Skip to content

Privacy policy

Last updated: 2026-09-26

Translation provided for convenience. In case of discrepancy, the Spanish version prevails.

1. Data controller

  • Identity:
  • Tax ID:
  • Address:
  • Email to exercise your rights:

2. What data we process

The data you provide in the contact form: name or company, email or phone/WhatsApp, service of interest, description of your case, urgency and language. In addition, for security, the IP address and submission date.

3. Purpose

  • To reply to your request and, if you ask for it, prepare a proposal.
  • To protect the form against abuse and spam (submission limits, anti-spam check).

We do not use your data for advertising or profiling.

4. Legal basis

  • Your consent when submitting the form (Art. 6(1)(a) GDPR).
  • Pre-contractual measures at your request, if you ask for a proposal (Art. 6(1)(b) GDPR).
  • Legitimate interest in site security for technical anti-spam data (Art. 6(1)(f) GDPR).

5. Retention

While we handle your request and then for a maximum of 12 months if no business relationship arises, unless a longer period is legally required. If an engagement is signed, the periods required by commercial and tax law.

6. Recipients

We do not disclose your data to third parties unless legally required. The following act as processors under an Art. 28 GDPR agreement:

  • The website and database hosting provider.
  • The email provider through which we receive notification of your request.
  • Cloudflare (Turnstile anti-spam check). This may involve international transfers covered by the EU-US Data Privacy Framework or standard contractual clauses.

7. Your rights

You may exercise your rights of access, rectification, erasure, objection, restriction and portability, and withdraw your consent at any time, by writing to the email above. If you believe your request has not been handled properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or with your local supervisory authority.

8. Security

We apply proportionate technical and organisational measures: encrypted connection (HTTPS), restricted access to data and access logging.