EXTENDED INFORMATION
LAST MODIFICATION: 25-09-2026
The Privacy Policy forms part of the conditions that govern the websites www.monhotels.com, www.hotelpergolamallorca.com, www.esprincep.com and www.hotelmonport.com, together with the Cookies Policy and the Legal Notice.
MON HOTELS, comprised of the companies CAS MIOT, SL and ENIX, SL, reserves the right to modify or adapt this Privacy Policy when necessary, in particular to adapt it to regulatory changes, criteria of the supervisory authorities, modifications in the processing or changes in the services offered.
Personal data collected through websites, forms, reservations, email communications, telephone or other channels will be processed by the MON HOTELS company that manages the establishment, service or corresponding relationship, as indicated below:
CAS MIOT, SL – CIF B07790512
Address: Ctra. Manacor, 272, 07198 Palma (Balearic Islands).
Registration details: Commercial Registry of the Balearic Islands, Volume 1398, Folio 117, Sheet PM-24363, entry 1 of 01-10-1996.
Establishments managed: MON PORT HOTEL & SPA, Cala d'Egos, Finca La Noria, 07157 Port d'Andratx; and HOTEL ES PRINCEP, C/ Bala Roja, 1, 07001 Palma.
ENIX, SL – CIF B07018781
Address: Ctra. Manacor, 272, 07198 Palma (Balearic Islands).
Registration details: Commercial Registry of the Balearic Islands, Volume 106, Folio 1, Page 2306, entry 1 of 23-01-1968.
Establishment managed: APARTHOTEL LA PÉRGOLA, Avinguda s'Almudaina, 16 A, 07157 Port d'Andratx.
Common contact at MON HOTELS for the protection of personal data:
Telephone: 971 200 222
Data Protection Officer (DPO): lopd@monhotels.com
For any questions related to the processing of your personal data or the exercise of your rights, you can contact the relevant data controller or, directly, the Data Protection Officer at lopd@monhotels.com.
During browsing of web pages, certain technical data may be processed, such as:
The use of analytics, measurement, advertising, or similar technologies will depend on the specific configuration of each website and, where necessary, on the user's prior consent. Specific information regarding cookies, technologies used, providers, purposes, and expiration dates is detailed in the Cookie Policy.
When third-party services, such as maps, embedded content, booking engines, or equivalent functionalities, are used, data processing may occur by these providers in accordance with their configuration and applicable safeguards. When the service is not strictly necessary, its activation will be subject to consent where legally required.
Technical browsing data will only be processed for purposes related to the technology actually used, such as ensuring the operation and security of the website, obtaining usage statistics when there is a legal basis for doing so, or managing the user's privacy preferences.
To use certain features, you may need to provide personal data, for example, to make an inquiry, request information, complete or manage a booking, participate in a loyalty program, submit an application, or request a service. Required fields will be clearly marked and should be limited to the data necessary to process each request.
Mere browsing will not be associated with an identified person unless this is technically necessary, there is a valid legal basis, or the user has consented to the use of technologies that allow such linking.
The data provided will be incorporated into MON HOTELS' systems and will be kept for the time necessary to manage the relationship or request and, subsequently, for the legal periods of conservation, blocking and limitation of responsibilities that may be applicable.
The legal basis will depend on the specific purpose: execution of a contract or application of pre-contractual measures, compliance with legal obligations, legitimate interest where appropriate and, only when necessary, the consent of the interested party.
Commercial communications will be sent when there is a legal basis for doing so. When based on consent, this consent may be withdrawn at any time without affecting the lawfulness of the processing carried out beforehand.
The purposes may include, depending on the form or service used:
a) Manage inquiries, requests, reservations and requested services.
b) Keep you informed about the processing, status or incidents of your application or reservation.
c) Manage website functionalities, loyalty programs and services associated with the stay.
We may contact you by email, phone, messaging or other channels you have provided when necessary to manage your request, booking, stay or relationship with MON HOTELS.
When sending marketing communications requires consent, it will be requested through a separate, non-pre-selected option. You can withdraw your consent or unsubscribe at any time using the mechanisms available in each communication or by contacting MON HOTELS.
When any of the websites allows subscription to a newsletter or promotional communications, only the data necessary to manage the sending will be requested, usually the email address and, where appropriate, minimal identification data.
The data will be kept for as long as the subscription is maintained and until the interested party requests to unsubscribe or withdraws their consent, without prejudice to the blocking that may be necessary to address possible liabilities.
The legal basis will be the consent of the interested party, given through a specific affirmative action.
The data will be used to manage the subscription and send the requested communications.
Consent may be withdrawn at any time by using the unsubscribe link included in communications or by contacting MON HOTELS. Withdrawal of consent will not affect the lawfulness of processing carried out prior to withdrawal.
