This policy explains how Viaondo processes the personal data of visitors to this website and of the people who use the Viaondo dashboard on behalf of a travel agency. If your agency has sent you a trip through Viaondo, go straight to the section If you are a traveler.
Controller
- Controller: [[OWNER: razón social]]
- Tax ID (NIF): [[OWNER: NIF/CIF]]
- Registered office: [[OWNER: domicilio social]]
- Contact email: [[OWNER: email de contacto]]
- Data protection officer: [[OWNER: delegado de protección de datos, si existe]]
Viaondo is the controller of website visitors’ data and of agency users’ account data. The data of travelers and clients that an agency manages in Viaondo is that agency’s responsibility: Viaondo processes it on the agency’s behalf, as a processor (article 28 GDPR), under the data processing agreement.
What data we process
If you visit the website
We do not ask for any data to browse the website. We only use one technical cookie, PARAGLIDE_LOCALE, which remembers the language you choose; details are in the cookie policy. We do not use analytics or advertising tools. If we enable visitor analytics in the future, it will be our own, aggregate and cookieless, and we will say so here.
Like any web server, ours receives your IP address and the technical data your browser sends so that it can show you the pages. We do not use them to identify you or to build profiles.
If you write to us or request a demo, we process the data you give us (for example, your name, your email, your agency’s name and your message) to reply to you.
If you use Viaondo on behalf of an agency
- Account data: name, email, password (stored only as a hash, never in plain text), preferred language and theme, and your role in the agency.
- Agency data: trading and legal name, contact details, brand elements (logo, color, WhatsApp, review link) and, where applicable, billing details.
- Service usage data: activity log (for example, who publishes or changes a trip and when), number of documents processed with AI import, and trial or subscription status.
- Technical security data: the IP address and browser associated with each signed-in session, and temporary request counters that limit abusive attempts.
- Communications: the messages you exchange with our support team.
The data of travelers and clients that you enter in Viaondo is not covered by this section but by the data processing agreement, because your agency is its controller.
Why we use the data and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating and managing your account and your agency’s account, providing the service and sending you the necessary emails (verification, sign-in, invitations and service notices) | Performance of the contract (art. 6.1.b GDPR). If your agency invited you, our legitimate interest in providing the service it has subscribed to (art. 6.1.f GDPR) |
| Handling your questions and your support or demo requests | Performance of the contract or pre-contractual steps (art. 6.1.b GDPR); if you are not a customer, our legitimate interest in replying to you (art. 6.1.f GDPR) |
| Issuing invoices and meeting tax and accounting obligations | Compliance with legal obligations (art. 6.1.c GDPR) |
| Protecting the service: account security, abuse prevention and fair use enforcement | Legitimate interest (art. 6.1.f GDPR) |
| Remembering your language and theme | Legitimate interest in showing you the website and the dashboard as you set them up (art. 6.1.f GDPR) |
| Sending you marketing communications about Viaondo | Consent (art. 6.1.a GDPR), which you can withdraw at any time |
Where the legal basis is legitimate interest, you can object to the processing as explained below. Every marketing communication includes an easy way to unsubscribe.
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. AI import only proposes booking data that a person at your agency reviews before using it.
How long we keep the data
- Account and agency: while the account is active. After cancellation, we keep them for [[OWNER: plazo de conservación tras la baja]] so that you can request a copy of your data, and then delete them.
- Invoices and accounting data: for the periods required by tax and commercial law (generally six years).
- Technical session data: while needed for account security; at the latest, it is deleted when the account is deleted.
- Inquiries: for as long as needed to handle them.
- Marketing communications: until you withdraw your consent.
- Cookies: for the period stated in the cookie policy.
Where the law requires us to keep data for longer, or while liability arising from the processing may be claimed, we will keep it blocked and use it only for that purpose.
Who we share the data with
We do not sell your data or share it with third parties for marketing purposes. We only share it:
- with the providers that help us deliver the service (server, database and files, email delivery), which process the data on our behalf under contract; the list is on the sub-processors page;
- with the entity that handles payments, where applicable;
- with public authorities and courts, where there is a legal obligation.
Within your agency, other team members can see your name, your email and the changes you make to trips.
