PRIVACY POLICY

Last updated: September 2026

This policy explains how Personaa, a consultancy based in Málaga, Spain, collects and processes personal data through this website, in line with the EU General Data Protection Regulation (GDPR) and Spanish data protection law (LOPDGDD).

Data controller

Ziad Alameddine, trading as Personaa (full registered details in our Legal Notice). For any privacy question or request, write to info@personaa.co.

What data we collect

Contact form data you choose to send us: name, company, email address and the content of your message.

Enquiries are sent to us by email and are not stored in any website database.

We use no analytics or tracking tools, so we collect no browsing data for statistical or advertising purposes.

Why we use it and on what legal basis

To reply to your enquiry and manage a potential client relationship — legal basis: steps taken at your request prior to entering into a contract, and our legitimate interest in responding to business enquiries.

To comply with accounting, tax and other legal obligations — legal basis: legal obligation.

Who we share it with

We do not sell personal data. We share it only with Lovable, which hosts this website and sends emails on our behalf, acting as a processor under its published data processing terms. Lovable processes data within the EU (Ireland, eu-west-1), so no additional transfer mechanism is required.

How long we keep it

Enquiry data is kept for as long as needed to handle your request and for up to 2 years afterwards, unless a client relationship starts, in which case related accounting and invoicing records are kept for 6 years as required under Spanish commercial and tax law.

Your rights

You can request access, rectification, erasure, restriction, portability, and object to processing, as well as withdraw consent at any time, by writing to info@personaa.co. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es).

Security

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss or misuse.