Privacy Policy
Last updated: 19 July 2026
1. DATA CONTROLLER
The controller responsible for processing personal data through this website and in connection with direct accommodation services is:
SAN BENEDICTO INVERSIONES, S.L.U.
NIF: B76794718
Registered office:
C/ Países Bajos, Complejo Ocean View, Local 1117-A/1
San Eugenio Alto, Adeje
38670 Santa Cruz de Tenerife
Spain
Email: sanbenedictoinversiones@gmail.com
Telephone: +34 682 813 579
Commercial Registry: Registered with the Registro Mercantil de Santa Cruz de Tenerife.
In this Privacy Policy, “Villa Isabella”, “the Company”, “we”, “us” and “our” refer to SAN BENEDICTO INVERSIONES, S.L.U.
2. PURPOSE OF THIS PRIVACY POLICY
This Privacy Policy explains how Villa Isabella collects, uses, shares and protects personal data when a person:
visits our website;
contacts us;
requests information;
checks accommodation availability;
makes or manages a direct booking;
stays at Villa Isabella;
communicates with us through a booking platform;
subscribes to marketing communications, where available; or
otherwise interacts with our accommodation services.
Personal data is processed in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”), Spanish Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights, and other applicable legislation.
3. PERSONAL DATA WE MAY COLLECT
Depending on how you interact with us, we may collect the following categories of personal data.
Identification data
This may include:
name and surname;
date of birth;
nationality;
gender, where legally required;
identity card, passport or other identification document details;
signature; and
legally required guest-registration information.
We will not normally retain a copy of an identification document unless this is necessary for legal, security or verification purposes.
Contact data
This may include:
postal address;
email address;
telephone number;
preferred language; and
communication preferences.
Booking and stay information
This may include:
check-in and check-out dates;
number and identity of guests;
ages of accompanying children, where necessary;
booking reference;
booking source;
selected rate and cancellation conditions;
arrival information;
special requests;
approved pet information;
services requested;
communications relating to the stay;
incidents, complaints or maintenance requests; and
information concerning damage or security-deposit deductions.
Payment and transaction information
This may include:
amounts paid;
payment dates;
transaction references;
invoice details;
deposit or pre-authorisation information;
refund information; and
limited payment information supplied by the payment provider.
Complete payment-card information is normally processed directly by the relevant payment service provider and is not stored by Villa Isabella or SAN BENEDICTO INVERSIONES, S.L.U.
Communication data
This includes the content of emails, telephone communications, website forms, platform messages and other correspondence exchanged with us.
Technical and website data
When you use the website, we may collect:
IP address;
browser and device information;
operating system;
pages visited;
date and time of access;
referral source;
language settings;
cookie identifiers; and
information about website errors or security events.
Further information is available in our Cookie Policy.
4. HOW WE OBTAIN PERSONAL DATA
We may obtain personal data:
directly from you;
from the person making a booking on your behalf;
from another member of your group;
through our website or booking engine;
through accommodation-management services such as Smoobu;
from Booking.com, Airbnb, Vrbo or another booking platform;
from payment service providers;
from authorised agents or intermediaries;
from publicly available sources where legally permitted; or
from competent public authorities.
If you provide personal data concerning another person, you confirm that you are authorised to provide it and that you have informed that person about this Privacy Policy.
5. PURPOSES AND LEGAL BASES FOR PROCESSING
Responding to enquiries
We process identification, contact and communication data to respond to questions, availability requests and other enquiries.
The legal basis is taking steps at your request before entering into a contract and our legitimate interest in managing communications and providing customer service.
Managing bookings
We process booking, guest, contact and transaction information to:
verify availability;
confirm and manage reservations;
process payments and refunds;
provide check-in information;
communicate before, during and after the stay;
organise requested services; and
manage changes, cancellations or complaints.
The legal basis is the performance of the accommodation contract and taking steps before entering into that contract.
Providing accommodation services
We process guest and stay information to provide the booked accommodation, manage access to Villa Isabella, respond to maintenance issues, protect the property and assist guests during their stay.
The legal basis is performance of the contract and our legitimate interest in operating and protecting the accommodation safely.
Guest identification and registration
We process the identification and stay information required by Spanish legislation governing persons staying in accommodation establishments.
