1. Who is responsible for your data
This platform is part of the IN-GENIOS — Duero Douro Industrial Tourism project (code 0247_IN_GENIOS_DUERO_DOURO_2_E), co-funded by the European Union under the Interreg VI-A Spain-Portugal (POCTEP) 2021-2027 programme. The controller of your personal data is the project's coordinating entity, AEICE — Clúster de Hábitat Eficiente, acting on behalf of the project partnership.
Contact for privacy and data-protection matters: info@tourexperience.com2. What data we collect
Account and profile
- Name, email address and password (stored encrypted);
- Profile details you choose to fill in, such as a bio and preferred language;
- Your cookie-consent preference (stored on your device).
Content you create on the platform
- Routes you create or mark as favourites;
- Reviews and comments you post on routes and articles;
- Images and GPX files you upload to your routes.
Contact messages
- When you use the contact, feedback, enrolment or suggestion forms: the name, email and message content you send us.
Technical data
- Minimal technical security logs (for example, authentication logs) needed to operate and protect the service.
We do not collect browsing data for advertising purposes and we do not build behavioural profiles.
3. Why we use your data and on what legal basis
- Providing the service (creating and managing your account, publishing your routes, reviews and comments) — performance of a contract (art. 6(1)(b) GDPR);
- Answering your contact messages — pre-contractual steps and our legitimate interest in replying to those who contact us (arts. 6(1)(b) and 6(1)(f));
- Sending news by email — only with your consent, given in your account and revocable at any time (art. 6(1)(a));
- Moderation and security (reviewing submitted content, preventing abuse and fraud) — legitimate interest in keeping the platform safe (art. 6(1)(f));
- Complying with legal obligations, including accountability requirements of the European funding (art. 6(1)(c)).
4. How long we keep your data
- Account and profile: for as long as the account exists. If you request deletion, data is erased within 30 days at most;
- Published content (routes, reviews, comments): while it remains published, or until you remove it or request deletion of your account;
- Contact messages: up to 24 months after our reply, unless a longer retention period is legally required;
- Technical security logs: up to 12 months.
5. Your rights
Under the GDPR you may at any time exercise your rights of:
- Access — know what data we hold about you and get a copy;
- Rectification — correct inaccurate or incomplete data;
- Erasure — request deletion of your account and associated data;
- Portability — receive the data you provided in a structured, machine-readable format;
- Restriction and objection — restrict or object to processing based on legitimate interest;
- Withdrawing consent — without affecting the lawfulness of prior processing.
To exercise any of these rights, write to info@tourexperience.com. You also have the right to lodge a complaint with a supervisory authority: in Portugal, the CNPD (Comissão Nacional de Proteção de Dados); in Spain, the AEPD (Agencia Española de Protección de Datos).
6. Cookies
This platform only uses strictly essential cookies and local storage:
- Session cookies — keep you securely signed in (authentication);
- Consent record (local key
tidd-consent) — stores on your device the choice you made in the cookie notice.
We use no analytics, advertising or third-party cookies. If audience-measurement tools are ever introduced, they will only be activated after we ask for your prior, specific consent through the cookie notice.
7. Where your data is hosted and who it is shared with
Data is hosted on servers located in the European Union. We do not transfer personal data outside the EU/EEA. Access is limited to the project team and to technical service providers (hosting and email delivery) acting as processors, bound by contract under art. 28 GDPR. We never sell or hand over personal data to third parties.
8. Security
We apply appropriate technical and organisational measures: encrypted connections (HTTPS), encrypted passwords, role-based access control and audit logs of administrative operations.
9. Changes to this policy
This policy may be updated to reflect changes in the platform or in the law. The date of the latest update is shown at the top of the page; significant changes will be announced on the platform.