HOSTELELLA Legal documentation

Privacy Policy

Version 1.9 Effective 29 August 2026 GDPR · LOPDGDD

1. Data controller

In accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), Organic Law 3/2018 (LOPDGDD), the rules derived from Directive 2002/58/EC (ePrivacy), the LSSI-CE (where applicable to cookies/electronic communications), Regulation (EU) 2024/1689 (Artificial Intelligence Act) where applicable, and other applicable European and Spanish law, the data controller is:

Company: HERMANOS VARELA LUIS SL
Tax ID (CIF): B67073320
Registered office: Travessera de les Corts 356, 08029 Barcelona, Spain
Commercial Registry: Barcelona Commercial Registry, Section 8, Sheet B-509004, entry 4 (I/A 4); background: Volume 46087, Folio 53
Legal and privacy email: legal@hostelella.com

HOSTELELLA has not formally appointed a Data Protection Officer where this is not mandatory under Article 37 GDPR and Article 34 LOPDGDD. If this becomes mandatory in the future or one is appointed voluntarily, the corresponding contact will be published and the AEPD notified where applicable. This conclusion will be reviewed periodically and before scaling processing involving large-scale regular and systematic monitoring, special categories or new high-risk features.

2. Scope, recipients and B2B nature

HOSTELELLA is a professional digital platform (SaaS and, where applicable, marketplace features and business-to-business interactions) intended exclusively for business and commercial use (B2B), offering tools for operational management, document processing, team and shift management, and analytical assistance.

The Service is not intended for personal, household or consumer use. Users act in a professional or business context. When a user contracts, configures a business or accepts terms on behalf of a company, they must have sufficient authority to do so.

3. Exclusion of minors as users

Access to and use of the Service as a user is reserved for adults. Users must be at least 18 years old. HOSTELELLA does not deliberately collect or process the personal data of minors acting as users.

Important clarification: the 18-year restriction applies to whoever uses the platform. By contrast, the data of persons managed by the business Customer (e.g., employees included in shift planning) may, where applicable, relate to minor workers lawfully employed. In that case, the Customer acts as Controller and is solely responsible for the legality of employing minors and for complying with labor rules protecting minors (working hours, rest, night work, etc.). Any access to or use of the platform by a minor is unauthorized and contrary to the intended scope of the Service.

4. Categories of data subjects

5. Categories of personal data processed

Depending on the use of the Service, the following categories of data may be processed:

5.1 Data that may reveal sensitive information (absences)

Managing absences and time off may include categories such as “sick leave”. Where an absence is linked to sick leave, that information may reveal data concerning health (a special category under Article 9 GDPR). In these cases:

Other than the above, the Service is not designed to process special categories under Article 9 GDPR. The Customer must not upload them unless it has an adequate legal basis, it is necessary and sufficient safeguards are applied.

6. Source of the data

7. Allocation of roles (Controller / Processor / Joint controller)

7.1 When HOSTELELLA acts as Controller

HOSTELELLA acts as Controller in respect of the data needed to operate the Service, such as: account administration, authentication, access control, security, fraud/abuse prevention, support, service communications, trials, subscriptions, billing, collection and refunds.

HOSTELELLA personnel access to personal data is limited to authorized persons bound by confidentiality and a need to know for requested support, security, continuity, compliance or incident investigation. Risk-appropriate least privilege and logging apply; there is no unrestricted commercial access to business data.

Stripe may act as a processor for certain activities performed under HOSTELELLA's instructions and as an independent controller for regulatory, fraud-prevention, security, compliance and payment-network operations. Its own terms and privacy notice supplement this information.

7.2 When HOSTELELLA acts as Processor

When business customers upload business documents and records or configure staff data (including shift, team and absence management) containing personal data of employees, customers, suppliers or other third parties, HOSTELELLA acts as Processor on behalf of the business customer, in accordance with the corresponding Data Processing Agreement (DPA) under Article 28 GDPR.

In these cases, the business customer remains the Controller and is solely responsible for: (i) informing data subjects, (ii) having an adequate legal basis, (iii) handling rights and (iv) complying with applicable obligations, including labor obligations (working hours, rest, protection of minors and informing workers' legal representatives).

