Your privacy matters. This policy explains, in plain language, what personal data we collect when you visit annamartineznorberto.com or write to us, what we use it for, and what rights you have over it. It is drafted in accordance with Regulation (EU) 2016/679 (GDPR) and the Ley Orgánica 3/2018 (LOPDGDD) (Spanish data protection act).
01Who processes your data
- Controller
- Anna Martínez Norberto
- NIF
- 38119388Q
- Address
- Calle Alt de Pedrell, 37-39, 1.º 1.ª — 08032 Barcelona (España)
- Contact email
- anna.cant.soprano@gmail.com
- Phone
- +34 620 907 517
- Data Protection Officer
- None has been appointed, as none of the circumstances in Article 37 of the GDPR apply.
02What data we process
Data you provide us
When you use the contact form we collect your name, your email address, the reason for your inquiry and your message. Your phone number is optional: we only ask for it in case you'd prefer us to call you.
If you write to us directly by email or through social media messaging, we will process the data you choose to include in your message.
Data generated while browsing
Our hosting provider automatically logs technical data needed to serve the website and protect it against abuse: IP address, date and time of the request, page requested, browser type and operating system. These logs are not used to build profiles and are not cross-referenced with contact-form data.
This site does not use Google Analytics or any other audience-measurement tool, advertising pixels, or tracking networks. We do not sell or share your data with third parties for commercial purposes.
We do not request special categories of data (health, beliefs, ethnic origin, etc.). Please do not include them in your messages.
03What we use your data for and on what legal basis
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Handling and responding to your inquiry through the form or by email. | Your consent, given when you submit the form (Art. 6(1)(a)). |
| Preparing quotes, managing bookings for performances, lessons or collaborations, and maintaining the professional relationship. | Application of pre-contractual measures and performance of the contract (Art. 6(1)(b)). |
| Complying with legal obligations, in particular tax and accounting obligations, where an economic relationship exists. | Legal obligation (Art. 6(1)(c)). |
| Ensuring the security, availability and proper functioning of the site, and preventing automated form submissions. | Legitimate interest in protecting the site and its users (Art. 6(1)(f)). |
| Displaying embedded third-party content (videos and maps) when you expressly request it. | Your consent (Art. 6(1)(a)), revocable at any time. |
| Defending or exercising claims should it become necessary. | Legitimate interest (Art. 6(1)(f)). |
We do not send commercial communications or newsletters. If a newsletter were offered in the future, it would be through a separate, voluntary subscription, with its own consent and an unsubscribe link in every message.
04How long we keep your data
| Data | Retention period |
|---|---|
| Contact messages that do not lead to a professional relationship | Up to 12 months from the last contact; deleted afterwards. |
| Data of clients, students and collaborators | For the duration of the relationship and, afterwards, for the legal limitation periods (up to 6 years for accounting and commercial matters, and 4 years for tax matters). |
| Server technical logs | The hosting provider's retention period, generally no longer than 30 days. |
| Language preference and embedded-content consent indicator | See the Cookie Policy. |
05Who else has access to your data
We do not disclose your data to third parties, except where legally required. We do work with providers who, as data processors, access it in order to provide their services to us, under a contract signed in accordance with Article 28 of the GDPR:
| Provider | Service | Location |
|---|---|---|
| Vercel Inc. | Website hosting and delivery | US / EU |
| Hostinger International Ltd. | Content management system hosting | EU |
| Google Ireland Ltd. / Google LLC | Email (receiving form submissions) | EU / US |
Your data may also be accessed by our tax and accounting advisors and, where applicable, banking entities, when an economic relationship exists, as well as by public authorities and courts when required by law.
06International transfers
Some of the above providers are based in the United States or may access data from there. These transfers rely on the EU-U.S. Data Privacy Framework, as those entities are certified under it, and, on a complementary basis, on the Standard Contractual Clauses approved by the European Commission.
You may request a copy of the safeguards applied by writing to anna.cant.soprano@gmail.com.
07Your rights
You may exercise the following rights at any time:
- Access. Find out what data of yours we process and obtain a copy.
- Rectification. Correct inaccurate or incomplete data.
- Erasure. Ask us to delete your data when it is no longer needed.
- Restriction. Request that we suspend processing while a claim is resolved.
- Objection. Object to processing based on our legitimate interest.
- Portability. Receive your data in a structured, commonly used format, or have it sent to another controller.
- Withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
How to exercise them
Simply write to anna.cant.soprano@gmail.com stating which right you wish to exercise. We will respond within one month at the latest. Exercising these rights is free of charge.
We will only request additional information to verify your identity if there are reasonable doubts about who is making the request, as permitted by Article 12(6) of the GDPR.
Complaints to the supervisory authority
If you believe we have not properly handled your request, you may file a complaint with the Agencia Española de Protección de Datos (C/ Jorge Juan, 6 — 28001 Madrid; www.aepd.es). We would appreciate the chance to resolve it directly with you first.
08Information security
We apply technical and organizational measures appropriate to the risk of the processing: HTTPS traffic encryption, secure-connection form submission, access control over mailboxes, regular software updates, and minimization of the data requested.
No system is completely invulnerable. Should a security breach occur that poses a high risk to your rights, we would inform you without undue delay, in addition to notifying the supervisory authority where required.
09Minors
The site is not directed at children under 14 and we do not knowingly collect their data. If teaching activities involve students under that age, consent and information will be handled directly with whoever holds parental authority or guardianship, outside of this website.
11Automated decisions
We do not make decisions based solely on automated processing of data, nor do we build profiles that produce legal effects or significantly affect you.
12Changes to this policy
We may update this policy to reflect legislative changes or new features on the site. The date of the last revision appears at the top of the page. If a change were substantial and affected processing based on your consent, we would notify you explicitly.