Personal Data Processing Policy

Apartamento Playa Rodadero de A. Zaffina protects the privacy of its guests and website users. This policy explains what personal data we collect, for what purpose, and what rights the Data Subject has.

1. Data Controller

Apartamento Playa Rodadero de A. Zaffina. Calle 1 #17-69, El Rodadero, Santa Marta, Magdalena, Colombia. NIT: 700171727. Contact email: info@apartamentoplayarodadero.com

2. Applicable law

The processing of personal data collected through this website is governed by Colombian Law 1581 of 2012 and Decree 1377 of 2013, since the Data Controller is domiciled and operates in Colombia. Additionally, the registration of foreign guests is governed by Decree 1067 of 2015 (Foreign Registration and Information System — SIRE, of Migración Colombia).

Since the site receives guests from different countries, protection criteria voluntarily aligned with Regulation (EU) 2016/679 (GDPR) are recognized for users located in the European Union, to the extent applicable.

3. Personal data collected and purpose of processing

a) Booking data (via the VikBooking reservation system, including bookings from Booking.com and Airbnb synchronized through VikChannelManager). Data: first name, last name, email, phone, stay dates, number of guests. Purpose: managing the reservation, check-in/check-out and communication related to the stay.

b) Identity document / passport (foreign guests). Data: type and number of identity document or passport; optionally, a scanned copy. Collection: recorded in the system at check-in, and kept in the guest's file within the VikBooking reservation management system. Purpose: compliance with the legal obligation to register with Migración Colombia's Foreign Registration and Information System (SIRE), under Decree 1067 of 2015. This data is transmitted directly to Migración Colombia and is not used for any other purpose.

c) Payment data (via the Wompi payment gateway). The site does not store credit/debit card data; these are processed directly by Wompi S.A. under its own security and PCI-DSS compliance policies. Purpose: processing the payment of the reservation.

d) Contact form. Data: first name, last name, email, physical address, phone number. Purpose: responding to user inquiries.

e) Browsing statistics (Google Analytics 4). Data: usage data, tracking identifiers (cookies). Purpose: analyzing site usage for statistical and service-improvement purposes.

f) Advertising (Google Ads — conversion tracking). Data: tracking identifiers (cookies). Purpose: measuring the effectiveness of the site's advertising campaigns.

g) WhatsApp Business (chat widget). Data: name, profile photo, phone number, message content, date/time sent. Purpose: customer support via WhatsApp.

h) Cookies. Managed through the CookieYes consent banner; the user can accept, reject or customize their cookie preferences at any time through the banner itself.

i) Email marketing. Data: name, email. Purpose: sending commercial communications, offers, promotions and news related to Apartamento Playa Rodadero. Legal basis: prior, express and unambiguous authorization from the Data Subject (opt-in), given separately and independently from the booking or use of the site — never as a condition to complete a reservation. The Data Subject may unsubscribe (opt-out) at any time, free of charge and easily, through a link included in each communication or by writing to info@apartamentoplayarodadero.com. Note: as of the date of this policy, Apartamento Playa Rodadero does not yet send email marketing communications; this clause is included preventively.

4. Legal basis

The processing is based on the prior, express and informed authorization of the Data Subject (art. 9, Law 1581 of 2012), given when using the site, completing a form or making a reservation, or when voluntarily subscribing to marketing communications; the performance of the accommodation contract, for the data strictly necessary for the reservation and payment; and compliance with a legal obligation (art. 6, Law 1581 of 2012), for registering the identity document/passport of foreign guests with Migración Colombia's SIRE.

5. Data retention

Booking and payment data linked to accounting are kept for 10 years from the date of the last accounting record, in accordance with Colombia's document-retention regime for accounting documentation (Law 962 of 2005, art. 28). Marketing/analytics data (cookies, Google Analytics, Google Ads) is kept until the Data Subject revokes consent through the CookieYes banner. Data used for email marketing (once the service is active) will be kept until the Data Subject unsubscribes. The identity document/passport transmitted to SIRE is kept only for as long as necessary to fulfill the registration obligation with Migración Colombia.

6. Rights of the Data Subject (ARCO rights / Habeas Data)

The Data Subject has the right to: know, update and rectify their data; request proof of the authorization given; be informed about the use given to their data; file complaints with the Superintendencia de Industria y Comercio (SIC) for infringements of Law 1581 of 2012; revoke authorization and/or request deletion of the data when there is no legal or contractual duty preventing it; and access their data free of charge.

For users located in the European Union, the rights of portability and objection provided for under the GDPR are additionally recognized, to the extent applicable.

These rights may be exercised by writing to: info@apartamentoplayarodadero.com

7. Transfer and disclosure of data to third parties

Data may be shared, solely for the purposes described above, with: VikBooking / VikChannelManager (also manages the synchronization of bookings with Booking.com and Airbnb; bookings made directly on those platforms are additionally subject to Booking.com/Airbnb's own privacy policies); Wompi S.A. (payment processing); Migración Colombia (SIRE registration of foreign guests, as a legal obligation — Decree 1067 of 2015); Google LLC (Google Analytics 4 / Google Ads), under its own privacy policies; and WhatsApp/Meta (chat widget), under WhatsApp Business's privacy policy.

8. Security

Reasonable technical and organizational measures have been implemented (HTTPS connection, payment processing delegated to a PCI-DSS certified provider) to protect data against unauthorized access, loss or alteration.

9. Minors

The site is not directed at minors and does not knowingly collect data from minors unaccompanied by an adult responsible for the reservation.

10. Changes to this policy

This policy may be updated periodically; the date of the last revision is indicated below.

Last updated: September 29, 2026

No encontraste lo que nececitabas escribas aqui por whatsapp

pregunta lo que nececitas , buscamos la forma de ayudarte lo mas pronto posible
🇨🇴 ES🇬🇧 EN