Clear information before you report.
This channel is intended to receive reports about potentially irregular facts or conduct within Grupo Vela.
Confidentiality and anonymity
You may submit a report without identifying yourself. If you choose to provide identity details, they are stored encrypted and access is restricted to authorised personnel responsible for handling the case.
Communication and follow-up
The system generates a code and secret key that allow you to check the case, receive messages from the system manager and provide additional information.
Responsible use
Report facts you reasonably believe to be true and provide only relevant data. This channel is not intended for emergencies or ordinary customer service.
Data protection information
Controller: GRUPO VELA.
Purpose: receipt, assessment, investigation and management of reports submitted through the Internal Reporting System.
Data: the system allows anonymous reporting. Where the reporter chooses to identify themselves, the information provided voluntarily is associated with the case.
Access: limited to persons who need to take part in managing or investigating the report and, where appropriate, competent authorities or other legally authorised recipients.
Privacy contact: privacidad@velice.es.
1. Information before completing the form
This channel allows you to report, in good faith, acts or omissions that may constitute breaches of European Union law, serious or very serious criminal or administrative offences, as well as breaches falling within the scope of Law 2/2023 and Grupo Vela's internal procedure.
You may submit the report anonymously, without providing your name, email address or any other contact details. Once completed, the system will provide you with an ID and password that you must keep in order to check the status of the case, receive requests for information and learn the outcome of the proceedings. The company will not be able to recover these credentials if they are lost.
You may also identify yourself voluntarily. In that case, your identity will remain confidential and will not be disclosed to the person concerned by the reported facts or to unauthorized third parties, except where required by law or requested by a competent authority and subject to the applicable safeguards.
Before submitting:
- Select or enter the establishment, area or company related to the reported facts. If you do not know it, provide the information available; this field may remain optional.
- Describe specific facts, approximate dates, persons or areas involved and any information that may help verify the report.
- Provide only relevant documents. Avoid including unnecessary personal data, especially health data, political opinions, sex life, ethnic origin or information about unrelated third parties.
- Check file metadata: a document, photograph or PDF may contain the author's name, location or other information that could identify you even if the form is anonymous.
- Do not use this channel for emergencies. If there is an immediate risk to people or property, contact the emergency services or the competent authority.
- Deliberately false reports or reports made in bad faith will not be accepted. The mere absence of conclusive evidence does not constitute bad faith where there were reasonable grounds to believe the information was true.
Receipt of the report will be acknowledged within a maximum of seven calendar days, unless doing so could compromise confidentiality. Information regarding the actions taken will generally be provided within a maximum of three months from the acknowledgement of receipt or, if no acknowledgement was sent, from the expiry of the seven-day period following submission of the report. In particularly complex cases, this period may be extended by up to an additional three months.
The report may also be made verbally. To request an in-person meeting within the statutory seven-day period, contact info@eticagrupovela.com. If you wish to preserve your anonymity, preferably use the application's secure mailbox to submit the request without providing identifying information.
2. Anonymity, confidentiality and security
Anonymous reporting. You are not required to provide your name, email address or other contact details. The application is configured not to store IP addresses or other technical metadata intended to identify the user.
After submitting the report, you will receive an ID and password to maintain secure communication with the case manager.
Technical anonymity does not prevent the content of the report, submitted documents or their metadata from indirectly revealing the identity of the reporting person. To reduce this risk, do not include unnecessary identifying information and review file properties before attaching them.
Access to the content of reports, their attachments and the record book is restricted to the System Manager and persons expressly authorized where strictly necessary to process or investigate the case. All such persons are subject to duties of secrecy and confidentiality.
Notifications sent by email will not contain the text of the report or attached documents; they will only indicate that a new case has been created so that the authorized person can access the application.
3. Internal reporting channel privacy notice
3.1. Data controller
The data controller will be the Grupo Vela company whose scope covers the reported facts. ACTIVIDAD OCIO VELA, S.L., as the parent or controlling company, coordinates the common Internal Reporting System.
