Privacy Policy
Last updated: April 3, 2026
1. DATA CONTROLLER INFORMATION
Identity: Soraya Collective SL
Address: Carrer Pere d’Alcàntara Penya 13, 7A, 07006 Palma de Mallorca, Spain
NIF/CIF: [INSERT NIF/CIF]
Email: hola@somallorca.com
Phone: (+34) 694 904 101
Website: https://somallorca.com
Data Protection Officer (DPO): Not designated
Registration with AEPD: In process
2. CATEGORIES OF PERSONAL DATA PROCESSED
2.1 Contact Form Data
– Name and surname
– Email address
– Phone number (optional)
– Message content
– IP address
– Date and time of submission
– User agent (browser/device info)
2.2 Newsletter Subscription Data
– Email address
– IP address
– Subscription timestamp
– Double opt-in confirmation
2.3 Website Analytics Data (Google Analytics)
– Anonymized IP address
– Browser type and version
– Operating system
– Screen resolution
– Referral source
– Time spent on pages
– Pages visited
– Bounce rate
3. PURPOSES OF DATA PROCESSING
PRIMARY PURPOSES:
1. Contact forms: Respond to inquiries about so FLOW classes, so CALM treatments, so CAFÉ inquiries and all other SO MALLORCA-related inquiries
2. Newsletter: Send promotional content about classes, events and special offers
3. Website analytics: Analyze user behavior to improve website functionality
SECONDARY PURPOSES:
4. Compliance with legal obligations (tax, accounting, anti-fraud)
5. Internal statistical analysis
4. LEGAL BASIS FOR PROCESSING
Contact forms: Legitimate interest (Art. 6(1)(f) GDPR)
Newsletter: Explicit consent (Art. 6(1)(a) GDPR)
Analytics cookies: User consent (Art. 6(1)(a) GDPR)
Essential cookies: Legitimate interest (Art. 6(1)(f) GDPR)
Legal compliance: Legal obligation (Art. 6(1)(c) GDPR)
5. DATA RECIPIENTS
Hosting provider: [INSERT: e.g., SiteGround, Spain]
Email service: [INSERT: e.g., Google Workspace, EEA]
Analytics: Google Analytics (USA with Standard Contractual Clauses)
Newsletter: [INSERT: e.g., Mailchimp, USA with SCCs]
No data transfers to third countries without adequate safeguards.
6. INTERNATIONAL DATA TRANSFERS
Google Analytics (USA): Standard Contractual Clauses approved by European Commission
Other providers: All located within EEA
7. DATA RETENTION PERIODS
Contact forms: 12 months after last interaction
Newsletter: Until unsubscription + 30 days
Analytics: 26 months (Google Analytics standard)
Server logs: 30 days
8. USER RIGHTS (GDPR Articles 15-22)
You have the right to:
– Access your personal data
– Rectify inaccurate data
– Request deletion (“right to be forgotten”)
– Restrict processing
– Data portability
– Object to processing
– Withdraw consent at any time
– Lodge complaints with AEPD (www.aepd.es)
Exercise rights: hola@somallorca.com
9. SECURITY MEASURES
Technical measures:
– SSL/TLS encryption (HTTPS)
– Secure hosting with firewall
– Regular security updates
– Access controls
– Data anonymization (analytics)
Organizational measures:
– Employee training
– Data processing agreements with vendors
– Incident response procedures
10. COOKIES POLICY
Detailed in separate Cookie Policy.
11. CONTACT FORM LEGAL BASIS
Legitimate interest assessment:
– Purpose: Respond to legitimate inquiries
– Necessity: Essential for business communication
– Proportionality: Minimal data collection
– User rights balanced against business needs
12. NEWSLETTER DOUBLE OPT-IN
1. User enters email
2. Confirmation email sent
3. User clicks confirmation link
4. Welcome email sent
5. Unsubscribe link in every email
13. AUTOMATED DECISION MAKING
No automated decision-making or profiling.
14. CHILDREN’S DATA
Website not directed at children under 16. No data knowingly collected from minors.
15. DATA BREACH NOTIFICATION
Users and AEPD notified within 72 hours of any data breach posing high risk.
16. SUPPLIER PROCESSING AGREEMENTS
All processors have DPA contracts per Art. 28 GDPR.
17. AEPD REGISTRATION
Registered as required by Spanish data protection law.
18. CHANGES TO PRIVACY POLICY
Updated versions published on website with date.
19. APPLICABLE LAW
GDPR (EU 2016/679) and Spanish Organic Law 3/2018.
20. CONTACT FOR QUESTIONS
hola@somallorca.com
Soraya Collective SL, April 3, 2026