Toledo AP - Alojamientos turisticos en el casco historico de Toledo

Privacy Policy

Version 2.0 · Last updated: // May 2026

1. Data Controller

  • Company name: Imperica Comunicación y Marketing SL
  • Tax ID: B88030564
  • Address: Plaza de Solarejo 1, 45001 Toledo (Spain)
  • Email: info@toledoap.com
  • Phone: +34 925 583 614

2. Whose Data Do We Collect?

This policy covers the processing of personal data carried out through toledoap.com and the associated management platform toledoap.es, both owned by Imperica Comunicación y Marketing SL.

We collect data from the following categories of individuals:

  • Website visitors who complete contact, quote, or subscription forms.
  • Guests who book or stay in accommodations managed by Toledo AP or Rentitec.
  • Property owners who contract us to manage their accommodations.
  • Individuals who contact us by email, phone, or WhatsApp.

3. What Data Do We Process and for What Purpose?

3.1. Website Visitors and Commercial Leads

Data Category Purpose Legal Basis Retention Period
Identifying information (name, email, phone) in forms Respond to inquiries and prepare quotes Art. 6.1.b GDPR (pre-contractual measures) and, where applicable, 6.1.a (marketing consent) 3 years from last contact
IP, browsing, analytics cookies (opt-in) Aggregated web analysis Art. 6.1.a (cookie consent) See cookie policy
Marketing cookies (opt-in) Advertising attribution Art. 6.1.a See cookie policy

3.2. Guests

Data Category Purpose Legal Basis Retention Period
Identifying information (name, ID/passport, date of birth, nationality, gender, address) Manage booking and check-in Art. 6.1.b (contract) + 6.1.c (RD 933/2021) 6 years from end of booking
Contact information (phone, email) Operational communications Art. 6.1.b 6 years
Payment information (cardholder name, last 4 digits) Booking payment Art. 6.1.b 10 years (tax purposes)
WhatsApp Business (messages, audio, photos sent) Guest assistance Art. 6.1.b + 6.1.a (consent for channel and AI assistant) 12 months internal + 24 months Meta platform
Voice in calls + transcription Quality control, incident resolution Art. 6.1.b + 6.1.f (with prior recorded notice) 12 months
Data sent to the Ministry of Interior (SES) Legal obligation for lodging Art. 6.1.c (RD 933/2021) 3 years
Image in common areas (video surveillance) Security of persons and property Art. 6.1.f (legitimate interest in security) 30 days

3.3. Property Owners

Identifying information (Tax ID/Company ID), contact details, IBAN, property data, and financial information (fee, rates) — to manage the contractual relationship for tourism management. Basis: art. 6.1.b (contract). Period: during the relationship + 6 years.

3.4. Form Spam Filtering

Public forms may use Akismet (Automattic Inc., United States) to filter spam. Data processed: message content, IP address, and user agent.

  • Basis: art. 6.1.f GDPR (legitimate interest in preventing form abuse).
  • International transfer: United States. Mechanism: EU-US Data Privacy Framework + Standard Contractual Clauses (EU Decision 2021/914).
  • Period: Automattic retains data according to its policy (typically 15 days for confirmed spam).

4. Use of Artificial Intelligence

To improve service and operations, we use third-party AI systems under strict control:

  • Anthropic (Claude) — WhatsApp message classification, incident description from photos, assisted translation.
  • OpenAI (Whisper) — automated call transcription.
Individuals interacting with AI assistants receive prior information (initial informative message on WhatsApp, prior recorded notice on calls). All decisions affecting the guest are made with human review: no automated decisions with legal effects are made without operator intervention.

AI providers are contractually prohibited from training their models with our data.

International transfers are covered by the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs 2021/914) — see section 6.

