1. DETAILS OF OUR PRIVACY POLICY

1.- GENERAL INFORMATION

The purpose of this "Privacy and Data Protection Policy" is to inform you of the conditions that govern the collection and processing of your personal data by our entity or corporate group in order to safeguard your fundamental rights, honor, and freedoms, all in compliance with current regulations governing the Protection of Personal Data in the European Union and the Spanish Member State. In accordance with these regulations, we require your authorization and consent for the collection and processing of your personal data. Therefore, below, we provide you with all the details of interest regarding how we carry out these processes, for what purposes, which other entities may have access to your data, and what your rights are. For all the above, once you have reviewed and read our Data Protection Policy, it is essential that you accept it as proof of your compliance and consent.

2.- DATA CONTROLLER

Who collects and processes your data?

The Data Controller is the natural or legal person, public or private, or administrative body, that alone or jointly with others determines the purposes and means of the processing of personal data; in the event that the purposes and means of processing are determined by the law of the European Union or the Spanish Member State. In this case, our identifying details as the Data Controller are as follows: madridtuktuk

How can you contact us?

Our office address: Calle de San Nicolás, 3, 28013 Madrid, Spain Email: contacto@madridtuktuk.com Telephone: 34630493722 Mailing address: Calle de San Nicolás, 3, 28013 Madrid, Spain

3.- SECURITY MEASURES

What do we do to guarantee the privacy of your data? Our entity or corporate group adopts the necessary organizational and technical measures to guarantee the security and privacy of your data, prevent its alteration, loss, unauthorized processing, or access, depending on the state of the technology, the nature of the data stored, and the risks to which it is exposed. Among others, the following measures stand out: Guarantee the permanent confidentiality, integrity, availability, and resilience of the processing systems and services. Restore the availability and access to personal data promptly in the event of a physical or technical incident. Regularly verify, evaluate, and assess the effectiveness of the technical and organizational measures implemented to ensure the security of the processing. Pseudonymize and encrypt personal data, in the case of sensitive data.

4.- PURPOSE OF THE PROCESSING

Why do we want to process your data? We require your authorization and consent to MAYBE collect and process your personal data, so we detail the intended uses and purposes below. *Email Email communications Website inquiries Response to inquiries received through the website's electronic form Subscriber management Marketing, advertising, and commercial prospecting Social media Sharing information on social media *WhatsApp communications WhatsApp instant messaging communications Tour package management Customer/supplier management Data protection Data protection and information privacy

How long do we retain your data?

We use your data for the time strictly necessary to fulfill the purposes indicated above. Unless there is a legal obligation or requirement, the expected retention periods are: Email: As long as the data subject does not request deletion. Website inquiries: As long as the data subject does not request deletion. Subscriber management: As long as the data subject does not request deletion. Commercial communications: As long as the data subject does not request deletion. Email: Until the data subject requests its deletion Website Inquiries: Until the data subject requests its deletion Subscriber Management: Until the data subject requests its deletion Commercial Communications: Until the data subject requests its deletion Social Media: Until the data subject requests its deletion WhatsApp Communications: Until the data subject requests its deletion Tour Package Management: Until the data subject requests its deletion Data Protection: Until the data subject requests its deletion

5.- LEGAL BASIS FOR PROCESSING

Why do we process your data? The collection and processing of your data is always legitimized by one or more legal bases, which are detailed below: Email: Legitimate interest of the Data Controller or third parties Website inquiries: Explicit consent of the data subject Subscriber management: Explicit consent of the data subject Commercial communications: Explicit consent of the data subject Social media: Explicit consent of the data subject WhatsApp communications: Explicit consent of the data subject Tour package management: Explicit consent of the data subject; Existence of a contractual relationship with the data subject through a contract or pre-contract Data protection: Legal obligation of the Data Controller

6.- RECIPIENTS OF YOUR DATA

To whom do we share your data within the European Union? Occasionally, in order to comply with our legal obligations and our contractual commitment to you, we are required and necessary to share some of your data with certain categories of recipients, which are specified below: Social networks. Entities providing social media services WhatsApp communications: Telecommunications service providers. Entities owning instant messaging applications Data protection: Public authorities with jurisdiction over the matter. Spanish Data Protection Agency Do we make international transfers of your data outside the European Union? In the processing of your data carried out by our entity, we need to contract external services that may involve your data being stored and/or processed by organizations established or operating outside the European Union, which would imply that we make international transfers of your data.

7.- SOURCE AND TYPES OF DATA PROCESSED

Where did we obtain your data? Email Clients: The data subject or their legal representative Employees: The data subject or their legal representative Suppliers: The data subject or their legal representative Website Inquiries Web Contacts: The data subject or their legal representative Subscriber Management Subscribers: The data subject or their legal representative Commercial Communications Clients: The data subject or their legal representative Prospective Clients: The data subject or their legal representative Social Media Followers: The data subject or their legal representative WhatsApp Communications Clients: The data subject or their legal representative Tour Package Management Data Protection Employees: The data subject or their legal representative What types of your data have we collected and processed? -------- Email Purposes: Email communications -------- Website inquiries Purposes: Response to inquiries received through the website's electronic form Website contacts Identification data First and last name Email address Telephone -------- Social media Purposes: Sharing information on social media Followers Identification data First and last name Email address -------- WhatsApp communications Purposes: WhatsApp instant messaging communications -------- Data protection Purposes: Data protection and information privacy

8.- RIGHTS OF THE DATA SUBJECTS

What rights do you have? Current data protection regulations protect you with a series of rights regarding our use of your data. Each and every one of your rights is personal and non-transferable, meaning they can only be exercised by the data subject, after verification of their identity. Below, we list your rights: Request ACCESS to your personal data Request RECTIFICATION of your data Request DELETION or deletion of your data (right to be "forgotten") LIMIT or OPPOSE the use of your data Right to data portability for telecommunications or internet services. Right to withdraw your consent at any time. Right to file a data protection complaint with the Supervisory Authority: Spanish Data Protection Agency. Mailing address: Calle de San Nicolás, 3, 28013 Madrid, Spain. How can you exercise your rights regarding your data? To exercise your rights of access, rectification, erasure, restriction or objection, portability, and withdrawal of your consent, you can do so as follows: Email Controller: madridtuktuk Address: Calle de San Nicolás, 3, 28013 Madrid, Spain Website Inquiries Controller: madridtuktuk Address: Calle de San Nicolás, 3, 28013 Madrid, Spain Social Media Controller: GRAN VIA TOUR S.L Address: Calle Ferraz, 22, 28008, Madrid (Madrid), Spain WhatsApp Communications Controller: madridtuktuk Address: Calle de San Nicolás, 3, 28013 Madrid, Spain Data Protection Office address: Calle de San Nicolás, 3, 28013 Madrid Spain Email: contacto@madridtuktuk.com Phone: 34630493722 How can you file a complaint? In addition to your rights, if you believe that your data is not being collected or processed in accordance with current Data Protection regulations, you may file a complaint with the Supervisory Authority, whose contact details are provided below: Spanish Data Protection Agency C/. Jorge Juan, 6. 28001, Madrid (Madrid), Spain Email: info@agpd.es - Phone: 912663517 Website: https://www.agpd.es 9. CONSENT AND ACCEPTANCE By accepting this document, you understand and accept all the clauses of our privacy policy and therefore authorize the collection and processing of your personal data under these terms. This acceptance is made by checking the "Read and Accept" checkbox of our Privacy Policy.