MYKEY
RestaurantsNightlifeEventsHospitality
ES/EN
Book
MYKEY · Privacy policy

Data protection

Privacy policy

Last updated: 3 August 2026

On this page

1. Controller 2. Data we process 3. Purposes and legal bases 4. Retention 5. Recipients 6. International transfers 7. Your rights 8. Complaints 9. Security 10. Minors 11. Automated decisions 12. Changes

This policy explains how Miguel Candelaria de la Llave ("MYKEY", "we") processes the personal data of people who visit mykeymadrid.com or get in touch to request a concierge service, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Act 3/2018 on the protection of personal data and the guarantee of digital rights (LOPDGDD).

1. Data controller

Owner
Miguel Candelaria de la Llave
Tax ID (NIF)
11085984F
Registered address
Avenida de Orovilla 48, 28041 Madrid (Spain)
Email
info@mykeymadrid.com
Phone / WhatsApp
+34 627 702 161
Trade name
MYKEY Concierge
Website
https://mykeymadrid.com
Activity
Concierge services, booking intermediation and experience planning in Madrid

No Data Protection Officer has been appointed, as none of the circumstances set out in Article 37 GDPR apply. For any privacy matter, please write to info@mykeymadrid.com.

2. Data we process

We only process the data you provide to us or that is generated by your browsing:

  • Contact and identification data: name, surname, email address, phone number and, where applicable, the username you write to us from on WhatsApp or Instagram.
  • Request data: date, time, number of guests, venue or experience of interest, preferences, allergies or dietary restrictions you choose to share, and any other information included in your message.
  • Billing data: when you engage a service, the tax details required to issue the invoice and process payment.
  • Browsing data: IP address, device and browser type, pages visited and aggregate usage data, only if you accept analytics cookies.

If you provide us with third-party data (for example, the names of guests on a booking), you warrant that you have their consent to do so and undertake to inform them of the content of this policy.

Special categories of data. We do not request health data. If you voluntarily tell us about a food allergy or intolerance so that we can manage a booking, we will process that information on the basis of your explicit consent (Art. 9(2)(a) GDPR) and will only share it with the venue where strictly necessary to provide the service.

3. Purposes and legal bases

PurposeDataLegal basis
Responding to your enquiry and handling your booking or experience requestContact and requestPerformance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR)
Providing the concierge service engaged and acting as intermediary with venuesContact and requestPerformance of a contract (Art. 6(1)(b) GDPR)
Invoicing and compliance with tax and accounting obligationsIdentification and billingLegal obligation (Art. 6(1)(c) GDPR)
Sending commercial communications, news and recommendationsEmail and phoneConsent (Art. 6(1)(a) GDPR) or legitimate interest for existing clients regarding similar services (Art. 21.2 LSSI)
Measuring and improving the website through analyticsBrowsingConsent given through the cookie banner (Art. 6(1)(a) GDPR)
Site security, fraud prevention and handling of complaintsBrowsing and contactLegitimate interest in protecting the service and defending our rights (Art. 6(1)(f) GDPR)

Providing the data marked as mandatory in our forms is necessary in order to handle your request; without it we will not be able to process it.

4. Retention periods

  • Enquiries that do not lead to an engagement: up to 1 year from the last contact.
  • Client data: for the duration of the relationship and thereafter for the limitation periods applicable to claims arising from the contract (generally 5 years, Art. 1964 of the Spanish Civil Code).
  • Invoicing and accounting records: 6 years (Art. 30 of the Spanish Commercial Code) and up to 4 years for tax purposes, calculated independently.
  • Commercial communications: until you withdraw your consent or object.
  • Browsing data: as set out in the Cookie policy.

Once these periods have elapsed, data is deleted or irreversibly anonymised.

5. Recipients and processors

Your data may be disclosed to:

  • Restaurants, clubs, hotels and organisers with whom you ask us to arrange a booking or entry, limited to the data strictly required to manage it (name, party size, time slot and special requests). Each venue acts as an independent controller in respect of the data it receives.
  • Service providers acting as processors: web hosting, email, messaging tools, web analytics, tax and accounting advisers, and payment gateways. Contracts required by Article 28 GDPR have been signed with all of them.
  • Public authorities and courts, where there is a legal obligation to do so.

We do not sell or transfer your data to third parties for advertising purposes.

6. International transfers

Some technology providers (for example Google, Meta or our email provider) may process data outside the European Economic Area. In those cases, the transfer is based on an adequacy decision of the European Commission — such as the EU-US Data Privacy Framework — or on the Standard Contractual Clauses approved by the Commission, together with any supplementary measures required. You may request a copy of the safeguards applied by writing to info@mykeymadrid.com.

7. Your rights

You may exercise the following rights at any time:

  • Access: find out what data of yours we process.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request deletion where the data is no longer necessary.
  • Restriction: ask us to suspend processing in certain circumstances.
  • Objection: object to processing based on legitimate interest and, in all cases, to direct marketing.
  • Portability: receive your data in a structured, commonly used format, or have it transmitted to another controller.
  • Withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.

To exercise them, write to info@mykeymadrid.com or to Avenida de Orovilla 48, 28041 Madrid (Spain), stating the right you wish to exercise and enclosing a copy of a document proving your identity. We will respond within one month, extendable by a further two months where the request is complex.

8. Complaints

If you believe your data is not being processed in accordance with the law, you may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid, www.aepd.es). We would be grateful for the opportunity to resolve the matter first by contacting us directly.

9. Security measures

We apply appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encrypted transmission via HTTPS, access control, backups and data minimisation. Should a security breach occur that poses a high risk to your rights, we will notify you without undue delay.

10. Minors

Our services are intended exclusively for persons aged 18 or over. We do not knowingly collect data from minors. If we become aware that we have received data from a minor without the authorisation of their legal guardians, we will delete it.

11. Automated decision-making

We do not carry out automated decision-making or profiling that produces legal effects or similarly significantly affects you.

12. Changes to this policy

This policy may be updated to reflect legal changes or changes to our services. The version in force is always the one published on this page, with its last update date shown. Where changes are substantial, we will notify you through the contact channels available.

© MYKEY Concierge · MadridHome · Legal notice · Privacy · Cookies · Cookie preferences