Skip to main content
Casa Fresneda
Casa Fresneda

Información legal

Privacy policy

Information about how personal data is processed on casadefresneda.com, in compliance with Regulation (EU) 2016/679 (GDPR) and Spain's Organic Law 3/2018 (LOPDGDD).

Last updated: 19 de mayo de 2026

1 · Data controller

Jesús María García Esteban · Spanish Tax ID 16525534B · Calle Mayor 1, 09267 Fresneda de la Sierra Tirón (Burgos), Spain · j.m.garcia@casadefresneda.com

2 · Purposes of processing

We process personal data to:

• Manage rural house bookings (forms, calendar, payments).

• Communicate with you before, during and after your stay.

• Comply with legal obligations (tourism registry, invoicing, fraud prevention).

• Reply to contact requests received via the form.

3 · Legal basis

• Performance of a contract when you book.

• Compliance with legal obligations (tourism, tax).

• Your explicit consent when you accept this policy at booking or when writing through the contact form.

• Legitimate interest in fraud prevention and service improvement.

4 · Retention periods

Data is kept for the time needed to manage the booking and afterwards for any applicable legal retention period (6 years for tax-related records; statutory periods for the tourism registry). After that, data is deleted.

5 · Recipients and processors

We use the following processors, all with GDPR safeguards in place:

Vercel Inc. (USA) — web hosting. Data transferred with European Commission Standard Contractual Clauses.

Supabase / AWS Frankfurt (EU) — database.

Stripe Payments Europe (Ireland) — payment processing.

Resend Inc. (USA) — transactional email delivery.

Google Maps — location map display.

No data is shared with third parties unless legally required.

6 · Your rights

You can exercise your rights of access, rectification, deletion, opposition, restriction and portability by writing to j.m.garcia@casadefresneda.com with a copy of your ID. You may also lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).

7 · Security measures

We apply technical and organisational measures: encryption in transit (HTTPS), role-segregated storage (Supabase RLS), admin access control and operation logging.