Security Policy
Version 2.0 · Last updated: 9 August 2026
1. Purpose
This Security Policy (the "Security Policy") describes the general framework of technical, organizational and operational measures implemented by Bike Booking Engine, S.L. ("Bike Booking Engine", "BBE", "we", "us" or the "Company") to protect the Platform, the Services and the information processed in connection with the provision of such Services.
Its purpose is to provide a general overview of Bike Booking Engine's approach to security, promoting the confidentiality, integrity, availability and resilience of the systems supporting the Services.
This Policy forms part of Bike Booking Engine's legal and contractual framework and shall be interpreted together with the Terms of Service, Data Processing Agreement (DPA), Service Level Agreement (SLA), Privacy Policy, Acceptable Use Policy (AUP) and any other applicable contractual documentation.
2. Scope
This Policy applies, among other things, to:
- The SaaS Platform;
- The Booking Engine;
- The administration dashboard;
- Official APIs;
- Development and staging environments;
- Cloud infrastructure;
- Authentication systems;
- Internal security-related processes; and
- Authorized personnel involved in the operation of the Services.
3. Security Principles
Bike Booking Engine develops and operates its Services in accordance with the following security principles:
- Security by design;
- Principle of least privilege;
- Defense in depth;
- Logical segregation of information;
- Continuous improvement;
- Infrastructure monitoring;
- Risk reduction;
- Coordinated incident response; and
- Periodic review of security controls.
The measures described in this Policy constitute a general security framework and may evolve as the Platform, technology and identified risks change over time.
4. No Absolute Security Guarantee
Bike Booking Engine implements reasonable technical and organizational measures designed to reduce the risks associated with the provision of the Services.
However, no Internet-connected system can guarantee absolute protection against unauthorized access, unknown vulnerabilities, sophisticated attacks, human error or unforeseen events.
Accordingly, this Policy shall not be interpreted as a guarantee of invulnerability, the complete absence of security incidents or uninterrupted availability of the Services.
5. Cloud Infrastructure
The Bike Booking Engine Platform operates on professional cloud infrastructure provided by specialized service providers.
The primary infrastructure is currently hosted in data centers located within the European Union, supplemented by specialized technology providers where necessary to deliver specific functionalities.
Bike Booking Engine selects infrastructure providers based on factors including:
- Security;
- Availability;
- Reliability;
- Technical capabilities;
- Scalability; and
- Compliance with applicable data protection requirements.
The infrastructure and providers used may evolve as the technical, operational or security requirements of the Platform change.
6. Infrastructure Services
Bike Booking Engine uses various infrastructure services and cloud technologies to support the operation of the Platform.
These services may include, among others:
- Computing capacity;
- Database services;
- Storage systems;
- Backup systems;
- Content delivery;
- Connectivity;
- Security services; and
- Other components necessary for the provision of the Services.
Where certain services are provided by external providers, Bike Booking Engine seeks to select providers offering appropriate levels of security and reliability.
The use of external providers does not imply that such providers have unrestricted access to the information managed through the Platform.
7. Logical Segregation of Information
The Platform is designed as a multi-tenant environment in which logical segregation mechanisms are implemented to prevent one Customer from accessing data belonging to another Customer.
Each organization operates within its corresponding logical environment, and authorization controls determine which information and functionalities may be accessed by each user.
Authorized Users may only access information for which they have the appropriate permissions.
8. Access to Production Environments
Administrative access to production environments is restricted exclusively to authorized technical personnel who require such access to perform functions related to the administration, maintenance, security or support of the Platform.
Bike Booking Engine applies the principles of least privilege and role-based access control, seeking to limit privileges to the level reasonably necessary for each individual's responsibilities.
The number of individuals with administrative access to production environments is limited to the minimum reasonably necessary for the operation of the Services.
9. Administrative Authentication
Accounts with administrative access to production systems are protected through enhanced authentication mechanisms.
Bike Booking Engine requires Multi-Factor Authentication (MFA) for accounts with administrative privileges.
Credentials are personal and shall only be used by the individuals authorized to access the relevant systems.
10. Access Management and Revocation
Access rights shall only be maintained for as long as a legitimate operational need exists.
Where an individual no longer requires access as a result of a change in responsibilities, termination of an employment or contractual relationship, or any other relevant circumstance, their permissions shall be revoked or modified as appropriate.
In particular, access associated with individuals whose employment or contractual relationship with Bike Booking Engine has ended shall be revoked without undue delay.
11. Physical Security
Bike Booking Engine's primary infrastructure is hosted in data centers operated by specialized cloud infrastructure providers.
Accordingly, measures relating to the physical security of such data centers—including physical access controls, facility protection, power supply, environmental controls and other physical infrastructure safeguards—are managed by the relevant infrastructure providers.
Bike Booking Engine does not directly operate the data centers in which its cloud infrastructure is hosted.
12. Shared Responsibility Model
The security of the Services is based on a shared responsibility model.
