Privacy policy
Last updated: June 2026
Your privacy matters. Here we explain clearly what data we collect when you use this site, what we use it for and what rights you have, in accordance with the General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
1. Data controller
- VAN DEN HOUT ENTERPRISES, S.L.
- CIF: B60972072
- Carrer Lepant 286-288, Bajo · 08013 Barcelona · España
- Email: office@vdhenterprises.com · Tel: +34 609 321 308
2. What data do we collect?
We only process the data you provide through the contact form:
- Name
- Phone (optional)
- The message or enquiry you send us
3. Why do we use it and on what legal basis?
- To handle and reply to your enquiry — basis: pre-contractual measures at your request and legitimate interest (art. 6.1.b and 6.1.f GDPR).
- To send you occasional communications, only if you tick the relevant box — basis: your consent (art. 6.1.a GDPR), which you may withdraw at any time.
- To ensure the security of the site and prevent abuse/spam — basis: legitimate interest (art. 6.1.f GDPR).
- To comply with applicable legal obligations — basis: legal obligation (art. 6.1.c GDPR).
4. How long do we keep your data?
We keep your enquiry data for as long as necessary to handle it and maintain our relationship and, thereafter, for the legally required periods. Enquiries that do not lead to a relationship are deleted after a reasonable period. If you gave consent for communications, we keep your email until you withdraw it.
5. Who else processes your data? (processors)
To provide the service we rely on providers who process data on our behalf, under a data-processing agreement (art. 28 GDPR):
- Supabase Inc. — database where form messages are stored.
- Vercel Inc. — website hosting and infrastructure.
- Resend Inc. — email notifications (when this service is active).
6. International transfers
The providers above (Supabase, Vercel and Resend) are located in the United States, so your data may be processed outside the European Economic Area. These transfers are covered by appropriate safeguards: those providers’ adherence to the EU-US Data Privacy Framework and/or the Standard Contractual Clauses approved by the European Commission. You may request a copy of these safeguards.
7. Your rights
You have the right to access, rectify, erase, object to the processing of, request restriction of and portability of your data, as well as to withdraw your consent at any time.
8. Automated decisions
We do not make automated decisions or carry out profiling with your data.
9. Security
We apply appropriate technical and organisational measures to protect your data (encryption in transit, access control, pseudonymisation of technical identifiers and minimisation of the data collected).
10. Changes to this policy
We may update this policy to reflect legal or service changes. We will always publish the current version on this page with its update date.