Skip to content

Data protection

Privacy Policy

This policy explains how Woomia33 Unipessoal Lda / YourTuk processes personal data through the website, bookings, customer support and applications.

Effective version: September 10, 2026

YourTuk
Woomia33 Unipessoal Lda
NIF 517644258
RNAAT
1061/2023
(+351) 938 586 100
Av. dos Bons Amigos, n.º 29, 9.º B, 2735-077 Agualva-Cacém, Portugal

1. Controller

The controller is Woomia33 Unipessoal Lda, Portuguese tax number 517644258, registered at Av. dos Bons Amigos, no. 29, 9B, 2735-077 Agualva-Cacém, Portugal, trading as YourTuk. Privacy questions and rights requests may be sent to staffyourtuk@gmail.com.

2. Data we process

We may process identity and contact details, group composition, language, requested date and experience, booking and billing data, communications, change or cancellation requests, security logs and, when supplied, strictly necessary dietary, mobility or health needs.

For Work With Us we process the fields submitted and an optional CV. Do not include identity documents, bank details or health information in an application.

3. Purposes and legal bases

We handle enquiries and bookings for pre-contract steps and contract performance; billing and records for legal obligations; support, security and abuse prevention for legitimate interests; health-related needs with explicit consent; and marketing only with consent or where the law permits similar own-service communications with an easy opt-out.

4. Bookings and payments

Bókun manages availability, bookings and related messages. Stripe processes payments. YourTuk receives only what is needed to supply the service and manage the transaction and does not receive the full card number or security code.

Provider terms and notices apply within their environments. Opening checkout is a voluntary user action.

5. Recipients and suppliers

Data may be shared on a need-to-know basis with Bókun, Stripe, Namecheap/cPanel hosting, Google Workspace/Gmail, VATA Systems for hosting and maintenance, guides, transport providers, restaurants, ticket suppliers and experience partners, and with authorities where legally required.

Each supplier acts according to its role and contract. YourTuk restricts access, uses individual accounts and requires appropriate instructions and safeguards where a supplier processes data on its behalf.

6. International transfers

Some suppliers may process data outside the European Economic Area. Where an international transfer occurs, GDPR mechanisms such as an adequacy decision, standard contractual clauses or another valid safeguard are used as appropriate to the service and destination.

7. Retention

  • Billing and tax-relevant records: for the statutory period, generally 10 years.
  • Bookings and service delivery: during the relationship and afterwards as needed for complaints, legal claims and statutory duties.
  • Enquiries without a booking: up to 12 months after the last contact unless a justified need applies.
  • Technical security logs: generally up to 90 days unless an incident occurs.
  • Applications and CVs: up to 6 months after the last contact; up to 12 months for future roles only with separate consent.
  • Marketing: until consent is withdrawn or an objection is made; only minimal evidence of the choice is retained as needed.

8. Dietary, mobility and health needs

We request only essential practical information. Where it may reveal health data, processing requires explicit consent and may involve sharing with the necessary guide, restaurant or partner. Consent may be withdrawn, although this may prevent an adaptation or safe delivery.

9. Applications

Expressions of interest and any PDF are delivered to YourTuk’s authorised mailbox, are not stored in a public database and are not used for marketing. Access is restricted to the responsible team. Unsuccessful files are deleted under the period above.

10. Marketing

An enquiry, booking or WhatsApp message does not automatically authorise campaigns. Marketing consent is optional, separate and withdrawable at any time. Confirmations, safety notices and booking support are not marketing.

11. Cookies and external services

At launch, analytics, advertising pixels and the live newsletter are disabled. The site uses only essential technologies and local preferences. Google review content is a static snapshot; maps and WhatsApp open through external links.

The Bókun interface loads only when the user asks to book. Non-essential technologies from any integration remain blocked until valid consent. If measurement or advertising tools are added, equivalent accept, reject and customise choices will be provided.

12. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, objection, portability and withdrawal of consent at staffyourtuk@gmail.com. We may request reasonable information to verify identity.

You may complain to the Portuguese Data Protection Authority at cnpd.pt. Exercising rights is free unless a request is manifestly unfounded or excessive under the law.

13. Security and changes

We use proportionate measures including HTTPS, access control, 2FA where supported, updates and data minimisation. No system removes every risk; incidents are documented and notified where required.

This policy may be updated to reflect actual changes. Material changes will be highlighted and the version date updated.