Privacy policy
Last updated: 30 September 2026
This is a courtesy translation. In case of discrepancy, the Spanish version prevails.
This policy explains how Playforward Consulting, S.L. processes the personal data collected through this website and its professional communications, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on Personal Data Protection (LOPDGDD).
1. Data controller
- Owner: Playforward Consulting, S.L.
- Tax ID (NIF): B05682026
- Registered office: Calle General Tamayo, 17, 3.º C, 04001 Almería (Spain)
- Registration: Company incorporated by public deed executed on 29 September 2026. Registration with the Almería Commercial Registry in progress.
- Email: info@playforward.es
- Website: https://playforward.es
Playforward is not required to appoint a Data Protection Officer. For any privacy question, write to info@playforward.es.
2. Data we process
- Contact form: name, organisation, email address and the content of your message.
- Email: the data you include when writing to us directly.
- Clients and suppliers: professional contact details of contact persons and billing details of the organisation.
We do not request special categories of data. Please do not include them in your messages.
3. Purposes and legal basis
| Purpose | Legal basis (GDPR) | Retention period |
|---|---|---|
| Answering enquiries and requests for information or quotes | Consent (Art. 6.1.a) and pre-contractual measures at the data subject's request (Art. 6.1.b) | Until the enquiry is resolved and at most 12 months if no business relationship begins |
| Managing client relationships: service delivery, invoicing and collection | Performance of a contract (Art. 6.1.b) and legal obligations (Art. 6.1.c) | For the duration of the relationship and then the statutory periods (6 years for commercial and 4 years for tax purposes) |
| Managing relationships with suppliers and partners | Performance of a contract (Art. 6.1.b) and legitimate interest in maintaining professional contact (Art. 6.1.f) | For the duration of the relationship and the subsequent statutory periods |
| Sending information about our services to clients | Legitimate interest (Art. 6.1.f GDPR and Art. 21.2 LSSI), with the option to object in each message | Until you object |
We do not make automated decisions or create profiles with your data.
4. Recipients
We do not share data with third parties, except where required by law (for example, the Spanish Tax Agency or courts).
To provide our services we rely on providers who process data on Playforward's behalf, under the corresponding data processing agreement:
- Netlify, Inc. (United States): website hosting and receipt of contact form messages.
- Hostinger: domain registration and email service.
- Accounting, tax and employment advisers, for administrative management.
5. International transfers
Netlify, Inc. may process data in the United States. These transfers rely on the safeguards provided for in the GDPR: the EU-U.S. Data Privacy Framework, where the provider is certified, and the standard contractual clauses approved by the European Commission.
6. Your rights
You may at any time exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw your consent, without affecting the lawfulness of prior processing.
To do so, write to info@playforward.es stating the right you wish to exercise. If we have reasonable doubts about your identity, we may ask for additional information to confirm it. We will reply within one month.
If you consider that your rights have not been properly addressed, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
7. Accuracy of data
By sending us your data you confirm that it is accurate and that, if it belongs to a third party, you have their authorisation to provide it.
8. Minors
This website is aimed at companies and institutions and is not intended for children under 14. We do not knowingly collect data from minors.
9. Security
We apply technical and organisational measures appropriate to the risk to protect your data: encrypted connection (HTTPS), access control and providers with security guarantees.
10. Changes to this policy
We may update this policy to reflect legal changes or changes to our services. The version in force is always the one published on this page, with its update date.