Privacy Policy
This policy explains what personal data we process when you book or contact us, what we use it for and what rights you have, under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Last updated: August 5, 2026
1. Data controller
The controller is Sea Mallorca, whose full identification details appear in the Legal Notice. Privacy contact: marcelo13flaque@gmail.com · +34 683 547 583 · Calle Ramon de Moncada 22, Muelle de Santa Ponsa, 07180.
We have not appointed a Data Protection Officer, as our activity does not require one.
2. What data we process
- Booking data: full name, email address, phone number, number of people, date, time and duration, boat chosen, extras and any notes you write.
- Payment data: amount, currency, payment status and transaction reference. Card details are handled directly by Stripe; we never receive or store them.
- Identification documents shown on the day of departure (ID card, NIE, passport or nautical licence): checked visually only, not copied or filed, unless a legal obligation requires it.
- Contract acceptance data: date, time and version of the Terms & Conditions accepted.
- Communications: the content of messages you send us by WhatsApp, email or phone.
- Technical data: server and security logs generated when visiting the site (IP address, browser, pages viewed).
3. Purposes and legal basis
- Managing your booking, charging the rental, handing over the boat and assisting you during the trip — basis: performance of the contract (art. 6.1.b GDPR).
- Blocking the time slot in the boat's calendar and preventing double bookings — basis: performance of the contract.
- Answering your enquiries by WhatsApp, email or phone — basis: performance of the contract or our legitimate interest in assisting you (arts. 6.1.b and 6.1.f).
- Complying with tax, accounting and maritime safety obligations, and keeping proof that the terms were accepted — basis: legal obligation (art. 6.1.c).
- Preventing payment fraud and keeping the website secure — basis: legitimate interest (art. 6.1.f).
- Handling complaints and bringing or defending legal claims — basis: legitimate interest and legal compliance.
We do not send marketing communications and we do not build profiles. If we ever wanted to, we would ask for your prior, separate consent, which you could withdraw at any time.
4. Retention periods
- Booking and invoicing data: for the duration of the contract and then for the statutory tax and commercial limitation period (up to 6 years, art. 30 of the Spanish Commercial Code and tax legislation).
- Proof of acceptance of the terms: for as long as liability may arise from the contract.
- Enquiries that do not result in a booking: up to 1 year from the last contact.
- Technical and security logs: up to 12 months.
Once those periods have elapsed, data is securely deleted or anonymised.
5. Recipients and processors
To provide the service we work with the following providers, acting as processors under a contract compliant with article 28 GDPR:
- Stripe Payments Europe, Ltd. (Ireland)
- Card payment processing and fraud prevention.
- Resend (USA)
- Sending booking notification and confirmation emails.
- Google Ireland Ltd. — Google Calendar
- Managing availability and each boat's calendar.
- Vercel Inc. (USA)
- Website hosting and delivery.
We may also disclose data to the tax authorities, maritime authorities or law enforcement where legally required, and to our insurer in the event of a claim. We never sell or share your data with third parties for commercial purposes.
6. International transfers
Some providers are established in the United States or may access data from there. These transfers rely on the EU–US Data Privacy Framework or, failing that, on the Standard Contractual Clauses approved by the European Commission, together with supplementary safeguards.
7. Your rights
You may at any time exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw consent where processing is based on it, without affecting the lawfulness of processing carried out beforehand.
To do so, write to marcelo13flaque@gmail.com stating the right you wish to exercise and attaching a copy of an identity document. We will reply within a maximum of one month.
If you believe your request has not been handled properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es · C/ Jorge Juan 6, 28001 Madrid).
8. Data security
We apply appropriate technical and organisational measures: HTTPS traffic encryption, restricted access to management tools, strong authentication on payment services, and credentials stored in encrypted environment variables.
9. Minors
Services may only be booked by people aged 18 or over. We do not knowingly collect data from minors; if we detect any, we will delete it.
10. Changes to this policy
We may update this policy to reflect legal or service changes. The version published on this page is always the one in force.
Any questions?
If anything in this document isn't clear, message us before booking and we'll explain it.
Message on WhatsApp