
You may exercise, at any time and free of charge, the rights set out below by writing to the email address dpo@vibrahotels.com, stating “Data Protection” as the subject and identifying yourself by a means that reasonably allows us to verify your identity, without it generally being necessary to provide a copy of your identity document.
In particular, you may exercise the following rights:
a) Withdraw the consent given for the processing and disclosure of your personal data.
b) Obtain information about whether or not your personal data is being processed.
c) Access your personal data.
d) Rectify inaccurate or incomplete data.
e) Request the erasure of your data where, among other reasons, the data is no longer necessary for the purposes for which it was collected.
f) Restrict the processing of data where any of the conditions set out in data protection regulations are met.
g) In certain circumstances and for reasons relating to their particular situation, data subjects may object to the processing of their data.
h) Request the portability of your data.
i) Lodge a complaint with the Spanish Data Protection Agency, at the following address: Calle de Jorge Juan, 6, 28001 Madrid, if you consider that the data controller has infringed the rights recognised to you under data protection regulations.
The data subject may contact the data controller's Data Protection Officer by email at: dpo@vibrahotels.com
15. GOOGLE ADVERTISING SERVICES
This site uses Google advertising services. For more information on how Google uses personal data when you visit websites or apps that use its services, you can visit the Google Business Data Responsibility page.
