Skip to content

Privacy Policy and Data Processing Agreement (DPA)

This translation is provided for convenience; the Spanish version is the legally binding one.

Last updated: August 2026

Part A — Privacy Policy

1. Data Controller

The controller of the data collected on this website and when subscribing to Manglar CRM is Mikel Alonso, with address at 27 Quartier Cayron, Beaumarchés 32160 (France), and email contact@evotime.es.

2. Purpose, Data Collected and Legal Basis

We collect contact and billing data of the travel agencies' representatives (name, corporate email, address, telephone, tax ID (NIF/VAT) and app usage data).

Purpose: To manage the subscription, issue invoices, provide technical support and send security notifications.

Legal basis: The legal basis is the performance of the B2B contract (Art. 6.1.b GDPR) and legitimate interest (Art. 6.1.f GDPR) for the improvement and security of the software.

Important: Payments are processed externally (e.g. Stripe). Manglar CRM does not store bank card details.

3. Recipients and Retention Period

We do not sell data to third parties. Data is only shared with strictly necessary technology providers (hosting and payment gateways) that comply with the GDPR and have servers in the European Union. Tax data will be retained for the years required by the applicable tax legislation after the Client's termination.

4. Users' Rights

You may at any time exercise your rights of access, rectification, erasure, objection, restriction and portability by sending an email to contact@evotime.es, attaching a copy of an identity document.

5. Cookies

This website does not use advertising, profiling or social media cookies. Your decision about analytics cookies is stored in your browser's local storage (key manglar-cookie-consent) and is only used so we do not ask you again.

Analytics cookies: Only if you accept them in the notice shown when you arrive are the Google Analytics cookies loaded: _ga and _ga_ followed by the property identifier, which expire after 2 years, and _gid, which expires after 24 hours. Their sole purpose is to measure, in aggregate, how many visits the website receives and which pages are viewed, in order to improve it. If you reject them, no Google script is loaded and no analytics cookie is installed.

Provider: Google Ireland Limited. The international transfers arising from this service are covered by the European Commission's Standard Contractual Clauses. Measurement is configured with consent limited to analytics: advertising and personalisation purposes are not enabled.

Legal basis: Your prior and express consent (Art. 6.1.a GDPR and Art. 22.2 of the Spanish LSSI).

Withdrawal of consent: You can change your mind at any time, as easily as you gave your consent, from the "Cookies" link in the footer, which displays the notice again. If you reject them, the Google Analytics cookies already installed in your browser are deleted. You can also delete or block them from your browser settings.


Part B — Data Processor Annex (DPA)

1. Subject Matter, Nature and Roles

This Data Processing Agreement (DPA) forms part of the Terms and Conditions. It governs the processing of the personal data of end clients and employees that the Travel Agency (the "Data Controller") enters into Manglar CRM. Mikel Alonso will act exclusively as "Data Processor".

2. Obligations of the Processor (Manglar CRM)

Documented instructions: To process personal data only in accordance with the Controller's documented instructions, through the normal interactions with the software interface.

Confidentiality: To ensure that the persons authorised to process the data (e.g. technical support) have committed themselves to the strictest confidentiality.

Security: To apply appropriate technical and organisational measures to ensure a level of security appropriate to the risk (encryption in transit via SSL/TLS, secure storage and backups).

Sub-processors: The Controller authorises the Processor to use cloud infrastructure providers (e.g. AWS, Google Cloud, mail servers) provided that they are located in the European Economic Area (EEA) or offer adequate safeguards (Standard Contractual Clauses).

Assistance: To assist the Controller, insofar as possible, in responding to requests from data subjects (the agency's clients) exercising their rights.

3. Notification of Security Breaches

In the event of a breach of the security of the personal data under its responsibility, the Processor shall notify the Controller without undue delay, and in no case later than 48 hours after becoming aware of it, providing all relevant information so that the Controller can comply with its obligation to notify the authorities.

4. Disposal of the Data

Once the service has ended, and after the sixty (60) day grace period stipulated in the Terms and Conditions for the Controller to export its information, the Processor will securely and permanently destroy all personal data, unless legislation requires its retention.

5. Obligations of the Controller (the Agency)

The Agency warrants that it has collected the personal data entered into Manglar CRM lawfully, informing the data subjects and obtaining their consent where necessary. The Agency shall hold Mikel Alonso harmless against any penalty or claim arising from the Agency's breach of data protection regulations.