Privacy Policy

This policy explains how DOVERMA GESTIÓN S.L. processes personal data through its website, Client Portal and communication channels under the GDPR and Spanish Organic Law 3/2018.

1. Controller

DOVERMA GESTIÓN S.L. (DYGP ASESORES), Spanish tax ID B93622074
Avda. Palma de Mallorca 17, 2nd B, 29620 Torremolinos (Málaga), Spain
General contact: info@dygpasesores.com · Data protection: privacidad@dygpasesores.com

2. Purposes and legal bases

  • Enquiries and requests: replying, assessing prospective clients and one-off services, and preparing offers or engagements. Legal bases: requested pre-contractual measures and, for general non-contractual enquiries, legitimate interests.
  • Client services: managing the professional relationship, files, documents, communications, billing and legal, tax and accounting duties. Legal bases: contract, legal obligations and legitimate interests in organisation and legal claims.
  • Client Portal: authentication, document and message exchange, enquiries, engagements, alerts, activity and security. Legal bases: contract, legal obligations and legitimate security interests.
  • Security: preventing fraud, misuse and unauthorised access using technical logs, hashed IP addresses and security tokens. Legal bases: legitimate interests and security obligations.
  • Email, telephone or WhatsApp: dealing with requests and communications required for the professional relationship. Legal bases: pre-contractual measures, contract or legitimate interests.
  • Marketing: sent only with consent or another lawful authorisation and always with a simple, free right to object.

3. Data

Identification and contact details; professional, employment, tax, accounting and financial information required for the service; requests, messages, uploaded documents, billing data, language preferences, and technical access and activity logs. Please do not include sensitive documents in public forms; use the Client Portal.

4. Sources

Data are obtained from the data subject, their representative, their organisation or, where necessary and lawful, public authorities and other legitimate sources.

5. Recipients and providers

Data may be disclosed to public authorities, financial institutions, Social Security, tax authorities, courts and other recipients where necessary or legally required. Hosting, email, maintenance, backup, communications and technology providers may process data on behalf of DOVERMA GESTIÓN S.L. under data-processing agreements.

The internal invoice-processing utility uses the OpenAI business API as a technology provider. Its use must remain covered by the applicable data-processing agreement and international-transfer safeguards. It is not used for incompatible purposes or solely automated decisions producing legal or similarly significant effects.

6. International transfers

Some technology or communications providers may process data outside the EEA. Where applicable, an adequacy decision, Standard Contractual Clauses or another valid GDPR safeguard will be used. Google Maps and WhatsApp connect only when the user chooses to use those services.

7. Retention

  • General enquiries: while handled and for no more than one year after the last interaction, unless needed for liabilities.
  • Pre-contractual requests: up to one year after closure, unless a contract follows or legal claims require retention.
  • Client files: during the relationship and afterwards for applicable legal, tax, accounting and limitation periods.
  • Security logs: for the proportionate period set in the internal policy; operational public-form anti-abuse records are deleted after 24 hours.
  • Consent-based data: until consent is withdrawn.

Afterwards, data will be erased or restricted where required by Spanish law.

8. Rights

You may request access, rectification, erasure, objection, restriction and portability and withdraw consent where applicable by contacting privacidad@dygpasesores.com or the postal address above. You may also complain to the Spanish Data Protection Agency.

9. Security and automated decisions

Technical and organisational measures are used to protect confidentiality, integrity, availability and traceability. No solely automated decisions with legal or similarly significant effects are made.

10. Updates

Last updated: 10 September 2026.

Back to home page