PRIVACY POLICY – EXTENDED INFORMATION
The Privacy Policy is part of the General Conditions that govern this Website.
Who is responsible for the processing of your data?
Paraty Hoteles S.L.U. Tax ID (CIF): B93165090
Address: Avda. Manuel Fraga Iribarne, nº 15, Portal 4 – 1ª Planta, C.P. 29620, Torremolinos.
Phone: +34 952230887
Email: protecciondatos@paratytech.com
You can reach out to us in any way to communicate with us.
We reserve the right to modify or adapt this Privacy Policy at any time. We recommend that you review it, and if you have registered and access your account or profile, you will be informed of any changes.
If you belong to any of the following groups, please consult the information:
WEBSITE OR EMAIL CONTACTS
What data do we collect through the Website?
We may process your IP address, the operating system or browser you use, and even the duration of your visit, anonymously.
If you provide us with data in the contact form, you will identify yourself so that we can contact you, if necessary.
For what purposes will we process your personal data?
- To answer your queries, requests, or petitions.
- To manage the requested service, respond to your request, or process your petition.
- Information by electronic means regarding your request.
- Commercial information or information about events by electronic means, provided there is express authorization.
- To perform analyses and improvements on the Website, regarding our products and services. To improve our commercial strategy.
What is the legitimacy for the processing of your data?
The acceptance and consent of the interested party: In those cases where it is necessary to fill out a form and click on the "send" button to make a request, doing so will necessarily imply that you have been informed and have expressly given your consent to the content of the clause attached to said form or acceptance of the privacy policy.
All our forms have the * symbol for mandatory data. If you do not provide these fields or do not check the privacy policy acceptance box, the information cannot be sent. It normally follows this formula: “□ I am over 14 years old and I have read and accept the Privacy Policy.”
You may revoke your consent at any time.
NEWSLETTER CONTACTS
What data do we collect through the newsletter?
The Website allows you to subscribe to the Newsletter if you provide us with an email address to which it will be sent.
We will only store your email in our database and will proceed to send you emails periodically until you request to unsubscribe or we stop sending emails.
The Newsletter may contain a web beacon, which statistically confirms to us if you have opened it, at what time, or how many times. This helps us study the best times to send emails and what interests you, but we will not have any personal information about you, only your email.
You will always have the option to unsubscribe in any communication.
For what purposes will we process your personal data?
- To manage the requested service.
- Information by electronic means regarding your request.
- Commercial information or information about events by electronic means, provided there is express authorization.
- To perform analyses and improvements on mailing distribution to improve our commercial strategy.
What is the legitimacy for the processing of your data?
The acceptance and consent of the interested party: In those cases where you subscribe, it will be necessary to check a box and click the send button. This will necessarily imply that you have been informed and have expressly given your consent to receive the newsletter.
If you do not check the privacy policy acceptance box, the information cannot be sent. It normally follows this formula: “□ I am over 14 years old and I have read and accept the Privacy Policy.”
You may revoke your consent at any time.
CLIENTS
For what purposes will we process your personal data?
- To provide technological solutions and increase your direct sales.
- Preparation of the budget and its follow-up through communications between both parties.
- Information by electronic means regarding your request.
- Commercial information or information about events by electronic means, provided there is express authorization.
- To manage the administrative, communication, and logistics services performed by the Controller.
- To perform the corresponding transactions. Billing and declaration of the appropriate taxes. Control and collection management.
What is the legitimacy for the processing of your data?
The legal basis is your contractual consent, which may be revoked at any time.
SUPPLIERS
For what purposes will we process your personal data?
- Information by electronic means regarding your request.
- Commercial information or information about events by electronic means, provided there is express authorization.
- To manage the administrative, communication, and logistics services performed by the Controller.
- To perform the corresponding transactions. Billing and declaration of the appropriate taxes. Control and collection management.
What is the legitimacy for the processing of your data?
The legal basis is the acceptance of a contractual relationship, or failing that, your consent when contacting us or offering us your products through any channel.
PARTNERS
For what purposes will we process your personal data?
- Organization of the actions necessary for the achievement of the company's goals.
- Internal management and legal compliance thereof.
- Summoning of meetings.
- To perform the corresponding transactions.
- Declaration of the appropriate taxes.
What is the legitimacy for the processing of your data?
The legal basis is contractual: the acceptance of a contract, whether for the purchase and sale of shares or similar, or participation in the incorporation of the company.
