Privacy Policy | mallorcatransfer.taxi
Esta página también está en español. Ver en español
Diese Seite gibt es auch auf Deutsch. Auf Deutsch ansehen

Privacy Policy

1. Introduction

Welcome to Mallorca Transfer Taxi (“we”, “us”, “our”). We are deeply committed to protecting your privacy. This Privacy Policy outlines our practices regarding the collection, use, storage, protection, and sharing of your personal data. We handle your data transparently, fairly, and lawfully, adhering strictly to the principles and requirements of the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Spanish Organic Law 3/2018 on Personal Data Protection and guarantee of digital rights (LOPDGDD).

Our Commitment to Data Protection Principles: All our data processing activities are guided by the core principles of GDPR:

  • Lawfulness, Fairness, and Transparency: We process data legally, fairly, and provide clear information about our practices.
  • Purpose Limitation: Data is collected for specified, explicit, and legitimate purposes and not further processed incompatibly.
  • Data Minimisation: We only collect data that is adequate, relevant, and limited to what is necessary for the purpose.
  • Accuracy: We strive to keep data accurate and up-to-date, providing means for rectification.
  • Storage Limitation: Data is kept identifiable only for as long as necessary for the purposes.
  • Integrity and Confidentiality: We implement appropriate security measures to protect data.
  • Accountability: We take responsibility for demonstrating compliance with these principles.

This Privacy Policy explains:

  • Who is responsible for your data.
  • What personal data we collect and how.
  • The specific purposes and legal bases for processing your data.
  • How long we retain your data.
  • With whom we might share your data (Recipients, Processors).
  • Information on international data transfers.
  • The security measures we implement.
  • Your data protection rights and how to exercise them.
  • How to contact us or the supervisory authority.

This policy applies to personal data collected through our website https://mallorcatransfer.taxi (the “Website”), our booking channels (online form, email, phone, WhatsApp), and during the provision of our private transfer services.

2. Who is Responsible for Your Data (Data Controller)?

The entity responsible for processing your personal data (the “Data Controller”) is:

3. Data Protection Officer (DPO)

Mallorca Transfer Taxi has assessed its data processing activities according to Article 37 of the GDPR and Article 34 of the LOPDGDD and determined that the appointment of a Data Protection Officer (DPO) is not legally mandatory for our organization at this time. For any questions or concerns regarding your privacy or this policy, please contact us directly using the details provided in Section 2 or Section 15.

4. What Personal Data Do We Collect?

We may collect and process the following categories of personal data depending on your interaction with us:

  • Identification Data: Full name, NIF/Passport number (if required for invoicing or legal compliance).
  • Contact Data: Email address, phone number, postal address (for pickup/drop-off if not a standard location like airport/port/hotel).
  • Booking and Service Data: Pickup and drop-off locations and times, flight or cruise details (for monitoring arrivals), number of passengers (including children/infants), child seat requirements, luggage details, special requests related to the service.
  • Payment Data: While we offer payment to the driver, if online payment is processed via our website or a payment link, payment card details may be collected directly by our secure third-party payment processor (we typically do not store full card details ourselves). For cash payments, no payment data is stored electronically. For card payments to the driver, data is processed via the payment terminal provider.
  • Communication Data: Records of communications via email, WhatsApp, phone calls, or contact forms on our website.
  • Chat Assistant Data (Otty): The content of the messages you type into the Website’s artificial-intelligence assistant (places, dates, number of passengers and anything else you choose to include), your rating of its replies, the language and the page you write from. The assistant does not ask for personal or payment data; card numbers are removed automatically before the conversation is stored.
  • Website Usage Data (via Cookies): IP address (potentially anonymized), browser type, operating system, referring URLs, pages visited, time spent on pages, interaction data. This data is primarily collected through cookies and similar technologies, subject to your explicit consent choices managed via our cookie banner and detailed in our Cookies Policy.
  • Data related to Incidents/Claims: Information provided in relation to any incidents, accidents, complaints, or claims during the service.

We do not intentionally collect sensitive personal data (e.g., health information, religious beliefs) unless you voluntarily provide it as part of a special request relevant to the service (e.g., need for accessible vehicle assistance, which might imply a health condition), in which case we process it only for that specific purpose and with your explicit consent or as necessary for the service.

5. How Do We Collect Your Data?

We collect personal data through various means:

  • Directly from You: When you fill out the booking form on our Website, contact us via email, phone, or WhatsApp to make a reservation or inquiry, or communicate with us during the service.
  • Automatically via Technology: When you browse our Website, certain data (like IP address, browsing patterns) may be collected automatically through cookies and similar technologies. The collection of data via non-essential cookies is subject to your explicit consent, managed via our cookie banner and detailed in our Cookies Policy.
  • From Third Parties: In some cases, bookings might be made via travel agencies or partners acting on your behalf, who provide us with your booking details.

