Policy privacy

1. ADDITIONAL AND DETAILED INFORMATION ON THE PROTECTION OF PERSONAL DATA

This Privacy Policy (hereinafter, the “Privacy Policy”) aims to provide additional and detailed information to interested parties regarding the processing of their personal data carried out through this Website, in compliance with current data protection regulations, in particular Regulation (EU) 2016/679 of 27 April 2016 (GDPR) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, as well as Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights.

The purpose of this Privacy Policy is to help you understand how your personal data is collected, used, and protected when you use the Website, and to enable you to make informed decisions about it. Therefore, we recommend that you carefully read this Privacy Policy to maintain control over your personal data at all times.

The User guarantees that the personal data provided is true, accurate, complete and duly updated, being responsible for any damage or loss, direct or indirect, that may be caused as a result of non-compliance with this obligation.

In the event that the data provided belongs to a third party, the User guarantees that he has previously informed said third party of the aspects contained in this Privacy Policy and that he has sufficient legitimacy to provide his personal data to BUENALSANTA, SL, for the purposes indicated.

1.1. Who is responsible for processing the User's personal data?

The company BUENALSANTA, SL, with NIF B81245656 and postal address at Calle Manuela Malasaña 18, 28004, Madrid, is the Controller of the processing of the User's personal data and informs you that this data will be processed in accordance with the provisions of Regulation (EU) 2016/679, of April 27 (GDPR) and Organic Law 3/2018, of December 5 (LOPDGDD).

BUENALSANTA, SL is part of a group of companies operating under the common name of Grupo La Musa (hereinafter, “Grupo La Musa”). Information regarding these entities can be found in the Legal Notice of this Website.

To contact the Data Controller directly and effectively, you can use the following email address: protecciondatos@grupolamusa.com and/or to the postal address indicated above.

1.2. For what purpose do we process the User's personal data?

Grupo La Musa will collect the User's name, surname, telephone number and email address, as well as any other data that the User includes in the form “LET'S GET STARTED?” through the “Contact” section of the Website, in order to resolve queries and/or send requested information.

Grupo La Musa will collect the User's name, surname, telephone number and email address, as well as any other personal data that the User includes in their CV or in the application form "DO YOU LIKE OUR STYLE?" through the "Send us your CV" section of the Website, in order to manage job applications and include their candidacy in selection processes.

Grupo La Musa will collect the User's name, surname, telephone number, and email address, as well as payment card details (number, expiry date, and CVV) or other enabled payment methods, provided through the "MyRestoo" booking manager via the "Reservations" form. This information will be used to manage, process, and finalize the reservation at the chosen establishment, process the User's registration on waiting lists, and offer alternative availability at other establishments within the Group if the selected venue is not fully booked. This includes sending confirmations, reminders, and communications regarding modifications or cancellations. Furthermore, this data may be used to implement the establishment's cancellation or "no-show" policy, allowing for the collection of penalties or deposits when this has been communicated and accepted during the booking process.

1.3. What is the legal basis for processing the User's personal data?

The processing of User data by Grupo La Musa will be based on:

  • Consent of the interested party: granted by the User by explicitly accepting this Privacy Policy, by accepting the “check box”, made available to him in each of the data collection forms, referred to above (article 6.1.a of the GDPR).
  • Execution of a contract or binding legal relationship: for the management, confirmation and execution of table reservations requested by the User, as well as for the management of personnel selection processes in which the User participates voluntarily (article 6.1.b of the GDPR).
  • Legitimate interest of the company: For sending commercial communications about products or services similar to those previously contracted by customers (Article 6.1.f of the GDPR and Article 21.2 of the LSSI). Likewise, the management of fraud and no-show prevention systems, as well as sending technical booking reminders by email or SMS to ensure the proper provision of the service, is based on legitimate interest.
  • Compliance with legal obligations by the company: especially in tax, accounting and fraud prevention matters (article 6.1.c of the GDPR).

1.4. How long will we keep the User's personal data?

Personal data collected through the Website forms will only be kept for the time necessary to fulfill the purpose for which they were collected, respecting applicable legal deadlines.

