TBV logoTENERIFE
BEACH VOLLEY
BACK TO HOMEPAGE ↗
TENERIFE BEACH VOLLEY / YOUR INFORMATION

PRIVACY POLICY

Last updated 9 October 2026

Privacy PolicyLegal Notice

1. Who is responsible

Website operator and data controller
CD UNDERDOG (Club Deportivo Underdog), operating Tenerife Beach Volley (TBV).
NIF
G75402180
Registered address
Avenida Juan Alfonso Batista - Los Cristianos, Arona 38650, Santa Cruz de Tenerife, Spain.
Registration
Registro de Entidades Deportivas de Canarias, Resolution n.º 1226/2024 of 2 October 2024, subsequently corrected.
Legal and privacy contact
tenerifebeachvolley@gmail.com. You may also write to the registered address. General inquiries: website contact form.

This policy covers tenerifebeachvolley.com and the TBV website served through its hosting domain. It explains information collected through our guide, contact and newsletter forms and ordinary website operation. Last updated: 9 October 2026.

2. Information we collect

  • Free guide: first name, last name, email, request date, privacy acknowledgment, optional marketing choice, delivery status and the date a tracked download starts.
  • Contact inquiries: first name, last name, email, social profile, inquiry type, message, privacy acknowledgment and optional company. We record submission date, verification, delivery and message-management status.
  • Newsletter: first name, last name, normalized email, active or unsubscribed status, registration source, and consent history including timestamp, source and the consent wording.
  • Operation and security: hosting providers receive technical requests, including IP addresses, browser information and requested resources. Our application keeps short-lived hashed IP or email rate-limit keys, request identifiers and hashed access tokens to prevent abuse, duplicate processing and unauthorized access. A hash is a security measure, not a guarantee of anonymity.

Required fields are marked with *. Without them, the corresponding form cannot be processed. Company is optional in the contact form, and marketing consent is optional in the guide form. Do not include passwords, identity-document copies, payment details or sensitive health information in messages. We obtain form details directly from you; we do not enrich them from external profiles.

3. Purposes and legal bases

How personal information is used
PurposeLegal basis
Deliver the free guide you request and keep a record of delivery and tracked access.Your consent to the guide request (GDPR Article 6(1)(a)). This is independent of marketing consent.
Respond to general inquiries, collaborations, media requests and correspondence.Our legitimate interest in managing communications you initiate (Article 6(1)(f)). When you request steps toward a contract with you, Article 6(1)(b) applies.
Send occasional newsletter and educational updates.Your explicit marketing consent (Article 6(1)(a)).
Verify contact email addresses, prevent duplicate registrations, secure the website and restrict administrator access.Our legitimate interest in preventing abuse and protecting visitors and records (Article 6(1)(f)).
Keep necessary consent or opt-out evidence, meet legal duties and handle legal claims.Applicable legal obligations (Article 6(1)(c)) or our legitimate interest in demonstrating compliance and establishing, exercising or defending claims (Article 6(1)(f)), as relevant.

Our legitimate interests are limited to running and securing this website, answering requested communications and protecting rights. You may object where processing relies on legitimate interests. We do not make automated decisions with legal or similarly significant effects, or build individual advertising profiles.

4. How the forms and emails work

Contact: the inquiry is saved pending email verification. A secure confirmation link expires after 24 hours. After successful verification, the system attempts to notify our team. Transactional verification and inquiry emails do not subscribe you to marketing. Multiple inquiries from the same email are allowed.

Free guide: registrations are deduplicated per guide and normalized email. The form shows the same neutral message for new and existing registrations. An existing request does not automatically receive another guide email. You can use the separate guide recovery form to request a new or retried email for a saved guide request. Recovery uses the email supplied for that original request, is rate limited, does not reveal whether the address is registered, and does not create a new lead, renew the retention deadline or change newsletter consent. Download links expire after seven days. We record when the tracked download endpoint is requested; this does not prove that the file was fully downloaded or read and can include an automated email-security request.

