Dear Customer and User:
Pursuant to the Federal Law on the Protection of Personal Data Held by Private Parties (the “Law”), its Regulations (the “Regulations”), and other applicable provisions, Diestra Restaurantes, S.A. de C.V. (hereinafter, “Diestra Restaurantes” or the “Data Controller”) makes this Comprehensive Privacy Notice available to you. This Notice has been prepared, among other applicable requirements, in accordance with Article 15 of the Law.
This Privacy Notice is intended to provide you, as the data subject, with the information necessary to make informed decisions regarding the processing of your personal data.
Diestra Restaurantes, S.A. de C.V. is solely responsible for collecting, obtaining, using, storing, retaining, administering and otherwise processing the personal data covered by this document. For commercial and operational purposes, the terms “Grupo Diestra” or “Group” are used solely to identify the establishments, brands and business units operating under a common corporate structure. Such terms do not, in themselves, imply the existence of a separate or additional data controller other than the entity identified in this Notice.
Data Processors
The companies, affiliates, subsidiaries, hotels, establishments, business units and other entities forming part of or associated with Grupo Diestra may participate in the provision of services and, when processing personal data on behalf of Diestra Restaurantes, will act as data processors in accordance with the Data Controller’s instructions. Their relationship with the Data Controller will be documented through contracts or other legal instruments governing processing, confidentiality, security, subcontracting, return or deletion of data, and other applicable obligations. Their status as data processors does not, by itself, make such entities independent data controllers.
For informational and operational purposes, Grupo Diestra includes, without limitation, the following lodging, food and beverage, and SPA establishments in Mexico, to which this Privacy Notice applies: Emporio Acapulco; Emporio Veracruz; Emporio Ixtapa; Emporio Cancún; Emporio Mazatlán; Emporio Zacatecas; Samba Vallarta; Marriott México City Reforma; Marriott México City Santa Fe; Marriott Aguascalientes; Marriott Tijuana; Marriott Los Cabos; Marriott Tuxtla Gutiérrez; Marriott Villahermosa; Emporium Vacation Club; Bacoli; Trattoria; Cúa; Condimento; Jasha Spa; Úa; Litoral; La Cevicheria; Káajal; and Quattro.
Identity and Address of the Data Controller:
Diestra Restaurantes, S.A. de C.V.
Address: Boulevard Manuel Ávila Camacho No. 50, Lomas Plaza Building, Fourth Floor, Suite 515, Lomas de Chapultepec, Miguel Hidalgo, ZIP Code 11000, Mexico City, Mexico.
Privacy and ARCO Rights Contact: confidencialidad@grupodiestra.com
1. PERSONAL DATA
Under applicable law, personal data means any information relating to an identified or identifiable individual. In order to properly provide lodging, restaurant, bar, SPA, social event and related technology services, Diestra Restaurantes may process the following categories of data:
• Identification Data: First and last name, date of birth, sex, nationality or citizenship, photograph, handwritten or digital signature, valid government-issued identification, passport, visa or immigration document, where applicable, information contained in official identity documents, and guest or customer number.
• Contact Data: Full physical address, mobile and landline telephone numbers, email address, professional contact information, social media profiles, and any other communication channel or means provided directly by you.
• Lodging, SPA and Commercial Relationship Data: Arrival and departure dates (check-in and check-out), reservations, room assignments, stay preferences, travel and stay history, purpose of travel, travel frequency, contracted services, food and beverage consumption, contracted SPA treatments and services, social events, memberships, participation in loyalty programs, benefits received, specific requests, comments, complaints, suggestions and satisfaction surveys.
• Employment or Professional Data: Company name, position, profession, occupation, corporate or work contact information, and relationship with the legal entity that contracts or pays for the services.
• Tax and Billing Data: Federal Taxpayer Registry (RFC), tax address, tax regime, requested use of CFDI, electronic invoicing information, and other information necessary to comply with applicable tax obligations.
