Privacy Policy
1. Data controller
In accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), Organic Law 3/2018 (LOPDGDD), the rules derived from Directive 2002/58/EC (ePrivacy), the LSSI-CE (where applicable to cookies/electronic communications), Regulation (EU) 2024/1689 (Artificial Intelligence Act) where applicable, and other applicable European and Spanish law, the data controller is:
Company: HERMANOS VARELA LUIS SL
Tax ID (CIF): B67073320
Registered office: Travessera de les Corts 356, 08029 Barcelona, Spain
Commercial Registry: Barcelona Commercial Registry, Section 8, Sheet B-509004, entry 4 (I/A 4); background: Volume 46087, Folio 53
Legal and privacy email: legal@hostelella.com
HOSTELELLA has not formally appointed a Data Protection Officer where this is not mandatory under Article 37 GDPR and Article 34 LOPDGDD. If this becomes mandatory in the future or one is appointed voluntarily, the corresponding contact will be published and the AEPD notified where applicable. This conclusion will be reviewed periodically and before scaling processing involving large-scale regular and systematic monitoring, special categories or new high-risk features.
2. Scope, recipients and B2B nature
HOSTELELLA is a professional digital platform (SaaS and, where applicable, marketplace features and business-to-business interactions) intended exclusively for business and commercial use (B2B), offering tools for operational management, document processing, team and shift management, and analytical assistance.
The Service is not intended for personal, household or consumer use. Users act in a professional or business context. When a user contracts, configures a business or accepts terms on behalf of a company, they must have sufficient authority to do so.
3. Exclusion of minors as users
Access to and use of the Service as a user is reserved for adults. Users must be at least 18 years old. HOSTELELLA does not deliberately collect or process the personal data of minors acting as users.
Important clarification: the 18-year restriction applies to whoever uses the platform. By contrast, the data of persons managed by the business Customer (e.g., employees included in shift planning) may, where applicable, relate to minor workers lawfully employed. In that case, the Customer acts as Controller and is solely responsible for the legality of employing minors and for complying with labor rules protecting minors (working hours, rest, night work, etc.). Any access to or use of the platform by a minor is unauthorized and contrary to the intended scope of the Service.
4. Categories of data subjects
- End users of business customers (owners, administrators, managers and employees).
- Customer workers whose data is managed in the Service (e.g., for shifts, team and planning), including, where applicable, lawfully employed minors.
- Persons requesting information, diagnosis, support or commercial contact via the website.
- Professional contacts of suppliers, distributors or partners (if applicable).
- Legal representatives and contact persons of customers (billing/commercial relationship).
5. Categories of personal data processed
Depending on the use of the Service, the following categories of data may be processed:
- Identification and contact data (e.g., name, email, professional phone).
- Authentication and account data (e.g., login identifiers, role, business membership, invitations).
- Subscription and billing data: plan, subscription status and periods, trial eligibility and use, amounts, currency, taxes, invoices, retries, cancellations, refund requests and status, and provider customer, payment or subscription references.
- Minimized payment data: brand and last digits when supplied by the provider, payment-method country, and a non-reversible cryptographic fingerprint used to prevent trial abuse. HOSTELELLA does not receive or store the full card number (PAN) or CVC.
- Business and operational information entered into the Service.
- Documents and financial, accounting and commercial data (invoices, receipts, expenses, sales, delivery notes, equivalent documents).
- Labor and workforce-planning data entered or configured by the Customer: contract hours and type, department or operational area, minimum rest, shift-band preferences, declared availability, minor-age indicator, assigned shifts, clock-ins/attendance and absences or time off (holidays, leave, public holidays, sick leave).
- Personal data of employees, suppliers or customers included in documents uploaded by business customers.
- Technical, security and usage data (e.g., IP, logs, device/browser info, timestamps, security events).
- Data derived from communications (e.g., incidents, support, transactional messages, notifications, team chat).
- Data entered in commercial or diagnostic forms (e.g., contact, business, needs and messages).
- Communication preferences and email delivery data (e.g., opt-in/opt-out for product or commercial communications, preferred language, date and proof of consent or objection, delivery status, bounces and, where lawfully enabled, invitation open/click events or aggregated communication metrics).
