Privacy policy
En Creacom Comunicació Estratègica, S.L. nos tomamos muy en serio tu privacidad. Esta política explica qué datos recogemos, para qué los usamos, durante cuánto tiempo los conservamos y cómo puedes ejercer tus derechos. Cumple con el RGPD y la LOPDGDD.
1. Data controller
The controller of your personal data is:
- Company name: Creacom Comunicació Estratègica, S.L.
- Address: Ronda Maiols, 1 — Edifici BMC (office 314) — 08192 Sant Quirze del Vallès, Barcelona
- Tax ID (NIF): B67597088
- Email: creacom@creacom.es
- Data Protection Officer: dpo@creacom.es
2. Purposes of processing
We process your personal data for the following purposes:
| Purpose | Legal basis | Data categories |
|---|---|---|
| Managing commercial contacts and customer service | Consent (Art. 6.1.a GDPR) | Identification, contact, professional data |
| Sending commercial communications | Explicit consent | Email, name, company |
| Statistical analysis of website usage | Legitimate interest + cookie consent | Anonymised browsing data |
| Compliance with legal obligations | Legal obligation (Art. 6.1.c GDPR) | Accounting and tax data |
3. Retention periods
We retain your data for the following periods:
- Commercial contacts without contracting: 2 years from the last contact.
- Active clients: for the duration of the contractual relationship and for the applicable legal periods (minimum 5 tax years).
- Newsletter subscribers: until you unsubscribe via the link in each communication.
- Accounting and tax data: 6 years in accordance with the Commercial Code.
4. Recipients of data
We do not transfer your data to third parties, except as legally required. We do use the following processors:
- Hosting providers (website server)
- Email marketing provider (newsletter sending)
- CRM platforms (commercial management)
- Analytics services (Google Analytics 4, with IP anonymisation)
- Tax and labour advisors (compliance with accounting obligations)
All our processors are bound by data processing agreements that ensure GDPR compliance.
5. International transfers
Some of our providers (Google, Meta, US-based SaaS platforms) may process data outside the European Economic Area. In such cases, Standard Contractual Clauses approved by the European Commission are applied, and Transfer Impact Assessments (TIAs) are carried out where appropriate.
6. Data subject rights
As a data subject, you may exercise the following rights at any time:
- Access: know what data we hold about you.
- Rectification: correct inaccurate data.
- Erasure: delete your data ("right to be forgotten").
- Restriction: restrict processing in certain circumstances.
- Portability: receive your data in a structured format.
- Objection: object to processing on grounds relating to your particular situation.
- Withdraw consent without affecting the lawfulness of prior processing.
- Complaint to the AEPD: lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
To exercise any right, write to creacom@creacom.es indicating the right you wish to exercise and attaching a copy of your identity document.
7. Data security
We apply appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including, where applicable: encryption of data in transit and at rest, access management based on the principle of least privilege, regular audits and ongoing staff training.
8. Changes to this policy
This policy may be updated to reflect regulatory changes, security improvements or service developments. The "Last updated" date appears at the top of this page. We recommend reviewing it periodically.