I have read and accept the Privacy Policy

PRIVACY POLICY – EXTENDED INFORMATION

The Privacy Policy is part of the General Conditions that govern this Website.

Who is responsible for the processing of your data?

Paraty Hoteles S.L.U. Tax ID (CIF): B93165090
Address: Avda. Manuel Fraga Iribarne, nº 15, Portal 4 – 1ª Planta, C.P. 29620, Torremolinos.
Phone: +34 952230887
Email: protecciondatos@paratytech.com

You can reach out to us in any way to communicate with us.

We reserve the right to modify or adapt this Privacy Policy at any time. We recommend that you review it, and if you have registered and access your account or profile, you will be informed of any changes.

If you belong to any of the following groups, please consult the information:

WEBSITE OR EMAIL CONTACTS

What data do we collect through the Website?

We may process your IP address, the operating system or browser you use, and even the duration of your visit, anonymously.
If you provide us with data in the contact form, you will identify yourself so that we can contact you, if necessary.

For what purposes will we process your personal data?
What is the legitimacy for the processing of your data?

The acceptance and consent of the interested party: In those cases where it is necessary to fill out a form and click on the "send" button to make a request, doing so will necessarily imply that you have been informed and have expressly given your consent to the content of the clause attached to said form or acceptance of the privacy policy.

All our forms have the * symbol for mandatory data. If you do not provide these fields or do not check the privacy policy acceptance box, the information cannot be sent. It normally follows this formula: “□ I am over 14 years old and I have read and accept the Privacy Policy.”

You may revoke your consent at any time.

NEWSLETTER CONTACTS

What data do we collect through the newsletter?

The Website allows you to subscribe to the Newsletter if you provide us with an email address to which it will be sent.

We will only store your email in our database and will proceed to send you emails periodically until you request to unsubscribe or we stop sending emails.

The Newsletter may contain a web beacon, which statistically confirms to us if you have opened it, at what time, or how many times. This helps us study the best times to send emails and what interests you, but we will not have any personal information about you, only your email.

You will always have the option to unsubscribe in any communication.

For what purposes will we process your personal data?

What is the legitimacy for the processing of your data?

The acceptance and consent of the interested party: In those cases where you subscribe, it will be necessary to check a box and click the send button. This will necessarily imply that you have been informed and have expressly given your consent to receive the newsletter.

If you do not check the privacy policy acceptance box, the information cannot be sent. It normally follows this formula: “□ I am over 14 years old and I have read and accept the Privacy Policy.”

You may revoke your consent at any time.

CLIENTS


For what purposes will we process your personal data?

What is the legitimacy for the processing of your data?

The legal basis is your contractual consent, which may be revoked at any time.

SUPPLIERS


For what purposes will we process your personal data?

What is the legitimacy for the processing of your data?

The legal basis is the acceptance of a contractual relationship, or failing that, your consent when contacting us or offering us your products through any channel.

PARTNERS



For what purposes will we process your personal data?

What is the legitimacy for the processing of your data?

The legal basis is contractual: the acceptance of a contract, whether for the purchase and sale of shares or similar, or participation in the incorporation of the company.

SOCIAL MEDIA CONTACTS


For what purposes will we process your personal data?

What is the legitimacy for the processing of your data?

The acceptance of a contractual relationship within the corresponding social network, and in accordance with its Privacy policies: Facebook http://www.facebook.com/policy.php?ref=pf
Instagram https://help.instagram.com/155833707900388
Twitter http://twitter.com/privacy
Linkedin http://www.linkedin.com/legal/privacy-policy?trk=hb_ft_priv
Pinterest https://about.pinterest.com/es/privacy-policy
Google* http://www.google.com/intl/es/policies/privacy/
*(Google+ and Youtube)

How long will we keep personal data?

We can only consult or unsubscribe your data in a restricted manner as we have a specific profile. We will process them for as long as you allow us by following us, being friends, or clicking “like,” “follow,” or similar buttons.

Any rectification of your data or restriction of information or posts must be done through your profile or user settings on the social network itself.

JOB APPLICANTS


For what purposes will we process your personal data?

What is the legitimacy for the processing of your data?

The legal basis is your unequivocal consent upon delivering your CV and receiving and signing information related to the processing we will perform.

WHISTLEBLOWING CHANNEL


For what purposes will we process your personal data?

What is the legitimacy for the processing of your data?

INFORMATION COMMON TO ALL PROCESSING:


Do we include personal data of third parties?

