Legal
Privacy policy
How we handle your personal data under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD). We collect only what is essential and keep your data within the European Union.
Last updated: 12 July 2026
1. Data controller
The controller of your data is Fernando Llabrés Socias, with contact address at Puerto Club de Mar, Muelle Pelaires, 07015 Palma de Mallorca, Illes Balears and contact email [email protected].
2. What data we collect
We apply the data-minimisation principle: we collect only the data needed to manage your booking or enquiry.
- Booking data: name, email, phone and the date of the experience.
- Contact data: whatever you provide via the form or WhatsApp.
- Payment data: handled entirely by Stripe. Holiboats never sees or stores your card details.
3. Purpose and legal basis
- Managing your booking and providing the contracted service (legal basis: performance of a contract).
- Responding to your enquiries (legal basis: your consent or our legitimate interest in replying).
- Complying with our legal and tax obligations (legal basis: legal obligation).
- Web analytics via Google Analytics 4, only if you accept it (legal basis: your consent).
4. Retention
We keep your data for as long as needed to provide the service and, afterwards, for the applicable legal periods (for example, tax and accounting). It is then deleted or anonymised.
5. Recipients and data processors
To provide the service we share data with providers acting as data processors, each under its corresponding agreement (DPA):
- Supabase (booking database), with data hosted in the European Union (Frankfurt).
- Stripe (payment processing), with infrastructure in Europe.
- Formspark (contact form processing), with data hosted in the European Union (Ireland).
- Google (Calendar for the team’s booking diary and Analytics for web analytics). See the section on international transfers.
- Resend (sending confirmation emails). See the section on international transfers.
6. International transfers
Most of the processing takes place within the European Union: Supabase (Frankfurt), Stripe (Europe) and Formspark (Ireland). In three specific cases data is transferred to US companies, always under the appropriate safeguards provided for in the GDPR (Art. 46), such as standard contractual clauses or the EU-US Data Privacy Framework:
- Resend (sending the booking confirmation email): your name and email address.
- Google Calendar (the team’s internal diary): when your booking is confirmed, an event is created with your name, phone number and email so the skipper can reach you on the day of the trip.
- Google Analytics and Google Ads (analytics and campaign measurement): website usage data, only if you have accepted the corresponding cookies.
7. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction and portability at any time by writing to [email protected]. You also have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).