Controller and contact
The verified legal identity of the controller, registered address and privacy contact must come from the company configuration. Find it in Spain is a brand name and is not described as the controller while the legal name remains unconfigured. Available verified details appear below.
Data we may collect
Depending on the interaction, data may include identity and contact details; business context; request details, type and category; destination, target date and phone region; attachments and filenames; correspondence; security and technical records; and attribution data only where the visitor has given the relevant consent.
Sensitive information
Please do not send passwords, payment-card data, special-category personal data, criminal-offence data or other unnecessary confidential information. If a request genuinely requires sensitive material, wait for an appropriate secure channel and specific instructions.
Purposes and legal bases
Data is intended to be used to assess and answer a request, take steps requested before a possible contract, communicate, deliver any later agreed service, meet legal obligations and protect the service. Bases may include GDPR Articles 6(1)(b), 6(1)(c), 6(1)(f) and, for optional purposes such as analytics attribution, 6(1)(a). Submitting a request does not opt anyone in to marketing.
Recipients and processors
Necessary categories may include hosting, secure storage, communications, CRM and professional-support providers, plus suppliers or specialists required to assess or perform a request. Access should be limited by role and contract, and identity details should be minimized before sharing with potential third parties.
International transfers
Some selected providers or request participants may process data outside the European Economic Area. Where Chapter V GDPR applies, an appropriate transfer mechanism and supplementary assessment or safeguards will be used as required; no transfer route is asserted until the actual provider and destination are known.
Retention
Data will be kept only for as long as needed for the request, any resulting relationship, security, dispute handling and mandatory records, then deleted or anonymized where appropriate. No fixed period is stated because an approved operational deletion schedule is still required before launch.
Rights and the AEPD
Subject to the law, people may request access, rectification, erasure, restriction, portability or objection, and may withdraw consent without affecting earlier lawful processing. Requests should use the verified privacy channel once configured. A complaint may also be made to the Spanish Data Protection Agency (AEPD) or another competent supervisory authority.
Security
Reasonable organizational and technical measures are intended to protect data according to risk, including controlled access and appropriate storage and transport safeguards. No system can be promised as completely secure, and controls must be reviewed as providers and operations are finalized.
Automated decisions
No solely automated decision-making producing legal or similarly significant effects is currently intended for website requests. If that changes, the required information, safeguards and review will be added before the processing begins.
Changes and review
This notice may change as the operating entity, providers and processes are confirmed. The date above identifies this draft; material changes will be documented, and professional approval is required before production publication.