Privacy policy
Last updated: August 2026
1. Two distinct processing activities
It is worth separating two situations that people often mix up:
- Your data as a visitor or prospective customer. If you fill in the demo form or write to us, WOWTECH SL is the data controller. That is what this policy governs.
- The data of guests staying at a hotel that uses Hostelum. In that case the controller is the hotel and WOWTECH SL acts as data processor, under the Article 28 GDPR agreement we sign with every customer. If you are a guest at a property and wish to exercise your rights, you should contact the property.
2. Data controller
- Identity: WOWTECH SL — tax ID B22782908
- Address: Carrer Mitja Galta, 1, àtic 2, 08301 Mataró (Barcelona), Spain
- Data protection contact: privacidad@hostelum.com
3. What data we process and why
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Responding to your demo or information request | Name, property, email, phone, number of rooms and whatever you tell us | Consent and pre-contractual steps taken at the data subject's request | Up to 12 months from the last contact, unless a contractual relationship begins |
| Managing the contractual relationship | Customer identification and billing data | Performance of a contract | For the duration of the relationship and the statutory limitation periods |
| Site security and abuse prevention | IP address and technical logs | Legitimate interest in protecting the service | The minimum technically necessary period |
4. Tracking, only with your permission
The Hostelum website is a static site that uses no behavioural analytics and no social network pixels. The only third-party tool is a Google advertising measurement tag, which is loaded only if you expressly accept it in the cookie notice; if you decline it, your browser makes no requests to Google's servers. Typefaces and all other resources are served from our own domain. See the cookie policy for the detail and to change your choice.
5. Recipients
We do not disclose your data to third parties for commercial purposes. It may be accessed, as processors and under a signed agreement, by the suppliers needed to deliver the service: server hosting in the European Union, corporate email and, where applicable, sales management tools. The list of sub-processors relevant to running the product is set out on the security page.
6. International transfers
Our servers are in the European Union. Some of the product's suppliers — notably the payment gateway and the document scanning service — may carry out processing outside the European Economic Area, covered by standard contractual clauses approved by the European Commission.
7. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to privacidad@hostelum.com, stating which right you are exercising. We will reply within one month. If you consider that we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) (aepd.es).
8. Security
We apply technical and organisational measures appropriate to the risk: traffic encryption, access control with two-factor authentication, access logging, data isolation per customer and daily backups. The detail is published on the security page, including what we do not do yet.
9. Changes
If we amend this policy, we will update the date shown above. Substantial changes will be communicated to customers by email.