No, as a general rule we only process the data provided by the owners. If you provide us with data of third parties, you must previously inform and request their consent, otherwise you exempt us from any liability for the breach of this requirement.

What about data of minors?

We do not process data of persons under 14 years of age; therefore, please refrain from providing them if you are not that age.

Will we perform communications by electronic means?

They will only be performed to manage your request, if it is one of the contact methods you have provided to us.

If we perform commercial communications, they will have been previously and expressly authorized by you.

What security measures do we apply?

You can rest assured: We have adopted an optimal level of protection for the Personal Data we handle, and we have installed all the technical means and measures at our disposal according to the state of technology to prevent the loss, misuse, alteration, unauthorized access, and theft of Personal Data.

To which recipients will your data be communicated?

Your data will not be transferred to third parties, except for legal obligation. Specifically, they will be communicated to the State Tax Administration Agency and to banks and financial institutions for the collection of the service provided or product purchased. As well as to the data processors necessary for the execution of the agreement.

In case of purchase or payment, if you choose any application, website, platform, bank card, or any other online service, your data will be transferred to that platform or processed in its environment, always with maximum security.

When we order it, the web development and maintenance company, or the hosting company, will have access to our website. They will have signed a service provision agreement that obliges them to maintain the same level of privacy as us.

We use applications that may imply an International Transfer of data to the United States. This will only be performed to entities that have adhered to the USA-EU Data Privacy Framework, or failing that, to those that have demonstrated that they comply with the regulations, and have committed through standard contractual clauses (SCCs) to comply with the level of protection and guarantees in accordance with the parameters and requirements provided in the current European regulations on data protection, such as the European Regulation, or failing that, when there is a legal authorization to perform the international transfer.

What are your Rights?
If you modify any data, we appreciate that you notify us to keep them updated.

How can you exercise your rights?
You can exercise your rights by contacting us by postal mail or email at the address indicated at the beginning of this text.
To process your request, we need to be able to identify you. The level of verification will be proportional to the type of request and the associated risk:

If you act on behalf of another person, you must prove said representation.
We have forms available to facilitate the exercise of your rights. You can request them by email or use those prepared by the Spanish Data Protection Agency.
Requests can be submitted by postal mail or email at the address indicated at the beginning of this text.

How long do we take to respond to the Exercise of Rights?

It depends on the right, but at most within one month from your request, and two months if the matter is very complex and we notify you that we need more time.

How long will we keep your personal data?
For each processing or type of data, we provide you with a specific period, which you can consult in the following table:



DATA RETENTION PERIODS

File Document Retention
Clients
Invoices10 years
Forms and coupons15 years
Contracts5 years
Human Resources
Payroll, TC1, TC2, etc.10 years
ResumesUntil the end of the selection process and 1 more year with consent
Compensation/dismissal documents, contracts, temporary worker data4 years
Worker's fileUp to 5 years after termination
Marketing
Databases or website visitorsWhile the processing lasts
Suppliers
Invoices10 years
Contracts5 years
Access control and video surveillance
Visitor list30 days
Videos30 days (blocking) / 3 years (destruction)
Accounting
Accounting books and documents6 years
Partner agreements, statutes, minutes, regulations6 years
Financial statements, audit reports6 years
Subsidy records and documents6 years
Fiscal
Tax management: taxes, dividends, withholdings10 years
Intra-group pricing establishment18 years
Intra-group transactions (pricing agreements)8 years
Health and Safety
Worker medical records5 years
Environment
Information on hazardous substances10 years
Environmental permitsDuring activity / 3 years after closing / 10 years (crime)
Recycling or waste disposal records3 years
Subsidies (rights, obligations, receipts, payments)4 years
Accident reports5 years
Insurance
Insurance policies6 years (general) / 2 years (damages) / 5 years (personal) / 10 years (life)
Purchases
Record of deliveries, acquisitions, imports/exports (VAT)5 years
Legal
Intellectual and industrial property, contracts and agreements5 years
Permits, licenses, certificates6 years from expiration / 10 years (criminal)
Confidentiality and non-compete agreementsDuration of the obligation
LOPD
Processing not notified to the AEPD3 years
Employee data in networks/equipment/internal systems5 years
Whistleblowing Channel
Internal complaints and compliance program3 months (general) / 10 years (criminal)


GROUP COMPANIES.


The following companies are part of the business group and carry out activities linked to the provision of technological, commercial, or data analysis services. Each of them acts as a Data Controller within the framework of its own business and sectoral activity.

