Privacy Policy
This is a courtesy translation. The Spanish-language version of this document is the official and prevailing version. In the event of any discrepancy, the Spanish text prevails.
UnoRed — unored.es
Last updated: 1st September 2026
1. Who is the data controller
Controller | Arjun Chhabra (trade name: UnoRed) |
NIF | Y7385955W |
Registered address | Calle Cadenas de San Gregorio 8, 47011 Valladolid, Castilla y León, Spain |
legal(at)unored(dot)es | |
Website | https://unored.es |
Data Protection Officer | Appointment is not required under article 37 of the GDPR or article 34 of the LOPDGDD (the Spanish Data Protection Act). For any matter relating to data protection, please write to legal(at)unored(dot)es |
At UnoRed we process personal data in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”), with Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales (“LOPDGDD”) and with the remaining applicable legislation.
2. Dual capacity: controller and processor
It is important to distinguish two different situations:
a) UnoRed as data controller. When we process data of website visitors, persons requesting information, prospective clients, clients, suppliers and collaborators for our own purposes, we act as controller. This Privacy Policy governs that processing.
b) UnoRed as data processor. When we provide our services to a client, we process data of that client’s customers and contacts (for example, the persons who call their business, who book an appointment or who appear in their database). In those cases the data controller is the client, and UnoRed acts exclusively on behalf of and following the documented instructions of the client, under the terms of article 28 of the GDPR and of the processing agreement signed with the client. If you are a customer or contact of a business that uses UnoRed and you wish to exercise your rights, you should contact that business; if you write to us, we will forward your request to the controller without undue delay.
3. Where we obtain your data
We process data that comes from:
You, when you complete a form on the website, request the free report, book a call, subscribe to our communications, write to us by email, instant messaging or social media, or call us by telephone.
The company or business you represent, when it provides us with your professional contact details.
Publicly accessible sources and professional sources, within the framework of our commercial prospecting directed at businesses and professionals: commercial and public registers, business directories, public business profiles, corporate websites and professional social networks.
Referrals and recommendations from third parties who put us in contact with you in your professional capacity.
Your browsing on the website, by means of cookies and similar technologies, under the terms of our Cookie Policy.
In the case of data obtained from sources other than the data subject, we will inform you in the first communication we address to you, in accordance with article 14 of the GDPR and article 11.3 of the LOPDGDD.
4. What data we process
Depending on the case, we may process the following categories of data:
Identifying and professional contact data: first name and surname, position or role, business name, NIF/CIF, postal address of the business, telephone, mobile telephone, email.
Professional activity data: sector, location, size, online presence, website, business profile, public reviews and business visibility data, obtained for the preparation of the free report.
Commercial and contractual relationship data: services contracted, plan, conditions, communications exchanged, incidents, support history.
Financial and billing data: tax details, amounts, method of payment, bank details necessary for direct debit or collection, and payment status. We do not store full payment card data; card payments are processed directly by a certified payment gateway.
Communications data: content of email messages, forms, instant messaging and chat, and, where applicable, recordings and transcriptions of telephone calls under the terms of section 6.
Browsing data: IP address, device identifiers, browser type and operating system, pages visited, time spent, source of the visit and interactions, obtained by means of cookies subject to prior consent.
Data necessary for the contracting and activation of electronic communications services, where the client decides to contract them: line ownership data, installation address, telephone number to be retained in the event of number portability, and identity verification documentation required by sectoral legislation.
We do not process special categories of data (article 9 of the GDPR: health, ethnic origin, beliefs, trade union membership, biometric data for identification purposes, etc.) or data relating to criminal convictions and offences. We ask you not to provide us with this type of information. If it should incidentally come to our knowledge, we will delete it unless there is a legal obligation to the contrary.
5. Why we process your data and on what legal basis
5.1 Handling enquiries and requests for information
Purpose: to manage and respond to enquiries submitted through the contact form, email, the website chat, instant messaging or our social media; and to maintain the history of the communication.
Legal basis: the application of pre-contractual measures at the data subject’s request (art. 6.1.b GDPR). Where the enquiry does not lead to a contractual relationship, our legitimate interest in handling and documenting the communications received (art. 6.1.f GDPR). In the case of contact data of natural persons providing services within a legal entity, or of sole traders and liberal professionals acting in that capacity, the presumption of article 19 of the LOPDGDD applies.
5.2 Preparation and delivery of the Free Business Report
Purpose: to analyse the online presence of the applicant’s business —business profile in search engines, performance and visibility of their website, local ranking, reviews, accuracy of the business data published on the internet and a comparison with up to three competing businesses—, to prepare the corresponding report, to deliver it to you and to discuss it with you.
