Privacy Policy

Last updated: August 4, 2026

1. Data Controller

Controller: Ricardo López Alcántara

Tax ID (NIF): 08005562K

Address: Calle Velázquez 31, 28001 Madrid, Spain

Email: ricardo@ruisenor.es

Phone: +34 655 342 923

Website: ruisenor.es

2. Processing Activities

I process personal data in three distinct contexts. Each has its own purpose, legal basis, and retention period.

2.1. People who contact through the website

Data: first and last name, email address, company, job title, and any information voluntarily included in their message.

Purpose: respond to inquiries, provide requested information, and, where applicable, carry out pre-contractual steps for a potential commercial relationship.

Legal basis: consent of the data subject when submitting the form (Art. 6(1)(a) GDPR) and pre-contractual measures at their request (Art. 6(1)(b) GDPR).

Retention: until the inquiry is resolved, plus one year thereafter, unless a commercial relationship begins.

2.2. Clients and client contacts

Data: first and last name, job title, professional email, professional phone, company, billing data, and records of communications.

Purpose: provide the contracted service, coordinate delivery, offer support, issue invoices, and comply with accounting and tax obligations.

Legal basis: performance of contract (Art. 6(1)(b) GDPR), compliance with legal obligations in tax and commercial matters (Art. 6(1)(c) GDPR), and legitimate interest in maintaining the commercial relationship and managing support (Art. 6(1)(f) GDPR).

Retention: during the contractual relationship and, once ended, six years for commercial and tax documentation, in accordance with the Commercial Code and tax regulations.

2.3. Professionals included in commercial intelligence reports

This is the core processing activity of the business and is described in the detail required by Article 14 of the GDPR, as the data is not obtained from the data subject directly.

Data: first and last name, job title or role, professional email, professional phone, company or organization, publicly accessible professional or corporate profiles, and information about the opening or upcoming opening of the establishment.

Source of data: publicly accessible sources and public registers, specifically Google Maps and Google Places, the Official Gazette of the Commercial Registry (BORME), corporate websites, public social media profiles, the Meta Ad Library, and specialized providers of professional contact data.

Purpose: prepare periodic commercial intelligence reports on new business openings and communicate them to client companies, so they can direct their commercial actions toward organizations potentially interested in their offering.

Legal basis: legitimate interest of the controller and report recipients in developing their B2B commercial activity (Art. 6(1)(f) GDPR). A corresponding balancing test between this interest and the rights and freedoms of affected individuals has been conducted and documented. This balancing took into account that the data processed is exclusively professional in nature, relates to the person in their capacity as representative or employee of an organization, comes from publicly accessible sources, does not involve special categories of data, and that an easily accessible right to object exists.

Retention: data is periodically reviewed and deleted after twenty-four months if no longer relevant for the described purpose. Minimum identifying data of those who exercise their right to object is retained indefinitely in an exclusion list, solely to ensure they are not re-incorporated into reports.

3. Data Recipients

3.1. Data processors

Certain providers access personal data to provide services to me, following my instructions and under a data processing agreement in accordance with Article 28 of the GDPR. By category:

  • Website hosting and domain registration
  • Email, cloud storage, and office productivity
  • Customer relationship management (CRM) system
  • Email delivery platform
  • Professional contact data enrichment and verification providers
  • Payment processing and billing

3.2. Communication of data to clients

The data described in section 2.3 is communicated to client companies that contract the reports. These companies act as independent controllers: they decide for themselves how to use the information received and assume their own data protection obligations, including informing affected individuals when they contact them.

3.3. Legal obligations

Data may be communicated to the tax administration, law enforcement, and courts and tribunals when there is a legal obligation to do so.

4. International Transfers

Some of the indicated providers are established outside the European Economic Area, primarily in the United States. In those cases, transfers are supported by an adequacy decision of the European Commission, the provider's adherence to the EU-U.S. Data Privacy Framework, or the signing of Standard Contractual Clauses, together with any supplementary measures that may be necessary.

You may request information about the safeguards applicable to a specific transfer by writing to ricardo@ruisenor.es.

5. Rights of Data Subjects

How to exercise them. By writing to ricardo@ruisenor.es indicating the right you wish to exercise. I may request additional information to confirm identity only if there are reasonable doubts about who is making the request. I will respond within one month, extendable to two if the request is complex, in which case I will communicate this within the first month. Exercising these rights is free of charge.

If your data comes from public sources. If you received this information because your professional data appears in my commercial intelligence reports and you do not wish to appear in them, simply reply to this communication or write to ricardo@ruisenor.es indicating "Unsubscribe". Your request will be processed immediately and your data will be added to an exclusion list to prevent future processing.

Complaint. If you consider that your rights have not been properly addressed, you may file a complaint with the Spanish Data Protection Agency (www.aepd.es), C/ Jorge Juan 6, 28001 Madrid.

Any person has the right to:

  • Access: know whether I process their data and obtain a copy.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request deletion when data is no longer necessary or when their objection succeeds.
  • Objection: object to processing based on legitimate interest. If they object, I will stop processing their data unless I demonstrate compelling legitimate grounds that override their rights.
  • Restriction: request suspension of processing while a challenge is verified.
  • Portability: receive data they have provided in a structured, commonly used format.
  • Withdraw consent at any time, when processing is based on consent, without affecting the lawfulness of prior processing.
  • Not be subject to automated decisions with legal or similar effects. No such decisions are made.

6. Security

I have adopted appropriate technical and organizational measures to protect personal data against destruction, loss, alteration, or unauthorized access, taking into account the state of the art, implementation costs, and the nature and risk of the processing.

7. Cookies

The use of cookies on the website is detailed in the Cookie Policy, accessible from the Site itself.

8. Modifications

This policy may be updated to adapt to regulatory changes or modifications in the activity. The current version will always be the one published on ruisenor.es, with its update date indicated.