BubbleBeer

Privacy

Privacy Notice

This notice describes processing on the BubbleBeer public website as currently delivered. Updated 12 August 2026.

1. Controller

Santa Maria Balear S.L., CIF/NIF B57636870, Carrer des Cuiram 12, 07660 Cala d’Or, Illes Balears, Spain. Phone: +34 696 623 811. Email: info@bubblesbeer.eu.

2. Access and server logs

Necessary connection data is processed when the site is accessed: IP address, time, requested resource, HTTP status, volume, referrer where supplied and browser/User-Agent data. Purposes are secure delivery, diagnostics and abuse prevention, based on the legitimate interest in a secure operational service (GDPR Art. 6(1)(f)). Logs are retained only for periods necessary for operation, security, diagnostics and legal evidence, then deleted or anonymised.

3. Language, display and public demo

The root address prioritises a manually saved language and otherwise the browser Accept-Language header. IP geolocation is not currently used. Language and colour theme are stored locally. The public demo holds visitor-entered demo state for the session and is intended for artificial data. Bases are the requested function (Art. 6(1)(b)) and legitimate interest in a usable demo (Art. 6(1)(f)).

4. Susi text and Voice

Text questions to the public Susi information feature are sent to our infrastructure and answered from approved website knowledge. If a visitor expressly activates Voice, audio, transcription and/or output text is technically processed through OpenAI services. Voice, spoken content, technical metadata and the response may be transmitted. Voice should not be used for confidential or special-category data. Bases are the requested function (Art. 6(1)(b)) and, where consent is required, Art. 6(1)(a). Voice never starts automatically.

5. Privacy in development / Privacy by Design

BubbleBeer is currently developing an additional technical privacy layer for Susi (“Privacy Gateway”). For approved processing paths, it is intended to consider before processing by external AI services factors including the type and sensitivity of data, processing purpose, the relevant company’s privacy profile, whether external processing is permitted, and whether redaction, pseudonymisation or local processing is required. A first part is technically implemented and is being tested in Shadow Mode alongside a real Susi text path. Shadow Mode means that the privacy logic already evaluates processing events in parallel but does not yet actively intervene: it currently does not block, alter, pseudonymise or route data. This allows decisions to be tested and improved before protection rules are technically enforced on approved paths. Before the production launch with the first regular BubbleBeer tenants, the goal is to implement and validate these mechanisms far enough for the intended rules to operate effectively on the processing paths approved for enforcement. This does not mean that all data is processed locally, that no data is sent to external AI providers, or that a privacy level automatically guarantees complete legal compliance.

6. Reviews, sign-in and contact

A submitted review includes rating, optional text and language; a necessary session marker prevents duplicates and associates the submission. Publication follows review. Sign-in processes username, password transmission and a secure session cookie. Phone/email contacts are processed to respond, under Art. 6(1)(b) or (f), and Art. 6(1)(c) where retention is legally required.

7. Maps, media and recipients

Fonts and most videos are served from this website; the partner-program video is technically loaded from rifu.es. The relevant media server receives the IP address and HTTP request data. No external webfonts or analytics are loaded. The public booking/demo view may load OpenStreetMap tiles, whose service also receives the IP address and request data. OpenAI receives data only when an AI/Voice path is actually used. Technical hosting, email and infrastructure providers may act as processors. Transfers outside the EEA take place only on a valid basis with appropriate safeguards.

8. Retention

Session Storage normally ends with the browser session; a manual language choice is kept for up to one year and the theme until changed or deleted. Susi sessions and security logs are limited according to operational and security needs. Communications are retained while required for handling, legal duties or claims.

9. Rights

Subject to the GDPR, you may request access, rectification, erasure, restriction, portability and object, and withdraw consent for the future via info@bubblesbeer.eu. You may also complain to the Spanish Data Protection Agency, www.aepd.es. The public site makes no solely automated decision producing legal or similarly significant effects.