Privacy
A quiet approach to your data.
This statement explains, in plain language, what we learn about you when you request private access, why we need it, how long we keep it and the rights you may exercise at any time.
Updated 12 August 2026
Text size
100%
Maintained by Lovisum, Mallorca. Written to satisfy Articles 13 and 14 of the General Data Protection Regulation, and to be read comfortably in a few minutes.
The controller of your data
Lovisum is a private companionship and concierge service based in Mallorca, Balearic Islands, Spain, and is the controller of the personal data described in this statement. Full identification details are published in our imprint.
For any privacy matter — including a request to see, correct or delete your data — you may write directly and in confidence to privacy@lovisum.com. Your message is read personally, never by an automated system.
Discretion as a design decision
Discretion is the reason Lovisum exists, and it shapes every choice we make about data. We collect only what is needed to answer a request and to arrange an occasion with care — nothing beyond that. We publish no profiles, build no advertising audiences and share no personal information with third parties for marketing purposes.
- No account is required, and no public directory exists.
- No advertising or cross-site tracking technology is used on this site.
- No personal data is ever sold, rented or exchanged.
- Every request is reviewed by a person, not by an algorithm.
What we collect
We ask for as little as possible, and you decide how much of it is your real name. The categories below are the only ones we hold.
Categories of personal data
- Request details
- The name or alias you choose to give, an email address at which we may reply, and any context you volunteer about the occasion you have in mind.
- Correspondence
- The content of the messages you send us and of our replies, kept so that we can serve you consistently.
- Consent record
- Your cookie and analytics choices, stored locally in your browser together with a version marker and a timestamp, so that we can honour and evidence them.
- Optional analytics events
- Only with your consent: page paths, event names, timestamps and a random session identifier that is discarded when you close the tab. No IP address, no advertising identifier.
- Security events
- For abuse prevention we may log an irreversibly hashed form of an IP address together with the type of event. The hash cannot be turned back into an address, and records are deleted after 30 days.
We do not knowingly collect special categories of data (Art. 9 GDPR). Please do not include health, religious, political or comparable details in your message; if you do, we will treat them with particular care and delete them once they are no longer needed.
How we use it
Your information is used solely to review your request, reply to you personally, arrange the occasion you have described, protect the safety of the companions and guests within our circle, keep this site secure, and meet obligations the law places on us. It is never used for advertising, profiling or resale.
The legal basis for each purpose
Article 6 GDPR
- Answering a request
- Art. 6(1)(b) GDPR — steps taken at your request before and within an arrangement.
- Safety and abuse prevention
- Art. 6(1)(f) GDPR — our legitimate interest in a lawful, respectful and secure service; balanced by data minimisation and hashing.
- Analytics
- Art. 6(1)(a) GDPR — your explicit, freely given and revocable consent.
- Service emails
- Art. 6(1)(b) GDPR for confirmations you have asked for; Art. 6(1)(a) GDPR for anything optional, with one-click unsubscribe.
- Legal retention
- Art. 6(1)(c) GDPR — compliance with commercial or tax retention duties.
Who may see your data
Access inside Lovisum is limited to the few people who need it in order to serve you. We rely on a small number of carefully chosen service providers, each bound by a data processing agreement under Art. 28 GDPR:
Processors
- Hosting & delivery
- Our infrastructure provider hosts this site and its backend within the European Union, or under equivalent safeguards.
- Email delivery
- A transactional email provider sends confirmations and internal notifications from our own sending domain.
- Database & storage
- A managed European database service stores requests and consent records.
A current, named list of processors is available on request. Beyond these, we disclose data only where a competent authority obliges us to do so, and never more than the law requires.
International transfers
We keep processing within the European Economic Area wherever possible. If a provider processes data outside the EEA, we rely on an adequacy decision of the European Commission or on Standard Contractual Clauses together with additional technical measures such as encryption in transit and at rest. You may ask us for a copy of the safeguards that apply.
How long we keep it
Retention periods
- Requests without an arrangement
- Deleted no later than 12 months after our last exchange.
- Arrangements and related correspondence
- Kept for the duration of the arrangement and afterwards only as long as statutory commercial or tax rules require.
- Security events
- Automatically deleted after 30 days.
- Consent records
- Held in your browser until you clear them; a new decision replaces the previous one.
The rights you may exercise
Under the GDPR you may ask us for access to the personal data we hold about you (Art. 15), for its correction (Art. 16) or erasure (Art. 17), for a restriction of processing (Art. 18), for a portable copy (Art. 20), and you may object to processing based on our legitimate interests (Art. 21). Where processing rests on consent, you may withdraw it at any time (Art. 7(3)) without affecting what happened before.
Write to privacy@lovisum.com. We answer within one month and free of charge; if a request is unusually complex we will tell you and may extend that period by up to two further months, as the regulation allows. To protect you, we may need to confirm that the request truly comes from you — never by asking for an identity document, only by replying from the address we already hold.
How we protect it
This site is served exclusively over encrypted connections with a strict content security policy and strict transport security. Data is encrypted in transit and at rest, access is limited to the people who genuinely require it, and administrative interfaces are protected by strong authentication. Should a breach occur that presents a risk to you, we will notify the competent supervisory authority within 72 hours and inform you without undue delay (Art. 33 and 34 GDPR).
No data from minors
Lovisum is strictly for adults aged eighteen or over. We do not knowingly collect information from anyone below that age. If we learn that we hold such data, we delete it immediately and close the corresponding request.
No automated decision-making
We take no decisions about you by automated means and carry out no profiling within the meaning of Art. 22 GDPR. Every request is read and answered by a person.
If you are not satisfied
We would like the chance to put things right first, so please write to privacy@lovisum.com. You also have the right to lodge a complaint with a supervisory authority — in Spain the Agencia Española de Protección de Datos (aepd.es), or the authority of your own country of residence or workplace.
Changes to this statement
We may refine this statement as our service develops. The version published here is always the current one, and any material change is reflected in the revised date above. Where a change requires your consent, we will ask for it before it takes effect.