7.3 Joint controllership (if applicable)

In certain flows (e.g., marketplace features, business-to-business communications or exchange of orders/data between parties), HOSTELELLA and other entities may jointly determine the purposes and means of processing and act as joint controllers under Article 26 GDPR. In those cases, the applicable framework of responsibilities and the contact point for exercising rights will be defined. Joint controllership is not presumed by default and will only apply where an agreement, configuration or flow justifies it.

8. Purposes of processing

9. Legal bases

We process personal data on one or more of the following legal bases:

For data processed on behalf of the Customer (including shift planning and team management), the legal basis vis-à-vis the workers is determined by the Customer as Controller (typically performance of the employment contract, compliance with labor obligations, or a legitimate interest in organizing work).

PurposeMain legal basisNotes
Account, authentication, roles and provision of the ServiceContract or pre-contractual measures; legitimate interest in securityNecessary to operate a professional account.
Documents, OCR/AI, reports and business data uploaded by the CustomerProcessing on behalf of the Customer; contractThe Customer decides the legal basis towards its employees, customers, suppliers or third parties.
Team, working-time, shifts and absences management (incl. AI-assisted generation)Processing on behalf of the Customer; the Customer determines the labor basis towards its workersSupport tool with human review; the Customer retains the final decision.
Support, incidents, security notices and transactional communicationsContract and legitimate interestNot commercial communications unless expressly stated.
Billing, accounting, tax obligations and legal defenseLegal obligation and legitimate interestStatutory periods and blocking apply where relevant.
Trial, purchase, renewal, cancellation, collection and refundsContract or pre-contractual steps; legal obligation; legitimate interest in fraud preventionStripe processes full payment-method details. Future charges require express authorization, evidence of which is retained.
External-purchase reporting to Apple or GooglePerformance of the contract and obligations undertaken to distribute the App; legitimate interest in maintaining the channelOnly where the relevant channel, territory and platform rules require reporting.
Non-essential web analyticsConsentGoogle Analytics is loaded only after analytics/cookie acceptance.
Optional communications: product news, guides, tips, newsletters, offers, promotions, events and surveysConsent (Art. 6.1.a GDPR) and Art. 21.1 LSSI-CEAlthough the Spanish LSSI-CE would allow us to rely on its Art. 21.2 "own similar products or services" case for existing customers, we have decided not to use that exemption: we ask for prior, express and separate consent for every optional communication. Never a condition for providing the Service, and always with one-click unsubscribe. See section 22.
Open and click measurement in team invitationsLegitimate interest (Art. 6.1.f GDPR) for subsequent processing and, for terminal access, prior consent where required by Art. 22.2 LSSI-CE/ePrivacyIt may be enabled only where both regulatory layers are met or a documented statutory exception applies. Otherwise processing is limited to technical delivery status. See section 12.
Management of preferences, opt-outs and proof of consent (suppression list)Legal obligation (Arts. 5.2 and 7.1 GDPR) and legitimate interestWe keep the minimum data needed not to contact you again and to demonstrate compliance.

Data marked as necessary to create an account, purchase, bill, protect the Service or meet legal duties is contractually or legally required: failure to provide it may prevent registration, payment or the affected service. Device permissions, non-essential cookies and optional communications are voluntary; refusing them does not reduce unrelated features. You may object to legitimate-interest processing on grounds relating to your particular situation by writing to legal@hostelella.com. HOSTELELLA will stop unless it demonstrates compelling legitimate grounds or needs the data for legal claims.

Data of our customers' workers. Data we process as a processor on behalf of a Customer (e.g., the team registered by a business, their shifts, clock-ins, or contacts contained in uploaded documents) is not used for HOSTELELLA's own marketing. The only way a person can receive an optional communication from us is by registering and turning it on themselves in their preference centre (section 22.2). We never buy or rent contact lists.

10. Device permissions (Mobile app)

For certain features, the App may request optional device permissions:

The operating-system authorization permits technical access to the device and can be revoked in its settings. It does not by itself determine the GDPR legal basis: for employment location verification the employer determines that basis under section 10.1 and it is not worker consent. Revocation may limit the affected feature but will not prevent basic use where possible.

