Privacy Policy
Last updated: 7 October 2025
CASA BLANCA is committed to protecting the privacy of users who access this website and/or any of its services. By using the website and/or any of the services offered by CASA BLANCA, users accept the provisions set out in this Privacy Policy and agree that their personal data may be processed in accordance with its terms. Please note that although our website may contain links to other websites, this Privacy Policy does not apply to the websites of other companies or organisations to which our website may redirect you. CASA BLANCA does not control the content of third-party websites and accepts no responsibility for their content or privacy policies.
Information on Data Processing (Regulation (EU) 2016/679 and Organic Law 3/2018)
| Data Controller: | BLANCA GARCIA GARRIDO (CASA BLANCA) Tax ID (NIF): 40532479Q C/ Migdia 139, L-2, 17003 Girona, Spain Email: reserves@casablancagirona.com |
| Purpose of Processing: | To provide and manage our gastronomic services for events. |
| Legal Basis |
|
| Recipients: | Personal data will not be disclosed to third parties unless required by law or necessary to fulfil the purpose for which the data was collected. |
| Data Subject Rights: | Data subjects have the right to exercise their rights of access, rectification, restriction of processing, erasure, data portability and objection by submitting a request to our address. |
| Data Retention Period: | Personal data will be retained for as long as the commercial relationship remains in place or for the period required to comply with applicable legal obligations. |
| Complaints: | Data subjects may contact the Spanish Data Protection Agency (AEPD) to lodge any complaint they consider appropriate. |
| Additional Information: | Further detailed information can be found below under “Privacy Matters”. |
Privacy Matters
In compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and Organic Law 3/2018 of 5 December on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD), we provide the following information regarding the processing of your personal data.
Who is responsible for processing your data?
Identity: BLANCA GARCIA GARRIDO (CASA BLANCA)
Tax ID (NIF): 40532479Q
Address: C/ Migdia 139, L-2, 17003 Girona
Tel.: 621684230
Email: reserves@casablancagirona.com
What is the purpose of processing your personal data?
- We process the information provided to us in order to manage our gastronomic services for events.
- If you contact us through the contact form on our website, we will process your data in order to manage and respond to your enquiry.
- We may also use your data to inform you about our activities, products or services when you are already a customer or, if you are not a customer, when you have given us your consent to do so.
How long will we retain your data?
The personal data provided will be retained for as long as you use our services or wish to receive information from us, as you may object to the processing of your data for promotional purposes either when you provide your data or at any subsequent time by contacting us at reserves@casablancagirona.com, and after this period, the data will be retained for the periods required to comply with our legal obligations. In the case of accounting and tax documentation, data will be retained for 6 years for commercial purposes, in accordance with Article 30 of the Spanish Commercial Code, and for 4 years for tax purposes, in accordance with Articles 66 to 70 of the Spanish General Tax Law.
What is the legal basis for processing your data?
For managing the contractual relationship with the data subject, we will base the processing of personal data on the performance of the contract or on pre-contractual measures.
For sending commercial information, processing will be based on your consent. However, if you are already a customer, we may send you information about our products and services, always providing a simple and free means of unsubscribing, in accordance with Article 21.2 of Law 34/2002 of 11 July on Information Society Services and Electronic Commerce.
With regard to information submitted by children under 14 years of age, it is an essential requirement that such information be provided with the consent of a parent, guardian or legal representative before the personal data can be processed. If this is not the case, the child’s legal representative must notify us as soon as they become aware of it.
To whom will your data be disclosed?
Personal data will not be disclosed to third parties unless required by law or necessary to fulfil the purpose for which the data was collected.
What are your rights when you provide us with your data?
- Everyone has the right to obtain confirmation as to whether or not we are processing their personal data.
- Data subjects have the right to access their personal data and to request the rectification of inaccurate data or, where applicable, its erasure when, among other reasons, the data is no longer necessary for the purposes for which it was collected.
- Under certain circumstances, data subjects may request the restriction of the processing of their data. In such cases, we will retain the data solely for the establishment, exercise or defence of legal claims.
- Under certain circumstances and for reasons relating to their particular situation, data subjects may also object to the processing of their personal data. In such cases, we will stop processing the data unless there are compelling legitimate grounds for doing so or the processing is necessary for the establishment, exercise or defence of legal claims.
- Data subjects also have the right to data portability.
- Data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
- Finally, data subjects have the right to lodge a complaint with the competent supervisory authority.
How can you exercise your rights?
You can exercise your rights by sending us a written request, together with a copy of an identification document, to our postal or email address.
How did we obtain your data?
The personal data we process comes from the data subject, who guarantees that the personal data provided is accurate and accepts responsibility for informing us of any changes. Fields marked with an asterisk are mandatory in order for us to provide the requested service.
What data do we process?
The categories of data we may process include:
- Identification data
- Postal or email addresses
The data collected is limited, as we only process the information necessary to provide our services and manage our business activities.
Do we use cookies?
We use cookies while you browse our website, with the user’s consent.
Users can configure their browser to notify them when cookies are being used and to prevent their use. Please refer to our Cookie Policy for further information.
What security measures do we apply?
We apply the security measures established under Article 32 of the GDPR and have therefore adopted the necessary security measures to ensure an appropriate level of security in relation to the risks associated with the data processing we carry out. These measures include mechanisms designed to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
Some of these measures include:
- Informing staff about data processing policies.
- Performing regular backups.
- Controlling access to data.
- Carrying out regular verification, assessment and evaluation processes.