Skip to main content
Neboda Farms

Privacy Policy

Last updated: January 2025

1. Overview & Scope

This privacy policy informs you about the nature, scope, and purpose of the processing of personal data within our online offering and the associated websites, functions, and content (hereinafter collectively referred to as "online offering" or "website"). This privacy policy applies regardless of the domains, systems, platforms, and devices (e.g., desktop or mobile) on which the online offering is accessed. The terms used, such as "personal data" or "processing," refer to the definitions in Art. 4 of the General Data Protection Regulation (GDPR).

2. Data Controller (Responsable del Tratamiento)

The data controller responsible for data processing on this website within the meaning of Art. 4 (7) GDPR is:

  • Néboda Farms, S.L.
  • Estrada Fragosiño, 32, Nave 2, Sárdoma
  • 36214 Vigo, Pontevedra, Spain
  • Email: info@neboda-farm.com
  • Phone: +34 615 461 403

3. Types of Data Processed

We process the following categories of personal data:

  • Contact data: Name, email address, phone number (when you contact us)
  • Content data: Text inputs, messages, inquiries
  • Usage data: Pages visited, access times, referring URLs
  • Meta/communication data: Device information, IP addresses (anonymized where possible)
  • Contract data: Subject of contract, term, customer category (for business inquiries)

4. Legal Bases for Processing (Art. 6 GDPR)

We process personal data only when there is a legal basis to do so:

  • Consent (Art. 6(1)(a) GDPR): You have given consent for a specific purpose (e.g., newsletter, analytics cookies)
  • Contract Performance (Art. 6(1)(b) GDPR): Processing is necessary for contract performance or pre-contractual measures (e.g., responding to inquiries, booking appointments)
  • Legal Obligation (Art. 6(1)(c) GDPR): Processing is necessary to comply with legal requirements (e.g., tax retention obligations)
  • Legitimate Interests (Art. 6(1)(f) GDPR): Processing is necessary for our legitimate interests (e.g., website security, fraud prevention, improvement of services), provided your interests do not override

5. Your Rights as a Data Subject

Under the GDPR, you have the following rights regarding your personal data:

  • Right to Access (Art. 15 GDPR): Obtain confirmation and a copy of your personal data
  • Right to Rectification (Art. 16 GDPR): Correct inaccurate personal data
  • Right to Erasure (Art. 17 GDPR): Request deletion of your data ("right to be forgotten")
  • Right to Restriction (Art. 18 GDPR): Restrict processing under certain conditions
  • Right to Data Portability (Art. 20 GDPR): Receive your data in a structured, machine-readable format
  • Right to Object (Art. 21 GDPR): Object to processing based on legitimate interests
  • Right to Withdraw Consent (Art. 7(3) GDPR): Withdraw consent at any time with future effect

To exercise these rights, please contact us at: info@neboda-farm.com

6. Right to Object (Art. 21 GDPR) — Special Notice

If we process your personal data based on legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to such processing at any time for reasons relating to your particular situation. If you object to processing for direct marketing purposes, we will stop processing your data for such purposes immediately. No specific reason is required for this objection. To object, simply contact us at: info@neboda-farm.com

7. Supervisory Authority & Right to Complain

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state of your habitual residence, your place of work, or the place of the alleged infringement. Competent Authority for Spain:

  • Agencia Española de Protección de Datos (AEPD)
  • C/ Jorge Juan, 6
  • 28001 Madrid, Spain
  • Phone: +34 901 100 099
  • Website: www.aepd.es

8. Security Measures (Art. 32 GDPR)

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • TLS/SSL encryption (HTTPS) for all data transmissions
  • Regular security updates and vulnerability assessments
  • Access controls to limit data access to authorized personnel only
  • Use of reputable, security-certified hosting providers
  • Pseudonymization and data minimization where possible

9. Server Log Files (Hosting)

The hosting provider of this website automatically collects and stores information in server log files that your browser transmits. This includes:

  • Browser type and version
  • Operating system
  • Referrer URL (previously visited page)
  • Hostname of the accessing device
  • Time of server request
  • IP address (anonymized or truncated where technically possible)

Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in secure and efficient website operation) Storage Duration: Log files are typically retained for 7-30 days for security purposes, then automatically deleted. This data is not merged with other data sources and cannot be attributed to specific persons.

10. Cookies, Local Storage & Consent Management

This website uses cookies and similar technologies. Cookies are small text files stored on your device that help analyze website usage.

Consent Management

  • Consent Tool: Custom Cookie Consent Banner
  • Function: The banner appears on first visit and allows selection between accepting and declining analytics cookies
  • Consent Storage: Consent is stored in the browser's Local Storage
  • Storage Duration: Consent is stored permanently until you revoke it via the 'Cookie Settings' link in the footer
  • Changes: You can change your cookie settings at any time via the 'Cookie Settings' link in the footer of this website

Essential Cookies (Strictly Necessary)

Required for basic website functionality. These cannot be disabled. Legal Basis: Art. 6(1)(f) GDPR. Examples: Session management, cookie consent preferences, security tokens.

Analytics Cookies (Optional)

Help us understand how visitors use the website. Only set after your consent. Legal Basis: Art. 6(1)(a) GDPR.

11. Contact Form & Email Communication

When you contact us via email or contact form, the data you provide (email address, name, message content, and any other information you include) will be stored to process your inquiry and handle follow-up questions.

  • Legal Basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries)
  • Storage Duration: Data is deleted once the inquiry is fully processed, unless legal retention obligations apply (typically up to 6-10 years for business correspondence under Spanish commercial law)
  • Email is a required field. Without this information, we cannot process your inquiry as we would be unable to contact you.

