SempereConsulting Tell us about your case

Legal information

Privacy policy

Last updated: 24/08/2026

Language of this text

This is an English translation provided for convenience. The binding version is the Spanish original, available at www.sempereconsulting.com/privacidad/. In the event of any discrepancy between the two, the Spanish version shall prevail.

SB RESOURCES, S.L. respects the privacy of those who visit www.sempereconsulting.com and undertakes to process their personal data in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and Spanish Organic Act 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).

This policy explains what data is collected through the website, for what purpose, on what legal basis, for how long it is retained, who may access it and how to exercise the rights recognised by the legislation.

1. Data controller

ItemDetails
ControllerSB RESOURCES, S.L.
Tax ID (CIF)B21900261
Registered officeCalle Juan de la Cosa, 15 · 03203 Elche (Alicante), Spain
Public-facing officeCalle Severo Ochoa, 44 · Parque Empresarial · 03203 Elche (Alicante), Spain
Data protection contact emailinfo@esempere.es
Telephone+34 606 44 51 14

2. Data processed, purposes and legal bases

This website is a static, informational site. It has no private area, no user registration, no e-commerce and no newsletter subscription. The only personal data collected is that which the user voluntarily provides in order to make contact.

2.1. Contact form

Data processed: name, email address, telephone (optional field), company (optional field) and the content of the message written by the user. The date and time of submission are also recorded.

Users are advised not to include special categories of data (article 9 GDPR) or confidential information about third parties in their message. If the user provides such data on their own initiative, it will be processed for the sole purpose of handling the enquiry.

Purposes:

  • To handle and reply to the enquiry or request for information submitted.
  • To maintain any subsequent communication needed to clarify or complete that request.
  • Where applicable, to prepare and send a quotation or proposal for professional services.

Legal bases:

  • Article 6(1)(b) GDPR (steps taken at the request of the data subject prior to entering into a contract), where the enquiry is aimed at assessing engagement of the firm's services.
  • Article 6(1)(a) GDPR (consent of the data subject), given by ticking the box accepting this privacy policy and submitting the form, for enquiries that do not fall within a pre-contractual relationship. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out beforehand.

Fields marked as mandatory are essential in order to handle the request; if they are not provided, it will not be possible to process it.

2.2. Communications by email and telephone

Where the user writes directly to info@esempere.es or calls the published telephone number, the identifying and contact data provided, together with the content of the communication, are processed for the same purposes and on the same legal bases described in the previous section.

2.3. Contact via WhatsApp

The website includes an outbound link to WhatsApp. If the user chooses to use that channel, SB RESOURCES will process the conversation data as controller (telephone number, profile name and message content) for the same purposes and on the same legal bases set out in section 2.1.

Separately, the messaging service itself processes the user's data in accordance with its own terms and privacy policy, over which SB RESOURCES has no control. Users are advised not to send confidential documentation or sensitive data through this channel.

2.4. Browsing data and server logs

The hosting provider generates technical activity logs which may include the IP address, the date and time of the request, the resource requested and the browser type.

  • Purpose: to ensure the security, integrity and correct operation of the website, and to detect and prevent fraudulent use or attacks.
  • Legal basis: article 6(1)(f) GDPR (legitimate interest of the controller in maintaining the security of its information systems), an interest considered to prevail given that this is minimal, expected processing limited to security purposes.

2.5. Compliance with legal obligations

Where an enquiry leads to the actual engagement of professional services, subsequent processing of the data will be governed by the information provided at that time, and will be based on performance of the contract (article 6(1)(b) GDPR) and compliance with the legal obligations applicable to the firm, in particular those of a commercial, accounting, tax and anti-money-laundering nature (article 6(1)(c) GDPR).

2.6. What is not done with the data

  • No commercial communications or newsletters are sent: the site has no subscription facility and form data is not used for advertising purposes.
  • No profiling is carried out and no automated decisions with legal or similar effects are taken (article 22 GDPR).
  • Data is neither sold nor transferred to third parties for commercial purposes.

3. Retention periods

Data is retained for as long as strictly necessary to fulfil the purpose for which it was collected and, thereafter, blocked — that is, accessible only in order to address potential liabilities — for the applicable statutory limitation periods. The criteria applied are as follows:

SituationPeriodCriterion applied
Enquiry that does not lead to a professional relationshipUp to one year from the last contact, unless the data subject requests earlier erasureA reasonable time to handle the enquiry, continue the conversation and evidence the answer given
Enquiry that does lead to a professional relationshipFor the duration of the relationship and, after it ends, for the periods set out in the rows belowPerformance of the contract and subsequent liability
Contractual liability5 years from the end of the relationshipLimitation period for personal actions with no specific period (article 1964.2 of the Spanish Civil Code)
Commercial and accounting records6 yearsDuty to retain books, correspondence and supporting documents (article 30 of the Spanish Commercial Code)
Documentation of tax relevance4 years from the end of the filing period, extendable to 10 years where the tax authorities may review tax bases or deductions from earlier yearsTax limitation period and right to review (articles 66 and 66 bis of Act 58/2003, the General Tax Act)
Anti-money-laundering due diligence records10 years from the end of the business relationshipArticle 25 of Act 10/2010, of 28 April
Technical server logsThose set by the hosting provider for security purposes, generally no longer than 12 monthsLegitimate interest in system security

Once the applicable periods have elapsed, the data is securely deleted.

