Privacy Policy
Effective date: 2024-01-01
Overview
This Privacy Policy explains how Auto Repair Shop in Spain collects, uses, shares, and protects personal data in connection with our website and automotive services. We follow the EU General Data Protection Regulation (GDPR) and applicable Spanish data protection requirements. If you do not agree with this policy, please do not use our website or submit your data.
- We only process data for clear purposes (bookings, quotes, customer support, and legal compliance).
- We keep data for as long as needed (and as required by Spanish law).
- You can exercise GDPR rights by contacting [email protected].
1. Data Controller
Auto Repair Shop in Spain, Calle de Alcalá 123, 28009 Madrid, Spain. Email: [email protected].
If you contact us about privacy matters, we may ask for enough information to verify your identity and handle the request securely.
2. Data We Process
The categories of personal data we may process depend on how you interact with us:
- Contact details (name, email, phone) for communication, appointments, and booking confirmations.
- Vehicle and service details you provide (make/model, mileage, symptoms, requested services) to prepare quotes and perform repairs.
- Service history associated with your booking to support after-service care and warranty handling, where applicable.
- Minimal local storage data for strictly necessary site features such as favorites, cart, and accessibility preferences.
- Technical data (approximate device and usage information) when required for security, fraud prevention, and reliability.
We do not intentionally collect special categories of data (e.g., health data) and ask you not to provide sensitive information through our forms.
3. Purposes and Legal Basis
We process personal data only when a GDPR legal basis applies. Depending on the context, our processing may rely on:
Contract (Art. 6(1)(b))
To provide our services, handle bookings, deliver quotes, and communicate about your vehicle and repair status.
Legal obligation (Art. 6(1)(c))
To comply with Spanish accounting, tax, consumer, and other applicable requirements.
Legitimate interests (Art. 6(1)(f))
To maintain site security, prevent fraud, improve service quality, and respond to support requests, while balancing your rights.
Consent (Art. 6(1)(a))
For optional communications or non-essential preferences where consent is required. You may withdraw consent at any time.
4. Retention
We retain personal data only for as long as necessary to provide our services and meet legal requirements in Spain. Retention periods may vary depending on the type of record (e.g., booking communications vs. legally required business documents).
- Booking and support data is retained for operational needs and dispute handling.
- Business and financial records are retained as required by applicable Spanish laws.
- Local storage preferences can be removed anytime via your browser settings or our cookie controls.
5. Your Rights (GDPR)
Subject to legal limits and applicable conditions, you may exercise the following rights:
- Access to your personal data and related information.
- Rectification of inaccurate or incomplete data.
- Erasure (“right to be forgotten”) where applicable.
- Restriction of processing under certain circumstances.
- Portability for data you provided to us when processing is based on consent or contract.
- Objection to processing based on legitimate interests and to direct marketing.
- Withdraw consent at any time where processing is based on consent.
To exercise your rights, contact [email protected]. You may also have the right to lodge a complaint with the relevant supervisory authority in Spain.
6. Cookies & Local Storage
We use browser storage (including localStorage) for strictly necessary features, such as favorites, cart, and accessibility preferences. Where applicable, we request consent for non-essential storage and you can manage your choice at any time.
Your controls
- Open cookie settings and change your choice.
- Clear stored preferences using your browser controls.
- Enable high-contrast mode if needed.
7. Sharing & International Transfers
We may share personal data with service providers that support our operations (for example, hosting, email delivery, security). Such providers are authorized to process data only as needed to provide services to us and are bound by appropriate safeguards.
If data is transferred outside the European Economic Area, we apply GDPR-recognized safeguards (such as Standard Contractual Clauses) where required.
8. Security
We implement technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Children’s Privacy
Our services are not directed to children. If you believe a minor has provided personal data, contact us and we will take appropriate steps to delete it where applicable.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The effective date above indicates the latest revision.
11. Contact
Questions? Email [email protected] or call +34 910 123 456.
Response time
We aim to respond to privacy requests within a reasonable timeframe and in line with GDPR timelines. If we need more information to process your request, we will let you know.