Legal basis: the application of pre-contractual measures at the data subject’s request (art. 6.1.b GDPR).
The report is prepared on the basis of publicly accessible information about businesses and of the data you provide to us. The report relates to businesses and does not contain assessments of natural persons. Delivery of the report is free of charge and does not give rise to any obligation to contract.
5.3 Booking and holding meetings and calls
Purpose: to manage the diary, to confirm and remind of appointments arranged through the booking calendar on the website, and to hold the meeting or call.
Legal basis: the application of pre-contractual measures at the data subject’s request (art. 6.1.b GDPR).
5.4 Subscription to informative and commercial communications
Purpose: to send you information, content, news, invitations to events and workshops, and offers regarding our services, by email or by other equivalent electronic means.
Legal basis: your express, freely given, specific and informed consent (art. 6.1.a GDPR and art. 21.1 of the LSSI-CE), which you may withdraw at any time without this affecting the lawfulness of prior processing.
If you are already a client, we may send you communications about our own services similar to those contracted on the basis of our legitimate interest (art. 6.1.f GDPR) and of article 21.2 of the LSSI-CE. In any event, you will have a simple and free-of-charge objection procedure in each communication and at the time the data is collected.
Before carrying out commercial prospecting without consent, we consult the advertising exclusion systems provided for in article 23 of the LOPDGDD, including the Lista Robinson.
5.5 Commercial prospecting directed at businesses and professionals
Purpose: to contact businesses and professionals who may be interested in our services, using professional contact data obtained from public or professional sources.
Legal basis: our legitimate interest in the development of our business activity (art. 6.1.f GDPR), in relation to the presumption established in article 19 of the LOPDGDD for professional contact data. We have carried out and documented the corresponding balancing of interests, a summary of which you may request from us at legal(at)unored(dot)es.
This processing is limited to the data strictly necessary for professional contact purposes and to the purpose of maintaining relations with the company or professional activity. You may object at any time, and we will act on your objection immediately and free of charge. Commercial communications are sent by electronic means only in the cases permitted by article 21 of the LSSI-CE.
5.6 Management of the contractual relationship with clients
Purpose: to formalise and perform the services contract; to set up, configure and maintain the services contracted; to provide support and client care; to manage incidents and complaints; and to manage the relationship in general.
Legal basis: performance of the contract to which the data subject is party or of the relationship maintained with the company the data subject represents (art. 6.1.b GDPR) and, in respect of the client’s contact persons, our legitimate interest in maintaining the relationship with that company (art. 6.1.f GDPR and art. 19 LOPDGDD).
5.7 Invoicing, collection and tax and accounting obligations
Purpose: to issue invoices, manage collections and payments, keep the accounts and comply with applicable tax and commercial obligations.
Legal basis: compliance with legal obligations applicable to the controller (art. 6.1.c GDPR), in particular Ley 58/2003, General Tributaria (Spanish General Taxation Act), Real Decreto 1619/2012 governing invoicing obligations and the accounting and commercial legislation in force.
5.8 Contracting, activation and management of electronic communications services
Purpose: to process the activation, provisioning, number portability, modification and termination of the mobile telephony and internet access lines included in the client’s plan, and to manage the associated incidents.
Legal basis: performance of the contract (art. 6.1.b GDPR) and compliance with legal obligations arising from sectoral telecommunications legislation (art. 6.1.c GDPR), in particular Ley 11/2022, de 28 de junio, General de Telecomunicaciones (Spanish General Telecommunications Act) and its implementing legislation.
In order to physically provide the connectivity service, it is essential to communicate the necessary data to a duly authorised electronic communications operator with which UnoRed has a wholesale agreement, as well as to the operators involved in number portability processes. Without such communication it is not possible to activate or maintain the service.
5.9 Service communications and notifications
Purpose: to send you operational and service notices necessary for the proper performance of the contract: confirmations, appointment reminders, incident notices, notifications of contractual or price modifications and billing communications.
Legal basis: performance of the contract (art. 6.1.b GDPR) and compliance with legal obligations (art. 6.1.c GDPR). These communications are not commercial communications and cannot be disabled for the duration of the contractual relationship, as they are necessary for the provision of the service.
5.10 Recording and transcription of calls
Purpose: where applicable, to document the contracting process, to evidence the consent given, to improve service quality and to have proof of the instructions received.
Legal basis: your specific consent for each call (art. 6.1.a GDPR) or, where applicable, compliance with a legal obligation to evidence telephone contracting (art. 6.1.c GDPR).
