PRIVACY POLICY

1. DATA CONTROLLER

Controller: El Mesón del Picoteo, S.L.
NIF: B38637237
Trade name: Donde Mario
Address: Carretera Provincial, 199, 38390 Santa Úrsula, Santa Cruz de Tenerife
Phone: 922 30 45 85
Email address: info@dondemario.net
Website: dondemario.net

El Mesón del Picoteo, S.L. is the party responsible for processing the personal data collected through this website. The data will be processed in accordance with Regulation (EU) 2016/679 of 27 April on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and with Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights.

2. PERSONAL DATA WE PROCESS

We may process the personal data that the user voluntarily provides through the forms, email, telephone or other means of contact available on the website.

Depending on the interaction, this data may include:

  • First and last name.
  • Email address.
  • Telephone number.
  • Information included in enquiries, requests or communications.
  • Data necessary to manage a booking, when it is handled directly through Donde Mario.
  • Technical and browsing data obtained through cookies, in accordance with the user’s consent preferences.

3. PURPOSES OF PROCESSING

Handling enquiries and requests

To manage and respond to enquiries, requests for information or communications sent by the user through the available means of contact.

Booking management

To process booking requests and carry out the necessary communications related to them, when the booking is managed directly by Donde Mario.

Provision of services and business relationship

To manage the requested services, maintain the relationship with customers and handle the administrative matters related to that relationship.

Commercial communications

To send information about news, activities, services, events or offers from Donde Mario only when the user has previously given their consent.

The user may withdraw this consent at any time.

Website performance analysis

To obtain statistics on the use and functioning of the website through analytical tools, provided that the user has accepted the corresponding cookies.

4. LEGAL BASIS FOR PROCESSING

The legal bases that allow us to process personal data are:

  • User consent: when submitting an enquiry, accepting analytical cookies or requesting to receive commercial communications.
  • Application of pre-contractual measures or performance of a contractual relationship: when the data is necessary to manage a booking or provide a requested service.
  • Compliance with legal obligations: especially in tax, accounting or administrative matters.
  • Legitimate interest of the controller: when necessary to handle communications related to a previous relationship, ensure the security of the website or defend against possible claims, always respecting the user’s rights and freedoms.

5. DATA RETENTION PERIOD

Personal data will be retained only for as long as necessary to fulfil the purpose for which it was collected.

  • Enquiry data will be retained for as long as necessary to respond to and follow up on the request.
  • Data related to bookings or services will be retained for the duration of the contractual relationship and, subsequently, for the periods required by tax, accounting or legal regulations.
  • Data used for commercial communications will be retained until the user withdraws their consent.
  • Data obtained through cookies will be retained for the periods indicated in the Cookie Policy.

Once these periods have elapsed, the data will be securely deleted or blocked when it is necessary to retain it to address possible legal liabilities.

6. DATA RECIPIENTS

As a general rule, personal data will not be transferred to third parties, unless there is a legal obligation or it is necessary to provide a requested service.

Certain data may be accessed by providers that render services to Donde Mario, such as:

  • Web hosting and technical maintenance services.
  • Email service providers.
  • Booking management platforms.
  • Web analytics services, when consented to.
  • Administrative, tax or legal advisory services.

These providers will process the data following the controller’s instructions and will be subject to the corresponding confidentiality and data protection obligations.

When a booking or service is managed through an external platform, the user should also consult the privacy policy of that platform.

7. INTERNATIONAL DATA TRANSFERS

Some technology providers may process information from countries located outside the European Economic Area.

When international data transfers occur, they will be carried out using the safeguards provided for in the applicable regulations, such as adequacy decisions, standard contractual clauses or other legally recognised mechanisms.

8. USER RIGHTS

The user may exercise the following rights:

  • The right to access your personal data.
  • The right to rectify inaccurate data.
  • The right to erasure of your data.
  • The right to object to the processing.
  • The right to restrict the processing.
  • The right to data portability, where applicable.
  • Right to withdraw consent at any time.
  • The right not to be subject to automated individual decisions, where applicable.

Contact details to exercise your rights

El Mesón del Picoteo, S.L.

Carretera Provincial, 199

38390 Santa Úrsula, Santa Cruz de Tenerife

Email: info@dondemario.net

The request must indicate the right you wish to exercise and allow verification of the applicant’s identity when necessary.

The user may also file a complaint with the Spanish Data Protection Agency if they consider that their rights have not been properly addressed.

9. MANDATORY OR OPTIONAL NATURE OF THE DATA

The fields identified as mandatory in the forms must be completed in order to process the corresponding request.

The remaining data is optional.

The user guarantees that the information provided is true, accurate and up to date, and undertakes to report any changes.

10. THIRD-PARTY DATA

If the user provides personal data of another person, they declare that they have sufficient authorisation to do so and that they have informed that person about the content of this Privacy Policy.

11. MINORS

The services on this website are not specifically aimed at minors.

Minors must not provide personal data without the authorisation of their parents or legal guardians when such authorisation is required under applicable regulations.

12. SECURITY MEASURES

The controller applies appropriate technical and organisational measures to protect personal data against loss, alteration, unauthorised access, disclosure or destruction.

These measures are reviewed periodically taking into account the nature of the data, the risks of processing and the state of technology.

13. CHANGES TO THE PRIVACY POLICY

This Privacy Policy may be updated when legal or technical changes occur, or changes in the processing carried out through the website.

We recommend reviewing this page periodically.

Last updated: July 2026.