Legal information
Privacy Policy
How we handle browsing data and communications sent to Elan Global Vision.
Updated on 21 September 2026
1. Data controller
Elan Global Vision Sociedad Limitada is the controller for the processing described in this policy. For privacy enquiries and rights requests, write to [email protected].
- Trading name
- Elan Global Vision
- Full legal name
- Elan Global Vision Sociedad Limitada
- Spanish tax identification number
- B75306753
- Registered office
- Plaza Ciudad de Viena, núm. 6, 28040 Madrid
- Commercial Registry
- Commercial Registry of Madrid. Section 8, sheet M-836429, entry 1. IRUS: 1000434522558.
- Contact
- [email protected]
- Website
- https://elanglobalvision.com
2. Data and website features
This corporate website presents EGV’s activities. It is static, has no backend of its own and contains no forms, user accounts or online purchases. The contact link opens your email application: we only receive a message if you choose to send it.
Messages may include your name, email address, organisation, professional details and any content or attachments you share. Providing this information is voluntary; without sufficient contact information we cannot reply. Please do not send health data or other sensitive information that is unnecessary for your enquiry.
To deliver and protect the website, Cloudflare may process IP addresses, dates and times, URLs and HTTP requests, connection, device or browser information, routing and traffic data, and signals needed for availability and abuse prevention.
Fonts and visual assets are served from the website itself. We do not use Cloudflare Web Analytics, Google Analytics, Meta Pixel, behavioural advertising or commercial tracking. EGV does not profile visitors or make automated decisions about them.
3. Purposes and legal bases
Emails are used solely to answer enquiries and manage possible collaborations. They are not used for marketing campaigns or automatically shared with other group companies. Visiting the website is not treated as consent for other purposes.
- Answering enquiries and maintaining the communication you request: EGV’s legitimate interest in responding to contacts and professional relationships, balanced against your rights and expectations (GDPR Article 6(1)(f)).
- Managing collaboration proposals and, where you request it and would be a party to a possible contract, taking precontractual steps (GDPR Article 6(1)(b)). Contact with representatives of organisations relies on the legitimate interest in maintaining that professional relationship (GDPR Article 6(1)(f)).
- Delivering the website, maintaining availability, preventing abuse and protecting security: our legitimate interest in providing a secure, operational service (GDPR Article 6(1)(f)).
- Handling rights requests and legal obligations: compliance with legal obligations (GDPR Article 6(1)(c)).
4. Providers and recipients
Cloudflare, Inc. provides hosting through Cloudflare Pages, content delivery (CDN) and security. It also provides domain registration through Cloudflare Registrar; domain registration does not involve disclosing the contents of email enquiries to it.
Cloudflare acts as a processor when handling content and logs on EGV’s behalf under its data processing agreement. Its privacy policy also describes operations it carries out as a controller to provide and protect its services. It is not used as a visitor analytics tool.
Google Workspace is the service used to receive, store and manage email. Data may be accessed by people authorised by EGV and the providers and subprocessors needed to deliver these services, subject to applicable data protection terms. Data may also be disclosed to authorities where legally required.
5. International transfers
Cloudflare and Google operate internationally and may process data, directly or through subprocessors, outside the European Economic Area, including in the United States. Processing is not guaranteed to be limited to Spain or the European Union.
According to its contractual documentation, Cloudflare relies on the EU–U.S. Data Privacy Framework for transfers covered by its certification and the applicable adequacy decision. For transfers not covered by adequacy, its agreement incorporates the European Commission’s standard contractual clauses and any additional safeguards required.
Google Workspace’s terms likewise provide for adequacy mechanisms or standard contractual clauses, depending on the recipient and transfer. You may request information or a copy of the applicable safeguards at the contact email, subject to any restrictions needed to protect confidential information.
6. Retention
Enquiries that do not lead to collaboration: up to 12 months from the last substantive communication, with earlier deletion when no longer necessary. EGV reviews the mailbox monthly; automated messages do not restart this period. This is EGV’s organisational criterion, not a universal period imposed by the GDPR.
Collaborations: we retain the necessary documentation for the duration of the relationship. Afterwards, only data required by legal obligations or needed to address specific liabilities is kept, for the periods applicable to each document. Where required, data is blocked under Article 32 of Spain’s LOPDGDD, excluded from ordinary use until destruction.
Technical data: retention reflects request delivery, service operation and security, incident resolution and legal obligations. Data processed by Cloudflare on EGV’s behalf is governed by its data processing agreement: until the contractual relationship ends or processing is no longer necessary to fulfil it, whichever occurs first, subject to the applicable deletion rules and legal exceptions. Cloudflare’s own controller operations follow the criteria in its privacy policy. The 12-month email period does not apply to this data.
Deletion from the mailbox and removal of Google’s technical copies do not occur simultaneously; those copies follow the deletion cycle in the service terms. Exercising your rights does not depend on ordinary retention periods expiring.
7. Rights and complaints
You may exercise rights of access, rectification, erasure, objection, restriction and portability in the circumstances provided by the GDPR. In particular, you may object on grounds relating to your situation to processing based on legitimate interests.
Send your request to [email protected]. We will only ask for additional information to confirm your identity if there are reasonable doubts. We will normally respond within one month; any legally permitted extension will be communicated within that month, together with the reasons.
You may complain to the Spanish Data Protection Agency (AEPD) if you consider that the processing infringes your rights, without first having to complain to EGV.
8. Security and changes
The website uses HTTPS and technical measures to secure its delivery. EGV limits access to communications to the people who need to handle them and applies proportionate organisational measures. No system can guarantee absolute security.
This policy is governed by the GDPR and Spanish Organic Law 3/2018. It will be updated when processing changes. Before introducing analytics, forms or other features, we will explain their effects on personal data and obtain consent where required.