Privacy policy
This policy explains how personal data are processed in connection with the website https://balearic-lighthouse.com and the contact channels published on it, in accordance with Regulation (EU) 2016/679, General Data Protection Regulation (GDPR), Organic Act 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) and Spanish Act 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE).
1. Controller
- Controller: Rodolfo Armando Bustos Catalán (sole trader / self-employed)
- Trading name: The Balearic Lighthouse
- NIF (Spanish tax ID): 43129838P
- Registered address: Carrer Conradors, 29, 07141 Marratxí, Illes Balears, Spain
- Email: [email protected]
- Telephone: +34 675 67 76 85
- Activity: professional event lighting and the handcrafted manufacture of lighting systems
The appointment of a Data Protection Officer is not mandatory under article 37 of the GDPR and article 34 of the LOPDGDD, and none has therefore been appointed. For any matter relating to data protection you may write to [email protected].
2. General principle: an informative website that does not collect data
The website is static and informative. It has no contact forms, user registration, private area, online shop or booking system, and does not use cookies or analytics, advertising or tracking tools, whether first-party or third-party (see the Cookie policy).
Consequently, simply browsing the website does not involve the collection of personal data by the Controller. Personal data are processed only when the user decides to make contact on their own initiative through the published email address or telephone number, or when a commercial relationship exists or is entered into.
3. Processing carried out
3.1. Handling enquiries and quotation requests
- Purpose: to handle, manage and respond to the enquiries, requests for information or quotation requests that the user sends by email or telephone, and to maintain the contact necessary for that purpose.
- Legal basis: the implementation of pre-contractual measures requested by the data subject (art. 6.1.b GDPR) where the enquiry concerns a possible engagement; in all other cases, the Controller's legitimate interest in dealing with the communications addressed to it (art. 6.1.f GDPR), an interest regarded as prevailing because the communication is initiated by the user themselves.
- Categories of data: identification and contact details (name, email address, telephone number and, where applicable, company) and any other data the user voluntarily includes in their message.
- Retention: for the time necessary to deal with the enquiry and, thereafter, for the limitation period of any liabilities arising from that communication. Enquiries that do not lead to a commercial relationship are erased when they are no longer necessary.
3.2. Managing the relationship with clients, suppliers and collaborators
- Purpose: to formalise, perform and follow up engagements for the hire, supply or installation of lighting equipment and associated services; to manage invoicing, collections and payments, and to comply with accounting, tax and administrative obligations.
- Legal basis: the performance of a contract or of pre-contractual measures (art. 6.1.b GDPR) and compliance with the Controller's legal obligations in commercial, accounting and tax matters (art. 6.1.c GDPR).
- Categories of data: identification and contact details, tax and invoicing details, bank details necessary for collection or payment, and data relating to the engagement performed.
- Retention: for the duration of the relationship and, afterwards, blocked for the applicable statutory limitation periods, in particular those provided for in commercial legislation (6 years, art. 30 of the Spanish Commercial Code), tax legislation (4 years, art. 66 of the Spanish General Tax Act) and civil legislation, at the disposal of judges, courts and public administrations.
3.3. Commercial communications
The Controller has no newsletter or mailing list and does not carry out mass commercial mailings.
Should commercial information about the Controller's own products or services be sent, it will be sent only: (i) to those who have given their prior, express and unequivocal consent (art. 6.1.a GDPR and art. 21.1 LSSI-CE), or (ii) to clients in respect of products or services similar to those previously contracted, in accordance with article 21.2 of the LSSI-CE. In both cases, consent may be withdrawn or an objection to such mailings raised at any time, simply and free of charge, by writing to [email protected].
- Retention: until the data subject asks to be removed from the mailings or withdraws their consent.
3.4. Technical server logs
As on any website, the hosting provider automatically generates technical records (logs) of the requests received, which may include the visitor's IP address, the date and time of the request, the page requested, the browser type and the operating system.
- Purpose: to ensure the operation, security and integrity of the service, prevent abusive use and diagnose technical incidents.
- Legal basis: the Controller's legitimate interest in the security of its systems and in the proper provision of the service (art. 6.1.f GDPR and recital 49).
- Processing: these logs are generated and retained by the hosting provider, as processor, for short periods; they are not used to identify visitors, are not cross-referenced with other information and are not used for analytics, profiling or advertising purposes.
4. Origin of the data
The personal data processed come from the data subject themselves or, where applicable, from the company or organisation they represent. The website does not obtain data from publicly accessible sources or from third parties, or through automated tracking or identification techniques.
5. Mandatory nature of the data
The data the user provides in their communications are the minimum essential to be able to assist them. If the necessary contact details are not provided, it will not be possible to respond to the enquiry or, where applicable, to formalise the contractual relationship.
