Privacy Policy
Version 2.0 · Last updated: // May 2026
1. Data Controller
- Company name: Imperica Comunicación y Marketing SL
- Tax ID: B88030564
- Address: Plaza de Solarejo 1, 45001 Toledo (Spain)
- Email: info@toledoap.com
- Phone: +34 925 583 614
2. Whose Data Do We Collect?
This policy covers the processing of personal data carried out through
toledoap.com and the associated management platform
toledoap.es, both owned by Imperica Comunicación y Marketing SL.
We collect data from the following categories of individuals:
- Website visitors who complete contact, quote, or subscription forms.
- Guests who book or stay in accommodations managed by Toledo AP or Rentitec.
- Property owners who contract us to manage their accommodations.
- Individuals who contact us by email, phone, or WhatsApp.
3. What Data Do We Process and for What Purpose?
3.1. Website Visitors and Commercial Leads
| Data Category |
Purpose |
Legal Basis |
Retention Period |
| Identifying information (name, email, phone) in forms |
Respond to inquiries and prepare quotes |
Art. 6.1.b GDPR (pre-contractual measures) and, where applicable, 6.1.a (marketing consent) |
3 years from last contact |
| IP, browsing, analytics cookies (opt-in) |
Aggregated web analysis |
Art. 6.1.a (cookie consent) |
See cookie policy |
| Marketing cookies (opt-in) |
Advertising attribution |
Art. 6.1.a |
See cookie policy |
3.2. Guests
| Data Category |
Purpose |
Legal Basis |
Retention Period |
| Identifying information (name, ID/passport, date of birth, nationality, gender, address) |
Manage booking and check-in |
Art. 6.1.b (contract) + 6.1.c (RD 933/2021) |
6 years from end of booking |
| Contact information (phone, email) |
Operational communications |
Art. 6.1.b |
6 years |
| Payment information (cardholder name, last 4 digits) |
Booking payment |
Art. 6.1.b |
10 years (tax purposes) |
| WhatsApp Business (messages, audio, photos sent) |
Guest assistance |
Art. 6.1.b + 6.1.a (consent for channel and AI assistant) |
12 months internal + 24 months Meta platform |
| Voice in calls + transcription |
Quality control, incident resolution |
Art. 6.1.b + 6.1.f (with prior recorded notice) |
12 months |
| Data sent to the Ministry of Interior (SES) |
Legal obligation for lodging |
Art. 6.1.c (RD 933/2021) |
3 years |
| Image in common areas (video surveillance) |
Security of persons and property |
Art. 6.1.f (legitimate interest in security) |
30 days |
3.3. Property Owners
Identifying information (Tax ID/Company ID), contact details, IBAN, property data, and financial information (fee, rates) — to manage the contractual relationship for tourism management. Basis: art. 6.1.b (contract). Period: during the relationship + 6 years.
3.4. Form Spam Filtering
Public forms may use
Akismet (Automattic Inc., United States) to filter spam. Data processed: message content, IP address, and user agent.
- Basis: art. 6.1.f GDPR (legitimate interest in preventing form abuse).
- International transfer: United States. Mechanism: EU-US Data Privacy Framework + Standard Contractual Clauses (EU Decision 2021/914).
- Period: Automattic retains data according to its policy (typically 15 days for confirmed spam).
4. Use of Artificial Intelligence
To improve service and operations, we use third-party AI systems under strict control:
- Anthropic (Claude) — WhatsApp message classification, incident description from photos, assisted translation.
- OpenAI (Whisper) — automated call transcription.
Individuals interacting with AI assistants receive prior information (initial informative message on WhatsApp, prior recorded notice on calls). All decisions affecting the guest are made with
human review: no automated decisions with legal effects are made without operator intervention.
AI providers are contractually prohibited from training their models with our data.
International transfers are covered by the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs 2021/914) — see section 6.
5. To Whom Do We Disclose Your Data?
Your data may be disclosed to:
- Data processors with DPA art. 28 GDPR signed:
- Channel managers: Octorate (Italy), Avaibook (Spain).
- Invoicing and CRM: Holded (Spain).
- Payments: Stripe (Ireland / USA).