We will always inform you at the start of the call and before recording begins, and we will maintain a perceptible notice while the recording is active. Consent relates solely to the specific call and expires at the end of that call: it does not authorise future recordings. You may refuse to be recorded without this entailing any detriment or preventing your request from being handled by another means. See section 6 for further detail.
5.11 Website, security and analytics
Purpose: to ensure the operation and security of the website, to prevent fraudulent or abusive use, and —subject to prior consent— to analyse use of the site and measure the effectiveness of our advertising activities.
Legal basis: our legitimate interest in the security of our systems and in fraud prevention (art. 6.1.f GDPR) for technical cookies and security logs; and your consent (art. 6.1.a GDPR and art. 22.2 of the LSSI-CE) for analytics, personalisation and advertising cookies. See the Cookie Policy.
5.12 Publication of success stories, testimonials and the Founding Members page
Purpose: to publish the name, logo, image, testimonial or success story of clients on our website, commercial materials and social media.
Legal basis: your express and specific consent (art. 6.1.a GDPR), obtained in writing and revocable at any time. No client will be included without their prior and express authorisation.
5.13 Management of suppliers and collaborators
Purpose: to manage the relationship with suppliers, collaborators, trainers and speakers.
Legal basis: performance of the contract or of the pre-contractual relationship (art. 6.1.b GDPR), legitimate interest in managing the relationship (art. 6.1.f GDPR) and compliance with legal obligations (art. 6.1.c GDPR).
5.14 Exercise and defence of claims
Purpose: to respond to requests from authorities and courts, and to bring or defend claims.
Legal basis: compliance with legal obligations (art. 6.1.c GDPR) and legitimate interest in the defence of our rights (art. 6.1.f GDPR).
6. Call recording and use of artificial intelligence voice agents
When you call a telephone number managed by UnoRed, the call may be answered by an artificial intelligence voice agent. In such a case:
You will be informed clearly and from the outset of the interaction that you are speaking with an artificial intelligence system and not with a person, in accordance with article 50.1 of Regulation (EU) 2024/1689.
You will be informed whether the call is to be recorded and/or transcribed, of the purpose and of the retention period, and your consent will be obtained before recording begins.
You may request at any time to speak with a person or to continue through another channel.
Automatic transcription systems may contain errors. You have the right to request access to the recording or transcription and its rectification without undue delay (arts. 15 and 16 of the GDPR).
We do not use voice recognition systems to uniquely identify individuals (biometric data under art. 9 GDPR) or emotion detection or inference systems.
We contractually require our technology providers not to use the content of calls, the recordings or the transcriptions to train their own models.
Further information is available in our Policy on Transparency in the Use of Artificial Intelligence.
7. How long we keep your data
Processing | Retention period |
Enquiries not leading to a contract | 1 year from the last interaction |
Free business report | 1 year from its delivery |
Unconverted call bookings | 1 year from the scheduled date |
Subscription to commercial communications | Until consent is withdrawn or the subscription is cancelled; the unsubscribe data is kept in blocked form to evidence the objection |
Commercial prospecting | Until the data subject objects and, in any event, a maximum of 1 year from the last contact without response |
Client data and contractual relationship data | For the term of the contract and, after its termination, blocked for the limitation periods for bringing actions (generally 5 years in accordance with art. 1964 of the Código Civil (Spanish Civil Code)) |
Invoicing, accounting and tax data | 6 years (art. 30 of the Código de Comercio (Spanish Commercial Code)) and 4 years for tax purposes from the end of the filing period (art. 66 of the Ley General Tributaria), the longer period applying |
Data relating to the contracting of electronic communications services | For the term of the line and the periods required by sectoral legislation and by the data retention legislation applicable to operators |
Call recordings and transcriptions | Maximum 6 months, unless they are necessary as evidence of a contract or of a claim, in which case they will be kept blocked until its final resolution |
Consents for testimonials and success stories | Until revoked; once consent is withdrawn, the content is unpublished |
Website security logs | 12 months |
Cookies | As indicated for each cookie in the Cookie Policy |
Once the periods indicated have elapsed, the data is blocked —remaining available exclusively to judges, courts, the Public Prosecutor’s Office and the competent Public Administrations— for the limitation period for bringing actions, and is definitively deleted at the end of that period.
8. To whom we disclose your data
We do not sell, rent or transfer your personal data to third parties for commercial purposes. We disclose data only where necessary, and to the following categories of recipients:
a) Data processors who provide us with services and process data following our instructions, under a contract in accordance with article 28 of the GDPR:
Providers of client management platforms, marketing automation, booking calendars, messaging, cloud telephony and conversational artificial intelligence.
Providers of web hosting, website building, email and cloud storage.
