Privacy Policy

Chicks on Waves

chicksonwaves.com

Last updated: April 2025

1. Introduction

 

Chicks on Waves (“we”, “us”, or “our”) is committed to protecting your personal information.This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website chicksonwaves.com or register for one of our retreats.

We are based in Portugal and operate in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and applicable Portuguese data protection law

. Please read this policy carefully. By using our website, you agree to the practices described here.

 

2. Data Controller

 

The data controller responsible for your personal data is:
• Organisation: Chicks on Waves
• Website: chicksonwaves.com
• Country: Portugal
• Contact: info@chicksonwaves.com

 

3. Information We Collect

 

We may collect and process the following categories of personal data:

 

3.1 Information you provide directly

 

• Full name and contact details (email address, phone number) • Booking and payment information (processed securely via our payment provider)

• Dietary requirements, health information, or physical limitations relevant to retreat participation

• Communications you send us via email or our contact form

• Newsletter subscription via Mailchimp (email address and name)

 

3.2 Information collected automatically

 

• IP address and browser type

• Pages visited, time spent on site, and referring URLs

• Device and operating system information

• Analytics data collected via Google Analytics (see Section 7)

 

4. How We Use Your

 

Information We use your personal data for the following purposes:

• To process and manage your retreat booking and related communications (legal basis: performance of a contract)

• To send you newsletters and marketing communications via Mailchimp, where you have opted in (legal basis: consent)

• To improve our website and services based on usage data (legal basis: legitimate interests)

• To comply with legal obligations (legal basis: legal obligation)

• To respond to enquiries and provide customer support (legal basis: legitimate interests / contract)

 

5. Legal Bases for Processing

 

Under the GDPR, we rely on the following legal bases:

Contractual necessity: processing required to fulfil your retreat booking

Consent: for email marketing (Mailchimp) and non-essential cookies (Google Analytics)

Legitimate interests: to improve our services, conduct analytics, and maintain website security

Legal obligation: where required by Portuguese or EU law

 

6. Email Marketing – Mailchimp

 

We use Mailchimp, a service provided by The Rocket Science Group LLC (USA), to manage our mailing list and send newsletters. When you subscribe to our mailing list, your name and email address are transferred to and stored on Mailchimp’s servers.

Mailchimp is certified under the EU-U.S. Data Privacy Framework, which ensures adequate data protection for transfers to the United States. You can unsubscribe from our newsletter at any time by clicking the unsubscribe link in any email or by contacting us directly.

For more information, see Mailchimp’s Privacy Policy at: https://mailchimp.com/legal/privacy/

 

7. Google Analytics

 

We use Google Analytics, a web analytics service provided by Google LLC, to understand how visitors interact with our website. Google Analytics uses cookies to collect information such as the number of visitors, pages visited, and traffic sources.

This data is anonymised and aggregated. We have enabled IP anonymisation in Google Analytics so that your full IP address is never stored. Google Analytics data may be transferred to and stored on servers in the United States under Google’s participation in the EU-U.S. Data Privacy Framework.

You can opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on, available at: https://tools.google.com/dlpage/gaoptout

 

8. Sharing Your Information

 

We do not sell, trade, or rent your personal data to third parties. We may share your data with trusted third-party service providers who assist us in operating our website and conducting our business, under strict data processing agreements. These include:

• Mailchimp (email marketing) • Google LLC (analytics)

• Payment processors (for secure booking transactions)

• Hosting and IT service providers

We may also disclose your information where required by law or to protect our rights.

 

9. Data Retention

 

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Specifically:

• Booking data: retained for a minimum of 7 years for accounting and legal compliance purposes

• Marketing data (Mailchimp): retained until you unsubscribe or withdraw consent

• Analytics data: retained as per Google Analytics default settings (up to 26 months)

 

10. Your Rights Under GDPR

 

As a data subject under the GDPR, you have the following rights:

• Right of access: to request a copy of the personal data we hold about you

• Right to rectification: to request correction of inaccurate or incomplete data

• Right to erasure: to request deletion of your personal data, subject to certain conditions

• Right to restriction: to request that we limit the processing of your data

• Right to data portability: to receive your data in a structured, commonly used format

• Right to object: to object to processing based on legitimate interests or for direct marketing

• Right to withdraw consent: at any time, without affecting the lawfulness of prior processing To exercise any of these rights, please contact us at info@chicksonwaves.com. We will respond within 30 days. You also have the right to lodge a complaint with the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD): www.cnpd.pt

 

11. Data Security

 

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. Our website uses HTTPS encryption. However, no transmission over the internet is completely secure, and we cannot guarantee absolute security.

 

12. Children’s Privacy

 

Our retreats and website are intended for adults aged 18 and over. We do not knowingly collect personal data from individuals under 18. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.

 

13. Changes to This Policy

 

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page indicates when the policy was last revised. We encourage you to review this page periodically. Continued use of our website after changes constitutes acceptance of the updated policy.

 

14. Contact Us

 

If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your personal data, please contact us at:

• Chicks on Waves

info@chicksonwaves.com

chicksonwaves.com