SOMA
Privacy notice
This notice explains what personal data we collect through thesoma.app, why we collect it, and the rights you hold over it. It is issued under Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) and is written to be read, not to be survived.
1. Responsible Entity & Scope
SOMA Private Access ("SOMA", "we", "us", or "the Firm"), operating with registered office in Polanco, Mexico City, and commercial desks in Madrid and Ibiza, is responsible for the legitimate, controlled, and informed processing of your personal data. You can reach our Data Protection & Compliance Officer directly at admin@thesoma.app or via direct WhatsApp desk at +52 56 3955 7580.
This Privacy Notice governs all data collected across our web platforms (thesoma.app, including client briefs and ambassador representations), direct concierge channels, and private communication systems.
2. Personal Data We Collect
We adhere to strict data minimization principles. We only collect information that you expressly and voluntarily provide across our interaction streams:
- Private Client Briefs: Full name, contact email, WhatsApp or telephone number, destination preferences, booking itineraries (private aviation, yacht charters, off market stays, bespoke buyouts), estimated magnitude, urgency, mood and privacy requirements, and referral context.
- Ambassador Network Applications: Full name, verified contact channels (WhatsApp, phone, email), primary residential/operating hub, social verification handles (Instagram/LinkedIn), target client demographics, commercial priorities, acquisition channels, and 30 day source mapping notes.
- Partner & Allied Operator Inquiries: Organization name, commercial profile (air, sea, stays, venues, luxury brands), operating markets, frequency, and contact credentials.
- Technical & Sourcing Metadata: Campaign attribution parameters (UTM tags), referrer origin, timestamps, and encrypted server logs.
Sensitive Data Policy: SOMA does not solicit sensitive personal data (such as political affiliations, religious beliefs, biometric data, or health records) through public web forms. Any specific dietary, medical, or security requirements needed for confirmed flights or private vessel manifests will be requested exclusively through private, encrypted channels with your explicit consent.
3. Purpose of Data Processing
Your data is collected strictly for the following Primary Purposes, necessary to fulfill your relationship with SOMA:
- Reviewing, qualifying, and preparing defensible, highly curated proposals for private travel, aviation, charters, and exclusive access.
- Evaluating ambassador representation candidacies and managing confidential CRM territory allocation.
- Coordinating with certified charter operators, private aviation managers, villa directors, and discreet ground hospitality providers to execute confirmed bookings.
- Maintaining institutional records, invoicing, and adhering to applicable legal and tax compliance obligations.
Secondary Purposes: Occasionally notifying you of off market openings, private seasonal calendar circuits (summer/winter), or private networking gatherings relevant to your profile. You may opt out of secondary purposes at any time by emailing admin@thesoma.app with the subject "Opt out Secondary Communications".
4. Discretion, Sharing & Transfers
Discretion is the founding principle of SOMA. We do not sell, rent, monetize, or trade your personal data to third parties or advertising brokers under any circumstance.
Transfers of personal data are strictly limited to:
- Execution Partners: Verified aircraft operators, yacht captains, villa hosts, and discreet logistics providers strictly as necessary to execute reservations confirmed by you.
- Infrastructure Providers: Encrypted hosting and serverless architecture (Netlify Inc., USA), and direct communications infrastructure. All providers operate under strict confidentiality agreements adhering to international data security frameworks.
5. Retention & Confidentiality Standards
Briefs and inquiries that do not materialize into confirmed engagements are retained for a maximum of 24 months to recognize returning clients and preserve continuity of service. Records relating to executed commercial engagements are archived in encrypted storage for statutory periods required by commercial, civil, and tax laws, after which they are irreversibly destroyed or anonymized.
6. Your ARCO & Privacy Rights (GDPR & LFPDPPP)
Whether you are located in Mexico, the European Union, the United Kingdom, or the Americas, you possess full sovereignty over your personal data. You have the right to:
- Access: Request confirmation of what personal data we hold about you and how it is processed.
- Rectification: Request correction of inaccurate, outdated, or incomplete data.
- Cancellation / Erasure: Request the deletion of your data from our active databases.
- Opposition: Object to processing for specific purposes or revoke previously granted consent.
To exercise any of these rights, submit a written request to admin@thesoma.app indicating your full name, the specific right you wish to exercise, and a valid identification for verification. We process and respond to all requests within 15 to 20 business days.
7. Cookies & Tracking Technologies
Our website utilizes zero invasive third party tracking cookies, behavioral ad pixels, or surveillance scripts. We only process session parameters necessary to maintain secure browsing and attribution tags to understand how you arrived at our site.
8. Security Architecture
All data submitted to SOMA is transmitted via TLS 1.3 encryption (HTTPS) with strict HTTP Strict Transport Security (HSTS). Internal access is restricted on a least privilege basis exclusively to authorized executive and operations personnel.
9. Modifications to this Notice
We may update this Privacy Notice periodically to reflect operational, legal, or regulatory enhancements. Any updates will be published immediately on this page with the corresponding version and revision date.