• Financial or Asset Data: Information necessary to process transactions, payments, deposits, charges, refunds, reservation guarantees and billing, including credit or debit card numbers, expiration dates, security codes, bank accounts, payment methods and transaction records. The Data Controller will seek to ensure that full credit card details are processed directly through certified payment terminals and payment processors in accordance with applicable security standards.
• Technology and Browsing Data: IP address, session or device identifiers, browser type, operating system, information concerning your use of our website or mobile applications, cookies, web beacons, SDKs, tracking pixels, similar technologies, and metadata generated by web analytics and digital marketing tools.
• Data Obtained Through Hotel and Technology Systems: Information recorded in property management systems (PMS), central reservation systems (CRS), customer relationship management systems (CRM), online reservation platforms and booking engines, access control systems, hotel Wi-Fi, guest service systems, loyalty programs, service operations management platforms, and other tools used for the coordinated operation of the hotels.
• Location or Mobility Data: Approximate or real-time geographic location where technically necessary and expressly enabled by the data subject for a particular functionality, security, personalized assistance, or guest service within the premises.
• Images and Audiovisual Recordings: Images and video captured through closed-circuit television (CCTV) or video surveillance systems visibly installed in common areas, hallways, entrances, exits and other authorized areas of the establishments, solely for security, crime prevention, investigation, access control and incident response.
• Third-Party and Accompanying-Person Data: Identification, contact and lodging information concerning third parties, accompanying persons or family members that you provide to make reservations, register stays, or coordinate events or services. By providing such data, you represent and warrant that you have sufficient authorization and authority from the third party to provide the information and that you have informed them of the terms of this Privacy Notice.
• Data Concerning Minors: Identification and registration data concerning minors that are strictly necessary for the provision of contracted services, formal guest registration, security controls in common areas (such as pools or SPA facilities), emergency response, or compliance with applicable regulatory obligations.
• Vehicle Data: License plate number, make, model, color, vehicle registration card, and other information necessary for parking and valet parking services, access control and physical security of the premises.
• Communications and Service Data: Records of requests, messages, correspondence, telephone calls, chats, contact records, complaints, claims, communication preferences, and any other information generated during your relationship with the hotel.
• Food, Accessibility and Special-Needs Data: Food preferences, food allergies, intolerances, dietary restrictions, special physical or mobility accessibility needs, or specific conditions voluntarily provided by the data subject to facilitate a safe and appropriate stay. Where this information reveals aspects of the data subject’s health status, it will be subject to restricted processing and the security measures applicable to sensitive personal data.
2. SENSITIVE PERSONAL DATA
The Law considers sensitive personal data to be data that affect the most private sphere of the data subject, or whose improper use could result in discrimination or pose a serious risk to the data subject. In the context of hotel, restaurant, bar, and SPA services, Diestra Restaurantes may process, only where necessary and lawful, data concerning present or future health status, genetic information, allergies or conditions that reveal health status, assistance needs, and other information that meets the legal definition of sensitive personal data.
In the context of hotel, restaurant, bar and SPA services, the Data Controller may process, only when strictly necessary for a legitimate purpose, data concerning present or future health status, medical conditions, allergies, intolerances where they reveal health status, specific assistance needs, disabilities that by their nature meet the legal definition of sensitive personal data, and clinical information voluntarily provided by the data subject.
Such processing will be carried out exclusively to adapt lodging and SPA services to your physical needs, prevent health risks, respond to medical emergencies, and comply with the applicable legal framework. Such data will be processed under the strictest administrative, physical and technical security measures, with absolute confidentiality and access limited to medical personnel or authorized employees.
Where required by the Law, Diestra Restaurantes will obtain your express written consent to process this category of data.
CCTV images are treated as personal data when they permit an individual to be identified and are used for security purposes. The capture of an image by CCTV does not, by itself, make the data sensitive. If facial-recognition, fingerprint, or other biometric technologies were implemented, Diestra Restaurantes would conduct the corresponding legal analysis, disclose the processing through the applicable privacy notice, and obtain any consent legally required.