Infrastructure providers are responsible for the security measures applicable to the services, systems and facilities under their control.
Bike Booking Engine is responsible for configuring, administering and protecting the components of the Platform under its control in accordance with the measures described in this Policy.
Customers, in turn, are responsible for protecting their own accounts, credentials, devices, networks and configurations, as well as for appropriately managing the permissions granted to their Authorized Users.
Effective security of the Platform therefore requires appropriate action by all parties involved.
13. Communications Security
Bike Booking Engine uses encryption mechanisms designed to protect communications between users and the Platform during the transmission of information.
Access to the Platform is provided through secure connections using HTTPS and industry-recognized TLS protocols.
The digital certificates used to protect such communications are issued by recognized certification authorities.
Bike Booking Engine may update the protocols, certificates and cryptographic mechanisms used as technology and security standards evolve.
14. Password Protection
Passwords used to access the Platform are not stored in plain text.
Bike Booking Engine applies cryptographic hashing mechanisms designed to protect stored credentials and reduce the risks associated with potential unauthorized access to its systems.
For security reasons, Bike Booking Engine does not publicly disclose detailed information regarding the specific algorithms, parameters or configurations used to protect credentials.
15. Protection Against Unauthorized Access Attempts
The Platform incorporates controls designed to reduce the risk of unauthorized access through repeated authentication attempts.
Such controls may include, where applicable:
- Login attempt limitations;
- Temporary account or access restrictions;
- Detection of suspicious activity patterns; and
- Other protective measures designed to prevent abusive behavior.
Bike Booking Engine may adapt these mechanisms based on identified risks and the evolution of security threats.
16. Session Management
User sessions are subject to controls designed to reduce the risk of unauthorized use of active sessions.
The Platform provides for the automatic expiration of sessions following specified periods of inactivity.
Security parameters relating to session management may be modified as the operational and security requirements of the Platform evolve.
17. Roles and Permissions
The Platform incorporates role-based access control and permission management mechanisms.
Customers may assign different access levels to their Authorized Users, allowing access to functionality and information to be restricted according to the responsibilities assigned within each organization.
Bike Booking Engine also implements authorization controls designed to prevent users from accessing resources for which they do not have the appropriate permissions.
18. Customer Data Isolation
Bike Booking Engine implements controls designed to preserve the logical segregation of data belonging to different Customers.
The Platform's authorization mechanisms are designed to prevent a Customer or its Authorized Users from accessing information belonging to another organization.
The technical architecture supporting such segregation may evolve over time, while seeking to maintain appropriate levels of data isolation and protection.
19. Protection of Sensitive Functionality
Certain Platform functionalities may be subject to additional controls where, due to their nature, they involve sensitive operations or require specific privileges.
Bike Booking Engine may implement additional authorization, validation, logging or control mechanisms where reasonably necessary to protect such functionality.
20. Customer Responsibility for Access Management
Customers are responsible for properly managing the accounts and permissions of their Authorized Users.
In particular, Customers are responsible for:
- Granting access only to authorized individuals;
- Assigning permissions appropriate to each user's responsibilities;
- Protecting access credentials;
- Preventing unauthorized sharing of credentials;
- Revoking access when it is no longer required; and
- Notifying Bike Booking Engine of any reasonable suspicion of unauthorized access.
The security controls implemented by Bike Booking Engine do not replace the Customer's obligation to maintain appropriate user and credential management practices.
21. Secure Development Lifecycle
Bike Booking Engine applies development practices designed to reduce the introduction of errors, vulnerabilities or unintended behavior as the Platform evolves.
Software changes are managed through development, review, validation and deployment processes appropriate to the nature and criticality of each modification.
Development practices may evolve as the Platform, technical team, tools and identified risks change over time.
22. Environment Separation
Bike Booking Engine maintains separate environments for the different stages of the development lifecycle.
As a general rule, separate environments are maintained for:
- Development;
- Pre-production or staging; and
- Production.
This separation allows changes to be developed and validated before they are introduced into the environment used by Customers.
Access controls and configurations may differ between environments according to their purpose and level of criticality.
23. Pre-Production Environment
Before being introduced into production, changes may be deployed and evaluated in a pre-production environment designed to validate their operation.
This environment enables preliminary checks intended to identify errors, incompatibilities or unexpected behavior before a modification is made available to Customers.
The nature and scope of testing performed will depend on the type and criticality of the change.
24. Version Control
The Platform's source code is managed through version control systems.
These mechanisms provide traceability over the evolution of the software, support the management of modifications and facilitate the review of implemented changes.
Access to repositories and development-related resources is restricted to authorized personnel according to their responsibilities.
25. Change Review and Validation
Changes intended for production are subject to review and validation processes prior to deployment.
Depending on the nature and criticality of each modification, these processes may include:
- Code review;
- Functional testing;
- Technical checks;
- Pre-production validation; and
- Other reasonable measures designed to reduce the risks associated with the change.
Bike Booking Engine may adapt the scope of such reviews according to the potential impact of each modification.
