1. Data Controller
The data controller is [COMPANY NAME], CIF [CIF NUMBER], registered address [REGISTERED ADDRESS], Málaga, Spain ("Happy Travel"). Contact: [EMAIL]. This policy is issued under the EU General Data Protection Regulation (GDPR, 2016/679) and Spanish Organic Law 3/2018 (LOPDGDD).
2. Data We Process
When booking: name, email, phone, stay dates, guest counts and language preference. For member accounts: name, email, phone and an irreversible hash of your password. Technically: IP address and basic device information (for security and fraud prevention).
Your payment card details are never stored on our systems; payments are processed directly by Stripe, which shares only a transaction reference with us.
3. Purposes and Legal Bases
Concluding and performing your booking (GDPR art. 6(1)(b): contract); statutory retention and tax obligations (art. 6(1)(c)); fraud prevention and platform security (art. 6(1)(f): legitimate interest); marketing communications only with your explicit consent (art. 6(1)(a)), with an unsubscribe link in every message.
4. Recipients and Processors
Your data is shared with the processors needed to deliver the service: Stripe (payments), our accommodation management and reservation infrastructure provider, Purelymail (transactional email) and our hosting provider. Data processing agreements under GDPR art. 28 are in place with all processors.
5. International Transfers
Some providers may process data outside the EU (e.g. the USA). Such transfers are safeguarded by European Commission adequacy decisions (including the EU-US Data Privacy Framework) or Standard Contractual Clauses.
6. Retention
Booking and invoicing records are retained for the periods required by Spanish tax law (as a general rule at least 4 years, and 6 years for accounting documents). Account data is kept until you request deletion; upon deletion, personal data is anonymised while legally required financial records are preserved.
7. Your Rights
You have the rights of access, rectification, erasure, restriction, data portability and objection. Write to [EMAIL]; after identity verification we respond within 30 days at the latest.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es).
8. Cookies
Our site uses only cookies strictly necessary for the service (session, language preference, security). If analytics or marketing cookies are ever introduced, prior consent will be collected under the LSSI-CE (34/2002) and this section updated.
9. Security
Data is encrypted in transit with TLS; passwords are stored with irreversible algorithms; access is role-restricted, and administrative actions are recorded in an audit trail.
10. Changes
Material changes to this policy are published on the site; the version date appears above.