The places map in the dashboard loads from OpenStreetMap’s servers. When it is shown, your browser connects directly to those servers, and OpenStreetMap receives your IP address.
International transfers
We do not intend to transfer data outside the European Economic Area. The database and files are hosted on Cloudflare with European Union jurisdiction, emails are sent from Resend’s EU region (Ireland), and the application server is located at: [[OWNER: proveedor y ubicación del VPS]]. The location of each provider is shown on the sub-processors page.
If a provider ever had to process data outside the European Economic Area, it would only do so with the safeguards required by the GDPR, such as a European Commission adequacy decision or standard contractual clauses.
Your rights
You can exercise the following rights at any time:
- access, to find out what data about you we process;
- rectification, to correct inaccurate or incomplete data;
- erasure, to ask us to delete your data;
- objection, to have us stop processing it where the basis is legitimate interest or for marketing purposes;
- restriction, to have us keep it without using it while a claim is resolved;
- portability, to receive the data you gave us in a structured, commonly used format.
You can also withdraw your consent at any time, without affecting earlier processing.
To exercise them, write to us at [[OWNER: email de contacto]] stating which right you wish to exercise. If we have reasonable doubts about your identity, we may ask you for additional information to confirm it. We will reply within one month, which may be extended by two further months if the request is complex; in that case we will let you know.
If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency, AEPD (www.aepd.es).
Security
We apply technical and organizational measures appropriate to the risk, including:
- TLS encryption on all connections;
- isolation between agencies: every request checks that you belong to the agency whose data it asks for;
- files in private storage, with no public addresses;
- passwords handled by the authentication library and stored only as hashes;
- trip links with 256 random bits, of which we store only a hash;
- technical logs without trip content, email addresses or links;
- security headers, such as a Content-Security-Policy and a no-referrer policy, which prevents other sites from receiving the address of the page you come from.
Minors
Viaondo is a service for professionals and is not aimed at minors. Dashboard accounts are for adults only. If an agency includes data about underage travelers in a trip, it is that agency, as controller, that must have a valid legal basis to do so.
Changes to this policy
We may update this policy when the service or the law changes. The date of the last update is shown on this page. If the change is significant, we will tell registered users by email before it applies.
If you are a traveler
This section is for you if your travel agency has sent you your trip through Viaondo.
Who processes your data
Your agency is the controller of your trip data: it decides what data to include and what to use it for. Viaondo processes it on your agency’s behalf, as a processor, only to provide the service to the agency, and does not use it for its own purposes. If your agency turns on email notices, we will send you an email on its behalf when it publishes changes to your trip.
What your agency sees
The traveler app has no ads and no third-party trackers. So that your agency knows your trip has reached you properly, the app records these events:
- that you opened the trip;
- that you saved it offline;
- which documents you viewed;
- that you applied an update;
- that you added the trip or a booking to your calendar;
- that you completed the pre-trip checklist;
- that the app showed you how to add it to your home screen.
If you use a group link, these events are anonymous. If you use a personal link, your agency sees them with your name. If you send a rating at the end of the trip, your agency receives the score and your comment. The app does not record your location or device data, does not store your IP address with these events and does not use cookies.
What is stored on your device
The first time you open the trip with a connection, the app saves a copy on your phone (itinerary, addresses and documents) so that it works offline. It also saves your preferences, such as the language, the items you tick on the pre-trip checklist and the tips you have already seen. Everything stays in your browser’s storage. You can delete the offline copy from the app itself, and all of this data by clearing the site’s data in your browser.
If your agency revokes the link or replaces it with a new one, the old link stops working. The app deletes the saved copy the next time it is opened with a connection, but nobody can delete it remotely while the device stays offline.
Maps and other services
The app’s street map loads from OpenStreetMap’s servers. When it is shown, your device connects directly to those servers: OpenStreetMap receives your IP address and the map areas being loaded, but not your trip link. The rest of the app works without that service.
If you open an address in your maps app, or contact your agency by WhatsApp or email from the app, those services process your data under their own terms.
How to exercise your rights
Contact your agency first, as it is the one that decides about your data. If you write to us at [[OWNER: email de contacto]], we will pass your request on to your agency and help it reply to you. You can also lodge a complaint with the Spanish Data Protection Agency, AEPD (www.aepd.es).