VenturaCuida Privacy Policy
This policy explains how VenturaCuida processes personal data when users interact with VenturaCuida services, including the website, the public booking API, and the ChatGPT MCP booking connector.
1. Data categories we collect
For website, Public API, and ChatGPT MCP booking workflows, VenturaCuida collects only data needed to process session requests and provide support.
- Identity and contact data: client name, phone number, email address.
- Booking request data: partnership slug (venue), service slug, preferred date, preferred time, duration, optional notes, optional language, and optional nationality.
- Service location data: service address (hotel, Airbnb, or other requested location).
- Status and reference data: session reference (VC- code) and status information linked to the booking lifecycle.
- Security and abuse-prevention data: request metadata, including IP-based rate-limit and security logging data used to protect Public API and MCP endpoints.
VenturaCuida does not collect payment card data in ChatGPT MCP booking tools. VenturaCuida also does not request passwords, OTP/MFA codes, or API keys in booking submissions.
2. Purposes of processing
We process personal data only for specific purposes:
- To receive and manage massage or wellness booking requests.
- To contact guests and confirm availability details.
- To coordinate therapists, partner venues, and operations.
- To provide customer support and resolve booking-related incidents.
- To protect platform integrity (including abuse prevention and rate limiting).
- To comply with legal and regulatory obligations applicable in Portugal and the EU.
3. Categories of recipients
VenturaCuida may share personal data only where necessary with:
- VenturaCuida staff handling booking operations and support.
- Therapists and partner venues involved in delivering the requested session.
- Infrastructure and communications processors (for example hosting, email, and messaging providers) under data-processing and confidentiality terms.
- Competent authorities where disclosure is legally required.
VenturaCuida does not sell personal data.
4. Retention timelines
VenturaCuida retains personal data only for as long as required for booking operations, support, security, and legal compliance:
- Booking and support records: kept while active and for up to 24 months after completion, unless law requires longer retention.
- Security and rate-limit logs: retained for up to 12 months, unless a longer period is required for investigations or legal obligations.
- Legally required records: retained for the period mandated by applicable law.
VenturaCuida applies internal procedures to enforce these timelines.
5. User controls and privacy rights
Subject to applicable law, users may request:
- Access to their personal data.
- Correction of inaccurate or incomplete data.
- Deletion where retention is no longer required.
- Restriction of or objection to specific processing activities.
- Data portability where legally applicable.
To exercise these rights, contact VenturaCuida using the details below.
6. MCP and public API scope
The ChatGPT connector endpoint (/mcp) and Public API
booking flows (/api/public/v1) are designed to collect only
fields required to submit and track session requests.
Public API status checks require both the VC reference and matching client phone number. Tool responses are limited to booking-relevant information and support details.
7. Security measures
VenturaCuida applies technical and organizational safeguards, including HTTPS transport encryption, access controls, and monitoring controls designed to reduce unauthorized access, alteration, disclosure, or loss of personal data.
8. Contact
VenturaCuida — VENTURA & CÂMARA, LDA
Caminho do Cabouco, 7, 9325-051 Estreito de Câmara de Lobos, Madeira
+351 928 095 512
venturacuida@gmail.com
Operational support: venturacareportugal@gmail.com