Financial or asset data require express consent, except where an exception under the Law applies. Classification as financial or asset data does not, by itself, mean that such data are legally considered sensitive personal data.
3. COLLECTION OF PERSONAL DATA AND SENSITIVE PERSONAL DATA
Diestra Restaurantes may collect your personal data through various channels, ensuring that the principles of transparency and lawfulness established by applicable regulations are observed in each case:
• In person: When you provide the data directly to our employees and personnel in reception, concierge, SPA, restaurants, bars, event management, or membership and loyalty-program sales, including through handwritten guest registration forms, health questionnaires, or feedback forms.
• Directly: When you provide the data through electronic, optical, audio, visual, or other technologies, such as calls to our reservation center, email, our official websites, brand mobile applications, social media, online forms, service chats, QR codes, electronic registration kiosks, Wi-Fi access portals, and interactive in-room television systems.
• Indirectly: When your personal data are lawfully transferred to Grupo Diestra by travel agencies, including online travel agencies (OTAs), event organizers, corporations and employers, tour operators, global distribution systems, business partners, or other third parties lawfully involved in contracting or managing services on your behalf.
• Through video surveillance systems: Through the capture of images and, where applicable, audiovisual recordings by CCTV cameras installed at Grupo Diestra establishments solely for protection, security, prevention of unlawful conduct, and incident response.
• Through digital tracking technologies (Cookies and similar technologies): Through cookies, web beacons, SDKs, tracking pixels, and equivalent technologies that collect browsing data when you access our digital environment, including analytics and advertising tools such as Google Analytics and Google Ads, when enabled by you or otherwise enabled by default under our configuration policies.
When personal data are obtained indirectly, Diestra Restaurantes will comply with the information requirements established by the Law and its Regulations and, where applicable, with legally permitted compensatory measures when direct notice to the data subject is impossible or would require disproportionate efforts.
4. PERSONAL DATA PROTECTION DEPARTMENT
The department responsible for internal privacy administration and for handling requests to exercise ARCO Rights, withdraw consent, and limit the use or disclosure of data is the Personal Data Protection Department of Diestra Restaurantes, designated for such purposes by the Data Controller. Its contact details are as follows:
• Contact Department: Personal Data Protection Department of Diestra Restaurantes, S.A. de C.V.
• Address: Boulevard Manuel Ávila Camacho No. 50, Lomas Plaza Building, Fourth Floor, Suite 515, Lomas de Chapultepec, Miguel Hidalgo, ZIP Code 11000, Mexico City, Mexico.
• Contact Email: confidencialidad@grupodiestra.comconfidencialidad@grupodiestra.com
5. PROCESSING OF PERSONAL DATA AND/OR SENSITIVE PERSONAL DATA
Under the applicable legal framework, processing of your personal data includes its collection, use, recording, organization, retention, preparation, utilization, communication, storage, possession, access, handling, use, transfer, or disposal, whether by physical, manual, or automated means.
Diestra Restaurantes is firmly committed to processing your information in strict accordance with the data protection principles established by the Law: lawfulness, consent, transparency, data quality, purpose limitation, fairness, proportionality, and accountability. Processing will be limited to what is appropriate, relevant, and necessary to fulfill the legitimate and explicit purposes described in this Notice.
If your personal data are to be processed for a purpose other than those formally stated in this document, Diestra Restaurantes will act strictly in accordance with the applicable legal framework, updating this Privacy Notice and obtaining your free, prior, and informed consent whenever required by the Law.
6. PURPOSES OF PROCESSING PERSONAL DATA
The processing of your personal data is divided into two categories of purposes. Primary purposes are those necessary to establish, maintain, and fully perform the legal and service relationship between the data subject and the Data Controller. Secondary purposes concern marketing, advertising, and commercial prospecting activities that may improve your experience but are not necessary to provide the services.
