Legal

Privacy policy

1. Data controller

RedData Legal (the "controller") is the entity responsible for processing the personal data collected through this website and in the course of managing claim files. You may contact the controller on data-protection matters at legal@reddatalegal.com. The controller's full tax and registry details are available to any interested party upon request.

2. Information we process

In the course of our activity we may process the following categories of data:

  • Identifying and contact data of the person or entity against whom a claim is directed (name, company name, email address, domain and data contained in the commercial communication that is the subject of the claim).
  • Technical data associated with the reported message (sender address, message headers, date and time, and email content).
  • Identifying and contact data of the companies we represent.
  • Connection and access data for the case portal (IP address, country, user agent and access log), for security and evidential purposes.

3. Purposes of processing

We process data for the following purposes:

  • To document, process and follow up out-of-court claims for unsolicited commercial communications.
  • To notify the reported party, manage the case portal and, where applicable, reach an out-of-court settlement.
  • To prepare, where appropriate, the complaint before the Spanish Data Protection Agency and abuse reports to the relevant providers.
  • To comply with applicable legal obligations and retain evidence for evidential purposes.

4. Legal basis

The processing of the reported party's data is based on the legitimate interest of the controller and of the company it represents in the establishment, exercise and defence of claims (article 6(1)(f) of Regulation (EU) 2016/679, GDPR, in conjunction with recital 47 and article 82). The processing of the represented companies' data is based on the performance of the contractual relationship (article 6(1)(b) GDPR). Compliance with legal obligations constitutes a basis for processing under article 6(1)(c) GDPR.

5. Information where data is not obtained from the data subject

In accordance with article 14 GDPR, where the reported party's data is not obtained directly from them but from the commercial communication sent and from the claimant company, it is stated that the source of the data is the email that is the subject of the claim and the documentation provided by the company we represent.

6. Retention periods

Data will be retained for as long as necessary to process the case file and, thereafter, for the limitation periods of any legal actions that may arise, after which it will be deleted or blocked in accordance with applicable law.

7. Recipients

Data may be disclosed to the claimant company we represent, to the Spanish Data Protection Agency and to the competent administrative or judicial bodies, as well as to sending, hosting and domain-registration service providers in the context of abuse reports, where necessary for the described purpose. No international data transfers outside the European Economic Area are carried out unless expressly stated.

8. Data subject rights

The data subject may exercise the rights of access, rectification, erasure, objection, restriction of processing and portability by contacting legal@reddatalegal.com and proving their identity. They also have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if they believe the processing does not comply with applicable law.

9. Security

The controller has adopted appropriate technical and organisational measures to ensure the security, confidentiality and integrity of personal data and to prevent its alteration, loss, unauthorised processing or access.

10. Changes to this policy

This privacy policy may be updated to adapt to legislative or case-law developments. Periodic review is recommended.