Privacy Policy
Last updated: 26 August 2026
1. Data controller
Dry Holidays SL
CIF B67894493
Calle Tigre 8A
Icod de los Vinos, 38340
Tenerife, Canary Islands, Spain
Privacy contact: [email protected]
2. Our commitment
We do not sell your data. We do not use your data for advertising or build an advertising profile on you. We do not currently use analytics cookies.
3. What we process, why, and the lawful basis
Local browser data: Chat threads and your boundary acknowledgement are stored in your browser's local storage so that the chat can work on your device and remember that acknowledgement. This data is not stored in an application database operated by us. Lawful basis: legitimate interests in providing a functioning, consistent service, and where applicable performance of the service you request.
Chat messages sent to the AI service: When you send a message, its content and the minimum conversation context needed to generate a reply are sent to OpenAI through its API. This is necessary to provide the chat response you request. Lawful basis: performance of the service you request.
Technical and security data: Cloudflare processes technical information such as IP address, request timestamp, device/browser information, and security events to host, protect, and operate the site. Lawful basis: legitimate interests in security, fraud prevention, and reliable operation.
Analytics: We do not currently use analytics cookies. If this changes, we will update this Privacy Policy and Cookie Policy before enabling them.
4. AI processing detail
When you use the chat, the message you enter and the conversation context needed to generate a reply are sent to OpenAI through its API. We do not operate a database of your chat history on our own servers. OpenAI states that API business data is not used to train its models by default. OpenAI may retain API inputs and outputs for a limited period, typically up to 30 days, for abuse monitoring and service protection, unless a longer retention period is required by law. Please avoid entering sensitive personal, medical, financial, or identifying information in the chat. See OpenAI's Enterprise Privacy information.
5. Processors
Cloudflare (hosting, security)
OpenAI (AI response generation)
6. International transfers
Our service providers may process personal data outside the European Economic Area, including in the United States. Where required, transfers are made using an applicable lawful transfer mechanism provided by the relevant service provider, such as Standard Contractual Clauses or another recognised safeguard. You can contact us using the details above for further information about the safeguards that apply.
7. Retention
Cloudflare technical logs: retained according to the account configuration and Cloudflare's service settings, and no longer than necessary for security, troubleshooting, and legal obligations.
OpenAI API data: OpenAI may retain API inputs and outputs for a limited period, typically up to 30 days, for abuse monitoring and service protection, subject to its own policies and legal obligations.
Chat history: stored locally until you clear it.
Boundary acknowledgement: stored locally until you clear it.
8. Automated decision-making
The chat uses an AI system to generate responses. It does not make decisions that produce legal effects or similarly significant effects about you. The chat is not a diagnostic, clinical, employment, credit, insurance, or eligibility decision-making service.
9. Your rights
Under GDPR, you have the right to access, correct, delete, restrict, port, and object to processing of your personal data. To exercise these rights, contact us using the details above.
You may also lodge a complaint with the Spanish supervisory authority: AEPD.
10. Managing and deleting local data
You can remove chat threads and the boundary acknowledgement stored on your device by clearing browser storage for this domain. Because we do not maintain an application database of chat history, we cannot retrieve or delete chat history that exists only in your browser.
Messages submitted to the chat are processed by OpenAI through its API as described above. If you have a privacy question or wish to exercise a data-protection right in relation to processing we control, contact us using the privacy contact details above.
Local reflection notes (optional). If you choose to use the "Your Private Reflection" text boxes on pages such as Movements or Self-Checks, your notes are stored only in your browser's local storage on this device. They are never sent to our servers or to any third party. You can clear them at any time using the "Clear my notes" button on each page, or by clearing your browser data.
11. Shadow Day booking data
If you book a Shadow Day, we collect additional information beyond ordinary chat use: your name, contact details, date of birth, any health-relevant information you disclose in connection with the day (for example, mobility limitations or allergies), and identity documentation used to confirm attendance.
Why we collect it: to arrange and conduct the day itself, to confirm your identity before the booking is finalised, to handle cancellations or rescheduling, and to meet our own legal and safety obligations.
Lawful basis: performance of the contract you enter into when booking; legitimate interests in the safety of both parties; and, for health-relevant information specifically, your explicit consent, since this is treated as a special category of personal data under GDPR.
Retention: Identity documentation used to confirm attendance is deleted the day after the Shadow Day takes place, subject to any legal, accounting, insurance, dispute, or incident-preservation obligations confirmed by our legal counsel — it is held only as long as needed to verify who is attending and meet those obligations, and no longer. Other booking data (name, contact details, and payment records) is retained for as long as needed for ordinary accounting and legal record-keeping, in line with Spanish tax and business obligations, and then deleted.
Your rights for this data: the same rights described in Section 9 apply — access, correction, deletion, restriction, portability, and objection. Given the sensitivity of identity documentation, requests relating to Shadow Day data will be handled directly by James, not through any automated process.
Third parties: Shadow Day booking data may be shared with a payment processor (to handle payment) and, if engaged, professional advisors such as legal or insurance providers, solely as needed to operate the booking. It is never sold, and never used for marketing without your separate, explicit consent.
Full terms governing a Shadow Day booking, including cancellation and liability, are set out in the separate Shadow Day Participation Agreement provided at the time of booking.
12. Age restriction
This site is for adults only. We do not knowingly collect data from children under 18.
For information about cookies and similar technologies, see our Cookie Policy.
Operated by Dry Holidays SL · CIF B67894493 · Spain