6. Recipients of the data
Personal data are not disclosed to third parties, except where legally required.
In addition to the above, the following providers, with whom the contracts required by article 28 of the GDPR have been concluded, may access the data, acting as processors and only to the extent necessary to provide their services:
- Website hosting: DigitalOcean, LLC, with this site's infrastructure deployed in data centres located in the European Union.
- Email and office tools: Google Workspace, a service provided to customers in the European Economic Area by Google Ireland Limited (Ireland).
- Tax, accounting and employment advisers.
- Financial institutions, for the management of collections and payments.
Likewise, data may be communicated to public administrations, law enforcement authorities, and courts and tribunals where there is a legal obligation to do so.
7. International data transfers
As a general rule, the data are hosted and processed in data centres located in the European Union.
However, the technology providers indicated in the previous section belong to corporate groups whose parent companies are based in the United States and may engage sub-processors which, occasionally and for support, maintenance or security functions, access the data from third countries. Any such transfers are covered by the mechanisms provided for in Chapter V of the GDPR:
- DigitalOcean, LLC is certified under the EU-U.S. Data Privacy Framework, which is covered by an adequacy decision of the European Commission, and incorporates in its data processing agreement the standard contractual clauses approved by the Commission as the applicable mechanism should that framework cease to be in force.
- Google Ireland Limited, as a provider established in the European Union, incorporates in its data processing agreement the standard contractual clauses approved by the European Commission for any transfers it may make to group entities located outside the European Economic Area, whose US parent company is in turn certified under the EU-U.S. Data Privacy Framework.
In all cases, the supplementary technical and organisational measures that may be necessary are also applied. The data subject may request information about these safeguards, or a copy of them, by writing to [email protected].
8. Automated decision-making and profiling
No automated decisions are taken that produce legal effects concerning the data subject or similarly significantly affect them, and no commercial or behavioural profiles are created from browsing activity.
9. Security measures
The Controller has adopted appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with article 32 of the GDPR, taking into account the state of the art, the nature of the data processed and the volume and scope of the processing. These include: encryption of the website's communications via HTTPS, control of access to information, backups and the selection of providers offering sufficient guarantees.
The Controller undertakes to process the data confidentially and to require the same obligation of the persons who, under its authority, may access them.
10. Rights of data subjects
Anyone has the right to obtain confirmation as to whether personal data concerning them are being processed. In particular, the following rights may be exercised:
- Access: to know what data are being processed and to obtain a copy of them.
- Rectification: to request the correction of inaccurate or incomplete data.
- Erasure: to request the deletion of the data where, among other grounds, they are no longer necessary for the purposes for which they were collected.
- Objection: to object to processing based on legitimate interest and, in any event, to processing for direct marketing purposes.
- Restriction of processing: to request that the data be retained solely for the exercise or defence of claims.
- Portability: to receive the data in a structured, commonly used and machine-readable format, or to request their transmission to another controller, where the processing is based on consent or on a contract and is carried out by automated means.
- To withdraw consent given, where applicable, at any time, without this affecting the lawfulness of the processing carried out before its withdrawal.
How to exercise them. By request addressed to [email protected] or in writing to Carrer Conradors, 29, 07141 Marratxí (Illes Balears), stating the right you wish to exercise. The request is free of charge and will be answered within one month of receipt, extendable by a further two months where the complexity or the number of requests so justifies.
Only where there are reasonable doubts about the identity of the person making the request may additional information be requested in order to verify it, in accordance with article 12.6 of the GDPR; it is not necessary to provide a copy of an identity document as a matter of course.
Complaint to the supervisory authority. If you consider that your rights have not been duly respected, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) (C/ Jorge Juan, 6, 28001 Madrid — www.aepd.es), without prejudice to contacting the Controller first.
11. Accuracy and updating of the data
The user warrants that the data they provide are true, accurate and up to date, and undertakes to notify any change to them. The user shall be liable for any false or inaccurate information they provide and for any harm this may cause to the Controller or to third parties.
12. Third-party data
Where the user provides personal data of third parties (for example, of work colleagues, or of the organisers or suppliers of an event), they must have previously informed those persons of the content of this policy and have the necessary legal basis to communicate the data, and the Controller shall bear no liability for any breach of this duty.
13. Minors
The website is not aimed at children under fourteen and does not knowingly collect their data. If it were detected that data of a minor had been received without the consent of the holders of parental authority or guardianship, the data would be erased.
14. Changes to this policy
This policy may be amended to adapt it to changes in legislation or case law or in the Controller's activity. Amendments will be published on this same page, indicating the date of the last update.
Last updated: 15 August 2026 · This is a translation of the Spanish original, which is the legally binding version.