Primary Purposes (Necessary and Essential to Provide the Services):
• Manage reservations, quotations, confirmations, modifications, cancellations of lodging stays, and other related services.
• Carry out guest check-in and check-out, including mandatory identity verification and immigration registration where legally required.
• Provide safe and high-quality lodging, food and beverage, restaurant, bar, SPA, concierge, internal or external transportation, event planning, banquet, entertainment, and other experiences contracted by you.
• Properly process charges, payments, security deposits, refunds, inquiries, room or account charges, electronic invoicing (CFDI), and tax receipts arising from your stay or purchases.
• Manage individual requirements, personal preferences, specific dietary requests (including allergies and intolerances), special accessibility needs, physical assistance requirements, and other accommodations requested during your stay.
• Register, identify, and manage the access and stay of accompanying persons, family members, and additional guests entering with the data subject, including appropriate controls concerning minors where necessary.
• Administer loyalty programs and memberships, including the accrual and redemption of points, exclusive frequent-traveler benefits, and promotions contracted or associated with your membership.
• Receive, route, respond to, and follow up on complaints, comments, suggestions, incidents, claims, inquiries, and special service requests.
• Maintain guest and customer files, historical databases, and accounting, administrative, and operational records for the periods required under Mexican law for proper tax, administrative, and legal compliance.
• Prevent, detect, mitigate, investigate, and document fraud, misuse of services, unlawful conduct, violations of terms, and risks that could compromise the safety of guests, employees, visitors, facilities, or Grupo Diestra property.
• Operate CCTV and video surveillance systems on an ongoing basis to protect the physical safety of persons, manage internal access controls, and respond to incidents.
• Provide and administer Wi-Fi Internet connectivity and technical and network support in common areas and guest rooms at Grupo Diestra hotels.
• Operate and maintain internal PMS (Property Management System), CRS (Central Reservation System), CRM (Customer Relationship Management), and other reservation and hotel property management technologies essential to operations.
• Comply with legal, tax, regulatory, and administrative obligations applicable to the hotel and restaurant industries in Mexico, and respond to duly supported requests and orders issued by competent authorities.
• Exercise, defend, or enforce any right or legal action arising from contracts, the commercial relationship, or legal relationships established with the data subject.
Secondary Purposes (Not Necessary to Provide the Services):
• Send marketing communications, promotional emails, personalized offers, newsletters, commercial updates, greetings, and invitations to special events organized by Grupo Diestra brands.
• Conduct market research, commercial segmentation, consumer profiling, and analysis of preferences and travel trends to improve our commercial offering and service design.
• Conduct opinion surveys and quality and satisfaction studies to improve the guest experience at hotels, restaurants, bars, and SPA facilities.
• Design, implement, and operate advertising campaigns, direct commercial prospecting activities, and specific customer loyalty and retention programs.
Opt-Out Mechanism for Secondary Purposes: In accordance with applicable law, if you do not wish your personal data to be processed for the secondary purposes described above, you may opt out at any time. You may do so by checking the applicable boxes below or by sending an email to confidencialidad@grupodiestra.com.confidencialidad@grupodiestra.com
[ ] No deseo recibir comunicaciones comerciales, publicitarias o de mercadotecnia de Grupo Diestra.
[ ] No deseo que mis datos sean utilizados para estudios de mercado, encuestas o análisis de hábitos de consumo.
Under no circumstances will opting out of the processing of personal data for secondary purposes be a condition for denying you lodging services or other primary services requested.
7. PURPOSES OF PROCESSING SENSITIVE PERSONAL DATA
When the data subject provides data classified as sensitive (including allergies, food or physical intolerances, particular medical or physical conditions, special needs, or clinical history in connection with SPA services), Diestra Restaurantes will process such data solely to assess whether the requested services can be provided, issue safety recommendations or warnings regarding body treatments or massages, adapt menus to dietary restrictions, respond to immediate health emergencies, protect the safety of guests and visitors, and comply with legal obligations arising from preventive health or emergency assistance services.
