Additional information on data protection — Information request of achamancapital.es

Additional information on data protection (Information request) for the processing of personal data collected from the data subject, pursuant to and for the purposes of Articles 12 and 13 of Regulation (EU) 2016/679 (hereinafter the “Regulation” or “GDPR”) and Article 11 of Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and guarantee of digital rights (“LOPDGDD”). The Data Controller indicated below informs that it will process the data for the purposes and in the manner indicated below. This notice is not valid for any subdomains or other websites accessible through links on this site.

1. DATA CONTROLLER (Article 13(1)(a) of the Regulation)

The identification details of the Data Controller are indicated in the box at the end of this document.

2. DATA PROTECTION OFFICER (DPO) (Article 13(1)(b) of the Regulation; Article 37 of the Regulation)

The identification details of the Data Protection Officer (DPO), if appointed, are indicated in the box at the end of this document.

3. CATEGORIES OF PERSONAL DATA

3.1 Personal data subject to processing: “personal data”: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

3.2 The data processed by the Data Controller are:

3.2.1 identifying personal data / navigation data: first name, surname, telephone number, e-mail address, IP address, browser user agent, date, time and requested URL;

3.2.2 special categories of data (Article 9 of the Regulation): No data;

3.2.3 data relating to criminal convictions and offences (Article 10 of the Regulation): No data;

3.2.4 type of possible profiling: No profiling.

The processing of the data will be carried out in accordance with the provisions of the Regulation, as specified below.

4. SOURCE OF THE PERSONAL DATA

The personal data processed are those collected from the data subject themselves.

5. PURPOSES OF THE PROCESSING (Articles 13(1)(c) and 13(2)(a) of the Regulation)

5.1 “Information request”: The purpose of this processing is the handling of the data provided in the site’s contact/chat forms in order to provide technical information about the services/products offered within the scope of your request (e.g. informative materials, quotations, enrolment forms for our services); replies may be given by e-mail or telephone (SMS, WhatsApp, social networks). For this purpose, the data will be kept for the time strictly necessary, not exceeding 3 years from the last bilateral contact (plus 3 months to carry out the deletion). This purpose does not require consent, in accordance with Article 6(1)(b) of the Regulation (pre-contractual measures at the data subject’s request). The data used for this purpose are those indicated in point 3.2.1.

5.2 “General statistics”: The purpose of this processing is the handling of the data provided while using the website in order to produce general statistics in anonymous and/or aggregate form, for the sole purpose of improving the quality of the products or services offered. The data will be kept for the time strictly necessary, not exceeding 1 year (plus 3 months to carry out the deletion). This purpose does not require consent, in accordance with Article 6(1)(f) of the Regulation (legitimate interest of the Controller in improving its products and services). The data used for this purpose are all those indicated in point 3.2.1.

5.3 “Meta Pixel (Facebook/Instagram)”: The purpose of this processing is the processing of navigation data through the Meta Pixel, to measure the effectiveness of advertising campaigns and to show personalised ads (retargeting) on the Meta platforms (Facebook, Instagram). The data collected through the pixel are transmitted to Meta Platforms Ireland Limited, which acts as joint controller for the collection and transmission (joint-controllership arrangement under Article 26 of the Regulation, available on the platform’s website), and may be transferred to Meta Platforms, Inc. in the United States under the EU-U.S. Data Privacy Framework. For this purpose, the data will be kept for the time strictly necessary, not exceeding 2 years (plus 3 months to carry out the deletion); Meta’s own retention terms (facebook.com/privacy/policy) also apply. This purpose requires consent, given through the dedicated banner, pursuant to Article 6(1)(a) of the Regulation and Article 22.2 of Law 34/2002 (LSSI-CE). Consent may be withdrawn at any time through the banner, as easily as it was given; if consent is not given the pixel is not activated, with no other consequence. The data used for this purpose are those indicated in point 3.2.1.

5.4 “Google Analytics”: The purpose of this processing is the processing of navigation data in pseudonymised form through Google Analytics 4, to measure the use of the site and to produce audience statistics. The data are processed on our behalf by Google Ireland Limited and may be transferred to Google LLC in the United States under the EU-U.S. Data Privacy Framework. For this purpose, the data will be kept for the time strictly necessary, not exceeding 26 months (plus 3 months to carry out the deletion). This purpose requires consent, given through the dedicated banner, pursuant to Article 6.1.a) of the Regulation and Article 22.2 of Law 34/2002 (LSSI-CE). Consent may be withdrawn at any time through the banner, as easily as it was given; if consent is not given the statistical measurement is not activated, with no other consequence. The data used for this purpose are those indicated in point 3.2.1.

