Privacy Policy

In compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), Organic Law 3/2018 of 5 December on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD), and Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSI-CE), we hereby inform you about the processing of your personal data carried out through the website www.hotels001.com.

NOTE: This Privacy Policy refers exclusively to the processing of personal data carried out through the Websites of the data controllers. Processing derived from the in-person accommodation relationship, such as guest registration, video surveillance, etc., is provided through the specific information clause made available to the guest at the establishment.

1. JOINT DATA CONTROLLERS

The personal data collected through the Websites are processed jointly by the following entities, acting as joint controllers pursuant to Article 26 of the GDPR:

DATA CONTROLLERS: FuerteItaka, S.L. and New Fit Canarias, S.L.

Company 1: FuerteItaka, S.L.
Tax ID: B76108125
Registered address: C/ Baja de los Erizos 2 – Costa Calma, Pájara – 35627 Las Palmas de Gran Canaria
Email: admin@nfitcanarias.com
Telephone: 928 875 642
Registration details: Registered in the Commercial Registry of Las Palmas, Volume 151, Folio 191, Section 8, Registration Sheet 6805, Entry 1.

Company 2: New Fit Canarias, S.L.
Tax ID: B76255611
Registered address: C/ Baja de los Erizos 2 – Costa Calma – 35627 Las Palmas
Email: admin@nfitcanarias.com
Telephone: 928 875 642
Registration details: Registered in the Commercial Registry of Puerto del Rosario, Section 8, Registration Sheet 7758, Entry 1. Bulletin 220, Sheet 487752.

Websites: www.hotels001.com

Data Protection Officer (DPO): admin@nfitcanarias.com

Both entities have entered into a joint controllership agreement determining the purposes and means of processing, as well as their respective responsibilities. The essential content of said agreement will be made available to any data subject who requests it.

2. DATA PROTECTION OFFICER (DPO)

The joint controllers have appointed a Data Protection Officer (DPO), whom you may contact regarding any matter related to the processing of your personal data at the following email address: admin@nfitcanarias.com.

Data Protection Officer (DPO)
Email: admin@nfitcanarias.com

You may contact the DPO for any matter relating to the processing of your personal data or the exercise of your rights.

3. PURPOSES OF PROCESSING

Through the Websites, we process your personal data for the following purposes:

3.1. Contact forms and requests for information

To manage enquiries, requests for information and communications sent by the User through the forms available on the Websites.
Legal basis: consent of the data subject, Article 6.1(a) GDPR. The User consents to the processing by voluntarily submitting the form.

3.2. Online booking management

To manage accommodation bookings and complementary services, such as restaurant, fitness and wellness services, made through the Websites or integrated booking platforms.
Legal basis: performance of a contract or pre-contractual measures, Article 6.1(b) GDPR.

3.3. Loyalty Club

To manage registration, participation and membership in the Loyalty Club: member registration, accumulation and redemption of points or benefits, personalisation of offers and segmented communications based on the user’s booking history and preferences.
Legal basis: consent of the data subject, Article 6.1(a) GDPR. Registration is voluntary and consent may be withdrawn at any time by requesting cancellation of the Club membership.

3.4. Commercial communications and email marketing

To send electronic commercial communications, including newsletters, offers, promotions and news, about the services of the joint controllers by email or equivalent electronic means.
Legal basis: express consent of the data subject, Article 6.1(a) GDPR and Article 21 of Law 34/2002, LSSI-CE. The User may withdraw their consent at any time through the unsubscribe link included in each communication or by contacting the DPO.

3.5. Browsing and cookies

To collect browsing data through cookies and similar technologies for statistical analysis, personalisation and advertising. Please see the Cookie Policy for detailed information.
Legal basis: legitimate interest for technical cookies, Article 6.1(f) GDPR and Article 22.2 LSSI-CE; consent for all other cookies, Article 6.1(a) GDPR and Article 22.2 LSSI-CE.