26. Deployment of New Versions
New versions are deployed through technical processes combining automation with supervision by authorized personnel.
Bike Booking Engine seeks to introduce changes in a controlled manner while minimizing, to the extent reasonably possible, any impact on the availability and stability of the Platform.
Where a deployment may affect Service availability, the maintenance provisions set out in the Service Level Agreement (SLA) shall also apply.
27. Software Dependencies and Components
Bike Booking Engine periodically reviews and updates the dependencies and components used by the Platform as part of its preventive maintenance activities.
Where applicable, mechanisms are used to identify known vulnerabilities that may affect the dependencies in use.
The priority and timing of updates may be determined by factors including:
- Severity of the vulnerability;
- Level of exposure;
- Potential impact;
- Availability of a fix;
- Compatibility with the Platform; and
- Risks associated with the update itself.
28. Vulnerability Management
Bike Booking Engine maintains processes designed to identify, assess and mitigate vulnerabilities that may affect components under its control.
Identified vulnerabilities may be assessed according to their criticality, potential impact and risk to the Platform.
Corrective measures may include, as appropriate:
- Updating components;
- Modifying configurations;
- Applying patches or fixes;
- Implementing additional controls; or
- Adopting other reasonable mitigation measures.
Bike Booking Engine may prioritize security actions according to the level of risk associated with each vulnerability.
29. Emergency Security Changes
Where a vulnerability or risk requiring immediate action is identified, Bike Booking Engine may implement emergency changes designed to protect the Platform, Customers or the information processed through the Services.
In such circumstances, certain standard deployment procedures may be reasonably adapted to reflect the urgency of the situation, while maintaining the controls considered appropriate under the circumstances.
30. Platform Monitoring
Bike Booking Engine maintains monitoring mechanisms designed to oversee the operation of the infrastructure and the Platform.
Monitoring is intended to facilitate the identification of:
- Technical incidents;
- Service degradation;
- Application errors;
- Anomalous behavior; and
- Other circumstances that may affect the operation, security or availability of the Services.
Monitoring mechanisms and tools may evolve as the architecture, operational requirements and identified risks change over time.
31. Error Logging
The Platform maintains technical logs of relevant errors in order to facilitate their identification, analysis and resolution.
These logs may contain technical information reasonably necessary to:
- Diagnose incidents;
- Investigate errors;
- Analyze the operation of the Services;
- Identify anomalous behavior; and
- Improve the stability and security of the Platform.
Bike Booking Engine seeks to limit the information recorded to that which is reasonably necessary for such purposes.
32. Access Logging
Bike Booking Engine maintains records relating to access to the Platform for security, operational and auditing purposes.
Such records may be used to:
- Investigate potential unauthorized access;
- Analyze security incidents;
- Detect anomalous behavior;
- Verify specific events; and
- Protect the integrity of the Platform.
The information recorded and its retention periods may vary depending on the nature of the record, its purpose and applicable legal or operational requirements.
33. Logging of Critical Actions
Certain actions considered relevant or sensitive within the Platform may be recorded through auditing mechanisms.
These records are intended to provide traceability for certain operations and, where necessary, facilitate:
- Incident investigation;
- Analysis of actions performed;
- Resolution of operational disputes;
- Detection of anomalous activity; and
- Protection of the security and integrity of the Services.
Not all actions performed within the Platform necessarily have the same level of logging or traceability.
34. Access to Logs
Access to technical, security and audit logs is restricted to authorized personnel where necessary for the performance of their responsibilities.
Bike Booking Engine implements controls designed to prevent indiscriminate access to such information.
Customers do not have automatic access to Bike Booking Engine's internal infrastructure or security logs, except where a specific Platform functionality expressly provides certain audit information.
35. Use of Logs
Logs generated by the systems may be used for purposes related to:
- Security;
- Maintenance;
- Support;
- Fraud or abuse prevention;
- Incident investigation;
- Technical diagnostics;
- Auditing;
- Compliance with legal obligations; and
- The establishment, exercise or defense of the legitimate rights and interests of Bike Booking Engine, its Customers or third parties.
Any processing of Personal Data arising from such logs shall be carried out in accordance with applicable law and the relevant contractual documentation.
36. Anomaly Detection and Analysis
Bike Booking Engine uses available monitoring and logging mechanisms to facilitate the detection and analysis of behavior that may be anomalous or inconsistent with the expected operation of the Platform.
Where a potentially relevant situation is identified, authorized personnel may perform reasonable checks to determine:
- Its origin;
- Scope;
- Impact;
- Potential risk; and
- Any appropriate corrective measures.
The existence of monitoring mechanisms does not imply that Bike Booking Engine can immediately or automatically detect every incident, vulnerability, attack or unauthorized activity.
37. Confidentiality of Security Information
Information generated by monitoring systems, internal logs, audit mechanisms and security tools may contain sensitive information regarding the architecture, operation or protection of the Platform.
