Privacy Policy

At Cork Valley we treat your personal data with the same care we put into the rest of your stay. This policy explains, processing activity by processing activity, what data we collect, what for, on what legal basis, how long we keep it and who we share it with.

1. Who is the data controller?

Cork Valley Management, S.L.U. is not required to appoint a Data Protection Officer under article 37 of the GDPR or article 34 of the LOPDGDD. Data protection enquiries are handled at the address given above.

2. Which rules do we apply?

Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR); Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD); and Spanish Law 34/2002, on Information Society Services (LSSI-CE).

3. Processing activities we carry out

Each processing activity is set out separately below.

3.1. Managing bookings and the stay

Data: first name and surname, email address, telephone number, country, arrival and departure dates, accommodation category, number of companions, amount and details of the payment transaction, preferences and special requests.

Purpose: to make, manage, modify and cancel the booking; to provide the accommodation services contracted; to issue an invoice and to manage the contractual relationship.

Legal basis: performance of a contract and pre-contractual measures (art. 6.1.b GDPR). For invoicing and for accounting and tax obligations, compliance with a legal obligation (art. 6.1.c GDPR).

Retention: for the term of the contractual relationship and, thereafter, blocked and available to judges, courts and public authorities for the applicable limitation periods — generally 6 years under commercial law (art. 30 of the Spanish Commercial Code) and 4 years under tax law.

3.2. Traveller register and reporting to the authorities

This reporting is mandatory and does not depend on your consent.

Data: those required by the applicable rules, including first name and surname, sex, number and type of identity document or passport, date of birth, nationality, address, telephone number and email address, date and time of arrival and departure, number of travellers, family relationship in the case of minors, and details of the means of payment used.

Purpose: to comply with the obligations to keep documentary records of, and report on, the people staying at the establishment, and to report that information to the competent authorities.

Legal basis: compliance with a legal obligation (art. 6.1.c GDPR), under Spanish Organic Law 4/2015, of 30 March, on the protection of public safety, and Royal Decree 933/2021, of 26 October, establishing the documentary record and reporting obligations of natural or legal persons carrying out accommodation and motor vehicle rental activities.

Recipient: the Spanish Ministry of the Interior, through the SES.Hospedajes.

Retention: three years from the end of the service, in accordance with Royal Decree 933/2021.

Please note: in relation to this data the rights of erasure and objection cannot be exercised while the legal obligation subsists. Providing it is a legal requirement in order to stay with us; if you do not, we will not be able to complete your check-in.

3.3. Health data: allergies, intolerances and accessibility

Data: only what you voluntarily tell us about food allergies and intolerances, or about accessibility and mobility needs.

Purpose: to adapt the catering service and the facilities to your needs and to ensure your safety during the stay.

Legal basis: explicit consent (arts. 6.1.a and 9.2.a GDPR). This data belongs to special categories and we only process it if you decide to give it to us. You can withdraw your consent at any time, although doing so may prevent us from meeting the need you told us about.

Retention: until the end of the stay, unless retention is necessary to deal with a claim.

We do not record diagnoses, medical treatments or clinical information. We ask only for the minimum data strictly necessary to provide the service.

3.4. Handling enquiries by form, email or WhatsApp

Data: name, email address, telephone number and the content of your message.

Purpose: to answer your enquiry, prepare quotes and handle requests for information.

Legal basis: pre-contractual measures at the request of the data subject (art. 6.1.b GDPR) or, failing that, consent (art. 6.1.a GDPR).

Retention: twelve months from the last interaction, unless the enquiry leads to a booking, in which case the period in section 3.1 applies.

If you contact us by WhatsApp, please note that this channel is operated by WhatsApp Ireland Limited (Meta group), which acts as an independent controller in respect of the communication metadata under its own terms.

3.5. Marketing communications

Data: name and email address.

Purpose: to send you news, offers and content about Cork Valley.

Legal basis: your consent (art. 6.1.a GDPR). If you have already been a customer, we may send you information about services similar to those contracted, under article 21.2 of the LSSI-CE, offering you the chance to object in every message.

Retention: until you withdraw your consent or unsubscribe. You can do so from the link included in every communication or by writing to hello@corkvalley.es.

3.6. Web analytics and digital advertising

Data: cookie and device identifiers, IP address, pages visited, traffic source, interactions with the booking engine and transaction data for conversion measurement.

