Last updated: 30 June 2026
Atlantor ("Atlantor", "we", "us", "our") operates the marketplace platform at bookatlantor.com. We are deeply committed to protecting your privacy and managing your personal data transparently, securely and in full compliance with the GDPR/RGPD, the Portuguese Data Protection Law and the Spanish Organic Law on Data Protection (LOPDGDD).
Atlantor is the sole controller of the personal data collected through this platform. For any question, concern or request regarding how your data is handled, contact us at hello@bookatlantor.com.
Booking and account information: when you request a booking we collect your full name, email, phone number, language preference and booking details (date, time, party size). Payment data: all financial transactions are handled by a certified PCI-DSS compliant payment processor. Atlantor never sees, stores or processes your raw card numbers or banking credentials — we only receive a transaction confirmation token (success/failure). Communications: if you email us, request a quote or submit an inquiry, we collect your name, email and the contents of the message. Technical and usage data: our servers automatically log standard web metadata for security, fraud prevention and analytics, including IP address, user agent, referring/exit pages and timestamps. Children's privacy: our platform is designed for adults. We do not knowingly collect data from individuals under 16; if discovered, it is deleted immediately.
Performance of a contract (Art. 6(1)(b)): we process booking details, contact information and payment status to fulfil the booking and intermediate your contract with the chosen Operator. Compliance with legal obligations (Art. 6(1)(c)): we retain billing, transactional records and tax-related details to comply with mandatory Portuguese, Spanish and European financial, accounting and consumer-protection laws. Legitimate interests (Art. 6(1)(f)): we process technical server logs and anonymised usage data to maintain platform security, detect and prevent fraud, and continuously improve the website. Consent (Art. 6(1)(a)): we only send marketing emails, newsletters or promotional offers if you have explicitly opted in. You can withdraw consent at any time.
We never sell your personal data. Independent local Operators: once a booking is requested or confirmed, we share your name, phone number and booking specifics with the Operator delivering the experience. They only receive what is strictly necessary to contact you, manage logistics and host you safely. Operators act as independent data controllers for the data they receive. Service providers: secure payment gateways, cloud hosting, deployment tools and privacy-preserving analytics providers — all contractually bound to protect your data. Legal authorities: we may disclose data when required by European law or valid legal requests by public authorities (e.g. tax offices or law enforcement).
While we prioritise keeping your data within the EEA, some cloud infrastructure and software providers may operate outside the EEA (such as in the United States). Before any transfer we ensure appropriate safeguards through the European Commission's Standard Contractual Clauses (SCCs) or applicable Adequacy Decisions to guarantee an equivalent level of protection.
Booking & financial records: up to 6 years to comply with fiscal, commercial and tax-audit laws. General inquiries and contact messages: 24 months after resolution, unless converted into a booking. Marketing newsletter subscribers: indefinitely until you withdraw consent or click "Unsubscribe". Server security logs: automatically overwritten or deleted after 12 months.
Under Chapter III of the GDPR you have the right to access your data and receive a copy of it; rectify any inaccurate or incomplete data; erase your data ("right to be forgotten") unless we have an overriding legal obligation to retain it; restrict processing under specific legal circumstances; port your data to another provider in a structured, machine-readable format; object to processing based on our legitimate interests; and withdraw consent at any time for processing based on prior consent (such as newsletters). To exercise any of these rights, email hello@bookatlantor.com. We will respond within the legally mandated timeframe of 30 days.
If you believe our processing of your personal data violates European data-protection regulations, you have the right to file a complaint with a Supervisory Data Protection Authority. You may contact your local authority, or our core regional authorities: in Portugal, Comissão Nacional de Proteção de Dados (CNPD) — cnpd.pt; in Spain, Agencia Española de Protección de Datos (AEPD) — aepd.es.