SOCIAL MEDIA CONTACTS
For what purposes will we process your personal data?
- To answer your queries, requests, or petitions.
- To manage the requested service, respond to your request, or process your petition.
- To relate to you and create a community of followers.
What is the legitimacy for the processing of your data?
The acceptance of a contractual relationship within the corresponding social network, and in accordance with its Privacy policies:
Facebook http://www.facebook.com/policy.php?ref=pf
Instagram https://help.instagram.com/155833707900388
Twitter http://twitter.com/privacy
Linkedin http://www.linkedin.com/legal/privacy-policy?trk=hb_ft_priv
Pinterest https://about.pinterest.com/es/privacy-policy
Google* http://www.google.com/intl/es/policies/privacy/
*(Google+ and Youtube)
How long will we keep personal data?
We can only consult or unsubscribe your data in a restricted manner as we have a specific profile. We will process them for as long as you allow us by following us, being friends, or clicking “like,” “follow,” or similar buttons.
Any rectification of your data or restriction of information or posts must be done through your profile or user settings on the social network itself.
JOB APPLICANTS
For what purposes will we process your personal data?
- Organization of selection processes for the hiring of employees.
- To summon you for job interviews and evaluate your candidacy.
- If you have given us your consent, we may keep your CV for new job postings.
- If you have given us your consent, we may transfer it to collaborating or affiliated companies, with the sole objective of helping you find employment.
What is the legitimacy for the processing of your data?
The legal basis is your unequivocal consent upon delivering your CV and receiving and signing information related to the processing we will perform.
WHISTLEBLOWING CHANNEL
For what purposes will we process your personal data?
- Internal detection of possible criminal and administrative offenses affecting the legal entity and compliance with the company's code of conduct and compliance policies.
- Management of complaints. The whistleblower's data may be processed anonymously.
What is the legitimacy for the processing of your data?
- Public interest tasks or public powers.
- Compliance with a legal obligation.
INFORMATION COMMON TO ALL PROCESSING:
Do we include personal data of third parties?
No, as a general rule we only process the data provided by the owners. If you provide us with data of third parties, you must previously inform and request their consent, otherwise you exempt us from any liability for the breach of this requirement.
What about data of minors?
We do not process data of persons under 14 years of age; therefore, please refrain from providing them if you are not that age.
Will we perform communications by electronic means?
They will only be performed to manage your request, if it is one of the contact methods you have provided to us.
If we perform commercial communications, they will have been previously and expressly authorized by you.
What security measures do we apply?
You can rest assured: We have adopted an optimal level of protection for the Personal Data we handle, and we have installed all the technical means and measures at our disposal according to the state of technology to prevent the loss, misuse, alteration, unauthorized access, and theft of Personal Data.
To which recipients will your data be communicated?
Your data will not be transferred to third parties, except for legal obligation. Specifically, they will be communicated to the State Tax Administration Agency and to banks and financial institutions for the collection of the service provided or product purchased. As well as to the data processors necessary for the execution of the agreement.
In case of purchase or payment, if you choose any application, website, platform, bank card, or any other online service, your data will be transferred to that platform or processed in its environment, always with maximum security.
When we order it, the web development and maintenance company, or the hosting company, will have access to our website. They will have signed a service provision agreement that obliges them to maintain the same level of privacy as us.
We use applications that may imply an International Transfer of data to the United States. This will only be performed to entities that have adhered to the USA-EU Data Privacy Framework, or failing that, to those that have demonstrated that they comply with the regulations, and have committed through standard contractual clauses (SCCs) to comply with the level of protection and guarantees in accordance with the parameters and requirements provided in the current European regulations on data protection, such as the European Regulation, or failing that, when there is a legal authorization to perform the international transfer.
What are your Rights?
- To know if we are processing your data or not.
- To access your personal data.
- To request the rectification of your data if they are inaccurate.
- To request the deletion of your data if they are no longer necessary for the purposes for which they were collected or if you withdraw your granted consent.
- To request the limitation of the processing of your data, in some cases, in which case we will only keep them in accordance with current regulations.
- To carry your data, which will be provided to you in a structured, commonly used, or machine-readable format. If you prefer, we can send them to the new controller you designate. It is only valid in certain cases.
- To file a complaint with the Spanish Data Protection Agency if you believe that we have not attended to you correctly.
- To revoke your consent for any processing for which you have consented, at any time.