The legal basis is compliance with a legal obligation.
Refusal to provide information required by law may prevent or delay check-in.
Payments, invoices and accounting
We process transaction, billing and booking data to receive payments, issue invoices, manage security deposits, process refunds and comply with accounting and tax requirements.
The legal basis is performance of the contract and compliance with legal obligations.
Security deposits and damage claims
We may process booking information, communications, photographs, invoices, estimates and other evidence where reasonably necessary to investigate damage, missing items, extraordinary cleaning or another breach of the booking conditions.
The legal basis is performance of the contract and our legitimate interest in protecting our property, establishing claims and defending our legal rights.
Legal and regulatory compliance
We may process and disclose personal data when necessary to comply with tourism, consumer, tax, accounting, anti-fraud, public-security, court or administrative requirements.
The legal basis is compliance with a legal obligation.
Website operation and security
We process technical information to operate the website, identify errors, prevent fraud, protect systems and maintain website security.
The legal basis is our legitimate interest in providing a secure and functional website.
Non-essential cookies are used only with the legal basis described in the Cookie Policy, normally your consent.
Marketing communications
Where permitted, we may send information about Villa Isabella or related accommodation services.
The legal basis will be your consent or another lawful basis permitted by electronic-marketing legislation.
You may unsubscribe at any time by using the link included in the communication or contacting sanbenedictoinversiones@gmail.com.
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
6. WHETHER PROVIDING DATA IS REQUIRED
Information marked as mandatory in a form or booking process is necessary to respond to the request, complete the booking, provide the accommodation or comply with a legal obligation.
If mandatory information is not supplied, we may be unable to process the enquiry, confirm the booking, complete check-in or provide the requested service.
Optional information is supplied voluntarily.
7. RECIPIENTS OF PERSONAL DATA
Personal data may be shared, only where necessary, with:
website hosting and technical-support providers;
booking and property-management providers, including Smoobu;
payment processors and financial institutions;
Booking.com, Airbnb, Vrbo and other booking platforms;
cleaning, maintenance, check-in and guest-support providers;
professional advisers, including accountants, lawyers and insurers;
fraud-prevention and security providers;
public authorities, law-enforcement bodies, courts and tax authorities;
tourism or guest-registration authorities; and
other service providers necessary to manage a booking.
Service providers acting on our behalf are required to process personal data only for authorised purposes and with appropriate confidentiality and security measures.
Booking platforms and certain payment providers may process personal data as independent controllers. Their processing is also governed by their own privacy policies.
SAN BENEDICTO INVERSIONES, S.L.U. does not sell personal data.
8. INTERNATIONAL DATA TRANSFERS
Some technology, booking, payment or communication providers may process personal data outside the European Economic Area.
Where an international transfer takes place, we will rely on an appropriate legal mechanism, such as:
a European Commission adequacy decision;
approved Standard Contractual Clauses;
another legally recognised safeguard; or
a specific legal exception where applicable.
Booking platforms acting as independent controllers are responsible for explaining any international transfers they make in their own privacy policies.
You may contact us for further information about the safeguards applicable to transfers made by SAN BENEDICTO INVERSIONES, S.L.U.
9. DATA RETENTION
Personal data will be kept only for as long as necessary for the purpose for which it was collected and for any additional period required to comply with legal obligations or establish, exercise or defend legal claims.
The following general criteria apply:
Enquiries that do not result in a booking may normally be retained for up to 12 months after the last communication.
Booking, contract, invoice and transaction records may generally be retained for six years or for any longer period required by tax, accounting or legal-claims legislation.
Guest-registration records are retained for the period required by Spanish public-security legislation, generally three years from the end of the accommodation service.
Security-deposit and damage documentation is retained until the matter has been resolved and for the applicable legal limitation period.
Marketing data is retained until consent is withdrawn or an objection is received.
Cookie information is retained for the periods described in the Cookie Policy.
Data necessary to demonstrate compliance with a request to exercise privacy rights may be retained for the applicable legal period.
When data is no longer required, it will be securely deleted, anonymised or blocked where Spanish law requires restricted retention.
10. CHILDREN’S DATA
Bookings must be made by a person who has the legal capacity and minimum age required by the Booking Terms and Conditions.
We do not knowingly offer online booking services directly to minors.
We may process information concerning children when they are included in a booking and the information is provided by a parent, guardian or responsible adult.
Such information is processed only when necessary to manage occupancy, provide requested services or comply with guest-registration and other legal obligations.
11. AUTOMATED DECISION-MAKING
SAN BENEDICTO INVERSIONES, S.L.U. does not normally make decisions producing legal or similarly significant effects based solely on automated processing.
Booking, payment or fraud-prevention providers may use automated security systems as described in their own privacy policies.
If SAN BENEDICTO INVERSIONES, S.L.U. introduces automated decision-making that produces legal or similarly significant effects, affected persons will receive the information and protections required by law.
12. DATA SECURITY
SAN BENEDICTO INVERSIONES, S.L.U. applies reasonable technical and organisational measures intended to protect personal data against:
unauthorised access;
unlawful use or disclosure;
accidental loss;
alteration;
destruction; and
other security risks.
Access to personal data is restricted to persons who require it for authorised business or legal purposes.
No internet transmission or electronic-storage system can be guaranteed to be completely secure. Users should also take reasonable precautions when communicating information and protecting their own devices and accounts.
13. DATA-PROTECTION RIGHTS
Subject to the conditions established by applicable law, you may exercise the following rights:
Access: to obtain confirmation of whether we process your personal data and receive a copy.
Rectification: to correct inaccurate or incomplete personal data.
Erasure: to request deletion where there is no lawful reason to continue processing.
Restriction: to request that processing be limited in certain circumstances.
Objection: to object to processing based on legitimate interests or to direct marketing.
Portability: to receive certain information in a structured, commonly used and machine-readable format or request its transfer to another controller.
Withdrawal of consent: to withdraw consent at any time where processing is based on consent.
Automated decisions: to request the protections available in relation to decisions based solely on automated processing.
These rights are not absolute and may be limited where continued processing is required by law or necessary for legal claims.
14. HOW TO EXERCISE YOUR RIGHTS
Requests may be sent to:
Email: sanbenedictoinversiones@gmail.com
Postal address:
SAN BENEDICTO INVERSIONES, S.L.U.
C/ Países Bajos, Complejo Ocean View, Local 1117-A/1
San Eugenio Alto, Adeje
38670 Santa Cruz de Tenerife
Spain
Please state which right you wish to exercise and provide sufficient information to identify the relevant data.
We may request reasonable proof of identity where necessary to prevent unauthorised disclosure.
Requests will be handled within the period established by applicable data-protection law.
15. RIGHT TO COMPLAIN
If you believe that your personal data has not been processed correctly, you may first contact us at sanbenedictoinversiones@gmail.com so that we can investigate the matter.
You also have the right to submit a complaint to the Spanish Data Protection Agency:
Agencia Española de Protección de Datos
C/ Jorge Juan, 6
28001 Madrid
Spain
Website: https://www.aepd.es
This does not affect your right to seek another administrative or judicial remedy.
16. THIRD-PARTY WEBSITES AND PLATFORMS
Our website may contain links to booking platforms, payment providers, maps, social networks or other external services.
These third parties operate independently and may collect personal data under their own privacy policies.
SAN BENEDICTO INVERSIONES, S.L.U. is not responsible for personal-data processing independently determined by those third parties.
We recommend reviewing the relevant privacy policy before submitting information or completing a transaction on an external website.
17. COOKIES
The website uses cookies and similar technologies.
Essential cookies may be used where necessary to operate the website or booking functions.
Analytical, advertising or other non-essential cookies will be used only in accordance with the consent choices made through the cookie-management system.
Further information is available in the Cookie Policy.
18. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy to reflect legal, technical or operational changes.
The latest version will always be published on this page with its revision date.
Where a change materially affects how existing personal data is processed, we will provide additional notice where required by law.
19. CONTACT
For any question concerning this Privacy Policy or the processing of personal data, please contact:
SAN BENEDICTO INVERSIONES, S.L.U.
Email: sanbenedictoinversiones@gmail.com
Telephone: +34 682 813 579
Address:
C/ Países Bajos, Complejo Ocean View, Local 1117-A/1
San Eugenio Alto, Adeje
38670 Santa Cruz de Tenerife
Spain

