GDPR & Your Data Rights

Last updated: 16 May 2026

1. Our commitment

DETAILCAR FRANQUICIAS, S.L. is fully committed to complying with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and Spain's Organic Law 3/2018 on Data Protection and Digital Rights (“LOPDGDD”).

Our management has adopted a formal Corporate Data Protection Commitment that applies privacy-by-design and privacy-by-default principles, data minimisation, lawful and transparent processing, purpose limitation, and security across the full data lifecycle. All personnel are required to understand and apply this commitment.

2. Data controller

CompanyDETAILCAR FRANQUICIAS, S.L.
CIFB98355530
Registered addressCalle Bello 9, Bajo Izquierda, 46024 Valencia, España
Commercial RegistryRegistro Mercantil de Valencia — Tomo 9345, Libro 6627, Folio 114, Hoja V-144277, Inscripción 1ª
Phone+34 961 059 959
Data Protection OfficerAUDIDAT
Data protection contactadministracion@detailcar.es

DetailCar is the data controller for all personal data collected through the Platform. Individual franchise Centres may act as joint controllers for data processed locally at their premises (e.g. CCTV footage, on-site records).

3. Legal bases for processing

Legal basisWhen we rely on it
Contract (Art. 6(1)(b))Bookings, account management, payments, confirmations and receipts.
Consent (Art. 6(1)(a))Marketing emails, non-essential cookies, SMS promotions. Withdrawable at any time.
Legitimate interest (Art. 6(1)(f))Service improvements, fraud prevention, support, internal analytics.
Legal obligation (Art. 6(1)(c))Tax records, compliance with Spanish commercial law, lawful authority requests.

4. Your rights under GDPR

You can exercise any of the following by emailing administracion@detailcar.es. We will respond within 30 days.

  • Access (Art. 15) — receive a copy of your data and information on processing.
  • Rectification (Art. 16) — correct inaccurate or incomplete data.
  • Erasure (Art. 17) — the right to be forgotten, subject to legal retention.
  • Restriction (Art. 18) — freeze processing in certain circumstances.
  • Portability (Art. 20) — receive data in a machine-readable format.
  • Object (Art. 21) — to processing based on legitimate interest or direct marketing.
  • Withdraw consent (Art. 7(3)) — at any time, without affecting prior processing.
  • No automated decisions (Art. 22) — we do not make purely-automated decisions with legal effect.

5. Data processors & international transfers

ProcessorPurposeLocationSafeguard
SupabaseDatabase, authentication, storageEU (Frankfurt)N/A (EU)
StripePayment processingUS / EUSCCs + DPF
TwilioSMS & WhatsApp notificationsUSSCCs + DPF
ResendTransactional emailUSSCCs
Google (Maps, Analytics)Maps and anonymised analyticsUSSCCs + DPF

International transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, the EU-US Data Privacy Framework (DPF).

6. Data breach notification

  • Notify the AEPD within 72 hours of becoming aware, if the breach is likely to pose a risk (Art. 33).
  • Notify affected individuals without undue delay if the risk to their rights is high (Art. 34).
  • Document all breaches in our internal register.

7. Children's data

Our services are not directed at children under 16. We do not knowingly process minors' data. Under Spanish law (LOPDGDD Art. 7) the minimum age for digital consent is 14.

8. Data retention summary

CategoryRetentionReason
Account profileActive + 12 monthsService provision
Booking history5 yearsSpanish commercial law
Payment / invoice records7 yearsSpanish tax law
Contact form messages12 monthsLegitimate interest
Marketing consent recordsConsent + 3 yearsProof of consent
Analytics (raw)26 monthsWebsite improvement

9. Supervisory authority

If you believe your data protection rights have not been respected:

Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan 6, 28001 Madrid
www.aepd.es
Tel: 901 100 099

10. Related policies