Privacy policy
1. Data Controller
In accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), users are informed that the data controller responsible for personal data processed through this website is:
Data Controller: GESTIÓN INTEGRAL DE EMPRESAS FUSTER, S.L.
NIF: B96279195
Address: Calle Enric Valor, 1 – bajo, 46717 La Font d’en Carròs, Valencia, Spain
Email: info@meritxellfuster.com
Website: meritxellfuster.com
2. Personal Data We May Collect
The personal data collected depends on how users interact with the website.
Contact Information
When a user submits the contact form, the following information may be collected:
- Name.
- Email address.
- Telephone number.
- Subject of the enquiry.
- Content of the message.
- Any other information voluntarily provided by the user.
Users should avoid including unnecessary sensitive or special-category personal data in free-text fields.
Technical and Browsing Information
The website and its technical infrastructure may process information necessary for its operation and security, including:
- IP address.
- Browser and device information.
- Date and time of access.
- Technical logs.
- Security information.
- Cookie identifiers or similar technologies, where applicable.
3. Purposes of Processing
Responding to Enquiries
Personal data may be processed to receive, manage and respond to questions, professional enquiries, project proposals, employment opportunities, collaborations or other communications submitted through the website.
Managing Professional Relationships
Where an enquiry may lead to a professional collaboration, project or contractual relationship, personal data may be processed to communicate with the interested party and take the necessary preliminary steps.
Website Operation and Security
Technical data may be processed where necessary to maintain website functionality, prevent misuse, identify malicious activity and protect information systems.
Compliance with Legal Obligations
Personal data may also be processed or retained where necessary to comply with legal obligations or requests from competent public authorities.
4. Legal Basis for Processing
The legal basis for processing depends on the purpose for which the information is collected.
General enquiries submitted voluntarily through the contact form may be processed on the basis of the user’s consent pursuant to Article 6(1)(a) GDPR.
Where an enquiry relates to a potential project, quotation, collaboration or contractual relationship, processing may also be necessary in order to take steps at the request of the data subject prior to entering into a contract, pursuant to Article 6(1)(b) GDPR.
Processing required to comply with legal obligations is based on Article 6(1)(c) GDPR.
Certain technical and security-related processing may be based on the legitimate interest of the Controller in maintaining the proper operation and security of the website, in accordance with Article 6(1)(f) GDPR.
5. Contact Form and Consent
Before submitting the contact form, users are required to confirm that they have read this Privacy Policy and agree to the processing of their personal data for the purpose of managing and responding to their enquiry.
Fields marked as mandatory must be completed in order to submit the form.
Users are responsible for ensuring that the information provided is accurate, complete and up to date.
6. Data Retention
Personal data will only be retained for as long as necessary to fulfil the purpose for which it was collected.
Enquiries that do not result in a professional or contractual relationship will be retained only for the period reasonably necessary to manage the communication and any subsequent follow-up.
Where a contractual or professional relationship is established, the information may be retained for the duration of that relationship and, subsequently, for the periods required by applicable tax, accounting, administrative or liability legislation.
Data may also be retained where necessary for the establishment, exercise or defence of legal claims.
7. Recipients of Personal Data
Personal data will not be sold to third parties.
Data may be accessed by service providers where necessary for the proper operation of the website and management of communications, including providers of:
- Web hosting.
- Email services.
- Website maintenance.
- Technical support.
- Cybersecurity and anti-spam services.
- Analytics services, where applicable.
Such providers will be subject to the corresponding confidentiality and data protection obligations where required by law.
Personal data may also be disclosed to courts, public administrations or competent authorities where legally required.
8. International Data Transfers
Some technology service providers may process information outside the European Economic Area.
Where an international transfer of personal data takes place, appropriate safeguards recognised under the GDPR will be used, such as adequacy decisions, Standard Contractual Clauses or another legally valid mechanism.
9. Rights of Data Subjects
Users may exercise the rights recognised under applicable data protection legislation.
- Access: request information about personal data being processed.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure: request deletion of personal data where legally applicable.
- Objection: object to certain processing activities.
- Restriction: request restriction of processing in legally established circumstances.
- Portability: receive personal data in a structured, commonly used and machine-readable format where applicable.
- Withdrawal of consent: withdraw previously granted consent at any time.
- Automated decisions: exercise rights relating to automated decision-making where applicable.
Requests to exercise these rights may be sent to: info@meritxellfuster.com.
The Controller may request appropriate information to verify the identity of the person making the request.
10. Right to Lodge a Complaint
If users consider that their personal data has been processed in breach of applicable data protection legislation, they have the right to lodge a complaint with the competent supervisory authority.
In Spain, the competent supervisory authority is the Agencia Española de Protección de Datos (AEPD).
11. Security of Personal Data
Appropriate technical and organisational measures are applied according to the nature of the information processed and the risks involved.
These measures are intended to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Nevertheless, no Internet-based system can guarantee absolute security.
12. Data Provided by Third Parties
Users who provide personal information relating to another person are responsible for ensuring that they are legally authorised to do so and, where required, for informing that person about the processing of their data.
13. External Websites
This website may contain links to third-party websites or online platforms.
This Privacy Policy applies only to this website. Users should review the privacy policies of external websites before providing personal information through them.
14. Changes to this Privacy Policy
This Privacy Policy may be modified where necessary due to legislative, regulatory, technical or operational changes.
The version published on the website at any given time will be the applicable version.