- Prompts, queries, content sent to AI features and generated results when the user decides to use such features.
5.1 Data that may reveal sensitive information (absences)
Managing absences and time off may include categories such as “sick leave”. Where an absence is linked to sick leave, that information may reveal data concerning health (a special category under Article 9 GDPR). In these cases:
- The business Customer is the Controller and must have an adequate legal basis (typically Article 9.2.b GDPR, in connection with employment and social-security obligations) and apply the required safeguards.
- HOSTELELLA applies minimization: for shift planning only the unavailability period is needed. The reason or type of absence is not transmitted to AI providers.
- The Customer must avoid entering more health data than strictly necessary and must not record diagnoses or clinical details in free-text fields.
Other than the above, the Service is not designed to process special categories under Article 9 GDPR. The Customer must not upload them unless it has an adequate legal basis, it is necessary and sufficient safeguards are applied.
6. Source of the data
- Data provided by the user when creating the account or completing their profile.
- Data provided by other users/administrators of the same business (e.g., invitations, role assignment, user onboarding, team labor and shift configuration).
- Data included in documents and records uploaded by the business customer.
- Data collected automatically through use of the Service (technical, security, analytics).
- Data obtained from third parties when the customer integrates external services or a marketplace is used (if applicable), in accordance with applicable law.
- Data received from Stripe, Apple or Google regarding the outcome and lifecycle of payments, subscriptions, refunds or external-purchase reports when the relevant channel is enabled.
7. Allocation of roles (Controller / Processor / Joint controller)
7.1 When HOSTELELLA acts as Controller
HOSTELELLA acts as Controller in respect of the data needed to operate the Service, such as: account administration, authentication, access control, security, fraud/abuse prevention, support, service communications, trials, subscriptions, billing, collection and refunds.
HOSTELELLA personnel access to personal data is limited to authorized persons bound by confidentiality and a need to know for requested support, security, continuity, compliance or incident investigation. Risk-appropriate least privilege and logging apply; there is no unrestricted commercial access to business data.
Stripe may act as a processor for certain activities performed under HOSTELELLA's instructions and as an independent controller for regulatory, fraud-prevention, security, compliance and payment-network operations. Its own terms and privacy notice supplement this information.
7.2 When HOSTELELLA acts as Processor
When business customers upload business documents and records or configure staff data (including shift, team and absence management) containing personal data of employees, customers, suppliers or other third parties, HOSTELELLA acts as Processor on behalf of the business customer, in accordance with the corresponding Data Processing Agreement (DPA) under Article 28 GDPR.
In these cases, the business customer remains the Controller and is solely responsible for: (i) informing data subjects, (ii) having an adequate legal basis, (iii) handling rights and (iv) complying with applicable obligations, including labor obligations (working hours, rest, protection of minors and informing workers' legal representatives).
7.3 Joint controllership (if applicable)
In certain flows (e.g., marketplace features, business-to-business communications or exchange of orders/data between parties), HOSTELELLA and other entities may jointly determine the purposes and means of processing and act as joint controllers under Article 26 GDPR. In those cases, the applicable framework of responsibilities and the contact point for exercising rights will be defined. Joint controllership is not presumed by default and will only apply where an agreement, configuration or flow justifies it.
8. Purposes of processing
- Provision, operation, maintenance, improvement and evolution of the Service. Where data forms part of a Customer processing mandate, improvement stays within its instructions; general improvement uses minimal telemetry and anonymous or aggregated data.
- User authentication, management of roles, permissions and access, and business administration on the platform.
- Processing, extraction and analysis of documents (including OCR/AI) at the user's express request.
- Team, working-time and shift-planning management, including AI-assisted generation of shift proposals at the Customer's request, as a support tool subject to human review.
- Generation of reports, metrics, insights and operational recommendations.
- Customer support and service communications (including security alerts and transactional notices).
- Administer the free trial, purchase and manage plans, process charges and renewals, issue invoices or receipts, handle failed payments, cancellations and refund requests, and evidence authorization for future charges.
