Información legal

Privacy policy

GDPR information. Version 2026-07-26.

1. Controller

  • IASEARCH SL, Spanish tax ID B21754767.
  • Address: Pasaje Cuartel de Caballería 4, Bajo B, 29013 Málaga, España.
  • Privacy rights: [email protected].

2. Data and purposes

  • Contact and booking details needed to answer enquiries and perform the accommodation contract.
  • Guest-account details: name, email, cryptographically derived password and revocable access sessions.
  • Stripe payment identifiers, amount and status; IASEARCH SL never receives the full card number or security code.
  • Billing details entered by the customer and invoices issued by IASEARCH SL.
  • Traveller data required by accommodation law.
  • Didit verification status and minimum extracted results. Didit temporarily processes document and selfie images.
  • Proportionate technical security logs and, when consented to, aggregate first-party analytics without individual profiles or cross-site tracking.

3. Legal bases

Processing relies on pre-contractual steps, performance of the booking contract, statutory duties, legitimate interests in service security and legal claims, and explicit consent for optional biometric verification. A reasonable non-biometric identity-check alternative is available by contacting us.

4. Identity verification

Didit Identity Spain SL hosts the verification flow. IASEARCH SL stores the result and minimum necessary fields, not full ID images, selfies, liveness videos or biometric templates. Images may be temporarily available in Didit for manual review and are subject to the shortest configured retention.

5. Processors and transfers

Necessary recipients may include Stripe, Didit, Formspree, Cloudflare, hosting and email providers, public authorities and professional advisers. EEA processing is preferred; adequacy decisions, EU Standard Contractual Clauses or another valid safeguard apply when data leaves the EEA.

6. Retention

  • Unsuccessful enquiries: up to 12 months.
  • Bookings, contracts and invoices: applicable legal limitation periods, normally up to 6 years.
  • Statutory traveller records: 3 years.
  • Security logs: normally up to 12 months.
  • Didit images/biometrics: minimum configured period or earlier deletion when no longer needed; no copy is stored on this website.

7. Rights

Contact [email protected] to request access, correction, deletion, restriction, objection, portability or consent withdrawal. You may complain to the Spanish Data Protection Agency. We do not require a full ID copy merely to process a rights request.

8. Security, minors and automated checks

We apply access controls, encryption in transit, server-only secrets, signed links and minimisation. Uncertain automated identity or fraud results may be manually reviewed. A parent or representative supplies legally required information about minors.