Last updated: September 2026
1. Data controller
Tax ID: F75532804
C. Guillermo Carrera Rubio, 8
29003 Málaga (Spain)
Contact and data rights requests: [email protected]
2. Data we process
The form requests only your name, email address, subject and message. Any information you choose to include in the message will also be processed in order to handle your enquiry.
The infrastructure and security systems may process necessary technical data, including IP addresses, basic request information, timestamps and anti-fraud signals. This data is not used for advertising, commercial profiling or first-party analytics.
3. Source of the data
Contact information comes directly from the person using the form or writing to the listed email address. Technical data is generated during the connection and through the use of infrastructure and security mechanisms.
4. Purposes
Form data will not be used for newsletters, marketing campaigns or subsequent marketing without a separate lawful basis.
- Manage and respond to general and professional enquiries and collaboration proposals.
- Handle requests connected with a potential pre-contractual, professional or contractual relationship.
- Protect the form and infrastructure against abuse, fraud and automated traffic.
- Obtain aggregated, privacy-first information about website operation through Cloudflare Web Analytics.
5. Lawful bases
Where an enquiry concerns potential work, processing is based on pre-contractual steps requested by the individual. General enquiries are processed under the controller’s legitimate interest in receiving, managing and responding to them, balanced against the rights and reasonable expectations of the person making contact.
Website security relies on the legitimate interest in preventing abuse and preserving the integrity of the service and, where applicable, compliance with legal obligations. If future processing relies specifically on consent, that consent may be withdrawn at any time without affecting earlier lawful processing.
6. Recipients and service providers
Personal data is not sold. The following providers may act as processors or service providers within their respective roles:
Data may also be disclosed where required by law or where necessary to establish, exercise or defend legal claims.
- Hostinger: website hosting and infrastructure.
- Cloudflare: DNS, proxy/CDN, security, Turnstile anti-bot protection and aggregated Cloudflare Web Analytics.
- Resend: transactional processing and delivery of information submitted through the form.
- Tuta Mail: final receipt and storage of email at [email protected].
7. International transfers
Some services may involve processing outside the European Economic Area. Where applicable, mechanisms recognised under the GDPR will be used, including adequacy decisions, standard contractual clauses or other legally valid safeguards. Further information may be requested from the controller through the contact email address.
8. Retention
Enquiries that do not lead to a professional relationship will be kept for no longer than 12 months after the last communication. Deletion is not described as automatic; it is carried out through periodic reviews.
If an enquiry leads to a pre-contractual, professional or contractual relationship, relevant correspondence may be retained for the duration of that relationship and afterwards for the applicable statutory periods, in order to meet obligations, address liability or defend claims.
Technical security data is retained only for the minimum period required by the configuration and legitimate needs of the infrastructure.
9. Your rights and how to exercise them
You may request access, rectification, erasure, objection, restriction of processing and portability where applicable, and withdraw consent for specific processing based on it. Email [email protected] and clearly identify your request.
A copy of an identity document is not required automatically. Additional information may be requested only where there are reasonable doubts about identity and only to the extent necessary for verification.
10. Complaint to the supervisory authority
If you believe the processing does not comply with the law, you may lodge a complaint with the Spanish Data Protection Agency (AEPD), without prejudice to any other available remedy.
11. Security
Technical and organisational measures proportionate to the risk are applied, including form validation, rate limiting, anti-bot controls and infrastructure protection services. No Internet-connected system can guarantee absolute security.
12. Updates
This policy may be updated to reflect legal or technical changes. The date shown at the beginning indicates its latest revision.