- Prevent trial abuse and payment fraud through minimized signals and resolve disputes.
- Comply with external-purchase information and reporting duties to Apple or Google where a user purchases through a mobile channel subject to those programs.
- Optional communications, only if you have turned them on: news and functional changes, how-to guides, setup tips, notices about new features and invitations to try them, newsletters, content, use cases, event invitations, surveys, offers and promotions about HOSTELELLA, as well as aggregated measurement of the effectiveness of such communications.
- Managing your communication preferences: recording and evidencing what you have turned on or off, handling opt-outs, and maintaining the suppression list that prevents us from contacting you again.
- Security, fraud prevention, abuse detection, internal audit and incident response.
- Compliance with applicable legal, tax, accounting and audit obligations.
- Defense against legal claims and protection of rights and legitimate interests.
9. Legal bases
We process personal data on one or more of the following legal bases:
- Performance of a contract (Art. 6.1.b GDPR): to provide and operate the Service.
- Compliance with a legal obligation (Art. 6.1.c GDPR): to comply with applicable law (e.g., tax/accounting where applicable).
- Legitimate interest (Art. 6.1.f GDPR): security, fraud/abuse prevention, proportionate Service improvement using data for which HOSTELELLA is controller, legal protection and business continuity, after balancing necessity, impact and reasonable expectations.
- Consent (Art. 6.1.a GDPR): device permissions, non-essential cookies and all optional communications — news, tips, offers, promotions, events and surveys — whether or not you are already a customer. See section 22.
For data processed on behalf of the Customer (including shift planning and team management), the legal basis vis-à-vis the workers is determined by the Customer as Controller (typically performance of the employment contract, compliance with labor obligations, or a legitimate interest in organizing work).
| Purpose | Main legal basis | Notes |
|---|---|---|
| Account, authentication, roles and provision of the Service | Contract or pre-contractual measures; legitimate interest in security | Necessary to operate a professional account. |
| Documents, OCR/AI, reports and business data uploaded by the Customer | Processing on behalf of the Customer; contract | The Customer decides the legal basis towards its employees, customers, suppliers or third parties. |
| Team, working-time, shifts and absences management (incl. AI-assisted generation) | Processing on behalf of the Customer; the Customer determines the labor basis towards its workers | Support tool with human review; the Customer retains the final decision. |
| Support, incidents, security notices and transactional communications | Contract and legitimate interest | Not commercial communications unless expressly stated. |
| Billing, accounting, tax obligations and legal defense | Legal obligation and legitimate interest | Statutory periods and blocking apply where relevant. |
| Trial, purchase, renewal, cancellation, collection and refunds | Contract or pre-contractual steps; legal obligation; legitimate interest in fraud prevention | Stripe processes full payment-method details. Future charges require express authorization, evidence of which is retained. |
| External-purchase reporting to Apple or Google | Performance of the contract and obligations undertaken to distribute the App; legitimate interest in maintaining the channel | Only where the relevant channel, territory and platform rules require reporting. |
| Non-essential web analytics | Consent | Google Analytics is loaded only after analytics/cookie acceptance. |
| Optional communications: product news, guides, tips, newsletters, offers, promotions, events and surveys | Consent (Art. 6.1.a GDPR) and Art. 21.1 LSSI-CE | Although the Spanish LSSI-CE would allow us to rely on its Art. 21.2 "own similar products or services" case for existing customers, we have decided not to use that exemption: we ask for prior, express and separate consent for every optional communication. Never a condition for providing the Service, and always with one-click unsubscribe. See section 22. |
| Open and click measurement in team invitations | Legitimate interest (Art. 6.1.f GDPR) for subsequent processing and, for terminal access, prior consent where required by Art. 22.2 LSSI-CE/ePrivacy | It may be enabled only where both regulatory layers are met or a documented statutory exception applies. Otherwise processing is limited to technical delivery status. See section 12. |
| Management of preferences, opt-outs and proof of consent (suppression list) | Legal obligation (Arts. 5.2 and 7.1 GDPR) and legitimate interest | We keep the minimum data needed not to contact you again and to demonstrate compliance. |
Data marked as necessary to create an account, purchase, bill, protect the Service or meet legal duties is contractually or legally required: failure to provide it may prevent registration, payment or the affected service. Device permissions, non-essential cookies and optional communications are voluntary; refusing them does not reduce unrelated features. You may object to legitimate-interest processing on grounds relating to your particular situation by writing to legal@hostelella.com. HOSTELELLA will stop unless it demonstrates compelling legitimate grounds or needs the data for legal claims.
