Madeira Real Tours
Política de Privacidad

Última actualización:

This Privacy Policy explains how we collect, use, store, share and protect your personal data when you visit our website, contact us, book a tour or transfer, or otherwise interact with our services. We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), Portuguese Law n.º 58/2019 of 8 August (the national GDPR implementation act), and Portuguese Law n.º 41/2004 on the protection of personal data in electronic communications.

1. Data Controller

The controller responsible for the processing of your personal data (the “Controller”) is:

Chiana — Transportes e Turismo, Lda.

Sociedade por Quotas
NIPC: 511 127 928
RNAVT n.º 7638 (Registo Nacional das Agências de Viagens e Turismo)
RNAAT n.º 355/2018 (Registo Nacional dos Agentes de Animação Turística)
Trading as: Madeira Real Tours

Caminho do Lombo da Levada, n.º 9
9350-128 Ribeira Brava
Madeira, Portugal

Email: info@madeirarealtours.com
Telephone / WhatsApp: +351 925 087 214

We have not appointed a Data Protection Officer because our core activities do not require one under Article 37 GDPR. For any privacy-related matter, please contact us using the email address above.

2. Scope of this Policy

This Policy applies to personal data processed in connection with:

  • your visit to madeirarealtours.com and its subdomains;
  • enquiries made via our contact form, email, telephone or WhatsApp;
  • bookings made directly with us or through third-party platforms such as GetYourGuide, Viator and TripAdvisor Experiences;
  • the performance of our private tours, transfers and shore excursions;
  • the issuance of invoices and the fulfilment of our tax and accounting obligations.

3. Categories of Personal Data

Depending on how you interact with us, we may process the following:

3.1 Data you provide directly

  • Identification and contact data: first and last name, email address, telephone or WhatsApp number.
  • Booking data: service requested (tour, transfer, shore excursion), date, preferred start time, group size, pick-up location, tour interests, language preference.
  • Special category data — health: allergies and dietary requirements that you voluntarily disclose so we can plan a safe tour or meal selection (Article 9(2)(a) GDPR).
  • Free-text content: any additional information you choose to include in your message or special requests.
  • Billing data: name, address and tax number (NIF) where required for invoicing.

3.2 Data collected automatically

  • Server log data: IP address, date and time of the request, requested URL, HTTP status, referrer, browser and operating system. This data is generated automatically and is necessary to deliver the website securely.
  • Language preference: the locale you select (English, Portuguese, Spanish) is stored in your browser using the URL path. We do not use cookies for tracking, advertising or analytics.

3.3 Data received from third parties

  • Booking platforms: when you book through GetYourGuide, Viator or TripAdvisor Experiences, we receive the booking details and the contact data those platforms collect from you under their own privacy policies.
  • Reviews: if you publish a review on Google, TripAdvisor or another platform, we can read it under that platform’s public terms.

4. Purposes and Legal Bases

We process your personal data for the following purposes:

PurposeLegal Basis
Responding to enquiries, preparing quotesArt. 6(1)(b) GDPR — pre-contractual measures
Booking and delivering tours, transfers and shore excursionsArt. 6(1)(b) GDPR — performance of a contract
Processing allergy / dietary information for safe tour deliveryArt. 9(2)(a) GDPR — explicit consent
Invoicing, accounting and tax record-keepingArt. 6(1)(c) GDPR — legal obligation (Código do IVA, Código Comercial, LGT)
Server logs, IT security, fraud preventionArt. 6(1)(f) GDPR — legitimate interest in a secure website
Handling reviews, complaints and customer feedbackArt. 6(1)(f) GDPR — legitimate interest in service quality
Defending or asserting legal claimsArt. 6(1)(f) GDPR — legitimate interest in legal protection

We do not currently send marketing emails or newsletters and do not process your data for direct marketing purposes. Should this change in the future, we will obtain your prior consent in accordance with Article 6(1)(a) GDPR and Article 13(2) of Portuguese Law n.º 41/2004.

5. Contact Form

When you submit our contact form, the following fields are mandatory: service type, group size, name and email. All other fields are optional. Without the mandatory fields we cannot respond to your enquiry.

Submitting the form requires that you tick the privacy consent checkbox, which constitutes your acknowledgement of this Policy. The information provided is sent by email to our internal address info@madeirarealtours.com via our email service provider (see Section 11).

6. Email, Telephone and WhatsApp

If you contact us by email, telephone or WhatsApp, we process the data you send us to handle your enquiry. The content of email correspondence is retained in our mail provider’s mailbox until it is no longer needed for the purposes for which it was collected.

WhatsApp is operated by Meta Platforms Ireland Limited. When you click our WhatsApp button you leave this website and your communication is governed by Meta’s own privacy policy. We have no control over the data Meta processes about you outside our messages. You can read Meta’s policy at whatsapp.com/legal/privacy-policy-eea.