Such data will be subject to restricted processing and strict confidentiality under the responsibility of Diestra Restaurantes and will be retained only for the period strictly necessary to fulfill the stated purpose.
8. CONSENT TO AND ACCEPTANCE OF PROCESSING
All processing of personal data will be subject to the data subject’s consent, except where an exception under the Law applies. Consent may be express or implied. Consent is express when the data subject’s intent is expressed verbally, in writing, through electronic or optical means, by unequivocal signs, or through other technology. Consent is implied when the Privacy Notice has been made available and the data subject does not express an objection.
As a general rule, implied consent will be valid unless a legal provision requires express consent.
Consent will be implied when this Privacy Notice has been made available to the data subject and the data subject does not express an objection.
Financial or asset data require express consent, except where an exception under Articles 9 and 36 of the Law applies.
For sensitive personal data, express written consent will be obtained through a handwritten signature, electronic signature, or other authentication mechanism established for that purpose, except where the Law provides otherwise.
For sensitive personal data, your express written consent will be obtained through a handwritten signature, advanced electronic signature, or authentication and acceptance mechanisms that unequivocally evidence your consent, except for the exceptions provided under Article 9 of the Law.
Consent may be withdrawn at any time, without retroactive effect. Withdrawal will be handled through the procedure described in this Notice, without prejudice to continued processing where a legal obligation or another exception under the Law applies. Withdrawal will not be available where processing is legally mandatory, necessary to perform or enforce a current contractual relationship, or necessary to safeguard or defend the rights of the parties.
9. LIMITATION ON THE USE OR DISCLOSURE OF YOUR PERSONAL DATA
To safeguard your personal information, Diestra Restaurantes continuously maintains and updates administrative, technical, and physical security measures comparable to those it uses for its own information, taking into account the level of risk, the sensitivity of the data, and the state of applicable technology.
Such measures include, without limitation:
• Strict access controls, assignment of authorized user profiles, and strong security passwords.
• Contractual confidentiality and professional secrecy obligations for all employees, data processors, and third parties with access to the information.
• Firewalls, encryption during data transmission, and secure storage on internal servers or those of trusted cloud-computing infrastructure providers.
• Physical security controls at corporate offices and hotels to restrict physical access to databases and paper records.
• Internal policies and procedures for the preventive management of security breaches and technology incidents.
• Ongoing training for personnel acting on behalf of Diestra Restaurantes regarding privacy, data protection, and cybersecurity.
Security Breach Notification: If a security breach occurs that significantly affects the property or moral rights of data subjects, Diestra Restaurantes will notify them promptly, pursuant to Article 19 of the Law, so that they may take appropriate measures to protect their rights. The notice will include, as applicable, the nature of the incident and the relevant measures, in accordance with the Law and other applicable provisions.
Listados de Exclusión y Registros de Oposición: Para limitar el uso y divulgación de sus datos personales, usted podrá solicitar su inscripción en el listado interno de exclusión de Diestra Restaurantes enviando su solicitud a confidencialidad@grupodiestra.com, a fin de que sus datos no sean utilizados con fines de mercadotecnia o publicidad.
10. ACCESS, RECTIFICATION, CANCELLATION AND OBJECTION RIGHTS (ARCO RIGHTS)
You have the right at any time to know what personal data we hold about you, the purposes for which we use it, and the conditions under which it is used (Access); request correction of your personal information where it is outdated, inaccurate, or incomplete (Rectification); request that it be removed from our records or databases when you consider that it is not being used in accordance with the applicable principles, duties, and obligations (Cancellation); and object to the processing of your personal data for specific purposes (Objection). These rights are legally known as ARCO Rights under Mexican law.
