Privacy Policy
This page explains what personal data we collect when you use this website, why we collect it, who else sees it, and what rights you have. We have tried to write it in plain language rather than legal shorthand.
Who is responsible
The controller of your personal data is:
Lackner Oberkanins SL, trading as Finca Legado Ibiza
Polígono 16, 0165A, 07840 Santa Eulària des Riu, Illes Balears, España
NIF: B16561201
Email: reservations@legado-ibiza.com
Telephone: +34 690 967383
We have not appointed a Data Protection Officer, as we are not required to do so.
When you contact us
If you write to us by email, message us on WhatsApp or call us, we process the details you give us — your name, your contact details and whatever you tell us about your enquiry — in order to answer you.
Legal basis: the steps taken at your request before entering into a contract, and our legitimate interest in responding to enquiries (Art. 6(1)(b) and (f) GDPR).
We keep enquiry correspondence for as long as it remains relevant, and in any case no longer than three years after our last contact, unless it becomes part of a booking.
When you book a stay
Bookings are made through our reservation system, Sirvoy. When you book, the data you enter — name, contact details, dates of stay, number of guests, payment details and any notes you add — is processed by Sirvoy on our behalf so that we can carry out your booking.
Legal basis: performance of the accommodation contract (Art. 6(1)(b) GDPR).
Booking and invoicing records are kept for the periods required by Spanish tax and commercial law — currently six years for accounting records, and longer where tax law requires it.
What we are required to report to the authorities
Spanish law requires accommodation providers to record and transmit guest data to the Ministry of the Interior. We do this through the SES.Hospedajes platform, as required by Royal Decree 933/2021.
To collect this data we use an online check-in service (Checkinscan). Before arrival we send you a secure link where you enter the required details and upload your identity document; from there the data is transmitted to the authorities through SES.Hospedajes.
This covers more than a copy of your passport. The data to be transmitted includes identification details of every guest, contact details, the details of the stay, and the means of payment used. We also transmit booking data, including bookings made through third parties.
We cannot accommodate you without this. It is a legal obligation, not something we can waive at your request, and it is not a decision of ours.
Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR).
When you buy a gift voucher
To issue a gift voucher we process the purchaser’s name and email address, the amount, and — if you enter one — the name of the recipient and your personal message. The voucher itself is sent to you as a PDF by email.
Payment is handled entirely by Stripe. We never see or store your card details; we only receive confirmation that payment succeeded, together with the payment reference.
We keep a record of each voucher — code, value, remaining balance and dates — for as long as the voucher can still be redeemed and thereafter for the retention periods required by accounting and tax law.
Where you enter the name of a recipient, please make sure they are content for you to do so. We use it only to personalise the voucher.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and compliance with a legal obligation (Art. 6(1)(c) GDPR).
When you subscribe to our newsletter
Our newsletter is sent with Mailchimp (Intuit Inc.). If you enter your email address in the subscription form, we pass it to Mailchimp, which sends you a message asking you to confirm that the address is yours. Your subscription only becomes active once you click the link in that email. If you do not confirm, the address is not added.
Mailchimp records your email address, the date and time of your subscription and of your confirmation, and the IP address used. This is how we can demonstrate that you consented — a requirement of data protection law, not a form of tracking.
Mailchimp also records whether our emails were opened and which links were clicked. We use this only to judge whether our newsletter is of interest, and we tell you so in the subscription form.
Legal basis: your consent (Art. 6(1)(a) GDPR).
You can withdraw your consent at any time, with effect for the future. Every newsletter contains an unsubscribe link, and you may also simply write to us.
When you simply visit this website
To understand how our website is used, we use Plausible, a privacy-friendly analytics service hosted in the European Union. Plausible measures visits and where they broadly come from — without cookies, without tracking you across other websites, and without building any profile of you. The figures are aggregated and anonymous, and we cannot identify you from them.
We use no advertising cookies and no tracking pixels, we do not build profiles of our visitors, and we do not sell data to anyone. We set no cookies of our own — which is also why you will not see a cookie banner on this site.
Legal basis: our legitimate interest in understanding and improving our website (Art. 6(1)(f) GDPR).
Our website is hosted by Netlify. Like every web server, Netlify records technical access data — the requesting IP address, the page requested, the time, and the browser and operating system reported by your device. This is necessary in order to deliver the page to you and to keep the service secure and stable.
Legal basis: our legitimate interest in operating a secure and functioning website (Art. 6(1)(f) GDPR).
Content we load from other providers
Two elements of this website are loaded from external servers. In both cases your IP address is transmitted to that provider, because otherwise the content cannot reach your device.
Typography: our typefaces are delivered by Adobe Fonts (Adobe Inc.).
Map: the map on our contact page uses map data from OpenFreeMap and the MapLibre display library, loaded from their servers. The map appears only on that page.
Legal basis: our legitimate interest in presenting the site consistently and in showing you where we are (Art. 6(1)(f) GDPR).
Who else processes your data
We use the following service providers, each bound by a data processing agreement:
— Netlify — hosting of this website
— Plausible — privacy-friendly, cookieless website analytics (hosted in the EU)
— Sirvoy — booking and guest management
— Stripe — payment processing for gift vouchers
— Supabase — storage of gift voucher records
— Resend — sending of gift vouchers and other transactional emails
— Checkinscan — online guest check-in and identity registration
— Mailchimp — our newsletter
Beyond these, we pass on data only where we are legally obliged to — in particular to the Ministry of the Interior through SES.Hospedajes, to the tax authorities, and to our tax adviser.
Transfers outside the European Union
Several of the providers named above — in particular Stripe, Mailchimp, Netlify and Resend — are established in the United States or process data there. Where that is the case, the transfer is based on the European Commission’s standard contractual clauses and, where applicable, on the EU–US Data Privacy Framework.
You may ask us for a copy of these safeguards at any time.
Your rights
You have the right to ask us:
— what data we hold about you, and to receive a copy of it
— to correct data that is wrong or incomplete
— to delete your data, where we are not required to keep it
— to restrict how we use your data
— to hand over the data you gave us in a portable format
— to stop processing based on legitimate interest, where your situation gives you grounds to object
Where processing is based on your consent, you may withdraw it at any time. This does not affect what we did lawfully before you withdrew it.
Please note that we cannot delete data we are required to keep — in particular guest registration data transmitted under Royal Decree 933/2021, and accounting records.
To exercise any of these rights, write to reservations@legado-ibiza.com. We will reply within one month.
If you believe we are handling your data unlawfully, you may lodge a complaint with the Spanish data protection authority: Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid, www.aepd.es
Security
This website is delivered exclusively over an encrypted connection (HTTPS). Access to guest and voucher records is restricted to the members of our team who need it, and is protected by individual credentials.
Changes to this policy
If we change how we handle personal data — for example by adding a new service — we will update this page. The date below tells you which version you are reading.
Last updated: 1 August 2026
Last updated: 1 August 2026