Data protection

Privacy policy

Last updated · 26 September 2026

This is an English translation provided for convenience. The Spanish version is the legally binding one.

1 · Data controller

Controller: Santiago García Solimei
NIE (Spanish tax ID): X8892388J
Address: Calle Anglada Camarasa 1, 6.º C · 07015 Palma de Mallorca, Balearic Islands, Spain
Email: [email protected]
Phone: +34 600 949 753

This policy applies to the website unfilteredworks.com and its associated contact channels.

2 · What data we process and where it comes from

We only process the data you give us. We do not buy databases or obtain information from third parties.

SourceData
Contact form or Reality Check requestName, email, phone, company, job title and whatever you write in your message.
WhatsApp BusinessPhone number, profile name and the content of the conversation.
Phone callYour number and the information you share during the call. We do not record calls.
EmailAddress, signature and the content of the message.
BrowsingTechnical and usage data, only if you accept analytics cookies. See the Cookie Policy.

We do not ask for special categories of data (health, beliefs, trade union membership and the like). Please do not include them in your messages.

3 · Why we use it and on what legal basis

PurposeLegal basis (GDPR)Retention
Answering your enquiry and preparing a proposalArt. 6(1)(b) — pre-contractual steps at your requestUp to 12 months from the last contact if no engagement follows
Providing and invoicing the service you hireArt. 6(1)(b) — performance of the contract · Art. 6(1)(c) — tax obligationsFor the duration of the relationship and 6 years afterwards (Spanish Commercial Code and tax law)
Sending you content or newsArt. 6(1)(a) — your express consentUntil you unsubscribe
Measuring and improving use of the siteArt. 6(1)(a) — your consent in the cookie bannerAs set out in the Cookie Policy
Site security and abuse preventionArt. 6(1)(f) — legitimate interest12 months

We do not make automated decisions with legal effects on you, and we do not build profiles.

4 · Who else has access to your data

We do not sell or pass on your data. Only the providers we need in order to operate have access, as data processors under a contract signed in accordance with Art. 28 GDPR:

  • GoHighLevel — CRM and management of forms and conversations (United States).
  • Meta Platforms — WhatsApp Business, if you choose that channel (United States and Ireland).
  • Hosting and email provider.
  • Tax and accounting adviser, for invoicing.

Data is also disclosed to the tax authorities and to banks where there is a legal obligation to do so.

5 · International transfers

Some of these providers are in the United States, so your data may leave the European Economic Area. These transfers rely on the Standard Contractual Clauses approved by the European Commission and, where applicable, on the EU-US Data Privacy Framework for participating organisations, together with supplementary security measures.

If you would rather your data did not leave the EU, write to us and we will handle your enquiry by email or phone.

6 · Your rights

You may at any time exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw your consent where processing is based on it, without affecting the lawfulness of processing carried out before.

Write to [email protected] stating the right you wish to exercise and attaching a copy of an identity document. We will reply within one month at most.

If you believe we have not handled your request properly, you may complain to the Spanish Data Protection Agency, the Agencia Española de Protección de Datos (C/ Jorge Juan 6, 28001 Madrid · aepd.es).

7 · Security

We apply appropriate technical and organisational measures: encryption in transit (HTTPS), access control, two-step authentication in the tools that allow it and regular review of permissions. No system is infallible; if a breach puts your rights at risk, we will inform you and notify the AEPD in accordance with Art. 33 GDPR.

8 · Minors

The site is aimed at professionals and businesses. It is not intended for children under 14 and we do not knowingly collect their data.

9 · Changes

We may update this policy. The version in force is always the one published here, with its update date.