Express Buchung
Thermal Bad und Aromatherapie

Privacy Policy

EXTENDED INFORMATION

LAST MODIFICATION: 25-09-2026

The Privacy Policy forms part of the conditions that govern the websites www.monhotels.com, www.hotelpergolamallorca.com, www.esprincep.com and www.hotelmonport.com, together with the Cookies Policy and the Legal Notice.

MON HOTELS, comprised of the companies CAS MIOT, SL and ENIX, SL, reserves the right to modify or adapt this Privacy Policy when necessary, in particular to adapt it to regulatory changes, criteria of the supervisory authorities, modifications in the processing or changes in the services offered.

Who is responsible for processing your data?

Personal data collected through websites, forms, reservations, email communications, telephone or other channels will be processed by the MON HOTELS company that manages the establishment, service or corresponding relationship, as indicated below:

CAS MIOT, SL – CIF B07790512

Address: Ctra. Manacor, 272, 07198 Palma (Balearic Islands).

Registration details: Commercial Registry of the Balearic Islands, Volume 1398, Folio 117, Sheet PM-24363, entry 1 of 01-10-1996.

Establishments managed: MON PORT HOTEL & SPA, Cala d'Egos, Finca La Noria, 07157 Port d'Andratx; and HOTEL ES PRINCEP, C/ Bala Roja, 1, 07001 Palma.

ENIX, SL – CIF B07018781

Address: Ctra. Manacor, 272, 07198 Palma (Balearic Islands).

Registration details: Commercial Registry of the Balearic Islands, Volume 106, Folio 1, Page 2306, entry 1 of 23-01-1968.

Establishment managed: APARTHOTEL LA PÉRGOLA, Avinguda s'Almudaina, 16 A, 07157 Port d'Andratx.

Common contact at MON HOTELS for the protection of personal data:

Telephone: 971 200 222

Data Protection Officer (DPO): lopd@monhotels.com

For any questions related to the processing of your personal data or the exercise of your rights, you can contact the relevant data controller or, directly, the Data Protection Officer at lopd@monhotels.com.

What data do we collect through the website?

During browsing of web pages, certain technical data may be processed, such as:

  • IP address.
  • Browser type and version.
  • Operating system and device.
  • Data relating to navigation and interaction with the website.

The use of analytics, measurement, advertising, or similar technologies will depend on the specific configuration of each website and, where necessary, on the user's prior consent. Specific information regarding cookies, technologies used, providers, purposes, and expiration dates is detailed in the Cookie Policy.

When third-party services, such as maps, embedded content, booking engines, or equivalent functionalities, are used, data processing may occur by these providers in accordance with their configuration and applicable safeguards. When the service is not strictly necessary, its activation will be subject to consent where legally required.

Technical browsing data will only be processed for purposes related to the technology actually used, such as ensuring the operation and security of the website, obtaining usage statistics when there is a legal basis for doing so, or managing the user's privacy preferences.

User registration / Form submission / Reservations

To use certain features, you may need to provide personal data, for example, to make an inquiry, request information, complete or manage a booking, participate in a loyalty program, submit an application, or request a service. Required fields will be clearly marked and should be limited to the data necessary to process each request.

Mere browsing will not be associated with an identified person unless this is technically necessary, there is a valid legal basis, or the user has consented to the use of technologies that allow such linking.

The data provided will be incorporated into MON HOTELS' systems and will be kept for the time necessary to manage the relationship or request and, subsequently, for the legal periods of conservation, blocking and limitation of responsibilities that may be applicable.

The legal basis will depend on the specific purpose: execution of a contract or application of pre-contractual measures, compliance with legal obligations, legitimate interest where appropriate and, only when necessary, the consent of the interested party.

Commercial communications will be sent when there is a legal basis for doing so. When based on consent, this consent may be withdrawn at any time without affecting the lawfulness of the processing carried out beforehand.

The purposes may include, depending on the form or service used:

a) Manage inquiries, requests, reservations and requested services.

b) Keep you informed about the processing, status or incidents of your application or reservation.

c) Manage website functionalities, loyalty programs and services associated with the stay.

