Portixol Group

Spain · owned by Independent (Spain) · esplendidohotel.com · 25 vendors

Portixol Group is a family-owned hospitality company founded on the island of Mallorca that operates luxury hotels, restaurants, sports clubs and leisure facilities. The company owns and operates Hotel Espléndido, a boutique hotel located in Puerto de Sóller, Mallorca, offering accommodation, dining, spa services and activities in the UNESCO World Heritage Sierra de Tramuntana region.

Resilience scores

Technology vendors

Insights

Last updated 2026-01-09 · revision 44

25 direct vendors, 211 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Portixol Group's migration readiness is assessed as medium-low, primarily due to an unoptimized tech stack for cloud migration, significant financial unknowns, and unclear vendor lock-in. **Strengths:** * **Clear Data Residency Requirements:** The company's compliance with GDPR and Spanish Data Protection Law provides clear guidelines for data residency (EU/EEA processing, compliant transfer mechanisms for third countries). This clarity, while a constraint, means the requirements are known and can be factored into migration planning, rather than being an unknown hurdle. * **Existing Cloud Service Usage:** The current use of 'Dropbox' and 'Google Analytics' indicates some familiarity with cloud services, which could potentially ease the transition for other workloads. * **Vendor Geographic Diversity (Service Origins):** The listed 'Vendor HQ Countries' (7 unique countries) suggests that the company is already interacting with services from diverse regions. If these services are to be migrated or replaced, this diversity might offer more options for new providers. **Weaknesses:** * **Legacy/Non-Cloud-Native Tech Stack:** The 'Internal Tech Stack' (WordPress, Myrestoo) is not inherently cloud-native. Migrating WordPress might involve re-hosting, while 'Myrestoo' (likely a SaaS) could require data migration and integration with a new platform, or continued reliance on the existing SaaS. The absence of containerization or microservices indicates a more traditional architecture, which typically requires more effort for cloud migration compared to modern, cloud-native applications. * **Significant Data Gaps (Financial Stability):** The 'null' values for 'Revenue Concentration by Product', 'Revenue Concentration by Geography', and 'Growth History' mean there is no data to assess the company's financial capacity to fund a potentially costly and complex migration project. This is a major unknown risk that directly impacts readiness. * **Unknown Vendor Lock-in Risk:** The data states 'Total Vendors: 0' (an inconsistency) and 'Vendor Lock-in Risk: Unknown'. This lack of clarity on vendor relationships and contract complexity is a significant challenge. High lock-in with critical systems (e.g., Online Reservation Systems, Property Management System) could make migration difficult, expensive, and time-consuming due to data extraction, integration, and contract termination complexities. * **Regulatory Assessment Gaps:** 'ISO 27001' and 'Spanish Tourism Regulations' are 'Assessment Required'. A migration project would need to ensure that the new environment and processes comply with these regulations, potentially adding scope and complexity to the migration effort. * **Single Point of Operation:** While not directly a migration *readiness* factor for the tech stack, the single country of operation ('Spain') means there's no existing distributed infrastructure to leverage for a phased, low-risk migration strategy. A 'big bang' migration could pose higher risks to business continuity.

Compliance

3 in-scope frameworks identified; showing 3.

GDPR (source) — Compliant

The company is EU-based (Spain) and processes personal data of EU residents, making GDPR directly applicable to its operations.

The company demonstrates GDPR compliance through their detailed privacy policy that references GDPR requirements, proper data controller identification (Davant la Mar SLU), and implementation of data subject rights. However, as a hospitality company processing significant amounts of personal data (guest information, payment data, employee data), there remains medium risk due to the volume and sensitivity of data processed. The hospitality industry faces regular scrutiny for data protection practices, and any breach could result in significant fines up to 4% of annual turnover under GDPR.

Evidence: https://esplendidohotel.com/politica-privacidad

SOC 2 (source) — Assessment Required

While not legally mandated, SOC2 certification is increasingly adopted by hospitality companies to demonstrate security controls to business partners and customers, especially when processing payment data and personal information.

While SOC2 is not legally required, hospitality companies increasingly adopt SOC2 to demonstrate security controls to business partners and customers, especially when processing payment data and personal information. The risk is medium because lack of SOC2 certification could impact business relationships and customer trust, though it's not a legal compliance requirement. The company processes sensitive guest data and payment information, making security controls important for business operations.

ISO 27001 (source) — Assessment Required

ISO 27001 is not legally required but is increasingly important for hospitality companies to demonstrate a systematic approach to information security management.

ISO 27001 is not legally required but is increasingly important for hospitality companies to demonstrate information security management. The risk is medium because while non-compliance won't result in fines, it could impact business relationships, insurance coverage, and competitive positioning. Given the company processes sensitive guest data, payment information, and operates multiple properties, implementing ISO 27001 would strengthen their security posture and business credibility.

Financials

Three-year financials

Financial Resilience Score: 7/10

This score reflects the company's ability to withstand economic shocks based on its business model, asset base, and market position, balanced against its inherent concentration risks. Strengths include strong brand equity & niche position, attracting an affluent clientele less price-sensitive during downturns. Asset ownership of prime real estate in desirable locations provides a substantial asset base. High customer loyalty fosters repeat business, creating a stable demand base. Experienced management has navigated the business for over two decades. Weaknesses/Risks include geographic concentration on Mallorca, exposing it to localized events. The luxury travel industry is highly cyclical and impacted by economic recessions. Limited scale as a small operator lacks diversification and economies of scale.

Key strengths: Strong Brand Equity & Niche Position, Asset Ownership, High Customer Loyalty, Experienced Management

Risk factors: Geographic Concentration, Market Sensitivity, Limited Scale

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report