In accordance with the provisions of Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD), this Privacy Policy informs you how your personal data is collected, processed, and safeguarded when visiting or interacting with www.martosaranda.com.
1. Data Controller
Controller: Francisco Martos Moreno – Martos Aranda | Digital Solutions
Tax ID (NIF): 30991038X
Registered Address: José RodrÃguez del Moral 27, Dúplex 5, 11540 Sanlúcar de Barrameda, Cádiz, Spain
Contact Email: info@martosaranda.com
The Controller maintains proactive accountability (Art. 5.2 GDPR) and holds an internal record of data processing activities documenting processing purposes, legal bases, categories of personal data, storage timelines, and technical security safeguards.
2. Purposes of Data Processing
We process your personal information strictly for legitimate commercial, contractual, and technical purposes:
- Customer & Prospect Management (Art. 6.1.b GDPR: Performance of a contract / Pre-contractual steps):
- Responding to contact inquiries, requests for proposals, and consultative assessments.
- Project planning, scoping, delivery, and post-launch technical support.
- Administrative, Tax & Legal Compliance (Art. 6.1.c GDPR: Legal obligation):
- Issuing formal commercial invoices and compliance with Spanish tax and VeriFactu obligations.
- Preserving fiscal and accounting documentation during mandatory legal retention periods.
- Commercial Communications & Updates (Art. 6.1.a GDPR: Explicit consent):
- Sending newsletters, technical insights, and company updates where explicitly requested by the subscriber.
- Subscribers can revoke consent instantly at any time via the unsubscribe link in every communication.
- Service Optimization & Analytics (Art. 6.1.f GDPR: Legitimate interest):
- Aggregated, anonymized website traffic analytics and performance monitoring.
3. Data Retention Periods
Personal data is retained only for the duration necessary to fulfill the specific purpose for which it was gathered:
- Inquiries and prospective requests: Retained for up to 12 months after the last active communication unless an ongoing commercial relationship develops.
- Billing and contractual records: Preserved for 6 years in compliance with the Spanish Commercial Code and 4 years for tax regulations.
- Marketing subscribers: Preserved until the user explicitly withdraws consent or requests erasure.
4. Recipients and Data Disclosures
Your data will not be sold, rented, or transferred to unauthorized third parties. Personal data may only be accessed by trusted technology service providers acting as Processors (Data Processing Agreement under Art. 28 GDPR), such as cloud hosting providers (European data centers), email delivery infrastructure, and official banking or tax administrations as legally required.
5. Exercise of Data Subject Rights
Under GDPR and LOPDGDD, you are entitled to exercise the following rights at any time, free of charge:
- Access: Obtain confirmation regarding whether your personal data is being processed and access details.
- Rectification: Request correction of inaccurate, incomplete, or outdated data.
- Erasure (Right to be Forgotten): Request deletion of your data when it is no longer needed.
- Restriction of Processing: Request temporary restriction of data processing in specified statutory situations.
- Portability: Receive your data in a structured, commonly used, and machine-readable format.
- Objection: Object to processing based on legitimate interests or direct marketing.
To exercise your rights, email your written request accompanied by a copy of your identity document (e.g. ID card or passport) to: info@martosaranda.com.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) if you believe your rights have not been appropriately addressed.
6. Security Measures
We implement robust technical and organizational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, including SSL/TLS encryption, secure infrastructure firewalls, and least-privilege administrative access policies.
7. Policy Updates
This Privacy Policy may be updated periodically to reflect legislative changes, jurisprudence, or technical modifications in our services. The date of the last revision will always appear at the top of this document.