We may contact you by email, phone, messaging or other channels you have provided when necessary to manage your request, booking, stay or relationship with MON HOTELS.

When sending marketing communications requires consent, it will be requested through a separate, non-pre-selected option. You can withdraw your consent or unsubscribe at any time using the mechanisms available in each communication or by contacting MON HOTELS.

Newsletter submission

When any of the websites allows subscription to a newsletter or promotional communications, only the data necessary to manage the sending will be requested, usually the email address and, where appropriate, minimal identification data.

The data will be kept for as long as the subscription is maintained and until the interested party requests to unsubscribe or withdraws their consent, without prejudice to the blocking that may be necessary to address possible liabilities.

The legal basis will be the consent of the interested party, given through a specific affirmative action.

The data will be used to manage the subscription and send the requested communications.

Consent may be withdrawn at any time by using the unsubscribe link included in communications or by contacting MON HOTELS. Withdrawal of consent will not affect the lawfulness of processing carried out prior to withdrawal.


If you belong to any of the following groups, please consult the dropdown information:

WEB OR EMAIL CONTACTS

For what purposes will we process your personal data?

  • To answer your questions, requests, or petitions.
  • Manage the requested service, answer your request, or process your petition.
  • Information via electronic means, regarding your request.
  • Commercial or event information by electronic means, provided there is express authorization.

What is the legal basis for processing your data?

The legal basis will be the application of pre-contractual measures or the execution of a contractual relationship when the query refers to services, reservations or contracting; in other cases, the legitimate interest of MON HOTELS in attending to the communications that are addressed to it or, where appropriate, the consent of the interested party.

The Privacy Policy should not be structured as a contract that the user must "accept" in order to submit an inquiry. The form should include basic data protection information and a link to this Policy. Consent checkboxes should be reserved for optional purposes, such as sending marketing communications.

CLIENTS

For what purposes will we process your personal data?

  • Budget preparation and monitoring through communication between both parties.
  • Information via electronic means, regarding your request.
  • Commercial or event information by electronic means, provided there is express authorization.
  • Manage the administrative, communications and logistics services performed by the Manager.
  • Carry out the corresponding transactions.
  • Billing and filing of appropriate taxes.
  • Control and recovery management.

What is the legal basis for processing your data?

The legal basis will primarily be the execution of the contract or the application of pre-contractual measures, compliance with legal obligations and, for optional treatments that require it, consent.

Recipients and suppliers

In general, personal data will not be communicated to third parties, except where legally required (for example, to the Tax Agency, financial entities or Security Forces when required by applicable regulations).

For the proper provision of services, technology, reservation, payment, communications, hosting, support, maintenance, or other auxiliary service providers may be involved. When processing data on behalf of MON HOTELS, they will act as data processors in accordance with Article 28 of the GDPR; when they determine their own purposes and means, they will act, where applicable, as independent controllers.

  • Web analytics or measurement services that are not strictly necessary will only be activated when there is a valid legal basis and, where appropriate, the user's consent, in accordance with the Cookie Policy.
  • Certain establishments may offer messaging channels, including WhatsApp, for communication with customers and users. The use of these services will be subject to the implemented configuration and the terms and policies of the corresponding provider.

MON HOTELS will formalize, where appropriate, the data processing agreements and will apply the guarantees required by the GDPR and the LOPDGDD.

GUESTS

For what purposes will we process your personal data?

  • Manage your booking, including pre-booking, confirmation, modification or cancellation.
  • To provide accommodation services and associated services (check-in, stay, complementary services, guest services, etc.).
  • Necessary communications during your stay, including those related to your booking, special requests or incidents.
  • Compliance with the legal obligations of documentary registration and communication of traveler data, in particular those provided for in Royal Decree 933/2021 and other applicable regulations.
  • Administrative, accounting and tax management, including invoicing and tax filing.
  • Perform the collections and transactions corresponding to the contracted services.
  • Customer satisfaction surveys and service quality monitoring.
  • Sending commercial or promotional information, provided there is express authorization from you.
  • Internal control, auditing, fraud prevention and debt collection procedures, where applicable.

