Privacy Policy
Last updated: January 2025
1. Overview & Scope
This privacy policy informs you about the nature, scope, and purpose of the processing of personal data within our online offering and the associated websites, functions, and content (hereinafter collectively referred to as "online offering" or "website"). This privacy policy applies regardless of the domains, systems, platforms, and devices (e.g., desktop or mobile) on which the online offering is accessed. The terms used, such as "personal data" or "processing," refer to the definitions in Art. 4 of the General Data Protection Regulation (GDPR).
2. Data Controller (Responsable del Tratamiento)
The data controller responsible for data processing on this website within the meaning of Art. 4 (7) GDPR is:
- Néboda Farms, S.L.
- Estrada Fragosiño, 32, Nave 2, Sárdoma
- 36214 Vigo, Pontevedra, Spain
- Email: info@neboda-farm.com
- Phone: +34 615 461 403
3. Types of Data Processed
We process the following categories of personal data:
- Contact data: Name, email address, phone number (when you contact us)
- Content data: Text inputs, messages, inquiries
- Usage data: Pages visited, access times, referring URLs
- Meta/communication data: Device information, IP addresses (anonymized where possible)
- Contract data: Subject of contract, term, customer category (for business inquiries)
4. Legal Bases for Processing (Art. 6 GDPR)
We process personal data only when there is a legal basis to do so:
- Consent (Art. 6(1)(a) GDPR): You have given consent for a specific purpose (e.g., newsletter, analytics cookies)
- Contract Performance (Art. 6(1)(b) GDPR): Processing is necessary for contract performance or pre-contractual measures (e.g., responding to inquiries, booking appointments)
- Legal Obligation (Art. 6(1)(c) GDPR): Processing is necessary to comply with legal requirements (e.g., tax retention obligations)
- Legitimate Interests (Art. 6(1)(f) GDPR): Processing is necessary for our legitimate interests (e.g., website security, fraud prevention, improvement of services), provided your interests do not override
5. Your Rights as a Data Subject
Under the GDPR, you have the following rights regarding your personal data:
- Right to Access (Art. 15 GDPR): Obtain confirmation and a copy of your personal data
- Right to Rectification (Art. 16 GDPR): Correct inaccurate personal data
- Right to Erasure (Art. 17 GDPR): Request deletion of your data ("right to be forgotten")
- Right to Restriction (Art. 18 GDPR): Restrict processing under certain conditions
- Right to Data Portability (Art. 20 GDPR): Receive your data in a structured, machine-readable format
- Right to Object (Art. 21 GDPR): Object to processing based on legitimate interests
- Right to Withdraw Consent (Art. 7(3) GDPR): Withdraw consent at any time with future effect
To exercise these rights, please contact us at: info@neboda-farm.com
6. Right to Object (Art. 21 GDPR) — Special Notice
If we process your personal data based on legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to such processing at any time for reasons relating to your particular situation. If you object to processing for direct marketing purposes, we will stop processing your data for such purposes immediately. No specific reason is required for this objection. To object, simply contact us at: info@neboda-farm.com
7. Supervisory Authority & Right to Complain
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state of your habitual residence, your place of work, or the place of the alleged infringement. Competent Authority for Spain:
- Agencia Española de Protección de Datos (AEPD)
- C/ Jorge Juan, 6
- 28001 Madrid, Spain
- Phone: +34 901 100 099
- Website: www.aepd.es
8. Security Measures (Art. 32 GDPR)
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- TLS/SSL encryption (HTTPS) for all data transmissions
- Regular security updates and vulnerability assessments
- Access controls to limit data access to authorized personnel only
- Use of reputable, security-certified hosting providers
- Pseudonymization and data minimization where possible
9. Server Log Files (Hosting)
The hosting provider of this website automatically collects and stores information in server log files that your browser transmits. This includes:
- Browser type and version
- Operating system
- Referrer URL (previously visited page)
- Hostname of the accessing device
- Time of server request
- IP address (anonymized or truncated where technically possible)
Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in secure and efficient website operation) Storage Duration: Log files are typically retained for 7-30 days for security purposes, then automatically deleted. This data is not merged with other data sources and cannot be attributed to specific persons.
10. Cookies, Local Storage & Consent Management
This website uses cookies and similar technologies. Cookies are small text files stored on your device that help analyze website usage.
Consent Management
- Consent Tool: Custom Cookie Consent Banner
- Function: The banner appears on first visit and allows selection between accepting and declining analytics cookies
- Consent Storage: Consent is stored in the browser's Local Storage
- Storage Duration: Consent is stored permanently until you revoke it via the 'Cookie Settings' link in the footer
- Changes: You can change your cookie settings at any time via the 'Cookie Settings' link in the footer of this website
Essential Cookies (Strictly Necessary)
Required for basic website functionality. These cannot be disabled. Legal Basis: Art. 6(1)(f) GDPR. Examples: Session management, cookie consent preferences, security tokens.
Analytics Cookies (Optional)
Help us understand how visitors use the website. Only set after your consent. Legal Basis: Art. 6(1)(a) GDPR.
11. Contact Form & Email Communication
When you contact us via email or contact form, the data you provide (email address, name, message content, and any other information you include) will be stored to process your inquiry and handle follow-up questions.
- Legal Basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries)
- Storage Duration: Data is deleted once the inquiry is fully processed, unless legal retention obligations apply (typically up to 6-10 years for business correspondence under Spanish commercial law)
- Email is a required field. Without this information, we cannot process your inquiry as we would be unable to contact you.