4. Recipients and processors

Personal data is not disclosed to third parties, except in the following cases:

4.1. Legal obligation. Where required by law, data may be disclosed to the tax authorities, social security bodies, courts and tribunals, law enforcement agencies, the Executive Service of the Commission for the Prevention of Money Laundering (SEPBLAC) or other competent authorities, within the scope of their respective functions.

4.2. Processors. The following service providers access the data on behalf of and following the instructions of the controller, under a data processing agreement in accordance with article 28 GDPR:

ProcessorService providedLocation of processing
OVH Hispano, S.L.U.Website hostingData centres located in the European Union
Google Ireland Limited (Google Workspace)Corporate email and associated productivity toolsEuropean Union, with possible access from third countries (see section 5)

In addition, website maintenance and technical support providers may occasionally access the data, always under a data processing agreement and subject to a duty of confidentiality.

5. International data transfers

The website is hosted on servers located in the European Union, so hosting does not involve any international data transfer.

Corporate email is provided by Google Ireland Limited, an entity established in the European Union. In certain cases — mainly technical support and maintenance operations — data may be accessed from the United States or other third countries by group entities or their sub-processors. Such transfers are covered by the safeguards provided for in Chapter V GDPR, in particular:

  • The European Commission's adequacy decision on the EU-US Data Privacy Framework, of 10 July 2023, in respect of US entities certified under that framework (article 45 GDPR).
  • Additionally or alternatively, the standard contractual clauses adopted by the European Commission, together with any supplementary measures that may be appropriate (article 46(2)(c) GDPR).

Further information about these safeguards may be requested by writing to info@esempere.es.

If the user follows the WhatsApp link or the LinkedIn links, any processing carried out by those platforms takes place outside the control of SB RESOURCES and is governed by their respective privacy policies.

6. Rights of the data subject

Everyone has the right to obtain confirmation as to whether SB RESOURCES processes personal data concerning them. Specifically, the following rights may be exercised:

  • Access (article 15 GDPR): to know what data is processed and obtain a copy.
  • Rectification (article 16 GDPR): to correct inaccurate data or complete it.
  • Erasure (article 17 GDPR): to request its deletion where, among other cases, it is no longer necessary for the purpose for which it was collected.
  • Restriction of processing (article 18 GDPR): to request that data be retained but not processed, in the cases provided for by law.
  • Portability (article 20 GDPR): to receive the data in a structured, commonly used, machine-readable format, or to request its transmission to another controller, where processing is based on consent or a contract and is carried out by automated means.
  • Objection (article 21 GDPR): to object to processing based on legitimate interest, on grounds relating to their particular situation.
  • Withdrawal of consent (article 7(3) GDPR): to revoke consent at any time, without affecting the lawfulness of processing carried out beforehand.

How to exercise them. By request addressed to info@esempere.es, or in writing to SB RESOURCES, S.L., Calle Juan de la Cosa, 15, 03203 Elche (Alicante), Spain. The request must state the right being exercised and enclose a copy of an identity card, passport or other valid identity document. Exercising these rights is free of charge.

The request will be answered within one month of receipt, extendable by two further months where the complexity or number of requests justifies it, in which case the data subject will be informed.

Complaint to the supervisory authority. If the data subject considers that the processing does not comply with the legislation, or that their request has not been properly handled, they may lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan, 6, 28001 Madrid, or through its electronic office at www.aepd.es. Beforehand, they may contact SB RESOURCES at the address indicated.

7. Accuracy of data and third-party data

The user warrants that the data provided is truthful, accurate and up to date, and undertakes to notify any changes. The user is responsible for the accuracy of the information supplied and shall refrain from providing third-party data without having previously informed those parties of the matters set out in this policy and without a lawful basis for doing so.

8. Security measures

SB RESOURCES applies appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with article 32 GDPR, taking into account the state of the art, the costs of implementation and the nature, scope and purposes of the processing. These include:

  • Encryption of communications between the user's browser and the server using HTTPS with a valid TLS certificate.
  • Hosting with a professional provider with data centres in the European Union and physical and logical security measures.
  • Access control to mailboxes through individual credentials and strong authentication.
  • Restriction of access to data to staff who need to know it in order to perform their duties, subject to a duty of confidentiality.
  • Regular backups and recovery procedures.
  • Software updates and periodic review of the measures in place.

In the event of a personal data breach, the AEPD and, where appropriate, the affected data subjects will be notified in accordance with articles 33 and 34 GDPR.

9. Changes to this policy

This privacy policy may be updated to reflect changes in legislation, case law or the processing carried out. The version in force will always be the one published on this page, stating the date it was last updated.

---