Privacy Policy

Last updated: April 3, 2026

 

1. Data controller information

Identity: Soraya Collective SL
Address: Carrer Pere d’Alcàntara Penya 13, 7A, 07006 Palma de Mallorca, Spain
NIF/CIF: VAT ESB22873996
Email: hola@somallorca.com
Phone: (+34) 694 904 101
Website: https://somallorca.com

Data Protection Officer (DPO): Not designated

Registration with AEPD: In process

 

2. Categories of personal data processed 

2.1 Contact Form Data
– Name and surname
– Email address
– Phone number (optional)
– Message content
– IP address
– Date and time of submission
– User agent (browser/device info)

2.2 Newsletter Subscription Data
– Email address
– IP address
– Subscription timestamp
– Double opt-in confirmation

2.3 Website Analytics Data (Google Analytics)
– Anonymized IP address
– Browser type and version
– Operating system
– Screen resolution
– Referral source
– Time spent on pages
– Pages visited
– Bounce rate

3. Purpose of data processing 

Primary Purposes:
1. Contact forms: Respond to inquiries about so FLOW classes, so CALM treatments, so CAFÉ inquiries and all other SO MALLORCA-related inquiries
2. Newsletter: Send promotional content about classes, events and special offers
3. Website analytics: Analyze user behavior to improve website functionality

Secondary Purposes: 
4. Compliance with legal obligations (tax, accounting, anti-fraud)
5. Internal statistical analysis

 

4. Legal Basis for processing 

Contact forms: Legitimate interest (Art. 6(1)(f) GDPR)
Newsletter: Explicit consent (Art. 6(1)(a) GDPR)
Analytics cookies: User consent (Art. 6(1)(a) GDPR)
Essential cookies: Legitimate interest (Art. 6(1)(f) GDPR)
Legal compliance: Legal obligation (Art. 6(1)(c) GDPR)

 

5. Data recipients 

Hosting provider: [INSERT: e.g., SiteGround, Spain]
Email service: [INSERT: e.g., Google Workspace, EEA]
Analytics: Google Analytics (USA with Standard Contractual Clauses)
Newsletter: [INSERT: e.g., Mailchimp, USA with SCCs]

No data transfers to third countries without adequate safeguards.

 

6. International data transfers 

Google Analytics (USA): Standard Contractual Clauses approved by European Commission
Other providers: All located within EEA

 

7. Data retention periods

Contact forms: 12 months after last interaction
Newsletter: Until unsubscription + 30 days
Analytics: 26 months (Google Analytics standard)
Server logs: 30 days

 

8. User rights (GDPR Articles 15-22) 

You have the right to:
– Access your personal data
– Rectify inaccurate data
– Request deletion (“right to be forgotten”)
– Restrict processing
– Data portability
– Object to processing
– Withdraw consent at any time
– Lodge complaints with AEPD (www.aepd.es)

Exercise rights: hola@somallorca.com


9. Security Measures 

Technical measures:
– SSL/TLS encryption (HTTPS)
– Secure hosting with firewall
– Regular security updates
– Access controls
– Data anonymization (analytics)

Organizational measures:
– Employee training
– Data processing agreements with vendors
– Incident response procedures

 

10. Cookies Policy 

Detailed in separate Cookie Policy.

 

11. Contact form legal basis 

Legitimate interest assessment:
– Purpose: Respond to legitimate inquiries
– Necessity: Essential for business communication
– Proportionality: Minimal data collection
– User rights balanced against business needs

 

12. Newsletter double opt-in 

1. User enters email
2. Confirmation email sent
3. User clicks confirmation link
4. Welcome email sent
5. Unsubscribe link in every email

 

13. Automated decision making 

No automated decision-making or profiling.

 

14. Childen’s data 

Website not directed at children under 16. No data knowingly collected from minors.

 

15. Data breach notification  

Users and AEPD notified within 72 hours of any data breach posing high risk.


16. Supplier processing agreements 

All processors have DPA contracts per Art. 28 GDPR.


17. AEPD registration 

Registered as required by Spanish data protection law.

 

18. Changes to privacy policy 

Updated versions published on website with date.


19. Applicable law 

GDPR (EU 2016/679) and Spanish Organic Law 3/2018.

 

20. Contract for questions 

hola@somallorca.com

Soraya Collective SL, April 3, 2026

About this Website

SO MALLORCA was created as a digital reflection of island living - calm, intentional, design-led, and rooted in a slower Mediterranean rhythm. The website was developed to communicate the brand’s philosophy through minimal design, refined storytelling and an immersive visual experience inspired by Mallorca’s natural landscape and lifestyle.

Strategic direction, content and communications lead: Ricarda Forstner

Web design, development, ongoing updates: Santa Helena & Balmain Studio

Creative direction, visual identity and branding: Santa Helena & Balmain Studio