[LEGAL ENTITY] (“DoAzores”, “we”), NIPC [NIPC], [REGISTERED ADDRESS, Açores], is the controller of your personal data for the DoAzores platform. This Privacy Policy explains how we collect, use, and protect it. We comply with the EU General Data Protection Regulation (GDPR) and Portuguese Law 58/2019. Our data-protection contact is privacy@doazores.com.
1. Our role, and Operators
When you book, the relevant Operator receives the data needed to deliver your activity and is an independent controller of that data for its own purposes, under its own privacy policy. Our payment provider (Stripe) processes payment data in its own controller and processor capacity.
2. Data we collect
- Account and identity: name, email, phone, password.
- Booking: activity, date, participants and details you provide, and communications.
- Payment metadata: confirmation and status (card data is handled by Stripe, not stored by us).
- Technical and usage: device, IP, pages viewed, and cookies and analytics (see the Cookie Policy).
3. Purposes and legal bases (GDPR art. 6)
- Create your account, process and manage Bookings — contract (art. 6(1)(b)).
- Issue and keep invoices and tax and accounting records — legal obligation (art. 6(1)(c); retained 10 years).
- Platform security, fraud prevention, and service improvement — legitimate interest (art. 6(1)(f)).
- Marketing emails and non-essential cookies and analytics — consent (art. 6(1)(a)).
- DAC7 and regulatory reporting — legal obligation (art. 6(1)(c)).
4. Who we share data with
- Operators (independent controllers) — to fulfil your Booking.
- Processors: Stripe (payments), Cloudflare (hosting, CDN and security), PostHog (analytics — only with your consent), Resend (transactional email), and our channel-manager connections (e.g. Bókun, Rezdy, FareHarbor) as needed to confirm availability and Bookings.
5. International transfers
Some processors are established in the USA. We rely on the EU–US Data Privacy Framework (adequacy, art. 45) for certified recipients and on EU Standard Contractual Clauses (art. 46) as a safeguard; transfers to non-EEA Operators rely on SCCs or the art. 49(1)(b) contract-necessity derogation.
6. Retention
We keep account data while your account is active; booking and tax records for 10 years (legal obligation); and analytics and marketing data for shorter, indicative periods ([e.g. analytics 26 months]), after which we delete or anonymise them.
7. Your rights
You have the rights of access, rectification, erasure, restriction, portability, and objection, and to withdraw consent at any time (GDPR arts. 15–22). To exercise them, contact privacy@doazores.com. You may also lodge a complaint with the supervisory authority, the CNPD (Comissão Nacional de Proteção de Dados), www.cnpd.pt.
8. Cookies
We use cookies and similar technologies as described in our Cookie Policy; non-essential cookies require your consent.
9. Children
The Platform is not directed to children. We do not knowingly process the data of children under 13 without appropriate consent (Law 58/2019).
10. Security
We use appropriate technical and organisational measures (encryption in transit, access controls, and reputable processors) to protect your data.
11. Automated decisions
We do not make decisions producing legal effects about you based solely on automated processing, other than routine fraud and security checks.
12. Changes and contact
We may update this Policy; we’ll post the new version with its date. Questions? Write to privacy@doazores.com.