Legal document
Privacy Policy
This policy explains in detail how Hotel Kimal collects, uses, stores, protects, and discloses personal data and website usage data when operating this website and its related services.
Last updated: February 18, 2026
1. Data controller
Hotel Kimal acts as the data controller for the personal data processed through this website.
Privacy contact channel: ameliafrank@kimal.cl
Operating reference address: Domingo Atienza 452, San Pedro de Atacama, Chile.
Regulatory reference: Chilean Law No. 19,628 and other applicable regulations, including any updates governing the processing of personal data.
2. Scope of this policy
This policy applies to the Hotel Kimal website, its forms, technical integrations, and digital service processes related to reservations.
This policy applies to visitors, prospective guests, guests, business contacts, and anyone interacting digitally with our web channels.
It does not apply to third-party websites or services linked from this site. Each third party operates under its own policies, terms, and data-protection mechanisms.
3. Categories of data we process
We process data that is adequate, relevant, and limited to what is necessary for legitimate service and operational purposes.
Identification and contact data
- • First and last name.
- • Email address and contact phone number.
- • Preferred language for guest service.
- • Country of residence and billing information where applicable.
Reservation and stay data
- • Check-in and check-out dates.
- • Reserved room or contracted service.
- • Special requests linked to the reservation.
- • Support interactions related to changes, confirmations, or incidents.
Payment and operational data
- • Payment status, currency, and transaction amount.
- • Technical identifiers used to reconcile payments and reservations.
- • Anti-fraud and operational validation records generated by payment providers.
Browsing and digital behavior data
- • Visited pages, navigation path, and interaction time.
- • Click events, form events, scroll depth, and section performance.
- • Device, browser, operating system, and screen resolution.
- • Traffic source and campaign parameters when available.
4. Sources of data collection
Data is obtained either through direct user interaction or through technical events generated by normal use of the site.
• Information entered by the data subject in forms, booking engines, or contact channels.
• Transaction data and process status sent by operational integrations.
• Technical logs and navigation events generated automatically through site usage.
• Data received from technology providers contracted to deliver the service.
5. Purposes of processing
Data is used for specific, explicit purposes compatible with service delivery.
- • Process reservations, payments, confirmations, and pre-contractual management.
- • Provide support before, during, and after the stay.
- • Manage hotel operations, internal coordination, and service continuity.
- • Analyze usage behavior to improve content, experience, and conversion.
- • Prevent abuse, technical fraud, unauthorized access, or malicious activity.
- • Comply with legal, tax, accounting, or regulatory obligations.
6. Legal basis for processing
Each processing activity relies on a valid legal basis according to its nature.
- • Performance of a contract or pre-contractual measures requested by the data subject.
- • Compliance with applicable legal obligations.
- • Legitimate interest in security, operations, and digital service improvement.
- • Consent for optional processing, especially advanced behavioral measurement.
7. Behavioral measurement and similar technologies
We use measurement technologies to understand how the site is used and to improve the digital experience.
Based on your privacy preferences, we may measure page views, clicks, section interaction, conversions, form events, and other usage signals relevant to performance analysis.
Where consent is the legal basis, you may manage it at any time from the site's privacy panel. Withdrawal does not affect the lawfulness of prior processing carried out under valid consent.
Behavioral metrics are used for experience, quality, and commercial effectiveness decisions, not for automated decision-making that produces significant legal effects on the data subject.
8. Data sharing and processors
We share data only when necessary to operate contracted services or to comply with legal obligations.
• Booking platforms, hotel-management tools, and payment gateways.
• Infrastructure, hosting, CDN, and security providers.
• Analytics, monitoring, and digital-experience observation tools.
• Email, messaging, and commercial support services.
We require confidentiality, security, and instruction-based processing commitments, limiting access to what is strictly necessary for the contracted service purpose.
9. International transfers
Some technology providers may process data outside Chile depending on their infrastructure.
Where cross-border processing occurs, we apply reasonable contractual and organizational safeguards to maintain an adequate level of protection.
Such transfers are limited to services necessary for digital operations, technical continuity, monitoring, and reservation management.
10. Retention periods
We retain data only for the time strictly necessary to fulfill purposes and legal obligations.
• Reservation and billing data: for the duration of the contractual relationship and any legally required period.
• Operational and support data: for reasonable periods to preserve service traceability.
• Analytics data: according to statistical need, technical configuration, and the digital improvement cycle.
• Security logs: for periods defined for incident investigation and internal audit.
11. Information security
We apply technical and organizational measures aimed at preventing unauthorized access, alteration, loss, or improper disclosure.
These include access controls, functional segregation, technical monitoring, backup protocols, and regular reviews of operational integrity.
No system is completely invulnerable; however, we maintain reasonable and proportionate safeguards to protect the data under our control.
12. Data subject rights and how to exercise them
You may exercise your rights at any time through the designated privacy contact channel.
- • Access: know which data we process about you and for what purpose.
- • Rectification: correct inaccurate, incomplete, or outdated data.
- • Erasure or deletion: request deletion where legally applicable.
- • Objection: request that we stop processing data in specific situations.
- • Restriction: request temporary limitation of processing in certain cases.
- • Portability, where applicable: request delivery in a structured format.
- • Withdrawal of consent: revoke optional permissions without affecting mandatory processing.
To exercise your rights, send your request to ameliafrank@kimal.cl stating your request, preferred response channel, and the minimum information required to verify your identity.
13. Minors
This website is not primarily directed to minors without adult supervision.
If we detect processing of minors' data without an applicable legal basis, we will take reasonable measures to restrict its use and/or delete the information in accordance with applicable law.
14. Changes to this policy
We may update this document to reflect legal, operational, or technical changes.
• We will publish each updated version at this same URL together with its effective date.
• If a change is material, we may communicate it through visible site channels.
• Continued use of the site after publication implies awareness of the current version.