If you modify any data, we appreciate that you notify us to keep them updated.
How can you exercise your rights?
You can exercise your rights by contacting us by postal mail or email at the address indicated at the beginning of this text.
To process your request, we need to be able to identify you. The level of verification will be proportional to the type of request and the associated risk:
- Low-risk requests (such as access to basic information): If you write to us from the same email with which you registered, it will normally be sufficient to verify your identity.
- Higher-impact requests (such as complete deletion of data or portability): We may request additional information to confirm your identity, such as answering security questions or, exceptionally, providing an identification document.
If you act on behalf of another person, you must prove said representation.
We have forms available to facilitate the exercise of your rights. You can request them by email or use those prepared by the Spanish Data Protection Agency.
Requests can be submitted by postal mail or email at the address indicated at the beginning of this text.
How long do we take to respond to the Exercise of Rights?
It depends on the right, but at most within one month from your request, and two months if the matter is very complex and we notify you that we need more time.
How long will we keep your personal data?
- Personal data will be kept as long as you remain linked to us.
- Once you unlink, the personal data processed for each purpose will be kept for the legally provided periods, including the period in which a judge or court may require them attending to the limitation period of legal actions.
- The processed data will be kept as long as the aforementioned legal periods do not expire, if there is a legal obligation for maintenance, or if there is no such legal period, until the interested party requests their deletion or revokes the granted consent.
- We will keep all information and communications related to your purchase or the provision of our service, while the guarantees of the products or services last, to attend to possible claims.
For each processing or type of data, we provide you with a specific period, which you can consult in the following table:
DATA RETENTION PERIODS
| File |
Document |
Retention |
| Clients |
| Invoices | 10 years |
| Forms and coupons | 15 years |
| Contracts | 5 years |
| Human Resources |
| Payroll, TC1, TC2, etc. | 10 years |
| Resumes | Until the end of the selection process and 1 more year with consent |
| Compensation/dismissal documents, contracts, temporary worker data | 4 years |
| Worker's file | Up to 5 years after termination |
| Marketing |
| Databases or website visitors | While the processing lasts |
| Suppliers |
| Invoices | 10 years |
| Contracts | 5 years |
| Access control and video surveillance |
| Visitor list | 30 days |
| Videos | 30 days (blocking) / 3 years (destruction) |
| Accounting |
| Accounting books and documents | 6 years |
| Partner agreements, statutes, minutes, regulations | 6 years |
| Financial statements, audit reports | 6 years |
| Subsidy records and documents | 6 years |
| Fiscal |
| Tax management: taxes, dividends, withholdings | 10 years |
| Intra-group pricing establishment | 18 years |
| Intra-group transactions (pricing agreements) | 8 years |
| Health and Safety |
| Worker medical records | 5 years |
| Environment |
| Information on hazardous substances | 10 years |
| Environmental permits | During activity / 3 years after closing / 10 years (crime) |
| Recycling or waste disposal records | 3 years |
| Subsidies (rights, obligations, receipts, payments) | 4 years |
| Accident reports | 5 years |
| Insurance |
| Insurance policies | 6 years (general) / 2 years (damages) / 5 years (personal) / 10 years (life) |
| Purchases |
| Record of deliveries, acquisitions, imports/exports (VAT) | 5 years |
| Legal |
| Intellectual and industrial property, contracts and agreements | 5 years |
| Permits, licenses, certificates | 6 years from expiration / 10 years (criminal) |
| Confidentiality and non-compete agreements | Duration of the obligation |
| LOPD |
| Processing not notified to the AEPD | 3 years |
| Employee data in networks/equipment/internal systems | 5 years |
| Whistleblowing Channel |
| Internal complaints and compliance program | 3 months (general) / 10 years (criminal) |
GROUP COMPANIES.
The following companies are part of the business group and carry out activities linked to the provision of technological, commercial, or data analysis services. Each of them acts as a Data Controller within the framework of its own business and sectoral activity.
Paraty Hoteles S.L.U.
Hotel Direct Sales. Booking engine and other related services.
https://www.paratytech.com/
Ring2travel S.L.
Call Center for Hotels.
https://www.ring2travel.com/
MEXICO PRIVACY NOTICE
This Privacy Notice is issued by Pmex Booking, S.A. de C.V. and is applicable to the processing of personal data carried out within the framework of the activities carried out by said company in the United Mexican States, in accordance with the Federal Law on Protection of Personal Data Held by Private Parties and other applicable regulations.
