
1. Data controller
Under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Act 3/2018 (LOPDGDD), the controller of your personal data is:
- Registered nameTruco y Trufa, S.L.
- Tax IDB86522711
- Registered addressCalle de Francisco Sancha 4, 2ª, 28034, Madrid, España
- Emailtrucoytrufa@trucoytrufa.es
- Phone91 513 46 94
- Company registerInscrita en el Registro Mercantil de Madrid, Tomo 30.158, Folio 186, Sección 8, Hoja M-542830, Inscripción 1
2. What data we process
We only process the data you give us. We do not buy databases or obtain data from third parties, and we do not profile or make automated decisions.
There is no user account, no purchase and no private area. Only two routes:
- The newsletter. If you subscribe from the site footer we store your email address and, if you fill them in, your first name, last name and the profile you tick (brand, marketer, partner or press). Nothing else: we do not store your IP or what you browse.
- If you write to us. We process what you include in that email to trucoytrufa@trucoytrufa.es: your name, your address and whatever you tell us.
3. Purpose and legal basis
- Sending you the newsletter and telling you what we publish. Legal basis: your consent, given by ticking the box on the form (art. 6.1.a GDPR). You may withdraw it at any time by writing to gema.saiz@trucoytrufa.es, and we will stop writing to you with no further steps. Data is kept while you remain subscribed; if you unsubscribe we keep only the record that you consented and when you withdrew it, which is what lets us show we acted properly.
- Answering your enquiry and keeping in touch. Legal basis: your consent in writing to us and, where the enquiry aims at engaging us, pre-contractual measures (art. 6.1.a and 6.1.b GDPR).
- Managing the commercial relationship if we end up working together, including invoicing. Legal basis: performance of the contract and compliance with legal, accounting and tax obligations (art. 6.1.b and 6.1.c GDPR).
4. How long we keep it
The shortest time necessary for the purpose and our legal obligations, or until you withdraw consent. Data is then blocked and available to the competent authorities for the statutory limitation periods and deleted afterwards. Indicative periods:
- 4 years — arts. 66 ff. of the Spanish General Tax Act.
- 5 years — art. 1964 of the Civil Code, personal actions with no special term.
- 6 years — art. 30 of the Commercial Code, books and invoices.
- 10 years — art. 25 of the Anti-Money Laundering Act.
5. Who we share it with
We do not share your data with third parties except where legally required. Our technology providers do access it as processors, solely to provide their service, under an article 28 GDPR agreement:
- Amazon Web Services — site and database hosting, Ireland region (European Union).
- Cloudflare — delivery network and security in front of the site, and cookieless aggregate visit measurement.
- Google — corporate email.
- Clerk — authentication for the admin panel, used by internal staff only.
- Actium Consulting, S.L. — accounting and tax advisors, processing the billing data required to keep the accounts and meet tax obligations.
Some of these providers are established outside the European Economic Area. Where that is the case, the transfer relies on the safeguards of chapter V GDPR: an adequacy decision (EU–US Data Privacy Framework) or standard contractual clauses.
6. Your rights
You may at any time exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw any consent given, without affecting the lawfulness of prior processing. Write to gema.saiz@trucoytrufa.es stating the right you are exercising. We may ask for a valid identity document where there is reasonable doubt, and for proof of authority if you act on someone else’s behalf. You may also send your request by post to Calle de Francisco Sancha 4, 2ª, 28034, Madrid, España. We will reply within one month.
If you believe we have not handled your request properly, you may complain to the Spanish Data Protection Agency (www.aepd.es), C/ Jorge Juan 6, 28001 Madrid.
7. Security
We apply reasonable technical and organisational measures: encryption in transit (HTTPS), credential-restricted access to the admin panel, and backups. By giving us data you warrant that it is accurate and that, if it belongs to a third party, you have informed them of this processing beforehand.
8. Data breaches
If we determine that a security breach affecting personal data has occurred, we will act immediately in accordance with the GDPR and the instructions of the competent supervisory authority, including notifying those affected where required.
9. Changes
We may update this policy to reflect legal or service changes. The version in force is always the one published on this page. For what is stored in your browser, see the cookie policy.
See also: legal notice · cookies
Last reviewed: 15/08/2026