12. Newsletter

If you subscribe to our newsletter, we collect your email address and, optionally, your name. We use the double opt-in procedure: after registration, you receive a confirmation email asking you to verify your subscription.

  • Legal Basis: Art. 6(1)(a) GDPR (consent)
  • Purpose: Sending newsletters, updates, and promotional content
  • Service Provider: Brevo (Sendinblue SAS), France — see External Services section
  • Withdrawal: You can unsubscribe at any time via the link in each newsletter or by contacting us
  • Logging: We log subscription and confirmation to prove consent as required by law

13. Appointment Booking (Zoom)

Appointment scheduling runs directly on our own website. When you book a meeting, you provide your name, email, company and any additional information you choose to share. A Zoom video meeting is then created automatically and the access link is sent to you by email.

  • Legal Basis: Art. 6(1)(b) GDPR (pre-contractual measures / contract performance)
  • Data Processed: Name, email, appointment details, optional message
  • Storage Duration: Until the purpose is fulfilled, subject to legal retention periods
  • Third Country Transfer: USA — SCCs + EU-U.S. Data Privacy Framework (DPF)

Alternative Appointment Booking: If you prefer not to use our online booking or Zoom, you can also contact us directly by email at info@neboda-farm.com to schedule an appointment.

14. Automated Decision-Making & Profiling

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.

15. Data Retention Periods

We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law:

  • Contact inquiries: Duration of business relationship + statutory retention (typically 6-10 years under Spanish commercial/tax law)
  • Newsletter data: Until consent is withdrawn
  • Server logs: 7-30 days
  • Analytics data: As configured in respective service (typically 14-26 months)
  • Contract-related data: 10 years (Spanish Commercial Code / Tax regulations)

16. Recipients of Personal Data

Your personal data may be disclosed to the following categories of recipients:

  • Hosting & Infrastructure Providers: For website operation and data storage
  • Email/Communication Providers: For processing contact requests and newsletters
  • Analytics Providers: For website usage analysis (only with consent)
  • Scheduling Providers: For appointment booking
  • Tax Advisors / Auditors: Where legally required
  • Authorities: If legally obligated to disclose

We have concluded Data Processing Agreements (Art. 28 GDPR) with all processors who handle personal data on our behalf.

17. External Services & Servers

This website uses external services to provide its functionality. Below is a comprehensive list of all third-party services, their purposes, data processed, and links to their privacy policies.

Hosting & Infrastructure

Lovable / Cloudflare

Provider: Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA

Purpose: Website hosting, content delivery (CDN), DDoS protection, SSL/TLS encryption

Data: IP addresses, HTTP request data, performance metrics

Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in secure, fast website delivery)

Transfer: EU-U.S. Data Privacy Framework certified

Supabase Inc.

Provider: Supabase Inc., 101 Jefferson Dr, Menlo Park, CA 94025, USA

Purpose: Database, authentication, serverless functions, backend services

Data: User accounts (if applicable), application data

Legal Basis: Art. 6(1)(b), (f) GDPR

Transfer: SCCs in place; data stored in EU region (Frankfurt)

Communication & Marketing

Brevo (formerly Sendinblue)

Provider: Sendinblue SAS, 55 rue d'Amsterdam, 75008 Paris, France

Purpose: Newsletter delivery, email marketing, transactional emails

Data: Email address, name, subscription status, email engagement metrics

Legal Basis: Art. 6(1)(a) GDPR (consent)

Transfer: EU (France, Germany) — no third-country transfer

Zoom Communications, Inc.

Provider: Zoom Communications, Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA

Purpose: Video meetings created for booked appointments

Data: Name, email, appointment details, timezone

Legal Basis: Art. 6(1)(b) GDPR (contract performance / pre-contractual steps)

Transfer: SCCs and EU-U.S. DPF in place

Content Delivery & Media

Google Fonts

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

Purpose: Web typography (font delivery)

Data: IP address, browser/device information during font request

Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in consistent typography)

Transfer: EU-U.S. Data Privacy Framework (DPF)

Maps & Location

Google Maps

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

Purpose: Interactive office location map

Data: IP address, location data, device info

Legal Basis: Art. 6(1)(a) GDPR (consent) — map loads only after user interaction

Transfer: EU-U.S. Data Privacy Framework (DPF)

18. Data Transfer to Third Countries

Some services are provided by companies based in the USA. Data transfers to the USA are conducted on the basis of:

  • EU-U.S. Data Privacy Framework (adequacy decision) where the provider is certified
  • Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR
  • Supplementary measures where required (e.g., encryption, access controls)

You can request copies of the applicable safeguards by contacting us at info@neboda-farm.com.

19. Children's Privacy

This website is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided personal data to us, please contact us immediately so we can delete such information.

20. Social Media Presence

We maintain presences on social media platforms (e.g., LinkedIn). When you visit our social media pages, the respective platform operator may collect data. We have no control over this data collection. For information about data processing by these platforms, please refer to their privacy policies. Note: This website does not include social media plugins that automatically transfer data. Links to social media open in a new tab without prior data transmission.

21. Changes to This Privacy Policy

We reserve the right to update this privacy policy to reflect changes in our practices or legal requirements. The current version is always available on this page. We recommend reviewing this policy periodically. Significant changes will be communicated through a notice on our website.

22. Source of Data (Art. 14 GDPR)

Where we do not collect personal data directly from you: We do not receive personal data from third parties. All personal data processed on this website is collected directly from the data subjects (you) — e.g., via contact forms, newsletter registrations, or appointment bookings.