Privacy Policy

Last updated: April 2026

At Portofino Hair & Beauty, the privacy and security of your personal data are our top priority. This Privacy Policy describes how we collect, use, process, and protect your personal information, in strict compliance with Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR) and the Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).

1. Data Controller

The data controller for the personal data collected through this website and at our premises is:

  • Company Name: Alex Marongiu
  • Tax ID (CIF/NIF): Y9589729P
  • Physical Address: Playa del Inglés, Gran Canaria, Spain (Portofino Hair & Beauty Premises)
  • Contact Phone: +34 642 28 84 87
  • Email: [email protected]

2. Personal Data We Collect

We do not collect personal data through automated forms on our website. The data we obtain is what you voluntarily and directly provide to us when contacting us through:

  • WhatsApp Business: Phone number, name, public profile picture (if configured), and any information, photograph, or history you choose to share with us to request a quote, advice, or booking.
  • Email: Email address, name, and the content of your message.
  • Web Browsing: Through analytics and advertising tools (Google Analytics, Clarity, Meta Pixel), we collect anonymous technical information about your device and browsing, provided you have accepted our Cookie Policy.

3. Purpose of Data Processing

Your personal data will be processed exclusively for the following purposes:

  • Appointment and Service Management: To organize, confirm, or modify your bookings at our salon, as well as to provide the requested hairdressing, aesthetic, and massage services.
  • Customer Service: To respond to your questions, quote requests, and inquiries received via WhatsApp, phone, or email.
  • Commercial Communications (Marketing): Only if you have given us your prior express consent, we may send you communications about promotions, new treatments, or reminders via WhatsApp or email.
  • Analysis and Improvement: To analyze user behavior on the website to improve our service offerings and optimize our advertising campaigns (Google Ads and Meta Ads).

4. Legal Basis for Processing

The legal basis that allows us to process your data varies depending on the purpose:

  • Execution of a contract / Pre-contractual measures: For managing your appointments and providing services at the salon.
  • Explicit consent: For sending marketing communications and installing analytical/advertising cookies.
  • Legitimate interest: To guarantee the security of our network and respond to spontaneous inquiries.

5. Recipients and International Transfers (Data Processors)

We do not sell or rent your data to third parties. However, to offer you our service, we share strictly necessary data with trusted service providers (Data Processors):

  • GoHighLevel (HighLevel Inc.): We use this platform as our customer relationship management (CRM) system and web host. Attention: GoHighLevel's servers are located in the United States. This international data transfer is carried out legally and securely, as HighLevel Inc. is certified under the EU-U.S. Data Privacy Framework and we operate under the Standard Contractual Clauses (SCC) approved by the European Commission.
  • WhatsApp Ireland Limited (Meta): Used as our main communication and booking channel.
  • Google Ireland Limited and Microsoft (Clarity): For analyzing web traffic and optimizing advertising campaigns.

6. Data Retention Period

We will keep your personal data only for the time necessary to fulfill the purposes for which it was collected:

  • Customer data: Kept for the duration of the commercial relationship and, subsequently, during the legal periods required by Spanish tax and accounting legislation (generally 5 years).
  • Marketing data: Kept until you revoke your consent or request to unsubscribe from our communications.
  • WhatsApp history: Periodically deleted when no longer relevant for providing future services, or immediately upon your request.

7. Your Rights (Data Subject Rights)

As the data subject, regulations grant you the following rights regarding your personal information:

  • Right of Access: To know what personal data of yours we are processing.
  • Right to Rectification: To request the correction of inaccurate or incomplete data.
  • Right to Erasure (Right to be forgotten): To request the deletion of your data when it is no longer necessary for the purposes collected.
  • Right to Restriction: To request the temporary suspension of the processing of your data.
  • Right to Data Portability: To receive your data in a structured format to transmit it to another controller.
  • Right to Object: To object to our processing of your data for specific purposes (such as marketing).

How to exercise your rights?

You can exercise any of these rights by sending an email to [email protected] attaching a copy of your ID or equivalent document to verify your identity.

If you consider that your rights have not been properly addressed, you have the right to file a claim with the competent supervisory authority, the Spanish Data Protection Agency (AEPD) through its website: www.aepd.es.