Privacy Notice
Last updated: 17 September 2026
This privacy notice (the “Privacy Notice”) explains how personal data are processed in respect of users who access the website astrolegal.net (the “Website”) and clients who request the Services offered by AstroLegal, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”) and Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales (Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and the Guarantee of Digital Rights, the “LOPDGDD”). This Privacy Notice is separate from the Terms and Conditions of the Services, the Legal Notice and the cookie notice, to which reference is made for the matters they respectively govern (see Art. 16).
Art. 1. CONTROLLER
1.1 The controller of personal data is AstroLegal (the “Controller”), whose address is Avenida Touroperador Neckermann 3, 35100 Maspalomas, Las Palmas, Spain, and whose tax identification number is NIE Z1622112-L. The Controller may be contacted by email at info@astrolegal.net.
1.2 The Controller has not appointed a Data Protection Officer (DPO), as none of the circumstances that make a designation mandatory under Article 37 GDPR or Article 34 LOPDGDD applies. To exercise the rights described in this Privacy Notice, or for any enquiry relating to data protection, the data subject may contact the Controller using the contact details set out in Art. 1.1.
Art. 2. SCOPE
2.1 This Privacy Notice applies to the processing of personal data carried out through the forms on the Website, and to the processing carried out in the subsequent administrative management of the relationship with any User who requests the Services (Quote, payment and Engagement), as those terms are defined in the Terms and Conditions of the Services.
2.2 The general conditions for accessing and browsing the Website remain governed by the Legal Notice, and the use of cookies and similar technologies remains governed by a separate cookie notice, to which reference is made (see Art. 16).
Art. 3. DEFINITIONS
3.1 For the purposes of this Privacy Notice, “processing” means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, storage, retrieval, consultation, use, disclosure, restriction, erasure or destruction.
3.2 “Personal data” means any information relating to an identified or identifiable natural person.
Art. 4. PURPOSES OF AND LEGAL BASES FOR PROCESSING
4.1 Requests submitted through the Website forms. Data provided through the Prescreening, Pre-Registrability Study and Contact forms are processed in order to act on the data subject’s request, on the basis of Article 6(1)(b) GDPR (performance of a contract, or steps taken at the request of the data subject prior to entering into a contract) or, for requests not aimed at entering into an Engagement, on the basis of the Controller’s legitimate interest in responding to the communications it receives (Article 6(1)(f) GDPR). By ticking the “I have read the privacy notice” box on the forms, the data subject acknowledges having read this Privacy Notice; ticking the box does not constitute consent to processing, as consent is not required for the purposes described in this paragraph.
4.2 Newsletter. The email address provided through the dedicated sign-up form is processed, subject to the data subject’s specific and separate consent (ticking the “I agree to receive the newsletter” box), on the basis of Article 6(1)(a) GDPR, for the purpose of sending informational communications about AstroLegal and the Services. Consent may be withdrawn at any time, with effect for all processing carried out after the withdrawal.
4.3 Administrative management of the relationship. Where a request leads to a Quote and, if accepted, to payment and entry into the Engagement, the necessary data are processed on the basis of Article 6(1)(b) GDPR (performance of a contract) and, for the related tax and accounting obligations, on the basis of Article 6(1)(c) GDPR (compliance with a legal obligation).
4.4 Communications about similar services. Where the data subject is already a client of AstroLegal for a Service, AstroLegal may use the data subject’s email address to send commercial communications about its own Services that are similar to those the data subject has already used, pursuant to Article 21(2) of Ley 34/2002, de 11 de julio, de Servicios de la Sociedad de la Información y de Comercio Electrónico (Spanish Law 34/2002 of 11 July on Information Society Services and Electronic Commerce, the “LSSI”) and on the basis of the legitimate interest referred to in Article 6(1)(f) GDPR. The data subject may object to such processing at any time, free of charge and by simple means, both when the data are collected and in each communication sent to the data subject.
4.5 Compliance with legal obligations and protection of rights. Personal data may also be processed without the data subject’s consent where necessary to comply with obligations imposed by law, by regulation or by European Union legislation, or for the establishment, exercise or defence of legal claims (Article 6(1)(c) and (f) GDPR).
Art. 5. CATEGORIES OF PERSONAL DATA PROCESSED
5.1 The following data are collected through the Website forms: identification and contact data (first name, surname and email address); data relating to the trade mark and the business (trade mark status, trade mark name or number, goods or services, and the plan of interest); and the content of any messages freely entered in the Contact form.
5.2 The following data are also collected automatically, for security and anti-spam purposes: the Website language; the page from which the form was submitted; the date and time; referral campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content), where present; the external referring website (referrer); and the time taken to complete the form. The User’s IP address is not included in the communications received by the Controller and is processed solely by the hosting service provider, for the purposes set out in Art. 7.
5.3 Where a Quote is issued and an Engagement is entered into, the Client’s full identification and tax details, the data required to handle the matter before the European Union Intellectual Property Office (“EUIPO”), and data relating to payment of the fee are processed.
5.4 The Controller does not process, through the Website, any special categories of personal data within the meaning of Article 9 GDPR.
Art. 6. MINORS
6.1 The Services are intended for adults and businesses. Under Article 7 LOPDGDD, the processing of personal data of a minor under the age of 14 based on consent is lawful only if that consent is given by the holder of parental authority or guardianship.
Art. 7. RECIPIENTS OF PERSONAL DATA
7.1 In order to operate the Website and provide the Services, personal data may be disclosed, as processors within the meaning of Article 28 GDPR, to: Netlify, Inc., which hosts the Website and operates the form submission function; Resend, which sends automated notifications and confirmations; and Namecheap, Inc., which manages the info@astrolegal.net mailbox.
