Legal information
Privacy policy
Language of this text
This is an English translation provided for convenience. The binding version is the Spanish original, available at www.sempereconsulting.com/privacidad/. In the event of any discrepancy between the two, the Spanish version shall prevail.
SB RESOURCES, S.L. respects the privacy of those who visit www.sempereconsulting.com and undertakes to process their personal data in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and Spanish Organic Act 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
This policy explains what data is collected through the website, for what purpose, on what legal basis, for how long it is retained, who may access it and how to exercise the rights recognised by the legislation.
1. Data controller
| Item | Details |
|---|---|
| Controller | SB RESOURCES, S.L. |
| Tax ID (CIF) | B21900261 |
| Registered office | Calle Juan de la Cosa, 15 · 03203 Elche (Alicante), Spain |
| Public-facing office | Calle Severo Ochoa, 44 · Parque Empresarial · 03203 Elche (Alicante), Spain |
| Data protection contact email | info@esempere.es |
| Telephone | +34 606 44 51 14 |
2. Data processed, purposes and legal bases
This website is a static, informational site. It has no private area, no user registration, no e-commerce and no newsletter subscription. The only personal data collected is that which the user voluntarily provides in order to make contact.
2.1. Contact form
Data processed: name, email address, telephone (optional field), company (optional field) and the content of the message written by the user. The date and time of submission are also recorded.
Users are advised not to include special categories of data (article 9 GDPR) or confidential information about third parties in their message. If the user provides such data on their own initiative, it will be processed for the sole purpose of handling the enquiry.
Purposes:
- To handle and reply to the enquiry or request for information submitted.
- To maintain any subsequent communication needed to clarify or complete that request.
- Where applicable, to prepare and send a quotation or proposal for professional services.
Legal bases:
- Article 6(1)(b) GDPR (steps taken at the request of the data subject prior to entering into a contract), where the enquiry is aimed at assessing engagement of the firm's services.
- Article 6(1)(a) GDPR (consent of the data subject), given by ticking the box accepting this privacy policy and submitting the form, for enquiries that do not fall within a pre-contractual relationship. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out beforehand.
Fields marked as mandatory are essential in order to handle the request; if they are not provided, it will not be possible to process it.
2.2. Communications by email and telephone
Where the user writes directly to info@esempere.es or calls the published telephone number, the identifying and contact data provided, together with the content of the communication, are processed for the same purposes and on the same legal bases described in the previous section.
2.3. Contact via WhatsApp
The website includes an outbound link to WhatsApp. If the user chooses to use that channel, SB RESOURCES will process the conversation data as controller (telephone number, profile name and message content) for the same purposes and on the same legal bases set out in section 2.1.
Separately, the messaging service itself processes the user's data in accordance with its own terms and privacy policy, over which SB RESOURCES has no control. Users are advised not to send confidential documentation or sensitive data through this channel.
2.4. Browsing data and server logs
The hosting provider generates technical activity logs which may include the IP address, the date and time of the request, the resource requested and the browser type.
- Purpose: to ensure the security, integrity and correct operation of the website, and to detect and prevent fraudulent use or attacks.
- Legal basis: article 6(1)(f) GDPR (legitimate interest of the controller in maintaining the security of its information systems), an interest considered to prevail given that this is minimal, expected processing limited to security purposes.
2.5. Compliance with legal obligations
Where an enquiry leads to the actual engagement of professional services, subsequent processing of the data will be governed by the information provided at that time, and will be based on performance of the contract (article 6(1)(b) GDPR) and compliance with the legal obligations applicable to the firm, in particular those of a commercial, accounting, tax and anti-money-laundering nature (article 6(1)(c) GDPR).
2.6. What is not done with the data
- No commercial communications or newsletters are sent: the site has no subscription facility and form data is not used for advertising purposes.
- No profiling is carried out and no automated decisions with legal or similar effects are taken (article 22 GDPR).
- Data is neither sold nor transferred to third parties for commercial purposes.
3. Retention periods
Data is retained for as long as strictly necessary to fulfil the purpose for which it was collected and, thereafter, blocked — that is, accessible only in order to address potential liabilities — for the applicable statutory limitation periods. The criteria applied are as follows:
| Situation | Period | Criterion applied |
|---|---|---|
| Enquiry that does not lead to a professional relationship | Up to one year from the last contact, unless the data subject requests earlier erasure | A reasonable time to handle the enquiry, continue the conversation and evidence the answer given |
| Enquiry that does lead to a professional relationship | For the duration of the relationship and, after it ends, for the periods set out in the rows below | Performance of the contract and subsequent liability |
| Contractual liability | 5 years from the end of the relationship | Limitation period for personal actions with no specific period (article 1964.2 of the Spanish Civil Code) |
| Commercial and accounting records | 6 years | Duty to retain books, correspondence and supporting documents (article 30 of the Spanish Commercial Code) |
| Documentation of tax relevance | 4 years from the end of the filing period, extendable to 10 years where the tax authorities may review tax bases or deductions from earlier years | Tax limitation period and right to review (articles 66 and 66 bis of Act 58/2003, the General Tax Act) |
| Anti-money-laundering due diligence records | 10 years from the end of the business relationship | Article 25 of Act 10/2010, of 28 April |
| Technical server logs | Those set by the hosting provider for security purposes, generally no longer than 12 months | Legitimate interest in system security |
Once the applicable periods have elapsed, the data is securely deleted.
