Privacy Policy

Privacy Policy
Last updated: 06.08.2025
1. Introduction
At BB Mallorca S.L., we are fully committed to protecting your personal data, ensuring transparency, and upholding the highest standards of data privacy and sustainability. This privacy policy informs you about how we collect, use, and safeguard your personal data when you use our online shop.
We operate this website in accordance with the European Union’s General Data Protection Regulation (GDPR).
2. Who We Are
BB Mallorca S.L.
Carrer de Guixers, 10
07001 Palma de Mallorca, Spain
Carrer de Guixers, 10
07001 Palma de Mallorca, Spain
Email: office@bibap-mallorca.com
VAT ID: ESB 57650236
Data Controller: BB Mallorca S.L.
VAT ID: ESB 57650236
Data Controller: BB Mallorca S.L.
3. Web Hosting & Infrastructure
Our website is hosted on secure servers provided by Hetzner Online GmbH, located in Germany (EU). Hetzner is a GDPR-compliant provider committed to data protection and sustainability, operating data centers using energy-efficient infrastructure and renewable power.
All personal data processed via this website remains within the European Economic Area (EEA).
4. What Data We Collect
We only collect personal data that is necessary for providing our services, fulfilling contractual obligations, or as required by law.
We collect the following categories of data:
• Name and contact information (when you place an order or register)
• Billing and shipping address
• Order and payment history
• Email and password (for Customer Dashboard login)
• IP address and browser information (for security and analytics)
We do not use tracking cookies for advertising, nor do we embed any external media or third-party trackers.
5. Customer Dashboard Login
If you register for a customer account, your login credentials and order history will be stored securely on our server. Access to your data is encrypted and protected using strong authentication and secure connections (SSL/TLS).
Your customer account is completely first-party and not connected to any external service.
6. Payment Processing via Stripe
We use Stripe, a certified PCI-DSS Level 1 payment processor, to securely process payments. Stripe may process:
• Payment card information
• Name and billing address
• Email address (for receipts)
Stripe acts as an independent data controller for processing payments. You can review Stripe’s privacy policy here: https://stripe.com/privacy
7. Legal Basis for Processing
We process your data on the following legal grounds:
• Art. 6(1)(b) GDPR – to perform a contract (e.g., processing your orders)
• Art. 6(1)(c) GDPR – to comply with legal obligations (e.g., tax records)
• Art. 6(1)(f) GDPR – for legitimate interests (e.g., security, server maintenance)
8. Data Retention
We retain your data only as long as necessary:
• Order and transaction records: up to 10 years (per legal requirement)
• Customer account: until deletion requested
• Contact inquiries: up to 12 months
9. Data Processors
All data processors (e.g., hosting, payment, analytics) used by BB Mallorca S.L. are:
• Located in the EU or in jurisdictions with adequate data protection
• Contractually bound by Data Processing Agreements (DPAs)
• GDPR-compliant
We do not transfer your personal data to third countries outside the EU without appropriate safeguards.
10. Your Rights Under GDPR
As a data subject, you have the following rights:
• Right to access (Art. 15)
• Right to rectification (Art. 16)
• Right to erasure (Art. 17)
• Right to restriction of processing (Art. 18)
• Right to data portability (Art. 20)
• Right to object (Art. 21)
You may also lodge a complaint with your local data protection authority.
To exercise any of your rights, please contact us at [Insert Email Address].
11. Security & Sustainability Commitment
We take technical and organizational measures to protect your data from unauthorized access, loss, or misuse. These include:
• HTTPS encryption
• Server-side firewalls and access controls
• Minimization of data collection
• No use of external fonts or embedded media
As part of our commitment to sustainability, we work with data center partners who use green energy and efficient infrastructure.
12. Cookies
Our website does not use non-essential cookies or third-party trackers. Only technically necessary cookies are used (e.g., for session management and login security).
No consent banner is required under GDPR for strictly necessary cookies.
13. Contact
If you have questions about this privacy policy or your personal data, please contact us:
BB Mallorca S.L.
Email: office@bibap-manufacture.com
Postal: Carrer de Guixers, 10, 07001 Palma de Mallorca, Spain
Email: office@bibap-manufacture.com
Postal: Carrer de Guixers, 10, 07001 Palma de Mallorca, Spain