Privacy Policy
This Privacy Policy governs the processing of personal data collected in the context of the promotion and marketing of the Siesta Living real estate development, whether through websites, electronic forms, messaging channels, the sales office, telephone calls or any other means. Such data are jointly processed by SIESTA LIVING, S.L. and JT REAL ESTATE IBIZA, S.L., which act as joint controllers within the meaning of Article 26 of the GDPR (hereinafter, jointly, “theJoint Controllers” or, interchangeably, “the Controller”), without prejudice to the processing that each entity carries out as an Independent Controller and that is expressly identified in this Policy.
This Policy has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter, the 'GDPR'), and with Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights (hereinafter, the 'LOPDGDD').
The Joint Controllers reserve the right to amend this Policy in order to adapt it to legislative developments, interpretative criteria of supervisory authorities, or changes in their processing activities, communicating such amendments through the websites and, where appropriate, by individual notification to the data subjects.
Data Controllers. Joint Controllership
The processing of data collected for the marketing of the Siesta Living development is carried out under a joint controllership arrangement (Article 26 of the GDPR) by the two entities identified below.
Joint Controller 1: Developer
| Identity | SIESTA LIVING, S.L. |
| Tax Identification Number (CIF) | B-26684860 |
| Registered Address | María de Molina Street, 40, 28006 — Madrid |
| ibiza@john-taylor.com | |
| Telephone | 682 15 22 28 |
Joint Controller 2: Marketer
| Identity | JT REAL ESTATE IBIZA, S.L. (John Taylor) |
| Tax Identification Number (CIF) | B-06955280 |
| Registered Address | Paseo Joan Carles I, 39 — Premises 1 and 2, Eivissa (Balearic Islands, Spain) |
| Registration Details | Madrid Commercial Registry — Volume 42079, Folio 11, Entry 1, Sheet M-745040 |
| ibiza@john-taylor.com |
Essential aspects of the joint controllership agreement (Article 26 of the GDPR)
Both entities act as joint controllers with regard to the collection, qualification and management of contacts interested in the Siesta Living development. To this end, they have entered into the agreement required by Article 26 of the GDPR, the essential aspects of which are: (i) SIESTA LIVING, S.L., as developer, determines the purpose of marketing its developments, and JT REAL ESTATE IBIZA, S.L., as marketer, provides and determines the technical means for collecting contacts (websites, domains, advertising and management tools forcontacts); (ii) both are responsible for ensuring compliance with the duty to provide information under Articles 13 and 14 of the GDPR; (iii) the handling of data subjects' rights is channelled through the single point of contact; and (iv) each entity adopts appropriate security measures and enters into data processing agreements with its suppliers pursuant to Article 28 of the GDPR.
Single point of contact: For transparency purposes and to facilitate the exercise of rights, the Joint Controllers have designated JT REAL ESTATE IBIZA, S.L. (ibiza@john-taylor.com) as the point of contact. However, pursuant to Article 26.3 of the GDPR, the data subject may exercise the rights granted by the Regulation against each of the Joint Controllers, regardless of the terms of the agreement. Data subjects may request additional information about the essential aspects of the agreement by contacting said point ofcontact.
None of the Joint Controllers has appointed a Data Protection Officer, as none of the mandatory appointment circumstances provided for in Article 37 of the GDPR and Article 34 of the LOPDGDD apply, according to the analysis carried out. Nevertheless, all matters relating to the protection of personal data may be addressed to the postal address or email address of the Joint Controllers indicated in the tables above, or to the single point of contact indicated below.
The processing of personal data by the Controller is governed by the principles established in Article 5 of the GDPR: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
The personal data processing activities carried out by the Controller in the course of its business are described separately below, indicating, where applicable, whether the entities act as Joint Controllers or as independent Controllers. For each processing activity, its purpose, legal basis, categories of data, recipients, retention period and source of the data are detailed.
