Privacy policy

Last updated: 2 October 2026

This policy explains how personal data is processed on carlosmendiola.com, in accordance with Andorran Law 29/2021 of 28 October on the protection of personal data (LQPD), its implementing regulation and, where applicable, Regulation (EU) 2016/679 (GDPR).

1. Data controller

No data protection officer has been appointed, as one is not required for this activity. For any privacy question you can write to [email protected].

2. What data is processed

This site has no forms and does not process special categories of data. It is not aimed at children under 16.

3. Purposes and legal basis

No automated decisions or profiling with legal effects are carried out.

4. Retention periods

5. Recipients and processors

Data is not shared with third parties unless required by law (for example, with the tax authorities). The following providers act as processors to deliver the service:

6. International transfers

Cloudflare and Google may process data in the United States. These transfers rely on the EU-US Data Privacy Framework, to which both companies have signed up, and on standard contractual clauses, in line with Article 43 et seq. of the LQPD. You can ask for more information at [email protected].

7. Your rights

You may at any time exercise your rights of access, rectification, erasure, restriction of processing, portability and objection, and the right not to be subject to automated decisions, by writing to [email protected] with the subject “Data protection” and proving your identity. We will reply within one month.

Consent given for a specific purpose may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.

If you believe your rights have not been respected, you can lodge a complaint with the Andorran Data Protection Agency: APDA, C/ Dr. Vilanova, 15-17, Nova seu del Consell General, planta -5, AD500 Andorra la Vella · tel. +376 808 115 · [email protected] · www.apda.ad.

8. Security

Appropriate technical and organisational measures are applied to protect data against loss, misuse or unauthorised access: encrypted connection (HTTPS), access control and providers with security guarantees.

9. Changes to this policy

This policy may be updated to reflect legal or service changes. The date of the last update is shown at the top.

Back to home