Privacy and data protection policy
Last updated: September 8, 2026
1. Identity of the data controller
In compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR), and with Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD), users are informed that personal data collected through the website https://nomdeskrent.com (the "Website") is processed under the responsibility of:
- Data controller: the founders/promoters of the NomDesk business initiative (currently in pre-launch and legal incorporation phase).
- Operating address / notifications: Valencia, Spain.
- Contact / privacy email: nomdeskrent@gmail.com
- Contact phone: +34 657 624 473
(Note: once registration as self-employed / RETA or the incorporation of a legal entity is formalised, the corresponding identification details and tax ID will replace this section in an updated version of this text.)
2. Purpose and categories of data processed
The controller collects and processes users' personal data for the following purposes and categories:
1. Managing requests and providing the rental service
- Data categories: identification and contact data (first name, last name, email address, phone number) and location/delivery data (postal address in Valencia).
- Purpose: to process office equipment rentals, coordinate delivery and pick up logistics, manage the corresponding deposits, and provide pre and post sale customer support.
2. Commercial communications and direct marketing
- Data categories: name and email address.
- Purpose: to send newsletters, service updates, offers and promotional communications about NomDesk.
3. Handling enquiries through direct channels (forms / WhatsApp)
- Data categories: identification data, phone number and any information voluntarily provided in the enquiry.
- Purpose: to respond to technical, commercial or logistical information requests made by the user.
3. Legal basis for processing
User data is processed on the basis of the following legal grounds (art. 6.1 GDPR):
- Performance of a contract or pre-contractual measures (art. 6.1.b GDPR): to manage, process and provide the rental services requested by the user.
- Consent of the data subject (art. 6.1.a GDPR): for sending commercial communications and newsletter subscriptions, given by ticking specific boxes on the Website's forms.
- Legitimate interest (art. 6.1.f GDPR): to respond to direct enquiries made by users and to ensure the security and integrity of the Website.
4. Recipients and data processors
Personal data will not be transferred or disclosed to third parties except where legally required. However, to provide the service and manage the web infrastructure, the controller uses service providers acting as data processors, who access information under strict confidentiality clauses and data processing agreements (art. 28 GDPR):
- Supabase Inc.: database infrastructure provider for the secure storage of requests, contacts and delivery addresses.
- Brevo (Sendinblue GmbH / Brevo SAS): marketing automation and customer relationship management (CRM) platform for sending transactional and commercial emails.
- Vercel Inc.: web hosting and technical infrastructure provider for the Website.
5. International data transfers
Some of the service providers listed above (such as Supabase Inc. or Vercel Inc.) are based in, or process data in, countries outside the European Economic Area (EEA), mainly the United States.
These international transfers are carried out under the appropriate safeguards set out in articles 44 et seq. of the GDPR, specifically under the EU-U.S. Data Privacy Framework or through the Standard Contractual Clauses (SCCs) approved by the European Commission.
6. Data retention period
Personal data will be kept only for as long as strictly necessary to fulfil the purposes for which it was collected:
- Data related to rentals and the pre-contractual/contractual relationship: kept for as long as the rental relationship lasts and, after it ends, for the legal limitation periods applicable to civil or commercial liability.
- Data used for commercial communications: kept until the user withdraws consent or exercises their right to erasure or unsubscribes from the mailing service.
- Enquiries and incidents: kept for as long as necessary to resolve the request and, at most, for a period of 12 months after resolution.
7. Data subject rights
Users may exercise their data protection rights at any time and free of charge by sending a written communication to nomdeskrent@gmail.com or a message to the official WhatsApp channel +34 657 624 473, attaching a copy of an ID document or equivalent proof of identity:
- Right of access: obtain confirmation as to whether the controller is processing your personal data, and access it.
- Right of rectification: request the correction of inaccurate or incomplete data.
- Right of erasure ("right to be forgotten"): request deletion of your data when, among other reasons, it is no longer necessary for the purposes it was collected for.
- Right to object: object to the processing of your data based on legitimate interest or for direct marketing purposes.
- Right to restriction of processing: request the suspension of data processing in the legally established cases.
- Right to data portability: receive your personal data in a structured, commonly used, machine readable format for transmission to another controller.
- Right to withdraw consent: at any time, without affecting the lawfulness of processing based on consent prior to its withdrawal.
If a user believes their rights have not been properly addressed, or that current legislation has been breached, they are entitled to file a complaint with the Spanish Data Protection Agency (AEPD) through its electronic office at www.aepd.es.
8. Security measures
The controller has implemented the technical and organisational security measures necessary to guarantee the confidentiality, integrity, availability and resilience of personal data, preventing its alteration, loss, unauthorised processing or access, taking into account the state of the art, the nature of the data stored and the risks to which it is exposed.