Privacy Policy

Last updated:

This Policy sets out how personal data of users of the website usava.team is processed and protected in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”).

1. Data controller

2. Categories of data we process

  • first and last name;
  • email address;
  • phone number;
  • IP address, cookie data, user agent;
  • messages and the content of contact forms;
  • promo codes and marketing campaign data.

3. Purposes of processing

  • entering into and performing a service agreement;
  • consultations and replies to enquiries;
  • sending news and marketing materials (with your consent);
  • analytics and improving the quality of our services;
  • complying with obligations under EU and Spanish law.

4. Legal bases

  • your consent (Art. 6(1)(a) GDPR);
  • performance of a contract (Art. 6(1)(b) GDPR);
  • our legitimate interests (Art. 6(1)(f) GDPR);
  • compliance with a legal obligation (Art. 6(1)(c) GDPR).

5. Retention

We keep personal data no longer than the purposes of processing require. Client data is kept for the term of the agreement and for 3 (three) years after it ends. Data for marketing subscriptions is kept until you withdraw your consent.

6. Your rights

  • to obtain information about the processing of your data;
  • to have your data rectified, restricted or erased;
  • to withdraw your consent at any time (Art. 7 GDPR);
  • to restrict processing (Art. 18 GDPR);
  • to data portability (Art. 20 GDPR);
  • to lodge a complaint with a supervisory authority — in Spain, the Agencia Española de Protección de Datos (AEPD).

To exercise your rights, write to [email protected]. We reply within 30 days.

7. Disclosure to third parties

Data may be shared with processors — hosting providers, email services and analytics systems — only for the purposes of processing and subject to security requirements. International transfers are made to countries with an adequate level of protection (Art. 45 GDPR) or under Standard Contractual Clauses (SCC).

8. Security measures

  • encryption in transit (TLS 1.3);
  • access restricted on the principle of least privilege;
  • regular backups and audit logs;
  • information security training for staff.

9. Cookies

The use of cookies is governed by our Cookie Policy.

10. Changes to this Policy

We may update this Policy. The current version is always available on this page.

11. Contact

Questions about the processing of personal data: [email protected] or [email protected].