This Privacy Policy explains how personal data is processed when you visit the Leonard’s Lookout website, submit a booking request, make or manage a direct booking, contact us, use a payment service connected with a booking, follow a link to an external service, or are present in areas of the property monitored by security cameras.
1. Data controller
The data controller responsible for this website and the personal data processed in connection with direct bookings is:
Verity-Jane Roworth
112 Fuente Nueva
Orce, Granada 18858
Spain
Email: hello@leonardslookout.com
2. Personal data we process
The information processed depends on how you use the website and whether you make a booking.
Direct booking enquiries
When you submit a direct booking request, we may process:
- First name and surname
- Email address
- Telephone or WhatsApp number
- Requested arrival and departure dates
- Number of adults
- Number of children
- Offer or promotional code, where provided
- Information included voluntarily in the message field
- Date and time of submission
- Technical information associated with the submission, such as IP address and browser or device information where recorded by the website or hosting system
Please do not include sensitive personal information in the message field unless it is genuinely necessary for your enquiry.
Direct booking administration
If a booking offer is prepared or a booking proceeds, we may also process:
- Agreed accommodation price
- Deposit and balance amounts
- Payment due dates
- Payment status and dates
- Wise payment-request links
- Whether a security deposit applies and, where applicable, its amount
- Booking reference
- Booking status
- Booking offers and confirmations
- Balance-payment correspondence
- Other correspondence concerning the reservation
Leonard’s Lookout does not collect or store online-banking passwords or payment-card credentials through this website.
Email enquiries and correspondence
If you contact us by email, we may process:
- Your name
- Email address
- Contents of your message
- Booking or stay details contained in the correspondence
- Other information you voluntarily provide
Copies of booking-related correspondence may be stored in the Leonard’s Lookout email system for record-keeping purposes.
Traveller registration
For confirmed stays, guests are required to provide information required by Spanish traveller-registration law.
The information requested for that purpose may include identification, contact, residence, booking and transaction information required by applicable legislation.
Leonard’s Lookout currently uses Check-in Scan to assist with guest registration and communication of the required information to the competent authorities.
Traveller-registration information is processed separately from the initial website booking-request form.
CCTV / security cameras
Two security cameras monitor the property drives for the safety of guests, owners, property and access areas. The cameras may record images of people and vehicles entering or leaving those areas.
Recordings are stored locally on a USB device and are normally deleted on a near-daily basis.
Technical and hosting data
When you visit the website, technical information may be processed automatically by the website and hosting provider. This may include:
- IP address
- Browser and device type
- Operating system
- Date and time of access
- Pages requested
- Referring website
- Technical errors
- Security information
This information is used to deliver, maintain and protect the website.
Website analytics
The website uses Google Analytics 4 to understand how visitors use the site and to improve its content and performance.
Analytics data may include:
- Pages viewed
- Approximate location
- Device and browser information
- Referring source
- Time spent on the website
- Interactions with links and website content
Google Analytics is activated in accordance with the visitor’s cookie and analytics consent choices.
Analytics cookies are not placed unless the required consent has been given.
The website may record interactions such as following links to Airbnb or submitting a booking request where analytics consent has been granted.
3. Purposes and legal bases
Personal data is processed for the following purposes.
Booking enquiries and pre-contractual steps
Information submitted through the Book Direct form or by email is used to:
- Check availability
- Respond to the enquiry
- Prepare a booking offer
- Provide prices and booking conditions
- Communicate with the prospective guest
- Take other steps requested before entering into a booking agreement
The legal basis is the taking of pre-contractual measures at the request of the person making the enquiry.
Managing confirmed bookings
Where a booking is confirmed, personal data is processed to:
- Administer the reservation
- Record payments
- Send booking confirmations
- Request outstanding balances
- Manage changes or cancellations
- Communicate before, during and after the stay
- Deal with problems, complaints or claims relating to the booking
The legal basis is the performance of the accommodation contract.
Traveller registration and other legal obligations
Information may be processed where necessary to comply with legal obligations, including:
- Traveller-registration requirements
- Communications required by competent authorities
- Tax and accounting requirements
- Consumer-protection obligations
- Official complaints or lawful requests
The legal basis is compliance with a legal obligation.
