Privacy Policy
This Privacy Policy provides information about the processing of personal data when using our website, our platform and the associated online services (collectively, the “Online Offering”). It applies pursuant to Regulation (EU) 2016/679 (“GDPR”), the Spanish Ley Orgánica 3/2018, de Protección de Datos Personales y garantía de los derechos digitales (“LOPDGDD”) and, insofar as cookies and similar technologies are concerned, the Spanish Ley 34/2002 de Servicios de la Sociedad de la Información y de Comercio Electrónico (“LSSI-CE”).
Personal data means any information relating to an identified or identifiable natural person. We process personal data only where there is a legal basis for doing so, in particular for the performance of a contract, the implementation of pre-contractual measures, compliance with legal obligations, the protection of legitimate interests or on the basis of consent.
1. Controller and Data Protection Contact
The controller responsible for processing personal data is:
Asociación I Love Me
G1/S1/25165-21/H
Hoyo del Barrio, 19
38916 Valverde, Santa Cruz de Tenerife
Spain
Represented by the association’s president, Daniel Hauenstein.
Email address for general enquiries and data protection enquiries:
For questions concerning the processing of personal data and for exercising your data protection rights, you may contact us at this email address.
2. General Principles
We process personal data in particular for the following purposes:
- Provision, technical security and further development of the Online Offering
- Establishment, performance and administration of user, membership, booking and purchase relationships
- Communication, handling of enquiries and support
- Fraud and misuse prevention as well as IT and system security
- Compliance with statutory retention, documentation and cooperation obligations
- Reach measurement and optimisation of the Online Offering, insofar as consent has been given for this purpose
Where the provision of data is necessary for entering into or performing a contract, we identify mandatory information in the relevant input forms. Without this data, we may not be able to provide the relevant service. Voluntary information is identified accordingly.
We take appropriate technical and organisational measures to protect personal data against loss, alteration, unauthorised access or unauthorised disclosure.
3. Retention Period
We retain personal data only for as long as is necessary for the respective purpose or as required by statutory retention obligations. Unless a different period is specified in this Privacy Policy, the following principles apply in particular:
- Contract and account data: for the duration of the user or contractual relationship; thereafter generally until the expiry of statutory limitation periods, insofar as this is necessary to assert or defend claims
- Server and security logs: generally 7 days; in the event of a security incident, suspected misuse or for legal defence, up to 30 days or longer where necessary in the individual case
- Contact and support enquiries: 12 months after final processing, unless longer retention is required for legal defence or due to statutory obligations
- Proof of consent: for the duration of processing based on consent and thereafter insofar as necessary for documentation, legal defence or compliance with accountability obligations
- Documents relevant under commercial and tax law: pursuant to Art. 30 para. 1 of the Spanish Commercial Code (Código de Comercio), generally 6 years from the last accounting entry; tax-relevant documents are retained for at least the period specified under Art. 29 para. 2 lit. e and Art. 66 of Law 58/2003, General Tax Law (Ley 58/2003, General Tributaria), which is generally 4 years
Longer retention may be necessary where statutory obligations, ongoing audits, court proceedings or the assertion, exercise or defence of legal claims require it.
4. Records of Processing Activities
We maintain a record of processing activities pursuant to Art. 30 GDPR and Art. 31 LOPDGDD, insofar as the statutory requirements are met. This record contains, in particular, information on the purposes of processing, categories of data, data subjects, recipients, transfers to third countries, deletion periods, and technical and organisational protective measures.
The record is continuously updated and made available to the competent data protection supervisory authority upon request. It is not intended for general publication.
5. Website Visits and Server Logs
Whenever our Online Offering is accessed, our server or hosting provider processes technically necessary access data. This may include, in particular:
- IP address of the requesting device
- Date and time of access
- Requested file, URL or interface
- Referrer URL
- Browser type, browser version, operating system and User-Agent
- Internet service provider
- For logged-in users: user ID, account ID and session ID
- Technical error messages and security events
- When using an app: app version
The processing is carried out to technically provide the Online Offering, ensure IT security and system stability, detect and prevent misuse, and analyse errors. The legal basis is Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in providing our Online Offering securely, reliably and economically.
Log data is generally deleted after 7 days. Where there are specific indications of a security incident, misuse or a legal violation, the relevant data may be retained until the investigation and necessary follow-up processing have been completed, generally for a maximum of 30 days. Longer retention will only take place where this is legally required in the individual case or is necessary for legal defence.
Our servers are located in Switzerland. The European Commission has determined that Switzerland provides an adequate level of data protection.
