Legal notice, privacy & cookies.
1. Legal notice
In line with Spanish Law 34/2002 on information society services (LSSI-CE):
- Owner of the website
- Nicolás Maldonado, trading as “300sun”
- Location
- Valencia, Spain
- 300sunvalencia@gmail.com
- Phone / WhatsApp
- +34 615 85 80 17
- Website
- 300sun.com
300sun offers private city walks in Valencia and arranges paella workshops and group accommodation with local partners. The texts and photographs on this site belong to 300sun or are used with permission. Please don’t reuse them without asking. We’re not responsible for the content of external websites we link to.
2. Privacy policy
We collect as little as we can, only to arrange what you asked for, and we never sell it or use it for advertising profiles. This policy follows the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and the Spanish data protection law (LOPDGDD, Organic Law 3/2018).
Who is responsible for your data
Nicolás Maldonado (300sun), contact details above. Write to 300sunvalencia@gmail.com for anything related to your data.
What we collect, why, and on what legal basis
| When | Data | Why | Legal basis |
|---|---|---|---|
| You book a walk | Name, email, WhatsApp number, number of people, and optionally your ship and all-aboard time, how you found us, and notes | To confirm and run your walk and to contact you about it | Taking steps at your request before a contract, and performing it (Art. 6(1)(b) GDPR) |
| You message us (WhatsApp form, WhatsApp, email) | What you write, your name and number or email | To answer you and prepare a quote | Pre-contractual steps (Art. 6(1)(b)) or our legitimate interest in answering questions (Art. 6(1)(f)) |
| You visit the site | IP address, browser and technical request data in server logs | To deliver the pages and protect the site from abuse | Legitimate interest in running a secure website (Art. 6(1)(f)) |
The contact form on this site doesn’t store anything. It opens WhatsApp with your message already written, and nothing is sent until you press send in WhatsApp.
Who else processes it
We use a few service providers. They process data only to provide their service to us:
- Cal.com, Inc. (USA): booking calendar and confirmation emails
- Vercel Inc. (USA): website hosting
- Google (Google Ireland Ltd / Google LLC): email and calendar
- Microsoft (Microsoft Ireland / Microsoft Corp.): calendar sync to avoid double bookings
- WhatsApp Ireland Ltd (Meta): only if you choose to contact us on WhatsApp, under WhatsApp’s own terms
- Porkbun LLC (USA): domain and email forwarding
We don’t give your data to anyone else, unless the law requires it (for example the tax authority).
Transfers outside the EU
Some of these providers are based in the USA. Transfers rely on the EU–US Data Privacy Framework where the provider is certified, or on the European Commission’s Standard Contractual Clauses (Art. 45 and 46 GDPR).
How long we keep it
Booking and message data is kept while we’re arranging your walk and for up to 12 months afterwards, in case you have questions or come back. After that it’s deleted, unless we need to keep a record for tax or legal reasons, and then only for as long as the law requires. Server logs are kept by the hosting provider for a short period, usually days.
Your rights
You can ask to see, correct or delete your data, to restrict or object to its use, and to receive it in a portable format. Just email us. We answer within one month. If you think we haven’t handled your data properly, you can complain to the Spanish Data Protection Agency (aepd.es).
Other things you should know
- We don’t make automated decisions or build profiles about you.
- If you’re under 14, a parent or guardian needs to book for you.
- Your name, email, WhatsApp number and group size are needed to book. The other fields are optional.
3. Cookies
This website doesn’t set any cookies and uses no analytics, advertising pixels or tracking. Fonts and images are served from our own site, not from Google or other third parties.
The booking calendar only loads when you click See available days. At that point Cal.com’s security provider (Cloudflare) may set one technical cookie, __cf_bm, which lasts 30 minutes and is used to tell people from bots. It’s strictly necessary for the booking service you asked for, so under Art. 22.2 LSSI it doesn’t require consent. If we ever add analytics or advertising cookies, we’ll ask for your permission first.
4. Security
- The whole site is served over HTTPS only (HSTS), with strict browser security headers, including a Content Security Policy.
- No personal data is stored on the website itself. Bookings live in Cal.com and messages in WhatsApp or email.
- Only we have access to the accounts that hold your data.
- Found a security problem? Tell us at 300sunvalencia@gmail.com (see also security.txt).