Privacy Policy

Last updated: June 8, 2026

This Privacy Policy explains how we process your personal data in accordance with the EU General Data Protection Regulation (GDPR) and national law when you use our website and services (boat trips and car rental).

1. Data Controller

The data controller is responsible for processing your personal data. Contact details for privacy matters:

  • Fuengirola Boat Trips / Fuengirola Car Rental
  • Kimmeltie 10, 90630 Oulu, Finland
  • Place of business: Puerto Deportivo, Fuengirola, Málaga, Spain
  • Email: varaukset@fuengirolanveneretket.fi
  • Phone: +358 400 770 991 / +34 633 969 224

2. What Personal Data We Collect

We only collect data necessary to provide our services:

  • Booking data: name, email, phone number, booking date/time, number of guests and any special requests
  • Payment data: payments are handled by our payment provider (Stripe) — we do not store card details on our servers
  • Contact form data: name, email and the content of your message
  • Account data: if you create an account, your login and profile details
  • Analytics and technical data: anonymised IP address, browser and device information, operating system, page views and paths, language settings, referring source and session identifiers

3. Purposes and Legal Bases for Processing

We process personal data for the following purposes and on the following GDPR legal bases:

  • Fulfilling, confirming and supporting bookings — legal basis: contract (GDPR Art. 6(1)(b))
  • Processing payments — legal basis: contract and legal obligation
  • Accounting and meeting statutory obligations — legal basis: legal obligation (Art. 6(1)(c))
  • Visitor analytics and marketing — legal basis: consent (Art. 6(1)(a))
  • Site security, fraud prevention and service improvement — legal basis: legitimate interest (Art. 6(1)(f))

4. Cookies and Similar Technologies

We use cookies for site functionality, analytics and storing your preferences. Analytics and marketing cookies are only enabled after you give consent in the cookie notice. You can change or withdraw your consent at any time via your browser settings.

  • Essential cookies: core site functions, login and security (no consent required)
  • Analytics cookies: help us understand how visitors use the site (Google Analytics)
  • Preference cookies: store your language and display settings

5. Recipients and Processors

We use trusted service providers who process data on our behalf under data processing agreements (DPAs). We do not sell your personal data.

  • Supabase — database and authentication (EU)
  • Vercel — website hosting platform
  • Stripe — payment processing
  • SendGrid / Twilio — email and message notifications
  • Google (Analytics & Tag Manager) — visitor analytics with consent

6. Transfers Outside the EU/EEA

Some of our providers (such as Google and Stripe) may process data outside the EU/EEA. Such transfers are based on the European Commission's Standard Contractual Clauses (SCCs) or another GDPR-compliant safeguard to ensure an adequate level of data protection.

7. Retention Periods

We retain personal data only as long as necessary for the purpose or to meet legal obligations:

  • Booking and accounting data: the period required by accounting law (in Finland generally 6 years)
  • Analytics data: up to 14–26 months
  • Contact messages: until the matter is resolved, up to 24 months
  • Account data: until the account is deleted

8. Your Rights as a Data Subject

Under the GDPR you have the following rights:

  • Right to access your data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent at any time
  • Right to lodge a complaint with a supervisory authority (in Finland, the Office of the Data Protection Ombudsman, tietosuoja.fi)

9. Data Security

We protect data with appropriate technical and organisational measures. Data is stored in secure infrastructure and encrypted both in transit and at rest. Access to personal data is limited to those who need it to perform their duties.

10. Automated Decision-Making and Profiling

We do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.

11. Minors

Our service is not directed at children under 16 without parental consent. We do not knowingly collect minors' personal data without appropriate consent.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will publish changes on this page and update the date above. We recommend reviewing this policy regularly.

13. Contact

For privacy questions or to exercise your rights, contact: varaukset@fuengirolanveneretket.fi or timo@fuengirolanveneretket.fi.