Privacy Policy
Last updated: August 31, 2026
This Privacy Policy is intended for the travelers, users and potential customers of WAVES & LOVE's products, services and platforms, and explains, in a transparent manner, how their personal data is processed.
1. Data Controller
This Privacy Policy applies to the website www.wavesnlove.com, published by WAVES & LOVE, Unipessoal, Lda., with registered office at Rua Cidade de São Paulo, n.º 25, 4.º A, 2735-656 Agualva-Cacém, Sintra, Portugal, tax number (NIPC) 519518225, hereinafter "WAVES & LOVE".
WAVES & LOVE is the data controller for personal data within the meaning of Regulation (EU) 2016/679 (GDPR) and Portuguese Law No. 58/2019 of August 8.
Contact for privacy matters:
- Address: Ericeira, Sintra, Portugal
- Phone: +33 7 59 70 81 91
- Email: contact@wavesnlove.com
The entity responsible for collecting and processing personal data is WAVES & LOVE, which, within the scope of the contractual or pre-contractual relationship and according to the service requested, will collect and process the personal data essential for that purpose.
WAVES & LOVE has not appointed a Data Protection Officer. The need for such an appointment is reassessed in light of Articles 37 to 39 of the GDPR; until then, requests should be directed to the privacy contact above.
2. Categories of Personal Data Processed
WAVES & LOVE may collect and process the following categories of data:
- Identification and travel data: first name, surname and strictly necessary fields from an identification document, passport or visa; a full copy is not routinely collected when partial information or verification without retention is sufficient. A copy of the national ID card is only made in the cases and under the conditions legally permitted.
- Contact data: email, phone number.
- Communication, support, complaints and public review data: messages, requests and responses; rating, text, destination or mission, date, display name or pseudonym, and authenticity and moderation records.
- Browsing data: cookies, IP address, online identifiers.
- Data necessary for organizing trips: booking, stay, activities, logistical and administrative requirements, necessary fields from travel documents, and minimal proof of the existence and essential coverage of insurance.
- Marketing data: email for sending newsletters.
- Billing and booking data: where applicable, data necessary for issuing accounting documents.
- Fitness and health-requirement data: by default, only functional "fit / not fit" confirmation or confirmation of meeting a requirement, without diagnosis, medical history or copy of a certificate. Individual confirmation is treated as health data whenever it allows an inference about physical or mental condition, in which case Articles 6 and 9 of the GDPR apply cumulatively.
- Minor-protection data: confirmation of awareness of the rules and, where legally applicable, operational indication from the responsible entity that a suitability check has been completed, without communicating the content of any criminal record. No criminal declaration is collected for merely deterrent purposes.
- Public review data: rating, comment, experience reviewed, date, optional display name or pseudonym, internal link to the booking, and complaint and moderation records; these are not used, manually or automatically, for profiling, pricing, bookings, participation or restriction of access.
3. Purposes and Legal Bases of Processing
Personal data is processed lawfully, fairly and transparently. The purposes and their respective legal bases are:
3.1 Managing Contacts and Responding to Requests
Purpose: managing requests sent through the "Contact us" section.
Data processed: first name, surname, email, phone, message.
Legal basis: steps taken prior to entering into a contract (Art. 6(1)(b) GDPR).
3.2 Marketing and Newsletter
Purpose: sending information about products, services, destinations and news.
Data processed: email.
Legal basis: consent (Art. 6(1)(a) GDPR).
3.3 Cookies and Browsing Data
Purpose: improving the browsing experience, personalizing content and analyzing statistics.
Data processed: online identifiers, cookies.
Legal basis: consent for non-essential cookies; strictly necessary cookies benefit only from the exception under Article 5 of Law No. 41/2004, and any subsequent processing of personal data must have its own basis under Article 6 of the GDPR.
3.4 Organizing Trips and Activities
Purpose: booking, coordination and execution of trips, stays and activities.
Data processed: only the booking, traveler, document, insurance, accommodation, activity and logistics data necessary for pre-contractual steps, contract performance, assistance and compliance with legal obligations.
