Legal document
Privacy Policy
Last reviewed: 3 August 2026
Madrid Urbana does not sell, rent or trade personal data. This page explains what data is collected, for what purpose, and what rights you have.
Data controller
The controller processes personal data of individuals who may be located in the European Union and therefore applies Regulation (EU) 2016/679 (GDPR) under its Article 3(2), to the extent applicable.
General principle
Only data voluntarily provided, and strictly necessary for the purposes set out below, is collected. No profiling and no automated decision-making with legal effects is carried out.
Contact form
- Data: name, email address, selected subject and the content of the message.
- Purpose: receiving, handling and replying to the enquiry.
- Legal basis: consent, given by submitting the form (Art. 6(1)(a) GDPR).
- Processor: Formspree, Inc. (United States), which receives the submission, stores it in the controller's account and forwards it by email.
- Retention: for the duration of the correspondence and up to 12 months after the last message, unless a legal obligation or a claim requires longer.
Newsletter subscription
- Data: name and email address.
- Purpose: sending site content, updates and articles.
- Legal basis: explicit consent (Art. 6(1)(a) GDPR), given by completing the subscription form.
- Processor: Formspree, Inc. (United States). Subscriptions are collected through the same service as the contact form and managed directly by the controller. If a dedicated email delivery platform is adopted in future, this policy will be updated before the change goes live.
- Retention: until unsubscription is requested or consent is withdrawn.
- Withdrawing consent: possible at any time by writing to the contact address, without giving reasons and without affecting the lawfulness of processing carried out beforehand. Unsubscribing is free and actioned as promptly as possible.
The subscription form includes a hidden anti-spam control field that collects no user data and serves only to discard automated submissions.
Site analytics
- Data: cookie identifiers, IP address, pages visited, visit duration, device and browser type, approximate country or region.
- Purpose: measuring site usage in aggregate to improve content and navigation.
- Legal basis: consent, collected through Google's consent management platform (Art. 6(1)(a) GDPR). If storing information on the device is not consented, analytics tools are not loaded.
- Processor: Google Ireland Limited / Google LLC (Google Analytics 4).
- Retention: whatever the data retention setting of the site's Analytics property establishes.
Advertising
- Data: cookie identifiers or equivalent technologies, browsing data and ad interaction data.
- Purpose: displaying advertising, measuring its performance and, where consented, personalising it.
- Legal basis: consent is collected through Google's consent management platform, certified and integrated with IAB Europe's TCF (Art. 6(1)(a) GDPR). If it is not given, Google serves non-personalised advertising, which also involves storing information on the device for delivery, measurement and frequency capping, without building a profile based on browsing history.
- Processor or independent controller: Google Ireland Limited / Google LLC (Google AdSense). Google acts as an independent controller for the data it collects through its own advertising technologies.
- More information and controls: policies.google.com/technologies/partner-sites and myadcenter.google.com
Hosting and server logs
- Data: IP address, request date and time, resource requested, response code and user agent.
- Purpose: delivering the service, keeping the site secure and detecting incidents or abuse.
- Legal basis: legitimate interest in keeping the site operational and secure (Art. 6(1)(f) GDPR).
- Processor: Railway Corp. (United States).
- Retention: the provider's default period, generally no longer than 30 days, unless a security incident is ongoing.
Recipients
Data is not shared with third parties other than the processors listed for each activity, and except where required by law.
No automated decision-making with legal effects and no profiling is carried out by the controller.
International transfers
Transfers outside the European Economic Area occur in two situations:
- Providers established in the United States — Formspree, Railway and Google's services. These transfers rely on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework where the provider is certified, or on Standard Contractual Clauses together with supplementary measures.
- Access from Colombia by the controller, who operates the site remotely. Colombia is not covered by a European Commission adequacy decision. Access is limited to what is necessary to answer enquiries and manage subscriptions, using accounts protected by two-step verification, and is not shared with third parties.
Further information about these transfers is available at the contact address.
Your rights
You may exercise the rights of access, rectification, erasure, restriction, objection, data portability and withdrawal of consent at any time.
How: write to the contact address with the subject "GDPR rights", specifying the right you wish to exercise. Requests are answered within one month of receipt. Proof of identity will be requested only where there is reasonable doubt about who is making the request, and only to the minimum extent necessary.
Consent for analytics and advertising cookies can be changed by clearing the browser's browsing data: the notice appears again on the next visit and a new choice can be made. Google ad personalisation can also be managed directly at myadcenter.google.com, independently of this site. Details are in the Cookie Policy.
Complaints: if you believe your rights have not been properly handled, you may lodge a complaint with the data protection authority of your country of residence. In Spain, the Agencia Española de Protección de Datos (www.aepd.es).
Minors
The site is not directed at children under 14 and their data is not knowingly collected. If it is found that a child's data has been provided without the consent of whoever holds parental responsibility, it is deleted.
Security
Reasonable technical and organisational measures are applied, including encrypted transmission over HTTPS and restricted access to the accounts handling correspondence and subscriptions. No system is entirely secure; where a breach poses a high risk, affected individuals will be informed.
Changes to this policy
This policy may be updated to reflect changes in processing activities or applicable law. The review date appears at the top of the page.