For this reason, Bike Booking Engine may restrict the disclosure of such information where it reasonably considers that disclosure could:
- Compromise the security of the Platform;
- Reveal internal security controls;
- Facilitate malicious activity;
- Adversely affect third parties; or
- Prejudice ongoing security investigations.
The foregoing shall not prevent the disclosure of information where required by an applicable legal or contractual obligation.
38. Incident Management
Bike Booking Engine maintains procedures designed to manage incidents that may affect the security, confidentiality, integrity or availability of the Platform or the information processed through the Services.
When a relevant incident is detected, Bike Booking Engine will seek to take reasonable measures designed to:
- Identify the incident;
- Analyze its nature;
- Contain its potential effects;
- Assess its scope and impact;
- Implement appropriate corrective measures;
- Restore normal operations where necessary; and
- Document and monitor the incident through to closure.
The specific actions taken will depend on the nature, severity, scope and characteristics of each incident.
39. Incident Assessment
Incidents may be assessed based on factors including:
- Affected systems;
- Information potentially compromised;
- Number of Customers or users affected;
- Duration;
- Impact on Service availability;
- Potential impact on the confidentiality or integrity of information;
- Risk to affected individuals; and
- Potential legal, operational or security consequences.
The classification and response may be adjusted as the investigation progresses and additional information becomes available.
40. Containment and Mitigation
Where necessary, Bike Booking Engine may take immediate measures designed to contain an incident or reduce its impact.
Such measures may include, depending on the circumstances:
- Temporarily restricting certain access;
- Suspending functionality;
- Revoking sessions or credentials;
- Modifying configurations;
- Applying updates or fixes;
- Isolating specific components; or
- Implementing other reasonable technical or organizational measures.
Protecting the Platform, Customers and the information processed through the Services may require temporary measures affecting certain Service functionalities.
41. Investigation
Bike Booking Engine may analyze logs, systems and other information reasonably necessary to investigate a potential security incident.
Where possible, the investigation will seek to:
- Determine the origin of the incident;
- Identify affected systems or information;
- Assess its scope;
- Determine the measures required for resolution; and
- Reduce the risk of recurrence.
The existence of an investigation does not necessarily mean that a Personal Data Breach or an actual compromise of security has occurred.
42. Customer Notification
Where an incident materially affects the Services or the information of one or more Customers, Bike Booking Engine will assess whether notification is necessary based on the nature and impact of the incident, applicable contractual obligations and applicable law.
The need for notification will be assessed by Bike Booking Engine's technical personnel together with Company management.
Where appropriate, communications may include reasonably available information regarding:
- The nature of the incident;
- Known impact;
- Affected Services or information;
- Measures taken; and
- Any actions that Customers may reasonably be advised to take.
Information provided may be updated as the investigation progresses.
43. Personal Data Breaches
Where an incident constitutes or may constitute a Personal Data Breach, Bike Booking Engine shall act in accordance with its obligations under applicable data protection law and the Data Processing Agreement (DPA).
Where Bike Booking Engine acts as a Data Processor, it shall notify the Customer of Personal Data Breaches of which it becomes aware in accordance with the requirements and conditions set out in the DPA and applicable law.
Where the Customer acts as the Data Controller, the Customer shall be responsible for determining its own notification obligations towards supervisory authorities and affected Data Subjects, without prejudice to any assistance Bike Booking Engine is required to provide under applicable law.
44. Notification to Authorities
Where Bike Booking Engine is subject to a direct legal obligation to notify an incident to a competent authority, it shall make such notification in accordance with the requirements established by applicable law.
Where Bike Booking Engine acts exclusively as a Data Processor in relation to the affected data, the respective responsibilities of Bike Booking Engine and the Customer shall be determined in accordance with applicable law and the DPA.
45. Service Recovery
Following containment of an incident, Bike Booking Engine will seek to restore the normal operation of affected systems as soon as reasonably practicable and safe.
Recovery may be carried out progressively where appropriate to protect the integrity or security of the Platform.
Where necessary, available recovery and backup mechanisms may be used in accordance with the Backup & Retention Policy.
46. Post-Incident Analysis
Where justified by the nature or severity of an incident, Bike Booking Engine may conduct a post-incident analysis designed to:
- Identify relevant causes;
- Assess the effectiveness of the measures taken;
- Identify potential improvements;
- Reduce the likelihood of recurrence; and
- Strengthen existing controls where appropriate.
The findings may be used to improve Bike Booking Engine's technical, organizational and security processes.
47. Confidentiality During Investigations
Bike Booking Engine may temporarily restrict the information disclosed regarding an incident where reasonably necessary to:
- Preserve the security of the Platform;
- Avoid disclosing information that could facilitate malicious activity;
- Protect other Customers or third parties;
- Preserve evidence;
- Avoid interference with the investigation; or
- Comply with legal obligations.
Such restrictions shall not affect any notification or disclosure obligations required by applicable law or contract.