We process your personal data only for specified, explicit, and legitimate purposes, ensuring we always have a valid legal basis under Article 6 of the GDPR. We clearly link each purpose to its corresponding legal basis:

PurposeExamples of Data UsedLegal Basis (GDPR Article 6) & Explanation
To Manage and Fulfill Your Booking/Service RequestIdentification, Contact, Booking/Service Data, Payment Data (if applicable)Art. 6(1)(b): Performance of a contract. Processing is necessary to manage your reservation and prepare for the service you contracted.
To Provide the Transport ServiceIdentification, Contact, Booking/Service Data (pickup/drop-off, flight monitoring)Art. 6(1)(b): Performance of a contract. Processing is necessary to execute the transport service as agreed.
To Communicate with You Regarding Your Booking/ServiceContact Data, Booking Data, Communication DataArt. 6(1)(b): Performance of a contract. Essential communications (confirmations, updates, driver contact) are necessary for service provision.
To Process Payments and Manage Billing/InvoicingIdentification, Contact, Booking Data, Payment Data (processed by provider), NIF/Tax IDArt. 6(1)(b): Performance of a contract (payment processing). Art. 6(1)(c): Legal Obligation (issuing invoices, tax compliance).
To Comply with Legal and Regulatory ObligationsIdentification, Booking Data, Billing DataArt. 6(1)(c): Legal Obligation. Necessary to comply with applicable laws (e.g., transport regulations, tax laws, accounting records).
To Answer Your Questions through the Chat Assistant (Otty)Chat Assistant DataArt. 6(1)(b): Pre-contractual steps at your request (calculating a price and preparing a booking) and Art. 6(1)(f): Legitimate interest in answering enquiries and improving the assistant’s replies. The assistant is an artificial-intelligence system and identifies itself as such; it takes no decision with legal effects on you: a booking is only made on the booking page.
To Handle Inquiries, Complaints, or ClaimsIdentification, Contact, Booking Data, Communication Data, Incident DataArt. 6(1)(f): Legitimate Interest. Our legitimate interest is to provide customer support, manage feedback, and establish, exercise, or defend legal claims. You have the right to object to processing based on legitimate interest (see Section 10).
To Improve Our Website and Services (Analytics)Website Usage Data (via Cookies)Art. 6(1)(a): Consent. Your explicit consent obtained via our cookie banner for non-essential analytics cookies. See Cookies Policy.
To Provide Personalized Advertising (Marketing)Website Usage Data (via Cookies)Art. 6(1)(a): Consent. Your explicit consent obtained via our cookie banner for marketing cookies. See Cookies Policy.
To Ensure Website Security and Prevent FraudIP Address, Website Usage DataArt. 6(1)(f): Legitimate Interest. Our legitimate interest is to protect our IT systems, prevent fraudulent activities, and ensure network security. You have the right to object (see Section 10).
To Send Marketing Communications (if opted-in)Contact Data (Email/Phone)Art. 6(1)(a): Consent. Requires your explicit, separate opt-in consent (e.g., checking a specific box). You can withdraw this consent anytime.

We will not use your personal data for purposes incompatible with those listed above unless required or permitted by law, or if you provide further consent.

7. How Long Do We Keep Your Data (Data Retention)?

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.

  • Booking & Service Data: Kept for the duration necessary to provide the service and then for the period required to handle potential claims or comply with legal obligations (e.g., typically up to 6 years for commercial/tax records in Spain, or longer if legal limitation periods for claims apply).
  • Communication Data: Retained as long as necessary to address the inquiry or manage the relationship, and potentially longer if related to a booking or claim subject to legal retention periods.
  • Chat Assistant Conversations: 30 days from the last message; ratings (thumbs up/down), 90 days. If you ask for a person or mention an existing booking, the conversation is forwarded by email to our operations team and kept as Communication Data. Your browser also keeps a local copy of your conversations for 30 days (see Cookie Policy), which you can delete at any time.
  • Website Usage Data (Cookies): Retention periods vary depending on the cookie type (session or persistent) as detailed in our Cookies Policy. Consent for non-essential cookies is typically valid for a maximum of 24 months.
  • Marketing Consent Data: Retained until you withdraw your consent.

Once the retention period necessary for the primary purpose expires, data may be blocked – kept only for the purpose of making it available to competent public administrations, judges, or courts, for the attention of possible liabilities arising from the treatment, during the prescription period of these – before being securely and definitively deleted or fully anonymized.

