version 1.0 · 28 July 2026 · translated from the Spanish version 3.0 · 28 July 2026

Privacy Policy

01
Controller

Name: Guillermo Passas Varo (PASSAS)

NIF: 76422540-A

Professional address: Calle Buensuceso, 9, Oficina 6 Izquierda, 18002, Granada (Spain)

Email: privacidad@passas.io

02
processing activities, purposes and legal bases

This Privacy Policy governs the processing of personal data carried out through the website https://passas.io and the digital services accessible from it. The processing of data arising from a professional engagement is governed by the privacy information included in the corresponding Engagement Letter.

2.1. Management of contact and pre-contractual communications

Data processed: name, email address and the content of the communication received through the website's contact channels.

Purpose: to deal with the enquiry or communication received and, where appropriate, to provide pre-contractual information.

Legal basis: legitimate interests of the Controller (Article 6.1.f GDPR) and, where the communication is directed towards entering into a contract, steps taken at the request of the data subject prior to entering into a contract (Article 6.1.b GDPR).

2.2. Contracting and provision of the Virtual Consultation

Data processed: name, email address, information about the matter provided in the booking form and any other data provided by the user in the course of the session.

Purpose: management of the booking, confirmation of contracting and provision of the Virtual Consultation service.

Legal basis: performance of the contract (Article 6.1.b GDPR).

2.3. Processing of payment for the Virtual Consultation

Payment for the Virtual Consultation is processed through Stripe, Inc. The Controller does not store payment card data. Payments relating to other services of the firm, including professional fees, advance payments on account and other invoiced items, are made by direct bank transfer.

Purpose: payment processing and issuing of the invoice.

Legal basis: performance of the contract (Article 6.1.b GDPR) and compliance with tax obligations (Article 6.1.c GDPR).

2.4. Recording and technological processing of the session

With the user's prior, express and informed consent, the Virtual Consultation may be recorded and processed by means of technological tools for the sole purpose of generating a session report to be sent to the user. This functionality is optional and does not condition the provision of the service.

The data processed in this context may contain special categories within the meaning of Article 9 GDPR.

Legal basis: explicit consent of the data subject (Articles 6.1.a and 9.2.a GDPR). Consent may be withdrawn before processing begins, without affecting the lawfulness of processing carried out prior to withdrawal.

2.5. Invoicing and tax obligations

Data processed: name or company name, NIF, address and the financial data necessary to issue the invoice.

Purpose: compliance with the invoicing and accounting obligations imposed by tax and commercial law.

Legal basis: compliance with legal obligations (Article 6.1.c GDPR).

03
Special categories of data

The matters that are the subject of a consultation or professional engagement may involve data concerning health, family circumstances, criminal proceedings, political opinions, racial or ethnic origin, financial circumstances or other special categories within the meaning of Article 9 GDPR. The Controller processes such data only to the extent that it is relevant to the provision of the service contracted, on the basis of Article 9.2.f GDPR and of the professional conduct obligations inherent to the practice of law, and subject at all times to the duty of professional secrecy.

04
Retention periods

Data will be retained for the time strictly necessary for the purpose that justified its collection:

(a) Data relating to the contracting and provision of the Virtual Consultation will be retained for five years from the end of the relationship, in accordance with Article 22 of the Estatuto General de la Abogacía Española.

(b) Invoicing data will be retained for five years in accordance with the Ley General Tributaria and for six years in accordance with Article 30 of the Código de Comercio.

(c) Contact data and prior communications will be retained until the request has been resolved and for the period necessary to address any resulting liabilities.

(d) Data processed on the basis of consent will be retained until consent is withdrawn, without prejudice to legally required retention periods.

05
Recipients and processors

The Controller does not disclose personal data to third parties except in the cases provided for by law or with the data subject's consent.

In connection with the services provided through the website, the Controller uses the following processors, bound by the legal instruments required by Article 28 GDPR:

(a) Google LLC (Google Workspace, Google Calendar, Google Meet): email, calendar and video conferencing services. Entity established in the United States.

(b) Stripe, Inc.: processing of payment for the Video Consultation. Entity established in the United States.

(c) Webflow, Inc.: hosting and management of the website. Entity established in the United States.

(d) Providers of artificial intelligence tools: the Controller may use artificial intelligence tools for the analysis and management of communications and for the technological processing of sessions, on the terms described in clause 2. Those providers act as processors, are bound by the safeguards required by Article 28 GDPR, and any international transfers involved are covered by the mechanisms set out in Article 46 GDPR. An up-to-date list of providers may be requested at privacidad@passas.io.

Transfers of data to the providers established in the United States listed in paragraphs (a), (b) and (c) are made on the basis of the standard contractual clauses adopted by the European Commission in accordance with Article 46.2.c) GDPR. The data subject may request information about the applicable safeguards by writing to privacidad@passas.io.

06
Data subject rights

The data subject may exercise the following rights against the Controller at any time:

Access (Article 15 GDPR): to obtain confirmation as to whether their personal data is being processed and, if so, to access that data and the information relating to the processing.

Rectification (Article 16 GDPR): to obtain the rectification of inaccurate data or the completion of incomplete data.