4. DATA COLLECTED THROUGH THE WEBSITES

Contact forms: name, surname, email address, telephone number and enquiry message.
Online bookings: name and surname, email address, telephone number, stay dates, number of guests, accommodation preferences and payment data, processed through a secure payment gateway. The data controller does not store full card details.
Loyalty Club: identification data, email address, booking and consumption history at the establishments of the data controller, preferences and accumulated points.
Email marketing: name, email address, interaction data with communications, such as openings and clicks, subscription and unsubscribe dates.
Browsing data: IP address, browser type and version, operating system, screen resolution, pages visited, time spent on the website and access source. Please see the Cookie Policy.

5. RECIPIENTS

Companies: FuerteItaka, S.L. and New Fit Canarias, S.L.: communication between joint controllers for the joint management of bookings, the Loyalty Club and commercial communications.

Processors: service providers that access data on behalf of the joint controllers, with contracts signed in accordance with Article 28 of the GDPR:

– Hotel management platforms, PMS/Channel Manager.
– Secure payment gateway.
– Email marketing platform.
– Web hosting service provider.
– Web analytics tools, such as Google Analytics.
– External advisors.

Public authorities: where there is a legal obligation, such as the Spanish Tax Agency, Courts and Tribunals.

No international data transfers will be made except those derived from the use of third-party tools, such as Google Analytics or email marketing platforms, ensuring the appropriate safeguards provided for in Chapter V of the GDPR, including standard contractual clauses, the EU-US Data Privacy Framework or adequacy decisions, as applicable.

6. RETENTION PERIODS

Contact forms: until the enquiry has been resolved and during the applicable statutory limitation periods, 3 years pursuant to Article 1967 of the Civil Code.
Online bookings: during the term of the contractual relationship and the applicable limitation periods, 5 years pursuant to Article 1964 of the Civil Code and 4 years pursuant to Law 58/2003, General Tax Law.
Loyalty Club: while the member remains active and, after cancellation, during the applicable statutory limitation periods.
Email marketing: until consent is withdrawn or unsubscription is requested.
Browsing data: according to the duration of each cookie. Please see the Cookie Policy.

7. RIGHTS OF DATA SUBJECTS

In accordance with Articles 15 to 22 of the GDPR and Articles 12 to 18 of the LOPDGDD, you have the right to:

Access, Article 15 GDPR: to know whether we process your data and to obtain a copy.
Rectification, Article 16 GDPR: to correct inaccurate or incomplete data.
Erasure, Article 17 GDPR: to request deletion when the data are no longer necessary.
Objection, Article 21 GDPR: to object to processing, including direct marketing.
Restriction, Article 18 GDPR: to request restriction of processing.
Portability, Article 20 GDPR: to receive your data in a structured format.
Withdrawal of consent: to withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal, Article 7.3 GDPR.

To exercise your rights, please contact the Data Protection Officer (DPO) by email at admin@nfitcanarias.com or in writing at C/ Baja de los Erizos Nº2 – Costa Calma, Pájara – 35627 Las Palmas de Gran Canaria, attaching a copy of your identity document. The request will be answered within a maximum period of one month from receipt, Article 12.3 GDPR, which may be extended by two additional months in the event of complexity.

You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid – www.aepd.es – Tel. 901 100 099.

8. SECURITY MEASURES

The joint controllers have implemented appropriate technical and organisational measures in accordance with Article 32 of the GDPR to ensure a level of security appropriate to the risk, including, among others: communication encryption, SSL/TLS, access control, backups, password policies, staff training and periodic security assessments.

9. SOCIAL MEDIA

The data controllers may have profiles on social media platforms, such as Facebook, Instagram, TikTok, etc. The processing of followers’ data will be that permitted by each platform for corporate profiles, in accordance with their own privacy policies. No data will be extracted without express consent. The terms of use and privacy policies of each social network are the responsibility of their respective owners.

10. AMENDMENTS

The joint controllers reserve the right to amend this Privacy Policy in order to adapt it to legislative or case-law developments, criteria of the Spanish Data Protection Agency or the European Data Protection Board (EDPB). Significant changes will be communicated on the Websites.

Last updated: May 2026

Scroll to Top