Privacy policy
Information template aligned with GDPR and Spanish data protection law. Complete bracketed sections and adapt to your real processing (vendors, cookies, etc.).
1. Data controller
[Company name] — Tax ID: [NIF/CIF] — Address: [address] — Email: [privacy contact email].
2. Purposes and legal basis
- Order and enquiry handling (web form, email, phone): legal basis in pre-contractual or contractual measures (GDPR Art. 6.1.b).
- Legal obligations (invoicing, tax): GDPR Art. 6.1.c.
- Web analytics (if you enable cookies or analytics tools): consent (Art. 6.1.a) or legitimate interest depending on setup; describe precisely here.
3. Retention
Data are kept as long as needed for the purpose and, where applicable, for legal retention periods (e.g. commercial or tax).
4. Recipients
We will not share data with third parties except where required by law or needed to provide the service (e.g. courier, payment gateway or transactional email such as Resend). List processors and links to their policies here if applicable.
5. Rights
You may exercise access, rectification, erasure, objection, restriction and portability by writing to [email], proving your identity. You may complain to the Spanish Data Protection Agency (www.aepd.es).
6. Security
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss or alteration.
