Privacy Policy of the app
Last updated: 6 August 2026
COSTA BELLVER, S.A. informs users of the Blue Tech Zone mobile app (hereinafter, the "App") about the processing of their personal data, in compliance with Regulation (EU) 2016/679, the General Data Protection Regulation (hereinafter, "GDPR"), and Spanish Organic Law 3/2018, on the Protection of Personal Data and the guarantee of digital rights (hereinafter, "LOPDGDD").
Basic data protection information
| Controller | COSTA BELLVER, S.A. — Tax ID A12102703 |
| Purposes | Management of registration and of the user account; management of restaurant bookings and registrations for events and experiences; personalisation of the content shown in the App; sending of service communications and notifications; maintaining the security of the App |
| Legal basis | Performance of the contractual relationship; consent of the data subject; legitimate interest of the controller |
| Recipients | Service providers acting as processors, listed in clause 5. International transfers are carried out with appropriate safeguards |
| Rights | Access, rectification, erasure, objection, restriction, portability and withdrawal of consent, on the terms of clause 7 |
| Further information | As set out in the clauses below |
1. Data controller
COSTA BELLVER, S.A. Tax ID: A12102703 Address: Calle María Rosa Molas, 6 bajo, 12004 Castellón de la Plana (Castellón), Spain Email: app@bluetechzone.com
"Blue Tech Zone" is the trade name under which COSTA BELLVER, S.A. provides its services.
2. Purpose and scope
This Policy governs the processing of the personal data of users of the App for iOS and Android devices, as well as the processing that the controller carries out in its systems of the data that the App transmits to it.
The website bluetechzone.com is governed by its own privacy policy and cookie policy, which are separate from this one.
3. Data processed, purposes and legal bases
3.1 Registration and management of the user account
| Data processed | Purpose | Legal basis |
|---|---|---|
| Email address and password or, where applicable, the identifier of the Google, Apple or Microsoft account used to sign in | Account creation, user authentication, session maintenance and account recovery | Performance of the contractual relationship (Art. 6.1.b GDPR) |
| First name and surname | Identification of the user in the App and in the bookings and registrations they make | Performance of the contractual relationship (Art. 6.1.b GDPR) |
| Preferred language | Provision of the service in the selected language | Performance of the contractual relationship (Art. 6.1.b GDPR) |
| User type and, where applicable, company or programme code and name of the associated entity | Enabling access to the content corresponding to the user's link with the resort | Performance of the contractual relationship (Art. 6.1.b GDPR) |
| Profile photo, taken from the device gallery or with the camera | Personalisation of the user profile | Consent of the data subject (Art. 6.1.a GDPR) |
| Date of birth | Optional completion of the user profile | Consent of the data subject (Art. 6.1.a GDPR) |
The profile photo and the date of birth are optional. Not providing them does not prevent use of the App nor impair any of its functionalities. The date of birth is not used to verify the user's age or to segment content, and may be deleted at any time from the profile.
3.2 Provision of the resort's services
| Data processed | Purpose | Legal basis |
|---|---|---|
| Restaurant bookings: date, time, number of guests, contact phone number and comments entered by the user | Management and confirmation of the booking with the relevant establishment | Performance of the contractual relationship (Art. 6.1.b GDPR) |
| Registrations for events and experiences | Management of the user's participation | Performance of the contractual relationship (Art. 6.1.b GDPR) |
| Email address and name | Sending of service communications: confirmations, account-related notices and password recovery | Performance of the contractual relationship (Art. 6.1.b GDPR) |
| Interests selected by the user | Ordering and recommendation of the resort's events and content shown in the App | Consent of the data subject (Art. 6.1.a GDPR) |
User interests. When starting to use the App, the user is offered the possibility of selecting their areas of interest. This is an optional step, which the user may skip with no consequence whatsoever for the remaining functionalities. Interests are used exclusively within the App, to determine the order in which content is presented, and are not disclosed to third parties or combined with data from external sources. The user may modify or delete them at any time from their profile, which takes effect as a withdrawal of consent.