Data of our customers' workers. Data we process as a processor on behalf of a Customer (e.g., the team registered by a business, their shifts, clock-ins, or contacts contained in uploaded documents) is not used for HOSTELELLA's own marketing. The only way a person can receive an optional communication from us is by registering and turning it on themselves in their preference centre (section 22.2). We never buy or rent contact lists.
10. Device permissions (Mobile app)
For certain features, the App may request optional device permissions:
- Camera / gallery access: to capture or upload photos and documents (e.g., invoices, receipts) for analysis.
- Attachment metadata: attached images are processed before upload to remove technical metadata, including EXIF/GPS, where the format allows. Documents uploaded by the Customer (e.g., PDF) may contain metadata embedded by the Customer or its authoring tools; HOSTELELLA processes them as part of the content/documentation provided for OCR, analysis and operations, and not as location data used for maps or proximity.
- Microphone access: for voice/dictation features (if enabled).
- Contacts access: to invite team members or suggest contacts (if enabled).
- Location access: only when the employing business enables presence verification at clock-in/out (see section 10.1). The App does not use location for maps, proximity or any other purpose, and never accesses it in the background.
The operating-system authorization permits technical access to the device and can be revoked in its settings. It does not by itself determine the GDPR legal basis: for employment location verification the employer determines that basis under section 10.1 and it is not worker consent. Revocation may limit the affected feature but will not prevent basic use where possible.
10.1 Location verification at clock-in/out (optional per business)
The employing business may optionally enable presence verification for the working-time record (clock-in/out). When enabled, the App captures a single, one-off position at the moment of clocking in or out, always in the foreground and after requesting the device's location permission. The position is sent to the server, which calculates the distance to the verified address of the workplace, for the sole purpose of verifying that the person is at the workplace when clocking in or out. There is no continuous tracking, no background capture and no capture outside the moment of clocking in or out.
- What is stored: only the verification result (inside/outside or equivalent) and the approximate distance to the workplace. The worker's coordinates are never stored: they are processed ephemerally on the server during the request and are not written to logs or to any storage.
- Roles and legal basis: the employing business is the Controller of this processing and HOSTELELLA acts as Processor under the DPA. The legal basis is determined by the employer, typically the employer's power to monitor work performance (Art. 20.3 of the Spanish Workers' Statute) and the working-time record (Art. 34.9), subject to the prior-information duty of Article 90 LOPDGDD; it is not based on the worker's consent.
- Proportionality and DPIA: before enabling it, the employer must document necessity, suitability, proportionality, less intrusive alternatives, consultation/information of representatives where applicable, and assess Article 35 GDPR criteria. If processing may create high risk — including a combination of employment monitoring, location or systematic evaluation — it must complete a data-protection impact assessment before use.
- Retention: the result and the approximate distance are kept together with the working-time record they accompany (generally 4 years under Art. 34.9 of the Spanish Workers' Statute).
- Alternative: the business may enable clocking in/out from a shared device at the workplace itself, which requires no location permission and captures no position; its availability is at the business's discretion.
If the business does not enable this feature, the App does not request location permission. The above does not change the attachment-metadata processing described in this same section: attached images are still processed before upload to remove technical metadata, including EXIF/GPS, where the format allows.
10.2 Daily working-time record (clock-ins) and who can see it
The employing business is the Controller of the daily working-time record of its staff (Art. 34.9 of the Spanish Workers' Statute) and HOSTELELLA acts as Processor under the DPA. The legal basis is the employer's compliance with that legal obligation (Art. 6.1.c GDPR); it is not based on the worker's consent. The employer organises and documents the record in accordance with labour law (collective bargaining, company agreement or employer decision after consulting workers' representatives) and informs its staff of its existence and purpose; this Policy supplements that information.
