RoundPlan processes personal data in two situations: as controller, the data of agency staff who create an account (this policy covers that); and as processor, the data agencies enter about their own clients and travelers, under the Data Processing Agreement (DPA) signed with each customer.
Data is kept for the duration of the contractual relationship and, afterwards, for the applicable legal periods. Data processed on the basis of consent is kept until consent is withdrawn.
The full list of sub-processors involved in the data agencies handle about their own clients, with locations and applicable safeguards, is in Annex III of the Data Processing Agreement (DPA).
Some providers may process data outside the EEA, in which case appropriate safeguards apply, such as the Standard Contractual Clauses. Data is not shared with other third parties except by legal obligation.
You may exercise your rights of access, rectification, erasure, objection, restriction and portability, and withdraw consent, by writing to support@roundplan.io. You may also lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
RoundPlan applies reasonable technical and organisational measures to protect data against unauthorised access, loss or alteration.
This policy may be updated. The version in force is the one published on the site, showing the last-updated date.