Legal
Privacy policy
1. Data controller
| Controller | METROPOLI BCN SL · Tax ID (CIF) B65272791 |
|---|---|
| Address | C/ Àngel Guimerà, 19, bajos, 08320 El Masnou (Barcelona), Spain |
| Data protection contact |
METROPOLI BCN SL is not required to appoint a data protection officer under article 37 of the GDPR and article 34 of the LOPDGDD. Any question regarding this policy may be addressed to the address indicated.
2. What data we process and where it comes from
This Site is informative and has no registration forms or client area. The only personal data we may process in relation to the Site are:
- Data you provide to us when writing to us by email or requesting a call: name, company, position, email, telephone and the content of your message.
- Technical browsing data generated when accessing the Site: IP address, date and time, page requested, browser and operating system, which the hosting infrastructure (Cloudflare) records automatically for security reasons and to mitigate automated attacks.
We do not process special categories of data nor make automated decisions with legal effects or profiling through the Site.
3. Purposes, legal bases and retention periods
| Purpose | Legal basis | Retention |
|---|---|---|
| Handle your enquiry or contact request and, where applicable, prepare a service proposal. | Pre-contractual measures at the data subject's request (art. 6.1.b GDPR) and, when acting on behalf of a company, legitimate interest in maintaining the professional relationship (art. 6.1.f GDPR and art. 19 LOPDGDD). | For the duration of the handling of the request and, afterwards, for the time necessary to address possible liabilities, with a maximum of 12 months if no contractual relationship is formalised. |
| Ensure the security of the Site and of the systems that support it (server logs). | Legitimate interest in network and information security (art. 6.1.f GDPR, recital 49). | Logs kept for a maximum of 12 months, unless it is necessary to keep them to investigate an incident. |
| Comply with legal obligations and respond to requests from authorities. | Legal obligation (art. 6.1.c GDPR). | For the statutory limitation periods. |
We do not use your contact data to send unsolicited commercial communications. If in the future we wished to send you commercial information, we would ask you expressly in accordance with article 21 of the LSSI-CE.
4. Recipients, processors and international transfers
We do not transfer your data to third parties, except where legally required. To operate the Site we rely on the following processors, under a contract in accordance with article 28 of the GDPR:
| Processor | Service | Data | Location and safeguards |
|---|---|---|---|
| Cloudflare, Inc. (San Francisco, USA) and Cloudflare Netherlands B.V. | Static site hosting, content delivery network, DNS, protection against attacks and bots | IP address, request headers and technical security logs | Global network; possible processing outside the EEA. Cloudflare is certified under the EU-US Data Privacy Framework and applies the European Commission's standard contractual clauses in its data processing agreement. |
| Email provider | Receiving and sending email | Whatever you include in your message | Servers in the European Union or, failing that, an adequacy decision or standard contractual clauses. |
Outside these cases no international data transfers are made. You may request a copy of the applicable safeguards by writing to the contact address.
5. Your rights
You may exercise at any time the rights of access, rectification, erasure, objection, restriction of processing and portability, as well as withdraw consent when this is the basis for processing, by writing to or by post to the controller's address, indicating the right you are exercising and enclosing a means to verify your identity. We will respond within a maximum of one month.
If you consider that the processing does not comply with the regulations, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid). We would be grateful if you would let us know beforehand so that we can resolve it.
6. Security
We apply technical and organisational measures proportionate to the risk of the processing: encryption of communications (TLS), role-based access control, access logging and incident response procedures. In the event of a security breach with a risk to your rights, we will notify the supervisory authority and, where applicable, those affected, in accordance with articles 33 and 34 of the GDPR.
7. Minors
The Site is aimed at companies and professionals. We do not knowingly collect data from minors under 14; if we detect that such data has been provided, we will delete it.
8. Changes to this policy
We may update this policy to adapt it to regulatory or Site changes. The version in force is the one published on this page, with its update date.