- What is recorded: the specific start and end time of each working day, using the server clock; where the person manually indicates the clock-out time, it is marked as "time indicated". Breaks are not recorded unless the business configures it.
- Integrity and traceability: each clock-in/out is linked to an audited event; corrections made by managers keep the previous value, the new value, who made them and when. Automatic safety closures are identified as such.
- Who can see the record: the worker (their own clock-ins and history), and those who manage the record on behalf of the business: the owner and people with admin or manager permission, in respect of lower-ranked people. Workers' legal representatives and the Labour Inspectorate access it through the business, which can export the record at any time. The record is not visible to other co-workers.
- Team presence (optional): the business may enable the team to see, in the internal chat, who is working at that moment (avatar and name of those who clocked in and are still in), for the sole purpose of coordinating the shift. In that case no clock-in/out times, lateness, overtime or any other record data are shown to the rest of the team. The business can disable it at any time.
- Notices to managers (optional): managers may receive a notice for each clock-in/out of their team and reminders when a clock-in/out is missing; those notices are not sent to the rest of the staff.
- Permissions assigned by the business: the business decides each person's permission. Whoever is granted manager, admin or owner permission can see and correct the clock-ins of lower-ranked people; the app warns of this when the permission is assigned, and that decision belongs exclusively to the business as Controller.
- Retention: four years from each clock-in/out (Art. 34.9 Workers' Statute), also after the person leaves the business. If the business stops using the Service, it can export the full record before deletion (see Retention Policy).
- Biometrics: HOSTELELLA does not perform biometric identification. Any fingerprint or face unlock the person enables in the app runs on their own device with the manufacturer's means; the business receives and stores no biometric data.
- Location verification: only if the business enables it and under the terms of section 10.1.
11. Artificial Intelligence and automated processing
HOSTELELLA may use automated processing and artificial intelligence to extract information from documents, classify data, assist with queries and generate shift-planning proposals, and to resolve the applicable labor framework or collective agreement based on the business's location and sector.
These features are designed as assistance and productivity tools, not as a substitute for human review nor as a system intended by default to make labor, tax, accounting, credit, legal or significantly impactful decisions. AI-generated shift proposals require human review and approval (by a person with a manager role or above) before publication or application; the Customer and its managers retain the final decision at all times.
No solely automated decisions. HOSTELELLA does not make decisions based solely on automated processing that produce legal effects on individuals or similarly significantly affect them within the meaning of Article 22 GDPR. Shift generation is decision support subject to human intervention.
Artificial Intelligence Act (EU 2024/1689). AI features are conceived as support tools. HOSTELELLA may be the provider or downstream provider of the integrated system and the Customer the deployer in its organization; each party retains its mandatory duties. Both must take AI-literacy measures for persons operating the system. Where a feature is used in the employment context, intended and actual use must be classified and documented, with an impact assessment and safeguards where required. The Customer must ensure lawful use, competent human oversight with authority, prior information to affected persons and retention of logs under its control. In Spain, it must also respect workers' representatives' right to information about parameters, rules and instructions of algorithms or AI systems affecting working conditions (Art. 64.4.d Workers' Statute).
To minimize processing, before sending information to AI providers measures such as pseudonymization are applied (e.g., the shift generator operates with initials and operational data, not full names) and unnecessary data is excluded (e.g., the reason for absences is not transmitted). Results may contain inaccuracies or limitations. The Service is not designed for biometric identification, social scoring, emotion recognition, recruitment, automated disciplinary assessment or other prohibited or high-risk purposes unless under specific contract, assessment and safeguards. HOSTELELLA does not use Customer Data to train its own or third parties' models unless under express authorization, specific contract or clear Customer configuration.
11.1 Cross-business learning (not active)
We are designing a feature that would let a business authorize its document-reading quality to contribute, in the form of aggregated signals within minimum-size cohorts, to improving the accuracy of the Service for every business. This feature is not active. Today, each business's documents, data and corrections are used for that business only, and nothing leaves it towards shared learning.
