NESTANZA PRIVACY POLICY

EUROCRODA S.L. (hereinafter referred to as “NESTANZA”) is responsible for the processing of your personal data. Accordingly, and in compliance with the applicable data protection legislation, with its registered office at Paseo 26, 1 A, Ourense, Spain, NESTANZA hereby informs you that it will process the personal data and sensitive personal data listed below for the purposes set out in this Privacy Notice.

GLOSSARY

For the purposes of this Privacy Notice, the following terms shall have the meanings set forth below:

• Agency: The Spanish Data Protection Agency (AEPD).

• Constitution: The Constitution of Spain.

• Cookies: Tools used to store user information in digital environments, including display preferences, passwords, browsing activity, and other information that enhances the user’s online experience.

• Directive: Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data.

• Sister Company: Companies with which the Controller may share certain categories of personal data, provided the user has given prior express consent.

• Law: Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights.

• Digital Environment: Any electronic environment, including mobile phones, computers, televisions, or other electronic devices through which users interact with the Controller using any of the contact methods described in this Privacy Notice.

• Regulation: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation – GDPR).

• Controller: NESTANZA, responsible for the protection, use, and processing of the personal data you provide through any of our available communication channels.

• Transfer: The transfer of personal data from Spanish territory to countries outside the European Economic Area (EEA).

• User: Any person who visits our websites or social media profiles, contacts us through digital channels, or uses our services, whose personal data may be collected, stored, processed, transferred, or otherwise handled.

CONTACT INFORMATION

As the Controller responsible for the protection and processing of your personal data, NESTANZA provides the following contact details:

EUROCRODA S.L.
Tax ID (CIF): B16818692
Paseo 26, 1 A
Ourense, Spain

Email: info@nestanza.com

PERSONAL DATA

The categories of personal data that NESTANZA may collect, store, use, and process include, but are not limited to, the following:

• Title
• First name and surname(s)
• National ID Card (DNI), Foreigner Identification Number (NIE), Passport, or any other official identification document
• Residential address
• Date and place of birth
• Biometric information
• Sex and/or gender
• Company or organization to which the user belongs
• Region of the company or organization
• Email address
• Mobile phone number
• Bank account number
• Credit card number
• Academic and professional information
• Interests, hobbies, and leisure activities

The user declares that all personal data provided is true, accurate, complete, current, and has not been altered or falsified.

The user accepts responsibility for any errors that NESTANZA may incur as a result of relying on inaccurate or outdated information.

COLLECTION OF PERSONAL DATA

NESTANZA reserves the right to amend this Privacy Notice at any time. Should any changes occur, users will be notified in writing whenever possible to ensure appropriate disclosure.

All personal data collected will be securely stored in a centralized database with restricted access.

Such information will be processed exclusively by authorized NESTANZA personnel and, where appropriate, by affiliated companies acting in support of the business relationship between the Controller and the user, always respecting the user’s privacy.

METHODS OF DATA COLLECTION

NESTANZA collects personal data through various channels, including but not limited to the following:

• The Controller’s website
• Social media platforms:
– Facebook
– X (formerly Twitter)
– Instagram
– YouTube
– LinkedIn
• Online forms and surveys
• Email and/or telephone communications

Additionally, through its online platforms, NESTANZA may collect cookies, geolocation data (location information), login credentials, and certain biometric data required to authenticate and register access to its platforms.

These remote methods of data collection may be disabled by the user through their browser settings, depending on the browser being used.

PURPOSES OF DATA PROCESSING

This Privacy Notice applies to all personal data held by NESTANZA or collected, stored, processed, or used by the company, regardless of the medium in which such data is stored or the method through which it was obtained.

Personal data will be processed exclusively for the following purposes:

• To establish, maintain, and, where appropriate, improve the legal and commercial relationship between NESTANZA and the user, particularly when such relationship relates to the rental of residential properties.

• To provide users with a wide range of services tailored to their needs, expectations, and budget through statistical analysis and market research.

• To analyze users’ browsing behavior through the use of cookies in order to improve the website experience and provide a more personalized service.

• To notify users of modifications, updates, or improvements to the services they have contracted, provided such communications are directly related to the existing contractual relationship.

• To communicate with users by email, telephone, or any other contact method provided when creating an account on our platforms.

• To ensure the safety and security of the properties and facilities rented or used by the user, as well as the safety of the user, their family members, and third parties, through the use of closed-circuit video surveillance (CCTV) systems.

