Privacy policy

In this policy we explain how we process the personal data of people who visit this website or get in touch with us. We do so in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and Organic Law 3/2018 of 5 December on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD).

1. Data controller

  • Controller: Ricardo Vilas de Escauriaza, practising under the trade name Vilas Abogados.
  • Tax identification number (NIF): 32406125E.
  • Address: Calle del Conde de Cartagena, 43, 28007 Madrid (Spain).
  • Email: ricardo@vilasabogados.com.
  • Telephone: +34 915 014 100.

We have not appointed a data protection officer. If you have any questions about this policy, please write to us at the email address above.

2. What data we process

This website has a contact form, does not ask you to register and does not use cookies. We process the following data:

  • Technical data about your visit. When you visit the website, your browser sends the server certain technical data, such as your IP address, the date and time, the page requested and the type of browser and operating system. Our hosting provider records this data automatically. We use it for security purposes only and do not compile statistics from it.
  • Contact form data. If you write to us through the form, we process your name, your email address, your telephone number if you choose to give it to us and the content of your message, together with the record that you ticked the box accepting this policy and the date you sent it. Form submissions are received and stored by Netlify, Inc., which also notifies us by email of each new enquiry and stores, with each submission, the IP address and browser it was sent from.
  • Data you give us when you contact us. If you write to us by email or call us, we process your identification and contact details (name, email address and telephone number), the content of your enquiry and any documents you send us.
  • Client data. If you instruct us on a matter, we also process the data needed to provide and invoice the service, and any data required by law: for example, the identification documents required by anti-money laundering legislation for the transactions to which it applies.
  • Data about other people. To handle a matter we may need data about third parties, such as heirs, spouses, business partners or the other party to a contract. The client gives us this data or we obtain it from public registries, notaries’ offices or public authorities. We only process the data necessary for the matter, and always subject to professional secrecy.

Please do not send us confidential documents, special categories of data (for example, about health, political opinions or trade union membership) or information about criminal offences or convictions through the form: describe your enquiry in general terms and, if necessary, we will agree a more secure way of sending us the documents afterwards.

If we add any other feature that processes personal data in the future, we will update this policy beforehand.

3. Why we use your data and on what legal basis

  • To respond to the enquiry you send us through the contact form, by email or by telephone, and to your request for a quote. Legal basis: taking steps at your request before entering into a contract (Art. 6(1)(b) GDPR). The box you tick on the form is not the legal basis for the processing: it records that you have read this policy before sending us your data, and we keep it together with your message.
  • To provide the professional services you instruct us to provide, including dealings with notaries’ offices, registries and public authorities, invoicing and collecting payment. Legal basis: performance of the services contract (Art. 6(1)(b) GDPR). If the client is a company or other entity, we process the contact details of its representatives and employees on the basis of our legitimate interest in maintaining the professional relationship with it (Art. 6(1)(f) GDPR and Art. 19 LOPDGDD).
  • To process data about third parties connected with the matter (for example, heirs, spouses, business partners or the other party to a contract): the identification, contact, family and financial data needed for the engagement. Legal basis: the client’s legitimate interest in receiving advice and defending their rights, and our legitimate interest in providing the services we have been instructed to provide (Art. 6(1)(f) GDPR); where applicable, compliance with legal obligations (Art. 6(1)(c) GDPR). Where special categories of data are involved, the processing is also based on one of the conditions in Article 9(2) GDPR, such as the establishment, exercise or defence of legal claims (point (f)).
  • To comply with the legal obligations that apply to us, such as tax obligations, those laid down by the rules governing the legal profession and, for transactions within its scope, those under Law 10/2010 of 28 April on the Prevention of Money Laundering and Terrorist Financing. Legal basis: compliance with legal obligations (Art. 6(1)(c) GDPR).
  • To keep the website secure and detect attacks or misuse, using the server’s technical logs, and to discard automated (spam) form submissions. Legal basis: our legitimate interest in protecting the website and ensuring that it works properly (Art. 6(1)(f) GDPR).
  • To establish, exercise or defend legal claims relating to the services provided. Legal basis: our legitimate interest (Art. 6(1)(f) GDPR).

We do not carry out profiling or take decisions based solely on automated processing. Nor do we use your data to send you marketing communications; if we ever wished to do so, we would ask for your consent first.

Providing your data is voluntary, but without it we will not be able to deal with your enquiry or accept your instructions. On the form, the fields marked as required (name, email address and message) are the ones we need in order to reply to you; the telephone number is optional. For transactions subject to anti-money laundering legislation, the data required by that legislation is mandatory.

4. How long we keep your data

  • Enquiries that do not lead to an engagement: for as long as necessary to deal with them and, after that, for no longer than [PENDING: retention period for enquiries that do not lead to an engagement]. That period also covers the copy stored in Netlify’s forms dashboard, which we delete when it expires.
  • Client data and case files: for as long as the professional relationship lasts. After that, we keep the data blocked for as long as liability may arise from the service or from our legal obligations. As a general rule, personal actions become time-barred after five years (Article 1964(2) of the Spanish Civil Code); we also take into account the time limits laid down in tax legislation. Once those periods have expired, we delete the data.
  • Anti-money laundering documentation: ten years from the end of the business relationship or the execution of the transaction, as required by Article 25 of Law 10/2010.
  • Server technical logs: kept by our hosting provider for [PENDING: retention period for server logs under the plan contracted with Netlify].

Keeping data blocked means setting it aside and restricting its use: it may only be made available to judges and courts, the Public Prosecutor’s Office or the competent public authorities, under the terms of Article 32 of the LOPDGDD.