Security videovigilance
CCTV images are processed only for security purposes: protecting people, property and access areas and, where necessary, establishing or responding to a security incident.
The legal basis is Leonard’s Lookout’s legitimate interest in protecting people, property and the accommodation, in accordance with Article 22 of Spain’s Organic Law 3/2018 (LOPDGDD).
Website operation, security and fraud prevention
Technical information may be processed to:
- Deliver the website
- Maintain website and booking-system security
- Diagnose technical problems
- Prevent misuse, fraud and unauthorised access
- Protect booking information
- Maintain reliable website performance
The legal basis is our legitimate interest in operating and protecting the website and booking system.
Managing correspondence and legal claims
Relevant records may be retained where reasonably necessary to establish what was agreed, respond to disputes, establish or defend legal claims, or demonstrate compliance with applicable obligations.
The legal basis is our legitimate interest in managing and protecting our legal position and, where applicable, compliance with legal obligations.
Website analytics
Analytics information is processed to understand website traffic and performance.
The legal basis is the visitor’s consent.
Consent can be withdrawn or changed at any time through the website’s cookie-preference controls.
4. How booking information is stored
Booking requests submitted through the website are processed through Contact Form 7.
A copy of the booking enquiry is stored within the WordPress website using Flamingo, allowing Leonard’s Lookout to maintain a record of enquiries received.
The secure booking workflow may additionally store information relating to:
- The booking request
- Price quoted
- Payment-request links
- Deposit and balance information
- Booking status
- Booking reference
- Payment confirmation
- Copies of booking offers and confirmations generated through the system
Secure booking links use randomly generated access tokens and are not intended to be publicly accessible or indexed by search engines.
Booking-related email correspondence is also stored in the Leonard’s Lookout email account hosted by Hostinger.
5. Payment processing
Direct booking payments may be requested using Wise.
Where Wise is used, you may receive or follow a payment-request link provided for your booking.
Wise processes payment-related personal data in accordance with its own terms and privacy information.
Leonard’s Lookout may retain information necessary to identify and reconcile the payment, such as:
- Amount requested
- Amount received
- Payment date
- Payment status
- Booking reference
- Wise payment-request link
Leonard’s Lookout does not receive or store your Wise password, online-banking password or payment-card credentials.
6. Data sharing and service providers
Personal data is not sold.
Information may be processed by service providers where necessary to operate the website and manage bookings.
Hostinger
Hostinger provides website hosting, database infrastructure, email hosting and related technical services.
Website, booking and email information may therefore be processed on Hostinger systems as necessary to provide those services.
WordPress, Contact Form 7 and Flamingo
The website uses WordPress together with Contact Form 7 and Flamingo to operate the website booking-request system and store submitted enquiries.
These components operate within the website environment hosted by Hostinger.
Check-in Scan
Check-in Scan is used to assist with legally required traveller registration.
Where guest information is processed through Check-in Scan, it acts on behalf of Leonard’s Lookout in relation to guest-registration processing and may transmit the required information to competent authorities.
Wise
Wise provides payment services used for some direct-booking payments.
Where a guest uses Wise, Wise processes relevant payment information under its own privacy terms.
Google Analytics
Google provides website analytics services where the visitor has consented to analytics processing.
Public authorities
Personal data may be communicated where required by law to competent authorities, including authorities responsible for traveller registration, taxation, consumer protection, courts or law-enforcement functions.
CCTV recordings may also be provided to police, courts or another competent authority where necessary in connection with a security incident or legal requirement.
Professional advisers
Information may be disclosed to professional advisers such as accountants, gestores, insurers or legal advisers where reasonably necessary to obtain advice, comply with legal requirements or deal with a claim or dispute.
7. International data transfers
Some technology providers may process information outside Spain or the European Economic Area.
Where personal data is transferred internationally, appropriate safeguards will be used where required by applicable data-protection law.
These may include:
- An adequacy decision
- European Commission Standard Contractual Clauses
- Another legally recognised transfer mechanism
The applicable provider may also provide further information about international transfers in its own privacy documentation.
8. Data retention
Personal data is not retained for longer than reasonably necessary for the purpose for which it was collected.
The following general retention approach applies.
Unconfirmed enquiries
Booking enquiries that do not result in a confirmed reservation will normally be deleted or anonymised when they are no longer reasonably required, and normally within 12 months of the last relevant contact.
