Last updated: May 2026.
The Bodysurf School (“we”, “us”, “our”) is committed to protecting your privacy and handling your personal data transparently and lawfully under the EU General Data Protection Regulation (GDPR) and Portuguese data protection law.
Who We Are
The Bodysurf School operates the website thebodysurfschool.com and provides bodysurf lessons at Praia da Sereia (Costa da Caparica) and Carcavelos.
Data controller: DESCANSO RADICAL – ASSOCIAÇÃO, RUA MARIA MATOS NUMERO, 34 2820-502 CHARNECA DE CAPARICA ALMADA
Tax ID (NIF): 517391473
Contact: info@thebodysurfschool.com
What Data We Collect
We collect only the data we need to provide our service:
- Booking information: Your name, email address, phone number, and any preferences you share when booking a lesson (e.g. experience level, special requests).
- Communication: Messages you send us via WhatsApp, email, or our contact form.
- Newsletter (future): If you sign up for our newsletter, we collect your name and email address to send you updates about lessons, events, and the school.
- Technical data: When you visit our website, we automatically collect anonymised information such as your IP address (truncated), browser type, and pages visited. This is used to improve the site and is not linked to your identity.
We do not collect payment data. All payments are processed by third-party payment providers (see “Who We Share Data With” below). We never see or store your card details.
How We Use Your Data
We use your personal data only for the purposes you would expect:
- To confirm, manage, and deliver your bookings
- To communicate with you about your lessons (confirmations, reminders, changes due to ocean or weather conditions)
- To respond to your enquiries
- To send you newsletters and updates (only if you have explicitly subscribed)
- To improve our website and service
- To comply with legal obligations (e.g. tax records)
We do not use your data for automated decision-making or profiling.
Legal Basis for Processing
Under GDPR, we process your data on the following legal bases:
- Performance of contract: To deliver the lesson you booked.
- Legitimate interest: To respond to your enquiries and improve our service.
- Consent: For marketing communications (newsletter), which you can withdraw at any time.
- Legal obligation: To keep records required by Portuguese tax and consumer protection law.
Who We Share Data With
We never sell your data. We only share it with trusted third parties who help us run our service:
- Payment providers (e.g. Stripe, PayPal, or other gateways we may use): to process your booking payments. These providers handle your card data directly under their own privacy policies.
- Email service providers: to send booking confirmations and (if subscribed) newsletters.
- Website hosting and analytics providers: to keep our website running and to understand how visitors use it.
- Authorities: if required by law (e.g. tax authority, court order).
We do not transfer your data outside the European Economic Area unless adequate safeguards are in place under GDPR.
How Long We Keep Your Data
We keep your data only as long as necessary:
- Booking records: Kept for the period required by Portuguese tax law (typically 10 years for invoicing records).
- Communication and enquiries: Kept for up to 2 years after the last interaction.
- Newsletter subscribers: Kept until you unsubscribe.
- Technical / analytics data: Kept for up to 26 months in anonymised form.
After these periods, your data is securely deleted or anonymised.
Your Rights
Under GDPR, you have the right to:
- Access the personal data we hold about you
- Correct any inaccurate or incomplete data
- Delete your data (the “right to be forgotten”), unless we are required to keep it by law
- Restrict how we process your data
- Port your data to another service provider
- Object to processing based on legitimate interest or marketing
- Withdraw consent at any time for processing based on consent
- Lodge a complaint with the Portuguese data protection authority (CNPD — Comissão Nacional de Proteção de Dados, www.cnpd.pt)
To exercise any of these rights, contact us at info@thebodysurfschool.com. We will respond within one month.
Cookies
Our website uses minimal cookies:
- Essential cookies: Required for the site to function (e.g. session, security).
- Analytics cookies: Anonymised statistics to improve the site (only if you accept them).
You can manage cookie preferences in your browser settings at any time.
Security
We take reasonable technical and organisational measures to protect your data, including encrypted connections (HTTPS), secure hosting, limited access to personal data, and regular software updates. No system is 100% secure, but we work to protect your data as if it were our own.
Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the most recent version. Significant changes will be communicated by email to active customers and newsletter subscribers.
Contact
For any questions about this Privacy Policy or how we handle your data, please contact us:
Email: info@thebodysurfschool.com
WhatsApp: +351 918 321 909
Address: Praia da Sereia, Costa da Caparica, Portugal
