Privacy Policy
Last updated: August 2026
This policy explains how Partelisto processes personal data when you use our guest check-in service. It covers hosts (account holders) and guests who complete a check-in link.
Who is responsible (roles)
Partelisto is operated by Mikhail Petrusheuski (self-employed / autónomo), NIE Z1493872G, Avinguda de la Vila Joiosa 12, 03502 Benidorm (Alicante), Spain — support@partelisto.es. For your account, billing and support, Partelisto is the data controller. For the guest check-in data collected on behalf of a host, the host (or their management company) is the controller and Partelisto acts only as their processor under Art. 28 GDPR. The Ministry of the Interior is the recipient established by law (RD 933/2021).
Data we collect
Account data: name, email, and authentication identifiers. Property and booking metadata: property name, address, NIF, municipality/province, dates. Guest check-in data (entered by the guest): name and surnames, date of birth, sex, nationality, document type and number, contact phone or email, residence, relationship for minors, and a typed or drawn signature. We do NOT ask for or store photos or scans of ID documents.
Purposes and legal basis
Account, billing and support: performance of the contract with the host (Art. 6.1.b) and our legitimate interest in securing the service (Art. 6.1.f). Guest register and its communication to SES.HOSPEDAJES: compliance with the host’s legal obligation (RD 933/2021; Art. 6.1.c). We do not rely on consent for the mandatory register, and we do not use guest data for marketing.
Recipients
Guest register data is transmitted to the Ministry of the Interior (SES.HOSPEDAJES) and is available to the host who requested the check-in. We use a small number of providers strictly needed to run the service (see subprocessors). We do not sell personal data and make no other disclosures except where required by law.
Subprocessors
We rely on a small set of providers — cloud hosting in Frankfurt, Germany (Kamatera, EU), Microsoft 365 for email delivery, and Stripe for host billing only (guests never pay); authentication, file storage and the databases are self-hosted on that infrastructure. The full, current list, with purpose and location, is published on our Subprocessors page (/subprocessors).
International transfers
Guest register data is hosted within the EU/EEA (Frankfurt, Germany). We do not sell it, and we do not use it beyond running the service and the SES filing. Some of our providers are US-incorporated (for example Kamatera and Microsoft), so an international transfer or remote access from outside the EEA cannot be entirely excluded; where that happens it is covered by an adequacy decision or by the appropriate safeguards under Chapter V GDPR, such as standard contractual clauses.
Retention
Account data is kept while the account is active and deleted (or anonymised) after closure, subject to legal retention of billing records. Guest register data is retained for the period required by the rules applicable to the host: a professionally-obliged host must keep the electronic register for three years from the end of the service (Real Decreto 933/2021); a non-professional host is exempt from keeping it but must still transmit it. Because that retention is a legal obligation of the host, for a professionally-obliged host we keep the full register on the host’s documented instruction and do not delete the identifying data before the three-year period ends, even on an erasure request — the legal retention duty prevails (Art. 17(3) GDPR); the host can export the register at any time to keep their own copy. Where erasure does apply — once the retention period has passed, or for a non-professional host — we remove the guest’s identifying data and delete the check-in PDF/CSV while keeping only the minimal filing record as proof the stay was reported. Backups are rotated and overwritten on a rolling basis.
Your rights
You may exercise access, rectification, erasure, objection, restriction and portability, and you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es). Guests: exercise your rights through the host (the controller) or by writing to support@partelisto.es and we will forward your request. Hosts: contact support@partelisto.es.
Minors
Guest data may include minors travelling with an adult. Their data is entered by the accompanying adult/guardian and processed solely for the legal traveller register, under the same legal obligation.
Automated decisions
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
Security
Data is stored in secured EU-hosted infrastructure. Access is restricted by role and by tenant, and the guest signature and identity data are handled only for producing the check-in documents and the SES filing. Guest passwords are never requested.
Changes and contact
We may update this policy; the "last updated" date reflects the current version. Privacy questions and requests: support@partelisto.es. This text has been reviewed by a Spanish data-protection professional.