Privacy Policy
Last Updated: -
1. Data Controller
This website is operated by:
Sera Villas [Legal Entity Name, if applicable] Registered address: [Address, Spain] Email: [Contact Email]
Sera Villas acts as the data controller and processes personal data in accordance with GDPR and Spanish data protection laws.
2. What Data We Collect
We may collect the following personal data:
- Full name
- Email address
- Phone number
- Booking details (stay dates, number of guests, preferences)
- Payment information (processed securely via third-party providers)
- Identification data if required by Spanish regulations (e.g. passport or ID details for guest registration)
- Technical data (IP address, browser type, device, usage data)
We only collect data necessary to provide our services.
3. How We Use Your Data
Your data is used for:
- Managing booking requests and reservations
- Communicating with you before and during your stay
- Sending booking confirmations and updates
- Complying with legal obligations in Spain (guest registration requirements)
- Improving website performance and user experience
We do not sell or rent your personal data.
4. Legal Basis for Processing
We process your personal data based on:
- Contractual necessity – to complete and manage bookings
- Legal obligation – compliance with Spanish laws (e.g. guest registration)
- Legitimate interest – improving our services and website
- Consent – for analytics cookies and optional communications
5. Data Sharing
We may share your data with trusted third parties necessary for service delivery:
- Payment provider: Stripe
- Property management system: Uplisting
- Analytics provider: Google Analytics
- Embedded content services: Elfsight (used to display external content such as reviews or feeds)
- Hosting and IT service providers
- Public authorities where required by law
These providers process data under GDPR-compliant agreements.
6. International Data Transfers
Some providers listed above may process data outside the European Economic Area (EEA).
Where this occurs, appropriate safeguards are applied, such as Standard Contractual Clauses approved by the European Commission.
7. Data Retention
We retain personal data only as long as necessary:
- Booking data: up to 5 years (legal and tax obligations)
- Inquiry data: up to 12 months
- Analytics data: according to configured retention settings
After this period, data is securely deleted or anonymized.
8. Your Rights
Under GDPR, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your data
- Restrict or object to processing
- Request data portability
To exercise your rights, contact: [email]
You also have the right to file a complaint with the Spanish authority Agencia Española de Protección de Datos.
9. Cookies and Tracking
We use cookies and similar technologies to improve your experience.
This includes:
- Google Analytics for website usage analysis
- Third-party widgets via Elfsight which may load content from external services
Cookies are only activated after your consent, except those strictly necessary for website functionality.
You can manage or withdraw your consent at any time via the cookie banner.
10. Data Security
We implement appropriate security measures, including:
- Encrypted HTTPS connections
- Secure hosting environment
- Restricted access to personal data
Despite these measures, no system can be completely secure.
11. Third-Party Content
Some parts of the website display embedded content (such as reviews or social feeds) via Elfsight.
When interacting with such content, data may be collected directly by the third-party platform providing the content.
We recommend reviewing their respective privacy policies.
12. Changes to This Policy
We may update this Privacy Policy from time to time.The latest version will always be available on this page.
13. Contact
For any questions about this Privacy Policy:
Email: [Insert Email]Address: [Insert Address]