7. Bookings via Third-Party Platforms

We accept bookings through the following Online Travel Agencies (“OTAs”):

  • GetYourGuide — GetYourGuide Deutschland GmbH, Sonnenburger Straße 73, 10437 Berlin, Germany. Privacy policy
  • Viator — Viator, Inc. (a Tripadvisor company), 400 1st Avenue, Needham, MA 02494, USA. Privacy policy
  • TripAdvisor Experiences — Tripadvisor LLC, 400 1st Avenue, Needham, MA 02494, USA. Privacy policy

When you book through one of these platforms, the OTA acts as the initial data controller and forwards the booking details to us so that we can deliver the service. From that moment we act as the controller for the personal data we receive. Each OTA has its own privacy policy, which governs its collection of your data on its own website or app.

Viator and TripAdvisor are based in the United States. The transfer of booking data from these platforms to us takes place under the GDPR rules applicable to international data transfers (see Section 12).

8. Payments

We accept the following payment methods:

  • MB WAY and Multibanco — operated by SIBS — Forward Payment Solutions, S.A., Lisbon, Portugal.
  • Bank transfer (SEPA) — processed via our Portuguese bank account.
  • Cash — paid in person to your guide or driver.

We do not process card data on this website. Where payment is made through MB WAY, Multibanco or bank transfer, the respective payment service provider acts as an independent controller for the technical processing of the transaction. We receive only the transaction reference and confirmation of receipt; we never see your full card or banking details.

For cash payments, no electronic payment data is collected, but a receipt or invoice is issued under Portuguese tax law.

9. Health-Related Information (Allergies and Dietary Requirements)

Where you disclose allergies, intolerances or dietary requirements, this constitutes a special category of personal data under Article 9 GDPR. We process this information solely to:

  • ensure your safety during the tour or transfer;
  • coordinate suitable food and beverage choices at the restaurants or stops included in your tour;
  • inform our guides and drivers of relevant medical considerations.

The legal basis is your explicit consent under Article 9(2)(a) GDPR. Providing this information is entirely voluntary, but without it we cannot accommodate specific dietary or health needs. You may withdraw your consent at any time by writing to info@madeirarealtours.com. Withdrawal does not affect the lawfulness of processing prior to the withdrawal.

Health-related information is deleted after completion of your tour, save where retention is required to defend against possible legal claims.

10. Photographs and Video Recordings

We respect your right to your own image, as protected by Article 79 of the Portuguese Civil Code and Article 8 of the Charter of Fundamental Rights of the European Union.

We do not systematically photograph or film our guests during tours. The photographs and videos shown on our website, in our gallery and on our social media channels feature our team, members of our personal circle who have consented, or scenic views without identifiable persons.

If a guide takes an informal photograph during a tour at your request or with your prior agreement, the photograph is used only for the purpose you authorised. You may at any time ask us to delete or refrain from using any photograph in which you are identifiable, by writing to info@madeirarealtours.com.

11. Recipients and Processors

We only share your personal data where necessary to operate our services and only with carefully selected recipients bound by appropriate data protection obligations (typically a Data Processing Agreement under Article 28 GDPR). Categories of recipients include:

  • Website hosting provider: {{ HOSTING_PROVIDER_NAME, ADDRESS, COUNTRY }}. The hosting provider stores the website files and processes server log data on our behalf.
  • Email service provider: {{ EMAIL_PROVIDER_NAME, ADDRESS, COUNTRY }}. Used to send and receive email correspondence, including form submissions.
  • Online travel agencies: GetYourGuide, Viator and TripAdvisor Experiences, where you book through their platform (see Section 7).
  • Payment service providers: SIBS — Forward Payment Solutions, S.A. (MB WAY, Multibanco) and our bank, for the technical processing of payments (see Section 8).
  • External accountant / certified bookkeeper (Técnico Oficial de Contas), for the fulfilment of accounting and tax obligations.
  • Public authorities: the Autoridade Tributária e Aduaneira, Turismo de Portugal, the CNPD and any other competent authority, where we are legally required to disclose data.
  • Legal advisors and insurers: where necessary to assert or defend legal claims, or to handle insurance matters.

A current list of our processors is available upon request from info@madeirarealtours.com.

12. International Data Transfers

Some of our processors and partners (notably Viator, TripAdvisor and, where applicable, our hosting or email provider) are established outside the European Economic Area (“EEA”), in particular in the United States. In such cases we ensure an adequate level of protection through:

  • the European Commission’s adequacy decision under the EU–U.S. Data Privacy Framework (10 July 2023), where the recipient is certified; or
  • Standard Contractual Clauses approved by the European Commission under Article 46(2)(c) GDPR; together, where appropriate, with supplementary technical and organisational measures.

You may request a copy of the safeguards in place by contacting us at info@madeirarealtours.com.

13. Data Retention

We retain personal data only for as long as is necessary for the purposes set out above. Specifically:

  • Contact enquiries that do not lead to a booking: up to 6 months after the last interaction.
  • Booking and contract data: for the duration of the contract and afterwards for the applicable limitation periods (typically up to 3 years under Article 309 of the Portuguese Civil Code; 2 years for package travel claims under Decreto-Lei n.º 17/2018).
  • Invoices and tax-relevant documents: 10 years, as required by Article 123(4) of the Portuguese VAT Code (Código do IVA) and Article 40 of the General Tax Law (Lei Geral Tributária).
  • Email correspondence: as long as it is needed for the purposes for which it was collected, and afterwards in line with the limitation periods above.
  • Server logs: typically up to 90 days, unless a longer retention is required to investigate a security incident.
  • Health-related information (allergies / dietary): deleted after completion of the tour, unless retention is necessary to defend against legal claims.

Where data must be retained for legal, regulatory or evidential reasons, its processing is restricted to those purposes until the relevant retention period expires.

14. Your Rights

Subject to the conditions of the GDPR, you have the following rights in relation to your personal data:

  • Right of access (Art. 15 GDPR) — to obtain confirmation of whether we process your data and a copy of it.
  • Right to rectification (Art. 16) — to have inaccurate or incomplete data corrected.
  • Right to erasure (Art. 17) — to have your data deleted, where one of the legal grounds applies.
  • Right to restriction (Art. 18) — to have processing restricted in certain circumstances.
  • Right to data portability (Art. 20) — to receive your data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21) — to object to processing based on legitimate interests.
  • Right to withdraw consent (Art. 7(3)) — at any time, without affecting the lawfulness of processing carried out before withdrawal.
  • Right not to be subject to automated decision-making (Art. 22).

To exercise any of these rights, please contact us at info@madeirarealtours.com. We will respond within one month of receipt of your request, in accordance with Article 12(3) GDPR. We may ask you to verify your identity before responding to a request.

15. Right to Lodge a Complaint

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with the competent supervisory authority. In Portugal, this is:

Comissão Nacional de Proteção de Dados (CNPD)

Av. D. Carlos I, 134 — 1.º
1200-651 Lisboa, Portugal
Telephone: +351 213 928 400
Email: geral@cnpd.pt
Web: www.cnpd.pt

If you reside in another Member State of the European Economic Area, you may alternatively lodge a complaint with the supervisory authority of your place of residence, place of work or place of the alleged infringement.

16. Children

In accordance with Article 16 of Portuguese Law n.º 58/2019, the processing of personal data of children below the age of 13 in connection with information society services is lawful only with the consent of the holders of parental responsibility. Where minors take part in our tours, we process only the data strictly necessary for safety and service delivery, provided by the accompanying parent or legal guardian.

17. Cookies and Similar Technologies

This website does not use cookies for tracking, advertising or analytics. We do not embed third-party scripts that store information on your device. Self-hosted web fonts are loaded from our own servers; we do not transmit your IP address to Google Fonts or any other font service.

Technically strictly necessary local storage may be used for basic site functionality (such as remembering your language preference). Under Article 5(3) of the ePrivacy Directive, transposed in Portugal by Article 5 of Law n.º 41/2004, such storage does not require prior consent.

Should we introduce non-essential cookies or trackers in the future, we will obtain your prior consent through an appropriate consent mechanism before any non-essential data is stored or accessed on your device.

18. External Links and Social Media

Our website contains plain hyperlinks to external services such as Google Maps, Instagram, Facebook, TripAdvisor, Google Reviews and WhatsApp. These are not embedded; no script or pixel from those providers is loaded before you click. Once you click, you leave our website and the destination provider’s own privacy policy applies. We are not responsible for the content or data processing of any third-party site.

19. Security

We apply technical and organisational measures appropriate to the risks of processing, in line with Article 32 GDPR. The website is served over TLS (HTTPS); access to our systems is restricted to authorised staff; we use up-to-date software and review our processors regularly. No method of transmission over the internet is, however, fully secure, and we cannot guarantee absolute security.

20. Automated Decision-Making

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR.

21. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal requirements or processing practices. The current version is always available at this URL, with the date of the last update shown at the top of the page. Where a change materially affects your rights, we will inform you by appropriate means.

22. Governing Language

This Privacy Policy is provided in English. A Portuguese version is available on request. In the event of any divergence between the language versions, the Portuguese version shall prevail.

Em caso de litígio, o consumidor pode recorrer a uma Entidade de Resolução Alternativa de Litígios de consumo. Mais informações em Portal do Consumidor www.consumidor.pt. Lei n.º 144/2015.