Legal basis: pre-contractual steps or performance of the contract with respect to the contracting traveler (Art. 6(1)(b) GDPR); with respect to non-contracting companions, the specifically applicable legal obligation or a documented legitimate interest, with data minimization, a balancing test and information under Article 14.
3.5 Compliance with Legal Obligations
Purpose: compliance with tax, accounting, administrative or security obligations.
Legal basis: legal obligation (Art. 6(1)(c) GDPR).
3.6 Health Data (Art. 9 GDPR)
Purpose: confirming functional fitness or compliance with a health requirement objectively necessary for the safe performance of a specific activity.
Data processed: by default, only confirmation of fitness or compliance, preferably verified without retention; where it allows an inference about physical or mental condition, it is treated as health data. No diagnosis, detailed medical information or full copies are requested, except where specifically and documentedly required by law.
Legal basis: a specifically documented basis under Article 6 and a specifically applicable condition under Article 9(2) of the GDPR. Explicit consent is used only when specific, informed, demonstrable, withdrawable and genuinely free, without conditioning services that do not depend on the data; absent this dual basis, the confirmation is not collected.
Retention: only for the minimum period of the verification and activity; wherever possible, no document is retained, only the functional result, with restricted access and subsequent deletion.
3.7 Protection of Minors and Suitability Verification
Purpose: preventing risks to minors and complying, for each mission, with the rules of the responsible entity and the applicable territorial and substantive law.
Data processed by WAVES & LOVE at launch: commitment to the protection rules and, where necessary, the operational status "verification completed" transmitted by the competent entity, without certificate, conviction, reason or non-existence statement.
Legal basis: Law No. 113/2009 is invoked only when the activity involves regular contact with minors and WAVES & LOVE is substantively the recruiting or responsible entity; in that case, Articles 6(1)(c) and 10 of the GDPR apply together with Article 2 of that law. Legitimate interest, contract or consent do not replace the authorization required by Article 10.
Retention: the responsible NGO collects directly the document required by the applicable law. If WAVES & LOVE is the legally obligated entity, it is preferably limited to viewing and to a minimal record of date, purpose, operational result and next check, with confidentiality, restricted access and a documented retention period.
3.8 Public Reviews
Purpose: enabling optional reviews of destinations and missions, verifying correspondence with the actual experience, preventing fake reviews, moderating content and providing information to other users.
Data processed: rating, comment, destination or mission, date, optional display name or pseudonym, internal link to the booking, and complaint, response and moderation records. By default, the review does not reveal the account holder's identity.
Legal basis: specific and demonstrable consent for public posting; documented legitimate interests for authentication, fraud prevention and moderation, following a balancing test; legal obligation only where specifically applicable.
Transparency: the interface identifies public fields, recipients, possible indexing, ranking method, moderation and incentives. No contact details, health or criminal data, or data of minors or third parties should be included. There is no manual or automatic use for behavioral scoring, profiling, pricing, bookings, participation or future access.
Rights: the author may edit or withdraw the review, request removal or anonymization, exercise their GDPR rights and challenge moderation decisions. Positive and negative reviews are subject to the same criteria. Reuse in advertising or on social media requires its own information and legal basis.
4. Recipients of the Data
Personal data may be shared with:
- Duly authorized WAVES & LOVE staff; for reviews, the public and search engines receive only the fields whose publication was specifically consented to.
- Partner accommodation providers and partner NGOs, only with respect to the data necessary for the booking, safety, activity or legal obligation, and according to documented roles.
- Technical service providers, including newsletter delivery, under a contract in accordance with Art. 28 GDPR.
- The insurer or distributor identified for the CHAPKA CAP EXPLORER product, when the traveler subscribes directly; it acts under its own privacy information, and no data is sent by WAVES & LOVE without a prior basis and prior information.
- Dispute-resolution bodies, courts, authorities, insurers and advisors, only when necessary for a claim, defense of rights or a legal obligation.
- Payment service providers, including Stripe as indicated at checkout, with respect to the data necessary for authorization, capture, fraud prevention and refunds; and public authorities, when required by law.
