Legal
Privacy Policy
This policy explains how the Spain RegTech Initiative processes personal data in line with the EU General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Last updated: 2026-07-10
1. Data Controller
The Spain RegTech Initiative (Iniciativa RegTech España) is an independent industry initiative founded by Andréas Hobbelin, based in Málaga, Spain. For any privacy request, contact us at ah@airi.no.
2. Personal data we process
- Contact and application data you submit via forms (name, email, organisation, role, website, message).
- Event registration data when you sign up for or join a waitlist for events.
- Directory data — publicly available business information about organisations and professionals we independently map.
- Technical data — IP address, browser type and basic request metadata, processed by our hosting provider for security and abuse prevention.
We do not use advertising cookies, cross-site tracking or behavioural profiling.
3. Purposes and legal bases (Art. 6 GDPR)
- Respond to your enquiries and applications — legal basis: your consent and pre-contractual steps (Art. 6(1)(a) and (b)).
- Manage event participation and waitlists — legal basis: consent and legitimate interest in operating the initiative (Art. 6(1)(a) and (f)).
- Maintain an independent directory of RegTech companies operating in Spain — legal basis: legitimate interest in advancing industry transparency (Art. 6(1)(f)). Listings use publicly available business information and do not imply endorsement.
- Site security, integrity and abuse prevention — legal basis: legitimate interest (Art. 6(1)(f)).
- Compliance with legal obligations — legal basis: Art. 6(1)(c).
4. Retention
We retain personal data only as long as necessary for the purpose it was collected: contact and application data for up to 24 months after last interaction; event data until the event and any follow-up communication is complete; technical logs for a short rolling window for security purposes.
5. Recipients and processors
We use trusted service providers (processors) to operate the website and back-end, bound by data processing agreements. These include cloud hosting and database providers within the EU/EEA. We do not sell personal data. We do not share data with third parties for advertising.
6. International transfers
Where a processor is located outside the EU/EEA, transfers rely on adequacy decisions or Standard Contractual Clauses (SCCs) approved by the European Commission, with supplementary measures where required.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict or object to processing, data portability, and to withdraw consent at any time. To exercise these rights, email ah@airi.no. You may also lodge a complaint with the Spanish Data Protection Agency (AEPD).
8. Directory listings and removal requests
Directory entries about organisations are compiled from public sources and describe legal entities, not natural persons. If a listing references you personally (e.g. as a named founder) and you wish to correct or remove that reference, email us and we will action the request without undue delay.
9. Security
We apply appropriate technical and organisational measures — including encryption in transit, access controls, and hardened infrastructure — to protect personal data against unauthorised access, loss or alteration.
10. Children
The website is not directed to children under 14 and we do not knowingly collect their data.
11. Changes to this policy
We may update this policy to reflect legal or operational changes. The "Last updated" date above indicates the current version.
12. Related policies
See our Cookie Policy for information about cookies and similar technologies.