8. Who Do We Share Your Data With (Recipients)?

We do not sell your personal data. We only share your data when necessary for the purposes described in Section 6 and with appropriate legal basis and safeguards. We distinguish between:

A. Data Processors (Encargados del Tratamiento):

These are third-party service providers who process data on our behalf and under our instructions. We prioritize using providers located within the European Union (EU) or European Economic Area (EEA) where feasible. We have legally binding contracts (as required by Art. 28 GDPR) with all processors to ensure they protect your data and only use it for the services commissioned. Categories include:

  • IT & Infrastructure Providers:
    • Cloudflare: Provides website security (CDN, WAF) and performance services. While Cloudflare operates globally, data processing may occur outside the EEA (see Section 9).
    • Google Cloud Platform (GCP): May be used for backend services or data storage. We strive to configure these services to use EU-based data centers where possible, but processing may still involve international aspects (see Section 9).
    • Website Hosting: Our primary website hosting (Cloudflare Pages) leverages a global network; content delivery may occur from servers outside the EEA, though core data processing is subject to Cloudflare’s policies (see Section 9).
    • Email Service Providers: Providers used for sending transactional or marketing emails (if applicable), preferably based in the EEA.
    • OpenAI (OpenAI Ireland Ltd / OpenAI, L.L.C.): Provides the language model that generates the Chat Assistant’s replies. It receives the conversation content to generate each reply, under a data processing agreement and without using it to train its models. Involves transfers to the USA (see Section 9).
  • Communication Platform Providers:
    • Meta Platforms Ireland Limited: Provides WhatsApp Business Platform / API services. Processing occurs primarily in the EEA but involves necessary transfers to Meta Platforms, Inc. (USA) (see Section 9).
  • Payment Processors: Secure third-party providers, often based in the EEA, processing online or terminal payments.
  • Analytics Providers:
    • Google LLC: Provides Google Analytics (subject to your cookie consent). Data processed by Google involves international transfers (see Section 9).
  • Advertising Providers:
    • Google LLC: Provides Google Ads services (subject to your cookie consent). Data processed by Google involves international transfers (see Section 9).
  • Professional Advisors: External accountants, lawyers, auditors, typically based in Spain/EEA (acting under confidentiality obligations).

B. Data Controllers (Cesiones a Terceros Responsables):

These are third parties to whom we may communicate data, and who will process it for their own purposes as independent controllers. Such communications only occur if legally required or with your explicit consent:

  • Public Authorities: Tax agencies, transport authorities, law enforcement, courts, when required by law or legal process.
  • Collaborating Transport Providers: In specific cases where we need to subcontract part of the service (e.g., due to high demand or specific vehicle needs), we may share necessary booking details (name, contact, service details) with another licensed transport provider to fulfill your request. This sharing is based on the performance of the contract (Art. 6(1)(b)) as it’s necessary to provide the service you booked. We ensure these collaborators are also compliant with data protection regulations.
  • Advertising Partners: Such as Google Ads (subject to your cookie consent), who process data collected via cookies for their own advertising purposes as described in their policies.

We require all recipients to respect the security of your personal data and treat it according to law.

9. International Data Transfers

While we prioritize using services and infrastructure located within the European Economic Area (EEA), the use of certain essential third-party services necessitates the transfer of personal data outside the EEA. This currently applies to:

  • Google LLC (USA): For Google Analytics, Google Ads, Google Tag Manager, and potentially Google Cloud Platform services.
  • Meta Platforms, Inc. (USA): As part of the processing for WhatsApp Business services provided via Meta Platforms Ireland Limited.
  • Cloudflare, Inc. (USA): For website security, performance (CDN), and hosting (Pages) services.
  • OpenAI, L.L.C. (USA): To generate the Chat Assistant’s (Otty) replies.

These transfers are necessary for the provision of their respective services. These companies process data according to their own privacy policies. Transfers to the United States are currently conducted under the framework of the EU-U.S. Data Privacy Framework (for certified companies like Google, Meta, Cloudflare) or based on Standard Contractual Clauses (SCCs) adopted by the European Commission, which provide safeguards for the protection of personal data. You can find more information about the data transfer mechanisms and privacy practices in the respective privacy policies of these providers:

By using our services and consenting to relevant cookies (where applicable), you acknowledge these necessary international transfers under the specified safeguards. We continuously evaluate our providers and data processing locations to minimize transfers outside the EEA where operationally feasible.