6. Cookies and Similar Technologies
We use cookies and similar technologies. Cookies are small text files that may be stored on your device. They may be technically necessary or, with your consent, may serve purposes such as measuring reach.
Technically Necessary Cookies
Technically necessary cookies are required to provide essential functions of our Online Offering, such as session management, login, security functions, storing your cookie selection or preventing errors.
The processing is based on Art. 6 para. 1 lit. f GDPR and, insofar as the provision of an expressly requested function is concerned, Art. 5 para. 3 of Directive 2002/58/EC in conjunction with Art. 22 para. 2 LSSI-CE. Our legitimate interest consists in providing the Online Offering securely and reliably.
Optional Cookies
Analytics, convenience or other cookies that are not technically necessary are only used if you have expressly consented in advance. The legal basis is Art. 6 para. 1 lit. a GDPR in conjunction with Art. 22 para. 2 LSSI-CE.
A cookie banner is displayed when you first visit the site. There you can choose between “Accept all”, “Reject all” and “Settings”. Acceptance and rejection of optional cookies are presented in an equivalent manner. Without consent, no optional cookies will be set and no corresponding technologies will be loaded.
You can change or withdraw your decision at any time with effect for the future via the permanently accessible “Cookie Settings” link. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Your cookie selection is stored using the sc_cookie_consent cookie for 180 days. After this period expires or after you delete the cookies through your browser, your selection will be requested again.
We do not use affiliate, remarketing, retargeting or social media tracking cookies unless the current cookie configuration expressly states otherwise.
7. Newsletter
If you subscribe to our newsletter, we process your email address to send you regular information about our offers and activities. The legal basis is your consent pursuant to Art. 6 para. 1 lit. a GDPR.
Where technically configured, registration takes place using a double opt-in procedure. In this process, we store the date and time of registration and confirmation as well as the IP address used during registration in order to be able to demonstrate consent.
You may withdraw your consent at any time with effect for the future by using the unsubscribe link contained in each newsletter or by emailing
8. Contact, Event Bookings and Support
When you contact us, submit an event booking enquiry or use support, we process the data you provide to us. This may include, in particular, your name, email address, account data, communication content, booking information and, in the case of reports, information concerning the reported content.
The processing takes place:
- for enquiries relating to a contract or event booking, on the basis of Art. 6 para. 1 lit. b GDPR
- for voluntary enquiries where there is no pre-contractual or contractual relationship, on the basis of Art. 6 para. 1 lit. f GDPR; our legitimate interest consists in properly handling your enquiry
- where statutory obligations or the handling of legal violations are concerned, on the basis of Art. 6 para. 1 lit. c and lit. f GDPR
We generally retain support and enquiry data for 12 months after final processing. Longer retention may be necessary where required to comply with statutory obligations, investigate an incident or assert, exercise or defend legal claims.
Telephone calls are generally not recorded. Where necessary to clarify a matter, the content of the conversation may be documented in the form of a support ticket.
9. Gift Shop, Crowdfunding and Payments
When you make a purchase in our gift shop or make a payment as part of a crowdfunding campaign, we process the data required to process the purchase or payment. This may include, in particular, your name, billing and delivery address, email address, order information, payment amount, transaction data and payment status.
As a general rule, we do not ourselves process payment data in the form of complete card or account details where these are collected directly by the payment service provider selected. The privacy information of the respective payment service provider also applies to payment processing.
The processing is carried out to perform the contract and process the payment on the basis of Art. 6 para. 1 lit. b GDPR. Where measures to prevent fraud, ensure IT security or prevent payment defaults are necessary, processing is based on Art. 6 para. 1 lit. f GDPR. Our legitimate interest consists in providing secure and functional payment methods.
Stripe
The provider is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland.
Stripe processes payment and transaction data for payment processing, fraud prevention and, where applicable, identity verification. As part of international processing, Stripe may transfer data to third countries, including the United States. The applicable legal basis and safeguards for transfers to third countries are set out in Stripe’s privacy information.
Further information: Stripe Privacy Information
Segpay
The provider is Segregated Payments (Ireland) Limited, Suite 207 The Victorians, 15–17 Earlsfort Terrace, St. Kevin’s, Dublin 2, D02 YX28, Ireland.
Segpay processes payment and transaction data for payment processing, fraud prevention and, where applicable, identity verification. Data may be transferred to third countries, including the United States. Where no adequacy decision exists, a transfer will only take place where appropriate safeguards pursuant to Art. 46 GDPR are in place, in particular on the basis of standard contractual clauses and, where applicable, supplementary protective measures.