48. Backup Strategy
Bike Booking Engine maintains backup mechanisms designed to reduce the risk of data loss and facilitate system recovery in the event of certain incidents.
Backups form part of the technical and organizational measures implemented to support the availability, integrity and resilience of the Services.
The backup strategy may evolve as the Platform architecture, identified risks and operational requirements change over time.
49. Backup Frequency
Bike Booking Engine performs backups periodically in accordance with its established internal procedures.
The strategy includes different backup and retention cycles with the aim of providing multiple recovery points in the event of certain incidents.
Specific backup frequencies and retention periods shall be described, where applicable, in the Backup & Retention Policy.
50. Separation of Backups
Backups are maintained separately from the primary server to which they relate, with the aim of reducing the risk that an incident affecting the primary system could simultaneously compromise the available recovery mechanisms.
The architecture and technical mechanisms used to achieve such separation may evolve over time as the technologies and providers used by Bike Booking Engine change.
51. Backup Retention
Backups are retained for defined periods in accordance with the retention cycles established by Bike Booking Engine.
Once the applicable retention period has expired, the corresponding backups are deleted in accordance with the ordinary rotation cycle.
Specific retention periods may vary depending on the type of backup, its purpose, the affected system and operational requirements.
The applicable criteria shall be further described in the Backup & Retention Policy.
52. Restoration Testing
Bike Booking Engine periodically performs restoration tests designed to verify the integrity of backups and the ability to recover from certain incidents.
These tests are intended to provide reasonable assurance that backup and recovery mechanisms operate in accordance with their intended purpose.
The performance of restoration tests does not constitute a guarantee that all information can be fully recovered under every circumstance.
53. Recovery Following Incidents
Where an incident results in the loss, corruption or unavailability of information, Bike Booking Engine may use the available recovery mechanisms where technically feasible and reasonably appropriate.
Recovery may depend on factors including:
- The nature of the incident;
- When the incident occurred;
- The systems affected;
- The available recovery point;
- The integrity of existing backups; and
- The technical characteristics of the affected system.
Bike Booking Engine does not guarantee that any individual item of data can be recovered in all circumstances.
54. Service Resilience
Bike Booking Engine implements measures designed to support the resilience of the Platform and reduce the impact of certain technical incidents.
Such measures may include, where applicable:
- Backups;
- Monitoring;
- Environment separation;
- Recovery procedures;
- Incident management;
- Preventive maintenance; and
- The use of professional cloud infrastructure.
The specific measures implemented may evolve as the Platform and the risks associated with its operation change over time.
55. Service Continuity
Bike Booking Engine seeks to maintain reasonable mechanisms designed to restore the provision of the Services following incidents affecting Platform availability.
However, continuity and recovery mechanisms do not constitute a guarantee of uninterrupted availability, immediate recovery or the absence of data loss under all circumstances.
Service availability commitments shall be governed by the Service Level Agreement (SLA) where applicable.
56. Customer Responsibility
The backup mechanisms maintained by Bike Booking Engine form part of the Platform's operational and security infrastructure and do not replace any retention, archiving or record-keeping obligations that may apply to the Customer under applicable law or according to its own business requirements.
Where the Platform provides functionality allowing certain information to be exported, Customers may use such functionality to maintain additional copies of any data they consider necessary for their business activities.
The existence of Bike Booking Engine's backup systems shall not be interpreted as an independent permanent archiving service or as a commitment to retain information indefinitely.
57. Protection of Information
Bike Booking Engine implements technical and organizational measures designed to protect information processed through the Platform against risks such as:
- Unauthorized access;
- Improper alteration;
- Loss;
- Destruction;
- Unauthorized disclosure; and
- Processing incompatible with the intended purposes.
The measures implemented are determined taking into account the nature of the Services, the information processed, identified risks and reasonably available technical capabilities.
58. Processing of Personal Data
Where Bike Booking Engine processes Personal Data on behalf of a Customer in connection with the provision of the Services, Bike Booking Engine will generally act as a Data Processor, while the Customer will act as the Data Controller, unless a different relationship applies according to the specific nature of the processing.
The specific terms governing the processing of Personal Data on behalf of the Customer shall be set out in the Data Processing Agreement (DPA).
This Security Policy describes the general security framework and does not replace the specific obligations established under the DPA or applicable law.
59. Personnel Access to Customer Data
Access to Customer information by Bike Booking Engine personnel is restricted to authorized individuals who require such access to perform their responsibilities.
Such access may occur, among other circumstances, where reasonably necessary to:
- Provide support;
- Investigate incidents;
- Perform maintenance activities;
- Protect the security of the Platform;
- Comply with legal obligations; or
- Perform other legitimate functions related to the provision of the Services.
Access shall be limited to the information reasonably necessary for the relevant purpose.
60. Confidentiality
Personnel with access to confidential information are subject to confidentiality obligations.
Bike Booking Engine seeks to ensure that access to Customer information occurs only within the scope of authorized responsibilities and in accordance with applicable internal security measures.
