Privacy policy

Rodríguez Martín Abogados is committed to protecting the personal data of the users of https://rodriguezmartinabogados.com and of its clients, and to processing it with the technical and organisational measures that guarantee its security and confidentiality. This policy explains what data we process, for what purpose, for how long and what rights data subjects may exercise.

1. Applicable legislation

This policy has been drafted in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR); Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD); and Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSI-CE). The lawyer's duty of professional secrecy under the Organic Law on the Judiciary and the General Statute of the Spanish Legal Profession also applies.

2. Data controller

  • Identity: Christian Rodríguez Martín, lawyer (Rodríguez Martín Abogados). Tax ID (NIF) 48104276Y.
  • Postal address: C/ Balmes 188, 4º 1ª · 08006 Barcelona.
  • Telephone: +34 620 29 29 78.
  • Email: christianrm19@icab.cat.

The firm is not required to appoint a data protection officer (Art. 37 GDPR and Art. 34 LOPDGDD). Any question regarding this policy may be addressed to the controller at the email address indicated.

3. Principles we apply

When processing personal data we apply the principles of Article 5 GDPR: lawfulness, fairness and transparency (we always inform of the purpose and legal basis of the processing); purpose limitation (data is collected for specified, explicit and legitimate purposes); data minimisation (we process only the data strictly necessary); accuracy (data is kept up to date); storage limitation (data is kept only for as long as necessary); integrity and confidentiality (data is processed with appropriate security); and accountability.

4. Data we process

We process the data that the data subject provides to us through the Website form, by email, by telephone or by WhatsApp, and the data provided or generated in the course of a professional engagement. In general this consists of:

  • Identification and contact data: full name, telephone, email, postal address and, where applicable, identity document.
  • Data relating to the matter: the description of the facts, the documents provided (contracts, statements, notices, court decisions) and any other information needed to review it and, where applicable, to conduct the case.
  • Financial and banking data needed for invoicing and payment of the services.
  • Technical browsing data recorded automatically by the server (IP address, date and time, pages visited), used solely to ensure the security and operation of the Website.

Given the nature of the activity, an enquiry or engagement may require the processing of special categories of data (for example, health data in personal injury claims or family matters, or data relating to criminal offences). Such data is processed only where necessary for the establishment, exercise or defence of legal claims (Art. 9(2)(f) GDPR) and is protected by professional secrecy.

The user guarantees that the data provided is true, accurate and up to date, and that they have authorisation when providing third-party data. We do not collect data from children under fourteen; if a minor provides us with data, we will delete it as soon as we become aware, unless they act with the consent of their parents or guardians.

5. Purposes and legal bases

  • Handling enquiries and requests for information received through the Website or any other channel, including the free first consultation. Legal basis: steps taken at the request of the data subject prior to entering into a contract (Art. 6(1)(b) GDPR).
  • Providing the legal services engaged: review of the matter, advice, out-of-court claims, representation and defence in court, invoicing and administrative management of the engagement. Legal basis: performance of the services contract (Art. 6(1)(b) GDPR) and, for special categories of data, the defence of legal claims (Art. 9(2)(f) GDPR).
  • Complying with legal obligations, including tax, accounting and bar obligations and, where applicable, those arising from Law 10/2010 of 28 April on the prevention of money laundering and terrorist financing. Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR).
  • Maintaining professional contact with clients and associates, and managing any claims or liabilities. Legal basis: legitimate interest of the controller (Art. 6(1)(f) GDPR).
  • Sending informational or commercial communications about legal developments or the firm's services, only where the data subject has authorised it or is a client and the communications relate to services similar to those engaged. Legal basis: consent (Art. 6(1)(a) GDPR) or Art. 21.2 LSSI-CE. The data subject may object at any time by the same means or by writing to christianrm19@icab.cat.
  • Ensuring the security and operation of the Website. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

The data marked as mandatory in the contact form (name, telephone, email and description of the matter) is necessary to deal with the enquiry; if it is not provided, we will be unable to respond. In professional engagements, the provision of the necessary data and documents is a requirement for the provision of the service.

We do not make automated decisions or carry out profiling with users' data.

6. Retention period

Data from enquiries that do not lead to an engagement is kept for a maximum of one year from the last communication, unless the data subject requests its deletion earlier. Client data is kept for the duration of the professional relationship and, once it has ended, for the limitation periods of any legal and professional liabilities that may arise, as well as the periods required by tax, accounting and anti-money-laundering legislation (generally between five and ten years). After those periods, the data is securely deleted or anonymised. Case files are also kept in the manner required by bar regulations on the retention of professional records.

7. Recipients of the data

Personal data is not disclosed to third parties, except in the following cases:

  • Associate lawyers, court agents, experts and other professionals involved in the matter, to the extent necessary for its handling and with the client's knowledge.
  • Courts and tribunals, public authorities, professional bodies, financial institutions or other parties or third parties, where necessary for the provision of the service or required by law.
  • Providers that supply services to the firm and act as processors under a contract in accordance with Article 28 GDPR: web hosting, email and office tools (Google Workspace), contact-form management, invoicing and accounting services, and legal databases. Where any of these providers is located outside the European Economic Area, the transfer is based on European Commission adequacy decisions (such as the EU-US Data Privacy Framework) or on the standard contractual clauses approved by the Commission.

8. Security and professional secrecy

The firm applies technical and organisational measures appropriate to the risk to ensure the confidentiality, integrity and availability of data: encrypted communications via SSL/TLS certificate, access control to systems, backups, device encryption and data-protection training. All information entrusted to the firm by the client is also protected by the lawyer's professional secrecy, which covers the facts, documents and communications known by reason of professional practice. In the event of a personal data breach likely to result in a high risk to the rights of data subjects, they will be informed without undue delay, in addition to notification to the supervisory authority.

9. Rights of data subjects

Any person has the right to obtain confirmation as to whether we process their personal data and, if so, to exercise the following rights:

  • Access: to know what data we process, for what purpose and to whom it is disclosed.
  • Rectification: to correct inaccurate data or complete incomplete data.
  • Erasure: to request deletion of data when it is no longer necessary, unless there is a legal obligation to retain it.
  • Objection: to object to processing on grounds relating to their particular situation, and in any event to the sending of commercial communications.
  • Restriction: to request that data be kept only for the exercise or defence of legal claims while a request for rectification or objection is being resolved.
  • Portability: to receive the data provided in a structured, commonly used and machine-readable format, or to request that it be transmitted to another controller.
  • Withdraw consent at any time, without affecting the lawfulness of prior processing.

How to exercise them. By writing to Christian Rodríguez Martín, C/ Balmes 188, 4º 1ª · 08006 Barcelona, or by email to christianrm19@icab.cat, stating the right being exercised and enclosing a copy of an identity document or other proof of identity. We will respond within one month at most, extendable in complex cases in accordance with Article 12 GDPR.

Complaints. If the data subject considers that the processing does not comply with the law, they may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid) or, in Catalonia, with the Catalan Data Protection Authority where it has jurisdiction.

10. Links to third-party sites

The Website contains links to third-party services (Google Maps, WhatsApp, professional bodies and public authorities). When accessing them, the user is subject to the privacy policies of those sites, over which the firm has no control.

11. Changes to this policy

This policy may be updated to reflect changes in legislation, case law or the firm's activity. The version in force will always be the one published on the Website. We recommend consulting it periodically.