Legal
Privacy policy
This explains what personal data we process, what for, on what legal basis, and what you can do about it. It is written in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Last updated: August 9, 2026
1. Data controller
- Owner
- Elisenda Herrero Molina
- Tax ID
- 49220491P
- Registered address
- Calle Marconi 39, Escalera B, Bajos 3, 08191 Rubí (Barcelona), España
- elisenda@elisendaherrero.com
- Phone
- +34 672 78 81 51
- Website
- elisendaherrero.com
- Hosting
- Vercel Inc. (Estados Unidos)
No data protection officer has been appointed, as none of the circumstances in article 37 GDPR apply.
2. What data we process
We only process data you give us voluntarily. We do not buy databases and we do not obtain data from third parties.
- Contact form: names, email address, phone number (optional), planned wedding date, approximate guest count, location, budget range, type of service, and whatever you write in the message.
- Direct communications: whatever you include when you write to us by email, phone or social media.
- Data arising from an engagement: what is needed to deliver and invoice the service, including supplier and guest data you provide during the planning.
- Browsing data: the site uses no analytics or advertising tools. The hosting provider records IP addresses in its technical logs for security purposes.
We do not process special categories of data. If, while planning a wedding, you give us sensitive information — guest allergies or intolerances, for example — we will process it solely for that purpose and on the basis of your explicit consent.
3. What we use it for, and on what legal basis
| Purpose | Legal basis | Data |
|---|---|---|
| Answering your enquiry and preparing a quote | Pre-contractual measures at the data subject's request (art. 6.1.b GDPR) | Contact form data |
| Delivering and managing the contracted service | Performance of a contract (art. 6.1.b GDPR) | Contact, wedding and billing data |
| Meeting tax and accounting obligations | Legal obligation (art. 6.1.c GDPR) | Identifying and billing data |
| Publishing wedding photographs in the portfolio or on social media | Consent (art. 6.1.a GDPR), withdrawable at any time | Image and first name, where you authorise their use |
| Keeping the site secure and preventing abuse | Legitimate interest (art. 6.1.f GDPR) | IP address in the hosting provider's technical logs |
We do not make automated decisions and we do not build profiles from your data.
4. How long we keep it
- Enquiries that do not lead to an engagement: up to one year from the last contact, unless you ask us to delete them sooner.
- Client data: for the duration of the contractual relationship and afterwards for as long as needed to address potential liabilities, with a general maximum of five years (art. 1964 of the Spanish Civil Code).
- Tax and billing data: six years under article 30 of the Commercial Code, and four years for tax purposes.
- Photographs published with your consent: until you withdraw it.
5. Who we share it with
We do not sell or trade your data. Only those who need it for the service to work have access:
- Technology providers acting as data processors, under a contract signed in accordance with article 28 GDPR: the web hosting provider and the transactional email provider.
- Wedding suppliers — catering, venue, photography, florist and similar — where strictly necessary to organise your event, and always limited to what is needed.
- Tax and accounting advisers, and banks, to manage payments and legal obligations.
- Public authorities and courts, where there is a legal obligation to provide the data.
6. International transfers
Website hosting and delivery of contact form emails are provided by companies based in the United States. This involves an international transfer of data.
These transfers rely on the appropriate safeguards set out in Chapter V of the GDPR: standard contractual clauses approved by the European Commission and, where the provider is certified, the EU-US Data Privacy Framework. You can request a copy of these safeguards by writing to the contact address.
7. Your rights
You may exercise the following rights at any time:
- Access: find out what data of yours we process.
- Rectification: correct data that is inaccurate or incomplete.
- Erasure: ask us to delete data when it is no longer necessary.
- Restriction: ask us to keep the data but not use it, while a challenge is resolved.
- Portability: receive the data you provided in a structured, commonly used format.
- Objection: object to processing based on our legitimate interest.
- Withdraw consent at any time, without affecting the lawfulness of earlier processing.
To exercise them, write to the email address above, identifying yourself and stating which right you wish to exercise. We will reply within one month at most.
If you believe we have not handled your request properly, you may complain to the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid — www.aepd.es).
8. Information security
We apply technical and organisational measures appropriate to the risk: HTTPS traffic encryption, restricted access to information, backups, and providers offering sufficient security guarantees.
Should a security breach occur that poses a high risk to your rights, we will inform you without undue delay, and notify the supervisory authority where required.
9. Minors
The services on this site are aimed at adults. We do not knowingly collect data from children under 14. If you notice that a minor has given us data, write to us and we will delete it.
10. Changes to this policy
We may update this policy if the services, the providers or the law change. The version in force is always the one published here, with its revision date. If a change were substantial and affected you, we would tell you by email.