Confidentiality obligations may continue after termination of the relevant employment or contractual relationship where applicable.
61. Third-Party Providers
Bike Booking Engine may engage specialized technology providers to deliver certain components of the Services.
Such providers may provide, among other things:
- Cloud infrastructure;
- Storage;
- Communications;
- Payment processing;
- Content delivery;
- Security services;
- Artificial intelligence services, where applicable; and
- Other technological functionality necessary for the operation of the Platform.
Bike Booking Engine seeks to select providers based on reasonable criteria relating to security, reliability, technical capabilities and regulatory compliance.
The identity of specific providers may evolve as the technical and operational requirements of the Platform change.
62. Provider Access to Information
The engagement of an external provider does not necessarily mean that such provider has access to all data managed through the Platform.
The scope of processing will depend on:
- The nature of the service provided;
- The integration used;
- The information necessary to provide that service; and
- Applicable instructions and configurations.
Where a provider processes Personal Data on behalf of Bike Booking Engine in connection with Services provided to a Customer, such processing shall be managed in accordance with applicable data protection obligations.
63. Payment Services
Where the Platform incorporates payment functionality, certain transactions may be processed through specialized payment service providers.
Bike Booking Engine may integrate such services without necessarily directly storing all financial information used in connection with a transaction.
The security, availability and processing of information directly managed by such providers shall also be subject to their own systems, controls and responsibilities.
64. Artificial Intelligence Features
The Platform may incorporate optional functionality based on artificial intelligence technologies.
Bike Booking Engine's core functionalities do not, by default, require sensitive Customer data to be transmitted to external artificial intelligence services.
Where an optional feature requires the involvement of an external artificial intelligence provider, the processing of information will depend on the nature of that functionality, its configuration and the Customer's use of the feature.
Bike Booking Engine may establish specific controls, limitations or conditions applicable to such functionality as the Platform, technology and applicable regulatory requirements evolve.
65. Data Retention Following Service Termination
Following the termination or cancellation of a subscription, Customer Data may be temporarily retained for the period established by Bike Booking Engine in order to allow, where applicable:
- Reactivation of the Service;
- Recovery or export of information;
- Management of outstanding obligations; and
- Compliance with legal or contractual obligations.
Once the applicable period has expired, the data shall be deleted from active systems in accordance with established procedures, unless a legal obligation or other lawful basis requires additional retention.
Specific retention periods shall be established in the applicable contractual documentation or in the Backup & Retention Policy, as appropriate.
66. Data Contained in Backups
Deletion of information from active systems does not necessarily result in its immediate deletion from all existing backups.
Data may remain temporarily within backups until those backups reach the end of their ordinary retention period and are deleted in accordance with the applicable rotation cycle.
During this period, backups shall remain subject to the applicable security controls and shall not be intended for use in the ordinary operation of the Platform.
Any restoration of a backup containing information that had previously been deleted shall be subject to the applicable technical and deletion procedures.
67. International Data Transfers
Where the provision of certain Services involves the processing or transfer of Personal Data outside the territory in which the relevant data protection legislation applies, Bike Booking Engine shall seek to implement the mechanisms and safeguards required under applicable law.
The specific terms governing international transfers carried out in Bike Booking Engine's capacity as a Data Processor shall be addressed, where applicable, in the Data Processing Agreement (DPA).
68. Organizational Security
Bike Booking Engine implements organizational measures designed to restrict access to systems and information based on each individual's responsibilities and operational needs.
The security of the Platform does not depend exclusively on technological measures, but also on the appropriate management of individuals who may have access to systems, infrastructure or Customer information.
Organizational controls may evolve as the Company's structure, personnel, Services and identified risks change over time.
69. Restricted Access to Information
Not all Bike Booking Engine personnel have access to Customer Data.
Access is restricted to authorized individuals who require such information to perform legitimate functions related to the provision of the Services.
Where access to Customer information is necessary, such access shall be reasonably limited according to:
- The individual's responsibilities;
- The purpose of the access;
- The systems required; and
- The level of privileges necessary.
Bike Booking Engine applies the principle of least privilege when managing such access.
70. Technical Personnel with Privileged Access
Privileged access to production systems, infrastructure and other sensitive resources is restricted to authorized technical personnel who require such privileges to perform their responsibilities.
Administrative privileges are not granted generally to all personnel.
Bike Booking Engine seeks to limit the number of individuals with privileged access to the minimum reasonably necessary to operate, maintain and protect the Platform.
71. Confidentiality Obligations
Individuals with access to confidential information are subject to confidentiality obligations appropriate to the nature of their responsibilities.
Personnel and collaborators with access to confidential information shall protect such information against:
- Unauthorized disclosure;
- Use for purposes other than those authorized;
- Access by unauthorized third parties; and
- Any other use incompatible with their obligations.
Such obligations may be established through employment agreements, service agreements, non-disclosure agreements or other appropriate legal instruments.