Purpose: to measure use of the Website, understand which content works, measure the effectiveness of our advertising campaigns and show you ads tailored to your interests on Google’s platforms.

Legal basis: your consent, given through the cookie banner (art. 6.1.a GDPR and art. 22.2 LSSI-CE). You can change or withdraw it at any time from the cookie settings link on the Website.

Tools used: Google Analytics 4, Google Tag Manager and Google Ads, from Google Ireland Limited. We apply Google’s Consent Mode , so that these tools do not install advertising or analytics cookies until you accept their use.

International transfers: these tools may involve transfers of data to the United States. Google LLC is certified under the Data Privacy Framework EU-US framework, an adequacy decision of the European Commission of 10 July 2023, and as an additional safeguard the Commission’s Standard Contractual Clauses are applied.

Retention: as set out in the Cookie Policy. As a general rule, advertising identifiers do not exceed 13 months.

3.7. Reviews and reputation

Data: what you voluntarily publish on third-party review platforms and that is displayed on the Website.

Purpose: to show what our guests think and to improve the service.

Legal basis: legitimate interest in knowing and sharing our customers’ feedback (art. 6.1.f GDPR). The original publication is governed by the terms of the relevant platform, which acts as an independent controller.

3.8. CCTV

The establishment has security cameras at entrances and in outdoor common areas.

Data: images captured by the CCTV system.

Purpose: security of people, facilities and property.

Legal basis: legitimate interest (art. 6.1.f GDPR) and article 22 of the LOPDGDD.

Retention: a maximum of one month from capture, unless the images must be kept to evidence acts against the integrity of people or property, in which case they will be made available to the competent authority within 72 hours.

There are no cameras inside the units or in any area of private use. The areas under CCTV are marked with the corresponding information sign.

3.9. Bookings for experiences and activities

Experiences and activities sold through catalogo.corkvalley.es are processed for the same purpose, on the same legal basis and for the same periods set out in section 3.1. Where the activity is provided by a third party, we will pass on to that supplier only the data necessary to carry it out.

4. Who do we share your data with?

We have the contract required by article 28 of the GDPR in place with all our data processors. We do not sell or transfer your data to third parties for unrelated commercial purposes.

5. International transfers

As a general rule your data is processed within the European Economic Area. The only transfers envisaged are those arising from the use of the Google tools described in section 3.6, covered by the Data Privacy Framework adequacy decision and by Standard Contractual Clauses.

6. Do we take automated decisions?

We do not take automated decisions that produce legal effects concerning you or similarly significantly affect you. The advertising segmentation described in section 3.6 is limited to showing you ads and does not affect the price or availability of your booking.

7. Do we process children’s data?

Cork Valley is adults-onlyaccommodation, with a minimum age of 16 to stay. Booking is reserved for people over 18, who provide their own data and that of their companions.

Where a booking includes a guest aged 16 or 17, their identification data will be processed solely to comply with the traveller registration obligation described in section 3.2, and is provided under the responsibility of the adult making the booking. We do not send marketing communications to minors and we do not knowingly collect their data for any other purpose; if we find that data on a child under 16 has been provided, we will delete it.

8. Your rights

You can exercise the following rights at any time:

How to exercise them: by writing to hello@corkvalley.es or by post to Cork Valley Management, S.L.U., Calle Sauco, 21, 45150 Navahermosa (Toledo), Spain, stating the right you wish to exercise and enclosing a copy of a document proving your identity. We will reply within a maximum of one month.

Please remember the limitation set out in section 3.2 regarding traveller register data.

9. Complaint to the supervisory authority

If you believe that the processing of your data does not comply with the rules, or that we have not dealt with your request properly, you can lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos):

10. Security

We apply appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encrypted transmission over TLS, access control, limiting data to the staff who need to know it, and selecting suppliers that offer sufficient guarantees.

11. Accuracy of the data

The data you give us must be true and up to date. When you provide third-party data — for example, that of your companions — you warrant that you have informed them in advance of the content of this policy and that you have their authorisation.

12. Amendments

This policy may be updated to adapt it to regulatory changes or to new processing activities. We recommend that you review it periodically.

Last updated: August 2026.

Hello! Can I help you with anything? 🌿