Privacy policy
What personal data Ajuridic processes when someone writes to the firm, what it uses it for, how long it keeps it and how to exercise the rights conferred by Regulation (EU) 2016/679.
Last updated: 6 August 2026.
The essentials, in four lines
Ajuridic processes only the data the person themselves provides so that they can be replied to. It is not sold or passed to third parties for commercial purposes, it is not used for advertising and there is no profiling and no automated decision-making. Everything communicated to the firm is also covered by legal professional privilege.
1. Data controller
- Controller Noemí Ampurdanés Parés (Ajuridic)
- NIF 46128288V
-
Address
Carrer del Freser, 104
El Clot (Sant Martí)
08026 Barcelona, Spain - Telephone 614 26 26 92
- Email [email protected]
The firm is not required to appoint a data protection officer, so enquiries on this subject are dealt with at the addresses above.
2. What data is processed and where it comes from
All the data comes from the person concerned. This site does not buy databases, does not track browsing and does not obtain information from third parties.
The website's contact form
- First name and surname.
- Email address.
- Telephone number, if provided.
- The free text of the message: the description of the matter the person chooses to write.
- The record of acceptance of this policy and the date on which it was sent.
When someone writes to [email protected] we process the email address, the name shown as sender, the content of the message and any documents attached.
Telephone and WhatsApp
When you call or write to 614 26 26 92 we process the telephone number and the information the person provides during the conversation. Calls are not recorded. In the case of WhatsApp, the message is transmitted by that application's provider under its own terms, which have nothing to do with the firm; anyone who prefers not to use it can write by email or telephone.
Requesting an appointment from the website
Anyone using the calendar at /cita/ provides their first name and surname, an email address, a telephone number if they wish, the area the enquiry relates to, the day and time they propose and, if they write one, a short note. Also saved are the record of acceptance of this policy, the date it was sent and, for a few hours, a fingerprint of the IP address, for the sole purpose of preventing anyone from flooding the calendar with false requests.
What is sent that way is a proposed day and time, not a booking: the time is not set aside until the firm replies accepting it or proposing another. Requests that nobody answers expire by themselves and their record is deleted.
Take care over what you send in a first contact
For a first consultation it is enough to explain the matter in general terms. It is best not to attach sensitive documents (medical reports, court decisions, third parties' data) until there is an instruction and a secure channel has been agreed for sending them.
Special category data
Some matters (medical negligence, accidents involving injuries, immigration, family) involve health data or other specially protected data under article 9 of the GDPR. Where the person provides it voluntarily so that their case can be assessed, it is processed under article 9(2)(f) of the GDPR: it is necessary for the establishment, exercise or defence of legal claims. It is handled with the discretion that legal professional privilege requires.
3. What it is used for
- Dealing with the enquiry and replying through the same channel it came in on, or through whichever the person indicates.
- Assessing whether the firm can take the matter on and explaining which route is appropriate and within what time limits.
- Providing the professional services instructed, if the enquiry leads to an instruction, including steps before courts, tribunals and public authorities.
- Complying with the firm's legal obligations : accounting, tax, professional conduct and those arising from anti-money-laundering rules where applicable.
- Preventing abuse of the form by means of a honeypot anti-spam field, which collects no personal data at all.
- Arranging the appointment proposed from /cita/: reviewing it, accepting the time or proposing another, and notifying the outcome by email.
No newsletters or marketing communications are sent. No profiles are built and no automated decisions with legal effects are taken.
4. Legal basis for processing
| Processing | Legal basis (GDPR) |
|---|---|
| Replying to an enquiry sent by form, email or telephone | The person's consent, art. 6(1)(a), and pre-contractual steps at their request, art. 6(1)(b) |
| Providing the legal services instructed | Performance of the contract for services, art. 6(1)(b) |
| Health data or other specially protected data provided by the person | Establishment, exercise or defence of legal claims, art. 9(2)(f) |
| Keeping invoices and case file documents | Compliance with a legal obligation, art. 6(1)(c) |
| Security of the form against automated submissions | Legitimate interest of the controller, art. 6(1)(f) |
Providing the data is voluntary, but without it no reply is possible: a form with no name and no means of contact does not allow any answer to be given.