10.1. REQUIREMENTS FOR ARCO AND CONSENT WITHDRAWAL REQUESTS
To exercise any ARCO Right or withdraw your consent to processing, you or your duly authorized legal representative must submit a written request to the Personal Data Protection Department, either at the Data Controller’s address or by email at confidencialidad@grupodiestra.com.confidencialidad@grupodiestra.com
The request must include, at a minimum, the information and documentation required by the Law and its Regulations:
• The data subject’s full name and a physical address, email address, or other specific means by which the response may be communicated.
• Los documentos oficiales vigentes que acrediten fehacientemente su identidad (copia simple de INE, pasaporte, cédula profesional o documento migratorio aplicable). En caso de actuar a través de representante legal, se deberá acompañar el instrumento público, carta poder firmada ante dos testigos o poder notarial que acredite la representación, así como la identificación oficial del representante.
• A clear, precise, and detailed description of the personal data in relation to which you seek to exercise an ARCO Right or withdraw consent.
• An express indication of the ARCO Right you wish to exercise (Access, Rectification, Cancellation, or Objection), or an express statement withdrawing your consent.
• If exercising the Rectification right, you must specify the requested changes or corrections and provide the supporting legal documentation establishing the accuracy of the requested correction.
• Any other information, document, stay date, or item that may facilitate the identification and retrieval of the personal data within systems administered by Diestra Restaurantes, such as a reservation number, hotel, or check-in and check-out dates.
Diestra Restaurantes may request additional information when necessary to verify identity or authority to act, or to locate the data covered by the request.
10.2. PROCEDURE AND STATUTORY RESPONSE AND IMPLEMENTATION PERIODS
Upon receipt of the request, the Personal Data Protection Department will verify compliance with the applicable requirements and process the request in accordance with the Law and its Regulations.
Response Period (Determination): Diestra Restaurantes will notify the data subject of its determination regarding the request within a maximum of 20 (twenty) business days from the date the request is received.
Implementation Period (Giving Effect to the Right): If the request is granted, Diestra Restaurantes will implement the determination within 15 (fifteen) business days following the date the response is communicated. Both periods may be extended once for an equal period where justified by the circumstances.
The exercise of ARCO Rights is free of charge. Charges may only be imposed to recover reproduction, copying, or mailing costs. If the data subject repeats a request within a period of less than twelve months, costs may be subject to the limit established in Article 34 of the Law, unless substantial changes to the Privacy Notice give rise to a new request.
The response will be communicated through the means designated by the data subject within the applicable statutory periods. In the event of a full or partial denial, Diestra Restaurantes will provide the applicable reasons and legal grounds.
10.3. GROUNDS FOR DENIAL OF ARCO RIGHTS
Diestra Restaurantes may deny, in whole or in part, the exercise of ARCO Rights or withdrawal of consent only in the circumstances expressly permitted by the Law, including:
• Where the requester is not the data subject or the legal representative has not been duly authorized in accordance with applicable law.
• Where the data subject’s personal data are not processed or held by Grupo Diestra in its systems or databases.
• Where the exercise of the right would directly or indirectly infringe the privacy or property rights of a third party in accordance with law.
• Where a binding legal restriction, confidentiality obligation, or formal order issued by a competent judicial or administrative authority restricts the exercise of the right.
• Where the requested rectification, cancellation, or objection has already been carried out by the Data Controller in response to a prior request or legal requirement.
10.4. DATA RETENTION, BLOCKING PERIOD AND DELETION
Once personal data are no longer necessary for the purposes described in this Notice and the legally required retention period under applicable Mexican accounting, tax, commercial, or civil law has expired, the personal data will be placed in a blocking period.
During the blocking period, Diestra Restaurantes will retain the personal data solely to determine potential liabilities arising from the processing, respond to judicial or administrative requirements, or defend rights in legal proceedings. During this period, the data may not be subject to ordinary or commercial processing. Once the applicable limitation period for such liabilities has expired, the information will be permanently deleted from the organization’s manual and electronic databases.