4. Recipients and processors
Personal data is not disclosed to third parties, except in the following cases:
4.1. Legal obligation. Where required by law, data may be disclosed to the tax authorities, social security bodies, courts and tribunals, law enforcement agencies, the Executive Service of the Commission for the Prevention of Money Laundering (SEPBLAC) or other competent authorities, within the scope of their respective functions.
4.2. Processors. The following service providers access the data on behalf of and following the instructions of the controller, under a data processing agreement in accordance with article 28 GDPR:
| Processor | Service provided | Location of processing |
|---|---|---|
| OVH Hispano, S.L.U. | Website hosting | Data centres located in the European Union |
| Google Ireland Limited (Google Workspace) | Corporate email and associated productivity tools | European Union, with possible access from third countries (see section 5) |
In addition, website maintenance and technical support providers may occasionally access the data, always under a data processing agreement and subject to a duty of confidentiality.
5. International data transfers
The website is hosted on servers located in the European Union, so hosting does not involve any international data transfer.
Corporate email is provided by Google Ireland Limited, an entity established in the European Union. In certain cases — mainly technical support and maintenance operations — data may be accessed from the United States or other third countries by group entities or their sub-processors. Such transfers are covered by the safeguards provided for in Chapter V GDPR, in particular:
- The European Commission's adequacy decision on the EU-US Data Privacy Framework, of 10 July 2023, in respect of US entities certified under that framework (article 45 GDPR).
- Additionally or alternatively, the standard contractual clauses adopted by the European Commission, together with any supplementary measures that may be appropriate (article 46(2)(c) GDPR).
Further information about these safeguards may be requested by writing to info@esempere.es.
If the user follows the WhatsApp link or the LinkedIn links, any processing carried out by those platforms takes place outside the control of SB RESOURCES and is governed by their respective privacy policies.
6. Rights of the data subject
Everyone has the right to obtain confirmation as to whether SB RESOURCES processes personal data concerning them. Specifically, the following rights may be exercised:
- Access (article 15 GDPR): to know what data is processed and obtain a copy.
- Rectification (article 16 GDPR): to correct inaccurate data or complete it.
- Erasure (article 17 GDPR): to request its deletion where, among other cases, it is no longer necessary for the purpose for which it was collected.
- Restriction of processing (article 18 GDPR): to request that data be retained but not processed, in the cases provided for by law.
- Portability (article 20 GDPR): to receive the data in a structured, commonly used, machine-readable format, or to request its transmission to another controller, where processing is based on consent or a contract and is carried out by automated means.
- Objection (article 21 GDPR): to object to processing based on legitimate interest, on grounds relating to their particular situation.
- Withdrawal of consent (article 7(3) GDPR): to revoke consent at any time, without affecting the lawfulness of processing carried out beforehand.
How to exercise them. By request addressed to info@esempere.es, or in writing to SB RESOURCES, S.L., Calle Juan de la Cosa, 15, 03203 Elche (Alicante), Spain. The request must state the right being exercised and enclose a copy of an identity card, passport or other valid identity document. Exercising these rights is free of charge.
The request will be answered within one month of receipt, extendable by two further months where the complexity or number of requests justifies it, in which case the data subject will be informed.
Complaint to the supervisory authority. If the data subject considers that the processing does not comply with the legislation, or that their request has not been properly handled, they may lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan, 6, 28001 Madrid, or through its electronic office at www.aepd.es. Beforehand, they may contact SB RESOURCES at the address indicated.
7. Accuracy of data and third-party data
The user warrants that the data provided is truthful, accurate and up to date, and undertakes to notify any changes. The user is responsible for the accuracy of the information supplied and shall refrain from providing third-party data without having previously informed those parties of the matters set out in this policy and without a lawful basis for doing so.
8. Security measures
SB RESOURCES applies appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with article 32 GDPR, taking into account the state of the art, the costs of implementation and the nature, scope and purposes of the processing. These include:
- Encryption of communications between the user's browser and the server using HTTPS with a valid TLS certificate.
- Hosting with a professional provider with data centres in the European Union and physical and logical security measures.
- Access control to mailboxes through individual credentials and strong authentication.
- Restriction of access to data to staff who need to know it in order to perform their duties, subject to a duty of confidentiality.
- Regular backups and recovery procedures.
- Software updates and periodic review of the measures in place.
In the event of a personal data breach, the AEPD and, where appropriate, the affected data subjects will be notified in accordance with articles 33 and 34 GDPR.
9. Changes to this policy
This privacy policy may be updated to reflect changes in legislation, case law or the processing carried out. The version in force will always be the one published on this page, stating the date it was last updated.
---