ANDvisor Legal
ExpertiseApproachANDvisorInsightsContact ↗
Contact ↗

ANDvisor Legal

PRIVACY POLICY

Last updated: 12 August 2026

1. Data controller

Controller: Martínez Murillo Legal Services, S.L. · Spanish tax identification number (NIF) B10528198 · Avenida de los Guindos 12, 29004 Málaga, Spain.

General contact: contacto@andvisor.es · Privacy and exercise of rights: privacidad@andvisor.es.

2. Data processed

When a person uses the contact form, the following data may be processed: name, email address, country of residence, area of enquiry, description of the matter, interface language and technical data strictly necessary to receive and protect the request (for example, basic request information and security measures).

The form does not request documents, health data, criminal records or other special categories of data. Please do not include particularly sensitive information unless it is essential and an appropriate channel has been indicated in advance.

3. Purposes

  • To receive, review and respond to enquiries concerning ANDvisor Legal’s legal services.
  • At the data subject’s request, to assess the potential provision of services and take pre-contractual steps.
  • To maintain the security of the form, prevent automated abuse and manage technical incidents.
  • To comply with legal obligations and address or defend potential claims where necessary.

4. Legal bases

The management of an enquiry seeking information about legal services or assessment of a potential engagement is based primarily on taking pre-contractual steps at the data subject’s request (Article 6(1)(b) GDPR).

Certain processing for security, abuse prevention and the defence of claims may be based on legitimate interests (Article 6(1)(f) GDPR), subject to a balancing assessment where appropriate. Compliance with legal obligations is based on Article 6(1)(c) GDPR.

The form is not used to subscribe users to commercial communications and no marketing consent checkbox is requested.

5. Recipients and providers

Data may be processed by technology providers necessary to operate the website and deliver the enquiry, acting as processors or sub-processors, as applicable.

In particular, the website infrastructure uses Cloudflare/Sites services to serve and protect the website and process the form endpoint. Transactional delivery is carried out through Brevo. The enquiry is ultimately delivered to the contacto@andvisor.es mailbox.

The functional flow of the form is: visitor → secure website endpoint → Brevo Transactional Email API → contacto@andvisor.es.

The form does not automatically create marketing contacts, lists, commercial profiles or CRM records in Brevo.

6. International transfers

Brevo states that the servers on which it processes and stores its databases are located in the European Union. Cloudflare’s infrastructure operates a global network, and certain processing or access may involve international transfers. Where applicable, such transfers must be covered by mechanisms recognised under the GDPR, such as adequacy decisions, the EU–US Data Privacy Framework or Standard Contractual Clauses, as appropriate.

7. Retention

Enquiries that do not lead to a professional relationship will be retained for the time necessary to handle them and, as a general rule, for up to 12 months from the last communication, unless certain data need to be retained for longer to comply with a legal obligation or to establish, exercise or defend legal claims.

If the enquiry results in a professional engagement, the necessary information will form part of the relevant matter file and will be retained in accordance with the applicable legal, professional and liability obligations.

In the Brevo account used for the form, transactional logs have been configured with a one-month retention period and content previews have been disabled. Open/click tracking is disabled.

8. Rights

Data subjects may request access, rectification, erasure, objection to or restriction of processing and, where applicable, data portability by writing to privacidad@andvisor.es and providing sufficient identification of their request. They may also lodge a complaint with the Spanish Data Protection Agency.

9. Security

Reasonable technical and organisational measures are applied to protect information. The form includes server-side validation, same-origin protection, size limits, a honeypot and rate limiting. Brevo credentials are stored as a production secret and are not exposed in the browser.

10. Changes

This Policy may be updated when processing activities, providers or legal requirements change. The date of the current version will be shown at the beginning of the document.

ANDvisor Legal

International legal services in Spain

Expertise

Immigration & International MobilityCorporate & Commercial LawReal Estate & Investment

ANDvisor

ANDvisorInsightsContact
© 2026 ANDvisor Legal. All rights reserved.
Legal NoticePrivacy PolicyCookies & Storage