7.2 Once the Quote has been accepted and the Engagement entered into, the data required to handle the matter are disclosed to the Assigned Professional named in the Quote (see Art. 4.2 of the Terms and Conditions of the Services), who processes those data as a processor within the meaning of Article 28 GDPR, on the documented instructions of the Controller. The Assigned Professional is directly liable, as an independent controller, where the Assigned Professional processes the data for purposes or by means not conforming to the instructions received, pursuant to Article 28(10) GDPR. The foregoing is without prejudice to Article 82 GDPR on liability and the right to compensation.
7.3 Depending on the payment method chosen by the Client, the data needed to carry out the payment are processed by: PayPal (Europe) S.à r.l. et Cie, S.C.A., established in Luxembourg, as an independent controller for the payment services it provides; Stripe Payments Europe, Limited, established in Ireland, as controller or processor depending on the service used, in accordance with its own privacy notice; or the Client’s bank and AstroLegal’s bank, in the case of payment by bank transfer. Reference is made to the respective privacy notices, available on each provider’s website.
7.4 If enabled, and only after the User has given consent through the cookie banner in accordance with the cookie notice, browsing data may be disclosed to Google Ireland Limited for the purpose of measuring advertising conversions (Google Ads). As at the date of this Privacy Notice, this service is not active.
7.5 Personal data may also be disclosed to judicial or administrative authorities, where required by applicable law, in order to comply with the obligations referred to in Art. 4.5.
Art. 8. TRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES
8.1 The providers listed in Art. 7.1 are based in the United States of America. The transfer of data to those providers relies on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795), to which Netlify and Resend are shown as adherents, the latter also by means of standard contractual clauses as a further safeguard. For the provider of the email service, the location of the servers is still being verified by the Controller; in the absence of confirmation, any extra-EU transfer, should one exist, will in any event be supported by the safeguards provided for in Chapter V GDPR.
8.2 Any transfers connected with the payment services referred to in Art. 7.3 are governed by the respective privacy notices of the providers, which the Controller invites the data subject to consult.
Art. 9. RETENTION PERIOD
9.1 Where a request submitted through the Website forms does not lead to a Quote, the data provided are kept for as long as necessary to deal with the request and, thereafter, in accordance with the Controller’s retention practices for email correspondence.
9.2 Data relating to an Engagement actually entered into are kept for the duration of the relationship and, following its termination, for a maximum period of six years, corresponding to the retention period for business records under Article 30 of the Código de Comercio (Spanish Commercial Code) and consistent with the general five-year limitation period for personal actions under Article 1964 of the Código Civil (Spanish Civil Code), save for different periods provided for by specific statutory obligations or necessary for the establishment, exercise or defence of legal claims.
9.3 Data processed on the basis of consent to the newsletter are kept until the consent is withdrawn.
Art. 10. SECURITY MEASURES
10.1 The Controller implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, pursuant to Article 32 GDPR, including encryption of communications (HTTPS), content security policies, limits on the number of form submissions per IP address, and automated mechanisms for detecting submissions that are not genuine.
Art. 11. RIGHTS OF THE DATA SUBJECT
11.1 The data subject has the right to obtain from the Controller, in the cases and in the manner provided for in Articles 15 to 22 GDPR: access to their personal data; rectification of inaccurate data; erasure of data, in the cases provided for by law; restriction of processing; data portability; the right to object to processing based on the Controller’s legitimate interest, including the processing referred to in Art. 4.4; and the withdrawal of consent given, without prejudice to the lawfulness of processing carried out before the withdrawal.
11.2 These rights may be exercised by sending a request to the Controller using the contact details set out in Art. 1.1, clearly indicating the right the data subject intends to exercise.
Art. 12. RIGHT TO LODGE A COMPLAINT
12.1 Without prejudice to the right to bring proceedings before the competent court, the data subject has the right to lodge a complaint with the Agencia Española de Protección de Datos (Spanish Data Protection Agency, the “AEPD”), Calle Jorge Juan 6, 28001 Madrid (www.aepd.es), as the competent supervisory authority by reason of the Controller’s place of establishment, or with the supervisory authority of the Member State where the data subject habitually resides or works, or of the place where the alleged infringement occurred.
Art. 13. SOURCE OF PERSONAL DATA
13.1 Where the Client is a legal person, the data of its contact persons or beneficial owners communicated to the Controller for the purposes of managing the relationship are processed for the purposes set out in Art. 4, including where not collected directly from the data subject, pursuant to Article 14 GDPR; the Client that communicates such data is required to inform the data subjects concerned.
Art. 14. WHETHER PROVIDING PERSONAL DATA IS MANDATORY
14.1 The provision of the data requested in the Website forms and, subsequently, for the purposes of the Quote and the Engagement, is necessary in order to act on the request and to provide the Services; failure to provide the data means the request cannot be handled and the Services cannot be provided. The provision of data for the newsletter is instead optional.
Art. 15. CHANGES TO THIS PRIVACY NOTICE
15.1 The Controller may amend this Privacy Notice to reflect legislative, regulatory, technological or organisational changes, giving notice of the amendment by publishing it on the Website together with the date of the update.
Art. 16. RELATED DOCUMENTS
16.1 This Privacy Notice is supplemented by the Terms and Conditions of the Services, the Legal Notice and the cookie notice, to which reference is made for the matters they respectively govern.
Version dated 17 September 2026