Further information: Segpay Privacy Information
We retain payment-related documents, in particular invoices, booking records and payment confirmations, pursuant to Art. 30 para. 1 of the Código de Comercio generally for six years from the last accounting entry. Tax-relevant documents are retained for at least the period specified under Art. 29 para. 2 lit. e and Art. 66 of Law 58/2003, General Tax Law (Ley 58/2003, General Tributaria), which is generally four years. Longer statutory retention obligations and the necessary preservation of legal claims remain unaffected.
10. User Accounts and Profiles
Guest Access
You can use parts of our Online Offering without a user account. In this case, we process the technical usage and log data described in this Privacy Policy, in particular to provide and secure the Online Offering.
When you begin a registration or booking process, we process the data you enter into the relevant input form. Where email confirmation is used, we store this data only insofar as necessary to carry out the confirmation procedure. If registration is not completed, we generally delete the data without undue delay unless retention is required for legal or evidentiary purposes.
Registered Users
Registering a user account and using functions that require registration may establish a user agreement. We process the data provided during registration and use in order to set up and manage the user account and provide the agreed platform functions. The legal basis is Art. 6 para. 1 lit. b GDPR.
Depending on the function, this may include, in particular, username, email address, age or age group, region, profile information, privacy settings, communication data, usage data and technical data. The data required in each case is indicated in the input fields. Additional profile information is voluntary unless expressly marked as mandatory.
The visibility of voluntary profile information is determined by the privacy settings available at the time. Please note that data you publish in an area visible to the public or to other members may be viewed by other users and may subsequently be processed by them.
We process usage and security data insofar as this is necessary for error analysis, fraud and misuse prevention, system security, enforcement of our terms of use and improvement of the platform. The legal basis is Art. 6 para. 1 lit. f GDPR. Our legitimate interest consists in operating the platform securely, reliably and free from misuse.
You can correct data in your user account yourself where technically provided for. For requests concerning rectification, deletion, access or other data protection matters, you can contact the association at
We generally delete the user account and the personal data stored in it when you request deletion or when the user relationship ends, unless statutory retention obligations, legitimate interests in legal defence or other compelling reasons prevent immediate deletion.
11. Authenticity and Age Verification
Membership in the Queen’s Club is exclusively available to persons who are at least 18 years old. To promote the protection of minors and prevent fake profiles, authenticity and age verification is a prerequisite for registering as a member.
As part of the verification, you may upload a photograph of yourself holding a sheet of paper showing the current date and your chosen username. The photograph is used exclusively for a one-time plausibility check to determine whether a real person is completing the registration and whether the person appears to be of legal age. No automated biometric analysis, biometric matching or permanent identification based on biometric characteristics takes place.
The processing is carried out to perform the membership you have requested and to protect against access by minors and abusive registrations, on the basis of Art. 6 para. 1 lit. b and lit. f GDPR. Our legitimate interest consists in protecting minors, maintaining the security of the association’s community and preventing fake profiles.
Where the specific design of the verification process in an individual case should involve the processing of special categories of personal data within the meaning of Art. 9 GDPR, we will obtain explicit consent pursuant to Art. 9 para. 2 lit. a GDPR before processing. Refusal to provide this optional consent will not have adverse consequences insofar as the verification can be carried out without processing special categories of personal data.
The uploaded photographs are stored on encrypted servers in Switzerland and automatically deleted immediately after completion of the verification, and no later than 24 hours after upload. We retain only technical evidence that the deletion has taken place, consisting of the verification ID and timestamp, for 12 months to fulfil our accountability obligation under Art. 5 para. 2 GDPR.
The photographs are not disclosed to third parties. Where technical service providers may have access to them, they act exclusively as processors bound by our instructions.
The guest area remains available without successful membership verification insofar as the relevant content and functions are enabled for this purpose.
12. Competitions and Surveys
When you participate in a competition or survey, we process the data required to conduct it. In the case of physical prizes, this may include, in particular, your name and delivery address.
The processing is carried out to conduct the competition or send the prize on the basis of Art. 6 para. 1 lit. b GDPR, provided that the participation terms establish a corresponding contractual relationship. Where participation is expressly based on consent, processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR.
We delete winners’ address data after dispatch and after a reasonable period for resolving delivery problems has elapsed, unless statutory retention obligations prevent this.
13. Recipients and Processors
We only disclose personal data where this is necessary and legally permissible. Recipients may include, in particular:
- Hosting and IT service providers
- Payment service providers
- Providers of security and content delivery services
- Communication and support service providers
- Tax advisers, banks, authorities or other bodies where there is a legal obligation to do so
- Legal advisers, courts or authorities where this is necessary to assert, exercise or defend legal claims or to comply with statutory obligations
Where service providers process personal data on our behalf, we conclude data processing agreements pursuant to Art. 28 GDPR where required.