5. Who we share your data with

We do not sell your data. We only disclose it to third parties in the following cases:

  • Where the law requires it, to the competent authorities and bodies, such as the tax authorities, the courts or the Executive Service of the Commission for the Prevention of Money Laundering and Monetary Offences (SEPBLAC), in the cases provided for by law.
  • Where your matter requires it, to notaries’ offices, public registries, public authorities, the other party and their lawyer, notaries and lawyers in other countries, or other professionals working with us on the matter. We will tell you so in the engagement letter [PENDING: confirm which external collaborators receive client data, for example gestorías (administrative and tax agents) for filing taxes].

In addition, some providers process data on our behalf (processors). Their contracts require them to use the data only to provide their services to us and to protect it:

  • Netlify, Inc. (United States): website hosting and content delivery network. It also receives and stores contact form submissions and sends us the email notification for each new enquiry. To discard automated submissions, Netlify uses Automattic Inc. (United States), which runs the Akismet spam filter and analyses the content of the submission.
  • Google Cloud EMEA Limited (Ireland): email, through Google Workspace. To provide this service it uses, among other sub-processors, Google LLC (United States).
  • [PENDING: other providers that process data on behalf of the firm, such as the invoicing software, the gestoría or the backup service]

6. International data transfers

  • Netlify, Inc., Automattic Inc. and Google LLC participate in the EU-U.S. Data Privacy Framework. Transfers to these entities, including the contact form submissions stored on Netlify’s servers, are based on Commission Implementing Decision (EU) 2023/1795 of 10 July 2023, which recognises an adequate level of protection (Art. 45 GDPR). You can check their participation on the official Data Privacy Framework List. If that decision ceases to apply, Google’s and Netlify’s contracts, including in respect of Netlify’s sub-processors, provide for transfers to be governed by the standard contractual clauses adopted by the European Commission (Art. 46(2)(c) GDPR). You can read Google’s clauses at cloud.google.com/terms/sccs or ask us for a copy of any of these providers’ clauses by writing to ricardo@vilasabogados.com.
  • If your matter requires us to disclose data to professionals outside the European Economic Area, in a country without an adequacy decision, we will send them only the data that is necessary. The transfer will be based on one of the derogations in Article 49(1) GDPR, such as the transfer being necessary to perform the engagement you have given us (point (b)), and we will inform you beforehand.

7. Your rights

You may exercise the following rights at any time:

  • Access: to find out whether we process your data and obtain a copy of it.
  • Rectification: to have inaccurate data corrected or incomplete data completed.
  • Erasure: to ask us to delete your data, for example when it is no longer necessary.
  • Objection: to object, on grounds relating to your particular situation, to processing based on our legitimate interest.
  • Restriction: to ask us to restrict processing in certain cases.
  • Portability: to receive the data you have provided to us in a structured format, where the processing is based on a contract or on your consent and is carried out by automated means.
  • Not to be subject to automated decisions: we do not take decisions based solely on automated processing.
  • To withdraw your consent at any time, where any processing is based on it, without affecting the lawfulness of processing carried out before its withdrawal.

To exercise these rights, write to us at ricardo@vilasabogados.com or by post to Calle del Conde de Cartagena, 43, 28007 Madrid, telling us which right you wish to exercise. If we have reasonable doubts about your identity, we may ask you for the additional information needed to confirm it. We will reply within one month. That period may be extended by a further two months if the request is complex or if we receive a large number of requests; in that case, we will let you know within the first month.

The law may limit some rights. For example, professional secrecy prevents us from disclosing information about other clients, and Article 32(2) of Law 10/2010 excludes the rights in Articles 15 to 22 GDPR in respect of data processed to comply with the obligations in Chapter III of that Law (special examination, reporting and record-keeping).

8. Complaints to the Spanish Data Protection Agency

If you believe that we have not processed your data properly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD), for example through its electronic office (sede electrónica, in Spanish). We would be grateful if you contacted us first so that we can try to resolve the matter.

9. Sensitive data, third-party data and minors

When you first contact us, and in particular through the form on this website, please do not send us particularly sensitive data, such as health data, or documents containing other people’s data, unless they are essential for us to understand your enquiry. If your matter later requires us to process special categories of data, we will do so only to the extent necessary and in the cases permitted by Article 9(2) GDPR, and we will tell you so when we formalise the engagement.

This website is not aimed at minors. If you are a minor, please contact us through your parents or legal guardians.

10. Security and professional secrecy

We apply technical and organisational measures appropriate to the risk in order to protect your data against loss, alteration and unauthorised access (Art. 32 GDPR). The website is served over an encrypted connection (HTTPS).

The information you entrust to us is protected by professional secrecy. Please bear in mind that neither ordinary email nor the form on this website is end-to-end encrypted: the form travels encrypted as far as the server, but the notification reaches us by email. If you need to send us confidential documents, we can agree a more secure method with you.

11. Cookies and similar technologies

This website does not use cookies or similar technologies, such as the browser’s local storage, tracking pixels or device fingerprinting techniques, whether our own or third-party. Nor does it use any analytics or advertising tools. That is why we do not show you a cookie notice.

Fonts and images, including the location map, are served from our own server. When the pages load, no requests are made to third-party services such as Google Fonts.

The location map and the firm’s address link to Google Maps. Google receives no data about your visit until you click one of those links. Once you are on Google Maps, Google’s terms and privacy policy apply.

If in the future we introduce cookies or third-party content that uses them, such as a map embedded in the page, we will update this policy and, where necessary, ask for your consent beforehand.

12. Changes to this policy

We may amend this policy to reflect changes in the law or to the website. The date of the last update is shown at the top of this page.