How Club TXP, Inc. collects, uses, shares and protects personal data, and the rights available to the people whose data we hold.
SECTION 01
Who we are
To be suppliedClub TXP, Inc. as controller, registered address, company number, and the contact route for privacy enquiries. Name a representative or DPO if one is appointed.
SECTION 02
What we collect and how
To be suppliedCategories of data and their source, in one section: identity and verification data received from SafeQloud, contact details, property and ownership records, payment metadata, communications, device and usage data.
SECTION 03
Why we process it
To be suppliedTwo frameworks apply. For US residents, describe the purposes and any sale or sharing of personal information as those terms are defined by state law. For EU and UK residents, map each purpose to a lawful basis — contract, legal obligation, legitimate interests, consent — and state the legitimate interests relied upon.
SECTION 04
Who we share it with
To be suppliedRecipient categories: SafeQloud, ecosystem brands, professionals acting under mandate, payment providers, infrastructure suppliers, advisers, authorities. State plainly if personal data is never sold.
SECTION 05
International transfers
To be suppliedWith the United States as the primary market and operations in Sweden, Spain and the UAE, data moves in several directions. Set out EU-to-US transfers and the mechanism relied upon (Data Privacy Framework certification or standard contractual clauses), and transfers to the UAE.
SECTION 06
How long we keep it
To be suppliedRetention periods or the criteria that set them. Address how “records persist for the life of the asset” interacts with erasure rights — this is the clause most specific to Club TXP and the one worth getting right.
SECTION 07
How we protect it
To be suppliedTechnical and organisational measures, stated accurately and without overstatement. Reference any certification actually held.
SECTION 08
Your rights
To be suppliedTwo sets of rights, stated separately and clearly. US state rights: know, delete, correct, portability, opt out of sale or sharing, limit use of sensitive information, and non-discrimination for exercising them. EU and UK rights: access, rectification, erasure, restriction, portability, objection, automated decision-making. Give the request route and response period for each. This replaces the separate GDPR page.
SECTION 09
Cookies
To be suppliedCookie categories and the consent mechanism. Note that US state law generally requires an opt-out for sale or sharing, while EU law requires opt-in consent before non-essential cookies are set — the banner has to satisfy both.
SECTION 10
Changes and complaints
To be suppliedHow changes are notified and prior versions obtained. Then the complaint routes: the internal channel, the relevant US state Attorney General, and the EU lead supervisory authority. Identify which EU authority is lead based on where the main establishment sits — Stockholm or Madrid — as that is a determination, not a default.