Booking comments field. The comments field associated with a booking is free text and its content is passed on to the establishment through the controller. Should the user enter sensitive information about themselves in it —notably food allergies or intolerances— such information will be processed exclusively to handle the booking, on the basis of the explicit consent given by the user through its voluntary provision (Art. 9.2.a GDPR). Users are advised to limit the content of that field to what is strictly necessary for the booking.
3.3 Technical and security data
| Data processed | Purpose | Legal basis |
|---|---|---|
| Session identifiers | Maintaining the signed-in session securely | Performance of the contractual relationship (Art. 6.1.b GDPR) |
| Technical device identifiers | Distribution of App updates and maintenance of its integrity | Legitimate interest of the controller in ensuring the proper functioning and security of the App (Art. 6.1.f GDPR) |
| Device identifier for notification purposes | Sending notices about bookings, registrations and news from the resort | Consent of the data subject (Art. 6.1.a GDPR) |
| Security logs | Prevention of unauthorised access, fraud and abusive use of the service | Legitimate interest of the controller in the security of its systems (Art. 6.1.f GDPR) |
The user may obtain information about the balancing test carried out in respect of the processing based on legitimate interest by sending a request to the address indicated in clause 1.
3.4 Nature of the data requested
The data identified as necessary for the creation of the account and for the management of bookings and registrations must be provided in order for the service to be delivered; failure to provide it will prevent the creation of the account or the processing of the relevant request. All other data is optional.
The user warrants the accuracy of the data provided and undertakes to keep it up to date, being able to amend it from their profile.
4. Source of the data
The personal data processed comes from the user themselves, provided at the time of registration or during use of the App.
In the case of users linked to a company or programme, the controller may receive from that entity or from the relevant host the access code and the linking data needed to enable access to the content associated with their programme.
5. Recipients of the data
5.1 Processors
In order to provide the service, the controller relies on the providers listed below, which access personal data as processors, subject to the controller's instructions and under the contract provided for in Art. 28 GDPR, and may not use it for their own purposes.
| Provider | Service provided | Categories of data |
|---|---|---|
| Supabase | Management of accounts and login credentials | Email address, password and identifying data |
| Google Cloud | Hosting of the profile photo and infrastructure | Profile photo |
| SendGrid | Sending of service communications | Email address and name |
| CoverManager | Management of restaurant bookings | Name, email address, phone number, number of guests and comments |
| Luma | Management of events and registrations | Name, email address and phone number |
| Expo | Distribution of App updates | Technical device identifiers |
The data is located in the controller's systems and in those of the listed providers. Only a copy of the session, encrypted in the secure store of the operating system, and the user's usage preferences are kept on the user's device.
5.2 Identity providers
Where the user chooses to sign in with a Google, Apple or Microsoft account, those providers will disclose to the controller the email address and name associated with the account, solely for the purpose of creating or linking it. As regards the processing of the account the user holds with them, these providers act as independent controllers, under their respective privacy policies, with no processing relationship with the controller.
5.3 Other disclosures
Beyond the cases described above, no personal data is disclosed to third parties, except where required by law or by a request from a competent judicial or administrative authority.
5.4 International transfers
The providers Supabase, SendGrid (Twilio), Luma and Expo are established in, or process data in, the United States. Those transfers rely on the safeguards provided for in Chapter V GDPR: the provider's certification under the EU-U.S. Data Privacy Framework, where available, and, failing that, the standard contractual clauses adopted by the European Commission, supplemented by any additional measures found appropriate following the corresponding assessment.
The user may request information about those safeguards at the address indicated in clause 1.
6. Retention periods
| Data | Period |
|---|---|
| User account and profile | For as long as the account remains active. Its deletion is governed by clause 7 |
| Interests and preferences | For as long as the account remains active or until deleted by the user |
| Bookings and registrations | 5 years from the provision of the service, to meet contractual obligations and defend against possible claims |
| Service communications | 12 months |
| Security logs | 12 months |
| Backups | 30 days, on a rolling retention basis |
Once the above periods have elapsed, the data is deleted or irreversibly anonymised, without prejudice to its retention, duly blocked, for the period during which liability may arise from its processing, in accordance with Art. 32 LOPDGDD.
