PRIVACY POLICY
1. DATA CONTROLLER IDENTIFICATION
In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation – GDPR), as well as applicable data protection legislation, users of this website are informed of the identity of the Data Controller:
Data Controller: GRAND HOTEL CENTRAL BARCELONA, S.L.U.
Tax Identification Number (NIF): B65256877
Registered Address: Via Laietana, 30, 08003 Barcelona, Spain
Email: info@grandhotelcentral.com
Website: www.grandhotelcentral.com
For any questions relating to the processing of your personal data, you may contact us using the details provided above.
2. PURPOSES OF PROCESSING PERSONAL DATA
The personal data provided by users may be processed for the following purposes:
a) Management of Enquiries and Information Requests
To respond to enquiries, requests for information, communications, and any other contact initiated by users through contact forms, email, telephone, or other communication channels made available by the Hotel.
b) Reservation Management and Provision of Hotel Services
To manage bookings, reservations, accommodation services, events, hospitality services, and any additional services requested by guests.
c) Compliance with Legal Obligations
To comply with legal obligations applicable to the hospitality sector, including the communication of guest information to competent authorities where required by law.
d) Administrative, Accounting and Tax Management
To manage invoicing, payments, collections, customer service, claims, and all administrative activities arising from the contractual relationship with customers.
e) Marketing Communications
To send information regarding services, promotions, special offers, events, and other commercial communications where a valid legal basis exists.
f) Security and Fraud Prevention
To ensure the security of our facilities, systems, and services, as well as to prevent fraudulent activities and misuse of the Website.
g) Improvement of User Experience
To analyse Website usage, generate statistical information, and improve the content, functionality, and services offered through the Website.
3. LEGAL BASIS FOR PROCESSING
The processing of personal data carried out by GRAND HOTEL CENTRAL BARCELONA, S.L.U. is based on one or more of the following legal grounds:
Consent of the Data Subject
Where the user voluntarily provides personal data, subscribes to marketing communications, or expressly consents to a specific processing activity.
Performance of a Contract or Pre-Contractual Measures
Where processing is necessary to manage reservations, provide hotel services, or respond to requests made prior to entering into a contractual relationship.
Compliance with Legal Obligations
Where processing is necessary to comply with obligations imposed by applicable laws and regulations.
Legitimate Interests
Where processing is necessary to ensure security, prevent fraud, improve services, manage customer relationships, or pursue other legitimate business interests, provided that such interests do not override the rights and freedoms of data subjects.
4. CATEGORIES OF PERSONAL DATA PROCESSED
Depending on the purpose of processing, we may collect and process the following categories of personal data:
• Identification data (name, surname, identification document details).
• Contact details (email address, telephone number, postal address).
• Reservation and accommodation information.
• Billing and payment information.
• Website browsing and usage data.
• Any information voluntarily provided by users through forms, emails, or other communications.
Users are responsible for ensuring that the personal data provided is accurate, complete, and up to date.
5. DATA RETENTION PERIODS
Personal data will be retained for as long as necessary to fulfil the purposes for which it was collected and thereafter for the periods required by applicable legal obligations.
As a general rule:
• Enquiries and information requests: up to twelve (12) months from the last communication.
• Customer and reservation data: for the duration of the contractual relationship and subsequently for the legally required retention periods.
• Accounting and tax-related information: for the periods established under applicable tax and commercial legislation.
• Marketing communications: until consent is withdrawn or the data subject objects to receiving such communications.
6. RECIPIENTS OF PERSONAL DATA
Personal data may be disclosed to:
• Public authorities and government agencies where legally required.
• Financial institutions for payment processing purposes.
• IT service providers and other processors acting on behalf of the Data Controller.
• Booking platforms, travel agencies, and commercial partners where necessary for the provision of requested services.
Personal data will never be sold or disclosed to third parties for their own marketing purposes without the prior consent of the data subject.
7. INTERNATIONAL DATA TRANSFERS
As a general rule, personal data will be processed within the European Economic Area (EEA).
However, certain technology providers may process data outside the EEA. In such cases, GRAND HOTEL CENTRAL BARCELONA, S.L.U. will ensure that appropriate safeguards are implemented in accordance with Articles 44 et seq. of the GDPR, including the use of Standard Contractual Clauses or other legally recognised transfer mechanisms.
8. DATA SUBJECT RIGHTS
Data subjects may exercise the following rights at any time:
• Right of access.
• Right to rectification.
• Right to erasure ("right to be forgotten").
• Right to object.
• Right to restriction of processing.
• Right to data portability.
• Right to withdraw consent at any time.
To exercise any of these rights, please send a written request together with proof of identity to:
Email: info@grandhotelcentral.com
Requests will be handled within the timeframes established by applicable data protection legislation.
9. RIGHT TO LODGE A COMPLAINT
If you believe that the processing of your personal data infringes applicable data protection laws, you have the right to lodge a complaint with the competent supervisory authority.
In Spain, the competent authority is:
Spanish Data Protection Agency (AEPD)
Website: https://www.aepd.es
You may also contact the supervisory authority in the country where you reside, work, or where the alleged infringement occurred.
10. CHILDREN'S DATA
The services offered through this Website are not specifically directed at children under the age of fourteen (14).
Where required by applicable law, the processing of personal data relating to minors will only take place with the prior consent of their parents or legal guardians.
11. SECURITY MEASURES
GRAND HOTEL CENTRAL BARCELONA, S.L.U. has implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risks associated with the processing of personal data.
These measures are designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
12. THIRD-PARTY WEBSITES
The Website may contain links to third-party websites.
GRAND HOTEL CENTRAL BARCELONA, S.L.U. is not responsible for the privacy practices, content, or policies of such websites. Users are encouraged to review the privacy policies of any third-party websites they visit.
13. COOKIES
The use of cookies and similar technologies is governed by our Cookies Policy, which is available on this Website.
14. CHANGES TO THIS PRIVACY POLICY
GRAND HOTEL CENTRAL BARCELONA, S.L.U. reserves the right to amend this Privacy Policy at any time to reflect changes in legislation, regulatory requirements, business practices, or technological developments.
Any updates will be published on this page and will become effective upon publication.
Last Updated: 2026
