Vai al contenuto

This document is available in English, German and Spanish. In case of discrepancies, the German version prevails.

Privacy Policy

Aggiornato: October 2026

Protecting your data matters to us – especially because you entrust us with sensitive details such as your ID number and date of birth for your application. Here we explain clearly what we do with your data.

1. Controller

Auerswald Marketing S.L.
Ctra. del Cap de la Nau Pla, 126-1-18, 03730 Xàbia, Spanien
NIF / VAT ID: ESB09946799
E-mail: [email protected]

For all data protection questions, contact us at this address with the subject “Data protection”.

2. Legal framework

We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Spanish Data Protection Act (Ley Orgánica 3/2018, LOPDGDD). Personal data is any information relating to you as a person.

3. Data we process

  • Application data: name, birth name, place and date of birth, nationality, sex, marital status, passport or ID number, home address, parents' first names, reason for the application, NIE number where applicable.
  • Company data (for NIF applications): company name, legal form, registration number, registered office, date of incorporation, VAT ID and the name of the contact person.
  • Contact data: e-mail address, phone number, preferred language.
  • Contract and payment data: services booked, prices, payment status. Card details are received only by our payment service provider, not by us.
  • Communication: the content of your messages by e-mail, WhatsApp or via the consultation form.
  • Technical data: IP address, date and time of access, browser and device information (server log files).

4. Purposes and legal bases

PurposeDataLegal basis
Processing your application, preparing the power of attorney, submission to authoritiesApplication, company and contact dataPerformance of contract (Art. 6(1)(b) GDPR)
Payment processing, invoicing, accountingContract and payment dataPerformance of contract and legal obligations (Art. 6(1)(b), (c) GDPR)
Status updates by e-mail and SMS, queriesContact dataPerformance of contract (Art. 6(1)(b) GDPR)
Answering enquiries and consultation requestsContact data, messagePre-contractual measures or legitimate interest (Art. 6(1)(b), (f) GDPR)
Newsletter with tips about SpainE-mail address, nameConsent (Art. 6(1)(a) GDPR)
Operation and security of the websiteTechnical dataLegitimate interest (Art. 6(1)(f) GDPR)
Analytics to improve the websiteUsage dataConsent (Art. 6(1)(a) GDPR, Art. 22.2 LSSI)

You can withdraw any consent at any time with effect for the future, e.g. via the unsubscribe link in the newsletter or the cookie settings in the footer. You can object to e-mail marketing at any time.

5. Recipients

We only share your data where this is necessary for the respective purpose:

  • Spanish authorities such as the Policía Nacional (NIE) and the Agencia Tributaria (NIF) – your application is not possible without this transfer.
  • Partners involved in performance, e.g. gestorías, notaries for notarisation, recognised trust service providers for digital certificates, and postal and courier services.
  • Payment service provider: Stripe Payments Europe, Ltd., Ireland.
  • Technical service providers (processors) for hosting, e-mail delivery and SMS, contractually bound by our instructions.
  • Tax advisers and auditors within the scope of our legal obligations.
  • WhatsApp (Meta Platforms Ireland Ltd.), only if you contact us via WhatsApp yourself.

6. Transfers to third countries

Some service providers (e.g. Stripe or Meta) may also process data in the USA. Transfers only take place on the basis of an adequacy decision of the European Commission (EU-US Data Privacy Framework) or the European Commission's standard contractual clauses.

7. Retention periods

  • Application and contract data: for the duration of processing and then for up to six years due to commercial and tax retention obligations (Art. 30 Spanish Commercial Code, General Tax Act).
  • Consultation requests without an order: 12 months.
  • Newsletter: until you unsubscribe.
  • Server log files: no more than 30 days, except in the event of security incidents.

We then delete or anonymise the data. Paper documents (e.g. powers of attorney) are destroyed in compliance with data protection rules.

8. Cookies and local storage

We only use cookies that are technically necessary to operate the website:

NamePurposeDuration
spainmate-sessionSession, e.g. so that form entries are kept if there are errors2 hours
XSRF-TOKENProtecting forms against misuse2 hours
sm_cookie_consent (local storage)Stores your cookie choiceuntil deleted

We currently do not use any analytics or marketing tools. Should we use such tools in future, we will only do so with your consent via the cookie banner and will update this policy. You can change your choice at any time via “Cookie settings” in the footer.

9. Website, hosting and fonts

When you visit the website, our hosting provider processes technically necessary data (including your IP address) to deliver the site and protect it against attacks. Transmission is encrypted (TLS).

Fonts are loaded locally from our own server. No connection to external font providers is made when you visit the site.

10. Obligation to provide data

The information marked as mandatory in the application form is required by the Spanish authorities. Without it, we cannot process your application. There is no automated decision-making or profiling.

11. Your rights

You have the right of access, rectification, erasure, restriction of processing and data portability, and the right to object to processing based on legitimate interests. To exercise them, write to [email protected]. We will reply within one month; in complex cases this period may be extended, in which case we will inform you.

You also have the right to lodge a complaint with a data protection supervisory authority – in Spain the Agencia Española de Protección de Datos (AEPD, www.aepd.es) – or with the supervisory authority in your country of residence.

12. Data security

We protect your data with technical and organisational measures, including encrypted transmission, need-to-know access rights and confidentiality obligations for our staff and partners. In the event of a data breach, we act in accordance with the statutory notification obligations.

13. Changes

We update this privacy policy when our services or the legal situation change. The version published on this page applies.