We disclose personal data in particular where:
- you have given your consent, Art. 6 para. 1 lit. a GDPR
- the disclosure is necessary to perform the contract or implement pre-contractual measures, Art. 6 para. 1 lit. b GDPR
- we are legally obliged to do so, Art. 6 para. 1 lit. c GDPR
- the disclosure is necessary to protect our legitimate interests or to assert, exercise or defend legal claims and no overriding interests of the data subject oppose this, Art. 6 para. 1 lit. f GDPR
14. Google Analytics 4
Where you have expressly consented to analytics cookies through our cookie banner, we use Google Analytics 4 to analyse the use of our Online Offering. Without your consent, Google Analytics is not loaded and no Google Analytics cookies are set.
The provider in the European Union is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics may also transfer data to Google LLC in the United States.
Google Analytics processes, in particular, information about your usage behaviour, technical device and browser data, pages visited, events, approximate location data based on the IP address, as well as cookie-based or similar online identifiers. According to Google, IP addresses of users in the EU are not logged or stored as part of the processing; however, this does not mean that all processing operations are carried out anonymously.
The processing is carried out exclusively on the basis of your consent pursuant to Art. 6 para. 1 lit. a GDPR and Art. 22 para. 2 LSSI-CE. You may withdraw your consent at any time with effect for the future via “Cookie Settings”.
We have concluded the data protection and data processing terms provided for Google Analytics with Google. Where data is transferred to the United States or other third countries, the transfer is based on the applicable mechanism under Chapter V GDPR, in particular an adequacy decision where the recipient is certified under such a decision, or on the European Commission’s standard contractual clauses and, where applicable, supplementary protective measures.
Further information: Google Analytics – Privacy
15. Cloudflare
We use services provided by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, or the respective Cloudflare group company responsible. Cloudflare provides, in particular, a content delivery network, security functions, DDoS protection, web application firewall and, where applicable, bot management.
This may involve processing, in particular, IP addresses, DNS log data, technical browser and device information, security events, request data and performance data. The processing is based on Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in providing the Online Offering securely, quickly and reliably and in preventing cyberattacks and abusive access.
Technically necessary security cookies are used for bot detection, CAPTCHA and load balancing. These cookies are only used where they are necessary for the relevant security or performance function. The specific cookies used are transparently identified in the cookie banner or cookie settings.
Where Cloudflare transfers data to the United States or other third countries, the transfer takes place on the basis of the applicable safeguards under Chapter V GDPR, in particular an adequacy decision where applicable, or the European Commission’s standard contractual clauses and, where applicable, supplementary protective measures.
Further information: Cloudflare Privacy Policy
16. Your Rights
Subject to the statutory requirements, you have the following rights against us:
- Access to the personal data we process, Art. 15 GDPR
- Rectification of inaccurate data or completion of incomplete data, Art. 16 GDPR
- Erasure of personal data, Art. 17 GDPR
- Restriction of processing, Art. 18 GDPR
- Data portability, Art. 20 GDPR
- Objection to processing based on legitimate interests, Art. 21 GDPR
- Withdrawal of consent with effect for the future, Art. 7 para. 3 GDPR
- Right to lodge a complaint with a data protection supervisory authority, Art. 77 GDPR
To exercise your data protection rights, you can contact the I Love Me association, represented by its president Daniel Hauenstein, at
The data protection supervisory authority responsible for us in Spain is:
Agencia Española de Protección de Datos
Calle Jorge Juan, 6
28001 Madrid
Spain
You may also lodge a complaint with the data protection supervisory authority of your habitual place of residence, your place of work or the place of the alleged infringement.
17. Right to Object
Where we process personal data on the basis of Art. 6 para. 1 lit. f GDPR, you have the right under Art. 21 GDPR to object to such processing at any time on grounds relating to your particular situation.
We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Where personal data is processed for direct marketing purposes, you may object to such processing at any time without giving reasons.
18. Data Security
We use transport encryption via TLS for the transmission of data between your device and our systems. In addition, we implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
Our security measures are continuously adapted to technological developments and the respective level of risk.
19. Changes to this Privacy Policy
We may amend this Privacy Policy if our Online Offering, the services we use, our data processing activities or the legal situation change. The current version published on the Online Offering shall apply in each case.
The current version is dated 02/10/2026.
Deutsch
Español
English