Legal
Privacy Policy
Casa Mirasol and Casita Mirasol · Last updated: 16 August 2026
This policy explains what data we collect when you book or stay at our properties, how we use it and what rights you have. It is written as simply as possible; the legal references are given in notes, for anyone who wishes to check them.
Information provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
1. Who processes your data
Tullio Severo — Calle San Borondón, 79, 35509 Playa Honda, Lanzarote, Spain. Email: casamirasollanzarote@gmail.com.
Data controller pursuant to art. 4(7) GDPR. No Data Protection Officer (DPO) has been appointed: the conditions of art. 37 GDPR do not apply.
2. What data we collect
- Booking data: first name, last name, email, phone number, stay dates, amount paid.
- Optional note: a short message you can leave us when booking (maximum 300 characters), for example your expected arrival time or a practical request. It is not required: if you write nothing, we collect nothing.
- Identity document: of each adult guest, collected in person at check-in — required by Spanish law (see point 4).
- Payment data: handled entirely by SumUp — we neither see nor store it (see point 5).
- Messages sent through the contact form: name, email address, the subject you choose and the text of the message (up to 1000 characters), plus any files you decide to attach (photos, PDFs or text files, up to 2 MB in total). Writing to us is never required: you can always reach us by phone, WhatsApp or email. The message and its attachments are not kept on the site, they go straight to the owner's mailbox, which is where they stay.
- Visit statistics: the site measures pages visited and loading times in aggregate, anonymous form, through Vercel, without cookies.
We only collect the data that is necessary: without it we cannot confirm your booking or host you legally. We do not collect special categories of data (health, beliefs, orientation) and we do not ask you for anything that is not needed for these purposes. The optional note and the contact form message are free-text fields, and an attachment can contain anything: please do not use them for data of that kind. If something along those lines matters for your stay, talk to us directly.
Data minimisation principle, art. 5(1)(c) GDPR. Information on the mandatory nature of providing the data and the consequences of refusal, art. 13(2)(e) GDPR.
3. Why we process your data and on what legal basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Manage the booking and the stay | Name, email, phone, dates, amount, optional note | Performance of the contract — art. 6(1)(b) GDPR |
| Charge the card on the agreed date, where you chose to pay later | Card identifier provided by SumUp (not the card number), name, email | Performance of the contract — art. 6(1)(b) GDPR |
| Report guests' identity to the Spanish authorities | Identity document data of each adult guest | Legal obligation — art. 6(1)(c) GDPR + Royal Decree 933/2021 |
| Keep transaction data for tax and accounting obligations | Name, dates, amounts | Legal obligation — art. 6(1)(c) GDPR + Law 58/2003 (General Tax Law) |
| Respond to requests, questions or complaints | Name, email, content of the message and of any attachments | Legitimate interest in providing assistance — art. 6(1)(f) GDPR |
| Defend a right in legal proceedings, if necessary | Booking data | Legitimate interest — art. 6(1)(f) GDPR |
We do not use your data for marketing, newsletters or advertising, and we do not sell it to anyone.
4. Disclosure of data to the Spanish authorities
By law we report the identity of each adult guest to the competent Spanish authorities through the SES.HOSPEDAJES system, within the timeframes set by the regulations. This is a legal obligation, not our choice: we cannot host you without making this report, and for this reason it is not possible to object to this specific processing.
Royal Decree 933/2021, applicable from 2 December 2024. Legal basis: art. 6(1)(c) GDPR.
5. Payments
Payments are processed securely by SumUp. SumUp supports various payment methods, including credit/debit cards, Apple Pay and Google Pay, without Mirasol accessing or storing card data. Mirasol does not store, process or retain any payment card data: all transactions are handled by SumUp as an independent controller for payment operations.
If you choose to pay on the stated date, with a saved card, the card data stays with SumUp, which gives us an identifier (a token) usable only to request the charge for that booking. We cannot recover the card number from it, nor use the token for anything else. We keep it until the charge is made or the booking lapses, and it is not used afterwards.
SumUp acts as an independent controller for payment operations, not as our processor under art. 28 GDPR. The processing of card data is governed by SumUp's privacy policy.