Erasure (Article 17 GDPR): to obtain the erasure of their data where, among other cases, it is no longer necessary for the purpose that justified its collection or the consent on which it was based is withdrawn.

Restriction of processing (Article 18 GDPR): to obtain the restriction of the processing of their data in the cases provided for by law.

Portability (Article 20 GDPR): to receive the data they have provided in a structured, commonly used and machine-readable format, where the processing is based on consent or on the performance of a contract and is carried out by automated means.

Objection (Article 21 GDPR): to object to the processing of their data where the legal basis is the legitimate interests of the Controller.

Withdrawal of consent: where processing is based on consent, the data subject may withdraw it at any time without affecting the lawfulness of processing carried out prior to withdrawal.

Rights may be exercised by written request to privacidad@passas.io, evidencing the identity of the applicant. The Controller will respond within a maximum of one month from receipt of the request, extendable by a further two months in cases of particular complexity, with prior notice to the data subject.

07
Professional secrecy and exercise of rights

The exercise of the rights described in clause 6 in relation to data processed in the course of an active professional engagement is subject to the duty of professional secrecy binding on the Controller under Article 542.3 of the Ley Orgánica del Poder Judicial and the Código Deontológico de la Abogacía Española, as well as to the limitations set out in Article 23 GDPR and Article 26 of Ley Orgánica 3/2018. Where a request to exercise rights cannot be fully complied with for reasons of professional secrecy or legal obligation, the Controller will notify the data subject with reasons.

08
Automated decision-making

The Controller does not take decisions based solely on automated processing which produce legal effects concerning the data subject or similarly significantly affect them, within the meaning of Article 22 GDPR. The artificial intelligence tools used by the firm support the lawyer's professional judgement and in no case replace it. For information on the use of artificial intelligence in PASSAS services, see the AI Policy available on the website.

09
Complaint to the supervisory authority

The data subject has the right to lodge a complaint with the Agencia Española de Protección de Datos (www.aepd.es) if they consider that the processing of their data does not comply with the applicable rules. It is recommended that the data subject first contact the Controller at privacidad@passas.io.

10
Amendments

The Controller may amend this Privacy Policy at any time in order to adapt it to regulatory changes or to new processing activities. The version in force is the one published on the website at the time of access. Material amendments will be communicated to affected users where legally required.

11
languages of this policy

This Policy is originally drafted in Spanish and is also published in English. Both versions correspond in their substantive content and each states its date of update. For the purposes of exercising their rights, the data subject may rely on the version they have consulted. Should they identify any discrepancy between the two versions, they may report it to hola@passas.io; the affected version will be reviewed and corrected. In respect of any matter not provided for in this clause, clause 6 of the Legal Notice shall apply.

frequently asked questions about the privacy policy

What exactly is this privacy policy you see everywhere online?

What is a privacy policy and what is it for?

the document telling the user what data your website collects, for what purpose and under what safeguards
+

The GDPR requires any controller processing personal data to inform the data subject clearly, accessibly and in advance about the conditions of that processing. The privacy policy performs that function: it turns the obligations of Article 13 GDPR into a text the user can read before providing their data. It is not a bureaucratic formality but the instrument that defines exactly what the controller will do with the information it receives, and on what legal basis.

Why won't a privacy policy template do?

Because the template describes a business that is not yours, and that matters
+

A generic template is designed for an abstract model: a contact form, a simple online sale. If your website also uses AI tools, manages bookings, works with processors established outside the EU or handles special categories of data, each of those elements requires a specific clause with its own legal basis, retention periods and safeguards. A policy that does not reflect the actual processing is not merely a breach of Article 13 GDPR; in proceedings before the AEPD it is also evidence that the controller did not have control over what it was doing with its users' data.

Who is required to have a privacy policy?

Any website collecting personal data, even if only an email address
+

Since the GDPR became applicable in May 2018, the obligation to provide information about processing applies to any controller established in the European Union or directing its services to European residents, regardless of the size of the organisation or the volume of data processed. A contact form, a booking system or a payment gateway are enough to trigger the information obligations of Article 13. Non-compliance can lead to administrative fines of up to 20 million euros or 4% of total worldwide annual turnover, in addition to individual claims by those affected.

What rights does the user have over their personal data?

Six: access, rectification, erasure, restriction, portability and objection
+

The data subject may exercise them against the controller at any time: to know what data is processed about them and for what purpose, to correct inaccurate data, to request erasure where it is no longer necessary, to obtain a copy in a reusable format or to request that processing be suspended. These rights are not absolute: in certain contexts, statutory retention obligations or the duty of professional secrecy may limit their scope, a circumstance the controller must give reasons for where a request cannot be fully complied with. Enquiries or requests relating to the processing of data at PASSAS may be addressed to privacidad@passas.io.

Can you draft the privacy policy for my website?

Yes, it is part of the web pack we prepare for businesses and professionals operating online
+

The privacy policy is the document in the pack that demands the greatest precision in identifying processing activities: what data is collected, which legal basis covers each purpose, which processors are involved and whether there are international data transfers. We draft it alongside the legal notice, the terms and conditions, the DPA and the AI policy, so that the set is coherent and there are no contradictions between the documents a user may find on your website. The starting point is a €90 video consultation, credited against the fees if an engagement is ultimately formalised.