Paraty Hoteles S.L.U.
Hotel Direct Sales. Booking engine and other related services.
https://www.paratytech.com/

Ring2travel S.L.
Call Center for Hotels.
https://www.ring2travel.com/


MEXICO PRIVACY NOTICE

This Privacy Notice is issued by Pmex Booking, S.A. de C.V. and is applicable to the processing of personal data carried out within the framework of the activities carried out by said company in the United Mexican States, in accordance with the Federal Law on Protection of Personal Data Held by Private Parties and other applicable regulations.
For the processing of personal data carried out by other entities of the Paratyworld group based in the European Union, the privacy policy published in the corresponding section of the website will be applicable, in accordance with Regulation (EU) 2016/679 (GDPR).

Identity and address of the controller

In compliance with article 15, section I, of the Federal Law on Protection of Personal Data Held by Private Parties (hereinafter, the “LFPDPPP”), it is informed that the controller of the processing of your personal data is:
Company name: Pmex Booking, S.A. de C.V.
RFC: PBO220706A63
Address: Avenida Bonampak, Manzana 2, Lote 5, Local 45 BIS, SM9, C.P. 77503, Cancún, Quintana Roo, Mexico.
Email: protecciondatos@paratytech.com
Phone: (+52) 998 341 4897
Website: https://www.paratytech.com

Pmex Booking, S.A. de C.V. (hereinafter, the “Controller”) is part of the Paraty Tech business group, with headquarters in the European Union, dedicated to the development of technological solutions for direct hotel sales, booking engines, and related services.

2. Personal data that will be subject to processing

In accordance with article 15, section II, of the LFPDPPP, the personal data that the Controller may collect and process, according to the category of the holder, are the following:
2.1 Clients and client representatives (hotels and hotel chains)
Identification data: name, surnames, position or function within the client company.
2.2 Website visitors and subscribers
2.3 Suppliers and supplier representatives
2.4 Job candidates
2.5 Sensitive personal data
In accordance with article 8 of the LFPDPPP, the Controller does not collect or process sensitive personal data (racial or ethnic origin, health status, genetic information, religious beliefs, political opinions, or sexual preference) within the framework of its ordinary activities. In the exceptional case of being required, the express written consent of the holder will be obtained beforehand.
2.6 Financial or patrimonial data
In accordance with article 7, fifth paragraph, of the LFPDPPP, financial or patrimonial data (for example, supplier bank details) are processed with the prior express consent of the holder, except for the exceptions provided in articles 9 and 36 of the Law itself.

3. Purposes of the processing

In compliance with article 15, section III, of the LFPDPPP, the purposes that are necessary for the legal relationship are distinguished from those that require the additional consent of the holder.
3.1 Primary purposes (necessary for the legal relationship)
The following purposes give rise to and are essential for the relationship with the holder, so they do not require additional consent under article 9, section IV, of the LFPDPPP: 3.2 Secondary purposes (require the holder's consent)
The following purposes are not necessary for the legal relationship and, therefore, require the holder's consent. If the holder does not wish for their data to be processed for any of these purposes, they can express it in accordance with section 4 of this Notice, without this affecting the provision of the main service:

4. Means to limit the use or disclosure of personal data and revocation of consent

In accordance with article 15, section IV, and article 7, sixth paragraph, of the LFPDPPP, the holder may limit the use or disclosure of their personal data or, where appropriate, revoke the consent granted for secondary purposes, through any of the following means: The revocation of consent will not have retroactive effects and will not affect the processing previously performed in accordance with applicable regulations.

5. ARCO Rights: access, rectification, cancellation, and opposition

In terms of article 2, section VII, and Chapter IV (articles 21 to 34) of the LFPDPPP, the holder has the right to access their personal data, request their rectification when they are inaccurate or incomplete, request their cancellation when they consider that they do not comply with the regulations, and oppose their processing for specific purposes, including decisions based on automated processing with significant legal effects (article 26, section II, LFPDPPP). 5.1 How to exercise ARCO rights

The request for the exercise of ARCO rights may be submitted through the email address protecciondatos@paratytech.com or in writing to the Controller's address, and must contain, in accordance with article 28 of the LFPDPPP: 5.2 Response deadlines
In accordance with article 31 of the LFPDPPP, the Controller will communicate to the holder the determination adopted within a maximum period of twenty (20) business days from the receipt of the request. If the request is appropriate, it will be made effective within the fifteen (15) business days following the communication of the response. These deadlines may be extended only once and for an equal period when the circumstances of the case justify it. 5.3 Cost of exercising ARCO rights

The exercise of ARCO rights is free. Charges may only be made to recover reproduction, copy, or shipping costs, in accordance with article 34 of the LFPDPPP.

