Data protection
Privacy policy
How we process the data you provide when contacting us or requesting information about Can Lloses.
Last reviewed: September 2026
Data controller
Controller: Can Lloses
Tax ID: —
Address: —
Privacy contact: —
Data we process
Through the enquiry form we may receive your first name, last name, email, telephone, country, company or group, message and any information you voluntarily provide.
We do not request special-category data. Please do not include sensitive personal information in the message field.
Purpose and lawful basis
Data is used to answer your enquiry, provide requested information or the dossier, manage your interest in the transaction and, where appropriate, arrange discussions or visits connected with a potential acquisition.
The principal lawful basis is taking pre-contractual steps at your request in connection with a possible acquisition. Where an enquiry is purely informational, processing may also rely on the legitimate interest in answering it appropriately and securely.
Retention
Data is retained for as long as necessary to answer the enquiry and manage the relevant interest or negotiation process. It may then be restricted and retained for the period necessary to address possible legal liabilities.
Recipients and processors
We do not sell personal data or disclose it for advertising purposes. Access may be given to providers strictly necessary for hosting, email, security and technical support, acting as processors where applicable.
No international transfer is intended beyond what may be technically required by the providers ultimately selected. Where a provider involves an international transfer, the safeguards required by the GDPR will be applied.
Your rights
You may request access, rectification, erasure, objection, restriction and, where applicable, portability by writing to —.
You may also lodge a complaint with the Spanish Data Protection Agency (AEPD) if you believe that processing does not comply with applicable law.
Security and automated decisions
Reasonable technical and organisational measures are used to protect information. The form includes anti-spam and rate-limiting controls without relying by default on third-party profiling services.
No automated decision-making or profiling producing legal or similarly significant effects is carried out.