For the processing of personal data carried out by other entities of the Paratyworld group based in the European Union, the privacy policy published in the corresponding section of the website will be applicable, in accordance with Regulation (EU) 2016/679 (GDPR).
Identity and address of the controller
In compliance with article 15, section I, of the Federal Law on Protection of Personal Data Held by Private Parties (hereinafter, the “LFPDPPP”), it is informed that the controller of the processing of your personal data is:
Company name: Pmex Booking, S.A. de C.V.
RFC: PBO220706A63
Address: Avenida Bonampak, Manzana 2, Lote 5, Local 45 BIS, SM9, C.P. 77503, Cancún, Quintana Roo, Mexico.
Email: protecciondatos@paratytech.com
Phone: (+52) 998 341 4897
Website: https://www.paratytech.com
Pmex Booking, S.A. de C.V. (hereinafter, the “Controller”) is part of the Paraty Tech business group, with headquarters in the European Union, dedicated to the development of technological solutions for direct hotel sales, booking engines, and related services.
2. Personal data that will be subject to processing
In accordance with article 15, section II, of the LFPDPPP, the personal data that the Controller may collect and process, according to the category of the holder, are the following:
3.1 Primary purposes (necessary for the legal relationship)
The following purposes give rise to and are essential for the relationship with the holder, so they do not require additional consent under article 9, section IV, of the LFPDPPP:
- Management, execution, and maintenance of the contractual relationship with the client.
- Provision of the contracted technological services (booking engine, direct hotel sales, complementary solutions).
- Preparation and follow-up of budgets and communications derived from the contractual relationship.
- Administrative, accounting, tax, and billing management.
- Attention to queries, requests, and petitions received through the contact channels.
- Compliance with legal obligations and, where appropriate, requirements of competent authorities.
- For job candidates: organization of selection processes and evaluation of candidacies.
- For suppliers: management of the commercial relationship, payment of invoices, and contractual compliance.
3.2 Secondary purposes (require the holder's consent)
The following purposes are not necessary for the legal relationship and, therefore, require the holder's consent. If the holder does not wish for their data to be processed for any of these purposes, they can express it in accordance with section 4 of this Notice, without this affecting the provision of the main service:
- Sending commercial communications and newsletters about the Controller's or group companies' products and services.
- Invitation to events, webinars, and training or promotional activities.
- Performance of satisfaction surveys and market studies.
- Statistical and segmentation analysis for the improvement of products, services, and commercial strategy.
- Retention of the candidate's curriculum not selected for future selection processes.
4. Means to limit the use or disclosure of personal data and revocation of consent
In accordance with article 15, section IV, and article 7, sixth paragraph, of the LFPDPPP, the holder may limit the use or disclosure of their personal data or, where appropriate, revoke the consent granted for secondary purposes, through any of the following means:
- By sending a request to the email address protecciondatos@paratytech.com, clearly indicating the purpose for which they wish to limit the processing or revoke the consent.
- Through the “unsubscribe” link included at the foot of each commercial communication sent by electronic means.
- By writing to the Controller's address indicated in section 1.
The revocation of consent will not have retroactive effects and will not affect the processing previously performed in accordance with applicable regulations.
5. ARCO Rights: access, rectification, cancellation, and opposition
In terms of article 2, section VII, and Chapter IV (articles 21 to 34) of the LFPDPPP, the holder has the right to access their personal data, request their rectification when they are inaccurate or incomplete, request their cancellation when they consider that they do not comply with the regulations, and oppose their processing for specific purposes, including decisions based on automated processing with significant legal effects (article 26, section II, LFPDPPP).
5.1 How to exercise ARCO rights
The request for the exercise of ARCO rights may be submitted through the email address protecciondatos@paratytech.com or in writing to the Controller's address, and must contain, in accordance with article 28 of the LFPDPPP:
- Holder's name and address or means to receive notifications.
- Document proving the identity of the holder or, where appropriate, the personality and identity of the legal representative.
- Clear and precise description of the personal data on which the right is sought to be exercised (except in the case of the right of access).
- Description of the ARCO right that is intended to be exercised or of what is requested.
- Any other element or document that facilitates the location of the data.