When it does become available, it will be enabled only with the express authorization of each business owner, after completing the corresponding impact assessment, and under these conditions: documents, text, names, tax IDs, suppliers, products and amounts will never leave the business; only data created after the authorization will be used, never historical data; the authorization will be revocable at any time with immediate effect on future contributions; and publishing any aggregated result will require minimum thresholds of businesses and samples. We will explain all of this here and inside the App before asking you for anything.
12. Cookies and tracking technologies (web/PWA)
On the website and/or PWA, HOSTELELLA may use cookies, pixels or similar technologies for:
- Essential: operation, security, load balancing, authentication and fraud prevention.
- Analytics/measurement: Google Analytics to understand aggregated usage of the public website and improve performance and experience, only with prior consent.
- Preferences: remembering user settings (if enabled).
Non-essential cookies will only be used where consent exists, in accordance with ePrivacy and applicable law. The specific Cookies Policy supplements this information and prevails for granular cookie management.
Email measurement. We draw a precise distinction between two levels, because they are not the same thing.
- Delivery (all emails). We record the technical outcome of the send — delivered, bounced, failed or marked as spam — because without it we could not tell whether a necessary communication arrived, nor stop writing to an address that permanently bounces. It says nothing about whether you read the message.
- Opens and clicks (team invitations only). An invitation email may embed a pixel and measurement links so the inviter can tell whether it was opened and decide whether to resend it. Because those techniques access the recipient's terminal, they will be enabled only with prior consent where required by Art. 22.2 LSSI-CE/ePrivacy, in addition to a GDPR basis for subsequent processing, or where a documented statutory exception applies. Otherwise only technical delivery status is processed. When lawfully used, the data is shown only in the inviting business and erased on acceptance, expiry or revocation. No other necessary email measures opens or clicks.
- Optional communications. In this version of the Service we do not measure individual opens or clicks in news, tips or offers. Should we ever do so, it would be a separate option from receiving the emails themselves, off by default in your preference centre.
Blocking remote images is an additional control; it does not replace any consent legally required. We never use this information to build profiles producing legal or similarly significant effects on you.
13. Recipients, processors and sub-processors
We do not sell personal data. Data may be accessible to selected providers acting as processors/sub-processors under contractual obligations of confidentiality, security and compliance, including providers of:
- Cloud infrastructure, hosting and storage.
- Databases and authentication.
- Email and communications.
- Payment processing, billing, fraud prevention and subscription management, primarily Stripe.
- AI and document-processing technologies, including Azure OpenAI, Anthropic (Claude models) when shift/labor or assistant features are used, and OpenAI when configured as a non-Azure provider.
- Monitoring, analytics and security tools, including Google Analytics when the user accepts web analytics.
Each recipient receives only the data necessary for its function. Providers acquire no right to reuse Customer Data for advertising, their own profiling or model training; where they act as independent controllers — for example, certain regulatory payment or mobile store activities — their own responsibilities and policies are identified.
Under external-purchase programs for iOS or Android, Apple and Google may receive reporting identifiers or tokens, country, amount, currency, date and transaction status in order to administer their programs and fees. They act under their own terms and responsibilities. HOSTELELLA does not send them the full card number.
When HOSTELELLA acts as a processor, sub-processors are governed by the DPA, the Sub-processors Annex and the requirements of Article 28 GDPR. The up-to-date list of sub-processors is published in the Sub-processors Annex.
14. Authorities and defense of rights
We may disclose data to competent authorities where there is a legal obligation or legitimate request, and/or to defend rights, prevent fraud, ensure security or respond to claims, in accordance with the GDPR.
15. Corporate restructurings
In the event of a merger, acquisition, reorganization, sale of assets or equivalent procedures, data may be disclosed to third parties to the extent necessary and proportionate, with adequate safeguards.
