Skip to main content
LegalCanarionet

Legal

Privacy Policy

Information required by GDPR (EU 2016/679) and LOPDGDD (Spain) for users and providers.

Last updated: 2026-08-31

1. Data controller

Controller: Boštjan Biber (trade name: Canarionet)

Email: privacy@canarionet.com

Address: Calle Las Cabezas, 38400 Puerto de la Cruz

DPO (if applicable): privacy@canarionet.com

2. Purpose of processing

  • Account creation and user authentication
  • Publication and management of listings and services
  • Responding to requests and support inquiries
  • Platform security, fraud prevention, and service integrity
  • Analytics (with consent where required)

3. Legal basis

  • Contract: account creation and service delivery
  • Consent: optional analytics and marketing communications
  • Legitimate interest: platform security and abuse prevention
  • Legal obligation: compliance with applicable laws

4. Data categories

Identification and contact details, listing content, service data, communications, and technical usage data. No special categories of data are processed unless explicitly provided by the user.

Where the data comes from

Most personal data comes from you. One exception: reference listings for businesses, venues and events are imported from official open-data sources (mainly datos.canarias.es and datos.tenerife.es — the full list, with licences, is on our Data sources page). Those datasets can include institutional contact details such as a venue's public email address or a public body's phone number. We publish institutional contacts only: addresses that look personal (for example on a private mail provider) are withheld, and photographs from those sources are never used.

If an imported listing concerns you and you want it corrected or removed, use the report link on the listing or write to legal@canarionet.com. A removed listing stays removed — the importer never republishes a suspended entry.

5. Recipients and processors

We share personal data only with the service providers (processors) strictly necessary to operate the platform. We never sell your personal data. The main recipients are:

  • [PENDING: owner to confirm] — website hosting, application servers, database and cache (European Economic Area).
  • Cloudflare R2 (EU jurisdiction) — storage of uploaded media and documents.
  • Cloudflare — DNS, reverse proxy and TLS termination for this platform and for organisation microsites. All traffic passes through it.
  • Brevo (Sendinblue SAS, France) — delivery of transactional and marketing email.
  • Mistral AI (France) — automated content review, moderation, translation, and the embeddings behind search. Content you submit for publication, and messages you send, may be processed by it.
  • MapTiler (Switzerland) — map tiles and address lookup.
  • Stripe Payments Europe (Ireland) — payment processing.
  • Browser push services (Google, Mozilla, Apple) — delivery of push notifications, if you enable them. Notification content is encrypted end-to-end; only the delivery address is visible to them.
  • Web analytics is self-hosted on our own infrastructure. It sets no cookies, collects no personal data and is shared with no one.

Each processor acts under a data-processing agreement (Art. 28 GDPR) and may process the data only on our documented instructions.

Signing in with Google or Facebook

Signing in with a social account is optional — an email address and a password work just as well. If you choose it, the sign-in itself happens on Google's or Meta's own page, and we receive only what is needed to create or recognise your account.

What we receive and keep: the provider's account identifier, your email address and your name. Nothing else — no profile photo, no friends or contacts, no date of birth, no location. The access token the provider issues is used once to read those fields and is never stored.

Until you actually press one of those buttons, no Google or Meta script runs on this site and neither company sets a cookie here. We deliberately do not embed their sign-in widgets, so opening the sign-in page tells them nothing.

Legal basis: performance of the contract (Art. 6(1)(b) GDPR) — you asked us to open your account this way. For that exchange Google Ireland and Meta Platforms Ireland act as independent controllers under their own privacy policies.

You can revoke the connection at any time in the provider's own settings, and you can delete your account from your account settings. A deletion request that Meta forwards to us is honoured exactly like one you make to us directly.

6. International transfers

Almost all of our processors are established in the European Economic Area, and the personal data behind this platform stays there. Two exceptions: Cloudflare (network and object storage) is a US company — object storage is pinned to Cloudflare's EU jurisdiction, and any transfer relies on the EU–US Data Privacy Framework together with the European Commission's Standard Contractual Clauses; and MapTiler processes data in Switzerland, which the European Commission recognises as providing an adequate level of protection. If you sign in with Google or with Facebook, the counterparties are Google Ireland and Meta Platforms Ireland, both established in the European Economic Area; where either routes data to its US parent, that transfer relies on the EU–US Data Privacy Framework. Either exchange happens only because you chose it, and never before you press the button. You may request a copy of the safeguards in place by contacting us.

Inquiries

When you post a request, its text, category, municipality and any photos you attach become public. Your name is shown according to your profile settings. Offers you receive are private between you and the business sending them.

If you drop an exact point on the map, that point is NOT published. We publish only an approximate position within a radius of about one kilometre. The exact point is disclosed to a business only if you choose to share it with them.

A request stays visible for the period you choose and can be renewed. Withdrawn, expired and rejected requests are deleted automatically after the periods set out in the Terms, together with their images. An open appeal suspends that deletion until it is resolved.

7. Retention

We keep personal data only for as long as necessary for the purposes described above. The following periods apply as our default and are subject to final legal confirmation:

  • Account data — while your account is active and for up to 12 months after it is closed.
  • Billing and tax records — 5 to 6 years, as required by Spanish commercial and tax law.
  • Server and security logs — approximately 12 months.
  • Analytics data — according to each provider's settings (for Google Analytics, approximately 14 months).
  • Marketing-lead data — until you object or withdraw your consent.
  • Backups — our database backups are rotated on a 14-day cycle, so data you delete can still exist in a backup copy for up to 14 days after it disappears from the live service. Backups are access-controlled, and we do not use them to reinstate data you asked us to delete.
  • Platform closure — if we close the platform, personal data is deleted on the closing date, except billing and tax records, which we keep for the period stated above. The Terms and the Service Continuity page explain the notice period and how to export your data beforehand.
  • Contact-form enquiries — support correspondence is kept for up to 24 months after the enquiry is closed, so we can follow up on a recurring problem.
  • Platform messages — conversations you hold through our messenger are kept for as long as your account exists, and are deleted with it. We do not currently apply a shorter automatic deletion window to message content.

These periods are draft defaults pending confirmation by our legal adviser.

8. Your rights

You may exercise the following rights free of charge at any time by contacting privacy@canarionet.com:

  • Access — confirmation of whether we process your data and a copy of it.
  • Rectification — correction of inaccurate or incomplete data.
  • Erasure — deletion of your data (the 'right to be forgotten').
  • Restriction — limitation of the processing of your data.
  • Portability — receiving your data in a structured, commonly used, machine-readable format.
  • Objection — objecting to processing based on our legitimate interests or to direct marketing.
  • Withdrawal of consent — withdrawing any consent you have given at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3) GDPR).

If you consider that your rights have not been respected, you may lodge a complaint with the Spanish Data Protection Agency (AEPD), AEPD – https://www.aepd.es.

Certain organisation profiles, listings, user reviews, and messages may be automatically reviewed by an AI system (built on Mistral AI, an EU-based provider) for safety, quality, and platform fit before publication. In some cases this results in content being approved, rejected, or hidden without prior human intervention. Where such a decision produces a legal effect or similarly significantly affects you, you have the right to obtain human intervention, to express your point of view, and to contest the decision.

To request a human review of an automated content decision, contact us at privacy@canarionet.com referencing the content in question. An administrator will review the case and may reverse or adjust the automated decision.

Providing the data marked as required is necessary to create an account and use the service; without it we cannot provide the contracted service. Optional data (such as analytics or marketing consent) is not required in order to use the platform.