5.2 Response deadlines
In accordance with article 31 of the LFPDPPP, the Controller will communicate to the holder the determination adopted within a maximum period of twenty (20) business days from the receipt of the request. If the request is appropriate, it will be made effective within the fifteen (15) business days following the communication of the response. These deadlines may be extended only once and for an equal period when the circumstances of the case justify it.
5.3 Cost of exercising ARCO rights
The exercise of ARCO rights is free. Charges may only be made to recover reproduction, copy, or shipping costs, in accordance with article 34 of the LFPDPPP.
6. Personal data transfers
In accordance with Chapter V (articles 35 and 36) of the LFPDPPP, the holder is informed that their personal data may be transferred to the following recipients:
6.1 Transfers that do not require the holder's consent
Under article 36 of the LFPDPPP, the holder's consent is not required for the following transfers:
- Paratyworld group companies: transfer to Paraty Hoteles, S.L.U. (Spain), Ring2travel, S.L. (Spain), and other companies of the same group that operate under common internal processes and policies, for the purpose of unified service management (article 36, section III).
- Competent authorities: transfer to the Tax Administration Service (SAT) and other authorities in compliance with legal obligations (article 36, section I).
- Contractual compliance: transfer to third parties when it is necessary for the maintenance or compliance of the legal relationship between the Controller and the holder (article 36, section VII).
6.2 Access by persons in charge (do not constitute a transfer)
In accordance with article 2, section XX, of the LFPDPPP, the access to personal data by persons in charge who process data on behalf of the Controller is not considered a transfer. These persons in charge are bound by service provision contracts that oblige them to comply with the same data protection guarantees as the Controller. The main persons in charge are providers of cloud hosting services, electronic communications sending, and web development and maintenance tools.
7. Security measures
In accordance with article 18 of the LFPDPPP, the Controller has implemented reasonable administrative, technical, and physical security measures to protect personal data against damage, loss, alteration, destruction, or unauthorized use, access, or processing, attending to the existing risk, the sensitivity of the data, and technological development.
In case of security breaches that significantly affect the economic or moral rights of the holders, the Controller will inform them immediately in accordance with article 19 of the LFPDPPP.
8. Retention periods
Personal data will be kept for the time necessary for the fulfillment of the purposes for which they were collected and, subsequently, for the applicable legal limitation periods, particularly in tax, commercial, labor, and administrative matters. Once said periods have elapsed, the data will be subject to blocking in accordance with article 2, section III, of the LFPDPPP and, subsequently, suppressed.
9. Use of cookies and tracking technologies
The Controller's website may use cookies and similar technologies to improve the user experience, analyze traffic, and, where appropriate, show personalized content. The holder can consult the detailed information and manage their preferences in the Cookies Policy available on the website itself.
10. Modifications to the Privacy Notice
In accordance with article 15, section VI, of the LFPDPPP, the Controller reserves the right to modify this Privacy Notice at any time to reflect regulatory changes, changes in its internal practices, or in the services offered. Any modification will be communicated to the holders through its publication on the website https://www.paratytech.com, indicating the date of the last update. The holder is recommended to consult this Notice periodically.
11. Competent authority for complaints
If the holder considers that their right to the protection of personal data has been violated by any conduct or omission of the Controller, or presumes any violation of the provisions of the LFPDPPP, they may file the corresponding request for data protection before the Secretariat for Anti-Corruption and Good Governance, the competent authority in matters of personal data protection held by private parties in accordance with article 2, section XV, and Chapter VII of the LFPDPPP, within the fifteen (15) business days following the date on which the Controller's response is communicated, in accordance with article 40 of the Law itself.
For more information, the holder can consult the official website of said Secretariat.
12. Applicable legal framework
This Privacy Notice is governed by the Federal Law on Protection of Personal Data Held by Private Parties (published in the DOF on March 20, 2025, with the last reform published on November 14, 2025) and other applicable regulations. Without prejudice to the above, and because the Controller belongs to a business group based in the European Union, the processing of personal data is carried out by adopting Regulation (EU) 2016/679 (GDPR) as an internal standard, which guarantees the holder a level of protection equivalent to or higher than that required by Mexican legislation.
13. Consent
In accordance with article 7 of the LFPDPPP, it will be understood that the holder tacitly consents to the processing of their data in accordance with the terms of this Privacy Notice when, having been made available to them, they do not express their will to the contrary. In the case of sensitive or financial personal data, as well as the secondary purposes indicated in section 3.2, the express consent of the holder will be required in the terms legally required.
Updated on 06/24/2026