Privacy Policy
1. Commitment to Privacy and Data Protection
At culiacanturismo.com (“we”, “us”, or “our”), your privacy is of paramount importance to us. We are committed to protecting and safeguarding the personal data of all users and visitors to our website in accordance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the California Consumer Privacy Act (“CCPA”). This Privacy Policy has been developed to inform you about how we collect, use, store, disclose, and safeguard your personal information when you access or use our services via culiacanturismo.com.
2. Scope of Policy and Data Controller Role
This Privacy Policy applies to all data collected through your use of culiacanturismo.com and associated services or communications. culiacanturismo.com operates as the data controller in relation to all personal data you provide or that is collected on our platform. Our responsibilities include determining the purposes and means of processing your personal data.
If you have any privacy-related questions or concerns, you may contact us at [email protected].
3. Categories of Data We Process
We may collect and process various categories of personal data depending on your interaction with our website:
a. Usage Data: Information relating to your interaction with our website, including your IP address, browser type, operating system, referrer URLs, duration of visits, page views, clickstream data, and session identifiers.
b. Account Data: Personal details you provide when creating an account, such as your full name, email address, postal address, and phone number.
c. Profile Data: Data that reflects your preferences, past travel bookings, interactive behavior, saved itineraries, interests, and any personalization settings.
d. Communication Data: Records of correspondence, customer support queries, feedback submissions, and email conversations you have had with us.
e. Technical Data: Device identifiers, mobile operating system, browser plug-in types, time zone settings, system configurations, and other diagnostic data.
f. Transaction Data: Details regarding bookings, purchases, payment history, billing information, and delivery-related data tied to your transactions.
g. Preference Data: Marketing consent status, email newsletter subscriptions, opted-in product updates, and your declared interests in tourism services.
4. Legal Bases for Processing
We rely on the following legal grounds to process your personal data:
– Consent: Where you have given us clear permission to process your personal data for a specific purpose, such as subscribing to a newsletter.
– Contractual Necessity: Where processing is necessary to fulfill our contractual obligations to you, such as processing bookings or customer support.
– Legal Obligation: Where we are required to process your data under applicable laws.
– Legitimate Interests: Where processing is necessary for the purposes of our legitimate interests, such as improving user experience, protecting website security, or conducting business analytics, provided such interests are not overridden by your rights and freedoms.
5. Your Data Protection Rights
Subject to applicable laws, you have the following rights concerning your personal data:
– Right of Access: You may request confirmation and access to the personal data we hold about you.
– Right to Rectification: You have the right to correct incomplete or inaccurate data.
– Right to Erasure: You may request that your data be deleted when it is no longer necessary or if you withdraw consent.
– Right to Restrict Processing: You can request that we limit the use of your personal data in specific circumstances.
– Right to Data Portability: When feasible, you may request that your data be transferred to another provider in a structured, commonly used format.
– Right to Object: You can object to the processing of your data for direct marketing or on the basis of legitimate interests.
– Right to Withdraw Consent: If processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.
Requests to exercise any of these rights may be submitted to [email protected].
6. Security Measures
We implement and maintain state-of-the-art administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of your personal data. These include but are not limited to:
– TLS/SSL encryption for data in transit.
– Role-based access control and authentication protocols for our personnel.
– Regular data backups and secure storage solutions.
– Security awareness training and compliance frameworks for staff handling personal data.
While we strive to use commercially acceptable means to protect your data, no method of transmission over the internet or method of storage is 100% secure.
7. International Data Transfers
Your personal data may be transferred to and stored on servers located outside of your jurisdiction, including in countries that may have different data protection laws than your own. Where such transfers occur, we ensure that appropriate safeguards are in place, such as European Commission-approved Standard Contractual Clauses for data transfers from the European Economic Area, or other mechanisms compliant with GDPR and CCPA requirements.
8. Data Retention
We retain personal data for only as long as it is necessary to fulfill the purposes for which it was collected, or as required by law. Our retention periods are as follows:
– Usage Data: 12 months
– Account Data: Retained while the account is active and for 2 years thereafter for record-keeping.
– Profile Data: Retained until deletion or deactivation of account.
– Communication Data: 3 years following resolution of query or termination of services.
– Technical Data: 12 months unless associated with a security investigation.
– Transaction Data: 7 years for accounting and tax obligations.
– Preference Data: Until consent is withdrawn or 2 years after last interaction, whichever comes first.
You may request deletion of your data subject to any legal limitations by contacting [email protected].
9. Cookie Policy
culiacanturismo.com uses cookies and similar tracking technologies to ensure the proper functioning of our website and to improve user experience. Our usage includes:
– Essential Cookies: Necessary for navigating the site and utilizing basic functions.
– Functional Cookies: Help personalize content and remember your preferences.
– Analytics Cookies: Used to track performance and usage data (e.g., Google Analytics).
– Performance Cookies: Allow us to analyze aggregated website behavior to improve responsiveness and reliability.
10. Cookie Management and Compliance
Upon your first visit to culiacanturismo.com, you will be presented with the option to manage your cookie preferences in compliance with GDPR and CCPA standards. You may also modify or withdraw your consent at any time by accessing your cookie settings or adjusting your browser preferences. Do Not Track (DNT) signals are honored where applicable.
11. Children’s Data Protection
Our services are not directed to children under the age of 13, and we do not knowingly collect personal information from anyone in this age group. If we discover that we have collected personal information from a child under 13 without verifiable parental consent, we will take immediate steps to delete such information. Parents or guardians who believe we may have inadvertently collected such data should contact us at [email protected].
12. Policy Updates and User Notifications
We reserve the right to amend this Privacy Policy to reflect changes in our operations, legal requirements, or best practices. We will notify users of significant changes by posting an updated policy on culiacanturismo.com and, where appropriate, through direct communication methods such as email. Please review this policy from time to time to stay informed of how we handle your data.
13. Contact
For any questions, requests, or concerns regarding your personal data or this Privacy Policy, please contact:
Email: [email protected]
We are committed to upholding the privacy principles outlined herein and to ensuring our compliance with all relevant data protection laws. If you believe your rights have been violated or have broader concerns about our data practices, please do not hesitate to get in touch with us.