Newsletter: selecting the optional guide marketing checkbox or submitting the clearly labelled newsletter form activates a single opt-in subscription immediately. No newsletter confirmation-link or welcome email is currently sent. Both methods use one audience. Leaving the guide checkbox unchecked does not unsubscribe an existing subscriber. Fresh explicit consent can reactivate a previous unsubscribe. Every future marketing email must provide a working unsubscribe link; you can also withdraw consent now through the privacy contact. Withdrawal does not affect earlier lawful processing or necessary transactional emails.

5. Who receives information

Authorized TBV administrators can access the private dashboard. We do not sell personal information or give partners the form database for their own marketing. Necessary information is processed by:

  • OpenAI / ChatGPT Sites: hosting, maintenance and administrator authentication. Published-site data is covered by the applicable Sites data processing addendum. For EEA users its stated contracting entity is OpenAI Ireland Ltd. Administrator account information is also governed by OpenAI’s own terms and privacy policy.
  • Cloudflare: domain/DNS, network delivery, security, Worker hosting and D1 database infrastructure used by the site. See Cloudflare’s privacy policy and security-cookie information.
  • Resend (Plus Five Five, Inc.): sending guide, contact and internal notification emails. This involves recipients, message content and delivery metadata. See its data processing addendum and subprocessor list.
  • Google / Gmail: receiving and storing TBV’s internal notifications and correspondence in our Gmail inbox. Automated form notifications contain only the form type and a generic private-dashboard link, without submitter names, email addresses, message contents, record identifiers or visitor Reply-To headers. Earlier notifications and direct correspondence may still contain personal information. See Google’s privacy policy.

Providers may use their own infrastructure suppliers under their applicable service arrangements. Their own account, security and service information may be processed under their privacy policies. We may disclose strictly necessary information to competent authorities when legally required, or to professional advisers where needed to protect rights.

6. International processing

Our providers operate internationally. Information may be processed outside Spain and the European Economic Area, including in the United States; this site is not represented as EU-only storage. The published OpenAI Sites addendum describes European Commission standard contractual clauses or an adequacy decision for relevant transfers. Resend’s published addendum includes standard contractual clauses and identifies its primary processing in the United States.

Google and Cloudflare describe international processing in their linked policies. The applicable safeguards depend on the particular service, contracting entity and processing arrangement. You can contact CD UNDERDOG for information about the safeguards applicable to your data or request a copy, subject to necessary confidentiality protections. Provider policies alone do not mean that every account-specific arrangement has been independently audited.

7. Retention and deletion

  • Guide requests and contact inquiries: normally up to two years from submission. An ongoing inquiry, specific legal obligation or claim can justify keeping only necessary information longer, with annual review.
  • Newsletter: while the subscription is active and relevant, with annual review. After withdrawal, marketing stops. Only necessary consent evidence and suppression information may be retained to demonstrate consent and honor the opt-out, reviewed annually and deleted when no longer necessary.
  • Scheduled review start: age-based guide/contact reviews begin August 9, 2028. Each record keeps its original two-year deadline; no bulk deletion occurs simply because reviews start. Short-lived security and analytics housekeeping continues, and individual privacy requests are handled independently.
  • Deletion matching reports: after database deletion, the record ID, type, email and submission/deletion dates are retained privately for up to 30 days to help the administrator remove matching inbox and exported copies. Message contents are not retained in these reports.
  • Access links: contact confirmation links expire after 24 hours and guide links after seven days. Expiry disables access; it does not delete the underlying registration.
  • Application rate-limit records: eligible for cleanup after 24 hours; cleanup runs on later rate-limited requests and during the daily retention check.
  • Aggregate statistics: a rolling 30-day reporting window. Delivery receipts expire after ten minutes. Physical cleanup runs on subsequent analytics collection requests and during the daily retention check.

