Back

Legal

Privacy Policy

Last updated: May 2026 · Demovance

1. Who we are

Demovance («we», «us») operates the Demo Ride Manager platform. We are the Data Controller for the personal data collected through this service.

Contact: privacy@demovance.com

2. Data we collect and why

DataPurposeLegal basis
Name, email, phoneBooking confirmation and event communicationContract (Art. 6.1.b)
Date of birthAge verification (18+ required)Legal obligation (Art. 6.1.c)
Document type and numberIdentity verification; document retained during test rideLegitimate interest (Art. 6.1.f)
Country, height, preferred sizeBike fitting and event logisticsContract (Art. 6.1.b)
Gender, province/regionAnonymized aggregate statistics to improve eventsLegitimate interest (Art. 6.1.f) — optional
Marketing consentSending news and promotional offersConsent (Art. 6.1.a)
Waiver acceptance timestampLegal record of liability waiverLegal obligation (Art. 6.1.c)

3. Data retention

  • Booking and personal data: retained for 24 months from the event date, then anonymized.
  • Document number: deleted 30 days after the event.
  • Marketing consent: retained until you withdraw consent.
  • Anonymized statistical data (gender, province in aggregate): retained indefinitely.

4. Your rights (GDPR Art. 15–22)

You have the right to:

  • Access — request a copy of all data we hold about you
  • Rectification — correct inaccurate personal data
  • Erasure — request deletion of your personal data («right to be forgotten»)
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interest
  • Restriction — request we limit processing of your data
  • Withdraw consent — at any time for marketing communications

You can exercise the rights of access, portability, erasure and marketing objection instantly through our self-service portal:

Manage my data →

For any other request, email privacy@demovance.com with your full name and booking code. We will respond within 30 days.

5. Data security

We implement technical and organisational measures to protect your data, including:

  • Encryption in transit (HTTPS/TLS)
  • Encryption at rest (Supabase managed PostgreSQL)
  • Application-level encryption for document numbers
  • Row-level security policies restricting data access by role
  • Access limited to authorised staff only

6. Third-party processors

All processors are bound by Data Processing Agreements (DPAs) in compliance with GDPR Art. 28.

7. Complaints

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Spanish Data Protection Authority (AEPD): www.aepd.es

© 2026 Demovance · All rights reserved.