Privacy
DATA PROTECTION INFORMATION
1. Controller and contact details
This notice applies to the Internal Reporting System of Turística Antel SL, tax identification number B57076580, for its Cala Llamp location, operating under the Grupo Folies brand.
Registered address: C/ Gabriel Roca Garcías, 1, 07157 Andratx, Illes Balears, Spain.
Data protection and rights contact: info@beachclubgranfolies.com. Postal address for requests: C/ Carlos Sáenz de Tejada 4, units 417–418, 07181 Magaluf, Illes Balears, Spain.
According to information provided by Turística Antel SL, the company has no Data Protection Officer and is not required to appoint one. It receives data protection advice from Conversia SLU. Turística Antel SL remains the controller of personal data processed through the reporting system. Requests concerning the reporting system will be handled confidentially.
2. Purposes and legal basis
Data are used to receive and assess reports, decide whether to investigate, conduct investigations, communicate with reporting persons, take corrective action, comply with legal duties and establish or defend rights. Access controls and activity records protect the operation of the system.
As the company has more than fifty employees, processing is based on a legal obligation (GDPR Article 6(1)(c) and Article 30(2) of Spanish Law 2/2023). Special-category data may only be processed where legally necessary, under the conditions and safeguards of GDPR Article 9(2)(g) and Law 2/2023. Acknowledging this notice is not consent to disclose identity and does not replace the applicable legal basis.
3. Data and sources
Data may include the account of events, dates, locations, documents, messages, information about persons concerned and witnesses and, if provided, the reporting person's identity and contact details. Information may come from the reporting person and investigative activities. Provide only relevant information and avoid unnecessary sensitive or third-party data. Irrelevant data will be deleted without undue delay, applying the specific deletion requirements of Articles 29 and 32 of Law 2/2023.
4. Anonymity, confidentiality and recipients
You may report anonymously and follow up using your reference and access key. If you identify yourself, your identity remains confidential and will not be disclosed to the person concerned. It may only be disclosed to a judicial authority, the Public Prosecutor or a competent administrative authority in the legally prescribed cases and subject to safeguards. You will be informed in advance unless doing so could compromise the investigation or proceedings.
Access is restricted to the System Officer and authorised managers; human resources where disciplinary action is appropriate; legal services where legal action is appropriate; designated processors and the Data Protection Officer, within their respective duties. Other disclosures must be necessary and legally justified. Authorised technical support is subject to confidentiality and activity logging.
Hosting, maintenance and email providers; international transfers and safeguards, if any: hosting and maintenance managed by Grupo Doutai; planned email delivery through Microsoft 365. Reporting data are not used for advertising.
5. Retention
Data remain in the intake system only for the time essential to decide whether to investigate. If no investigation has begun within three months of receipt, the data must be deleted, except evidence of the system's operation, which must be anonymised for reports that are not pursued. Information established to be untrue must be deleted promptly unless its falsity may constitute a criminal offence and retention is required for judicial proceedings.
Investigation and register data are retained only as necessary and proportionate for the statutory purposes, never for more than ten years under Article 26. This maximum does not authorise retaining every case for ten years. The organisation must apply the criteria to backups and document retention and deletion decisions.
6. Rights and complaints
You may request access, rectification, erasure, restriction, objection and, where applicable, portability through the contact in section 1. These rights are subject to legal conditions and do not entitle anyone to learn the reporting person's identity or protected third-party information. For anonymous reports, additional identifying information will not be required solely to identify you unless necessary to handle your request. You may complain to the Spanish Data Protection Agency: https://www.aepd.es/
No decisions with legal effects are based solely on automated processing: assessment is performed by the responsible persons.
7. Security and browsing
Protect your reference and access key and sign out on shared devices. Documents and their metadata may identify you even if you leave identity fields blank. Technical session cookies are used; this portal does not incorporate advertising analytics. Hosting may generate technical connection logs subject to the installation's security controls and retention periods. Email notifications do not contain case narratives or documents.
Applicable legislation: Spanish Law 2/2023, the GDPR and Spanish Organic Law 3/2018.
https://www.boe.es/eli/es/l/2023/02/20/2/con