What is the legal basis for processing your data?

The legal bases that legitimize the processing are:

  • The execution of a contract, to manage the reservation, the stay and the associated services.
  • Compliance with legal obligations, especially those arising from traveler registration, tax and accounting regulations.
  • Your consent, only when necessary for commercial communications, optional services or treatments that cannot be covered by another legal basis.

Recipients and suppliers

In general, your personal data will not be shared with third parties, except:

  • Legal obligation, for example: Security Forces and Corps, when appropriate in compliance with the obligations of registration and communication of travelers; Tax Agency; financial entities and payment providers; courts, tribunals and other competent authorities when there is a legal obligation or valid requirement.

SUPPLIERS

For what purposes will we process your personal data?

  • Information via electronic means, regarding your request.
  • Commercial or event information by electronic means, provided there is express authorization.
  • Manage the administrative, communications and logistics services performed by the Manager.
  • Billing.
  • Carry out the corresponding transactions.
  • Billing and filing of appropriate taxes.
  • Control and recovery management.

What is the legal basis for processing your data?

The legal basis will be the performance of the contractual relationship or the application of pre-contractual measures. For tax, accounting, or administrative obligations, compliance with legal obligations will also apply.

MONAMICS LOYALTY PROGRAM USERS

For what purposes will we process your personal data?

  • Manage your registration and participation in the MonAmics program, including the creation and maintenance of your profile or account when necessary.
  • Apply the advantages, discounts, preferential rates and other benefits associated with the program.
  • Manage the benefits generated or applicable to your bookings and stays, in accordance with the program conditions.
  • To send operational communications related to your membership status, benefits, changes in conditions or associated services.
  • Send personalized commercial communications, promotions or exclusive offers when there is a legal basis to do so and, where required, with your consent.
  • To analyze the use of the program and the preferences derived from the relationship with MON HOTELS for management, improvement and personalization purposes, within the limits of applicable regulations.
  • Prevent fraudulent use, ensure program security, and perform internal controls when necessary.

What is the legal basis for processing your data?

The legal bases that legitimize the processing are:

  • The execution of the relationship derived from joining the program and its conditions, to manage participation, apply benefits and maintain the account.
  • Consent, when necessary for commercial communications or optional treatments.
  • MON HOTELS' legitimate interest in preventing fraud, protecting the program, and carrying out proportionate internal controls, where applicable.

SOCIAL MEDIA CONTACTS

For what purposes will we process your personal data?

  • To answer your questions, requests, or petitions.
  • Manage the requested service, answer your request, or process your petition.
  • Connecting with you and building a community of followers.

What is the legal basis for processing your data?

The legal basis will depend on the interaction carried out: the user's consent or initiative when contacting or following profiles, the execution of a contractual relationship where applicable and MON HOTELS' legitimate interest in managing its presence and community on social networks, without prejudice to the conditions and policies of each platform.

MON HOTELS and its establishments' profiles may be present on social networks such as Instagram or Facebook.

Additionally, some establishments may offer messaging channels such as WhatsApp.

The processing carried out directly by each platform will be governed by its own terms and privacy policies.

How long will we keep personal data?

The data will be processed while the interaction or connection with the MON HOTELS profile is maintained and, subsequently, for the time necessary to address any potential liabilities. Actions that depend exclusively on the platform must be managed through the user's own settings.

Any corrections to your data or restrictions on information or publications must be made through your profile or user settings on the social network itself.

VIDEO SURVEILLANCE

For what purposes will we process your personal data?

  • Ensuring the safety of people, property and facilities through video surveillance systems.
  • When cameras can be used for workplace monitoring, the purpose and processing will comply with labor regulations and Article 89 of the LOPDGDD, with the prior information required of workers.
  • The images may be communicated to Security Forces, courts, tribunals or other authorities when necessary to investigate facts or to exercise or defend claims.

