Last updated: 31 August 2026.
This Privacy Policy explains how the personal data of people who visit the website https://carloschadacastro.com or who get in touch through it are processed, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (GDPR) and with Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD).
1. Data controller
- Controller: Carlos Gabriel Chada Castro
- Spanish Tax ID (NIF): 41610882H
- Address: Carrer de Celaya, 24, floor 2, door 12 – 46017 Valencia (Spain)
- Email: carloschada@gmail.com
- Data Protection Officer: none has been appointed, as none of the circumstances set out in Article 37 GDPR or Article 34 LOPDGDD apply.
2. What data are processed and where they come from
Only data voluntarily provided by the data subject are processed. No data are obtained from third parties or from publicly accessible sources.
a) Contact form. The following are collected: name and surname, email address, telephone number, reason for contact and the content of the message you choose to write.
Each form submission is emailed to the controller and is also recorded in the website’s own database, where it is kept together with the date and time of submission, the IP address it was sent from and the browser used. These last two items are recorded solely as a security measure and to prevent automated submissions.
b) Email. If you write directly to the addresses published on the website, the data contained in your message will be processed.
c) Browsing data. The server automatically records, in its log files, the IP address, the date and time of the request, and the browser and operating system used. These data are used solely for security and technical diagnostic purposes.
This website does not use web analytics, advertising or profiling tools, and does not install third-party cookies. Full details are available in the Cookie Policy.
3. Health data: important notice
The contact form is not designed or enabled to collect health data, which are a special category of data under Article 9 GDPR.
Please do not describe symptoms, diagnoses, treatments, clinical history or any other information about your health or that of third parties in the form or in emails sent to the published addresses. If you nevertheless include such information, it will be understood that you provide it at your sole responsibility and with your explicit consent (Article 9.2.a GDPR) for the sole purpose of allowing your request to be dealt with; that information will be treated with the utmost confidentiality and deleted as soon as it is no longer necessary.
Use of the form does not create any doctor–patient relationship and is not a substitute for a clinical consultation. In an emergency or life-threatening situation, call 112.
4. Purposes and legal bases for processing
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| To handle and respond to enquiries, requests or messages sent through the contact form or by email. | Consent of the data subject, given by ticking the acceptance box and submitting the form (Art. 6(1)(a)). |
| To maintain any subsequent correspondence arising from that enquiry. | Consent (Art. 6(1)(a)) and, where applicable, steps taken at the request of the data subject prior to entering into a contract (Art. 6(1)(b)). |
| To ensure the security of the website, prevent unsolicited bulk messaging and keep the server’s technical logs. | Legitimate interest of the controller in protecting the integrity and availability of the website (Art. 6(1)(f)). |
| To comply with legal obligations and respond to requests from competent authorities. | Compliance with a legal obligation (Art. 6(1)(c)). |
The data provided are not used to send commercial communications. This website has no newsletter or subscription list.
5. How long data are kept
- Enquiries through the form or by email: for as long as necessary to deal with the request and, once resolved, for a maximum of one year, unless the enquiry gives rise to a subsequent relationship or the data need to be kept in order to address potential liabilities, in which case they will be kept for the applicable statutory limitation periods.
- Form records stored on the website: these are reviewed periodically and deleted from the database once the enquiry has been dealt with and, in any event, once the maximum period of one year indicated above has elapsed.
- Server technical logs: a maximum of twelve months.
Once those periods have elapsed, the data are deleted or anonymised.
6. Who receives your data
Personal data are not disclosed to third parties except where legally required. They are not sold, rented or shared for commercial purposes.
The following processors are involved in providing the service. They access the data solely in order to provide their services and have entered into, or will enter into, the corresponding data processing agreements under Article 28 GDPR:
- MandarinaWebs SL (Spanish Tax ID B72797814, Avenida Tres Forques 6, 46018 Valencia, Spain): web hosting, domain email and technical maintenance services. The servers are located in Spain (European Union).
- Google Ireland Limited / Google LLC: provider of the email mailbox in which the controller receives messages sent through the form.
Technical route taken by form data
For the sake of transparency, this is the full route a message sent from the contact form follows:
- The message is transmitted, encrypted via HTTPS, to the server hosting the website, located in Spain.
- It is recorded in the website’s database, hosted on that same server.
- The website generates an email notification addressed to the controller.
- That notification is delivered to a Gmail mailbox, provided by Google, where the controller reads it.
International transfers: the website and its database are hosted entirely within the European Union. The only international transfer arises from the use of the Gmail email service, whose provider may process data in the United States. That transfer relies on the European Commission adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework, as well as on the standard contractual clauses entered into by the provider.
7. Automated decision-making
No automated decisions are taken and no profiling is carried out using the data provided.
8. Your rights
Anyone has the right to obtain confirmation as to whether personal data concerning them are being processed. Data subjects may exercise the following rights:
- Access: to find out which data are processed and obtain a copy.
- Rectification: to correct inaccurate or incomplete data.
- Erasure: to request deletion of the data when they are no longer necessary.
- Restriction of processing: to request that the data be kept only for the establishment or defence of legal claims.
- Objection: to object to processing on grounds relating to their particular situation.
- Portability: to receive the data in a structured, commonly used, machine-readable format and transmit them to another controller.
- Withdrawal of consent at any time, without affecting the lawfulness of processing carried out beforehand.
To exercise these rights, simply send a request to carloschada@gmail.com, stating the right you wish to exercise and enclosing a copy of a document proving your identity. Requests will be answered within one month, extendable by a further two months in particularly complex cases, in accordance with Article 12(3) GDPR.
If you consider that your rights have not been properly addressed, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, C/ Jorge Juan, 6, 28001 Madrid – www.aepd.es), without prejudice to your right to an effective judicial remedy.
9. Minors
This website is not aimed at children under fourteen. Under Article 7 LOPDGDD, the processing of the data of a child under fourteen is lawful only with the consent of the holder of parental responsibility or guardianship. If it is found that data relating to a child under fourteen have been received without such consent, they will be deleted immediately.
10. Information security
Appropriate technical and organisational measures are applied to ensure a level of security appropriate to the risk, including: encryption of communications by means of an SSL/TLS certificate (HTTPS protocol), access control to the website administration area, strong authentication, a web application firewall, regular software updates and backups.
Everyone who, by reason of their role, may access the data is bound by a corresponding duty of confidentiality.
In the event of a personal data breach entailing a risk to the rights and freedoms of the individuals concerned, the Spanish Data Protection Agency will be notified within 72 hours and, where appropriate, so will the data subjects, in accordance with Articles 33 and 34 GDPR.
11. Accuracy of the data
Users warrant that the data they provide are truthful, accurate and up to date, and are liable for any damage arising from their inaccuracy. Users also undertake not to provide third-party data without having previously informed those third parties and obtained their consent.
12. Cookies
Information on the use of cookies and similar technologies is set out in the Cookie Policy.
13. Changes to this policy
This Privacy Policy may be amended to reflect legislative developments, guidance from supervisory authorities or changes to the website itself. Any amendment will be published on this page, updating the date shown at the top of the document. Periodic review is recommended.