Privacy Policy
Last updated: June 2026
At traspasso we are committed to protecting the personal data of our users. Data is collected and processed in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
1. DATA CONTROLLER
| Controller | Nicolás Tabares Wiede |
| Tax ID (NIF) | 78552025X |
| Contact email | [email protected] |
| Website | https://traspasso.com |
traspasso is not required to appoint a Data Protection Officer (DPO) under Article 37 of the GDPR. For any data protection query you can contact us at [email protected].
2. DATA WE COLLECT AND PURPOSES OF PROCESSING
We process the following personal data according to the purpose for which it is collected:
2.1. Registration and account management
- Data: first name, last name, email address and password.
- Purpose: to create and manage your user account and allow you to publish and manage business sale listings.
- Legal basis: performance of a contract (Art. 6.1.b GDPR).
2.2. Publishing listings
- Data: business information, photographs, the advertiser's contact details and, where applicable, the business's financial data.
- Purpose: to publish and manage the listing on the platform and facilitate contact between buyers and sellers.
- Legal basis: performance of a contract (Art. 6.1.b GDPR).
2.3. Subscriptions and payments
- Data: billing data and, where applicable, card data processed by our payment provider.
- Purpose: to process payment for the subscription plans purchased and issue the corresponding invoices.
- Legal basis: performance of a contract (Art. 6.1.b GDPR) and legal obligation to keep accounting records (Art. 6.1.c GDPR).
2.4. Contact and enquiry form
- Data: name, email and message content.
- Purpose: to respond to your enquiry or request for information.
- Legal basis: the controller's legitimate interest (Art. 6.1.f GDPR).
2.5. Commercial communications (newsletter and promotions)
- Data: email address.
- Purpose: to send you communications about news, new listings and traspasso promotions.
- Legal basis: the user's express consent (Art. 6.1.a GDPR) or, for users who have already purchased a service, legitimate interest under Art. 21.2 of Law 34/2002 (LSSI-CE), limited to our own services similar to those purchased. You can withdraw your consent at any time.
2.6. Website analysis and improvement (analytics cookies)
- Data: browsing data, anonymised IP, pages visited, session duration.
- Purpose: statistical analysis of website use to improve its performance and content.
- Legal basis: the user's consent (Art. 6.1.a GDPR) obtained through the cookie panel.
3. SHARING DATA WITH THIRD PARTIES
We do not share your data with third parties except in the following cases:
- Payment service providers, to process transactions, acting as data processors under a processing agreement in accordance with Art. 28 GDPR.
- Technology and analytics service providers (e.g. Google Analytics/Tag Manager) needed for the website to function, likewise acting as data processors.
- Where required by legal obligation or by a request from a competent authority.
- In the context of a possible merger, acquisition or transfer of the business, with prior notice to the affected users.
traspasso does not sell or share personal data with third parties for those third parties' own marketing purposes.
4. INTERNATIONAL DATA TRANSFERS
Some of our providers (in particular Google LLC, provider of Google Analytics and Google Tag Manager) may transfer data to servers located outside the European Economic Area (EEA), specifically to the United States. These transfers are covered by the appropriate safeguards provided for in Art. 46 GDPR and, in Google's case, by the EU-US Data Privacy Framework, adopted by the European Commission's Decision of 10 July 2023.
If you would like more information about the applicable safeguards, you can request it at [email protected].
5. DATA RETENTION
| Data type | |
|---|---|
| User account data | While the account is active; 1 additional year after closure unless the user objects. |
| Published listing data | While the listing is active; data anonymised after its removal. |
| Billing data | 5 years from the last invoice (Art. 30 Commercial Code) or 4 years under tax law. |
| Contact communications | 1 year from the last communication. |
| Analytics cookie data | As set out in our Cookie Policy. |
6. USER RIGHTS
As a user you can exercise the following rights recognised by the GDPR and the LOPDGDD:
- Access (Art. 15 GDPR): to know what data we process about you.
- Rectification (Art. 16 GDPR): to correct inaccurate or incomplete data.
- Erasure / right to be forgotten (Art. 17 GDPR): to request the deletion of your data when it is no longer necessary, you have withdrawn consent or you object to the processing.
- Restriction of processing (Art. 18 GDPR): to request that the use of your data be restricted in certain circumstances.
- Portability (Art. 20 GDPR): to receive your data in a structured, commonly used format, or to request its transmission to another controller, where processing is based on consent or on a contract.
- Objection (Art. 21 GDPR): to object to the processing of your data, in particular for commercial communications.
How to exercise your rights
To exercise your rights, send an email to [email protected] with the subject "Data Protection: [right you wish to exercise]", stating your full name and the email you are registered with on the platform. If we are unable to verify your identity with the information provided, we may ask you for additional information.
Complaint to the supervisory authority
If you believe that the processing of your data breaches the regulations, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD):
- Website: www.aepd.es
- Address: C/ Jorge Juan, 6, 28001 Madrid
7. DATA SECURITY
We apply appropriate technical and organisational measures to guarantee the security of personal data and prevent its loss, misuse, unauthorised access, disclosure, alteration or destruction, in line with the state of the art, the cost of implementation and the nature of the data processed. Among other measures, we use HTTPS encryption on all communications, system access controls and security incident response procedures.
In the event of a security breach that poses a risk to your rights and freedoms, we will notify you without undue delay in accordance with Art. 34 GDPR.
8. CHANGES TO THE PRIVACY POLICY
We may update this policy to adapt it to regulatory changes or changes in our services. We will publish the updated version on our website, stating the date of the last revision. If the changes are substantial, we will notify you by email or through a prominent notice on the platform.