PRIVACY POLICY

Yes Mobility Ibiza Privacy Policy

(Last updated: April 30, 2025)

In accordance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights (LOPD-GDD), we inform you that the controller of your personal data is:

  • Trade Name: Yes Mobility Ibiza
  • Legal Representative: Eduardo Persichino
  • NIE: Y5290545F
  • Registered Office: Carrer Ramon Muntaner, 45, 07800, Ibiza, Spain
  • Contact Email: info@yesmobilityibiza.com
  • Official Website: yesmobilityibiza.com

    Purpose of this Document: To inform you about how personal data provided to Yes Mobility Ibiza is collected, used, protected, and stored when using our services (vehicle reservations and rentals, activity bookings, website usage, etc.).

    2. Scope of Application

    This Privacy Policy applies to all personal data provided or generated during the use of the following services or channels offered by Yes Mobility Ibiza:

    • Official Website: yesmobilityibiza.com, including:
      • Online reservation system.
      • Contact and customer support forms.
      • Subscription forms (newsletter, promotions, etc.).
    • Telephone and In-Person Services:
      • Telephone reservations and in-person management at our office located at Carrer Ramon Muntaner, 45, Ibiza.
    • Sale of Third-Party Activities and Tourism Services:
      • Intermediation in the sale and reservation of tourist activities, transportation tickets (e.g., Trasmapi), and other services provided by external operators, subject to their own privacy policies.
    • Integrated Systems:
      • Data processed through the virtual POS (secure online payment via Redsys).
      • Geolocation via GPS devices integrated into rented vehicles.

    This Policy does not cover external websites linked from our site or services with specific privacy conditions provided directly by third parties (activity providers, external services, or external links).

    3. Principles of Personal Data Processing

    Yes Mobility Ibiza is committed to complying with the fundamental principles established by the General Data Protection Regulation (GDPR) and current Spanish legislation (Organic Law 3/2018), ensuring appropriate and transparent processing of your personal data through:

      • Lawfulness, Fairness, and Transparency: We process your personal data lawfully, fairly, and transparently, providing clear and precise information about its use.
      • Purpose Limitation: We collect and process your data only for specific, explicit, and legitimate purposes, as previously informed.
      • Data Minimization: We only request personal data that is necessary and strictly relevant to fulfill the specific purpose of processing (vehicle reservations, online payments, activity bookings, customer service, etc.).
      • Accuracy: We keep your data updated and accurate, taking necessary measures to rectify or delete incorrect information.
      • Storage Limitation: We store your personal data only for the time strictly necessary for the informed purpose and/or to comply with legal obligations.
      • Integrity and Confidentiality: We adopt technical and organizational measures to ensure secure processing, protecting data against unauthorized access, unlawful processing, accidental loss, or destruction.
      • Accountability: We actively take responsibility for data processing, periodically evaluating our security and protection measures and implementing continuous privacy improvements.

    4. Categories of Personal Data Processed

    Yes Mobility Ibiza may collect and process the following categories of personal data, depending on the service requested or contracted:

    4.1. Identification and Contact Data

    • Name and surname
    • National Identity Document (DNI), Foreigner Identification Number (NIE), or Passport
    • Date of birth
    • Nationality
    • Full postal address (street, number, city, postal code, country)
    • Email address
    • Mobile or landline phone number

    4.2. Vehicle Rental Data

    • Driver’s license number and type
    • Issuance and expiration date of the license
    • License seniority and category
    • History of previous reservations and contracts
    • Category and model of the rented vehicle
    • Pick-up and return date and time
    • Additional services requested (premium helmets, phone holders, special deliveries, etc.)