10.1 Location verification at clock-in/out (optional per business)

The employing business may optionally enable presence verification for the working-time record (clock-in/out). When enabled, the App captures a single, one-off position at the moment of clocking in or out, always in the foreground and after requesting the device's location permission. The position is sent to the server, which calculates the distance to the verified address of the workplace, for the sole purpose of verifying that the person is at the workplace when clocking in or out. There is no continuous tracking, no background capture and no capture outside the moment of clocking in or out.

If the business does not enable this feature, the App does not request location permission. The above does not change the attachment-metadata processing described in this same section: attached images are still processed before upload to remove technical metadata, including EXIF/GPS, where the format allows.

10.2 Daily working-time record (clock-ins) and who can see it

The employing business is the Controller of the daily working-time record of its staff (Art. 34.9 of the Spanish Workers' Statute) and HOSTELELLA acts as Processor under the DPA. The legal basis is the employer's compliance with that legal obligation (Art. 6.1.c GDPR); it is not based on the worker's consent. The employer organises and documents the record in accordance with labour law (collective bargaining, company agreement or employer decision after consulting workers' representatives) and informs its staff of its existence and purpose; this Policy supplements that information.

11. Artificial Intelligence and automated processing

HOSTELELLA may use automated processing and artificial intelligence to extract information from documents, classify data, assist with queries and generate shift-planning proposals, and to resolve the applicable labor framework or collective agreement based on the business's location and sector.

These features are designed as assistance and productivity tools, not as a substitute for human review nor as a system intended by default to make labor, tax, accounting, credit, legal or significantly impactful decisions. AI-generated shift proposals require human review and approval (by a person with a manager role or above) before publication or application; the Customer and its managers retain the final decision at all times.

No solely automated decisions. HOSTELELLA does not make decisions based solely on automated processing that produce legal effects on individuals or similarly significantly affect them within the meaning of Article 22 GDPR. Shift generation is decision support subject to human intervention.

Artificial Intelligence Act (EU 2024/1689). AI features are conceived as support tools. HOSTELELLA may be the provider or downstream provider of the integrated system and the Customer the deployer in its organization; each party retains its mandatory duties. Both must take AI-literacy measures for persons operating the system. Where a feature is used in the employment context, intended and actual use must be classified and documented, with an impact assessment and safeguards where required. The Customer must ensure lawful use, competent human oversight with authority, prior information to affected persons and retention of logs under its control. In Spain, it must also respect workers' representatives' right to information about parameters, rules and instructions of algorithms or AI systems affecting working conditions (Art. 64.4.d Workers' Statute).

To minimize processing, before sending information to AI providers measures such as pseudonymization are applied (e.g., the shift generator operates with initials and operational data, not full names) and unnecessary data is excluded (e.g., the reason for absences is not transmitted). Results may contain inaccuracies or limitations. The Service is not designed for biometric identification, social scoring, emotion recognition, recruitment, automated disciplinary assessment or other prohibited or high-risk purposes unless under specific contract, assessment and safeguards. HOSTELELLA does not use Customer Data to train its own or third parties' models unless under express authorization, specific contract or clear Customer configuration.

11.1 Cross-business learning (not active)

We are designing a feature that would let a business authorize its document-reading quality to contribute, in the form of aggregated signals within minimum-size cohorts, to improving the accuracy of the Service for every business. This feature is not active. Today, each business's documents, data and corrections are used for that business only, and nothing leaves it towards shared learning.

When it does become available, it will be enabled only with the express authorization of each business owner, after completing the corresponding impact assessment, and under these conditions: documents, text, names, tax IDs, suppliers, products and amounts will never leave the business; only data created after the authorization will be used, never historical data; the authorization will be revocable at any time with immediate effect on future contributions; and publishing any aggregated result will require minimum thresholds of businesses and samples. We will explain all of this here and inside the App before asking you for anything.

12. Cookies and tracking technologies (web/PWA)

On the website and/or PWA, HOSTELELLA may use cookies, pixels or similar technologies for:

Non-essential cookies will only be used where consent exists, in accordance with ePrivacy and applicable law. The specific Cookies Policy supplements this information and prevails for granular cookie management.

Email measurement. We draw a precise distinction between two levels, because they are not the same thing.