12. Newsletter
If you subscribe to our newsletter, we collect your email address and, optionally, your name. We use the double opt-in procedure: after registration, you receive a confirmation email asking you to verify your subscription.
- Legal Basis: Art. 6(1)(a) GDPR (consent)
- Purpose: Sending newsletters, updates, and promotional content
- Service Provider: Brevo (Sendinblue SAS), France — see External Services section
- Withdrawal: You can unsubscribe at any time via the link in each newsletter or by contacting us
- Logging: We log subscription and confirmation to prove consent as required by law
13. Appointment Booking (Zoom)
Appointment scheduling runs directly on our own website. When you book a meeting, you provide your name, email, company and any additional information you choose to share. A Zoom video meeting is then created automatically and the access link is sent to you by email.
- Legal Basis: Art. 6(1)(b) GDPR (pre-contractual measures / contract performance)
- Data Processed: Name, email, appointment details, optional message
- Storage Duration: Until the purpose is fulfilled, subject to legal retention periods
- Third Country Transfer: USA — SCCs + EU-U.S. Data Privacy Framework (DPF)
Alternative Appointment Booking: If you prefer not to use our online booking or Zoom, you can also contact us directly by email at info@neboda-farm.com to schedule an appointment.
14. Automated Decision-Making & Profiling
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
15. Data Retention Periods
We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law:
- Contact inquiries: Duration of business relationship + statutory retention (typically 6-10 years under Spanish commercial/tax law)
- Newsletter data: Until consent is withdrawn
- Server logs: 7-30 days
- Analytics data: As configured in respective service (typically 14-26 months)
- Contract-related data: 10 years (Spanish Commercial Code / Tax regulations)
16. Recipients of Personal Data
Your personal data may be disclosed to the following categories of recipients:
- Hosting & Infrastructure Providers: For website operation and data storage
- Email/Communication Providers: For processing contact requests and newsletters
- Analytics Providers: For website usage analysis (only with consent)
- Scheduling Providers: For appointment booking
- Tax Advisors / Auditors: Where legally required
- Authorities: If legally obligated to disclose
We have concluded Data Processing Agreements (Art. 28 GDPR) with all processors who handle personal data on our behalf.
17. External Services & Servers
This website uses external services to provide its functionality. Below is a comprehensive list of all third-party services, their purposes, data processed, and links to their privacy policies.
Hosting & Infrastructure
Lovable / Cloudflare
Provider: Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA
Purpose: Website hosting, content delivery (CDN), DDoS protection, SSL/TLS encryption
Data: IP addresses, HTTP request data, performance metrics
Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in secure, fast website delivery)
Transfer: EU-U.S. Data Privacy Framework certified
Supabase Inc.
Provider: Supabase Inc., 101 Jefferson Dr, Menlo Park, CA 94025, USA
Purpose: Database, authentication, serverless functions, backend services
Data: User accounts (if applicable), application data
Legal Basis: Art. 6(1)(b), (f) GDPR
Transfer: SCCs in place; data stored in EU region (Frankfurt)
Communication & Marketing
Brevo (formerly Sendinblue)
Provider: Sendinblue SAS, 55 rue d'Amsterdam, 75008 Paris, France
Purpose: Newsletter delivery, email marketing, transactional emails
Data: Email address, name, subscription status, email engagement metrics
Legal Basis: Art. 6(1)(a) GDPR (consent)
Transfer: EU (France, Germany) — no third-country transfer
Zoom Communications, Inc.
Provider: Zoom Communications, Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA
Purpose: Video meetings created for booked appointments
Data: Name, email, appointment details, timezone
Legal Basis: Art. 6(1)(b) GDPR (contract performance / pre-contractual steps)
Transfer: SCCs and EU-U.S. DPF in place
Content Delivery & Media
Google Fonts
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: Web typography (font delivery)
Data: IP address, browser/device information during font request
Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in consistent typography)
Transfer: EU-U.S. Data Privacy Framework (DPF)
Maps & Location
Google Maps
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: Interactive office location map
Data: IP address, location data, device info
Legal Basis: Art. 6(1)(a) GDPR (consent) — map loads only after user interaction
Transfer: EU-U.S. Data Privacy Framework (DPF)
18. Data Transfer to Third Countries
Some services are provided by companies based in the USA. Data transfers to the USA are conducted on the basis of:
- EU-U.S. Data Privacy Framework (adequacy decision) where the provider is certified
- Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR
- Supplementary measures where required (e.g., encryption, access controls)
You can request copies of the applicable safeguards by contacting us at info@neboda-farm.com.
19. Children's Privacy
This website is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided personal data to us, please contact us immediately so we can delete such information.
20. Social Media Presence
We maintain presences on social media platforms (e.g., LinkedIn). When you visit our social media pages, the respective platform operator may collect data. We have no control over this data collection. For information about data processing by these platforms, please refer to their privacy policies. Note: This website does not include social media plugins that automatically transfer data. Links to social media open in a new tab without prior data transmission.
21. Changes to This Privacy Policy
We reserve the right to update this privacy policy to reflect changes in our practices or legal requirements. The current version is always available on this page. We recommend reviewing this policy periodically. Significant changes will be communicated through a notice on our website.
22. Source of Data (Art. 14 GDPR)
Where we do not collect personal data directly from you: We do not receive personal data from third parties. All personal data processed on this website is collected directly from the data subjects (you) — e.g., via contact forms, newsletter registrations, or appointment bookings.