  • Contact form / general inquiries: The personal data provided will be kept for as long as necessary to manage the query or request made and, subsequently, for the legal periods of retention of accounting or administrative records that may be applicable, or until the User withdraws their consent.
  • CV/Job Application Submission Form: The personal data provided will be kept during the selection process and, where applicable, while the candidate remains included in our employment databases, in accordance with applicable labor and data protection legislation (for example, one year) or until the User withdraws their consent.
  • Reservation Form (MyRestoo): The personal data provided will be kept for the time necessary to manage the booking and provide the requested service. Once the booking is complete, the data will be blocked for the legally prescribed periods (especially for tax and commercial matters related to payment processing or "no-show" guarantees), or until the User withdraws their consent for marketing purposes, if such consent has been given.

1.5. To which recipients will the User's personal data be communicated?

The User's personal data will not be communicated to third parties outside the La Musa Group, unless it is necessary to comply with a legal obligation or for the exercise of legal actions.

Likewise, the data may be processed and shared among the companies that are part of the La Musa Group, under the coordination of BUENALSANTA, SL, for the sole purpose of managing the purposes indicated in this Privacy Policy.

Additionally, third-party entities may have access to the data in their capacity as Data Processors, for the sole purpose of providing auxiliary services necessary for the Group's activity (such as the "MyRestoo" booking manager, web hosting services or technical support), always guaranteeing compliance with the security measures required by the GDPR.

In particular, the data may be communicated to public bodies, courts and other administrative authorities, when necessary to comply with legal obligations or for the defense of the legal interests of the La Musa Group.

1.6. What are the User's rights when providing us with their personal data?

The User has and may exercise the following rights in relation to the personal information provided to Grupo La Musa:

  • Right of access: The User has the right to obtain confirmation as to whether Grupo La Musa is processing personal data concerning him or her and to access such personal data.
  • Right of rectification: The User may request the rectification of inaccurate data or the completion of incomplete data.
  • Right to erasure: The User has the right to request that we delete or remove their personal data in some circumstances when, among other reasons, the data is no longer necessary for the purposes for which it was collected or if they withdraw their consent (in relation to processing based on it).
  • Right to restriction of processing: The User may request us, in certain circumstances, to temporarily limit the processing of the personal data provided, for example, when they dispute the accuracy of said personal data or oppose the processing, in which case we will only retain them for the exercise or defense of claims.
  • Right to data portability: The User has the right, in the case of processing carried out by automated means, to obtain personal data that he/she has provided to us (in a structured, commonly used and machine-readable format) as well as to request that it be transmitted to another entity responsible for the processing, when this is technically possible.
  • Revoke your consent: The User will have the right to revoke their consent at any time.
  • Right to lodge a complaint with the supervisory authority: Users who have doubts about our privacy practices, including how we have processed their personal data, can file a complaint with the Spanish Data Protection Agency (agpd.es), especially if they have not obtained satisfaction in the exercise of their rights.

The User has the possibility of exercising their legal rights before the Data Controller, at any time, by requesting it in writing addressed to Grupo La Musa at the email address (e-mail): protecciondatos@grupolamusa.com (Reference: “Exercise of GDPR rights”) which must contain: your name and surname, copy of your identity document (DNI, NIE, passport or other valid document that identifies you), request specifying your application, address for notification purposes, date, signature and, where applicable, supporting documents for the request you make.

2. MANDATORY OR OPTIONAL NATURE OF THE INFORMATION PROVIDED BY THE USER

By checking the corresponding boxes and entering data in the fields marked with an asterisk (*) on the contact form or download forms, Users expressly and freely and unequivocally accept that their data is necessary for the provider to process their request. Providing data in the remaining fields is voluntary. The User guarantees that the personal data provided to the Data Controller is accurate and is responsible for communicating any changes to it.

The Data Controller informs and guarantees that all data requested through the website is mandatory, as it is necessary for providing optimal service to the User. If all the data is not provided, the Data Controller cannot guarantee that the information and services provided will be fully tailored to the User's needs.

3. SECURITY MEASURES

That in accordance with the provisions of current regulations on the protection of personal data, the Controller is complying with all the provisions of the regulations Regulation (EU) 2016/679, of 27 April 2016 (GDPR), and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights (LOPDGDD), for the processing of personal data under its responsibility, and expressly with the principles written in Article 5 of the GDPR and in Article 4 of the LOPDGDD, by which they are processed lawfully, fairly and transparently in relation to the data subject and adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.

The Controller guarantees that it has implemented appropriate technical and organizational policies to apply the security measures established by the GDPR and the LOPDGDD in order to protect the rights and freedoms of Users and has communicated to them the appropriate information so that they can exercise them.