Handling enquiries and requests for information through the website
| Purpose | To respond to enquiries, requests for information and communications submitted by data subjects through the forms available on the website, by email or through any other contact channel of the Controller. |
| Legal basis | Implementation of pre-contractual measures at the request of the data subject (Article 6(1)(b) GDPR) and, alternatively, the Controller's legitimate interest in responding to communications addressed to it (Article 6(1)(f) GDPR). |
| Categories of data | Identification data (first and last name) and contact data (email address, telephone number) and, where applicable, the free-text content of the enquiry. |
| Recipients | No disclosures to third parties are envisaged, except to the Controller's data processors (technology service providers) and those required by legal obligation. |
| International transfers | None are envisaged, except those arising from the hosting or technological tools indicated in section 6 of this Policy. |
| Retention | The data will be retained for the time necessary to respond to the inquiry and, subsequently, for the limitation period applicable to any potential actions arising from it. |
| Source | The data are provided directly by the data subject. |
Request for information about the real estate development and lead management
| Purpose | Manage requests for information about the Siesta Living developments and other developments of the Controller; send commercial information related to the requested development; carry out commercial follow-up with the data subject; qualify and categorize contacts based on their expressed interest; and, where appropriate, schedule visits to the sales office or the model property. |
| Legal basis | Application of pre-contractual measures at the request of the data subject (Article 6.1.b GDPR). In order to send commercial communications regarding promotions other than the one in which the data subject has expressly shown interest, the data subject's consent will be required (Article 6.1.a GDPR and Article 21 of Law 34/2002 on Information Society Services and Electronic Commerce). Likewise, the inclusion of the data in JT REAL ESTATE IBIZA, S.L.'s own CRM and its reuse for the marketing of promotionsbelonging to said entity, which in such case acts as an independent controller, require the data subject's consent (Article 6.1.a GDPR and Article 21 of Law 34/2002). |
| Categories of data | Identification and contact details; stated preferences regarding the type, location, budget and characteristics of the property; history of interactions with the Controller; and, where applicable, professional or financial data voluntarily provided by the data subject. |
| Recipients | Processors engaged by the Controller (CRM, marketing and sales tools, collaborating agencies). The data are incorporated into the commercial management systems of the Joint Controllers, including the proprietary CRM of JT REAL ESTATE IBIZA, S.L. No disclosures are made to third parties for commercial purposes. |
| International transfers | See section 6. |
| Retention | For as long as the user's relationship of interest is maintained and, once it has ended, for a maximum period of one (1) year, unless the data subject withdraws their consent earlier or requests erasure, without prejudice to the applicable statutory limitation periods for addressing potential liabilities. |
| Source | The data are provided directly by the data subject through web forms, email, telephone calls, visits to the sales office or other channels of the Controller. |
Property reservation and sale and purchase
| Purpose | Execution, management, performance and, where applicable, termination of the reservation agreement and subsequent sale and purchase agreement; management of payments, sureties and guarantees; notarial and land registry procedures; compliance with applicable legal obligations, particularly those arising from anti-money laundering, tax, accounting, commercial and housing consumer protection regulations; administrative, accounting and contractual documentation filing management; and defence against potential claims. |
| Legal basis | (i) Performance of the contract and implementation of pre-contractual measures at the request of the data subject (Article 6(1)(b) GDPR); (ii) compliance with legal obligations applicable to the Controller, in particular Law 10/2010 on the prevention of money laundering, tax regulations and Law 38/1999 on Building Regulation (Article 6(1)(c) GDPR); (iii) the Controller's legitimate interest in internal administrative management, fraud prevention and defence against claims (Article 6(1)(f) GDPR). |
| Categories of data | Identification data (including identity document); contact details; marital status data and matrimonial property regime where applicable; financial and economic data (bank account, justification of the origin of funds for anti-money laundering purposes); professional data; and any other data necessary for the formalization of the contract. |
| Recipients | Notaries and Land Registries; State Tax Administration Agency (AEAT); Executive Service of the Commission for the Prevention of Money Laundering (SEPBLAC) in cases legally required; financial institutions involved in payments, sureties or guarantees; professional firms, consultancies and administrative service providers that provide services to the Controller; insurance companies in cases involving insurance linked to the transaction; and the Controller's data processors. |
| International transfers | No international transfers are envisaged in this processing activity. |
| Retention | The data will be retained for the duration of the contract and, once it has ended, for the legally required periods: five (5) years for the limitation period for personal actions (Article 1964 of the Civil Code); six (6) years pursuant to Article 30 of the Commercial Code; four (4) years for tax purposes (Article 66 of the General Tax Law); and ten (10) years for anti-money laundering purposes (Article 25 of Law 10/2010). Once these periods have elapsed, the data will be erased or anonymized. |