6. Personal data transfers

In accordance with Chapter V (articles 35 and 36) of the LFPDPPP, the holder is informed that their personal data may be transferred to the following recipients: 6.1 Transfers that do not require the holder's consent
Under article 36 of the LFPDPPP, the holder's consent is not required for the following transfers: 6.2 Access by persons in charge (do not constitute a transfer)
In accordance with article 2, section XX, of the LFPDPPP, the access to personal data by persons in charge who process data on behalf of the Controller is not considered a transfer. These persons in charge are bound by service provision contracts that oblige them to comply with the same data protection guarantees as the Controller. The main persons in charge are providers of cloud hosting services, electronic communications sending, and web development and maintenance tools.
6.3 International transfers and applicable protection framework
Certain transfers may imply the sending of personal data to countries other than Mexico, including the European Union (headquarters of the business group) and, occasionally, the United States of America. The Controller adopts as an internal standard Regulation (EU) 2016/679 (GDPR) for belonging to a business group based in the European Union that applies said regulation uniformly, which offers the holder a level of protection equivalent to or higher than that required by the LFPDPPP. For transfers to the United States, the Controller only contracts with entities adhered to the EU-US Data Privacy Framework or that have signed Standard Contractual Clauses (SCCs) approved by the European Commission.
6.4 Transfers that require the holder's consent
Any transfer other than the above will require the holder's consent, which may be expressed at the time of data collection or subsequently in accordance with section 4 of this Notice.

7. Security measures

In accordance with article 18 of the LFPDPPP, the Controller has implemented reasonable administrative, technical, and physical security measures to protect personal data against damage, loss, alteration, destruction, or unauthorized use, access, or processing, attending to the existing risk, the sensitivity of the data, and technological development. In case of security breaches that significantly affect the economic or moral rights of the holders, the Controller will inform them immediately in accordance with article 19 of the LFPDPPP.

8. Retention periods

Personal data will be kept for the time necessary for the fulfillment of the purposes for which they were collected and, subsequently, for the applicable legal limitation periods, particularly in tax, commercial, labor, and administrative matters. Once said periods have elapsed, the data will be subject to blocking in accordance with article 2, section III, of the LFPDPPP and, subsequently, suppressed.

9. Use of cookies and tracking technologies

The Controller's website may use cookies and similar technologies to improve the user experience, analyze traffic, and, where appropriate, show personalized content. The holder can consult the detailed information and manage their preferences in the Cookies Policy available on the website itself.

10. Modifications to the Privacy Notice

In accordance with article 15, section VI, of the LFPDPPP, the Controller reserves the right to modify this Privacy Notice at any time to reflect regulatory changes, changes in its internal practices, or in the services offered. Any modification will be communicated to the holders through its publication on the website https://www.paratytech.com, indicating the date of the last update. The holder is recommended to consult this Notice periodically.

11. Competent authority for complaints

If the holder considers that their right to the protection of personal data has been violated by any conduct or omission of the Controller, or presumes any violation of the provisions of the LFPDPPP, they may file the corresponding request for data protection before the Secretariat for Anti-Corruption and Good Governance, the competent authority in matters of personal data protection held by private parties in accordance with article 2, section XV, and Chapter VII of the LFPDPPP, within the fifteen (15) business days following the date on which the Controller's response is communicated, in accordance with article 40 of the Law itself. For more information, the holder can consult the official website of said Secretariat.

12. Applicable legal framework

This Privacy Notice is governed by the Federal Law on Protection of Personal Data Held by Private Parties (published in the DOF on March 20, 2025, with the last reform published on November 14, 2025) and other applicable regulations. Without prejudice to the above, and because the Controller belongs to a business group based in the European Union, the processing of personal data is carried out by adopting Regulation (EU) 2016/679 (GDPR) as an internal standard, which guarantees the holder a level of protection equivalent to or higher than that required by Mexican legislation.

13. Consent

In accordance with article 7 of the LFPDPPP, it will be understood that the holder tacitly consents to the processing of their data in accordance with the terms of this Privacy Notice when, having been made available to them, they do not express their will to the contrary. In the case of sensitive or financial personal data, as well as the secondary purposes indicated in section 3.2, the express consent of the holder will be required in the terms legally required.

Updated on 06/24/2026