The legal basis will be the application of pre-contractual measures or the execution of a contractual relationship when the query refers to services, reservations or contracting; in other cases, the legitimate interest of MON HOTELS in attending to the communications that are addressed to it or, where appropriate, the consent of the interested party.
The Privacy Policy should not be structured as a contract that the user must "accept" in order to submit an inquiry. The form should include basic data protection information and a link to this Policy. Consent checkboxes should be reserved for optional purposes, such as sending marketing communications.
The legal basis will primarily be the execution of the contract or the application of pre-contractual measures, compliance with legal obligations and, for optional treatments that require it, consent.
In general, personal data will not be communicated to third parties, except where legally required (for example, to the Tax Agency, financial entities or Security Forces when required by applicable regulations).
For the proper provision of services, technology, reservation, payment, communications, hosting, support, maintenance, or other auxiliary service providers may be involved. When processing data on behalf of MON HOTELS, they will act as data processors in accordance with Article 28 of the GDPR; when they determine their own purposes and means, they will act, where applicable, as independent controllers.
MON HOTELS will formalize, where appropriate, the data processing agreements and will apply the guarantees required by the GDPR and the LOPDGDD.
The legal bases that legitimize the processing are:
In general, your personal data will not be shared with third parties, except:
The legal basis will be the performance of the contractual relationship or the application of pre-contractual measures. For tax, accounting, or administrative obligations, compliance with legal obligations will also apply.
The legal bases that legitimize the processing are:
The legal basis will depend on the interaction carried out: the user's consent or initiative when contacting or following profiles, the execution of a contractual relationship where applicable and MON HOTELS' legitimate interest in managing its presence and community on social networks, without prejudice to the conditions and policies of each platform.
MON HOTELS and its establishments' profiles may be present on social networks such as Instagram or Facebook.
Additionally, some establishments may offer messaging channels such as WhatsApp.
The processing carried out directly by each platform will be governed by its own terms and privacy policies.
The data will be processed while the interaction or connection with the MON HOTELS profile is maintained and, subsequently, for the time necessary to address any potential liabilities. Actions that depend exclusively on the platform must be managed through the user's own settings.
Any corrections to your data or restrictions on information or publications must be made through your profile or user settings on the social network itself.
The legal basis is the legitimate interest of the data controller in preserving the security of persons, property and facilities (Art. 6.1.f GDPR), in conjunction with Article 22 of the LOPDGDD. In the workplace, the legal powers of employer control and Article 89 of the LOPDGDD will also apply.
The legal basis will be the application of pre-contractual measures at the candidate's request (Art. 6.1.b GDPR) to manage the selection process. When it is requested that the candidacy be retained for future processes unrelated to the initial process, consent will be requested where necessary.
As a general rule, the curriculum vitae will be kept during the selection process and, when it has been reported that it has been added to a pool of candidates, for a maximum period of one year, unless the candidacy is updated or another duly justified period is applicable.
The legal bases that allow the processing are:
As a general rule, we will process the data provided by its owners. However, for reservations, stays, or other services, it may be necessary for a person to provide data about companions or other third parties. In these cases, you should only provide the necessary data and, where appropriate, inform these individuals about the processing or ensure that there is a valid legal basis for its disclosure.
MON HOTELS may process data of minors when necessary to manage a reservation or stay, provide services aimed at families, implement security measures, or comply with legal obligations. Specifically, accommodation regulations require the registration of certain data of minors. This data will be provided, as applicable, by their parents, legal guardians, or accompanying adult in the legally permitted cases. Website functionalities requiring direct consent are not directed at children under 14 years of age without the involvement of their legal guardians.
MON HOTELS will apply the appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR and the LOPDGDD, taking into account the nature of the data, the context and purposes of the processing, the state of the art and the risks to the rights and freedoms of individuals.
Applicable measures, depending on each system and treatment, may include access controls, credential management, encryption or protection of communications, backups, security event logging, system updates, confidentiality agreements, incident management procedures, and periodic reviews.
The measures will be reviewed and adapted when risks, systems used, or treatment characteristics change.
MON HOTELS does not intend to make decisions based solely on automated processing that produces legal effects concerning the user or similarly significantly affects them. Should such processing be implemented, the information required by the GDPR will be provided beforehand.
Commercial segmentation or personalization based on information obtained from the relationship with MON HOTELS may be carried out when there is a valid legal basis. These actions will not, in general, involve exclusively automated decisions with legal or similar effects. When a specific profiling activity requires consent or additional information, this will be obtained or provided beforehand.
Data may be disclosed to third parties when there is a legal obligation to do so or when it is necessary to fulfill the relationship or provide the requested service, for example, to public authorities, law enforcement agencies, financial institutions, payment providers, and courts. Providers accessing data on behalf of MON HOTELS will act as data processors where applicable.
In payments, reservations or services managed through external platforms or providers, data may be processed within the environment of said providers to the extent necessary to execute the transaction or provide the service.
