1. Data controller
Justino David Martins Correia, trading as Titus Boat Tours, tax number (NIF) 221 828 753, Urbanização VerdeMar, Lote 20, 8900-027 Vila Nova de Cacela, Portugal.
For any personal data matter: geral@titusboattours.pt · +351 965 890 566.
Given its size and type of activity, Titus Boat Tours is not required to appoint a Data Protection Officer (article 37 GDPR). Requests are handled directly by the controller at the email above.
This policy complies with the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), Portuguese Law no. 58/2019 of 8 August and, for cookies, Portuguese Law no. 41/2004 of 18 August, as amended.
2. What data we collect
| When | Data |
|---|---|
| Buying Fábrica Beach tickets | Name, email, mobile number, date, number of adults and children, amount, ticket code, payment status and record of the boarding validation |
| Booking a water taxi, boat tour or tailor-made service | Name, email, mobile number, date and time, route or meeting point, number of passengers, any notes you send and, where relevant, the hotel or partner that made the booking |
| Payments | Payment method, amount, date and transaction reference. Full card details are handled only by the payment provider |
| Invoicing | Name and, if you ask for it, tax number and address |
| Contact form, email, WhatsApp, SMS and phone | Name, contact details and the content of your messages |
| Visiting the website | Technical data (IP address, browser type, pages requested) logged by the server, and your cookie choice |
| With your consent | Browsing data collected by the Meta (Facebook) Pixel, described in point 9 |
We do not ask for sensitive data. We only process health or mobility information (for example pregnancy or reduced mobility) if you give it to us voluntarily so we can prepare boarding, with your explicit consent (article 9(2)(a) GDPR). We delete it after the service, unless an incident requires us to keep it.
Your contact and booking details are needed to enter into the contract: without them we cannot accept the booking.
3. Why we use the data and on what legal basis
| Purpose | Legal basis under the GDPR |
|---|---|
| Managing bookings, issuing and sending QR tickets, validating boarding and talking to you about the service | Performance of a contract and pre-contractual steps (article 6(1)(b)) |
| Answering requests for information and quotes | Pre-contractual steps (article 6(1)(b)) |
| Issuing invoices and meeting tax and accounting obligations | Legal obligation (article 6(1)(c)) |
| Meeting maritime safety obligations and answering authorities | Legal obligation (article 6(1)(c)) |
| Handling complaints and defending rights in a dispute | Legal obligation and legitimate interest (article 6(1)(c) and (f)) |
| Keeping the website secure and preventing fraud | Legitimate interest (article 6(1)(f)) |
| Preparing boarding for someone who tells us about a health or mobility condition | Explicit consent (article 9(2)(a)) |
| Measuring visits that come from ads (Meta Pixel) | Consent (article 6(1)(a)), which you can withdraw at any time |
| Sending news or offers, if you have agreed | Consent (article 6(1)(a)) |
We do not sell personal data. We do not take decisions based solely on automated processing that have legal effects on you.
4. Who we share data with
We only share what is necessary, with organisations that process data on our behalf under contract and with data protection safeguards (article 28 GDPR), or that must receive it by law:
- Payment providers: Stripe, MB WAY (through its payment service provider), myPOS and Revolut, to process payments and refunds and prevent fraud. For part of the processing they act as independent controllers.
- Website and email hosting: the provider that hosts the website, database and email.
- WhatsApp Business (WhatsApp Ireland Limited and, for automated messages, Meta Platforms Ireland Limited): to send tickets and talk to you, when you choose this channel.
- SMS delivery: the provider that delivers messages with your ticket or confirmation, when we use this channel.
- Google Ireland Limited: only when you tap "Show map" (Google Maps) or choose a language in the automatic translator (French, German, Italian, Russian or Chinese).
- Meta Platforms Ireland Limited (Facebook Pixel): only if you accept measurement cookies.
- Partners (hotels and agencies): when a booking is made through them, they receive the details of the booking they made.
- GetYourGuide and other platforms: for bookings made on them, the platform is responsible for the data it collects and sends us what we need to provide the service.
- Certified accountant and Portuguese Tax Authority: for invoicing and tax obligations.
- Insurers, maritime authorities, courts and other authorities: when required by law or in the event of an accident or dispute.
5. Transfers outside the European Economic Area
Some providers (for example Meta, Google and Stripe) may process data in the United States. In those cases, the transfer is based on the European Commission adequacy decision for the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795) or on standard contractual clauses approved by the Commission (articles 45 and 46 GDPR).
6. How long we keep the data
| Data | Period |
|---|---|
| Invoices and sales records | 10 calendar years, as required by tax law (article 52 of the Portuguese VAT Code) |
| Contact details and other booking and ticket data | 3 years after the service, to handle complaints and defend rights |
| Messages and contact requests that did not lead to a booking | Up to 24 months |
| Health or mobility information given for boarding | Deleted after the service, unless there is an incident |
| Server technical logs | As long as needed for website security, up to 12 months |
| Consent to receive news | Until you withdraw it |
| Cookies | The periods in point 9 |
At the end of these periods the data is deleted or anonymised.
7. Your rights
At any time and free of charge, you can:
- find out what data we hold about you and get a copy (article 15 GDPR);
- correct wrong or incomplete data (article 16);
- ask for it to be erased when we no longer need to keep it (article 17);
- ask for processing to be restricted (article 18);
- receive the data you gave us in a commonly used format (article 20);
- object to processing based on legitimate interest (article 21);
- withdraw consent, without affecting processing carried out before (article 7(3)).
Just write to geral@titusboattours.pt. We reply within one month (article 12(3) GDPR). We may ask for proof of identity if there is doubt about who is making the request.
You also have the right to lodge a complaint with the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD), at cnpd.pt.
8. Children
Bookings are made by adults (18 or over). For children we only collect the number and age group, for pricing and safety on board. Where processing is based on consent (measurement cookies, news), children under 13 need their parents' permission (article 8 GDPR and article 16 of Portuguese Law no. 58/2019).
9. Cookies and similar technologies
Cookies are small files stored in your browser. We only use those needed for the website to work and, if you accept, measurement cookies.
| Name | Set by | Purpose | Duration | Type |
|---|---|---|---|---|
| tt-consent-v1 (local storage) | Titus Boat Tours | Remember your cookie choice | Until you clear it in your browser | Necessary |
| Session cookie on booking pages | Titus Boat Tours | Keep your booking details while you buy | Until you close the browser | Necessary |
| Payment provider cookies (for example __stripe_mid and __stripe_sid) | Stripe | Prevent payment fraud | Up to 1 year | Necessary, only on payment pages |
| googtrans | Remember the language chosen in the automatic translator | Until you close the browser | Functional, only if you use the translator | |
| Google Maps cookies | Show the map | Set by Google | Only if you tap "Show map" | |
| _fbp | Meta (Facebook) | Measure visits that come from ads | 90 days | Measurement, only if you tap "Accept" |
How to manage them: on your first visit you choose "Accept" or "Reject". You can change your mind at any time with the Cookies link in the website footer, or delete cookies in your browser settings. If you reject, the website still works.
10. Security
We use technical and organisational measures appropriate to the risk: encrypted connection (HTTPS), password-only access to management and ticket validation areas, backups and providers that guarantee data protection. If there is a personal data breach that puts you at risk, we notify the CNPD within 72 hours and, when the risk is high, we also inform you (articles 33 and 34 GDPR).
11. Changes to this policy
We may update this policy when the law or our services change. The date of the last update is at the end of this page. If the change is significant, we will say so on the website.