Data Controller Information
Data Controller: Bernadette Varhelyi (Autonomo)
Email: hello@allincosta.com
Phone: +34 651 681 337
Tax ID: ES Y8720461W
Privacy Policy
This Privacy Policy explains how we collect, store, use, and protect personal data received through https://allincosta.com, in accordance with applicable data protection laws and the General Data Protection Regulation (GDPR).
Legal Framework
- Act CXII of 2011 on Informational Self-Determination and Freedom of Information
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)
Purposes and Legal Bases
| Purpose | Personal Data | Legal Basis | Retention |
|---|---|---|---|
| Contact and communication | Name, email, phone, country, form type, message, and any optional details you provide | Consent (GDPR Art. 6(1)(a)) | Up to 3 months after last communication |
| Marketing communications and newsletters | Name, email address, IP address (technical logs) | Consent (GDPR Art. 6(1)(a)) | Until consent is withdrawn |
| Website security & server logs | IP address, user agent, timestamp | Legitimate interest (GDPR Art. 6(1)(f)) | Up to 90 days |
Data Collected via the Contact Form
Depending on the selected form type, we collect the following data:
- Common (all types): form type (Customer / Partner / Community), name, email address, phone number.
- Customer: country, preferred location in Costa del Sol (optional), selected services (checkboxes).
- Partner: company name, office location(s), business service description, motivation statement, proposed benefits.
- Community: community name, president name (optional), location, number of units, community status, selected services.
- Consents: mandatory consent to data processing; optional consent for marketing communications.
Consent Declaration via Contact Form
When submitting the contact form, users are required to actively give their consent by checking the box stating: “I consent to the processing of my personal data by ALLinCOSTA in accordance with the Privacy Policy. *”
By ticking this checkbox and sending the message, the user explicitly agrees to the processing of their personal data (name, email, phone number, country, message, and any optional information) for communication and inquiry handling, in accordance with this Privacy Policy.
This consent serves as the legal basis for processing under Article 6(1)(a) of the GDPR and can be withdrawn at any time by contacting hello@allincosta.com.
Marketing Communications and Newsletter Subscription
If you subscribe to receive marketing updates, news, or special offers from ALLinCOSTA, we will process your name and email address for direct marketing purposes. The subscription is voluntary and based on your explicit consent (GDPR Art. 6(1)(a)).
We use the data only to send you relevant information about our services and promotions. Your data will not be shared with third parties for marketing purposes. Messages are sent via a secure email delivery system that complies with EU data protection standards.
You may withdraw your consent at any time by clicking the “Unsubscribe” link included in every marketing email, or by contacting us at hello@allincosta.com.
The management of marketing email subscriptions and related personal data is carried out in accordance with the Data Processing Policy of hirlevelek-kuldese.hu, which we fully comply with.
Server Logs
For security and diagnostics, our server may log IP addresses, browser type, and timestamps when the website or contact form is used. The legal basis is our legitimate interest in maintaining website security (GDPR Art. 6(1)(f)). Logs are automatically deleted within 90 days unless required longer for security reasons.
Third-Party Map Embed
Our contact page includes a Google Maps embed to display location information. When you view this map, Google may process technical data such as your IP address and browser details. This processing is governed by Google's Privacy Policy and may involve transfers outside the EEA. If you prefer not to share this data with Google, please do not load the map and contact us directly at hello@allincosta.com.
Data Retention
We retain personal data only as long as necessary to fulfill communication or service requests and legal obligations. Contact form messages are deleted within 3 months unless continued communication requires otherwise. Marketing data is retained until consent is withdrawn.
Data Security
Personal data is stored on secure servers in controlled environments. We use technical and organizational measures to prevent unauthorized access, disclosure, alteration, or destruction of personal information.
Cookies and Analytics
We do not use cookies, tracking tools, or analytics on this website.
International Data Transfers
If any third-party service (e.g., hosting, email delivery, or map integration) processes data outside the EEA, we ensure appropriate safeguards through EU Commission adequacy decisions or Standard Contractual Clauses (SCCs).
Withdrawing Consent
You can withdraw your consent at any time by contacting hello@allincosta.com. This will not affect the lawfulness of processing based on consent before its withdrawal.
Rights of Data Subjects
- Right to be informed about the collection and use of data
- Right to access your data
- Right to rectification (correction) of inaccurate data
- Right to erasure (“right to be forgotten”)
- Right to restrict processing
- Right to data portability
- Right to object to processing
Exercising Your Rights
You may exercise your rights by contacting us at hello@allincosta.com. We will respond within 30 days and may ask for proof of identity to ensure the security of your data.
Right to Lodge a Complaint
If you believe your data has been processed unlawfully, you may lodge a complaint with your local supervisory authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD). We are also happy to assist you directly at hello@allincosta.com.
Children’s Data
Our services are not directed to individuals under the age of 16, and we do not knowingly collect data from minors.
Automated Decision-Making
We do not engage in automated decision-making or profiling that produces legal or significant effects on individuals.
Last updated: 10 October 2025