Privacy Policy

Last updated: July 25, 2026

This text is a GENERAL DRAFT prepared for a Spain-based holiday rental business and does not constitute legal advice. It must be reviewed by your lawyer before go-live, and the bracketed fields must be completed.

1. Data Controller

The data controller is [COMPANY NAME], CIF [CIF NUMBER], registered address [REGISTERED ADDRESS], Málaga, Spain ("Happy Travel"). Contact: [EMAIL]. This policy is issued under the EU General Data Protection Regulation (GDPR, 2016/679) and Spanish Organic Law 3/2018 (LOPDGDD).

2. Data We Process

When booking: name, email, phone, stay dates, guest counts and language preference. For member accounts: name, email, phone and an irreversible hash of your password. Technically: IP address and basic device information (for security and fraud prevention).

Your payment card details are never stored on our systems; payments are processed directly by Stripe, which shares only a transaction reference with us.

3. Purposes and Legal Bases

Concluding and performing your booking (GDPR art. 6(1)(b): contract); statutory retention and tax obligations (art. 6(1)(c)); fraud prevention and platform security (art. 6(1)(f): legitimate interest); marketing communications only with your explicit consent (art. 6(1)(a)), with an unsubscribe link in every message.

4. Recipients and Processors

Your data is shared with the processors needed to deliver the service: Stripe (payments), our accommodation management and reservation infrastructure provider, Purelymail (transactional email) and our hosting provider. Data processing agreements under GDPR art. 28 are in place with all processors.

5. International Transfers

Some providers may process data outside the EU (e.g. the USA). Such transfers are safeguarded by European Commission adequacy decisions (including the EU-US Data Privacy Framework) or Standard Contractual Clauses.

6. Retention

Booking and invoicing records are retained for the periods required by Spanish tax law (as a general rule at least 4 years, and 6 years for accounting documents). Account data is kept until you request deletion; upon deletion, personal data is anonymised while legally required financial records are preserved.

7. Your Rights

You have the rights of access, rectification, erasure, restriction, data portability and objection. Write to [EMAIL]; after identity verification we respond within 30 days at the latest.

You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es).

8. Cookies

Our site uses only cookies strictly necessary for the service (session, language preference, security). If analytics or marketing cookies are ever introduced, prior consent will be collected under the LSSI-CE (34/2002) and this section updated.

9. Security

Data is encrypted in transit with TLS; passwords are stored with irreversible algorithms; access is role-restricted, and administrative actions are recorded in an audit trail.

10. Changes

Material changes to this policy are published on the site; the version date appears above.