Privacy policy
Last updated: 20 September 2026
This is a translation provided for convenience. In the event of any discrepancy, the Spanish version prevails.
This policy describes how IMPARAGON SL processes the personal data of people who use the website imparagon.com, the platform mi.imparagon.com, and the contact and diagnostic forms, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
1. Data controller
- Identity: IMPARAGON SL
- Tax ID (NIF): B-75664524
- Registered address: Carrer de Felip II, 210, 2-2, 08027 Barcelona, Spain
- Email: hola@imparagon.com
2. What data we process
We process only the data the user provides through the website’s forms, and the data generated by their use of it:
- Identification and contact data: first name, surname, email address, telephone, company and job title.
- Professional data provided in the diagnostic request: industry, approximate advertising spend, platforms used, CRM system, and any other information the user chooses to share about their company.
- Browsing data: pages visited, source of the visit and technical connection data, processed anonymously as described in the Cookie policy.
- Platform access data (clients only): credentials and activity logs on mi.imparagon.com.
We do not process special categories of data. The user is responsible for the accuracy of the data they provide and for not including third-party data without authorisation.
3. Purposes and legal basis
| Purpose | Description | Legal basis |
|---|---|---|
| Responding to diagnostic and contact requests | Handling the enquiry, preparing the requested diagnostic and maintaining the communication needed to do so | Pre-contractual measures at the data subject’s request (Art. 6.1.b GDPR) |
| Commercial management | Following up with companies interested in IMPARAGON SL’s services, preparing and sending proposals | Legitimate interest in conducting business (Art. 6.1.f GDPR), balanced against the rights of the data subject |
| Providing the service to clients | Managing the contractual relationship and access to the mi.imparagon.com platform | Performance of a contract (Art. 6.1.b GDPR) |
| Sending communications | Sending content, articles and news from IMPARAGON SL by email | Consent of the data subject (Art. 6.1.a GDPR), which may be withdrawn at any time |
| Website analytics | Anonymous measurement of website use in order to improve it | Legitimate interest (Art. 6.1.f GDPR); the data does not identify the user |
| Advertising measurement | Loading advertising platform tags to measure campaign effectiveness | Consent of the data subject (Art. 6.1.a GDPR), via the cookie banner |
| Compliance with legal obligations | Responding to requests from authorities and meeting tax and commercial obligations | Legal obligation (Art. 6.1.c GDPR) |
4. How long we keep the data
- Diagnostic and contact requests: for as long as needed to handle the request and, if it does not lead to a contractual relationship, for a maximum of two years from the last contact.
- Client data: for the duration of the contractual relationship and, afterwards, for the limitation periods of the applicable legal obligations (generally six years for commercial purposes and four for tax purposes).
- Communications sent with consent: until the data subject withdraws consent or unsubscribes.
- Analytics data: being anonymous, it is not subject to personal data retention periods.
Once those periods have elapsed, the data is deleted or anonymised so that the person can no longer be identified.
5. Who receives the data
IMPARAGON SL does not sell or transfer personal data to third parties. To deliver its services it uses suppliers who act as processors under contract and follow its instructions:
- Hosting and database providers with servers located in the European Union.
- Meeting scheduling tools, used to arrange diagnostic and follow-up sessions.
- Email providers for sending communications.
- Advertising platforms (Google, Meta and others), only where the user has given consent through the cookie banner and solely for campaign measurement.
Some of these suppliers may be established outside the European Economic Area. Where that is the case, IMPARAGON SL ensures the transfer is made with the safeguards required by the GDPR (a European Commission adequacy decision or standard contractual clauses).
Data may also be disclosed to public administrations and competent authorities where there is a legal obligation to do so.
6. Your rights
Any person has the right to:
- Access: find out what data we process about them.
- Rectification: correct inaccurate or incomplete data.
- Erasure: ask for their data to be deleted when it is no longer needed.
- Objection: object to processing based on legitimate interest, including processing for commercial purposes.
- Restriction: ask for processing to be restricted in the cases set out in the legislation.
- Portability: receive their data in a structured, commonly used format, or have it transmitted to another controller.
- Withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.
- Not be subject to automated decisions producing legal effects or significantly affecting them.
To exercise these rights, write to hola@imparagon.com stating which right you wish to exercise and attaching a document that allows us to verify your identity. We will reply within one month of receiving the request, extendable in the cases provided for by law.
7. Complaints to the supervisory authority
If you believe the processing of your data does not comply with the legislation, you may lodge a complaint with the Spanish Data Protection Agency (AEPD), at www.aepd.es or at its offices at C/ Jorge Juan, 6, 28001 Madrid. We would be grateful if you contacted us first at hola@imparagon.com so we can try to resolve it.
8. Security
IMPARAGON SL applies appropriate technical and organisational measures to protect personal data against unauthorised access, loss or alteration, taking into account the state of the art and the nature of the data processed. Access to the mi.imparagon.com platform is protected by individual credentials and authenticated sessions.
9. Client data processed on behalf of third parties
In delivering its services, IMPARAGON SL may process data belonging to the contacts and customers of its client companies (for example, leads recorded in a CRM). In those cases IMPARAGON SL acts as a processor on behalf of the client company, which is the controller, and the processing is governed by the data processing agreement signed between both parties under Article 28 GDPR.
10. Changes to this policy
IMPARAGON SL may update this policy to reflect changes in legislation or in its processing activities. The version in force will always be available on this page, showing the date it was last updated.