72. Contractors and External Collaborators
Where Bike Booking Engine engages developers, consultants, contractors or other external collaborators who require access to systems or information, such access shall be subject to appropriate controls based on the tasks they are required to perform.
Where applicable, such individuals shall also be subject to confidentiality obligations and applicable access restrictions.
The status of an external collaborator does not, in itself, grant general access to systems or Customer Data.
73. Access Lifecycle Management
Access permissions may be granted, modified or revoked as each individual's responsibilities and operational requirements change.
Bike Booking Engine seeks to keep privileges aligned with the responsibilities actually performed.
Where an individual ceases to collaborate with Bike Booking Engine or no longer requires certain access rights, the corresponding permissions shall be revoked or modified as appropriate.
74. Termination of Employment or Contractual Relationships
Where an employment or contractual relationship involving access to Bike Booking Engine systems ends, the corresponding access rights shall be revoked without undue delay.
Where applicable, Bike Booking Engine may also implement other reasonable measures designed to protect systems and information following the termination of such relationship.
Confidentiality obligations that, by their nature, are intended to survive termination shall continue to apply in accordance with the relevant agreements.
75. Authorized Use of Systems
Bike Booking Engine's internal systems, credentials and resources shall be used exclusively for authorized purposes related to the relevant individual's responsibilities.
Authorized individuals shall act reasonably to protect:
- Their credentials;
- The systems to which they have access;
- Confidential information;
- Customer Data; and
- Any other Bike Booking Engine resources under their control.
Authorized access to a system does not constitute authorization to use the information available within that system for any purpose other than the purpose for which access was granted.
76. Management of Access-Related Incidents
Where Bike Booking Engine becomes aware of, or reasonably suspects, that credentials, an account or privileged access may have been compromised, it may take immediate measures designed to protect its systems.
Such measures may include, as appropriate:
- Revoking access;
- Resetting credentials;
- Terminating active sessions;
- Temporarily modifying permissions;
- Reviewing logs; and
- Implementing other reasonable containment or investigative measures.
Such actions may be taken as a precaution where there is a reasonable risk to the security of the Platform.
77. Shared Personnel Responsibility
Bike Booking Engine considers security to be a shared responsibility among the individuals involved in the development, operation, maintenance and support of the Platform.
Authorized personnel shall act in accordance with the security measures applicable to their responsibilities and cooperate in the identification, reporting and resolution of potential security risks or incidents.
Organizational measures may be reviewed and adapted as the threat environment, the Platform and the Company's organizational structure evolve.
78. Security Governance
Bike Booking Engine considers security an essential component of the development, operation and evolution of the Platform.
Security-related decisions may involve the Company's technical personnel and management depending on the nature, impact and criticality of the matter under consideration.
Bike Booking Engine seeks to integrate security considerations into the technical and operational processes relevant to the provision of the Services.
79. Risk Assessment
Bike Booking Engine adopts a risk-based approach to determining and prioritizing the security measures applicable to the Platform.
The assessment of a risk may take into account factors including:
- The nature of the threat;
- The reasonable likelihood of occurrence;
- The potential impact;
- The systems or information affected;
- The criticality of the Services involved;
- Existing protective measures; and
- Reasonable mitigation options.
Measures adopted may be proportionate to the level of risk identified.
80. Review of Security Measures
Bike Booking Engine may review the technical and organizational measures applicable to the Platform in order to assess their suitability in light of existing risks, technologies and operational requirements.
Such reviews may take place, among other circumstances:
- As part of Platform maintenance;
- Following significant infrastructure changes;
- After significant incidents;
- Upon identification of new vulnerabilities;
- When new functionalities are introduced;
- In response to relevant regulatory changes; or
- Where justified by the evolution of identified risks.
81. Continuous Improvement
Bike Booking Engine applies a principle of continuous improvement to the security of the Platform.
As a result of monitoring, maintenance, vulnerability analysis, incident investigation or technological developments, Bike Booking Engine may:
- Modify existing controls;
- Introduce new measures;
- Replace technologies;
- Update procedures;
- Strengthen configurations; or
- Adopt other measures designed to reduce risks.
The evolution of security measures shall not necessarily require an amendment to this Policy where the general principles and commitments described herein remain substantially unchanged.
82. Adaptation to Emerging Threats
Cybersecurity threats continuously evolve.
Bike Booking Engine may adapt its technical and organizational controls when new threats, vulnerabilities, attack patterns or risks that may affect the Platform are identified.
The measures adopted may vary depending on the severity, likelihood and potential impact of the identified risk.
83. Technological Evolution
Bike Booking Engine may modify the architecture, infrastructure, providers, tools, systems and technologies used to provide the Services.
Such changes may be made for reasons relating to:
- Security;
- Performance;
- Availability;
- Scalability;
- Maintenance;
- Efficiency;
- Regulatory compliance; or
- The general evolution of the Platform.
This Security Policy shall not be interpreted as a commitment to maintain any particular architecture, technology, provider or technical implementation.
