1. Data Controller
The controller of personal data is Ticando Technologies ("Ticando"), domiciled in Spain.
- Contact email: info@ticando.tech
- Website: https://ticando.tech
2. Data We Collect
We collect the following types of personal data:
2.1. Data provided directly
- Registration data: first name, surname, email, phone, company name, tax ID, registered address, country.
- Contact form data: name, email, company, phone, message.
- Activity data: descriptions, prices, photos and schedules of the published tourist activities.
- Payment data: processed directly by the payment gateways. Ticando does not store credit card data.
2.2. Data of the traveller making a booking
When you book an activity through a booking engine or a website built with Ticando, we additionally process the data necessary to formalise and deliver that booking:
- Identification data: first name and surname, contact email and phone.
- Booking data: activity booked, date and time, number of participants, meeting point and amount.
- Data required for the activity: only what the Provider requires to deliver it safely (for example age, weight or relevant restrictions in adventure activities).
- Payment data: entered directly in the gateway's secure environment. Neither Ticando nor the Provider accesses or stores the full card number.
This data is disclosed to the activity Provider, who is your counterparty in the contract and who must deliver the service.
2.3. Data collected automatically
- Browsing data: IP address, browser type, operating system, pages visited, time spent.
- Cookies: we use technical and analytics cookies. See our cookie policy for more information.
3. Purpose of Processing
Personal data is processed for the following purposes:
- Service delivery: account management, website creation, booking and payment processing.
- Communications: sending booking confirmations, service notifications and technical support.
- Service improvement: usage analysis to improve the Platform.
- Legal obligations: compliance with applicable tax and commercial regulations.
- Marketing communications: only with the user's prior consent, sending news and offers.
4. Legal Basis for Processing
- Performance of a contract: the data is necessary to deliver the contracted service (Art. 6.1.b GDPR).
- Consent: for marketing communications and non-essential cookies (Art. 6.1.a GDPR).
- Legitimate interest: for service improvement and fraud prevention (Art. 6.1.f GDPR).
- Legal obligation: for compliance with tax obligations (Art. 6.1.c GDPR).
5. Data Recipients
Personal data may be disclosed to:
- Activity Providers: your booking data is disclosed to the Provider organising the activity, who is responsible for delivering it and is your counterparty in the contract.
- Payment gateways: to process transactions (Stripe, MultiSafepay, GreenPay, among others). They process payment data as independent controllers, under their own policies.
- Service providers: web hosting, email delivery, analytics (all under confidentiality agreements).
- Public authorities: where required by law or court order.
We do not sell or transfer personal data to third parties for commercial purposes.
6. International Transfers
Some of our service providers may be located outside the European Economic Area (EEA). In such cases, we ensure that appropriate safeguards are in place under the GDPR, such as standard contractual clauses approved by the European Commission.
7. Retention Period
- Account data: while the account is active and for the subsequent statutory retention periods (up to 6 years for commercial and tax obligations).
- Booking data: during delivery of the activity and for the subsequent statutory claim and tax periods.
- Contact data: up to 2 years from the last communication, unless consent for marketing communications is given.
- Browsing data: maximum 13 months.
8. Cancellations, Refunds and No-Shows
The cancellation, no-show, refund and force majeure terms applicable to activity bookings are set out in full in a separate document, which includes the deadlines, refund percentages and the procedure for requesting a cancellation:Booking Terms and Conditions
Each Provider may set specific terms for their activities, which will be shown to you before completing payment and which prevail over the general terms as stated therein.
9. Your Rights
Under the General Data Protection Regulation (GDPR) and Spanish data protection law (LOPDGDD), you have the right to:
- Access: know what personal data we process about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your data when it is no longer necessary.
- Objection: object to the processing of your data in certain circumstances.
- Restriction: request restriction of processing in the cases provided by law.
- Portability: receive your data in a structured, commonly used format.
- Withdrawal of consent: withdraw consent given at any time.
To exercise any of these rights, send an email to info@ticando.tech stating your request and attaching a copy of your identity document.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if you consider that the processing of your data does not comply with applicable regulations.
10. Security
Ticando implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or destruction, including:
- SSL/TLS encryption on all communications.
- Secure storage with encryption at rest.
- Role-based access controls.
- Regular backups.
- Continuous infrastructure monitoring.
11. Amendments
Ticando reserves the right to amend this Privacy Policy to adapt it to legislative developments or changes in our services. Amendments will be published on this page with the update date. We recommend reviewing it periodically.
12. Contact
For any query relating to this Privacy Policy or the processing of your personal data:
- Email: info@ticando.tech
- Web: ticando.tech/contacto