| Source | The data are provided directly by the data subject and, where applicable, by their legal representative or by the professionals involved in the transaction. |
Sending commercial communications
| Purpose | To send the data subject, by electronic or postal means, commercial communications relating to other real estate developments of the Controller, as well as information about products and services related to real estate activities. |
| Legal basis | The data subject's express consent (Article 6.1(a) GDPR and Article 21 of Law 34/2002). |
| Categories of data | Identification data, contact details and, where applicable, stated preferences. |
| Recipients | Data processors acting on behalf of the Controller (providers of email marketing platforms and marketing services). No disclosures are made to third parties. |
| International transfers | See section 6. |
| Retention | Until the data subject withdraws their consent or objects to the processing. Consent may be withdrawn at any time, free of charge, through the procedures described in each communication or by requesting it from the Controller. |
| Source | The data subject, through express consent given in web forms, in the reservation contract, or by any other means that makes it possible to demonstrate such consent. |
Contact via WhatsApp
| Purpose | To respond to inquiries made by the data subject through the WhatsApp messaging channel; provide information about the real estate development; and manage the pre-contractual relationship. |
| Legal basis | Implementation of pre-contractual measures at the request of the data subject (Article 6(1)(b) GDPR). |
| Categories of data | Identification and contact data, the content of communications, and metadata associated with them. |
| Recipients | The use of WhatsApp involves the processing of data by WhatsApp Ireland Limited and, where applicable, Meta Platforms, Inc., as independent controllers, in accordance with their own privacy policies. The Controller does not control such processing. |
| International transfers | The use of WhatsApp may involve international data transfers to the United States, covered by the safeguards provided by Meta Platforms (EU-U.S. Data Privacy Framework and standard contractual clauses). |
| Retention | The data will be retained for the time necessary to handle the inquiry and, subsequently, for a maximum period of one (1) year, unless they are required to address potential liabilities. |
| Source | The data subject themselves, when initiating communication through WhatsApp. |
Management of suggestions and complaints
| Purpose | To address, manage and respond to suggestions, complaints and claims submitted by data subjects and, where applicable, process any actions arising from them. |
| Legal basis | The Controller's legitimate interest in handling suggestions and improving its services (Article 6(1)(f) GDPR). In the case of claims that may give rise to civil or contractual liability, compliance with legal obligations (Article 6(1)(c) GDPR). |
| Categories of data | Identification and contact details; data relating to the complaint, suggestion or claim; and, where applicable, alleged property or personal damages. |
| Recipients | Insurance companies and brokers where the claim is covered by a policy; professional firms involved in the processing; and those third parties to whom the data must be disclosed pursuant to a legal obligation. |
| International transfers | None are envisaged. |
| Retention | The data will be retained for one (1) year from the resolution of the complaint or suggestion (Article 1968 of the Civil Code). In the case of claims, until the case file is closed and, subsequently, for the limitation period applicable to any actions that may arise. |
| Source | The data subject themselves. |
Data recipients
Con carácter general, los datos personales tratados por el Responsable no se comunican a terceros, salvo en los supuestos expresamente identificados en cada uno de los tratamientos descritos en el apartado 4 anterior, en los casos legalmente previstos, o cuando exista consentimiento expreso del interesado.
Acceden a los datos, en calidad de encargados de tratamiento conforme al artículo 28 del RGPD, los prestadores de servicios que el Responsable ha contratado para el desarrollo de su actividad, en particular: proveedores de alojamiento web y hosting; proveedores de servicios de CRM y plataformas de marketing; proveedores de servicios de chatbot y atención virtual; gestorías, asesorías y despachos profesionales; y empresas de comercialización inmobiliaria, en su caso. Con todos ellos, el Responsable ha formalizado los contratos de encargo de tratamiento exigidos por la normativa, que garantizan un nivel de protección equivalente al del Responsable.
International data transfers
Determinados encargados de tratamiento del Responsable pueden estar ubicados fuera del Espacio Económico Europeo, en particular en Estados Unidos. En tales casos, las transferencias internacionales se realizan al amparo de las siguientes garantías previstas en el Capítulo V del RGPD:
- Decisión de adecuación de la Comisión Europea 2023/1795, de 10 de julio de 2023, relativa al marco EU-U.S. Data Privacy Framework, para aquellos proveedores adheridos al mismo.
- Cláusulas contractuales tipo aprobadas por la Comisión Europea mediante la Decisión de Ejecución (UE) 2021/914, complementadas, cuando proceda, con medidas suplementarias y la correspondiente evaluación del nivel de protección del país de destino, conforme a la doctrina del Tribunal de Justicia de la Unión Europea en el asunto Schrems II (C-311/18).
El interesado puede solicitar al Responsable información detallada sobre las transferencias internacionales realizadas y obtener copia de las garantías aplicadas, dirigiendo su solicitud al correo electrónico de contacto.
Data subject rights
The data subject may exercise, at any time, the following rights recognized by the GDPR and the LOPDGDD:
- Derecho de acceso (artículo 15 RGPD): a obtener confirmación sobre si se están tratando o no sus datos personales y, en caso afirmativo, a acceder a los mismos y a la información sobre el tratamiento.
