PRIVACY POLICY
Last updated 9 October 2026
1. Who is responsible
- Website operator and data controller
- CD UNDERDOG (Club Deportivo Underdog), operating Tenerife Beach Volley (TBV).
- NIF
- G75402180
- Registered address
- Avenida Juan Alfonso Batista - Los Cristianos, Arona 38650, Santa Cruz de Tenerife, Spain.
- Registration
- Registro de Entidades Deportivas de Canarias, Resolution n.º 1226/2024 of 2 October 2024, subsequently corrected.
- Legal and privacy contact
- [email protected]. You may also write to the registered address. General inquiries: website contact form.
This policy covers tenerifebeachvolley.com and the TBV website served through its hosting domain. It explains information collected through our guide, contact and newsletter forms and ordinary website operation. Last updated: 9 October 2026.
2. Information we collect
- Free guide: first name, last name, email, request date, privacy acknowledgment, optional marketing choice, delivery status and the date a tracked download starts.
- Contact inquiries: first name, last name, email, social profile, inquiry type, message, privacy acknowledgment and optional company. We record submission date, verification, delivery and message-management status.
- Newsletter: first name, last name, normalized email, active or unsubscribed status, registration source, and consent history including timestamp, source and the consent wording.
- Operation and security: hosting providers receive technical requests, including IP addresses, browser information and requested resources. Our application keeps short-lived hashed IP or email rate-limit keys, request identifiers and hashed access tokens to prevent abuse, duplicate processing and unauthorized access. A hash is a security measure, not a guarantee of anonymity.
Required fields are marked with *. Without them, the corresponding form cannot be processed. Company is optional in the contact form, and marketing consent is optional in the guide form. Do not include passwords, identity-document copies, payment details or sensitive health information in messages. We obtain form details directly from you; we do not enrich them from external profiles.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Deliver the free guide you request and keep a record of delivery and tracked access. | Your consent to the guide request (GDPR Article 6(1)(a)). This is independent of marketing consent. |
| Respond to general inquiries, collaborations, media requests and correspondence. | Our legitimate interest in managing communications you initiate (Article 6(1)(f)). When you request steps toward a contract with you, Article 6(1)(b) applies. |
| Send occasional newsletter and educational updates. | Your explicit marketing consent (Article 6(1)(a)). |
| Verify contact email addresses, prevent duplicate registrations, secure the website and restrict administrator access. | Our legitimate interest in preventing abuse and protecting visitors and records (Article 6(1)(f)). |
| Keep necessary consent or opt-out evidence, meet legal duties and handle legal claims. | Applicable legal obligations (Article 6(1)(c)) or our legitimate interest in demonstrating compliance and establishing, exercising or defending claims (Article 6(1)(f)), as relevant. |
Our legitimate interests are limited to running and securing this website, answering requested communications and protecting rights. You may object where processing relies on legitimate interests. We do not make automated decisions with legal or similarly significant effects, or build individual advertising profiles.
4. How the forms and emails work
Contact: the inquiry is saved pending email verification. A secure confirmation link expires after 24 hours. After successful verification, the system attempts to notify our team. Transactional verification and inquiry emails do not subscribe you to marketing. Multiple inquiries from the same email are allowed.
Free guide: registrations are deduplicated per guide and normalized email. The form shows the same neutral message for new and existing registrations. An existing request does not automatically receive another guide email. You can use the separate guide recovery form to request a new or retried email for a saved guide request. Recovery uses the email supplied for that original request, is rate limited, does not reveal whether the address is registered, and does not create a new lead, renew the retention deadline or change newsletter consent. Download links expire after seven days. We record when the tracked download endpoint is requested; this does not prove that the file was fully downloaded or read and can include an automated email-security request.
Newsletter: selecting the optional guide marketing checkbox or submitting the clearly labelled newsletter form activates a single opt-in subscription immediately. No newsletter confirmation-link or welcome email is currently sent. Both methods use one audience. Leaving the guide checkbox unchecked does not unsubscribe an existing subscriber. Fresh explicit consent can reactivate a previous unsubscribe. Every future marketing email must provide a working unsubscribe link; you can also withdraw consent now through the privacy contact. Withdrawal does not affect earlier lawful processing or necessary transactional emails.
5. Who receives information
Authorized TBV administrators can access the private dashboard. We do not sell personal information or give partners the form database for their own marketing. Necessary information is processed by:
- OpenAI / ChatGPT Sites: hosting, maintenance and administrator authentication. Published-site data is covered by the applicable Sites data processing addendum. For EEA users its stated contracting entity is OpenAI Ireland Ltd. Administrator account information is also governed by OpenAI’s own terms and privacy policy.
- Cloudflare: domain/DNS, network delivery, security, Worker hosting and D1 database infrastructure used by the site. See Cloudflare’s privacy policy and security-cookie information.
- Resend (Plus Five Five, Inc.): sending guide, contact and internal notification emails. This involves recipients, message content and delivery metadata. See its data processing addendum and subprocessor list.