5.5 “Social networks and embedded content”: The purpose of this processing is the processing of the navigation data of users who view pages of the site containing buttons, widgets or embedded content of third-party social networks (e.g. Facebook, Instagram, LinkedIn, X, TikTok). When such elements are loaded, the platform concerned may set its own cookies and receive navigation data (including the IP address); for the collection and transmission of such data the platform may act as joint controller (joint-controllership arrangement under Article 26 of the Regulation, available on the platform’s website). Any transfers to the United States take place under the EU-U.S. Data Privacy Framework or the safeguards indicated in the platform’s policy. For this purpose, the data will be kept for the time strictly necessary, not exceeding 2 years (plus 3 months to carry out the deletion); the platforms’ own retention terms also apply. This purpose requires consent, given through the dedicated banner, pursuant to Article 6(1)(a) of the Regulation and Article 22.2 of Law 34/2002 (LSSI-CE). Consent may be withdrawn at any time through the banner, as easily as it was given; if consent is not given the social content is not loaded (plain links to the social profiles remain usable), with no other consequence. The data used for this purpose are those indicated in point 3.2.1.

6. LEGAL BASIS OF THE PROCESSING (Article 13(1)(c) of the Regulation)

The legal basis of the processing is set out in each of the purposes indicated in point 5.

7. MANDATORY OR OPTIONAL NATURE OF THE INFORMATION PROVIDED BY THE USER (Article 13(2)(e) of the Regulation)

In accordance with Article 13(2)(e) of the Regulation, the provision of the data is optional or mandatory depending on the specific purpose for which the data is processed. If the personal data indicated above are not provided, it will not be possible to obtain what has been requested or to use the services of the Data Controller.

8. DATA DISCLOSURE (Article 13(1)(e) of the Regulation)

The personal data provided will be disclosed to recipients who will process them as processors (Article 28 of the Regulation) and/or as natural persons acting under the authority of the Controller and of the Processor (Article 29 of the Regulation), for the purposes listed in point 5.

The categories of subjects who may become aware of your personal data are: authorised persons (e.g. employees), Data Processors (e.g. suppliers, professionals, firms or companies within assistance and consultancy relationships with the Data Controller), the DPO (if appointed and indicated in the “DPO” box) and the public Authorities competent for controls or legal obligations. The data will not be disclosed to other third parties, except where there is a legal obligation or an adequate legal basis.

9. INTERNATIONAL DATA TRANSFERS (Article 13(1)(f) of the Regulation)

The data will/may be transferred to Member States of the European Union or of the European Economic Area, or to third countries for which the European Commission has adopted an adequacy decision pursuant to Article 45 of the Regulation. For further information, please contact the Data Controller.

Apart from the above cases, the data will NOT be transferred to third countries that do not ensure an adequate level of protection of personal data. Should such a transfer become necessary in the future, it will take place exclusively with the appropriate safeguards provided for by Articles 46 et seq. of the Regulation (for example, the standard contractual clauses approved by the European Commission by Commission Implementing Decision (EU) 2021/914), a copy of which the data subject may obtain by contacting the Data Controller.

10. SECURITY MEASURES (Article 32 of the Regulation)

The processing will be carried out in electronic form, with the aid of automated and electronic tools, for the time strictly necessary to achieve the purposes for which the data were collected. Specific security measures are observed to prevent the loss of data, unlawful or incorrect uses and unauthorised access, in accordance with Article 32 of the Regulation.

11. RIGHTS OF DATA SUBJECTS (Article 13(2)(b) and (c) of the Regulation)

The data subject may exercise their rights as provided for in Articles 7(3), 12, 13, 14, 15, 16, 17, 18, 19, 20, 21 and 22 of the Regulation:

Art. 7(3): Right to withdraw consent at any time, as easily as it was given, without the withdrawal affecting the lawfulness of processing based on consent given before its withdrawal;

Art. 12: Transparent information, communication and modalities for the exercise of the rights of the data subject;

Art. 13: Right to information and transparency: information to be provided where personal data are collected from the data subject;

Art. 14: Right to information and transparency: information to be provided where personal data have not been obtained from the data subject;

Art. 15: Right of access: right to obtain confirmation as to whether personal data concerning the data subject are being processed and to request a copy thereof;

Art. 16: Right to rectification: right to request the correction of inaccurate data or the completion of incomplete data;

Art. 17: Right to erasure / right to be forgotten: right to obtain from the Data Controller the erasure of personal data concerning the data subject; erasure cannot override the legal retention obligations to which the Data Controller is subject (e.g. tax and accounting obligations);

Art. 18: Right to restriction of processing: right to block or restrict the use of the data in the event of a dispute (e.g. while the accuracy of the personal data is being verified, where the processing is unlawful or where the data subject has objected to the processing);

Art. 19: Right to receive from the Data Controller a notification in the event of rectification or erasure of personal data or restriction of processing;

Art. 20: Right to data portability: right of the data subject to receive their data in a structured, machine-readable format, or to request its transmission to another controller;

Art. 21: Right to object: right to object to the processing of the data on legitimate grounds, including profiling and the sending of advertising material;

Art. 22: Right not to be subject to decisions based solely on automated processing (including profiling) which produce legal effects concerning the data subject;

The documentation is available at the registered office of the Data Controller (indicated in the corresponding box), who undertakes to guarantee the exercise of the data subject’s rights. To exercise their rights, the data subject may contact the Data Controller, identifying themselves sufficiently in their request.

In exercising the rights referred to in Articles 12 to 22 of the Regulation, the data subject may grant, in writing, a delegation or power of attorney to a natural person of their trust, attaching a copy of their identity document, or — pursuant to Article 80 of the Regulation — mandate a duly constituted not-for-profit body, organisation or association whose statutory objectives are in the public interest and which is active in the field of the protection of personal data. Requests may be sent to the Data Controller or to the DPO, if appointed, through the e-mail addresses indicated in the boxes at the end of the document; the Controller will reply within one month of receipt of the request (Article 12(3) of the Regulation).

The Data Controller does not take decisions based solely on automated processing, including profiling, which produce legal effects concerning the data subject or similarly significantly affect the data subject (Article 22 of the Regulation).

Article 23 of the Regulation allows the Member States or the European Union to restrict, by means of appropriate legislative measures, the rights of users (e.g. access, erasure) in order to safeguard primary interests such as national security, defence, criminal investigations, tax and anti-fraud assessments and judicial protection.

12. COMPLAINTS TO THE SUPERVISORY AUTHORITY (Article 77 of the Regulation; Article 13(2)(d))

The data subject has the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD) — C/ Jorge Juan, 6 — 28001 Madrid — www.aepd.es (electronic office: https://sedeagpd.gob.es) —, in particular if they consider that they have not obtained satisfaction in the exercise of their rights, following the procedures and instructions published on the official website of the Authority.

13. DATA RETENTION PERIOD (Article 13(2)(a) of the Regulation)

In accordance with Article 5(1)(e) of the Regulation, the personal data collected will be kept in a form which permits the identification of data subjects for a period not exceeding that necessary to achieve the purposes for which they are processed, with an additional margin of 180 days for technical reasons. Once the purpose has been fulfilled, the data will be kept blocked (Article 32 of the LOPDGDD), remaining at the exclusive disposal of judges and courts, the Public Prosecutor’s Office or the competent public Administrations during the limitation periods of any actions that may arise, and will then be deleted. Retention for a longer period is reserved in the event of the Controller’s defence in legal proceedings, for the entire duration of the litigation.

14. CHANGES TO THIS PRIVACY POLICY

Any future changes to this privacy policy will be published on this page; please check it regularly to stay informed of any updates.

CONTACT DETAILS OF THE DATA CONTROLLER:

ACHAMAN CAPITAL, SOCIEDAD ANÓNIMA — Calle San Borondón, 20 – 38632 El Fraile (Santa Cruz de Tenerife) – España — Tax ID (NIF) A-16465379 — Tel. +34616926436 — E-mail achamancapital2@achamancapital.com

CONTACT DETAILS OF THE DPO:

“NOT APPOINTED” (as not mandatory under Article 37 of the GDPR)

Date of last update: 29/07/2026

ACHAMAN CAPITAL, SOCIEDAD ANÓNIMA
Calle San Borondón, 20 – 38632 El Fraile
(Santa Cruz de Tenerife) – Spain
NIF A-16465379

Email

Phone

achamancapita2@achamancapital.com

+34 616 926 436

© 2026. All rights reserved.

LEGAL INFORMATION