We ensure such transfers comply with Chapter V of the GDPR. Currently, transfers to certified companies in the U.S. may be covered by the EU-U.S. Data Privacy Framework adequacy decision. For transfers not covered by an adequacy decision, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission, potentially supplemented with additional technical and organizational measures assessed through a Transfer Impact Assessment (TIA), to ensure your data receives a level of protection essentially equivalent to that within the EEA. You can request more information about the specific safeguards applied to international transfers by contacting us.

10. Your Data Protection Rights

Under the GDPR and LOPDGDD, you possess several rights concerning your personal data, which we are committed to facilitating:

  • Right of Access (Art. 15 GDPR): Request confirmation whether we process your data, access the data we hold, and obtain supplementary information about the processing.
  • Right to Rectification (Art. 16 GDPR): Request correction of inaccurate personal data or completion of incomplete data.
  • Right to Erasure (‘Right to be Forgotten’) (Art. 17 GDPR): Request deletion of your personal data when it’s no longer necessary for the purposes collected, you withdraw consent (if applicable), you object and there are no overriding legitimate grounds, or the data was processed unlawfully, among other reasons. This right is subject to legal retention obligations.
  • Right to Restriction of Processing (Art. 18 GDPR): Request suspension of processing when you contest data accuracy, processing is unlawful but you oppose erasure, we no longer need the data but you require it for legal claims, or you have objected pending verification of our legitimate grounds.
  • Right to Data Portability (Art. 20 GDPR): Receive the personal data you provided to us in a structured, commonly used, machine-readable format, and transmit it to another controller, where processing is based on consent or contract and automated.
  • Right to Object (Art. 21 GDPR): Object, on grounds relating to your particular situation, to processing based on our legitimate interests (Art. 6(1)(f)). We will cease processing unless we demonstrate compelling legitimate grounds overriding your interests, rights, and freedoms, or for legal claims. You have an absolute right to object to processing for direct marketing purposes at any time.
  • Right Not to be Subject to Automated Decision-Making (Art. 22 GDPR): Right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects on you. (As stated previously, we do not currently engage in such processing).
  • Right to Withdraw Consent (Art. 7(3) GDPR): Where processing relies on your consent (e.g., non-essential cookies, marketing emails), you can withdraw it at any time, easily. Withdrawal does not affect the lawfulness of processing before withdrawal. Manage cookie consent via our Cookies Policy or the settings link. Unsubscribe from marketing emails via the link within them.

How to Exercise Your Rights: To exercise any of these rights, please send a written request, clearly identifying yourself and the right(s) you wish to exercise, to our contact details provided in Section 2 (email: bookings@mallorcatransfer.taxi is preferred for faster processing). We may request proof of identity to ensure data security. We will respond to your request free of charge within one month, extendable by two further months if necessary, considering the complexity and number of requests. We will inform you of any such extension within the first month.

11. Data Security

We are committed to protecting the security of your personal data. We implement appropriate technical and organizational measures designed to prevent accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed. These measures are chosen based on the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as the risks to your rights and freedoms. Access to your personal data is restricted to authorized personnel who require it for their job functions and are bound by confidentiality obligations.

12. Children’s Data

Our services are intended for booking by adults (18 years or older). We do not knowingly collect personal data directly from children under the age of 14 (as per LOPDGDD Article 7) without verifiable parental or guardian consent, except where necessary data (like age for child seat requirements) is provided by the adult making the booking solely for the purpose of providing the service safely and legally. If we become aware that we have collected personal data from a child under 14 without such consent, we will take immediate steps to delete that information.

Our Website may contain links to other websites not operated by us. If you click on a third-party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Last Updated” date at the top. We encourage you to review this Privacy Policy periodically for any changes.

15. Contact Us

If you have any questions about this Privacy Policy, our data processing practices, or wish to exercise your data protection rights, please do not hesitate to contact us through the following channels:

  • Preferred Method (for rights requests): Email to bookings@mallorcatransfer.taxi
  • Postal Address: Mallorca Transfer Taxi, Attn: Privacy Inquiry, Carrer d’Eusebi Estada, 29, Planta 8, Puerta A, 07004 Palma, Illes Balears, España
  • Telephone (for general inquiries): +34 649 27 16 95

16. Supervisory Authority

You have the right to lodge a complaint at any time with the relevant supervisory authority for data protection issues. The competent authority in Spain is the Agencia Española de Protección de Datos (AEPD).

  • Website: www.aepd.es
  • Address: C/ Jorge Juan, 6, 28001-Madrid, Spain.
  • Telephone: +34 900 293 183

We would, however, appreciate the chance to deal with your concerns before you approach the AEPD, so please contact us in the first instance.