Guide requests and contact inquiries in the website database are automatically deleted at the next daily cleanup after two calendar years from submission. Deletion also revokes their verification and guide links and removes retained legacy database copies. Records explicitly placed on a retention hold for an ongoing matter, legal obligation or claim are excluded until an administrator releases the hold; holds must be reviewed annually. Active newsletter subscriptions and necessary consent or opt-out evidence follow their separate criteria above and are not erased by the two-year guide/contact timer. Retention periods are our necessity-based criteria, not a statutory maximum allowing indefinite storage. Reviews must also cover email copies, exports and applicable provider logs or backups; deleting a dashboard record does not automatically erase a Gmail notification or exported copy. Notification copies in our receiving inbox follow a two-year review/deletion rule; guide and contact copies use the original submission date. Temporary CSV working exports are removed within 30 days after their task is completed and no later than the source record deadline, unless a documented lawful exception applies. Necessary ongoing correspondence and legal holds are reviewed annually. Inbox and export cleanup is manual and separate from database deletion. Email queue payloads are removed after provider acceptance; unresolved terminal payloads are removed after 30 days. Queue metadata is deleted with the related form record; newsletter notification metadata is removed after two years. Provider-controlled operational records are governed by the applicable service arrangements.

8. Cookies, fonts and aggregate statistics

TBV’s own audience measurement stores anonymous daily totals for homepage loads, active time in visible sections, selected clicks and broad viewport sizes. It does not store individual visit histories, form values, names or email addresses, and is not linked to form records. It uses no identifying analytics cookies or browser-storage identifiers. Each delivery batch has a fresh random nonce for duplicate prevention, not a persistent visitor ID. Do Not Track and Global Privacy Control signals disable this measurement. Infrastructure still handles the technical requests needed to deliver these statistics.

We do not currently use advertising pixels or third-party advertising analytics. Hosting security may set Cloudflare’s __cf_bm bot-protection cookie, which expires after approximately 30 minutes of inactivity. Security challenges may use additional necessary cookies, described in Cloudflare’s linked documentation. Administrator sign-in has separate authentication/session mechanisms. These necessary functions are distinct from TBV’s aggregate analytics; we do not claim the entire website is cookie-free.

Website fonts are served from this website; your browser does not contact Google’s font servers to load them. Social icons are ordinary external links rather than embedded feeds: clicking them takes you to Instagram, TikTok, YouTube or WhatsApp, where that provider’s privacy rules apply. Joining the WhatsApp group can make your profile or phone number visible to others depending on WhatsApp’s current group settings. It is a community channel, not the business or privacy-contact channel.

You may control cookies through your browser, although blocking necessary security or authentication cookies can affect access. If optional tracking is introduced later, this policy and any required consent controls must be updated before it is enabled.

9. Your rights and how to contact us

Subject to applicable conditions, you can request access, correction, deletion, restriction and portability of your personal information; object to processing based on legitimate interests; and withdraw consent at any time. You can object to direct marketing at any time. Deletion is not absolute where necessary information must be retained for legal obligations or claims.

Email tenerifebeachvolley@gmail.com with your request, or write to the registered address above. You do not need to provide a social profile or use the business contact form to exercise your rights. Tell us enough to locate the relevant record; we may ask for proportionate identity verification where necessary. Do not send identity documents unless requested through an appropriate secure method.

We will respond without undue delay and normally within one month. Where legally justified by complexity or number of requests, this can be extended by up to two further months, with an explanation within the first month. You can complain to the Agencia Española de Protección de Datos (AEPD) or your competent supervisory authority; you do not have to contact us first.

10. Security, age and changes

The application uses HTTPS, server-side validation, rate limiting, private administrator authorization and hashed access tokens. API secrets are stored server-side. No system can guarantee absolute security. This website does not intentionally collect sensitive personal information and its forms are not directed at children under 14. If information from a child requiring parental authorization has been provided, contact us so we can assess and remove it where appropriate.

We will update this page when processing changes, showing the revision date and providing additional notice where required. A change to this policy is not itself consent to a new marketing purpose.

© 2026 TENERIFE BEACH VOLLEYBACK TO HOMEPAGE ↗