Website Privacy Policy
We are concerned about the personal data we process and about the exact compliance with the regulations currently in force regarding the protection of personal data, including, among others, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC, and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights. Accordingly, the following matters relating to the processing of personal data we carry out are hereby reported:
1. Data Controller
- Owner: Tulchin AIE
- Tax ID (CIF): V88047758
- Address: C/ Ilustración, 7. 12560 Benicàssim, Castelló
- Email: hola@tulchinevents.com
Hereinafter, it will be identified as the data controller of the website.
2. Principles Relating to Processing
When processing personal data, we follow the principles established by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (hereinafter, the General Data Protection Regulation or GDPR):
-Principle of lawfulness, fairness and transparency: the data we collect is processed lawfully, fairly and transparently, with the prior consent of the data subjects where necessary or, where applicable, for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract, or where the processing is necessary for compliance with a legal obligation applicable to the controller or for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
-Principle of purpose limitation: the personal data we process is used for the purposes indicated in the section “Purpose of Processing”.
-Principle of data minimisation: in accordance with this principle, the only personal data we collect from users is that which is strictly necessary to manage and process the taxi booking requests they make and to provide the requested public passenger transport service. Personal data marked with an asterisk is necessary for the indicated purpose and must therefore be provided; otherwise, we will not be able to process the request.
-Principle of accuracy: the personal data we collect will be kept accurate and, where necessary, up to date. To this end, should any personal data change, the user must inform us so that we can make the corresponding update.
-Principle of storage limitation: the personal data we process will be kept for the periods indicated in the section “Retention Period”.
-Principle of integrity and confidentiality: in order to comply with this principle, personal data will be processed in such a way as to ensure appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, by applying appropriate technical and organisational measures.
3. Categories of Personal Data
The categories of data we process through the website are:
-Personal data collected through the booking form: name; email address; telephone number; data related to the requested transport service (number of passengers, origin, destination, date and time); comment or message.
We do not process data that the General Data Protection Regulation classifies as “special categories of data” (health data, biometric data, trade union membership, etc.), nor personal data relating to criminal convictions or offences.
All personal data requested, marked with an asterisk, is necessary to manage and process the taxi booking requests made by users and to provide the requested public passenger transport service, and must therefore be provided; otherwise, we will not be able to process the request.
4. Origin of Personal Data
All personal data we process is provided to us by the data subjects themselves or their legal representatives.
The personal data we collect through this website is collected through the taxi booking form, via the email address provided to contact us or, where applicable, by telephone.
The personal data we request, marked with an asterisk, is the minimum necessary to process and fulfil the corresponding purposes and, therefore, if it is not provided, we will not be able to process them.
5. Purpose of Processing
Users are informed that we will use their personal data to manage and process the taxi booking requests they make and to provide the requested public passenger transport service. We do not process data for the adoption of automated decisions or for profiling.
6. Legal Basis for Processing
The legal basis legitimising the processing of users' personal data is that such processing is necessary to manage booking requests and to perform the contract to which they are parties.
7. Recipients of Personal Data
We do not disclose or transfer personal data internationally, except where necessary for the performance of a contract, the management of bookings or compliance with legal obligations. However, users are informed that bookings are managed through:
- Company: Tulchin AIE
- Tax ID (CIF): V88047758
- Address: C/ Ilustración, 7. 12560 Benicàssim, Castelló
- Email: hola@tulchinevents.com
For this purpose, when users complete the form provided for bookings, their personal data is received directly by this Association, which acts as the data processor, having signed the corresponding data processing agreement with it in accordance with the provisions of Article 28.3 of the General Data Protection Regulation.
8. Retention Period
We will retain users' personal data throughout the management and processing of taxi booking requests, until the service has been completed and, subsequently, for the periods necessary to comply with legal obligations.
9. Users' Rights
-Right to request access to their personal data: in order to know and verify the lawfulness of the processing, users may request at any time confirmation as to whether the data controller is processing their personal data and, if so, we will inform them, among other matters, about what data we are processing, its purpose, the origin of the data, the expected retention period of the data and, where applicable, the recipients or categories of recipients.
-Right to request rectification: users may request the rectification of personal data that is inaccurate or the completion of incomplete data, including by means of providing an additional statement. In such cases, they must indicate in their request which data they are referring to and the correction to be made and, where applicable, provide supporting documentation proving the inaccuracy or incomplete nature of the data being processed.
-Right to request erasure (“right to be forgotten”): users may request that their personal data be erased and no longer processed if it is no longer necessary for the purposes for which it was collected or otherwise processed, if they withdraw their consent, if it has been unlawfully processed or if it must be erased in order to comply with a legal obligation.
-Right to request restriction of the processing of personal data: in this case, the data controller will only retain users' personal data for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest.
-Right to data portability: users may request that their personal data be provided to them, or to another controller designated by them, in a structured, commonly used and machine-readable format.
-Right to object to processing: The data controller will cease processing personal data in the manner indicated by users, unless it is required to continue processing it for compelling legitimate reasons or for the establishment, exercise or defence of potential claims.
To exercise these rights: Send a request to the data controller at the postal address or email address indicated at the beginning of this document. The data controller will respond to all requests within the time limits and under the conditions required by the regulations currently in force regarding the protection of personal data.
10. Complaints to the Supervisory Authority
If users consider that we have not processed their personal data appropriately or that we have not properly addressed the exercise of their data protection rights, they may lodge a complaint with the Spanish Data Protection Agency, either through its electronic office or at its registered address at Calle Jorge Juan, No. 6, 28001 Madrid.
More information about data protection rights and complaints to the Supervisory Authority can be found at www.aepd.es.
11. Security Measures
In accordance with the provisions of Article 32 of the General Data Protection Regulation, the data controller has adopted appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
In order to assess the adequacy of the level of security, particular account has been taken of the risks presented by the processing of data, in particular as a result of the accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, or the unauthorised disclosure of or access to such data.
12. Duty of Confidentiality
The data controller has adopted measures to ensure that any person acting under its respective authority and having access to the personal data provided by users may only process it following the instructions of the data controller and must also maintain the corresponding professional secrecy regarding such data, which shall remain in force indefinitely.
13. Use of the Website by Minors
We recommend consulting the corresponding section in the Legal Notice of our website.
14. Cookie Policy
Cookies are small text files stored on the device used to access or visit certain websites, allowing the user's preferences to be known when they reconnect. Cookies stored on the user's device cannot read the data contained therein, access personal information or read cookies created by other providers. See information about the cookies used on this website in the cookie policy section.
Text dated: 20 March 2026