Information and transparency
Privacy policy
Last updated: 5 October 2026 · Version 2026-10-05
Data controller
BOAT ADVENTURE TENERIFE SLU, NIF B42833228, registered address Marina del Sur Las Galletas, Pantalán 5, 38631 Las Galletas, Arona, Santa Cruz de Tenerife, España. Contact for privacy and rights: boatadventuretenerife@gmail.com. This policy applies to the Ocean Friends Tours website and its handling of enquiries and bookings.
Data and purposes
When you contact us by email or WhatsApp, we receive the identification and contact details and content you choose to send. When you book, we process the activity, option, date, time, quantity, amount, reference and payment status. Stripe collects payment details and any contact details requested on its form directly. Our server does not store the full card number or its security code.
We use the information to respond to enquiries, organise and provide the service, manage payments, changes, cancellations, invoicing and legal obligations. Data needed for safety or activity documentation will be requested through the appropriate channel. Do not send medical data, identity documents or sensitive information through general forms.
Legal bases
Pre-booking enquiries and bookings are handled to take pre-contractual steps and perform the contract. Invoicing and legally required communications are based on legal obligations. Service security and fraud prevention are managed under the applicable legal basis. No advertising subscription is active; any optional commercial communication will require a valid legal basis and a simple way to object.
Providers and recipients
Hostinger provides hosting and infrastructure. Stripe provides payment services and processes data for its own security, fraud prevention and compliance obligations. If you choose WhatsApp, the WhatsApp/Meta policy also applies; if you email us, the email service provider is involved. Links to these services open only when you use them. We do not sell personal data. Data may be disclosed to authorities, public bodies or professionals when necessary and where there is a legal basis.
See Stripe's policy, Hostinger's policy, WhatsApp's policy and Google's policy.
International transfers
Some providers operate internationally. Where transfers outside the European Economic Area take place, they must be covered by the mechanisms provided for in the GDPR, such as adequacy decisions or standard contractual clauses, as appropriate. You can consult the safeguards published by each provider and request information from the controller.
Retention
Data is retained for as long as necessary to respond to the enquiry or provide and manage the service. It will subsequently be retained or blocked for the statutory periods applicable to invoicing, business documentation and potential liabilities. No universal maximum of five or six years is set for all data. Once the applicable periods have ended, data will be securely deleted or anonymised. Retention by providers is also governed by their obligations and policies.
Rights
You may request access, rectification, erasure, objection, restriction and portability where applicable by writing to boatadventuretenerife@gmail.com, or to the address stated. Where processing is based on consent, you may withdraw it without affecting previous processing. Additional identity information will be requested only when necessary to verify the request. You may lodge a complaint with the Agencia Española de Protección de Datos. This version of the website does not carry out automated decision-making with legal effects or advertising profiling.
Security and data minimisation
The connection uses HTTPS. Bookings are stored outside public files and deployment versions. The server verifies Stripe payment notifications and does not confirm a booking merely because the customer returns from the payment gateway. Booking information is limited to what is necessary for its management. Contact channels are not intended to collect medical histories or sensitive documents.