16. International transfers
Where international transfers of data outside the European Economic Area occur, we apply adequate safeguards, including adequacy decisions, Standard Contractual Clauses (SCCs), the EU-US Data Privacy Framework where applicable and supplementary measures, in accordance with Articles 44–49 GDPR. Certain AI and communications providers are located in the United States; in such cases the above mechanisms and the minimization described in this Policy apply. Stripe payment services may involve global processing by its entities, financial institutions and payment-method providers under its DPA, terms and applicable safeguards.
In certain cases there may be a risk of access by authorities of third countries. In such cases we will apply supplementary measures where appropriate and, where necessary, inform and/or obtain consent in accordance with applicable law.
17. Data retention
We retain personal data only for as long as necessary for the purposes described in this Policy and for the periods required by legal, tax, accounting, audit and security obligations. Thereafter, data will be deleted or anonymized, unless there is a retention obligation or a need to defend claims.
Retention is detailed in the Retention Policy. When HOSTELELLA acts as a processor, retention is governed by the DPA and the customer's instructions, without prejudice to legal obligations.
A deliberate exception: proof of your decisions. The record of when you turned an optional communication on or off — and the cryptographic fingerprint of your address in the suppression list — are retained even if you close your account. That is the only way to guarantee we will not write to you again and to demonstrate to the supervisory authority that we respected your decision (Arts. 5.2 and 7.1 GDPR). That record is kept blocked, separate from the rest, and is not used for any other purpose.
18. Security measures
HOSTELELLA applies appropriate technical and organizational measures (Art. 32 GDPR) to ensure a level of security appropriate to the risk. The Security Policy describes the main measures, including access control, least privilege, encryption where appropriate, activity logging, incident management and service continuity.
Nonetheless, no system can guarantee absolute security. Users are responsible for keeping access to their accounts and devices secure.
19. Personal data breaches
In the event of a personal data breach, HOSTELELLA will follow internal procedures to assess the risk and, where appropriate, notify the competent supervisory authority and/or affected persons in accordance with Articles 33 and 34 GDPR.
When HOSTELELLA acts as a processor, notifications to the controller will be handled in accordance with the DPA.
20. Rights of data subjects
Data subjects may exercise their rights of access, rectification, erasure, restriction, objection and portability, as well as withdraw consent where applicable, by contacting: legal@hostelella.com.
We may request reasonable information to verify identity or representation. We will respond within one month of receipt of the request; this period may be extended by up to two additional months where necessary due to complexity or number of requests, informing the requester in accordance with the GDPR.
If the request relates to data processed by HOSTELELLA as a processor on behalf of a business customer, we may refer the requester to the relevant controller, who is the party that must handle the request.
Objection to direct marketing. Under Articles 21.2 and 21.3 GDPR, you may object at any time to the processing of your data for direct marketing purposes, including related profiling. This is an absolute right: no balancing test applies and we will stop processing your data for that purpose immediately. See section 22.
21. Complaints
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD).
22. Communications and preferences
22.1 How we classify what we send you
Every message that leaves HOSTELELLA belongs to one of these three classes. The class determines its legal basis and whether you can opt out.
| Class | Examples | Legal basis | Opt-out |
|---|---|---|---|
| Necessary | account verification, sign-in and password recovery, security alerts, team invitations, billing and failed payments, changes to these legal documents, incidents and operational notices you asked for yourself | Performance of the contract (Art. 6.1.b GDPR) and compliance with legal obligations (Art. 6.1.c GDPR) | No unsubscribe link: it is part of the Service while you have an active account |
| Optional | product news, management tips, offers, promotions, events and surveys | Prior, express and separate consent (Art. 6.1.a GDPR and Art. 21.1 LSSI-CE) | Mandatory, one click, in every message |
| The Customer's | the purchase order or claim a business sends to its supplier from the platform | The Customer's instruction: HOSTELELLA acts as processor and the actual sender is the business | Not applicable: it is not a HOSTELELLA commercial communication |
Accepting the Terms, acknowledging this Policy or signing the Data Processing Agreement does not enable any communication in the Optional class. Granting the operating system's notification permission does not either: that permission enables a technical capability, not a commercial purpose. And giving us a phone number does not authorize us to call or text you.
