Rusker Travel

Privacy Policy

Personal data protection — GDPR (EU 2016/679) and Spanish LOPDGDD (Ley Orgánica 3/2018)

RUSKER TRAVEL, S.L. — Version 1.0 · 9 July 2026

This policy describes how Rusker Travel, S.L. processes your personal data when you book a Learning Expedition on app.rusker-travel.com. It complements Article 16 of the General Terms of Sale and forms an integral part of it.

1. Data controller

Rusker Travel, S.L. — Carrer de l’Arc de Sant Agustí 3, 08001 Barcelona, Spain — NIF B44897510 — travel agency FUE-2023-03315922.

Contact for any data-related question: info@rusker-travel.com, subject "DATA PROTECTION".

2. Data we collect

As part of your registration, we collect:

  • Identity: first name, last name, date of birth, nationality.
  • Contact details: email address, phone number.
  • Identity document: copy of the passport or national ID card, document number and expiry date.
  • Professional data: company, position, departure station.
  • Emergency contact: name and phone of the person to notify.
  • Billing data: legal name, billing address and EU VAT number (optional).
  • Special-category data: dietary requirements, allergies and medical needs that you choose to share with us.
  • Consent-related technical data: IP address, user agent and timestamp of your acceptance of the contractual documents.

3. Purposes and legal bases

PurposeLegal basis
Managing registration and performing the PackagePerformance of the contract (art. 6.1.b GDPR)
Transmission to hotels, carriers and caterers for bookingsPerformance of the contract
Summit ticket issuance — transmission to AI Summit Alliance S.L., organizer of the AI Summit Barcelona 2026Performance of the contract
Traveller record and transmission to the Ministry of the Interior (SES.Hospedajes platform), under Real Decreto 933/2021Legal obligation (art. 6.1.c GDPR)
Access lists and security checks of visited companiesPerformance of the contract and host company’s legitimate interest
Dietary requirements, allergies, medical needsExplicit consent — special categories (art. 9.2.a GDPR)
Invoicing and accounting/tax obligationsLegal obligation
Proof of consent to the contractual documents (consent log)Legitimate interest (proof) and legal obligation
Identifying photographs and videos for communicationSeparate consent — never required to register
Rusker Travel marketingConsent, or legitimate interest for existing customers

4. Recipients

Rusker Travel does not sell or rent your data. Transmissions are limited to what is strictly necessary to perform the Package, comply with legal obligations and carry out the processing you consented to:

  • The Rusker Travel team in charge of organization.
  • The hotels, carriers and caterers providing the trip.
  • AI Summit Alliance S.L. for issuing your personal ticket.
  • The visited companies, for access lists and security checks.
  • The Spanish Ministry of the Interior (SES.Hospedajes), for the legal traveller record.

Technical processors. Our IT providers act on instruction and under a contract compliant with Article 28 GDPR: Stripe Payments Europe (payment and invoicing), Supabase (database and document hosting, European Union), Resend (email delivery) and Vercel (site hosting).

5. Retention periods

  • (a) Traveller record required by Real Decreto 933/2021 (identity, document number, nationality, date of birth, contact details, payment data): three (3) years from departure. This data cannot be deleted before that term, in fulfilment of a legal obligation.
  • (b) Copies and scans of ID documents collected for the visited companies’ access lists: deleted as soon as the visit has taken place, and at the latest one (1) month after the end of the Package. Uncompleted bookings are purged automatically, and their documents deleted, at short notice.
  • (c) Contractual and accounting management data: statutory limitation and accounting retention periods.
  • (d) Consent log: kept as long as necessary for proof, within the same legal limits.
  • (e) Marketing data: three (3) years after the last contact.

6. Security

Data is hosted in the European Union (Supabase, Paris region). ID document copies are stored in a private, non-public space, accessible only through time-limited signed links restricted to authorized staff. Access to the admin is protected by one-time-code authentication limited to an allowlist of authorized addresses.

7. Transfers outside the EEA

No transfer of your data outside the European Economic Area is carried out without appropriate safeguards within the meaning of Chapter V of the GDPR.

8. Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw your consent at any time, without such withdrawal affecting the lawfulness of prior processing. These rights are exercised within the limits of the legal retention obligations referred to in point 5 (a).

To exercise your rights: info@rusker-travel.com, subject "DATA PROTECTION". We respond within thirty (30) days.

You may lodge a complaint with the Agencia Española de Protección de Datos (www.aepd.es) or the supervisory authority of your country of residence (in France, the CNIL — www.cnil.fr).

9. Changes

This policy may be updated. The applicable version is the one in force on the day of your registration; its reference is recorded in our consent log.