ES / EN
Legal

Privacy policy

Privacy policy of MDC21 Agency S.L. under GDPR and Spanish data protection law: what we process, on what legal basis, retention periods and your rights.

Last updated: May 13, 2026

1. Data controller

  • Controller: MDC21 Agency S.L.
  • Tax ID (NIF): B70918503
  • Registered address: C/ Mar Denoruega 2, 04770 Adra (Almería), España
  • Email: contact@mdc21.agency

MDC21 Agency S.L. is not required by its size to appoint a Data Protection Officer (DPO). Privacy enquiries are handled at the email above.

2. Data we process and purposes

2.1 Contact form

When you fill in the form at /contact we collect:

  • Name
  • Email
  • Company (optional)
  • Phone and international prefix (optional)
  • Project type (optional)
  • Free-text message
  • Request language, IP address and user agent (anti-spam)

Purpose: reply to your request, assess fit, and start a commercial conversation if applicable.

Legal basis: data subject consent (Art. 6.1.a GDPR) and pre-contractual measures at the data subject's request (Art. 6.1.b GDPR).

Retention: for the duration of the commercial relationship and 6 years afterwards to address potential legal liability (Spanish Commercial Code, Art. 30).

2.2 Navigation data

The site uses Plausible Analytics (EU-hosted, cookieless). Plausible processes aggregated navigation data (URL, country, device) without identifying the visitor.

3. Data recipients

Your data is not transferred to third parties except where legally required. We use the following processors, all under signed data-processing agreements:

  • Amazon Web Services EMEA SARL (servidores en la UE — Irlanda / Frankfurt): website and database hosting.
  • Resend, Inc. (US, EU Standard Contractual Clauses): notification emails for each lead.
  • Plausible Insights OÜ (Estonia, EU): cookieless usage analytics.

We carry out no international data transfers outside the EEA beyond those covered by EU-approved Standard Contractual Clauses.

4. Your rights

You may exercise the following rights at any time by emailing contact@mdc21.agency indicating the right exercised and attaching a copy of your ID:

  • Access: know what data of yours we process.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure (right to be forgotten).
  • Restriction of processing.
  • Portability.
  • Object for reasons related to your particular situation.
  • Withdraw consent at any time.

If you believe the processing does not comply with applicable law, you may lodge a complaint with the Spanish Data Protection Agency (AEPD).

5. Security

We apply appropriate technical and organisational measures: encryption in transit (HTTPS / TLS 1.3), database encryption at rest, per-user access control to the admin panel (authentication + panel access secret), daily backups and a documented incident-response process.