1. Controller
The controller responsible for data processing on this website is:
MONTE MARINA PLAYA S.L.
VAT ID (CIF): B35480961
Calle Volcán de Vayuyo N.º 8
35626 Esquinzo, Fuerteventura, Spain
Represented by: Mr Philipp Duffner
Phone: +34 928 544 052
Email: info@montemarinaplaya.com
2. General information on data processing
We generally process personal data of our users only to the extent necessary to provide a functional website as well as our content and services. Processing regularly takes place only with the user’s consent or where a statutory permission applies. In doing so, we observe in particular the principles of lawfulness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, as well as integrity and confidentiality.
3. Legal bases
We process personal data on the basis of the following legal grounds:
- Art. 6(1)(a) GDPR – consent of the data subject;
- Art. 6(1)(b) GDPR – performance of a contract or pre-contractual measures;
- Art. 6(1)(c) GDPR – compliance with a legal obligation;
- Art. 6(1)(f) GDPR – safeguarding legitimate interests.
4. Hosting and server log files
This website is operated by an external service provider (host). The personal data collected on this website is stored on the host’s servers. When you access the website, the host automatically collects information transmitted by your browser in so-called server log files:
- anonymised/shortened IP address,
- date and time of access,
- page/file accessed and volume of data transferred,
- browser type and version,
- operating system used,
- referrer URL.
This data is not merged with other data sources. Processing takes place on the basis of Art. 6(1)(f) GDPR; our legitimate interest lies in the technically error-free presentation and the security of our website. A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with the host.
5. SSL/TLS encryption
For security reasons, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the “https://” in your browser’s address bar and by the lock symbol. This prevents the data you transmit to us from being read by third parties.
6. Cookies and consent management (Complianz)
Our website uses cookies and comparable technologies. Cookies are small text files stored on your device. Technically necessary cookies are set on the basis of Art. 6(1)(f) GDPR to ensure technically error-free operation.
For all non-necessary cookies and services, we obtain your consent via a consent management tool (Complianz). Corresponding cookies are only set, or external services only loaded, after your active consent. Your consent is voluntary and can be revoked at any time with effect for the future via the cookie settings on our website. The legal basis is Art. 6(1)(a) GDPR in conjunction with the applicable e-privacy legislation.
7. Contact and enquiry form
If you contact us via the enquiry/contact form or by email, we process the data you provide (e.g. name, address, email address, telephone number, desired period, room preference and your message) in order to handle your enquiry.
- Purpose: handling and answering your enquiry and, where applicable, preparing a non-binding booking offer.
- Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(a) GDPR (consent).
- Recipients: no disclosure to third parties unless there is a legal obligation. No transfer to countries outside the EU.
- Storage period: your data is deleted as soon as it is no longer required to achieve the purpose, or at your request, subject to statutory retention periods.
8. Bookings and customer management
When you make a booking or use our accommodation and restaurant services, we process your data for contract performance, booking and reservation management, invoicing and accounting.
- Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (legal obligations, in particular tax law).
- Recipients: where applicable, the competent public authority within the scope of legal obligations. No transfer to countries outside the EU.
- Storage period: for the duration of the contractual relationship and in accordance with statutory tax and commercial retention periods.
Without providing the required data, the agreed service cannot be delivered. No automated individual decision-making (profiling) takes place.
9. Spam protection with hCaptcha
To protect our forms against abusive entries and spam, we use the hCaptcha service. The provider is Intuition Machines, Inc., 350 Alabama St, San Francisco, CA 94110, USA.
hCaptcha checks whether an entry is made by a human or in an automated manner (by a program). For this purpose, hCaptcha analyses various information, in particular the IP address, information about your device and browser, and your interaction behaviour. This data is transmitted to hCaptcha and processed there.
- Legal basis: your consent (Art. 6(1)(a) GDPR) and our legitimate interest in protection against spam and abuse (Art. 6(1)(f) GDPR).
- Third-country transfer: processing may involve a transfer to the USA, based on the Standard Contractual Clauses of the EU Commission.
Further information can be found in hCaptcha’s privacy policy: https://www.hcaptcha.com/privacy.
10. Web analytics with Burst Statistics
To statistically evaluate visits to our website, we use the privacy-friendly analytics tool Burst Statistics. Burst Statistics runs on our own server; no data is transferred to third parties. The evaluation is largely anonymised (e.g. shortened IP addresses); no profiles going beyond this website are created.
Insofar as cookies are set for this purpose, this is done exclusively on the basis of your consent (Art. 6(1)(a) GDPR). In anonymous mode, the legal basis is our legitimate interest in the needs-based design of our website (Art. 6(1)(f) GDPR).
11. Fonts (locally hosted)
This website uses fonts that are hosted locally on our server. When you access a page, no connection to third-party servers (e.g. Google Fonts) is established, and no related data is transmitted to third parties.
12. Booking of transfers and excursions (Triggle)
For booking transfers and excursions, we use the external booking service Triggle (triggle.app). When you make such a booking, you are redirected to Triggle’s booking system or it is embedded. The data you provide as part of the booking (e.g. name, contact details, booking details) is transmitted to Triggle and processed there to handle your booking.
- Purpose: handling and management of transfer and excursion bookings.
- Legal basis: Art. 6(1)(b) GDPR (performance of a contract) or Art. 6(1)(a) GDPR (consent, insofar as the service is only loaded after consent).
- Recipients: Triggle as the provider of the booking system.
The respective provider is jointly responsible for data processing within the booking system. Please note Triggle’s privacy information at https://triggle.app.
13. External links (HolidayCheck)
Our website contains a link to our review profile on HolidayCheck. Simply viewing our page does not transfer any data to HolidayCheck. Only when you actively click the link are you redirected to the HolidayCheck website, for whose data processing the respective provider is responsible.
14. Personal data of minors
Persons under the age of 16 should not transmit any personal data to us without the consent of their legal guardians. We do not request personal data from children and adolescents and do not knowingly collect such data.
15. Your rights
As a data subject, you have the following rights:
- access (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection to processing (Art. 21 GDPR),
- revocation of consent given, with effect for the future (Art. 7(3) GDPR).
To exercise your rights, please contact: MONTE MARINA PLAYA S.L., Calle Volcán de Vayuyo N.º 8, 35626 Esquinzo, or by email at info@montemarinaplaya.com.
16. Right to lodge a complaint with the supervisory authority
Without prejudice to any other remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence or the place of the alleged infringement. The authority competent for the controller is the Spanish data protection authority (Agencia Española de Protección de Datos, AEPD, www.aepd.es).
17. Validity and amendment of this privacy policy
This privacy policy is currently valid (as of: July 2026). As our website develops further, or due to changed legal or regulatory requirements, it may become necessary to amend this privacy policy.