Where a report concerns several companies, access to and exchange of information will be limited to what is strictly necessary to determine responsibilities and process the case in accordance with applicable regulations.
The complete list of companies and identifying details is provided in section 6.
3.2. Purposes
- To receive, register, analyze and process reports falling within the Internal Reporting System.
- To maintain secure communication with the reporting person, including anonymous communication.
- To investigate the facts, take corrective or disciplinary measures and protect against retaliation.
- To respond to requests from judicial authorities, the Public Prosecutor's Office, administrative authorities or other competent bodies.
- To maintain the confidential record book and evidence of compliance, security and auditing.
3.3. Legal basis
Processing is necessary for compliance with a legal obligation applicable to the companies concerned, pursuant to Article 6(1)(c) of Regulation (EU) 2016/679, Article 8 of Organic Law 3/2018 and Articles 30 et seq. of Law 2/2023.
Where the system voluntarily receives reports outside the mandatory scope, processing will be based on the public interest in accordance with Law 2/2023. Consent is not requested for managing the report.
3.4. Data processed and source
The data processed may include data that the reporting person chooses to provide, data relating to persons concerned or connected with the facts, the content of the report, documents, follow-up conversations, investigative actions and conclusions.
The data comes from the reporting person, internal checks and, where applicable, third parties or legitimate sources consulted during the investigation.
Manifestly irrelevant or unnecessary data will be deleted without delay. If special categories of data are received and are not necessary, they will be deleted in accordance with Law 2/2023.
3.5. Recipients and access
As a general rule, data will only be accessible to the System Manager.
Data may be disclosed or access may be granted, where necessary and proportionate, to:
- The management body.
- Legal advisers.
- Human Resources.
- Compliance officers.
- The Data Protection Officer.
- Contracted data processors.
- Competent authorities.
The identity of the reporting person will not be disclosed outside the personnel authorized to receive and follow up reports, except where required by law.
INFORMÁTICA, FORMACIÓN Y MULTIMEDIA, S.L. (Tax ID B53697231; C/ Ramón y Cajal, 35, 03182 Torrevieja) developed the application and will not have access to production content.
IONOS España provides hosting with servers and backups located in Spain and must be subject to the corresponding data processing agreement. No international transfers of data are envisaged.
3.6. Automated decision-making
No decisions will be made solely by automated means, nor will profiling be carried out with legal effects on individuals based on the information received.
3.7. Confidentiality of identity
The identity of the reporting person will be kept confidential and will not be disclosed to the person concerned by the reported facts.
If a judicial authority, the Public Prosecutor's Office or a competent administrative authority requires disclosure of the reporting person's identity in the context of an investigation, the reporting person will be informed in advance, unless such information could compromise the investigation or proceedings.
4. Retention and deletion
Guiding principle. Data will be retained only for as long as strictly necessary to decide whether to open an investigation, conduct it and demonstrate the proper operation of the system. The following periods are maximum periods and do not justify retaining unnecessary data.
- Reports not admitted or not investigated: maximum 3 months from their entry into the system. Afterwards, personal data will be deleted from the channel; only an anonymized record of the system's operation may be retained.
- Accepted cases: throughout the investigation and until closure.
- Closed cases: up to 5 years from closure, with restricted access, where necessary to demonstrate actions taken, address liabilities or defend rights. Data will be deleted earlier if it is no longer necessary.
- Judicial, administrative or disciplinary proceedings: until a final decision has been issued and the applicable limitation periods or resulting liabilities have expired.
- Record book: maximum 10 years. It must remain confidential, with data minimized and anonymized where compatible with its purpose.
- Access and audit logs: 2 years, unless retention is necessary due to a security incident, investigation or legal obligation.
- Backups: maximum rotation period of 30 days. Effective deletion will take place when the backup is overwritten; deleted data will not be restored except where necessary for business continuity or an incident.
- Attachments: the same retention period as the case to which they are linked.
- Temporary files: maximum 24 hours, with secure automatic deletion.
5. Exercise of rights
Data subjects may request access, rectification, erasure, objection and restriction of processing, where applicable, by contacting rrhh@grupovelabeach.com.