What is the legal basis for processing your data?

The legal basis is the legitimate interest of the data controller in preserving the security of persons, property and facilities (Art. 6.1.f GDPR), in conjunction with Article 22 of the LOPDGDD. In the workplace, the legal powers of employer control and Article 89 of the LOPDGDD will also apply.

JOB SEEKERS

For what purposes will we process your personal data?

  • Organization of selection processes for hiring employees.
  • To schedule job interviews and evaluate your application.
  • Data may be retained for future processes only when there is a valid legal basis and the candidate has been previously informed.

What is the legal basis for processing your data?

The legal basis will be the application of pre-contractual measures at the candidate's request (Art. 6.1.b GDPR) to manage the selection process. When it is requested that the candidacy be retained for future processes unrelated to the initial process, consent will be requested where necessary.

How long will we keep personal data?

As a general rule, the curriculum vitae will be kept during the selection process and, when it has been reported that it has been added to a pool of candidates, for a maximum period of one year, unless the candidacy is updated or another duly justified period is applicable.

HR

For what purposes will we process your personal data?

  • Manage the employment relationship, including the creation and maintenance of your employee file.
  • Carry out all the necessary administrative, tax, accounting and Social Security procedures to comply with our obligations as an employer, in accordance with labor, occupational risk prevention, tax and accounting regulations.
  • Manage payroll and other compensation payments through the corresponding financial institution.
  • Manage time tracking, using timekeeping systems such as cards, personal codes, employee platforms or portals, or any other system enabled by the company.
  • Manage group insurance, social benefits or pension plans in which the workforce may be included.
  • Manage staff training, both subsidized and non-subsidized training, as well as mandatory actions in the area of occupational risk prevention.
  • Manage incidents, permits, absences, sanctions and any action derived from the employment relationship.
  • Ensure compliance with internal regulations, internal audit controls and fraud prevention measures, to the extent permitted by law.

What is the legal basis for processing your data?

The legal bases that allow the processing are:

  • The execution of the employment contract and the application of pre-contractual measures (art. 6.1.b) GDPR).
  • Compliance with legal obligations applicable to the employer in matters of labor, Social Security, prevention of occupational risks, taxation and accounting (art. 6.1.c) GDPR).
  • The worker's consent is only required for those treatments that are not covered by the employment relationship or a legal obligation (for example, certain voluntary benefits or optional training actions).
  • The legitimate interest of the employer, in cases such as internal controls, audits or fraud prevention, always within the limits of art. 6.1.f) GDPR.

Do we include personal data of third parties?

As a general rule, we will process the data provided by its owners. However, for reservations, stays, or other services, it may be necessary for a person to provide data about companions or other third parties. In these cases, you should only provide the necessary data and, where appropriate, inform these individuals about the processing or ensure that there is a valid legal basis for its disclosure.

And what about data on minors?

MON HOTELS may process data of minors when necessary to manage a reservation or stay, provide services aimed at families, implement security measures, or comply with legal obligations. Specifically, accommodation regulations require the registration of certain data of minors. This data will be provided, as applicable, by their parents, legal guardians, or accompanying adult in the legally permitted cases. Website functionalities requiring direct consent are not directed at children under 14 years of age without the involvement of their legal guardians.

Will we be communicating electronically?

  • They will only be used to process your request, if it is one of the contact methods you have provided to us.
  • Commercial communications will be sent when there is a legal basis for them and, where necessary, with prior consent. All electronic communications will include a simple mechanism for opting out or unsubscribing.

What security measures do we apply?

MON HOTELS will apply the appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR and the LOPDGDD, taking into account the nature of the data, the context and purposes of the processing, the state of the art and the risks to the rights and freedoms of individuals.

Applicable measures, depending on each system and treatment, may include access controls, credential management, encryption or protection of communications, backups, security event logging, system updates, confidentiality agreements, incident management procedures, and periodic reviews.