22.2 Your preference centre
Inside the App, under Account → Preferences → Privacy and communications, you can see and change at any time which optional communications you accept. This preference is yours as a person and does not depend on the business you are working in: if you belong to several businesses, it is still a single decision.
- Every optional purpose is off by default. We do not use pre-ticked boxes and we do not infer your consent from your sign-up, your activity, your plan, your role or the fact that you gave us your email address.
- The purpose and the approximate frequency are described on the screen itself, next to the control, not behind a link.
- Each time you turn an option on or off we record a new event with the date and time, the version and hash of the exact text shown to you, the language and the origin of the decision (App settings or a link in an email). That record is the evidence required by Article 7.1 GDPR; it is never overwritten, only appended to.
- Withdrawing consent is as easy as giving it and takes effect immediately for future sends, including messages already prepared. It does not affect the lawfulness of prior processing.
- Refusing or withdrawing consent does not limit any feature of the Service and does not change your plan.
22.3 One-click unsubscribe
Every optional communication includes an unsubscribe link that works in a single click, without signing in and without asking you for a
reason, plus the List-Unsubscribe and List-Unsubscribe-Post technical headers so that your own email client can
offer you its unsubscribe button. The link uses a random, single-use, expiring identifier: it never carries your email address or phone number.
When you unsubscribe we do two things in the same operation: we record the preference change and we add a cryptographic fingerprint of your address (HMAC-SHA256 with a key we keep separately; we never store your address in clear text in that list) to a suppression list. That list takes precedence over any prior consent and over any message already queued. We also add addresses to it automatically when they bounce permanently or when someone marks one of our emails as spam.
We handle opt-outs free of charge and without undue delay. You can also write to legal@hostelella.com or manage your preferences from your account settings.
22.4 Channels we do not use yet
In this version of the Service, optional communications are sent by email only. We do not send commercial SMS or WhatsApp messages, we do not make commercial phone calls and we do not display third-party advertising inside the App. Should we ever add any of those channels, it would appear as its own option, off by default, with its own consent and its own opt-out; and before using the telephone we would check advertising exclusion registries where the law requires it.
22.5 How we decide what to send you
Before an optional message is prepared, and again immediately before it is handed to the email provider, the system checks that the template is classified, that the purpose is allowed, that no active suppression exists and that your consent is still valid against a valid version of the text. If any of those conditions is missing, the send is blocked and logged: the system's default behaviour is not to send.
We may use automated systems to choose between already approved templates, adjust frequency or timing, and reduce or pause sending if we detect low interest or complaints. Those systems can never create a new purpose, infer a consent you did not give, reactivate an opt-out or change your preferences.
22.6 Limits we commit to
- We do not sell, rent or transfer contact data to third parties for advertising purposes.
- We do not buy lists or scrape email addresses.
- We do not use for our own marketing the data we process as a processor on behalf of a Customer: team, shifts, clock-ins, suppliers, products, amounts or contacts contained in uploaded documents.
- We do not send third-party advertising and do not disclose your email to advertisers.
- We do not take automated decisions producing legal or similarly significant effects about you based on your interaction with our emails.
- At most, we segment by language, business type, plan and level of Service usage, in order to reduce irrelevant messages.
If you receive a commercial communication from us that you consider unsolicited, write to legal@hostelella.com: we will investigate it, unsubscribe you immediately and fix the source.
23. Third-party links
The platform may contain links to third-party services (e.g., maps, integrations). HOSTELELLA is not responsible for the privacy practices of such third parties. We recommend reviewing their respective policies.
24. Changes to this Policy
This Privacy Policy may be updated to reflect legal, regulatory or operational changes. The current version will be available within the Service. Material changes will be prominently communicated before they take effect where required and will not retroactively legalize processing. Where a new purpose requires consent, it will be requested separately before processing begins.
25. Limitation of liability (Privacy)
Nothing in this Policy limits the mandatory rights provided by data-protection law. To the maximum extent permitted by law, HOSTELELLA will not be liable for damages arising from: (i) misuse of the Service, (ii) unlawful data uploads by customers/users, or (iii) actions taken solely on the basis of informational results, including AI proposals applied without the required human review.