When you have authorized the use of your image, name or other data for promotional or communication purposes, they may be published on MON HOTELS channels within the scope of the consent given.
In general, MON HOTELS ensures that personal data is stored and processed within the European Economic Area (EEA). However, certain technology providers or services used may involve international access to or transfers of data.
When an international transfer takes place, one of the mechanisms provided for in Chapter V of the GDPR will apply, as appropriate:
Specific information on transfers associated with cookies or tracking technologies will be provided, where appropriate, in the Cookie Policy and in the information of the relevant provider.
When an interested party requests additional information on the safeguards applied to an international transfer that affects their data, they may contact the Data Protection Officer.
If you change any information, please let us know so we can keep it up to date.
You have the right to file a complaint with the Spanish Data Protection Agency if you believe that your request for your rights has not been properly addressed.
The general time limit for responding is one month from receipt of the request, without prejudice to the possible extension of up to two additional months in the cases provided for by the GDPR, taking into account the complexity and number of requests.
You have the right to withdraw your consent at any time for any of the treatments for which you have given it.
Information about cookies and similar technologies, including their purposes, providers, duration, and consent management mechanisms, can be found in each website's Cookie Policy. Non-essential technologies will remain blocked until consent is obtained where required.
| Data relating to | Document / treatment | Conservation |
|---|---|---|
| Customers, guests and suppliers | Contracts, reservations, communications and documentation related to the provision of services. | During the relationship and after its termination, the documents are blocked for the duration of the statute of limitations for any potential liabilities. Commercial documentation will generally be kept for 6 years in accordance with Article 30 of the Commercial Code, where applicable. |
| Tax / Accounting | Invoices, receipts, books and documentation with tax implications. | Generally, 4 years for tax purposes, without prejudice to other specific periods; commercial documentation must be kept for a minimum period of 6 years when applicable. |
| Guests | Documentary record of travelers and data required by accommodation regulations. | 3 years from the completion of the contracted service or benefit, in accordance with Article 5 of Royal Decree 933/2021. |
| MonAmics Program | Registration details, account, benefits, linked reservations and loyalty program management. | While the status of member is maintained and, after leaving the membership, for the periods necessary to meet obligations and responsibilities arising from the relationship. |
| Marketing and newsletter | Contact details, preferences and proof of consent where required. | Until consent is withdrawn, objected to, or unsubscribed. Subsequently, the necessary information may be kept blocked for the applicable statutory limitation periods to demonstrate compliance. |
| Job seekers | Curriculum vitae, application details and documentation of the selection process. | During the selection process and, if you have been informed of your inclusion in a pool of candidates, up to 1 year, unless the candidacy is updated or there is another valid legal basis. |
| Human Resources | Employment file, contracts, payroll, Social Security, incidents and associated documentation. | During the employment relationship and subsequently for the applicable legal retention and statute of limitations periods. Documentation related to labor and Social Security obligations will generally be kept for the periods required by their specific regulations. |
| Human Resources | Work schedule record. | 4 years, in accordance with art. 34.9 of the Workers' Statute. |
| Occupational risk prevention | Documentation and records proving compliance with preventive obligations. | During the periods established by the regulations on risk prevention and the statute of limitations for liability; the specific period corresponding to each document will apply. |
| Video surveillance | Images captured by video surveillance systems. | Maximum of 1 month from the date of collection, unless they must be kept to prove facts against persons, property or facilities or made available to competent authorities, in accordance with art. 22 LOPDGDD. |
| Access control | Access logs to facilities, where they exist. | For as long as strictly necessary for the security purpose and subsequently for the applicable blocking or limitation periods when there is an incident or outstanding liability. |
| Spa / Wellness | Data provided to manage treatments, reservations or assess contraindications, when collected. | For the time necessary to provide the service and subsequently for the limitation periods for any potential liabilities. Health data, if processed, will be limited to what is strictly necessary and will have the enhanced safeguards of Article 9 GDPR. |
| Data protection rights | Requests to exercise rights and supporting documentation of their attention. | During the time necessary to process the request and, subsequently, blocked during the limitation periods for liabilities in matters of data protection. |
| Data protection | Commissioning contracts, analyses, evaluations, records and evidence of compliance. | While the documented treatment, relationship or measure is in effect and subsequently during the applicable limitation periods of liability. |
| Information security | Logs, access records, and security evidence. | During the period defined according to the security purpose, the risk and the applicable regulations, avoiding indiscriminate or longer than necessary storage. |
| Corporate | Deeds, statutes, corporate books, minutes and structural documentation of companies. | During the life of the company and, according to the document, at least during the applicable commercial and statute of limitations periods. |
| Legal | Contracts, agreements, claims, files and documentation necessary for the exercise or defense of rights. | While the relationship or file is maintained and subsequently during the limitation periods of the corresponding actions. |