CCTV images will ordinarily be retained in accordance with Grupo Diestra’s security and prevention policies and infrastructure, generally for a short period depending on the storage capacity of the relevant equipment. If an image or video is necessary for a criminal investigation, incident response, contractual claim, or defense in legal proceedings, it will be blocked and retained separately and securely for the duration of the investigation or proceeding.
10.5. LEGAL REMEDIES
A data subject who believes their rights have been infringed may submit the corresponding data protection request to the Secretariat for Anti-Corruption and Good Government, in accordance with the Law and applicable provisions.
11. CHANGES TO THE PRIVACY NOTICE
Diestra Restaurantes reserves the right to modify, supplement, adapt, or update this Comprehensive Privacy Notice at any time to address legislative reforms, regulatory changes, new operational requirements in the hotel industry, new technologies used, or changes to Grupo Diestra’s business model or privacy policies.
Any amendment to this Notice will be communicated to data subjects through the following channels:
• Physical posting at the reception desks of hotels forming part of Grupo Diestra.
• Publication of the current and updated version on the official websites of the Group and its individual hotels.
• Informational emails sent to addresses registered in our guest and customer databases where substantial changes occur or express consent is required.
The date of the latest update will appear at the end of this Notice. Diestra Restaurantes will take the necessary steps to obtain your express consent in advance where changes introduce a new primary purpose, new categories of personal or sensitive personal data, or material changes to the contemplated data transfers.
12. TRANSFER OF PERSONAL DATA
Pursuant to Articles 35 and 36 of the Law, Diestra Restaurantes may make domestic or international transfers of personal data to third parties other than data processors. When a transfer is made, the Data Controller will provide the recipient with the Privacy Notice and the purposes to which the data subject subjected the processing, and the transfer will be carried out in accordance with the Law. This Notice contains the applicable consent or opt-out provision for transfers where required.
Las transferencias de datos se podrán realizar, de manera enunciativa mas no limitativa, a:
• Travel agencies, including online travel agencies (OTAs), tour operators, event organizers, and airlines that lawfully and necessarily participate in coordinating, purchasing, or managing the tourism services and itineraries you contract.
• Affiliated companies and business partners with whom joint products, promotional lodging packages, corporate programs, or special benefits are offered.
• Employers or corporate entities that contract, sponsor, coordinate, or pay for lodging, events, or food and beverage services for their employees, executives, or advisors at our hotels.
• Financial and banking service providers solely for processing and collecting payment for purchases, inquiries, pre-authorizations, or bank transactions authorized by you.
• Insurance companies and external medical advisors in the event of health incidents, medical emergencies, accidents, or incidents on the premises, in order to provide immediate assistance and coordinate applicable insurance coverage.
Transferencias que no requieren consentimiento: Las transferencias nacionales o internacionales podrán realizarse sin consentimiento cuando se actualice alguno de los supuestos previstos en el artículo 36 de la Ley, incluyendo, entre otros, los siguientes:
• Where the transfer is provided for under a law or treaty to which Mexico is a party.
• Where the transfer is necessary for medical prevention or diagnosis, healthcare assistance, medical treatment, or the management of healthcare services.
• Where the transfer is made to holding companies, subsidiaries, affiliates, or entities under common control with Grupo Diestra, or to a parent or other company within the same corporate group operating under the same internal corporate privacy processes and policies.
• Where the transfer is necessary pursuant to a contract entered into or to be entered into in the interest of the data subject between the Data Controller and a third party.
• Where the transfer is necessary or legally required to safeguard a public interest or for the administration of justice.
• Where the transfer is necessary for the recognition, exercise, or defense of a right in judicial proceedings.
• Where the transfer is necessary to maintain or perform a legal relationship between the Data Controller and the data subject.