Secure booking workflow
Secure booking links and operational booking records use shorter access and retention periods appropriate to the booking workflow.
Access links may expire before the underlying correspondence or other records that must legitimately be retained.
Confirmed bookings
Booking contracts, confirmations, payment records and relevant correspondence may be retained after the stay where necessary for:
- Tax or accounting obligations
- Consumer obligations
- Establishing or defending legal claims
- Demonstrating the terms of the booking and payments made
Relevant contractual records may be retained for up to five years after the stay, where necessary, unless a different legal retention period applies.
Records required for tax purposes will be retained for the applicable statutory period.
Traveller-registration information
Traveller-registration information is retained and communicated in accordance with the legal requirements applicable to the accommodation and the systems used for that purpose.
Email correspondence
Booking-related emails may be retained for the same period as the related booking record where necessary.
General enquiries that do not lead to a booking will normally be removed when they are no longer required.
CCTV recordings
CCTV recordings are stored locally on a USB device and are normally deleted on a near-daily basis. In any event, recordings will be deleted within one month of capture unless a recording must be preserved for a specific security incident, legal claim or request by a competent authority.
Technical logs
Server and security logs are retained in accordance with the website’s security needs and the hosting provider’s applicable arrangements.
Analytics information
Analytics information is retained according to the retention settings configured within Google Analytics.
Cookie and consent records
Cookie and consent information is retained for the period reasonably necessary to remember and demonstrate the visitor’s choices.
Data may be retained for longer where necessary because of an ongoing dispute, legal claim, investigation or other legal requirement.
Where applicable, data may be restricted or blocked rather than immediately destroyed where Spanish law requires this while potential legal responsibilities remain outstanding.
9. Your data-protection rights
Subject to the conditions established by applicable law, you may have the right to:
- Request access to your personal data
- Request correction of inaccurate or incomplete information
- Request deletion of personal data
- Request restriction of processing
- Object to processing based on legitimate interests
- Request data portability
- Withdraw consent at any time where processing is based on consent
- Object to certain automated decision-making where applicable
These rights are not absolute. For example, information may sometimes need to be retained where required by law or where necessary for the establishment, exercise or defence of legal claims.
Withdrawing consent does not affect the lawfulness of processing carried out before consent was withdrawn.
To exercise your rights, email:
Please use Data protection request in the subject line and explain your request clearly.
Additional information may be requested where reasonably necessary to confirm your identity.
You also have the right to lodge a complaint with the Agencia Española de Protección de Datos — AEPD.
10. Cookies
This website uses necessary cookies and, where consent is provided, analytics cookies.
Detailed information about the cookies used, their purposes and how to change or withdraw consent is available in the website’s Cookie Policy (EU).
Visitors can change or withdraw their cookie choices through the website’s cookie-preference controls.
11. External websites and booking platforms
The website contains links to external websites and services, including Airbnb, Wise and third-party visitor information.
When you follow an external link, you leave the Leonard’s Lookout website.
The external provider may then process personal data under its own privacy policy and terms.
Leonard’s Lookout does not control how independent external websites process personal information.
Bookings made through Airbnb or another external booking platform are additionally subject to that platform’s own privacy arrangements.
12. Automated decision-making and marketing
Personal data processed by Leonard’s Lookout is not used for automated decision-making that produces legal or similarly significant effects.
Automated calculations within the direct-booking workflow, such as calculating the booking deposit, remaining balance or payment due date, are administrative calculations only and do not independently determine whether a person may make a booking.
The website does not currently operate an email newsletter.
Information supplied for a booking enquiry or reservation is not added to an automated marketing list without an appropriate legal basis.
13. Security
Reasonable technical and organisational measures are used to protect personal data against accidental loss, unauthorised access, alteration, disclosure or misuse.
Measures used within the direct-booking system include:
- Secure HTTPS website connections
- Restricted WordPress administration access
- Time-limited secure booking links
- Randomised booking-access tokens
- Authenticated SMTP for booking emails
- Restricted access to booking and email records
No internet transmission or storage system can be guaranteed to be completely secure.
14. Changes to this Privacy Policy
This Privacy Policy may be updated when the website, booking process, service providers or applicable legal requirements change.
The latest version will always be published on this page with its revision date.