The measures will be reviewed and adapted when risks, systems used, or treatment characteristics change.

To what extent will decision-making be automated?

MON HOTELS does not intend to make decisions based solely on automated processing that produces legal effects concerning the user or similarly significantly affects them. Should such processing be implemented, the information required by the GDPR will be provided beforehand.

Will profiling take place?

Commercial segmentation or personalization based on information obtained from the relationship with MON HOTELS may be carried out when there is a valid legal basis. These actions will not, in general, involve exclusively automated decisions with legal or similar effects. When a specific profiling activity requires consent or additional information, this will be obtained or provided beforehand.

To whom will your data be communicated?

Data may be disclosed to third parties when there is a legal obligation to do so or when it is necessary to fulfill the relationship or provide the requested service, for example, to public authorities, law enforcement agencies, financial institutions, payment providers, and courts. Providers accessing data on behalf of MON HOTELS will act as data processors where applicable.

In payments, reservations or services managed through external platforms or providers, data may be processed within the environment of said providers to the extent necessary to execute the transaction or provide the service.

When you have authorized the use of your image, name or other data for promotional or communication purposes, they may be published on MON HOTELS channels within the scope of the consent given.

International transfers.

In general, MON HOTELS ensures that personal data is stored and processed within the European Economic Area (EEA). However, certain technology providers or services used may involve international access to or transfers of data.

When an international transfer takes place, one of the mechanisms provided for in Chapter V of the GDPR will apply, as appropriate:

  • Adequacy decision of the European Commission, including the EU-US Data Privacy Framework when the recipient is validly adhering to it and the transfer is covered by that decision.
  • Standard Contractual Clauses approved by the European Commission or other appropriate safeguards, supplemented where necessary by additional assessments and measures.

Specific information on transfers associated with cookies or tracking technologies will be provided, where appropriate, in the Cookie Policy and in the information of the relevant provider.

When an interested party requests additional information on the safeguards applied to an international transfer that affects their data, they may contact the Data Protection Officer.

What rights do you have?

  • To find out whether we are processing your data or not.
  • To access your personal data.
  • To request the correction of your data if it is inaccurate.
  • To request the deletion of your data if it is no longer necessary for the purposes for which it was collected or if you withdraw the consent you have given us.
  • You may request the limitation of the processing of your data in some cases, in which case we will only keep them in accordance with current regulations.
  • You have the right to data portability, meaning your data will be provided to you in a structured, commonly used, and machine-readable format. If you prefer, we can send it to the new data controller you designate. This right is only valid in certain circumstances.
  • To file a complaint with the Spanish Data Protection Agency if you believe we have not treated you correctly.
  • To revoke consent for any treatment for which you have consented, at any time.

If you change any information, please let us know so we can keep it up to date.

Do you want a form for exercising your rights?

  • We have forms for exercising your rights; request them by email, or if you prefer, you can use those prepared by the Spanish Data Protection Agency or third parties.
  • It is not generally necessary to provide a copy of your ID to exercise your rights. If there are reasonable doubts about the identity of the applicant, MON HOTELS may request the additional information strictly necessary to confirm it.
  • If you are acting through a representative, proof of representation must be provided by a legally valid means. When it becomes necessary to confirm the identity of either party, only the information provided for that purpose will be requested.
  • Applications may be submitted through the contact methods indicated at the beginning of this Policy, including the DPO email address lopd@monhotels.com.

You have the right to file a complaint with the Spanish Data Protection Agency if you believe that your request for your rights has not been properly addressed.

The general time limit for responding is one month from receipt of the request, without prejudice to the possible extension of up to two additional months in the cases provided for by the GDPR, taking into account the complexity and number of requests.

You have the right to withdraw your consent at any time for any of the treatments for which you have given it.

Do we use cookies?

Information about cookies and similar technologies, including their purposes, providers, duration, and consent management mechanisms, can be found in each website's Cookie Policy. Non-essential technologies will remain blocked until consent is obtained where required.

How long will we keep your personal data?