Mecanismo de Aceptación o Negativa para Transferencias que Requieren Consentimiento: En caso de que se realicen transferencias de datos con fines mercadotécnicos, publicitarios o de prospección comercial a favor de socios comerciales terceros ajenos al grupo, usted podrá manifestar su negativa en la siguiente casilla, o bien, mediante correo electrónico enviado a confidencialidad@grupodiestra.com
[ ] No acepto que mis datos personales sean transferidos a terceros comerciales para fines publicitarios o promocionales.
13. SURVEILLANCE TECHNOLOGIES, WI-FI AND DIGITAL ENVIRONMENT
To provide a comfortable and secure stay, Grupo Diestra establishments use various security and digital connectivity technologies at their physical premises and on their digital platforms.
Video surveillance and CCTV are used solely to protect individuals, assets, and hotel security. Camera systems are visibly installed and identified at main entrances, lobbies, hallways, elevators, and public common areas. In accordance with privacy rights, the installation of any camera in areas of heightened personal privacy, including restrooms, changing rooms, showers, individual SPA cabins, guest rooms, or equivalent areas, is strictly prohibited.
Wi-Fi Internet connectivity at the premises may require you to provide basic registration information, such as your name, room number, or email address, and may collect technical information from your mobile device, including MAC address, IP address, and technical identifiers. This technical information is processed solely to manage network bandwidth, maintain system stability, prevent criminal or hacking activity on the hotel network, and provide technical support.
On our websites and online booking engines, we use tracking and storage technologies such as cookies, web beacons, SDKs, and tracking pixels. Some cookies are strictly technical and necessary for the basic operation and security of the site; others are used for analytics or advertising and allow us to analyze aggregated browsing patterns anonymously to optimize the site. You may configure your browser preferences to disable, delete, or restrict these cookies in accordance with the browser developer’s instructions.
14. CONTRACTUAL RELATIONSHIP WITH DATA PROCESSORS AND SERVICE PROVIDERS
In accordance with the principles of lawfulness and proportionality, Diestra Restaurantes enters into data protection agreements with all external individuals or legal entities acting as Data Processors. This includes external providers of information technology support, hosting, cloud storage, PMS (Property Management System) providers, CRS global reservation systems, CRM management platforms, electronic payment engines, digital marketing agencies, physical security and CCTV control companies, and hotel Wi-Fi infrastructure providers.
Under the Law, its Regulations, and applicable contractual instruments, all external Data Processors are legally required to: (i) process personal data solely and exclusively in accordance with Diestra Restaurantes’ detailed instructions; (ii) refrain from transferring personal data to third parties except with the Data Controller’s express authorization or where legally required; (iii) maintain strict secrecy and confidentiality regarding the information processed; (iv) adopt and maintain the technical, administrative, and physical security measures required by the Law and secondary regulations; and (v) return or permanently delete personal data once the legal or contractual relationship giving rise to their involvement has ended.
15. INFORMATION REGARDING THIRD PARTIES, ACCOMPANYING PERSONS AND MINORS
When the data subject makes room reservations, SPA packages, or group purchases at Grupo Diestra restaurants and bars for accompanying persons or third parties, the data subject must provide only the information strictly necessary to coordinate the stay and properly provide the relevant corporate or individual services.
The data subject represents that they have obtained the consent of such third parties to provide their information and agrees to fully disclose the contents of this Privacy Notice to accompanying persons before their arrival.
With respect to personal data concerning minors who enter the establishments accompanied by family members or guardians, Diestra Restaurantes will apply enhanced physical, logical, and operational security measures. Information concerning minors will be processed strictly for mandatory registration at reception, management of supervised recreational access (such as kids’ clubs, pools, or beaches), risk prevention, and response to health emergencies. Under no circumstances will information concerning minors be processed for marketing, advertising, or commercial prospecting purposes.
16. TERM OF THE PRIVACY NOTICE
This Grupo Diestra Comprehensive Privacy Notice becomes effective on the date of its latest update and will remain in full force and effect until replaced by a subsequent version duly authorized by the Data Controller.
Last updated: August 27, 2026.