84. Regulatory Compliance
Bike Booking Engine seeks to adapt its security measures to the obligations applicable to it under relevant laws and regulations.
Where Bike Booking Engine processes Personal Data, the applicable measures shall be interpreted together with the Privacy Policy, the Data Processing Agreement (DPA) and any other relevant documentation.
The existence of this Policy shall not be interpreted as a representation of certification or compliance with any specific standard unless expressly stated by Bike Booking Engine.
85. Certifications and Standards
This Security Policy does not imply that Bike Booking Engine holds any particular certification, independent audit or accreditation under specific information security standards.
Any certification, audit or standard that Bike Booking Engine may adopt in the future shall be expressly communicated where applicable.
References to security principles or best practices contained in this Policy shall not be interpreted as a representation of certification under any particular framework.
86. Cooperation with Customers
Bike Booking Engine may provide Customers with reasonable information regarding its security measures where necessary to assess the use of the Services or comply with regulatory obligations.
Any information provided shall be subject to limitations necessary to protect:
- The security of the Platform;
- Confidential information;
- Trade secrets;
- Information relating to other Customers;
- Internal configurations; and
- Any information whose disclosure could reasonably increase security risk.
Bike Booking Engine may require appropriate confidentiality commitments before providing non-public security information.
87. Shared Responsibility
The security of the Services requires cooperation between Bike Booking Engine, its technology providers and Customers.
Bike Booking Engine is responsible for implementing reasonable measures in relation to the systems and components under its control.
External providers are responsible for the measures applicable to the services and infrastructure under their control.
Customers are responsible, among other things, for:
- Protecting their credentials;
- Properly managing their Authorized Users;
- Correctly configuring permissions;
- Protecting their devices and networks;
- Using the Platform in accordance with applicable documentation; and
- Reporting potential incidents or unauthorized access of which they become aware.
88. Review of this Policy
Bike Booking Engine may review and update this Security Policy where necessary to reflect changes in:
- Security measures;
- The Platform;
- The Services;
- Applicable law;
- Identified risks; or
- Organizational practices.
The version in force shall be the version published or otherwise made available by Bike Booking Engine from time to time.
Where a change is materially relevant to Customers, Bike Booking Engine will seek to communicate such change through reasonable means.
89. Relationship with Other Documents
This Security Policy forms part of Bike Booking Engine's general security, privacy and service delivery framework.
Where applicable, it shall be interpreted together with:
- The Terms of Service;
- The Service Level Agreement (SLA);
- The Data Processing Agreement (DPA);
- The Privacy Policy;
- The Acceptable Use Policy (AUP);
- The Backup & Retention Policy; and
- Any other contractual documentation applicable to the Services.
Each of these documents governs specific matters and shall apply within its respective scope.
90. Contractual Precedence
This Security Policy describes the general security framework applied by Bike Booking Engine and is not intended to replace specific obligations undertaken through individual agreements with particular Customers.
In the event of any conflict between this Policy and a specific written agreement entered into between Bike Booking Engine and a Customer, the specific agreement shall prevail with respect to the matters expressly governed by it.
The foregoing shall be without prejudice to any obligations arising under applicable law.
91. Confidential Security Information
This Policy is intended to provide transparency regarding Bike Booking Engine's general approach to security without disclosing information that could compromise the protection of the Platform.
Bike Booking Engine may keep confidential certain information relating to:
- Detailed technical architecture;
- Security configurations;
- Credentials or internal authentication mechanisms;
- Security and protection rules;
- Detailed vulnerability information;
- Internal logs;
- Incident response procedures;
- Security tools;
- Investigation findings; and
- Any other information whose disclosure could reasonably increase the risk to the Platform, Customers or third parties.
The absence of such information from this Policy does not imply that additional security measures are not in place.
92. Amendments
Bike Booking Engine may amend this Security Policy where necessary to reflect changes in the Services, technology, security measures, internal processes, legal requirements or identified risks.
An amendment to this Policy shall not necessarily be required where changes affect only technical implementations, providers, tools or internal configurations and the general principles described in this Policy remain substantially unchanged.
Where an amendment to the Policy is materially relevant to Customers, Bike Booking Engine will seek to communicate it through reasonable means.
93. Security Contact
Questions relating to this Security Policy or the security of the Services may be submitted to:
BIKE BOOKING ENGINE, S.L.
Tax Identification Number (NIF): B44711695
Avinguda Bartomeu Riutort, 57, Ground Floor 07610 Palma Balearic Islands Spain
Email: info@bikebookingengine.com
Where a communication relates to a potential vulnerability or security incident, sufficient information should be provided to enable its assessment, while avoiding the public disclosure of details that could compromise the security of the Platform.
94. Effective Date
This Security Policy shall take effect on the date indicated as its Last Updated date.
Continued use of the Services shall be subject to the version of this Policy then in force, without prejudice to the rights and obligations established under applicable agreements.
95. Version and Last Updated
Version: 2.0
Last Updated: 09/08/2026