    4.3. Payment Data

    • Transaction-related data generated during payment (operation result)
    • Token generated by Redsys (secure payment gateway) for future recurring transactions (full card details are never stored)

    4.4. Data Derived from Service Use

    • Information on mileage traveled
    • Incidents or accidents during the rental
    • Vehicle location and geolocation via integrated GPS devices for security, fraud prevention, and roadside assistance purposes
    • Information related to fines or traffic sanctions, if applicable

    4.5. Data from Booked Activities and Tourism Services

    • Booked tourist activities (excursions, tickets, transportation, complementary activities)
    • Confirmations, reservation numbers, or tickets sent by email
    • Preferences or special requests communicated to the service provider

    4.6. Preferences and Marketing Data (with explicit prior consent)

    • Interests and preferences related to products or services
    • Explicit consent for sending newsletters, promotions, and commercial communications

    4.7. Technical and Browsing Data

    • Technical information from website use (IP address, browser, operating system, access time, language, etc.)
    • Technical cookies necessary for navigation and basic website functionality
    • Analytical (Google Analytics 4) and advertising (Meta/Facebook Pixel, in the future) cookies, activated only with explicit user consent

    5. Sources of Personal Data

    The personal data processed by Yes Mobility Ibiza comes from various sources, depending on the contracted service or interaction with our company:

    5.1. Data Provided Directly by the User

    • Through online reservation and booking forms on our website (yesmobilityibiza.com).
    • Via telephone reservations or inquiries.
    • During in-person management at our offices at Carrer Ramon Muntaner, 45, Ibiza.
    • Through email (info@yesmobilityibiza.com) when the user contacts us directly.
    • When booking additional tourist activities intermediated by Yes Mobility Ibiza.

    5.2. Data Generated Automatically During Service Provision

    • Data related to the use of the rented vehicle (mileage, GPS location, incident or accident data, fines, or sanctions).
    • Technical data from website use, such as technical, analytical, or advertising cookies (the latter only with explicit consent).

    5.3. Data Provided by Third Parties (External Providers or Collaborators)

    • For intermediated tourist activities, providers may provide information about booking confirmations or service-related incidents.
    • Banking or financial entities providing information on payments or transactions made through the virtual POS (Redsys).
      (Note: We do not receive or store full card details, only transaction results or tokens for recurring payments).

    Yes Mobility Ibiza only collects third-party data when there is a valid legal basis, particularly the execution of a contract requested by the data subject.

    6. Purposes of Processing and Legal Bases

    Yes Mobility Ibiza processes your personal data for specific, previously informed purposes, based on the legal grounds established in the GDPR and current Spanish legislation. Below are the purposes and their corresponding legal bases:

    Purpose of Processing

    Legal Basis (Art. 6 GDPR)

    6.1. Management of vehicle reservations and rentals

    Execution of the contract requested by the data subject.

    6.2. Management and processing of online payments via virtual POS (Redsys), including secure storage of tokens for recurring payments

    Execution of the contract and compliance with legal obligations related to payment security (PSD2, banking regulations).

    6.3. Sale and intermediation of tourist activities and complementary services offered by third parties

    Execution of the contract requested by the data subject.

    6.4. Vehicle geolocation via integrated GPS devices for security, fraud prevention, and technical or roadside assistance

    Legitimate interest in the security and protection of rented vehicles and service quality.

    6.5. Customer service, management of incidents, complaints, and inquiries related to rentals and tourist activities

    Legitimate interest in ensuring proper service and after-sales support, as well as compliance with consumer legal obligations.

    6.6. Sending commercial communications, promotions, or newsletters about rental and activity services, with prior explicit consent

    Explicit consent granted by the data subject through specific forms or checkboxes.

    6.7. Statistical analysis and evaluation of website usage, continuous service improvement via analytical tools (Google Analytics 4) and advertising tools (Meta Pixel)

    Explicit consent granted by the data subject through the cookie management banner.

    6.8. Compliance with legal and tax obligations arising from our activity (accounting, invoicing, taxation, official requirements)

    Compliance with legal obligations applicable to Yes Mobility Ibiza’s activities.

    If Yes Mobility Ibiza intends to process your personal data for a purpose other than those listed above, we will inform you in advance and request your explicit consent when required by applicable regulations.

    7. Data Retention Periods

    Yes Mobility Ibiza will retain your personal data for the time strictly necessary to fulfill the purposes for which they were collected and, in any case, for the specific periods required by applicable regulations or until you request their deletion, provided no legal obligations prevent it.

