PRIVACY POLICY

1. Data Controller

In accordance with the General Data Protection Regulation, Regulation (EU) 2016/679, and Organic Law 3/2018 on the Protection of Personal Data and guarantee of digital rights, users are informed that any personal data provided through this website will be processed by:

Data Controller: Iñaki Arizmendi Fernández
Tax ID (NIF): 43482506V
Trade name: Velero Rafael Verdera
Registered address: C/ Muelle Viejo 11, 07012 Palma de Mallorca, Balearic Islands, Spain
Email: info@rafaelverdera.com
Phone / WhatsApp: +34 644 177 632
Website: https://privateboatexperiencemallorca.com

2. Data Processed

The Data Controller may process the personal data voluntarily provided by the user through contact forms, email, telephone, WhatsApp, or any other available communication channels.

The data processed may include name, surname, email address, telephone number, information relating to the request or booking, desired date, number of guests, and any other information included by the user in their communication.

Users should avoid sending special category data or any information that is not necessary for the handling of their request.

3. Purpose of the Processing

Personal data will be processed for the following purposes:

  • To respond to requests for information.

  • To manage enquiries regarding availability, services, conditions, and bookings.

  • To maintain communications necessary for the organisation and provision of the service.

  • To manage bookings, contracts, amendments, cancellations, or incidents.

  • To comply with legal, tax, administrative, and accounting obligations.

  • To send informational or commercial communications related to Velero Rafael Verdera, only where the user has authorised this or where a prior relationship exists that permits it under applicable law.

4. Legal Basis for Processing

The legal basis for processing personal data shall be the user’s consent, the implementation of pre-contractual measures, the performance of a contract, compliance with legal obligations, and, where applicable, the Data Controller’s legitimate interest in handling communications, managing incidents, and retaining information in the event of potential liabilities.

For the sending of commercial communications, the legal basis shall be the user’s consent or the existence of a prior relationship in accordance with applicable regulations.

5. Data Retention

Personal data will be retained for as long as necessary to respond to the request, manage the contractual relationship, or fulfil the purpose for which the data was collected.

Where a booking, invoice, contract, or potential legal liability exists, the data may be retained for the periods required by applicable law.

Data used for informational or commercial communications will be retained until the user withdraws consent or requests to unsubscribe.

6. Recipients of the Data

Personal data will not be sold or disclosed to third parties for commercial purposes.

Where necessary, access to personal data may be granted to service providers acting on behalf of the Data Controller, such as web hosting providers, technical maintenance providers, email service providers, accounting firms, advisers, communication tools, WhatsApp, mailing tools, or other providers necessary to manage requests and bookings.

Personal data may also be disclosed where required by law or pursuant to an administrative, judicial, or competent authority request.

7. International Data Transfers

As a general rule, no international transfers of personal data outside the European Economic Area are envisaged.

However, some technology providers used for the operation of the website, email, analytics, maps, forms, WhatsApp, or communication tools may process data outside the European Economic Area. In such cases, processing will be carried out in accordance with the safeguards required under applicable data protection regulations.

8. Users’ Rights

Users may exercise their rights of access, rectification, erasure, objection, restriction of processing, data portability, and withdrawal of consent by sending a request to:

info@rafaelverdera.com

The request must clearly indicate the right the user wishes to exercise and allow the identification of the requester.

Users also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos) if they believe that the processing of their personal data does not comply with applicable law.

9. Security

The Data Controller shall implement reasonable technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration, disclosure, or destruction.

10. Accuracy of the Data

Users guarantee that the data provided is truthful, accurate, complete, and up to date, and shall be responsible for any damage or loss arising from the communication of false, inaccurate, or third-party data without authorisation.

11. Minors

This website is not specifically directed at minors. Minors must not provide personal data without the consent of their parents, guardians, or legal representatives.

12. Cookies

This website may use its own and third-party cookies. The use of cookies is governed by the corresponding Cookies Policy available on this website.

13. Amendments

The Data Controller reserves the right to amend this Privacy Policy whenever necessary to adapt it to legal, technical, operational, or website-related changes.

The version in force at any given time shall be the one published on this website.

14. Contact

For any questions relating to this Privacy Policy or the processing of personal data, users may contact:

info@rafaelverdera.com