Privacy policy
1. Data controller
| Controller | Carlos Torres Pérez (CT Advisory) |
|---|---|
| Spanish tax ID (NIF) | 54201795H |
| Address | Madrid, Spain. Full postal address available on request at carlostorres@ctadvisory.es |
| Data protection contact | carlostorres@ctadvisory.es |
No data protection officer has been appointed, as none of the circumstances in article 37 GDPR or article 34 of Spanish Organic Law 3/2018 applies.
2. Processing activities
a) Enquiries and information requests
| Purpose | Responding to messages received through the contact form, email, telephone or the meeting booking tool, maintaining contact and, where appropriate, preparing a proposal. |
|---|---|
| Legal basis | Pre‑contractual measures taken at the data subject’s request (art. 6.1.b GDPR). |
| Data | Name, company, email, telephone and the content of the message. |
| Retention | One year from the last contact, unless an engagement follows. |
b) Business‑to‑business prospecting
| Purpose | Identifying companies whose profile matches the services offered and sending them a professional communication about corporate transactions. |
|---|---|
| Legal basis | Legitimate interest of the controller in promoting its professional activity (art. 6.1.f GDPR), following a balancing assessment against data subjects’ rights. |
| Data | Professional identification and contact details: company name, sector, size, registered address, job title, name of the representative and company contact details. |
| Source | Not obtained from the data subject. Sourced from the SABI database (Bureau van Dijk / Moody’s), the Spanish Commercial Registry and its official gazette (BORME), filed annual accounts and publicly available sources such as corporate websites. |
| Retention | Until the data subject objects, or three years without interaction. Minimal data of those who object are kept blocked on a suppression list so they are not contacted again. |
These are professional contact details used to address a communication to the company about its own business activity, in line with article 19 of Spanish Organic Law 3/2018. You may object at any time, without giving reasons and free of charge, by writing to carlostorres@ctadvisory.es or replying to any communication received.
c) Clients and delivery of services
| Purpose | Performing the agreed engagement, managing the contractual relationship and meeting accounting, tax and invoicing obligations. |
|---|---|
| Legal basis | Performance of a contract (art. 6.1.b GDPR) and compliance with legal obligations (art. 6.1.c GDPR). |
| Data | Identification and tax data, contact details, bank details and the financial and corporate information required for the engagement. |
| Retention | For the duration of the relationship and thereafter, blocked, for the applicable limitation periods: four years for tax matters, six years for commercial records and ten years where anti‑money‑laundering rules apply. |
3. Recipients
Data are not disclosed to third parties except where required by law. The following providers act as processors under article 28 GDPR: GitHub, Inc. (website hosting); IONOS Cloud, S.L.U. (domain and professional email); the contact form provider and the meeting booking provider; and the tax and accounting adviser together with the bank, for administrative purposes.
Within a specific transaction it may be necessary to share information with legal, tax or technical advisers and with the counterparty. Sensitive information is never disclosed without the client’s prior authorisation, and always under a confidentiality agreement.
4. International transfers
Some technology providers are established outside the European Economic Area, mainly in the United States. Such transfers rely on the EU‑US Data Privacy Framework adequacy decision or, failing that, on the European Commission’s standard contractual clauses, with any additional safeguards required.
5. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and data portability by writing to carlostorres@ctadvisory.es, stating the right invoked and enclosing a copy of an identity document. Requests are answered within one month.
You may also lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid — www.aepd.es).
6. Security
Technical and organisational measures proportionate to the risk are applied: TLS encryption of site communications, strong passwords with two‑factor authentication, full‑disk encryption of the working device, regular backups, exclusive use of the professional email account and confidentiality agreements with every counterparty.
7. Automated decision‑making
No automated decisions or profiling producing legal effects on data subjects are carried out.
8. Minors
Services are addressed exclusively to professionals and companies. No data relating to minors are knowingly collected.
9. Changes
This policy may be updated to reflect legal changes or new services. The version in force is the one published on this page, showing its update date.
10. Language
This is a courtesy translation. In the event of any discrepancy, the Spanish version prevails.
← Back to home