Privacy policy
Privacy Policy
This Privacy Policy explains how MI FLOW HOTELS, S.L. processes personal data in connection with the MiFlow website, bookings, stays, retreats, communications, applications and hotel operations.
1. Controller
MI FLOW HOTELS, S.L. NIF: B56966518 Carrer de la Baixada de la Platja Cristall 6 43892 Mont-roig del Camp, Tarragona, Spain
Email: team@hotel-miamiplatja.com
2. Data we process
• Contact and communication data, including name, email address, telephone number and the content of enquiries by website form, email, telephone or WhatsApp.
• Booking and stay data, including travel dates, accommodation, guests, special requests, booking history and communications.
• Payment and billing data, including transaction status, invoice details and limited or masked card information. Full card numbers and security codes are processed by the payment provider and are not stored by MiFlow.
• Identification and registration data required by Spanish accommodation laws, including identity-document, nationality, date-of-birth, address, relationship and stay information.
• Technical website data, such as IP address, device, browser, time of access and security or server logs.
• Video images from cameras in public, non-sensitive areas. MiFlow does not record audio and does not monitor bedrooms, bathrooms, changing areas or other private areas.
• Electronic access data, such as access codes and, where recorded by the system, date and time of access.
• Application data, including CV, qualifications, employment history and correspondence.
• Retreat registration and organisational data. MiFlow does not request health data as part of standard booking or retreat registration. If this changes, separate information and an appropriate legal basis will be provided.
3. Purposes and legal bases
MiFlow processes technical and security data on the basis of its legitimate interests in operating and protecting the website and its systems. Contact and communication data are processed to respond to enquiries and provide guest service on the basis of pre-contractual measures, contract performance and, where appropriate, MiFlow’s legitimate interests. Booking, guest, stay and retreat data are processed to take steps at your request before entering into a contract and to perform the booking or accommodation contract. Payment, billing and transaction data are processed for contract performance and compliance with accounting, tax and other legal obligations. Identity, booking and stay data required for guest registration and reporting are processed to comply with Spanish legal obligations. Video images from public areas and electronic access records are processed on the basis of MiFlow’s legitimate interests in protecting guests, staff, property and facilities and ensuring secure access. Access data may also be necessary to perform the accommodation contract. Application data are processed to take pre-contractual steps and on the basis of MiFlow’s legitimate interest in managing and documenting the recruitment process. Relevant records may also be processed to comply with legal obligations and to establish, exercise or defend legal claims. MiFlow does not currently send newsletters. If direct marketing is introduced, contact data will only be used with consent or where permitted by law for existing customers. Every marketing message will include a simple way to opt out.
4. Sources of data
We usually receive data directly from you. We may also receive booking data from the person making a booking for other guests, from Booking.com, Smoobu, payment providers or check-in providers. The person making a booking should inform accompanying guests that their data will be processed under this Privacy Policy.
5. Service providers and recipients
• Smoobu, as the website host and booking-management provider.
• Booking.com, where a booking is made through that platform.
• Stripe, PayPal, card processors, banks and payment-service providers.
• Chekin, when used for online check-in and statutory guest reporting; alternatively, data may be entered directly into the competent government system.
•Cloudflare and other hosting, security, IT, electronic-lock and communications providers.
• WhatsApp and its provider where you choose to communicate through WhatsApp.
• Accountants, tax advisers, legal advisers, insurers and auditors.
• Housekeeping, retreat partners and other service providers only where access to limited data is necessary to provide the requested service.
• Police, courts, tax authorities, tourism authorities and other public bodies where disclosure is legally required.
6. International data transfers
Some providers or their group companies may process data outside the European Economic Area. Where this occurs, MiFlow relies on an adequacy decision, the EU-U.S. Data Privacy Framework where applicable, Standard Contractual Clauses, Binding Corporate Rules or another lawful safeguard. Further information about the relevant safeguard can be requested from MiFlow.
7. Retention
• Guest-registration data required by Spanish accommodation law: three years after the end of the service.
• Booking, payment, invoice and business records: for the contractual relationship and thereafter for applicable legal retention and limitation periods, generally up to six years.
• Enquiries that do not lead to a booking: normally up to twelve months after the enquiry is closed.
• Job applications: for the recruitment process and normally up to six months afterwards; longer only with consent or where required for a legal claim.
• Video-surveillance recordings: a maximum of one month, unless footage must be preserved for an incident, investigation or legal claim.
• Electronic-access records: only for as long as needed for access management and security, normally no longer than 90 days after the stay unless required for an incident.
• Technical and security logs: for short operational and security periods according to system settings, or longer where required to investigate an incident.
• Data processed on the basis of consent: until consent is withdrawn, unless another legal basis or retention obligation applies.
8. Cookies and similar technologies
MiFlow currently does not use analytics or advertising cookies. The website and security services may use strictly necessary technical storage or process technical data required to provide and protect the website. If non-essential cookies or tracking technologies are introduced, they will only be activated where legally required after consent, and the relevant information will be added to the cookie notice and this policy.
9. Your rights
You may request access to, correction or deletion of your data, restriction of processing, data portability, or object to processing based on legitimate interests or for direct marketing. You may withdraw consent at any time without affecting earlier lawful processing. Requests can be sent to team@hotel-miamiplatja.com. MiFlow may request reasonable proof of identity. You also have the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD).
10. Required data
Data marked as mandatory in a booking or check-in process is required to enter into or perform the accommodation contract or to meet legal registration duties. If this information is not provided, MiFlow may be unable to confirm the booking, accept the guest or provide the requested service.
11. Security and automated decisions
MiFlow applies appropriate technical and organisational measures and limits access to persons who need the data for their work. No decision producing legal or similarly significant effects is made solely by automated means, and MiFlow does not carry out individual profiling beyond any future consent-based, standard website marketing tools.
12. Changes
This Privacy Policy may be updated when services, providers or legal requirements change. The version available on the website at the relevant time applies. Material changes will be communicated where legally required.
Last updated: July 2026.

