PRIVACY AND PERSONAL DATA PROTECTION POLICY
At GESTORIA VECTUM OMNIA, S.L., we understand that trusting an administrative agency involves sharing personal information and, in many cases, sensitive documentation. Our commitment is to process your data transparently, responsibly and respectfully, in accordance with data protection regulations and the obligations inherent to the profession of Administrative Manager.
This Privacy Policy clearly explains how we collect, use, protect and retain your personal data. If you have any questions, you can contact us at any time.
- IDENTIFICATION OF THE DATA CONTROLLER
In accordance with current legislation, we inform you that the personal data collected through this website will be incorporated into the data processing systems for which the following entity is responsible:
- Owner/Controller: GESTORIA VECTUM OMNIA, S.L.
- NIF: B93929198
- Registered office: CARRETERA DE MARTORELL, NÚM. 289, BA 1, 08224, TERRASSA (BARCELONA)
- Registry details:
- Contact email: contacto@gestoriavectumomnia.com
- Telephone: +34 638 81 54 97
- APPLICABLE DATA PROCESSING REGULATIONS
When processing your personal data, GESTORIA VECTUM OMNIA, S.L. applies the principles required by Regulation (EU) 2016/679 (GDPR), as well as national data protection legislation, established by Organic Law 3/2018 on Personal Data Protection and guarantee of digital rights (LOPDGDD), and Law 34/2002 on Information Society Services and Electronic Commerce (LSSI).
Likewise, as an Administrative Agency, we act in accordance with the national and regional legal framework applicable to our profession, which regulates not only how we practise it but also how we must safeguard, retain and protect our clients’ documentation and personal data:
- Law 2/1974 on Professional Associations
- Law 2/2007 on Professional Companies
- Organic Statute of the Administrative Manager Profession
- Regulations governing the individual practice of the profession (Royal Decree 2532/1998)
- Professional Code of Ethics (COGAC, 2020)
- Applicable regional regulations (Law 7/2006 and COGAC Statutes)
- CATEGORIES OF DATA PROCESSED
We collect personal data when you interact with us, whether through the website, by email, by telephone or while providing our services. The information we may collect includes:
Data you provide to us:
- Identification data: first name, surname, national ID/foreigner ID/passport.
- Contact details: postal address, email address, telephone.
- Personal characteristics data: date of birth, marital status (if necessary to carry out procedures).
- Economic and financial data: bank details and tax and asset information required to provide the service.
- Documentation provided for specific procedures (deeds, certificates, registrations, payslips, etc.).
Data generated during the professional relationship:
- Communication history.
- Documentation generated by the agency.
- Administrative and tax records arising from the procedures carried out.
- Information about payments, invoicing and funds provided.
Browsing data:
We collect basic information about how you interact with our website (for example, IP address or usage statistics). To learn about the cookies and tracking technologies we use, please refer to our Cookie Policy.
- PURPOSES OF PROCESSING
We use your data to provide you with a professional, secure and efficient service. Specifically, your personal data will be processed for the following purposes and legal bases:
- Handling enquiries and requests: when you complete contact forms, write to us or call us, we use your data to reply, send you information or prepare a quotation.
- Performance of professional services: we process the information needed to carry out administrative, tax, accounting, employment or documentary procedures on your behalf and within the framework of the contracted agency services.
- Compliance with legal obligations: as an agency, we are required to retain and process certain data to comply with tax, commercial and employment regulations, obligations under other applicable sectoral laws, and anti-money laundering regulations.
- Sending commercial communications: we send communications related to our services that we consider relevant to our clients, such as news, reminders, regulatory changes or useful information, based on legitimate interest. If you are not a client, we will do so only with your consent.
- Service improvement: we internally analyse how our services are used to improve processes, customer service and security.
- Data protection: we apply security measures and carry out internal controls to prevent unauthorised access and ensure the integrity of the information.
- LAWFULNESS OF PROCESSING
We process your data because:
- You have given us your consent.
- It is necessary to provide a service or perform a contract with you.
- We must comply with legal obligations.
- We have a legitimate interest in maintaining our relationship with you and improving our services.
- RECIPIENTS AND DATA TRANSFERS
Your personal data may be disclosed, only when necessary and always with safeguards, to:
- Public administrations and official bodies (Tax Agency, Social Security, public registers, town halls, Directorate-General for Traffic, Land Registry, etc.), in compliance with legal obligations.
- Financial institutions, for the management of collections and payments.
- Technology service providers acting as processors (hosting, management software, cloud storage, communications, etc.).
- External professionals (notaries, lawyers, etc.), when essential to provide the contracted service.
All our providers and collaborators are required to comply with strict security and confidentiality measures.
- RETENTION PERIODS
The Organic Statute and Code of Ethics establish that the Administrative Manager must keep records of matters handled, safeguard documentation diligently, return documents to the client when the engagement ends, and maintain professional secrecy even after leaving the profession.
Following these principles and in accordance with our internal retention policy, we retain your data while a relationship with you exists or we are handling a request; during the statutory retention periods required by tax, commercial or employment regulations; and during the limitation periods for liabilities.
Specifically, the regulations governing our professional activity require us to retain documents for the following periods:
- Tax documentation: 4 years (tax limitation period).
- Employment documentation: 4 years (employment-law infringements).
- Commercial documentation: 6 years (Commercial Code).
- Professional civil liability: up to 15 years in certain cases.
- Documentation provided by the client: returned when the engagement ends, unless there is a legal obligation to retain it.
Once these periods have ended, the data is blocked and subsequently securely deleted.
- SECURITY MEASURES
We apply the following technical and organisational measures to protect your data and ensure a level of security appropriate to the risk identified in our risk assessments:
- Encryption and secure communications.
- Access and permission controls.
- Backups.
- Internal security protocols.
- Periodic audits and reviews.
- Staff training in data protection.
- DATA SUBJECT RIGHTS
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to «contacto@gestoriavectumomnia.com» and attaching a copy of your national ID or equivalent document to verify your identity.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) if you believe your rights have been violated.
- POLICY UPDATES
This privacy policy may be amended to reflect legislative or case-law developments or improvements to our data-processing procedures. We recommend checking it periodically to remain informed of the latest version in force.
Last updated: 6 September 2026.