Blocking remote images is an additional control; it does not replace any consent legally required. We never use this information to build profiles producing legal or similarly significant effects on you.

13. Recipients, processors and sub-processors

We do not sell personal data. Data may be accessible to selected providers acting as processors/sub-processors under contractual obligations of confidentiality, security and compliance, including providers of:

Each recipient receives only the data necessary for its function. Providers acquire no right to reuse Customer Data for advertising, their own profiling or model training; where they act as independent controllers — for example, certain regulatory payment or mobile store activities — their own responsibilities and policies are identified.

Under external-purchase programs for iOS or Android, Apple and Google may receive reporting identifiers or tokens, country, amount, currency, date and transaction status in order to administer their programs and fees. They act under their own terms and responsibilities. HOSTELELLA does not send them the full card number.

When HOSTELELLA acts as a processor, sub-processors are governed by the DPA, the Sub-processors Annex and the requirements of Article 28 GDPR. The up-to-date list of sub-processors is published in the Sub-processors Annex.

14. Authorities and defense of rights

We may disclose data to competent authorities where there is a legal obligation or legitimate request, and/or to defend rights, prevent fraud, ensure security or respond to claims, in accordance with the GDPR.

15. Corporate restructurings

In the event of a merger, acquisition, reorganization, sale of assets or equivalent procedures, data may be disclosed to third parties to the extent necessary and proportionate, with adequate safeguards.

16. International transfers

Where international transfers of data outside the European Economic Area occur, we apply adequate safeguards, including adequacy decisions, Standard Contractual Clauses (SCCs), the EU-US Data Privacy Framework where applicable and supplementary measures, in accordance with Articles 44–49 GDPR. Certain AI and communications providers are located in the United States; in such cases the above mechanisms and the minimization described in this Policy apply. Stripe payment services may involve global processing by its entities, financial institutions and payment-method providers under its DPA, terms and applicable safeguards.

In certain cases there may be a risk of access by authorities of third countries. In such cases we will apply supplementary measures where appropriate and, where necessary, inform and/or obtain consent in accordance with applicable law.

17. Data retention

We retain personal data only for as long as necessary for the purposes described in this Policy and for the periods required by legal, tax, accounting, audit and security obligations. Thereafter, data will be deleted or anonymized, unless there is a retention obligation or a need to defend claims.

Retention is detailed in the Retention Policy. When HOSTELELLA acts as a processor, retention is governed by the DPA and the customer's instructions, without prejudice to legal obligations.

A deliberate exception: proof of your decisions. The record of when you turned an optional communication on or off — and the cryptographic fingerprint of your address in the suppression list — are retained even if you close your account. That is the only way to guarantee we will not write to you again and to demonstrate to the supervisory authority that we respected your decision (Arts. 5.2 and 7.1 GDPR). That record is kept blocked, separate from the rest, and is not used for any other purpose.

18. Security measures

HOSTELELLA applies appropriate technical and organizational measures (Art. 32 GDPR) to ensure a level of security appropriate to the risk. The Security Policy describes the main measures, including access control, least privilege, encryption where appropriate, activity logging, incident management and service continuity.

Nonetheless, no system can guarantee absolute security. Users are responsible for keeping access to their accounts and devices secure.

19. Personal data breaches

In the event of a personal data breach, HOSTELELLA will follow internal procedures to assess the risk and, where appropriate, notify the competent supervisory authority and/or affected persons in accordance with Articles 33 and 34 GDPR.

When HOSTELELLA acts as a processor, notifications to the controller will be handled in accordance with the DPA.

20. Rights of data subjects

Data subjects may exercise their rights of access, rectification, erasure, restriction, objection and portability, as well as withdraw consent where applicable, by contacting: legal@hostelella.com.

We may request reasonable information to verify identity or representation. We will respond within one month of receipt of the request; this period may be extended by up to two additional months where necessary due to complexity or number of requests, informing the requester in accordance with the GDPR.

If the request relates to data processed by HOSTELELLA as a processor on behalf of a business customer, we may refer the requester to the relevant controller, who is the party that must handle the request.

Objection to direct marketing. Under Articles 21.2 and 21.3 GDPR, you may object at any time to the processing of your data for direct marketing purposes, including related profiling. This is an absolute right: no balancing test applies and we will stop processing your data for that purpose immediately. See section 22.

