Privacy
Privacy policy
1. Who is responsible for your data
This website is operated by two individuals acting together. Under Article 26 of the General Data Protection Regulation (EU) 2016/679 (GDPR) they are joint controllers of the personal data described in this policy.
- Joint controllers
- Ignacio Fernández and Irakli Diasamidze, acting jointly
- Contact point
- contact@2iberia.com — a single mailbox monitored by both controllers, and the address to use for any request about your data
Essence of the joint-controller arrangement
GDPR Article 26(2) requires that the essence of the arrangement between joint controllers be made available to you. It is as follows.
- The controllers have jointly determined the purposes of the processing described here, and jointly decide what is collected and for how long.
- Both have equal access to enquiries submitted through this site. Both are bound to the same handling and confidentiality standards.
- Ignacio Fernández has operational responsibility for the website and its technical providers. Irakli Diasamidze has operational responsibility for correspondence and record-keeping arising from enquiries.
- Requests to exercise your rights are handled through the single contact point above. Whichever controller receives a request will action it on behalf of both, and will inform the other.
- Regardless of this internal allocation, you may exercise your rights against either controller, and each remains fully responsible to you and to the supervisory authority for compliance.
No data protection officer has been appointed, as the processing does not meet the criteria in GDPR Article 37. Given the very limited scale of processing, no representative under Article 27 is required.
2. What we collect
We collect only what you actively send us, plus the minimum technical data our hosting provider records to serve and protect the site.
If you use the contact form or email us
- Your name.
- Your email address.
- Your organisation, if you choose to give it (optional).
- The category you select (investor, owner or developer, or other).
- The content of your message, and anything you later send us by email.
- A record of your consent: the fact that you ticked the consent box, and the date and time.
Please do not send special-category data (health, political opinions, religious beliefs, trade-union membership, biometric or genetic data) or details of criminal offences. We do not ask for it and have no basis to process it.
Technical data
- Our hosting provider records standard connection data — IP address, date and time, page requested, user agent, and referring page — in server logs, to deliver the site and to protect it from attack and abuse.
We do not use analytics, advertising, tracking pixels, social plugins, or any form of profiling. Fonts and every other asset are served from this website itself, so simply reading these pages sends no data to any third party.
3. Why we use it, and on what legal basis
- To answer you
- To read, answer and follow up on your enquiry, and to hold the resulting correspondence. Legal basis: your consent, GDPR Article 6(1)(a), given by ticking the box on the form. Where you email us directly rather than using the form, the basis is our legitimate interest in responding to a communication you chose to initiate, Article 6(1)(f).
- To pursue a possible working relationship
- If your enquiry leads to discussions, to keep a record of them and continue the exchange. Legal basis: steps taken at your request prior to entering into a contract, Article 6(1)(b), and our legitimate interest in developing professional relationships, Article 6(1)(f).
- To keep the site secure
- To operate, maintain and defend the website against attack, abuse and fraud. Legal basis: our legitimate interest in the security and availability of our own site, Article 6(1)(f).
- To evidence compliance
- To retain proof that consent was given, and to respond to any regulatory or legal request. Legal basis: compliance with a legal obligation, Article 6(1)(c), and our legitimate interest in defending legal claims, Article 6(1)(f).
Where we rely on legitimate interests, we have considered your rights and freedoms and concluded that this processing is limited, expected in a professional context, and not overriding of those rights. You may object at any time (see section 6).
We do not use your data for marketing, and we will not send you unsolicited commercial messages. We carry out no automated decision-making or profiling that produces legal or similarly significant effects on you.
4. Who else sees your data
We do not sell personal data and we do not share it for anyone else’s marketing. Your data is disclosed only to the service providers we need in order to run the site and reply to you. Each acts as a processor on our documented instructions under a data processing agreement.
- Website hosting
- Cloudflare, Inc. Serves the site and records the security logs described above. Data processing agreement and EU Standard Contractual Clauses in place.
- Enquiry delivery
- Brevo (Sendinblue SAS), France. Transmits the contents of the contact form to our mailbox. Servers located in the European Union; data processing agreement in place.
- Email and domain
- Hostinger International Ltd. Provides the domain and the contact@2iberia.com mailbox where correspondence is stored.
We may also disclose data where we are legally required to do so, or where it is necessary to establish, exercise or defend legal claims.
International transfers
Our providers are selected so that enquiry data is processed within the European Economic Area. Where a provider or one of its sub-processors is established outside the EEA, the transfer is protected by an adequacy decision of the European Commission or by Standard Contractual Clauses together with any additional measures required. You may request a copy of the relevant safeguards using the contact point above.
5. How long we keep it
- Enquiries that do not lead anywhere: deleted within 12 months of our last exchange with you.
- Enquiries that lead to an ongoing discussion or relationship: kept for the duration of that relationship and for 5 years afterwards, in line with the general limitation period for personal actions under Article 1964 of the Spanish Civil Code.
- Consent records: kept for as long as the consent is relied upon, and for 3 years after it is withdrawn or expires, as evidence of compliance.
- Server logs: retained by our hosting provider for a short period, typically no more than 30 days, and then deleted or aggregated.
At the end of these periods data is deleted, or irreversibly anonymised.
6. Your rights
Under the GDPR and Spanish Organic Law 3/2018 (LOPDGDD) you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Rectify data that is inaccurate or incomplete.
- Erase your data where one of the grounds in Article 17 applies.
- Restrict processing in the circumstances set out in Article 18.
- Portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller.
- Object to processing based on legitimate interests, on grounds relating to your particular situation.
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before you withdrew it.
To exercise any of these, write to contact@2iberia.com. We will respond within one month, extendable by two further months for complex requests, and will tell you if we need that extension. We may ask you to confirm your identity where we have genuine doubt about who is making the request. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.
If you believe your data has been handled improperly you may lodge a complaint with the Spanish Data Protection Agency, the Agencia Española de Protección de Datos (C/ Jorge Juan 6, 28001 Madrid, www.aepd.es), or with the supervisory authority where you live or work. We would appreciate the chance to resolve the matter with you first.
7. Cookies and tracking
This website sets no cookies of its own, and uses no analytics, advertising or tracking technology. Nothing is stored on your device for tracking purposes, and there is therefore no consent banner, because there is nothing to consent to under Article 22 of the LSSI-CE.
Our hosting provider may set a strictly necessary cookie for security purposes, for example to identify abusive traffic. Such a cookie carries no advertising or analytics function and is exempt from the consent requirement. If we ever introduce cookies that are not strictly necessary, we will implement a consent mechanism and update this policy before doing so.
8. Security
The site is served over HTTPS. Access to enquiry correspondence is limited to the two controllers, protected by individual accounts with multi-factor authentication. We keep the number of providers deliberately small and collect as little data as possible, which is itself the strongest protection we can offer. No system can be guaranteed absolutely secure; if a breach occurs that is likely to result in a high risk to your rights, we will notify you and the supervisory authority as required by Articles 33 and 34.
9. Changes to this policy
We may update this policy to reflect changes in how the site works or in the law. The version in force is always the one published here, with the date shown below. Where a change materially affects how we use data you have already given us, we will contact you.