6. Who we share your data with
To run the site and manage bookings we rely on a few technical providers, who process the data solely on our instructions and on the basis of a GDPR-compliant agreement. None of them receives your data for advertising or marketing purposes.
The categories of providers are as follows:
- Website hosting and distribution provider — keeps the site online and serves its pages.
- Managed cloud database provider — stores your booking data.
- Transactional email provider — sends the booking confirmation email and delivers messages written through the contact form to the owner.
- Application security provider — protects the booking system and the contact form from automated or abusive use.
- Payment service provider — SumUp, with the independent role described in point 5.
You can ask us at any time for the named, up-to-date list of these providers, by writing to the address given in point 1: we will provide it without you having to give a reason.
In addition to these, we disclose data to the Spanish authorities where the law requires it (point 4) and, if necessary, to a tax or legal advisor bound by professional secrecy.
Indication by categories of recipients, as permitted by art. 13(1)(e) GDPR. Processors appointed pursuant to art. 28 GDPR, on the basis of their respective Data Processing Agreements.
7. Transfer of data outside the European Union
Some of the providers indicated in point 6 — in particular those handling email delivery, hosting and application security — may also process data on servers located in the United States. European law allows this provided that appropriate safeguards are in place: these providers rely on Standard Contractual Clauses approved by the European Commission and/or on the EU-US Data Privacy Framework certification.
You can ask us at any time for a copy of the safeguards applied, by writing to the address given in point 1.
Arts. 44-49 GDPR. Standard Contractual Clauses: Implementing Decision (EU) 2021/914. EU-US Data Privacy Framework: adequacy decision of 10 July 2023.
8. How long we keep your data
| Category of data | How long | Why |
|---|---|---|
| Booking and payment data (name, email, dates, amounts, optional note) | 5 years from the end of the stay | Spanish 4-year tax limitation period, plus a prudential margin |
| Identity document data collected for guest registration | Only as long as strictly necessary for the report to the authorities, then deleted | As a non-professional private individual we are not required to keep the document register |
| Correspondence (contact form messages with their attachments, emails with requests, questions, complaints) | 2 years from the last contact | Handling assistance and any disputes |
| Data subject to an ongoing dispute | Until final resolution | Defence of a right in legal proceedings |
Storage limitation principle, art. 5(1)(e) GDPR. Once the period expires, data is deleted or anonymised.
9. Your rights
You have the right to:
- access the data we hold about you and obtain a copy (art. 15);
- correct it if inaccurate or incomplete (art. 16);
- request its erasure, where the law allows (art. 17);
- request its restriction in case of dispute (art. 18);
- receive it in a readable format or have it transferred to another controller (art. 20);
- object to processing based on our legitimate interest (art. 21).
Erasure and objection do not apply to data we are required by law to keep or report (points 4 and 8). We respond within one month of the request.
To exercise these rights, write to us at casamirasollanzarote@gmail.com. You also have the right to lodge a complaint with the competent supervisory authority — in Spain, the Spanish Data Protection Agency (art. 77).
10. No automated decision-making
We do not make decisions about you in an automated way and we do not carry out profiling. The booking system automatically checks the availability of dates, but this does not involve any assessment of you as a person.
Art. 22 GDPR.
11. Minors
We accept bookings that include minors only if accompanied by a parent or guardian, who must provide an identity document at check-in. Bookings can only be made by adults: we do not process data of minors collected directly from them.
12. Security
We adopt technical and organisational measures appropriate to the risk: limited access to the database, encrypted connections (HTTPS), two-factor authentication on critical accounts, anti-abuse protection on the booking system and the contact form, verification of what attached files really contain, and selection of providers with adequate security guarantees.
Art. 32 GDPR.
13. If something goes wrong
In the event of a personal data breach that poses a risk to your rights, we will inform the supervisory authority within 72 hours and, if the risk is high, we will also notify you directly, explaining what happened and what you can do.
Arts. 33 and 34 GDPR.
14. Changes to this policy
We may update this policy from time to time, for example if our technical providers or legal obligations change. The date of the last update is always shown at the top of the page; in the event of substantial changes we will notify you.
15. Contact
For any questions about this policy, write to us at casamirasollanzarote@gmail.com.