5. How long it is kept
- Appointment requests: one that expires without a reply or is declined is deleted straight away; one that leads to an appointment follows the period for enquiries.
- Enquiries that do not lead to an instruction: they are kept for as long as is needed to reply and, afterwards, for a reasonable period in case the person returns to the matter. Once that period has passed they are deleted.
- Client files: for the duration of the professional relationship and, once it has ended, for the limitation periods of any claims that might arise from the instruction and from professional liability.
- Accounting and tax documents: for the periods imposed by commercial and tax legislation.
While they must be kept by legal obligation, the data is blocked: it is made available only to judges, courts, the public prosecutor or the competent authorities.
6. Who it is disclosed to
The data is not sold, rented or transferred for commercial purposes. It is disclosed only where the matter itself requires it or where a rule imposes it:
- Courts, tribunals, the public prosecutor and public authorities, where the matter we are instructed on requires it.
- Court agents, notaries, experts and specialist solicitors from the firm's network of associates, only to the extent that their involvement is necessary for the matter and subject to their own duty of confidentiality.
- Insurance companies and their legal departments, in the claims they are involved in.
- The Ilustre Colegio de la Abogacía de Barcelona, where Bar rules require it.
- The tax authorities and banks, in order to comply with tax obligations and to manage payments.
- Technology providers serving the firm (web hosting, email), which act as processors under a contract complying with article 28 of the GDPR and do not use the data for their own purposes.
- Cloudflare, which provides the anti-bot verification system for the contact form. It acts as a processor and, in order to check that the sender is a person and not an automated program, processes the IP address and technical data about the connection. It does not access the content of the enquiry.
International transfers. Cloudflare's anti-bot system may process the IP address and that technical data outside the European Economic Area. That transfer relies on the safeguards in Chapter V of the GDPR. The firm's other providers, hosting and email, process the data within the European Economic Area.
7. Legal professional privilege
Quite apart from data protection rules, all the information a client or a potential client communicates to the firm is protected by legal professional privilege, a duty imposed by the Estatuto General de la Abogacía Española (the Spanish Bar's General Statute) and the Code of Conduct, which does not fall away even if the enquiry never becomes an instruction, or when the professional relationship ends.
That obligation goes beyond the GDPR: it covers facts, documents and conversations, and breaching it is a disciplinary offence.
8. The rights of the person concerned
Anyone may exercise the following rights, free of charge:
- Access: to know what data about them is being processed.
- Rectification: to correct data that is inaccurate or incomplete.
- Erasure: to ask for data to be deleted when it is no longer needed.
- Restriction: to ask for data to be kept but not used, while a challenge is being resolved.
- Objection: to object to processing based on legitimate interest.
- Portability: to receive the data in a structured, commonly used format.
- To withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.
To exercise them, simply write to [email protected] or to Carrer del Freser, 104, 08026 Barcelona, stating which right is being exercised and enclosing a copy of a document proving identity. A reply is given within one month, extendable to two if the request is complex.
These rights have one limit: they do not allow the deletion of documents the firm must keep by legal obligation or for the defence of claims. In those cases the reason will be explained in writing.
9. Complaint to the supervisory authority
If someone considers that their request has not been dealt with properly, they may lodge a complaint with the Agencia Española de Protección de Datos (the Spanish data protection authority) (C/ Jorge Juan, 6, 28001 Madrid — www.aepd.es). They can also come to the firm first: almost everything is resolved with an explanation.
10. Data security
The firm applies technical and organisational measures proportionate to the risk: an encrypted HTTPS connection across the whole site, access control over case files, backups and the duty of confidentiality of those who work with the firm. No measure removes the risk entirely, but they are reviewed periodically.
11. Minors
This site is not aimed at children under fourteen and does not deliberately collect their data. Where a matter concerns a minor, which is common in family law, the data is provided by the person with legal responsibility for them.
12. Changes to this policy
This policy may be updated if the firm's services or the rules change. The version in force is always the one published on this page, with the date shown at the top. You can also consult the legal notice and the cookie policy.
Tell us about the case and we will weigh up the next step together
For a first contact it is enough to explain the matter in broad terms. There will be time to gather the documents later.