21. Complaints

You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD).

22. Communications and preferences

22.1 How we classify what we send you

Every message that leaves HOSTELELLA belongs to one of these three classes. The class determines its legal basis and whether you can opt out.

ClassExamplesLegal basisOpt-out
Necessary account verification, sign-in and password recovery, security alerts, team invitations, billing and failed payments, changes to these legal documents, incidents and operational notices you asked for yourself Performance of the contract (Art. 6.1.b GDPR) and compliance with legal obligations (Art. 6.1.c GDPR) No unsubscribe link: it is part of the Service while you have an active account
Optional product news, management tips, offers, promotions, events and surveys Prior, express and separate consent (Art. 6.1.a GDPR and Art. 21.1 LSSI-CE) Mandatory, one click, in every message
The Customer's the purchase order or claim a business sends to its supplier from the platform The Customer's instruction: HOSTELELLA acts as processor and the actual sender is the business Not applicable: it is not a HOSTELELLA commercial communication

Accepting the Terms, acknowledging this Policy or signing the Data Processing Agreement does not enable any communication in the Optional class. Granting the operating system's notification permission does not either: that permission enables a technical capability, not a commercial purpose. And giving us a phone number does not authorize us to call or text you.

22.2 Your preference centre

Inside the App, under Account → Preferences → Privacy and communications, you can see and change at any time which optional communications you accept. This preference is yours as a person and does not depend on the business you are working in: if you belong to several businesses, it is still a single decision.

22.3 One-click unsubscribe

Every optional communication includes an unsubscribe link that works in a single click, without signing in and without asking you for a reason, plus the List-Unsubscribe and List-Unsubscribe-Post technical headers so that your own email client can offer you its unsubscribe button. The link uses a random, single-use, expiring identifier: it never carries your email address or phone number.

When you unsubscribe we do two things in the same operation: we record the preference change and we add a cryptographic fingerprint of your address (HMAC-SHA256 with a key we keep separately; we never store your address in clear text in that list) to a suppression list. That list takes precedence over any prior consent and over any message already queued. We also add addresses to it automatically when they bounce permanently or when someone marks one of our emails as spam.

We handle opt-outs free of charge and without undue delay. You can also write to legal@hostelella.com or manage your preferences from your account settings.

22.4 Channels we do not use yet

In this version of the Service, optional communications are sent by email only. We do not send commercial SMS or WhatsApp messages, we do not make commercial phone calls and we do not display third-party advertising inside the App. Should we ever add any of those channels, it would appear as its own option, off by default, with its own consent and its own opt-out; and before using the telephone we would check advertising exclusion registries where the law requires it.

22.5 How we decide what to send you

Before an optional message is prepared, and again immediately before it is handed to the email provider, the system checks that the template is classified, that the purpose is allowed, that no active suppression exists and that your consent is still valid against a valid version of the text. If any of those conditions is missing, the send is blocked and logged: the system's default behaviour is not to send.

We may use automated systems to choose between already approved templates, adjust frequency or timing, and reduce or pause sending if we detect low interest or complaints. Those systems can never create a new purpose, infer a consent you did not give, reactivate an opt-out or change your preferences.

22.6 Limits we commit to

If you receive a commercial communication from us that you consider unsolicited, write to legal@hostelella.com: we will investigate it, unsubscribe you immediately and fix the source.

23. Third-party links

The platform may contain links to third-party services (e.g., maps, integrations). HOSTELELLA is not responsible for the privacy practices of such third parties. We recommend reviewing their respective policies.

24. Changes to this Policy

This Privacy Policy may be updated to reflect legal, regulatory or operational changes. The current version will be available within the Service. Material changes will be prominently communicated before they take effect where required and will not retroactively legalize processing. Where a new purpose requires consent, it will be requested separately before processing begins.

25. Limitation of liability (Privacy)

Nothing in this Policy limits the mandatory rights provided by data-protection law. To the maximum extent permitted by law, HOSTELELLA will not be liable for damages arising from: (i) misuse of the Service, (ii) unlawful data uploads by customers/users, or (iii) actions taken solely on the basis of informational results, including AI proposals applied without the required human review.