- Google / Gmail: receiving and storing TBV’s internal notifications and correspondence in our Gmail inbox. Automated form notifications contain only the form type and a generic private-dashboard link, without submitter names, email addresses, message contents, record identifiers or visitor Reply-To headers. Earlier notifications and direct correspondence may still contain personal information. See Google’s privacy policy.
Providers may use their own infrastructure suppliers under their applicable service arrangements. Their own account, security and service information may be processed under their privacy policies. We may disclose strictly necessary information to competent authorities when legally required, or to professional advisers where needed to protect rights.
6. International processing
Our providers operate internationally. Information may be processed outside Spain and the European Economic Area, including in the United States; this site is not represented as EU-only storage. The published OpenAI Sites addendum describes European Commission standard contractual clauses or an adequacy decision for relevant transfers. Resend’s published addendum includes standard contractual clauses and identifies its primary processing in the United States.
Google and Cloudflare describe international processing in their linked policies. The applicable safeguards depend on the particular service, contracting entity and processing arrangement. You can contact CD UNDERDOG for information about the safeguards applicable to your data or request a copy, subject to necessary confidentiality protections. Provider policies alone do not mean that every account-specific arrangement has been independently audited.
7. Retention and deletion
- Guide requests and contact inquiries: normally up to two years from submission. An ongoing inquiry, specific legal obligation or claim can justify keeping only necessary information longer, with annual review.
- Newsletter: while the subscription is active and relevant, with annual review. After withdrawal, marketing stops. Only necessary consent evidence and suppression information may be retained to demonstrate consent and honor the opt-out, reviewed annually and deleted when no longer necessary.
- Scheduled review start: age-based guide/contact reviews begin August 9, 2028. Each record keeps its original two-year deadline; no bulk deletion occurs simply because reviews start. Short-lived security and analytics housekeeping continues, and individual privacy requests are handled independently.
- Deletion matching reports: after database deletion, the record ID, type, email and submission/deletion dates are retained privately for up to 30 days to help the administrator remove matching inbox and exported copies. Message contents are not retained in these reports.
- Access links: contact confirmation links expire after 24 hours and guide links after seven days. Expiry disables access; it does not delete the underlying registration.
- Application rate-limit records: eligible for cleanup after 24 hours; cleanup runs on later rate-limited requests and during the daily retention check.
- Aggregate statistics: a rolling 30-day reporting window. Delivery receipts expire after ten minutes. Physical cleanup runs on subsequent analytics collection requests and during the daily retention check.
Guide requests and contact inquiries in the website database are automatically deleted at the next daily cleanup after two calendar years from submission. Deletion also revokes their verification and guide links and removes retained legacy database copies. Records explicitly placed on a retention hold for an ongoing matter, legal obligation or claim are excluded until an administrator releases the hold; holds must be reviewed annually. Active newsletter subscriptions and necessary consent or opt-out evidence follow their separate criteria above and are not erased by the two-year guide/contact timer. Retention periods are our necessity-based criteria, not a statutory maximum allowing indefinite storage. Reviews must also cover email copies, exports and applicable provider logs or backups; deleting a dashboard record does not automatically erase a Gmail notification or exported copy. Notification copies in our receiving inbox follow a two-year review/deletion rule; guide and contact copies use the original submission date. Temporary CSV working exports are removed within 30 days after their task is completed and no later than the source record deadline, unless a documented lawful exception applies. Necessary ongoing correspondence and legal holds are reviewed annually. Inbox and export cleanup is manual and separate from database deletion. Email queue payloads are removed after provider acceptance; unresolved terminal payloads are removed after 30 days. Queue metadata is deleted with the related form record; newsletter notification metadata is removed after two years. Provider-controlled operational records are governed by the applicable service arrangements.
9. Your rights and how to contact us
Subject to applicable conditions, you can request access, correction, deletion, restriction and portability of your personal information; object to processing based on legitimate interests; and withdraw consent at any time. You can object to direct marketing at any time. Deletion is not absolute where necessary information must be retained for legal obligations or claims.
Email [email protected] with your request, or write to the registered address above. You do not need to provide a social profile or use the business contact form to exercise your rights. Tell us enough to locate the relevant record; we may ask for proportionate identity verification where necessary. Do not send identity documents unless requested through an appropriate secure method.
We will respond without undue delay and normally within one month. Where legally justified by complexity or number of requests, this can be extended by up to two further months, with an explanation within the first month. You can complain to the Agencia Española de Protección de Datos (AEPD) or your competent supervisory authority; you do not have to contact us first.
10. Security, age and changes
The application uses HTTPS, server-side validation, rate limiting, private administrator authorization and hashed access tokens. API secrets are stored server-side. No system can guarantee absolute security. This website does not intentionally collect sensitive personal information and its forms are not directed at children under 14. If information from a child requiring parental authorization has been provided, contact us so we can assess and remove it where appropriate.
We will update this page when processing changes, showing the revision date and providing additional notice where required. A change to this policy is not itself consent to a new marketing purpose.