• To send commercial information regarding our real estate services, promotional campaigns, property offers, market studies, budget updates, newsletters, and other relevant commercial communications.

• To receive, manage, and respond to inquiries, requests, complaints, or claims submitted by users regarding the services provided.

• To transfer personal data to credit reporting agencies when a user fails to pay rent or any other overdue and enforceable obligations owed to NESTANZA. Such transfers shall be carried out in strict compliance with Article 20 of Organic Law 3/2018, always safeguarding the privacy rights of our clients and users.

Personal data provided by users will be stored and retained only for as long as necessary to maintain the legal and commercial relationship described above, unless applicable legislation requires a longer retention period or judicial proceedings require the data to be preserved in order to comply with legal obligations.

Should NESTANZA need to process personal data for any purpose other than those described above, users will be informed in advance through one of the contact methods provided during registration or through any other verified communication channel belonging to the user.

This prior notification constitutes one of the security measures implemented by NESTANZA to protect the privacy, integrity, and security of its users, in accordance with Recital 50 of the General Data Protection Regulation (GDPR).

USER RIGHTS

In accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), users may exercise any of the following rights:

• Request access to the personal data held by NESTANZA.

• Request the rectification or correction of inaccurate or incomplete personal data.

• Request the restriction of the processing of their personal data for the purposes described in this Privacy Notice.

• Request the erasure of their personal data held by the Controller or object to its processing.

• Withdraw their consent at any time for the collection, storage, processing, transfer, or retention of their personal data, without affecting the lawfulness of any processing carried out before such consent was withdrawn.

• Lodge a complaint with the Spanish Data Protection Agency (AEPD) if they consider that the processing of their personal data does not comply with the applicable legislation.

To exercise any of these rights, users must submit a written request to NESTANZA by emailing:

info@nestanza.com

The appropriate request forms will be provided upon request.

The above rights may not be exercised where the processing of personal data is necessary to comply with a legal obligation or for the establishment, exercise, or defense of legal claims.

Furthermore, given the nature of NESTANZA’s commercial activities, users who provide sensitive personal data are informed that they may exercise their rights of Access, Rectification, Erasure, Restriction, Objection, and Data Portability under the applicable data protection legislation.

CONFIDENTIALITY

Due to the nature of NESTANZA’s business operations, personal data stored in its systems may be transferred within Spain, to affiliated companies, and, where necessary, to recipients located outside the European Economic Area (EEA).

Personal data may also be shared with courier services, payment service providers, and public authorities responsible for supervising the quality and legality of the services provided.

Where personal data has been obtained with the data subject’s consent but not directly from the data subject, such transfers shall be carried out in strict compliance with the applicable legal requirements.

During any transfer of personal data, NESTANZA shall implement appropriate technical and organizational security measures to ensure the confidentiality, integrity, and protection of users’ information.

For additional information regarding these security measures, users may contact:

info@nestanza.com

DISCLAIMER OF LIABILITY

NESTANZA shall not be liable for any damages or losses arising from the processing of personal data under the following circumstances:

• When the data subject provides inaccurate, incomplete, false, fabricated, or outdated information, or makes improper use of the contracted services, thereby releasing the Controller from any consequences resulting from such conduct.

• When damages result from acts or omissions of third parties unrelated to the Controller, including unauthorized access, security breaches, or cyberattacks, provided that the Controller has implemented the security measures required by applicable law.

• When non-compliance with data protection obligations is caused by unforeseeable or unavoidable events, including natural disasters, civil unrest, widespread telecommunications failures, or other similar force majeure events.

• When the communication or processing of personal data is necessary to comply with a legal obligation imposed on the Controller, including requests from judicial, administrative, or other governmental authorities.

• When personal data is processed by individuals or entities duly engaged by the Controller, and any failure or breach is solely attributable to those parties, provided that the Controller has exercised due diligence in their selection and supervision in accordance with Article 28 of Regulation (EU) 2016/679.

• When interruptions, errors, or failures in the operation of the system or platform arise from technical causes beyond the Controller’s reasonable control, including failures attributable to technology providers or service providers.

• Where the processing is based on the data subject’s consent, the Controller shall not be liable for the use of the personal data in accordance with the terms accepted by the data subject, except where such processing violates applicable law.

• The Controller does not guarantee the absolute security of data transmitted over the Internet or other open networks. Users acknowledge and accept the inherent risks associated with such communications.

Last Updated: May 12, 2026.

Copyright © 2025 nestanza –
Todos los derechos reservados.