Legal

Privacy Policy

Last updated: August 2026

Leer en español →

1. Who is responsible for your data

Nexo Activities is responsible for the personal data described in this policy, together with its registered autónomo, Manuel Luis Anders Kuckuck (self-employed sole trader) under Spanish law.

Contact for data protection matters: contact@nexoactivities.com.

2. General

We take the protection of your personal data seriously. We handle it in accordance with the applicable data protection law, in particular the General Data Protection Regulation (GDPR) and the Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD), as well as this privacy policy. Personal data is only collected on a voluntary basis or where necessary to perform a contract with you. Data transmitted over the internet (for example, by email) can never be made completely secure, and full protection against unauthorised access by third parties cannot be guaranteed.

3. Personal data we process

3.1. Booking through our website. When you book a Nexo Event or a Third-Party Event through our website, the payment is processed by our payment provider Stripe, which collects your name, email address and phone number, plus which event you booked and how many places. Your card details are entered directly into Stripe’s payment form and never reach our servers — we only ever see the amount, the currency and the payment method type (for example “Visa” or “Apple Pay”).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

3.2. Failed payments. If a payment is declined, we keep the same contact details together with the decline reason given by the bank, so we can get in touch and help you complete the booking if you still want to come.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in following up on an incomplete booking). You can object to this at any time.

3.3. Newsletter. When you subscribe to our newsletter, we collect your email address and, if you gave it to us, your name. We only send you event announcements if you explicitly opted in.
Legal basis: Art. 6(1)(a) GDPR (consent) — you can withdraw it at any time using the unsubscribe link in any email.

3.4. Contact form. If you contact us through the form on our website, we collect your name, email address and, where given, your phone number, whether you are contacting us as a customer or a business, and the content of your message.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).

3.5. Email. In the course of email correspondence we process your name and email address.
Legal basis: Art. 6(1)(f) GDPR.

3.6. Social media and community channels. If you communicate with us via social media (Instagram, TikTok) or our WhatsApp community, we record the contact details that arise from this in our CRM to manage the customer relationship efficiently.
Legal basis: Art. 6(1)(f) GDPR.

4. Consent and purpose limitation

Where processing is based on your consent, by submitting your personal data you agree that it may be processed for the purposes described in this policy. We do not process it for any other purpose. You may withdraw your consent at any time, with effect for the future and without giving reasons, by contacting contact@nexoactivities.com.

5. How long we keep your data

We keep the data described in Section 3 for the duration of our business relationship with you and for a further three months after it ends. Newsletter subscriptions are kept until you unsubscribe. This does not apply where statutory retention obligations — for example under commercial or tax law — prevent deletion; in that case the data is deleted once the applicable legal retention period has expired.

6. Who we share your data with

6.1. Third-Party Events. Where we mediate a Third-Party Event in cooperation with a partner company, we pass on the personal data collected from you to that partner company to the extent necessary for the proper execution of the event. Once the data has been transferred, our data protection responsibility for it ends — from that point on, the partner company acts as an independent controller.
Legal basis: Art. 6(1)(b) GDPR.

6.2. Processors. We use the following processors, which process data exclusively on our instructions. We don’t sell your data and we don’t share it for advertising:

ProviderWhat it doesBased in
StripePayment processing and collection of the checkout data.Ireland / United States
SupabaseDatabase for newsletter subscriptions and event capacity.European Union
CentralStationCRMOur CRM for customer data — bookings, enquiries and notes.Germany
ResendSends the booking confirmation and other transactional emails.United States
VercelHosts the website and provides cookie-free visitor statistics.United States

7. International transfers

Personal data is transferred to countries outside the European Economic Area to the extent that our processors Stripe, Resend and Vercel are based in the United States. This transfer is safeguarded by the European Commission’s Standard Contractual Clauses.

8. Your rights

You have the right to withdraw any consent you've given us (Art. 7(3) GDPR), to access your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict how we use it (Art. 18), to receive it in a portable format (Art. 20), and to object to processing we base on legitimate interest (Art. 21).

To exercise any of these, email contact@nexoactivities.com. If you think we’ve handled your data badly and we haven’t resolved it, you have the right to complain to the competent supervisory authority (Art. 77 GDPR), for example the Spanish data protection authority, the Agencia Española de Protección de Datos.

9. Obligation to provide data

There is no statutory obligation to provide your data. However, once a contract for participation in an event organised by us or a partner company has been concluded, you are contractually obliged to provide the data described in Section 3 for the purposes of communication and of carrying out the event.

10. Consequences of not providing data

Booking an event is not possible without the data transfer described in Section 3.1.

11. Automated decision-making

No automated decision-making within the meaning of Art. 22(1) and (4) GDPR takes place.

12. Cookies

Our website uses cookies to make our offering more user-friendly, effective and secure through web analytics. Most of the cookies we use are so-called “session cookies”, which are automatically deleted once you end your visit. The cookies and similar technologies this site uses are listed separately in our Cookie Policy.
Legal basis: Art. 6(1)(f) GDPR.

13. Changes to this policy

If we change how we handle personal data we’ll update this page and the date at the top. If the change is significant, we’ll tell people who have booked with us by email.