Privacy policy.
01Data controller
This policy describes how Sonortec ("Sonortec", "we") collects and processes the personal data of people who visit this website or engage our services.
- Registered name
- Sonortec S.L.
- Tax ID (CIF)
- B-00000000 (placeholder — to be confirmed)
- Registered office
- Marbella, Málaga, Spain
- hola@sonortec.es
- Telephone
- +34 651 381 989
02What data we collect
We collect only the data strictly necessary to provide our services and respond to your enquiries:
- Contact data: name, phone, email, project address — when you provide them via the contact form, by email, or by phone.
- Project data: room characteristics, indicative budget, dates, and any other information you choose to share so we can prepare a quote.
- Browsing data: pages visited, session time, and basic technical data (language, device, browser) — collected in aggregate form through analytics tools.
- Contract data: if you go on to engage our services, the billing information and data required to perform the contract.
We do not collect special categories of data ("sensitive data") unless you volunteer them.
03Why we use it
- To answer your enquiry and send you a quote if you request one.
- To perform the contract if you decide to commission a project: design, construction, calibration, aftercare, warranty.
- To meet legal obligations — tax, accounting, and consumer-protection requirements.
- To improve the website through aggregated, anonymous analytics.
- Occasional communications— project follow-ups, maintenance reminders, and very occasionally studio news. You can unsubscribe at any time by replying to the email or writing to us at hola@sonortec.es.
We do not use your data for automated profiling and we do not make automated decisions that affect you.
04Legal basis
We process your data on the following grounds:
- Your consent (art. 6.1.a GDPR) — when you send us the form or contact us.
- Performance of contract (art. 6.1.b GDPR) — when you engage us for a project.
- Legal obligation (art. 6.1.c GDPR) — for issuing and retaining invoices and accounting records.
- Legitimate interest (art. 6.1.f GDPR) — for website security and improving our services through aggregated analytics.
05How long we keep it
We retain your data only for as long as necessary:
- Enquiries without engagement: 24 months from the last contact, then deleted.
- Engaged projects: for the duration of the contract and warranty period (up to 5 years after delivery), plus statutory tax retention periods (up to 6 years for invoices).
- Browsing data: a maximum of 14 months in analytics tools.
06Who we share it with
We do not sell or rent your data to third parties. We share it only with:
- Essential service providers needed to deliver the service — tax advisors, website hosting, email tools. All of them are contractually bound to comply with the GDPR.
- Public authorities where there is a legal obligation (Spanish Tax Agency, Social Security).
In some cases, our providers may be located outside the EU. Where that happens, we ensure appropriate safeguards are in place (European Commission standard contractual clauses).
08Your rights
You may exercise the following rights over your data at any time:
- Access — to know what data we hold about you.
- Rectification — to correct inaccurate data.
- Erasure ("right to be forgotten").
- Restriction of processing.
- Portability — to receive your data in a structured format.
- Objection to processing.
- Withdrawal of consent at any time, without affecting processing already carried out.
To exercise any of these rights, write to us at hola@sonortec.es with a copy of your ID or equivalent document. We will respond within a maximum of one month.
If you consider that we have processed your data incorrectly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) (www.aepd.es).
09Security
We apply reasonable technical and organisational measures to protect your data: encryption in transit (HTTPS), regular backups, access control on email and internal systems, and team training.
No system is infallible; in the event of a security breach affecting your data, we would notify you and report it to the AEPD within the timeframes required by the GDPR.
10Changes to this policy
We may update this policy to reflect changes in the way we work or in applicable law. The version in force is always the one published on this page, with the update date shown at the top.
If the change is substantial and you have an active project with us, we will notify you directly by email.