1. Data Controller
ATKINSKY S.L.
Commercial Register No.: B72775893
Registered Office: Mallorca, Balearic Islands, Spain
Email: [email protected]
Phone: +34 685 407 513
The entity identified above is responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR / RGPD) and the Spanish Ley Orgánica 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
2. Data Collected
We collect and process the following categories of personal data:
a) Membership data:
- First and last name
- Email address
- Phone number (optional)
- Date of birth (for age verification)
- Postal address (optional)
b) Profile and portal data:
- Profile photos and uploaded images (up to 10 photos)
- Profile description and personal details voluntarily provided by the Member
- Messages and interactions with other Members through the portal
- Wine Vault storage data (product names, quantities, values)
c) Technical and usage data:
- IP address and browser information
- Device type and operating system
- Access timestamps and page views
- Online status ("Last seen" timestamp) to improve member interaction
- Cookie data in accordance with our cookie policy
d) Payment data:
- Payment information is processed and stored exclusively by the payment service provider Stripe, Inc.
- We only receive a transaction confirmation from Stripe, the last four digits of the card number, and the payment status – no complete credit card or bank data.
3. Purpose of Processing & Legal Basis
- Contract performance (Art. 6(1)(b) GDPR): Management of membership, provision of the portal, payment processing, Wine Vault management.
- Legitimate interests (Art. 6(1)(f) GDPR): Improvement of our services, platform security, fraud prevention, online status display to foster member interaction.
- Consent (Art. 6(1)(a) GDPR): Marketing communications, newsletters, non-essential cookies.
- Legal obligations (Art. 6(1)(c) GDPR): Fulfilment of tax and commercial record-keeping requirements.
4. Data Processors & Data Sharing
We share personal data with the following categories of recipients:
- Stripe, Inc. (USA) – Payment processing. Stripe is certified under the EU-US Data Privacy Framework.
- Amazon Web Services (AWS) – Cloud hosting and file storage. Data processing within the EU (eu-west region).
- Abacus.AI – Technical platform infrastructure.
- Partners/Bodegas – Transaction-related data only (name, delivery address), as required for order fulfilment.
Data is not shared with other third parties unless we are legally obliged to do so or the Member has given express consent.
5. Data Sharing Between Members
In the members portal, certain profile data (name, photo, description) may be visible to other Members. Each Member is aware and agrees that:
- Profile information and photos are visible to all registered Members.
- The online status ("Last seen") may be visible to other Members.
- ATKINSKY S.L. has no control over how other Members use shared information and therefore assumes no liability for misuse by other Members.
- Each Member is personally responsible for deciding which personal data to share on the portal.
6. Cookies & Tracking
Our website uses:
- Technically necessary cookies: Required for the functioning of the website and members portal (session management, authentication, language settings). Legal basis: Art. 6(1)(f) GDPR.
- Online status tracking: We record the timestamp of the last access ("LastSeenAt" timestamp) of logged-in Members. This serves to improve interaction in the members portal. Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
A cookie banner is displayed upon first visit to our website. The Member may reject the use of non-essential cookies without affecting the core functionality of the website.
7. WhatsApp Communication
Our members portal offers a WhatsApp chat function for direct communication with our team. When you use this function, you will be redirected to WhatsApp (operated by Meta Platforms Ireland Ltd.). The privacy policies of WhatsApp/Meta apply. We have no influence over the data collected by WhatsApp.
8. Photos & Cloud Storage
Members may upload up to 10 photos to their profile. These photos are stored in a cloud infrastructure (AWS S3, EU region). Uploaded photos are visible to other portal Members. The Member may delete their photos at any time. Upon deletion, the photo files are irrevocably removed from cloud storage.
9. Retention Period
- Membership data: For the duration of membership and subsequently for the legally required retention period (in Spain: 6 years under Art. 30 Código de Comercio for business records; 4 years for tax-relevant data).
- Profile photos and portal content: Until deletion by the Member or until termination of membership.
- Technical log data: Maximum 90 days.
- Payment data at Stripe: According to Stripe's retention policies and legal requirements.
10. Your Rights
Under the GDPR and LOPDGDD, you have the following rights:
- Right of access (Art. 15 GDPR): You may request information about your stored personal data.
- Right of rectification (Art. 16 GDPR): You may request the correction of inaccurate data.
- Right of erasure (Art. 17 GDPR): You may request deletion of your data, provided no legal retention obligations apply.
- Right to restriction of processing (Art. 18 GDPR): You may request restriction of processing.
- Right to data portability (Art. 20 GDPR): You may receive your data in a structured, commonly used format.
- Right to object (Art. 21 GDPR): You may object to processing based on legitimate interest.
- Withdrawal of consent: Consent given may be withdrawn at any time with effect for the future.
To exercise your rights, please contact us by email at [email protected]. We will process your request within 30 days.
In addition, you have the right to lodge a complaint with the competent supervisory authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es.
11. Security Measures
We employ state-of-the-art technical and organisational measures to protect your personal data against loss, misuse, and unauthorised access. These include, among others, encrypted data transmission (TLS/SSL), access control systems, and regular security reviews.
12. Changes to This Privacy Policy
We reserve the right to adapt this privacy policy to reflect changes in the legal framework or changes to our services. The current version is always available on our website at aurum-lounge.com/datenschutz. In the event of material changes, registered Members will be informed by email.
As of: July 2026 · ATKINSKY S.L. · All rights reserved.