7. Rights of data subjects
The user may exercise at any time the rights of access, rectification, erasure, objection, restriction of processing and portability, as well as withdraw the consent given, without this affecting the lawfulness of processing prior to its withdrawal.
Direct exercise from the App. Without the need for a prior request, the user may:
- Obtain a copy of their data, from their profile, section Privacy and security.
- Delete their account, from their profile, section Privacy and security.
- Rectify their profile data and change their email address.
- Modify or delete their interests, with the effects of withdrawal of consent set out in clause 3.2.
- Revoke the notifications permission from their device settings, with the effects of withdrawal of consent.
Effects of deleting the account. Deletion entails the anonymisation of the user's name and the erasure of their email address, profile photo, interests and preferences and device identifier, as well as a deletion request to the identity provider. Records of bookings and registrations are kept anonymised for the period set out in clause 6.
Exercise by request. A user who does not have the App installed may request the deletion of their account at https://bluetechzone.com/en/delete-account, or send any request concerning their rights to app@bluetechzone.com, quoting the reference "Data Protection" and attaching, where necessary to verify their identity, the corresponding documentation.
Requests will be answered within one month of receipt, extendable on the terms of Art. 12.3 GDPR.
Complaint to the supervisory authority. A user who considers that the processing of their data does not comply with the applicable rules may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan, 6, 28001 Madrid — www.aepd.es).
8. Minimum age of use
Use of the App requires the user to be at least 14 years old. Users aged 14 and 15 also require the authorisation of the holder of their parental responsibility or guardianship.
The conditions of access by reason of age are set out in the App's Terms and Conditions of Use, whose acceptance by the user during registration entails the declaration that they meet those requirements. The controller keeps a record of that acceptance.
Where an account is found not to meet the above requirements, the controller will delete it. Holders of parental responsibility or guardianship of a minor may request the deletion of their account by writing to app@bluetechzone.com.
9. Security measures
The controller has adopted appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Art. 32 GDPR. In particular, communications between the App and the controller's systems take place over TLS; the user's session is stored in the secure store of the device's operating system; and staff access to data is subject to role-based control, limited to what is necessary to perform their duties and bound by a duty of confidentiality.
10. Automated decisions and profiling
The controller does not take decisions based solely on automated processing that produce legal effects concerning the user or similarly significantly affect them, within the meaning of Art. 22 GDPR.
The ordering of content according to the interests selected by the user constitutes a personalisation of a purely informational nature within the App.
The controller does not carry out processing for advertising or marketing purposes based on the user's data, does not build profiles for commercial purposes, does not disclose data to third parties for that purpose and does not use in the App any third-party analytics, advertising, tracking or crash-reporting tools, nor advertising identifiers, nor techniques for tracking the user across third-party apps or websites.
11. Communications and notifications
Communications sent by email are service communications linked to the contractual relationship —booking and registration confirmations, account-related notices and password recovery— and do not constitute commercial communications.
Sending notifications to the device requires the prior grant of the operating system permission. That permission may be withheld, without this affecting the remaining functionalities, and may be revoked at any time from the device settings, in which case notifications will cease.
12. Changes to the Privacy Policy
The controller may amend this Policy to adapt it to legislative or case-law developments or to changes in the processing carried out. Any amendment will be published at this same address, stating its update date.
Where the amendment affects the purposes or the legal bases of the processing, the user will be informed through the App and, where required by law, their consent will be obtained beforehand.
13. Contact
Any query concerning this Policy may be addressed to COSTA BELLVER, S.A., Calle María Rosa Molas, 6 bajo, 12004 Castellón de la Plana (Castellón), Spain, or to the email address app@bluetechzone.com.
