Privacy and data protection policy (GDPR)
Version 1 · in force since 8/28/2026
This policy explains how FUSTIBUS S.COOP GALEGA processes the personal data of tucoworking users, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Act 3/2018 (LOPDGDD).
1. Data controller
- Controller: FUSTIBUS S.COOP GALEGA (ESF44660918)
- Address: RUA CONDESA CASA BÁRCENA 11, 36204 - Vigo, Pontevedra (España)
- Privacy contact: privacidad@tucoworking.com
When a customer makes a booking, the operator of the venue becomes the controller of the data it needs in order to provide the service (access, capacity control, invoicing). tucoworking and the operator are independent controllers, each for their own purpose.
2. Data we process
- Identification and contact: first name, surname, email address, phone number and language.
- Account: encrypted credentials, social sign-in provider identifier where used, and preferences.
- Bookings and contracting: venue, space, dates, amounts, booking code, status and related communications.
- Billing: the tax details of the billing profile (name or company name, tax ID, address).
- Payment: transaction identifiers at the payment gateway. tucoworking does not store card numbers: card details are entered directly into the gateway's PCI-DSS certified environment.
- Usage and security: IP address, user agent, date and time of legal acceptances, and activity logs.
3. Purposes and legal bases
- Creating and managing the account and bookings — performance of a contract (art. 6(1)(b) GDPR).
- Charging and, where applicable, refunding — performance of a contract and legal obligation.
- Disclosing to the operator the data needed to provide the service — performance of a contract.
- Handling enquiries and complaints — performance of a contract and legitimate interest.
- Complying with tax and reporting obligations, including reporting operator data to the authorities under Directive (EU) 2021/514 (DAC7) — legal obligation.
- Preventing fraud and ensuring the security of the platform — legitimate interest.
- Sending marketing communications — consent, which may be withdrawn at any time.
- Measurement and analytics — consent given through the cookie manager.
4. Recipients
Data is disclosed to: the operator of the booked venue; the payment gateways (Stripe and, where applicable, Paycomet) to process payments and refunds; email, hosting, search and analytics providers acting as processors under a signed agreement; and public authorities where there is a legal obligation.
Data is never sold or transferred to third parties for advertising purposes.
5. International transfers
Some providers may process data outside the European Economic Area. In those cases the transfer relies on a European Commission adequacy decision or on standard contractual clauses, together with any additional safeguards required.
6. Retention periods
- Account: for as long as it remains active and, after closure, for the period needed to handle any liabilities.
- Bookings and payments: 6 years (art. 30 of the Spanish Commercial Code) and the applicable tax periods.
- Consents: while they remain in force and, after withdrawal, as evidence that they were obtained.
- Security logs: strictly for as long as necessary for their purpose.
7. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction, portability and not to be subject to automated decisions by writing to privacidad@tucoworking.com, providing proof of identity. You may also withdraw your consent at any time, without affecting the lawfulness of prior processing.
If you believe your rights have not been respected, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or with your local supervisory authority.
8. Automated decision-making
The platform does not take automated decisions producing legal effects on users. The ranking of search results is automated processing without such effects, and its criteria are explained in the Platform terms.
9. Security
Appropriate technical and organisational measures are applied: encryption in transit, role-based access control, audit logging of sensitive operations and two-factor authentication for staff with administrative access.
This is a translation of the Spanish version, which prevails in the event of any discrepancy.