- Derecho de rectificación (artículo 16 RGPD): a obtener la rectificación de los datos personales inexactos o incompletos.
- Derecho de supresión (artículo 17 RGPD): a obtener la supresión de los datos personales cuando concurra alguna de las circunstancias previstas en el RGPD.
- Derecho a la limitación del tratamiento (artículo 18 RGPD): a obtener la limitación del tratamiento en los supuestos legalmente previstos.
- Derecho a la portabilidad de los datos (artículo 20 RGPD): a recibir los datos personales en un formato estructurado, de uso común y lectura mecánica, y a transmitirlos a otro responsable, cuando el tratamiento se base en consentimiento o en un contrato y se efectúe por medios automatizados.
- Derecho de oposición (artículo 21 RGPD): a oponerse, por motivos relacionados con su situación particular, al tratamiento de sus datos basado en el interés legítimo del Responsable, así como, en cualquier momento, al tratamiento con fines de mercadotecnia directa.
- Derecho a no ser objeto de decisiones individuales automatizadas (artículo 22 RGPD), incluida la elaboración de perfiles, que produzcan efectos jurídicos o le afecten significativamente de modo similar. El Responsable no adopta decisiones de esta naturaleza en el desarrollo de su actividad.
- Derecho a revocar el consentimiento prestado, en cualquier momento, sin que ello afecte a la licitud del tratamiento basado en el consentimiento previo a su revocación.
De conformidad con el artículo 26.3 del RGPD, el interesado podrá ejercer sus derechos frente a cualquiera de los Corresponsables. A tal efecto, los derechos podrán ejercitarse mediante solicitud dirigida a cualquiera de los Corresponsables o al punto de contacto único, por correo postal a las direcciones indicadas en el apartado 2 o por correo electrónico a [···], acompañando copia del documento identificativo del solicitante o, en su caso, del representante legal junto con el documento acreditativo de la representación.
El Responsable atenderá la solicitud en el plazo máximo de un mes desde su recepción, prorrogable por dos meses adicionales cuando la complejidad o el número de solicitudes así lo justifique, en cuyo caso se informará al interesado de la prórroga dentro del primer mes.
El Responsable dispone de formularios para facilitar el ejercicio de los derechos, que pueden solicitarse al correo electrónico indicado. Asimismo, el interesado puede utilizar los modelos elaborados por la Agencia Española de Protección de Datos disponibles en su sede electrónica.
El interesado tiene derecho a presentar reclamación ante la Agencia Española de Protección de Datos cuando considere que el tratamiento de sus datos personales infringe el RGPD o la LOPDGDD, sin perjuicio de cualquier otro recurso administrativo o acción judicial. La Agencia Española de Protección de Datos tiene su sede en C/ Jorge Juan, 6, 28001 Madrid, y dispone de sede electrónica en www.aepd.es.
Security measures
Los Corresponsables han adoptado las medidas técnicas y organizativas apropiadas para garantizar un nivel de seguridad adecuado al riesgo del tratamiento, en cumplimiento de lo dispuesto en los artículos 24, 25 y 32 del RGPD. Dichas medidas tienen en cuenta el estado de la técnica, los costes de aplicación, la naturaleza, el alcance, el contexto y los fines del tratamiento, así como los riesgos de probabilidad y gravedad variables para los derechos y libertades de los interesados.
Sin perjuicio de lo anterior, el interesado reconoce que la transmisión de datos a través de Internet no es absolutamente segura y que cualquier información transmitida lo es bajo su propia responsabilidad.
Veracidad de los datos
El interesado declara que los datos personales facilitados al Responsable son veraces, exactos y actualizados, y se compromete a comunicar cualquier modificación de los mismos. En el supuesto de que el interesado facilite datos personales de terceros, declara haber informado previamente a dichos terceros del contenido de la presente Política y haber recabado, cuando resulte preceptivo, su consentimiento para la comunicación de sus datos al Responsable.
Tratamiento de cookies
Los sitios web utilizados para la comercialización de las promociones utilizan cookies y tecnologías similares, cuya información detallada se encuentra disponible en la Política de Cookies accesible desde cada sitio web. El uso de cookies no estrictamente necesarias requiere el consentimiento expreso del usuario, prestado conforme a lo dispuesto en el artículo 22.2 de la Ley 34/2002 y en las Directrices de la Agencia Española de Protección de Datos sobre el uso de cookies. La gestión de las cookies, los píxeles de seguimiento y las herramientas publicitarias (Google y Meta) corresponde a JT REAL ESTATE IBIZA, S.L. como titular de los sitios web y de las correspondientes cuentas publicitarias.

