1) Controller & Scope

Zero Expeditions S.L. (CIF B22943369) is the data controller for personal data processed through this website and our services.

Registered address: Calle Luigi Pirandello 13, 28830 San Fernando de Henares, Madrid, Spain
Contact for privacy matters: info@zeroexpeditions.com

Travel Agency License: CICMA 4861 (Comunidad de Madrid)

This Policy follows:

  • Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)
  • Spanish Organic Law 3/2018 on the Protection of Personal Data and Digital Rights (LOPDGDD)
  • Spanish Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE)

2) Purposes of Processing

We process personal data to:

  • Manage travel and activity services you contract with us (bookings, payments, trip operations).
  • Respond to enquiries sent via forms, email, or other channels.
  • Send commercial communications (email, newsletters, social media, messaging apps) about Zero Expeditions’ services or curated partner content—never selling your data to third parties.
  • Conduct analytics and service improvement (aggregated statistics, usability).
  • Create and manage optional messaging groups (e.g., WhatsApp) for trip coordination, with your prior consent.

3) Lawful Bases

Depending on the purpose, processing is based on:

  • Performance of a contract (trip booking and delivery).
  • Consent (newsletters, inclusion in messaging groups, certain marketing).
  • Legitimate interests (service quality, basic analytics, security), always balanced against your rights.

4) Data We Collect

Identification and contact data (name, email, phone), travel preferences, billing and tax data (DNI/NIF/CIF or equivalent), postal address, and payment information (tokenised or via secure gateway—Zero Expeditions does not store full card details). Data collected are limited to what is necessary for each purpose. Fields marked with (*) on forms are mandatory; without them, we may be unable to provide the requested service.

5) Retention

We keep data for as long as the commercial relationship remains active or there is a mutual interest. Afterwards, data are securely deleted or anonymised, subject to statutory limitation/retention periods (e.g., tax/accounting).

6) Recipients & International Transfers

  • We do not share personal data with third parties except where required by law or to service providers (processors) acting under our instructions (e.g., hosting, email, payment gateways, analytics) under GDPR-compliant contracts.
  • International transfers, if any (e.g., cloud services outside the EEA), will rely on an adequacy decision, standard contractual clauses, or other GDPR safeguards.

7) Rights of Data Subjects

You may at any time:

  • Access, rectify, or erase your data.
  • Restrict or object to processing.
  • Request portability of your data.
  • Withdraw consent without affecting prior lawful processing.
  • Lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es if you believe your rights have been infringed.

How to exercise: write to Zero Expeditions S.L., Calle Luigi Pirandello 13, 28830 San Fernando de Henares, Madrid, Spain or email info@zeroexpeditions.com with the subject “Data Protection – Request”. We may ask for proof of identity to protect your data.

8) Security Measures

We apply appropriate technical and organisational measures (SSL/TLS, access controls, encryption where appropriate, least-privilege policies) to prevent unauthorised access, alteration, loss, or disclosure of personal data, consistent with Article 32 GDPR. Processing is lawful, fair, transparent, and data-minimised.

9) Newsletter

By subscribing, you consent to receive content about trips, activities and updates from Zero Expeditions. You can unsubscribe at any time via the link in each email or by contacting us at info@zeroexpeditions.com. Retention continues until you unsubscribe.

10) Messaging Groups (e.g., WhatsApp)

With your prior consent, we may add you to a group created to coordinate a specific trip:

  • Your name and phone number may be visible to other members.
  • Use of member data for any purpose other than coordination is prohibited.
  • You may leave the group at any time or request removal by messaging the admin.
  • Upon leaving or being removed, please delete chat history unless you have a legal need to retain it.

11) Policy Updates

We may update this Policy to reflect changes in law or our processing. Please review periodically.
Last updated: 28 September 2025.