  • Personal data will be kept for as long as necessary to maintain the relationship, manage the request or fulfill the purpose for which it was collected.
  • Once the relationship or purpose has ended, the data will be deleted or, where appropriate, will remain blocked for the limitation periods of the applicable legal obligations and responsibilities.
  • Where there is a legal obligation to retain data, the retention period stipulated in the relevant regulation will be respected. When processing is based on consent, its withdrawal will prevent further processing for that purpose, without prejudice to any necessary blocked storage.
  • Contractual, reservation, payment, billing and service provision information will be kept for the periods necessary to meet legal obligations and possible claims.
  • The following are the main applicable conservation criteria:
Data relating to Document / treatment Conservation
Customers, guests and suppliers Contracts, reservations, communications and documentation related to the provision of services. During the relationship and after its termination, the documents are blocked for the duration of the statute of limitations for any potential liabilities. Commercial documentation will generally be kept for 6 years in accordance with Article 30 of the Commercial Code, where applicable.
Tax / Accounting Invoices, receipts, books and documentation with tax implications. Generally, 4 years for tax purposes, without prejudice to other specific periods; commercial documentation must be kept for a minimum period of 6 years when applicable.
Guests Documentary record of travelers and data required by accommodation regulations. 3 years from the completion of the contracted service or benefit, in accordance with Article 5 of Royal Decree 933/2021.
MonAmics Program Registration details, account, benefits, linked reservations and loyalty program management. While the status of member is maintained and, after leaving the membership, for the periods necessary to meet obligations and responsibilities arising from the relationship.
Marketing and newsletter Contact details, preferences and proof of consent where required. Until consent is withdrawn, objected to, or unsubscribed. Subsequently, the necessary information may be kept blocked for the applicable statutory limitation periods to demonstrate compliance.
Job seekers Curriculum vitae, application details and documentation of the selection process. During the selection process and, if you have been informed of your inclusion in a pool of candidates, up to 1 year, unless the candidacy is updated or there is another valid legal basis.
Human Resources Employment file, contracts, payroll, Social Security, incidents and associated documentation. During the employment relationship and subsequently for the applicable legal retention and statute of limitations periods. Documentation related to labor and Social Security obligations will generally be kept for the periods required by their specific regulations.
Human Resources Work schedule record. 4 years, in accordance with art. 34.9 of the Workers' Statute.
Occupational risk prevention Documentation and records proving compliance with preventive obligations. During the periods established by the regulations on risk prevention and the statute of limitations for liability; the specific period corresponding to each document will apply.
Video surveillance Images captured by video surveillance systems. Maximum of 1 month from the date of collection, unless they must be kept to prove facts against persons, property or facilities or made available to competent authorities, in accordance with art. 22 LOPDGDD.
Access control Access logs to facilities, where they exist. For as long as strictly necessary for the security purpose and subsequently for the applicable blocking or limitation periods when there is an incident or outstanding liability.
Spa / Wellness Data provided to manage treatments, reservations or assess contraindications, when collected. For the time necessary to provide the service and subsequently for the limitation periods for any potential liabilities. Health data, if processed, will be limited to what is strictly necessary and will have the enhanced safeguards of Article 9 GDPR.
Data protection rights Requests to exercise rights and supporting documentation of their attention. During the time necessary to process the request and, subsequently, blocked during the limitation periods for liabilities in matters of data protection.
Data protection Commissioning contracts, analyses, evaluations, records and evidence of compliance. While the documented treatment, relationship or measure is in effect and subsequently during the applicable limitation periods of liability.
Information security Logs, access records, and security evidence. During the period defined according to the security purpose, the risk and the applicable regulations, avoiding indiscriminate or longer than necessary storage.
Corporate Deeds, statutes, corporate books, minutes and structural documentation of companies. During the life of the company and, according to the document, at least during the applicable commercial and statute of limitations periods.
Legal Contracts, agreements, claims, files and documentation necessary for the exercise or defense of rights. While the relationship or file is maintained and subsequently during the limitation periods of the corresponding actions.