    Below are the indicative retention periods based on the purpose of processing:

     

    Purpose of Processing

    Retention Period

    Management of reservations and vehicle rentals

    During the contractual relationship and for 6 additional years to address accounting, tax, or civil liabilities arising from the contract.

    Online payment data and card tokens (Redsys POS)

    Immediate payment data: only during the transaction. Tokens for recurring payments: up to 15 months from the last transaction.

    Sale and intermediation of tourist activities

    Until the contracted service ends and for 6 additional years for potential legal liabilities arising from the intermediated service.

    Geolocation and GPS data of rented vehicles

    During the rental and up to 30 days after the vehicle’s effective return, unless specific incidents or legal requirements justify longer retention.

    Customer service, inquiries, complaints, and incidents

    Until the inquiry or complaint is fully resolved and for 3 additional years for potential legal liabilities.

    Sending commercial communications (marketing/newsletters)

    Until you withdraw your consent or exercise your right to object or delete.

    Website usage analysis (analytical/advertising cookies)

    Anonymous statistical data retained for 24 months from the last interaction (per Google Analytics 4 standard settings), unless consent is withdrawn earlier.

    Compliance with tax, accounting, and legal obligations

    As provided by applicable regulations: generally 6 years for commercial, accounting, and tax documentation; up to 10 years in specific cases required by Spanish tax legislation.

    After these retention periods, Yes Mobility Ibiza will delete or appropriately anonymize personal data, adopting necessary security measures to ensure their confidential destruction.

    8. Recipients and Data Processors

    In compliance with the GDPR and current Spanish regulations, Yes Mobility Ibiza informs you that your personal data may be shared or communicated, when necessary and under strict confidentiality conditions, with the following categories of recipients and data processors:

    8.1. Payment Service Providers

    • Redsys Servicios de Procesamiento, S.L. (Virtual POS):
      • Purpose: Secure processing of online payments, generation, and storage of tokens for future recurring payments.
      • Location: European Union.

    8.2. Hosting and Web Service Providers (Managed by Gecko Studio)

    • Hosting Provider (pending details)
      • Purpose: Hosting of the website and data related to the operation of yesmobilityibiza.com.
      • Location: Pending details.
    • Content Delivery Network (CDN) (pending details)
      • Purpose: Website optimization and security.
      • Location: Pending details.

    8.3. Web Analytics and Advertising Tools (Subject to Explicit Consent)

    • Google Ireland Limited (Google Analytics 4):
      • Purpose: Statistical analysis of website usage.
      • Location: European Union (European servers).
    • Meta Platforms Ireland Ltd. (Facebook Pixel):
      • Purpose: Measurement and optimization of future advertising campaigns.
      • Location: European Union (European servers).

    8.4. Management and Digital Signature Service Providers (Future Implementation)

    • Carplus (reservation, fleet, and digital signature management software):
      • Purpose: Comprehensive management of contracts, reservations, and digital signatures.
      • Location: European Union (Spain).

    8.5. Insurance Companies and Roadside Assistance

    • Yes Mobility (for specific claims requiring insurance management):
      • Purpose: Management and resolution of accident or claim reports, if insurance activation is required.
      • Location: European Union (Spain).
    • External Roadside Assistance or Towing Companies (contracted as needed):
      • Purpose: Technical and roadside assistance services for breakdowns or specific incidents.
      • Location: European Union (mainly Spain).

    8.6. External Providers of Intermediated Tourist Activities

    • Specific providers of activities and complementary services (e.g., maritime transport like Trasmapi, excursions, boat rentals):
      • Purpose: Management and confirmation of intermediated reservations; limited communication of strictly necessary customer data (name and contact details).
      • Location: European Union (mainly Spain).

    8.7. Competent Public Authorities

    • Public administrations, tax, or judicial authorities (if legally required):
      • Purpose: Compliance with legal obligations or response to official requests (e.g., Tax Agency, Local Police, Guardia Civil for traffic violations or vehicle-related crimes).

    Yes Mobility Ibiza ensures that all external providers or data processors comply with strict security, privacy, and confidentiality guarantees, in accordance with applicable regulations. Your personal data will not be transferred outside the European Economic Area without adequate safeguards or legal mechanisms ensuring an equivalent level of protection.

    9. International Data Transfers

    Yes Mobility Ibiza informs you that, in general, your personal data will be processed and stored exclusively within the European Economic Area (EEA), ensuring full application of the safeguards provided by the GDPR and current Spanish regulations (Organic Law 3/2018).

    However, if international data transfers outside the EEA are required in the future due to operational needs or the use of certain technological services (e.g., digital marketing tools, hosting providers, or content delivery networks), Yes Mobility Ibiza commits to:

    • Ensuring that such transfers are made only to countries recognized by the European Commission as adequate or with equivalent safeguards (e.g., the United States under the EU-U.S. Data Privacy Framework for specific digital services).
    • Implementing legal mechanisms such as Standard Contractual Clauses (SCCs) approved by the European Commission or other legally valid mechanisms to ensure an adequate level of data protection.

    In such cases, Yes Mobility Ibiza will provide clear and transparent prior information about any international transfers, detailing the legal mechanisms applied to ensure the security and privacy of your personal data.

    Currently, no international transfers outside the EEA are performed. If this changes in the future due to the incorporation of new services or technological providers, you will be duly informed through an updated version of this Privacy Policy.

    10. Data Subject Rights

    In accordance with current data protection regulations (Regulation EU 2016/679 GDPR and Organic Law 3/2018), as a data subject, you have the right to exercise the following rights free of charge:

    10.1. Right of Access
    You can request information about what personal data we process, the purpose of processing, and the recipients to whom the data has been or will be disclosed.

    10.2. Right to Rectification
    You have the right to request the correction of inaccurate or incomplete personal data.

    10.3. Right to Erasure (“Right to be Forgotten”)
    You can request the deletion of your personal data when it is no longer necessary for the purpose for which it was collected or if you withdraw your consent, among other reasons provided by law.

    10.4. Right to Restriction of Processing
    You have the right to request the restriction of data processing under certain circumstances, such as during the verification of data accuracy or the lawfulness of processing.

    10.5. Right to Data Portability
    You can request to receive the personal data provided to Yes Mobility Ibiza in a structured, commonly used, and machine-readable format, or request that we transmit it directly to another controller when technically feasible.

    10.6. Right to Object
    You can object, at any time, to the processing of your data for reasons related to your particular situation, especially in cases of direct marketing or when processing is based on our legitimate interest.

    10.7. Right Not to Be Subject to Automated Decision-Making
    You have the right not to be subject to decisions based solely on automated processing that produce significant legal effects or similarly affect you, except as legally permitted.

    How to Exercise Your Rights
    To exercise any of the above rights, you can submit a written request to:

    Your request must clearly indicate the right you wish to exercise and include a copy of your identification document (DNI, NIE, or Passport). We will respond to your request within a maximum of one month from receipt, which may be extended by two additional months for complex requests or high volumes, with prior notification.

    Right to Lodge a Complaint
    If you believe your data protection rights have been violated, you can file a complaint with the competent supervisory authority in Spain:

      • Spanish Data Protection Agency (AEPD)
      • Address: C/ Jorge Juan, 6, 28001-Madrid, Spain
      • Website: aepd.es

      11. Information Security

      Yes Mobility Ibiza adopts and maintains appropriate technical and organizational measures to protect your personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. The implemented security measures align with international standards and fully comply with the requirements of current regulations (GDPR and Organic Law 3/2018).

      Key security measures include:

      11.1. Technical Security

      • Encryption and Secure Communications:
        • Mandatory use of HTTPS protocol with TLS 1.2 or higher for all electronic communications and the website (yesmobilityibiza.com).
        • Secure online payment gateway via Redsys virtual POS, with 3-D Secure v2 enhanced authentication.
      • Access Protection:
        • User and password-based access control systems.
        • Restricted internal access to personal data, limited to authorized personnel only.
        • Access logs and periodic audits.
      • Protection of Sensitive and Payment Data:
        • Secure storage through tokenization systems managed exclusively by the Redsys payment platform (full card numbers are not stored).
      • Geolocation and GPS Data:
        • Exclusive use of GPS systems for security and fraud prevention.
        • GPS data access limited to authorized personnel and retained only for the necessary period (up to 30 days after vehicle return).

      11.2. Organizational Security

      • Continuous training of responsible staff on personal data protection and privacy.
      • Clear internal procedures for managing data-related incidents and established protocols for responding to potential security breaches.
      • Specific policy for periodic backups to ensure data recovery and availability in case of loss or technical incidents.

      11.3. Periodic Evaluations and Proactive Accountability

      • Continuous review and updating of security measures, regularly adapting them to current technical and legal requirements.
      • Ongoing commitment to continuous improvement in security and privacy matters.

      Yes Mobility Ibiza is firmly committed to information and personal data security, implementing all necessary measures to ensure secure, confidential, and legally compliant processing.

      12. Geolocation and GPS Devices

      Yes Mobility Ibiza clearly informs all customers that, for security, fraud prevention, asset protection, and roadside assistance purposes, rented vehicles are equipped with electronic geolocation (GPS) devices.

      The processing of data derived from the geolocation system will be carried out under the following specific terms:

      12.1. Purpose of GPS Processing

      • Vehicle location in case of accidents, theft, or technical incidents during the rental period.
      • Prevention and detection of fraud, theft, or misuse of the vehicle.
      • Efficient management of roadside assistance, providing immediate solutions for incidents.
      • Verification of compliance with the General Rental Conditions, particularly regarding the authorized territorial scope (limited to the island of Ibiza) and permitted road types (only paved roads).

      12.2. GPS Data Retention Period

      • Geolocation data is stored only for the strictly necessary period, specifically during the vehicle rental and up to 30 days after its effective return.
      • In case of specific incidents or legal requirements, the retention period may be extended, always in compliance with applicable legislation.

      12.3. Authorized Access to Data

      • Access to geolocation data is restricted exclusively to authorized Yes Mobility Ibiza personnel.
      • These data will be managed with strict confidentiality and security, fully respecting current data protection regulations.

      12.4. Customer Information and Implied Consent

      • By signing the rental contract with Yes Mobility Ibiza, the customer is clearly informed about the presence and purpose of the GPS system, accepting its installation and use during the rental period.
      • Tampering, disabling, or attempting to interfere with these devices by the customer will be considered a serious breach of contractual conditions, potentially leading to immediate cancellation of the contracted insurance and additional financial penalties.

      Yes Mobility Ibiza commits to using the geolocation system only for the specific purposes informed, always ensuring maximum respect for customer privacy.

      13. Minors and Persons with Limited Legal Capacity

      Yes Mobility Ibiza does not target its services to minors or persons with legally limited capacity to contract. Therefore:

      13.1. Minimum Age and Capacity Requirements for Contracting

      • To rent vehicles, book activities, or make payments through yesmobilityibiza.com, you must be at least 18 years old and have full legal capacity to contract on your own behalf.
      • The company reserves the right to request, at any time, documentation verifying the applicant’s age and legal capacity.

      13.2. Special Cases – Legal Representative Authorization

      • If a reservation or contract is made on behalf of a minor or a person with judicially modified capacity, the express and documented consent of the parent, guardian, or authorized representative is required, who will assume direct responsibility for the contract and its legal consequences.

      13.3. Exclusion of Liability

      • Yes Mobility Ibiza is not responsible for the fraudulent or unauthorized use of its services by minors or legally incapacitated persons when it has not been possible to verify their identity or capacity prior to contracting, provided reasonable measures to prevent this have been applied.

      13.4. Automatic Rejection of Contracting

      • We reserve the right to reject any contract request if there are indications of a lack of legal capacity or if the required documentation for verification is not provided.

      14. Automated Decision-Making or Profiling Processes

      Yes Mobility Ibiza does not apply automated decisions with legal effects on users based solely on the automated processing of personal data, as described in Article 22 of the GDPR.

      14.1. Absence of Automated Decisions with Legal Effects

      • Vehicle rentals, intermediation of tourist activities, tariff setting, and contractual risk analysis are conducted through human-supervised processes, without exclusive intervention of automated systems.

      14.2. No Automated Personalized Commercial Profiling

      • Yes Mobility Ibiza does not create user profiles for commercial or advertising purposes without the explicit consent of the data subject.
      • If automated analysis tools are introduced in the future (e.g., segmentation based on browsing habits for personalized offers), these will be subject to prior and explicit user consent, in accordance with the GDPR and LOPDGDD.

      14.3. Anti-Fraud Alerts Activation (Redsys POS)

      • For online payments, the Redsys payment gateway may activate automated transaction validation mechanisms (as part of 3-D Secure 2.0 banking security measures). These decisions are executed within Redsys systems, in accordance with their privacy policy and under the supervision of payment service regulations (PSD2).

      15. Cookie Management

      15.1. Consent Management

      • Upon first accessing the website, a cookie banner will be displayed, allowing the user to:
        • Accept all cookies.
        • Reject all optional cookies.
        • Configure preferences by cookie type.
      • Non-essential cookies (analytical and marketing) are only activated with the user’s explicit consent.
      • Consent can be modified at any time via the cookie settings panel available at the bottom of the website (“Cookie Settings”).

      15.2. Cookie Withdrawal and Deletion

      • Users can configure their browser to reject or delete all cookies, including technical ones. However, disabling these may negatively affect website functionality.
      • Learn how to manage cookies in common browsers:
        • Google Chrome: support.google.com
        • Mozilla Firefox: mozilla.org
        • Safari: apple.com
        • Microsoft Edge: microsoft.com

      15.3. More Information

      • Details of the cookies used can be found in the specific “Cookie Policy” document, permanently available in the website footer.

      16. Changes to the Privacy Policy

      Yes Mobility Ibiza reserves the right to modify or update this Privacy Policy at any time to adapt to legislative, jurisprudential, or Spanish Data Protection Agency criteria changes, technological developments, or modifications in service provision.

      16.1. Notification of Changes

      • Any significant changes will be communicated through our website (yesmobilityibiza.com), updating the last revision date at the document’s start.
      • If changes significantly affect user rights or freedoms (e.g., new purposes or data transfers), the explicit consent of the affected user will be required.

      16.2. Policy Validity

      • This Privacy Policy will be permanently accessible on the Yes Mobility Ibiza website.
      • It will be effective from the date indicated and applicable to all users accessing or using our services after its publication.

      Date of Last Update: April 30, 2025.

      17. Supervisory Authority

      If you believe Yes Mobility Ibiza has not processed your personal data in accordance with current regulations or are dissatisfied with the response received after exercising your rights, you can file a complaint with the competent national supervisory authority:

      • Spanish Data Protection Agency (AEPD)
      • Address: C/ Jorge Juan, 6, 28001, Madrid, Spain
      • Phone: 901 100 099 / 912 663 517
      • Website: aepd.es
      • Online Complaints Channel: AEPD Electronic Headquarters

      Yes Mobility Ibiza recommends contacting us first to attempt an amicable resolution of any discrepancies related to your data protection rights before filing a formal complaint.

      18. Contact for Exercising Rights

      To exercise your rights of access, rectification, erasure, objection, restriction of processing, or data portability, or to resolve any doubts related to this Privacy Policy, you can contact Yes Mobility Ibiza through the following channels:

      Requirements for Processing Your Request

      • Clearly indicate the right you wish to exercise.
      • Attach a legible copy of your official identification document (DNI, NIE, or Passport).
      • If acting on behalf of another person, provide a signed authorization and a copy of the data subject’s identification document.

      Response Time

      • Yes Mobility Ibiza will respond to all requests within a maximum of 1 month from receipt. This period may be extended by 2 additional months for particularly complex requests, with prior notification to the data subject.