- Database: Supabase (data in EU / technical support USA).
- eIDAS electronic signature: Documenso (own server in EU) with Camerfirma timestamps (Spain).
- Access codes: Padword (Spain), Yacan / TTLock (various).
- WhatsApp Business: Meta Platforms (Ireland / USA).
- AI: Anthropic (USA), OpenAI (Ireland / USA).
- Email and collaboration: Google Workspace (Ireland / USA).
- Spam filtering: Automattic / Akismet (USA).
- Infrastructure: Hetzner (Germany).
- Public authorities when required by law: AEAT, TGSS, SEPE, Ministry of Interior (SES), Labor and Social Security Inspectorate (ITSS), judicial authorities.
- Property owners of the accommodation you booked, when the nature of the management requires communicating guest data to them.
- Social Security mutual insurance company and labor management firm (in the employment context, does not apply to guests).
We do not transfer your data to third parties for external marketing purposes without your express consent.
6. International Transfers
Some processors are located or have subprocessors in the United States:
- Stripe Inc. — under EU-US Data Privacy Framework + SCCs.
- Anthropic PBC — under DPF + SCCs.
- OpenAI LLC — under DPF + SCCs.
- Meta Platforms Inc. — under DPF + SCCs.
- Google LLC — under DPF + SCCs.
- Automattic Inc. (Akismet) — under DPF + SCCs.
All international transfers include impact assessments (Transfer Impact Assessment, TIA) in accordance with Schrems II case law and EDPB Recommendations 01/2020.
All other processing takes place in the European Economic Area.
7. How Long Do We Retain Your Data?
General retention periods are indicated in the table in section 3. After the retention period, we proceed to:
- Effective deletion for data without legal retention obligation.
- Blocking (functional anonymization) when retention is legally required (tax, RD 933/2021, statute of limitations).
8. Your Rights
You have the following recognized rights:
- Access: know what data of yours we hold.
- Rectification: correct inaccurate data.
- Erasure: request deletion where applicable.
- Objection: object to processing based on legitimate interest. Marketing objection is unconditional — simply reply STOP or click the unsubscribe link.
- Restriction: temporarily suspend processing while a dispute is resolved.
- Portability: receive your data in a structured format.
- Not to be subject to automated decision-making: right to human intervention. Imperica does not make automated decisions with effects on you: all our decisions involve human review.
- Withdraw consent when processing is based on it, without affecting the lawfulness of prior processing.
How to Exercise Your Rights
Send an email to
info@toledoap.com (or to
info@imperica.es) with:
- Clear identification of the right you are exercising.
- Copy of your ID or identification document to verify identity.
- Contact details where you wish to receive our response.
We will respond within the legal period of
1 month (extendable to 3 with justification if the request is complex).
If you do not receive a satisfactory response or believe the processing is not compliant, you may file a complaint with the
Spanish Data Protection Agency (
https://www.aepd.es).
9. Security
We apply technical and organizational measures to protect your personal data in accordance with art. 32 GDPR, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access control with multi-factor authentication (MFA).
- Regular backups.
- Audit logs.
- Incident and breach management procedures.
- Regular staff training.
If we detect a security breach that poses a risk to your rights, we will notify the AEPD within 72 hours and, where applicable, notify you directly.
10. Specific Information on the Guest Register (RD 933/2021)
If you stay with us, in compliance with Royal Decree 933/2021 we are required to communicate to the Ministry of Interior the identifying information required by law (name, ID/passport, date of birth, gender, nationality, address, dates of stay). This communication is legally required and does not require your consent. Data is retained for 3 years.
11. Children and Minors
We do not directly request data from children under 14 years of age. When a minor stays, the data is provided by the adult booking holder. In the RD 933/2021 register, only guests over 14 years of age are reported.
12. Cookies
Cookie use is governed by our Cookie Policy, accessible at /cookies/, which details the categories used, providers, international transfers, and how to manage your consent.
13. Changes to This Policy
This Policy may be updated to reflect regulatory changes or changes in our processing. Substantial changes will be communicated prominently on the website. The date of last update appears at the beginning of the document.
14. Contact
For any questions about this Policy or the processing of your data: