Privacy Policy
1. Data Controller
The data controller responsible for processing your personal data is:
Somatic Marbella
Self-employed practitioner (autónoma)
Marbella, Spain
Email: hello@yourdomain.com
This website is operated in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Spanish Organic Law 3/2018 (LOPDGDD).
2. Personal Data We Collect
We only collect personal data that is necessary and proportional to provide our services. This may include:
-
Name
-
Email address
-
Phone number (if provided)
-
Information you voluntarily share via contact or booking forms
-
Technical data (IP address, browser type, device information)
We do not collect sensitive health data through this website. Any information shared in person during a session is treated confidentially and is not stored digitally.
3. Purpose of Data Processing
Your personal data is processed for the following purposes:
-
To respond to inquiries and contact requests
-
To manage appointments and communication related to sessions
-
To ensure the security and proper functioning of this website
-
To comply with legal obligations
Your data will not be used for automated decision‑making or profiling.
4. Legal Basis for Processing
We process your personal data on the basis of:
-
Your consent (Article 6(1)(a) GDPR)
-
Performance of a service or pre‑contractual communication (Article 6(1)(b) GDPR)
-
Legal obligations where applicable (Article 6(1)(c) GDPR)
These legal bases are recognised under both GDPR and Spanish data protection law.
5. Data Retention
Personal data is kept only for as long as necessary to fulfil the purposes outlined above or to comply with legal requirements.
Contact inquiries are typically retained for a maximum of 12 months, unless a longer retention period is legally required.
6. Data Sharing and Third Parties
Your personal data will not be sold, rented, or shared with third parties, except:
-
When required by law
-
When necessary to operate essential technical services (e.g. website hosting), under strict data protection agreements
All third‑party providers comply with GDPR requirements.
7. International Data Transfers
If data is transferred outside the European Economic Area (EEA), it is done only to countries with an adequate level of data protection or under appropriate safeguards in accordance with GDPR.
8. Your Rights
You have the right to:
-
Access your personal data
-
Rectify inaccurate data
-
Request erasure (“right to be forgotten”)
-
Restrict processing
-
Object to processing
-
Request data portability
To exercise your rights, please contact: hello@yourdomain.com
You also have the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD):
https://www.aepd.es
9. Cookies & Analytics
This website may use essential cookies required for functionality.
Non‑essential cookies or analytics tools are only used with your explicit consent, in accordance with Spanish and EU regulations.
A separate Cookie Policy may apply if analytics or tracking tools are used.
10. Data Security
We implement appropriate technical and organisational measures to protect your personal data against loss, misuse, unauthorised access, or disclosure, as required by GDPR and LOPDGDD.
11. Changes to This Privacy Policy
This Privacy Policy may be updated to reflect legal or operational changes. The current version will always be available on this website.