The request must allow the identity of the person exercising the right to be verified without providing more data than necessary.
These rights may be restricted where exercising them could reveal the identity of the reporting person, affect the rights of other persons, prejudice an investigation or where there is a legal obligation to retain the data.
In particular, the person concerned will not have the right to know the identity of the reporting person through the exercise of the right of access.
You may also contact the Data Protection Officer, Álvaro Tortosa Selma, at rrhh@grupovelabeach.com, and lodge a complaint with the Spanish Data Protection Agency.
6. Companies included
- ACTIVIDAD OCIO VELA, S.L. — B54909114 — C/ Antonio Ruiz Coves, 7, 03183 Torrevieja (Alicante). Velice, El Parking, Vela Puerto, Makala and Amai.
- POPEX ALIMENTACIÓN, S.L. — B54684626 — Av. de los Españoles, 1, 03188 Torrevieja (Alicante). La Fusión.
- BARLOVENTO RESTAURANTE, S.L. — B53473716 — C/ Vicente Blasco Ibáñez, 30, bajo, 03181 Torrevieja (Alicante). Barlovento.
- ABADÍA DE LOS NUEVE PISOS, S.L. — B73149718 — Callejón Burruezo, 1, 30005 Murcia. Alter Ego.
- GRUPO VELA SABORES CRUZADOS, S.L. — B24879082 — C/ Antonio Ruiz Coves, 7, 03183 Torrevieja (Alicante). Restaurante Vela Beach.
7. System Manager, DPO and access profiles
System Manager
Álvaro Tortosa Selma, Head of the Human Resources Department, is the System Manager for the common system covering all included companies.
The management body of each company must document his appointment or ratification and ensure that he performs his duties independently and autonomously, with sufficient resources and without receiving instructions regarding the handling of specific cases.
Data Protection Officer
Álvaro Tortosa Selma.
Contact: rrhh@grupovelabeach.com.
Technical administration
Rocío Amat Mora, Marketing Department, technical administrator. She must operate using an individual account, enhanced authentication and exclusively technical permissions, without access to content, attachments, conversations or the record book.
Notification mailbox
info@eticagrupovela.com. Access will be restricted to Álvaro Tortosa Selma and the other expressly authorized and documented person.
- Emails will contain notifications only, without case content.
- Multi-factor authentication must be enabled.
- Automatic forwarding must be avoided.
- Persons with access must be reviewed periodically.
8. External reporting channels
Use of the internal channel is recommended where it allows the infringement to be handled effectively and there is no risk of retaliation, but it is not mandatory. The reporting person may directly use a competent external reporting channel.
Facts limited to Alicante / Valencian Community
Reports may be submitted through the external channel of the Agency for the Prevention and Fight against Fraud and Corruption of the Valencian Community where the facts fall within its material and territorial scope.
If there is uncertainty regarding its competence, the Independent Authority for Whistleblower Protection may be used, which may provide guidance or refer the report to the competent body.
Facts limited to Murcia
Reports may be submitted through the external channel of the Independent Authority for Whistleblower Protection (AIPI), without prejudice to other bodies that may have jurisdiction over the matter.
Facts affecting several autonomous communities
Where the facts affect establishments or companies located in more than one autonomous community, or where their scope is not limited to a single autonomous community, the reference external channel will be the AIPI.
Other channels
Depending on the subject matter, channels provided by sectoral authorities, law enforcement agencies, the Public Prosecutor's Office, the European Public Prosecutor's Office or courts and tribunals may also be used. The application must not present the above links as an exhaustive list or as advice regarding the competent authority in each case.
Appendix. Legal sources and official links
- Law 2/2023 on the protection of persons who report regulatory infringements.
- Regulation (EU) 2016/679 (GDPR).
- Organic Law 3/2018 on Personal Data Protection.
- Independent Authority for Whistleblower Protection (AIPI).
- AIPI external reporting channel procedure.
- Valencian Anti-Fraud Agency: reporting mailbox.
- Spanish Data Protection Agency.
