Privacy notice
Draft privacy notice: obtain legal review and confirm the marked retention periods and supplier details before final publication.
English
1. Who is responsible?
The data controller is the service provider identified below. Use the contact details shown for questions or requests about personal data.
Costa Care Group
Address: Bedrijfsadres, 30001 Alicante, Spanje
Tax ID: NIF nummer
VAT number: VAT nummer
Email: Care@costacaregroup.nl
2. What data do we process?
Depending on how you use the service, we may process account and contact details such as name, email address, telephone number and address; business and billing details such as company name, registration number, VAT number and billing address; property and access information such as property address, key/safe information and handover notes; and information about requests, scheduling, contracts, signatures, service reports, documents, invoices and payments. We also process technical information needed to secure accounts and operate cookies.
3. Why and on what legal basis?
We use data to manage accounts, assess requests, schedule and provide services, arrange property access, prepare contracts, deliver reports and respond to enquiries. This may be necessary to perform a contract or take steps requested before a contract is made. Billing and company details may be processed to meet legal accounting and tax obligations. Security and access data support the security and administration of our services. Newsletter data is used following a subscription; the exact legal basis and consent records must be confirmed before final publication.
4. Who receives the data?
We use Holded for invoicing and customer-contact management; billing information is shared with Holded, where invoices are managed and sent. Data may also be processed by our hosting and database provider, email provider and, when the translation feature is used, DeepL. The website also loads components from external CDN, font and script providers. Their legal names, locations, data-processing agreements and any transfers outside the European Economic Area must be verified before final publication.
5. How long do we keep data?
We keep data no longer than necessary for the purpose for which it was collected. Account, request and service data are retained while the customer relationship or potential claims require them. Invoice and accounting data are retained for applicable statutory periods. Specific retention periods for each category still need to be set and legally reviewed.
6. How do we protect data?
We use access controls and encrypt selected personal data in the database with a key managed separately from the database. Exact email lookups use a keyed hash. Uploads and report photos are stored separately as files; their encryption, access controls, backups and retention must be assessed and confirmed separately. No security measure can guarantee absolute security.
7. Your privacy rights
Subject to legal requirements, you may request access, rectification, erasure, restriction, portability or object to processing. Where processing is based on consent, you may withdraw it. Legal record-keeping duties may limit the erasure of some data. You can send a request to the contact address below. You may also complain to the supervisory authority in your country of residence; in Spain this is the AEPD and in the Netherlands the Autoriteit Persoonsgegevens.
8. Cookies and remembered sign-in
The website uses necessary session cookies for security and signed-in features. The remember-device function is used according to your cookie choice. Please use the website cookie settings to review the current options.
9. Transfers and automated decisions
If a provider processes personal data outside the European Economic Area, we will use an appropriate transfer mechanism where required. The current locations and safeguards of all providers must be confirmed before final publication. We do not make decisions based solely on automated processing that produce legal effects on the basis of the data described above.
10. Costa Care Swimming
The separate swimming portal processes the parent’s name and email, the child’s nickname, assigned instructor, diploma route, lesson requests, times, locations and feedback. Instructors record five-level exercise progress; earlier assessments remain in an update history. This supports requested lessons and does not automatically award a diploma. Parents see only their own children; instructors see assigned children and administrators manage accounts and lessons. The child view requires login and may be printed by the parent; there is no public sharing link. Do not provide medical information in enquiries or lesson notes. Invitations and access links are sent by email. Use the swimming contact address for swimming privacy enquiries. Specific retention periods for child profiles, lessons and assessment history must be set before final publication.
Parents and the assigned instructor can exchange messages per child in the swimming portal. Message contents are encrypted; sender, time and read records are retained for conversations and unread portal notifications. Administrators can read messages. When instructors change, the new instructor can read earlier messages and the previous instructor loses access. No message notification emails are sent. Do not share medical or other sensitive data in chat.
11. Costa Care Casa
For bookings and guest registration, Casa processes the customer’s first name, optional name prefix, last name, date of birth, telephone number and email address. For every guest we process the full name shown on the identity document, date of birth, nationality and ID/passport number. We do not request document copies. These personal details are encrypted; extended identity details are accessible only to administrators and are not sent to Stripe, iCal or internal scheduling. Contact and identity details and recorded ages are removed from the Casa database 3 years after departure by the scheduled cleanup task. Financial totals, property, stay dates and counts are kept separately under an administrative retention period that still requires legal confirmation. Stripe Checkout receives the customer email and payment details, not guest identity details. iCal only shares booked dates; confirmed bookings create internal preparation and cleaning tasks. Backups, emails, Stripe and data already shared with other systems have separate retention policies and are not erased by this Casa task. Legal bases, required guest registration fields and reporting to Spanish authorities, processor arrangements and final terms must be reviewed before launch.
For each guest, we also record whether the document is a passport or identity card. This is encrypted with the identity details and deleted under the same retention period.