This policy explains which personal data Tenerife Wonder processes, why it is used and how you can exercise your rights.
Last updated: 28 September 2026.
1. Data controller
- Controller: Iván MartÃnez GarcÃa.
- Tax ID: 46716938M.
- Address: Calle Chiguergue 5, 38296 San Cristóbal de La Laguna, Santa Cruz de Tenerife, Spain.
- Email: hola@tenerifewonder.com.
- Telephone: +34 642 934 298.
2. Data we process
Depending on the form or communication, we may process your name, email address, telephone number, dates, number and ages of travellers, accommodation or area, language, preferences, message, activity viewed and technical source data. Professional applications may also include trading and legal name, tax ID, contact person, website, operating base, activities, areas, languages, registrations, qualifications, insurance information and accessibility details.
Identity documents, full insurance policies, bank details and particularly sensitive information must not be submitted through public forms.
3. Purposes and legal bases
- Traveller requests: to reply, clarify needs, find options and follow up. Legal basis: steps requested before entering into a contract.
- Contact with potential providers: to ask about availability initially without revealing the traveller’s identity. Legal basis: legitimate interest in responding to the request.
- Sharing data with an identified provider: only after identifying the provider and obtaining specific authorisation. Legal basis: consent.
- Professional registration: to review an application, verify information and contact the applicant. Legal basis: pre-contractual steps and legitimate interest in maintaining a reliable network.
- Security and abuse prevention: to protect forms, limit automated submissions and document incidents. Legal basis: legitimate interest and legal obligations.
- Marketing communications: only where separate consent has been requested. Legal basis: consent, which can be withdrawn at any time.
4. Recipients
We do not sell personal data. Essential hosting, email, maintenance and security providers may access data as processors. Traveller data is only shared with the specific activity provider after the provider has been identified and authorisation has been obtained. Data may also be disclosed to public authorities or courts where legally required.
5. International transfers
The current forms do not deliberately involve international transfers. If a technology provider outside the European Economic Area is introduced, Tenerife Wonder will verify that an adequacy decision, standard contractual clauses or another valid safeguard is in place and will update this policy where appropriate.
6. Retention
Enquiries are retained while active and afterwards for as long as necessary to document the service, resolve incidents and meet legal obligations. Incomplete or rejected professional applications are reviewed periodically and deleted or anonymised when no longer needed. Verified profiles are retained while the relationship exists or there is a legitimate interest in maintaining the directory, and afterwards for applicable legal periods. Consents and authorisations may be retained as evidence.
7. Your rights
You may request access, rectification, erasure, objection, restriction or portability, and withdraw consent without affecting earlier processing. Email hola@tenerifewonder.com and state which right you wish to exercise. We may ask for information previously provided to verify your identity. You may also lodge a complaint with the Spanish Data Protection Agency.
8. Source of data and automated decisions
Data usually comes from the person concerned. Business information may also come from public sources and is checked before a profile is activated. No decisions with legal or similarly significant effects are made solely by automated means.
9. Children
Forms must be submitted by an adult. The ages of children may only be requested to check whether an activity is suitable and to verify its requirements.
10. Security and updates
Reasonable access control, authentication, backup, data minimisation and abuse-prevention measures are applied. This policy will be updated when processing activities, technology providers or website functions change.