Privacy policy
Last updated: 15 September 2026
This is a courtesy translation. The binding version of this policy is the Spanish one, available at borrou.es/privacidad. In the event of any discrepancy, the Spanish text prevails.
1. Data controller
The controller of the personal data collected through borrou.es is Alejandro Carvajal Martínez, resident in Santa Cruz de Tenerife (Spain). Contact address for data protection matters: info@borrou.es, through which the controller’s remaining identifying details may be requested.
This policy has been drawn up in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
2. Data we process and where it comes from
We process only the data that the user provides themselves and the data generated by use of the service:
3. Purposes and legal bases
4. Retention periods
Data is kept for as long as is strictly necessary for each purpose and, thereafter, blocked and available to the competent authorities for the applicable limitation periods:
5. Recipients and processors
Personal data is neither sold nor transferred to third parties for advertising purposes. It is disclosed only to the providers needed to deliver the service, which act as processors and are bound by contract under article 28 GDPR:
In addition, certain data is shown publicly by the very nature of the service: the name, profile photo, length of time on the Platform, the verified-identity badge and the reviews received are visible on the public profile. No other data is accessible to other users.
6. International data transfers
Some of the providers listed are based in the United States. In such cases transfers are covered by the Standard Contractual Clauses approved by the European Commission and, where applicable, by the adequacy Decision on the EU-US Data Privacy Framework, together with any supplementary measures required. Further information about those safeguards may be requested by writing to info@borrou.es.
7. Automated decisions
The identity verification process is carried out automatically by the relevant provider and its result determines whether a booking can be completed. A user whose verification is refused may request human intervention, express their point of view and contest the decision by writing to info@borrou.es. No other automated decisions with legal effects are made, and no profiling is carried out.
8. Rights of data subjects
You may exercise at any time the rights of access, rectification, erasure, objection, restriction of processing and portability, as well as withdraw any consent given, by writing to info@borrou.es stating the right you wish to exercise. The request will be dealt with within a maximum of one month, extendable under article 12.3 GDPR.
Many of these rights can be exercised directly from the application: profile data can be changed at any time and the account can be deleted from the profile editing section.
If you consider that the processing does not comply with the regulations, you may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid - www.aepd.es).
9. Cookies and similar technologies
The Platform uses only technical cookies necessary to keep the session open and to ensure safe browsing, which are exempt from the consent requirement under article 22.2 of Law 34/2002.
The usage analytics used are aggregated and use neither cookies nor persistent identifiers, so they do not allow individual users to be recognised. No advertising or third-party profiling cookies are used. Should any be added in future, prior consent would be requested through the appropriate mechanism.
10. Security measures
Technical and organisational measures appropriate to the risk are applied, in accordance with article 32 GDPR, including:
- Encryption of communications in transit and of stored data.
- Row-level access control in the database, so that each user can access only the information that belongs to them.
- Minimisation: the Platform stores neither full card numbers nor identity documents, which are handled directly by the specialised providers.
- Restricted access to handover and incident photographs, which are served through temporary links and are not publicly accessible.
- Pseudonymisation of the IP addresses used for rate limiting.
- Logging and review of errors and anomalous access.
In the event of a personal data breach entailing a risk to the rights and freedoms of data subjects, the Spanish Data Protection Agency will be notified within 72 hours and, where appropriate, so will the people affected, in accordance with articles 33 and 34 GDPR.
11. Minors
The service is not aimed at minors and its use is reserved to those aged 18 and over. If an account belonging to a minor is detected, it will be deleted immediately.
12. Changes to this policy
This policy may be updated to adapt it to regulatory changes or to how the service evolves. Any change will be published on this page with an indication of its update date and, where it substantially affects the processing, users will be informed beforehand.
13. Contact
For any question about this policy or about the processing of personal data: info@borrou.es. The conditions of use of the service are in the terms and conditions.