5. To Whom Do We Disclose Your Data?

Your data may be disclosed to:

  • Data processors with DPA art. 28 GDPR signed:
    • Channel managers: Octorate (Italy), Avaibook (Spain).
    • Invoicing and CRM: Holded (Spain).
    • Payments: Stripe (Ireland / USA).
    • Database: Supabase (data in EU / technical support USA).
    • eIDAS electronic signature: Documenso (own server in EU) with Camerfirma timestamps (Spain).
    • Access codes: Padword (Spain), Yacan / TTLock (various).
    • WhatsApp Business: Meta Platforms (Ireland / USA).
    • AI: Anthropic (USA), OpenAI (Ireland / USA).
    • Email and collaboration: Google Workspace (Ireland / USA).
    • Spam filtering: Automattic / Akismet (USA).
    • Infrastructure: Hetzner (Germany).
  • Public authorities when required by law: AEAT, TGSS, SEPE, Ministry of Interior (SES), Labor and Social Security Inspectorate (ITSS), judicial authorities.
  • Property owners of the accommodation you booked, when the nature of the management requires communicating guest data to them.
  • Social Security mutual insurance company and labor management firm (in the employment context, does not apply to guests).
We do not transfer your data to third parties for external marketing purposes without your express consent.

6. International Transfers

Some processors are located or have subprocessors in the United States:

  • Stripe Inc. — under EU-US Data Privacy Framework + SCCs.
  • Anthropic PBC — under DPF + SCCs.
  • OpenAI LLC — under DPF + SCCs.
  • Meta Platforms Inc. — under DPF + SCCs.
  • Google LLC — under DPF + SCCs.
  • Automattic Inc. (Akismet) — under DPF + SCCs.
All international transfers include impact assessments (Transfer Impact Assessment, TIA) in accordance with Schrems II case law and EDPB Recommendations 01/2020.

All other processing takes place in the European Economic Area.

7. How Long Do We Retain Your Data?

General retention periods are indicated in the table in section 3. After the retention period, we proceed to:

  • Effective deletion for data without legal retention obligation.
  • Blocking (functional anonymization) when retention is legally required (tax, RD 933/2021, statute of limitations).

8. Your Rights

You have the following recognized rights:

  • Access: know what data of yours we hold.
  • Rectification: correct inaccurate data.
  • Erasure: request deletion where applicable.
  • Objection: object to processing based on legitimate interest. Marketing objection is unconditional — simply reply STOP or click the unsubscribe link.
  • Restriction: temporarily suspend processing while a dispute is resolved.
  • Portability: receive your data in a structured format.
  • Not to be subject to automated decision-making: right to human intervention. Imperica does not make automated decisions with effects on you: all our decisions involve human review.
  • Withdraw consent when processing is based on it, without affecting the lawfulness of prior processing.

How to Exercise Your Rights

Send an email to info@toledoap.com (or to info@imperica.es) with:

  1. Clear identification of the right you are exercising.
  2. Copy of your ID or identification document to verify identity.
  3. Contact details where you wish to receive our response.
We will respond within the legal period of 1 month (extendable to 3 with justification if the request is complex).

If you do not receive a satisfactory response or believe the processing is not compliant, you may file a complaint with the Spanish Data Protection Agency (https://www.aepd.es).

9. Security

We apply technical and organizational measures to protect your personal data in accordance with art. 32 GDPR, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access control with multi-factor authentication (MFA).
  • Regular backups.
  • Audit logs.
  • Incident and breach management procedures.
  • Regular staff training.
If we detect a security breach that poses a risk to your rights, we will notify the AEPD within 72 hours and, where applicable, notify you directly.

10. Specific Information on the Guest Register (RD 933/2021)

If you stay with us, in compliance with Royal Decree 933/2021 we are required to communicate to the Ministry of Interior the identifying information required by law (name, ID/passport, date of birth, gender, nationality, address, dates of stay). This communication is legally required and does not require your consent. Data is retained for 3 years.

11. Children and Minors

We do not directly request data from children under 14 years of age. When a minor stays, the data is provided by the adult booking holder. In the RD 933/2021 register, only guests over 14 years of age are reported.

12. Cookies

Cookie use is governed by our Cookie Policy, accessible at /cookies/, which details the categories used, providers, international transfers, and how to manage your consent.

13. Changes to This Policy

This Policy may be updated to reflect regulatory changes or changes in our processing. Substantial changes will be communicated prominently on the website. The date of last update appears at the beginning of the document.

14. Contact

For any questions about this Policy or the processing of your data: