This Privacy Policy describes how we process your personal data when you visit our website (notanothertravelapp.com and related domains), join our waitlist, or use the waltru mobile application (the "App"; together with the website, the "Service"). It is drafted in accordance with Regulation (EU) 2016/679 (the "GDPR"), the Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights ("LOPDGDD"), and Directive 2002/58/EC ("ePrivacy Directive") as implemented in Spain by Law 34/2002 (LSSI-CE).

1. Data Controller

The controller of your personal data is:

We have not appointed a Data Protection Officer because we are not required to do so under Article 37 GDPR. You may nevertheless raise any privacy matter at the address above.

2. Personal Data We Process

We process the following categories of personal data, depending on how you interact with the Service:

We do not knowingly collect special categories of personal data (Article 9 GDPR). Please do not submit health, religious, political or similar data through free-text fields.

3. Purposes and Legal Bases

We process your personal data for the following purposes, each supported by the legal basis set out below:

4. Recipients and Processors

We share your personal data only with the recipients necessary to run the Service, under written data-processing agreements (Article 28 GDPR) that include the EU Standard Contractual Clauses where required. Our current sub-processors are:

We do not sell your personal data, do not share it for cross-context behavioural advertising, and do not use it to train third-party AI models.

We may also disclose data to competent public authorities (police, courts, tax authorities) when legally required, and to professional advisers (lawyers, auditors) under duties of confidentiality, or to an acquirer in the context of a corporate transaction, in which case you will be informed in advance.

5. International Data Transfers

Some of the processors listed above are located in, or may access data from, countries outside the European Economic Area, principally the United States. Where no European Commission adequacy decision applies, transfers are protected by the EU Standard Contractual Clauses (2021/914) together with supplementary technical and organisational measures (encryption in transit and at rest, access controls, contractual limitations on government-access requests). Several US providers we rely on (including Google, Stripe, AWS and Anthropic) are also certified under the EU-US Data Privacy Framework where applicable. You can request a copy of the relevant transfer mechanism by writing to waltru@notanothertravelapp.com.

6. Automated Processing and Profiling

To build your itinerary we combine your Travel DNA, your coarse location and our POI catalogue, and submit them to a large-language-model service (Anthropic Claude). The output is a suggested route that you can edit, reject or ignore. This processing involves profiling within the meaning of Article 4(4) GDPR, but it does not produce legal effects or similarly significant effects on you within the meaning of Article 22(1) GDPR: the App is a travel companion and you remain free to follow, change or abandon the suggestions at any time. You can request human review of a suggestion or challenge it by writing to us.

7. Retention

We keep personal data only as long as necessary for the purposes described in this Policy:

After these periods expire we delete or irreversibly anonymise the data. We may retain data for longer where necessary to establish, exercise or defend legal claims, or where an applicable law requires a longer period.

8. Your Rights

Under the GDPR and the LOPDGDD you have the right to:

To exercise any of these rights, write to us at waltru@notanothertravelapp.com with enough information to identify you. We will reply within one month (Article 12(3) GDPR), extendable by two further months for complex requests. The exercise of these rights is free of charge, save for manifestly unfounded or excessive requests.

You also have the right to lodge a complaint with a supervisory authority, in particular the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es, C/ Jorge Juan 6, 28001 Madrid), or with the supervisory authority of your EU/EEA country of residence or work.

9. Cookies and Similar Technologies

Our website uses strictly-necessary storage and, subject to your consent, analytics cookies from Google Analytics 4 (e.g. _ga, _ga_*) and Microsoft Clarity (e.g. _clck, _clsk, MUID, CLID), plus functional storage (such as remembering your language preference in localStorage). Analytics services load only after you accept through our cookie consent banner, and you can withdraw consent at any time from the "Cookie preferences" link at the bottom of every page. Full details are set out in our Cookie Policy. The mobile App does not use browser cookies but relies on equivalent local-storage mechanisms to keep you signed in and to store your preferences on the device.

10. Security

We apply technical and organisational measures appropriate to the risk (Article 32 GDPR), including HTTPS/TLS in transit, encryption at rest for audio and database storage, role-based access controls, least-privilege credentials, logging and monitoring, periodic backups, and contractual confidentiality obligations for our staff and processors. No system is perfectly secure; if a personal-data breach is likely to result in a risk to your rights, we will notify the AEPD within 72 hours and, where required, inform you directly (Articles 33–34 GDPR).

11. Children

The Service is not directed at children under the age of 14 (the age of digital consent in Spain under Article 7 LOPDGDD) and we do not knowingly collect their data. If you believe a child has provided us with personal data, please contact us and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, new features, or legal requirements. When changes are material we will inform you by email or through an in-App notice at least 30 days before they take effect, and we will update the "Last updated" date above. Continued use of the Service after the effective date of the updated Policy means you have read it; where the change relies on consent we will ask for it again.

13. Contact

For any question or request related to this Policy or your personal data, contact us at waltru@notanothertravelapp.com.