Transfers to third parties are strictly limited to the intended purposes and applicable legal bases, including contract performance, compliance with legal obligations, legitimate interest or consent, where required.
Irreversibly anonymized data may be used for statistical or marketing purposes.
5. International Transfers
Where the organization of trips involves transferring data to entities located outside the European Economic Area, WAVES & LOVE ensures that:
- an applicable adequacy decision or appropriate safeguard exists, including Standard Contractual Clauses, following a documented assessment of the country, recipient and need for supplementary measures;
- the data subject is informed about the country, recipient, legal basis and how to obtain a copy of the safeguard; derogations under Article 49 are exceptional and do not support repeated transfers. Only the minimum data necessary is transferred.
6. Cookies
The Website uses cookies to improve browsing and personalize the user experience.
Non-essential cookies are used only with prior consent, collected through the cookie banner.
Users may change their cookie preferences at any time through the banner or their browser settings.
The detailed Cookie Policy is available at Cookie Policy.
7. Data Subject Rights
Under applicable law, users have the following rights:
- Access to their personal data.
- Rectification of inaccurate data.
- Erasure of data, under legal terms.
- Restriction of processing.
- Objection to processing.
- Data portability.
- Withdrawal of consent, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise these rights, please contact:
- Address: Ericeira, Sintra, Portugal
- Email: contact@wavesnlove.com
For security purposes, additional information is only requested, proportionately, where there is reasonable doubt as to identity. If, exceptionally, a copy is required, unnecessary fields are hidden, access is restricted and the copy is destroyed immediately after verification.
8. Personal Data of Minors
Data of minors is processed only when necessary for the trip, safety or a legal obligation, under the involvement of whoever holds parental responsibility or is legally authorized. At launch, minors do not post public reviews.
Information is presented in age-appropriate language; there is no behavioral scoring, profiling, automated decision-making or marketing directed at minors. Access and sharing are limited, and the representative may exercise rights, without prejudice to the minor's own personal rights according to their age and maturity.
9. Data Security
WAVES & LOVE implements appropriate technical and organizational measures, including:
- encryption in transit and, where appropriate to the risk, at rest;
- access control based on functional need, authentication and periodic review;
- logging, backups, vulnerability management and incident response proportionate to the risk;
- internal policies, training, contracts with providers and regular effectiveness testing.
These measures aim to ensure the integrity, confidentiality and availability of the data.
10. Data Retention Period
Personal data is retained only for the period necessary for the purposes of processing:
- Requests and prospective customers: for the time necessary to respond and, where justified, for a limited evidentiary or limitation period, with review and deletion of inactive contacts.
- Contractual and complaint data: during performance and for the legal periods of liability, evidence and limitation applicable; data relating to price reductions or compensation is kept for at least two years. Exceptional copies of identification or insurance documents are destroyed immediately after the necessary verification or transmission, with only the minimum fields and verification status kept until the end of the trip or a justified incident.
- Marketing: ceases immediately upon withdrawal of consent or objection. Only a minimal suppression list is kept, for a justified period, to prevent further unwanted contact.
- Identity verification for exercising rights: the exceptional copy is destroyed immediately after verification; only a minimal record of the request and validation is kept for the period necessary to prove compliance.
- Billing data: 10 years.
- Functional or health confirmation: only until the verification or activity is completed and, wherever possible, without a document; longer retention only in the event of a specifically documented incident, legal obligation or defense of rights.
- Suitability: the minimal verification record is kept for the period required by applicable law.
- Reviews: positive and negative reviews remain published for twenty-four months or until withdrawn, if earlier; minimal proof of consent, authenticity and moderation is kept for twelve months after removal, except in the case of documented litigation or legal obligation.
11. Complaints
Users may file a complaint with the Comissão Nacional de Proteção de Dados (CNPD), Portugal's national data protection authority, at: https://www.cnpd.pt
12. Changes to this Privacy Policy
WAVES & LOVE may update this Privacy Policy at any time as necessary. The updated version will be published on the Website.
Last updated: August 31, 2026