Providers of electronic signature and document management services.
Providers of IT support and security.
b) Recipients of data disclosures acting as independent controllers:
The duly authorised electronic communications operator with which UnoRed has a wholesale agreement and the operators involved in number portability processes, exclusively where the client contracts connectivity services and for their processing, activation and maintenance.
Financial institutions and payment service providers, for the management of collections and payments.
Tax, accounting and employment advisers, and lawyers or court representatives, where necessary.
Public Administrations, supervisory authorities, Law Enforcement Agencies, judges and courts, where there is a legal obligation.
Insurance companies, where applicable, for the management of claims.
If you wish to know the specific identity of the providers involved in each processing activity, you may request this from us at legal(at)unored(dot)es and we will provide it.
9. International data transfers
Some of our technology providers are established outside the European Economic Area, mainly in the United States of America.
Where this occurs, we ensure that the transfer is covered by one of the mechanisms provided for in Chapter V of the GDPR:
The European Commission adequacy decision of 10 July 2023 relating to the EU-U.S. Data Privacy Framework, where the provider is certified under that framework (art. 45 GDPR); or
The Standard Contractual Clauses approved by the European Commission by Implementing Decision (EU) 2021/914, supplemented, where necessary, by the additional measures derived from the corresponding transfer impact assessment (arts. 46.2.c and 46 GDPR).
You may request a copy of the safeguards applied or information on where to consult them by writing to legal(at)unored(dot)es.
10. Automated decisions and profiling
We do not take decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you, within the meaning of article 22 of the GDPR.
We use automated tools to segment communications, prioritise enquiries, schedule reminders and prepare the free business report. The plan recommendation and the decision on contracting are always taken with human intervention.
If in the future we were to incorporate processing involving automated decisions with the effects of article 22 of the GDPR, we would inform you beforehand, indicating the logic applied and its consequences, and we would guarantee your right to obtain human intervention, to express your point of view and to contest the decision.
11. What your rights are
You may exercise the following rights at any time and free of charge:
Access: to know whether we process your data and to obtain a copy of it.
Rectification: to correct inaccurate data or complete incomplete data.
Erasure (“right to be forgotten”): to request the deletion of your data where it is no longer necessary or where one of the legally provided grounds applies.
Objection: to object to processing based on our legitimate interest on grounds relating to your particular situation; and, in the case of direct marketing, to object at any time and without giving reasons, after which we will cease processing your data for that purpose.
Restriction of processing: to request that we suspend processing in the cases set out in article 18 of the GDPR.
Portability: to receive your data in a structured, commonly used and machine-readable format, and to transmit it to another controller, where processing is based on your consent or on a contract and is carried out by automated means.
Not to be subject to automated individual decisions with legal or similar effects.
To withdraw consent at any time, without this affecting the lawfulness of processing prior to its withdrawal.
How to exercise them: send a request to legal(at)unored(dot)es or in writing to the postal address indicated in section 1, stating the right you wish to exercise and enclosing a copy of a document evidencing your identity. We will respond within a maximum period of one (1) month from receipt, extendable by a further two months in the case of particularly complex requests, in which case we will notify you.
Complaint to the supervisory authority: if you consider that the processing of your data does not comply with the legislation, or if you are not satisfied with our response, you may lodge a complaint with the Agencia Española de Protección de Datos (Spanish Data Protection Agency, “AEPD”), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es. We would be grateful if you would first contact us so that we can try to resolve the matter.
12. Data security
We have adopted appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with article 32 of the GDPR, including: encryption of communications (HTTPS/TLS) and of information at rest where appropriate; access control with two-factor authentication; the principle of least privilege; periodic backups; access logging; training and confidentiality undertakings; selection of providers offering sufficient guarantees; and procedures for the detection, notification of and response to security breaches.
In the event of a personal data breach entailing a risk to your rights and freedoms, we will notify the Agencia Española de Protección de Datos within 72 hours and, where the risk is high, we will also inform you without undue delay.
13. Obligation to provide data
The data requested in our forms and marked as mandatory is necessary in order to handle your request or to perform the contract. If you do not provide it, we will not be able to handle your request or provide the service. The remaining data is provided voluntarily.
You warrant that the data you provide to us is truthful, accurate and up to date, and you undertake to notify us of any change. If you provide us with third-party data (for example, of an employee or partner), you warrant that you are entitled to do so and that you have previously informed that person of the content of this Policy.
14. Minors
Our services are directed exclusively at businesses and professionals. We do not knowingly collect data from persons under eighteen (18) years of age. If we became aware that we had collected such data, we would proceed to delete it immediately. If you are a parent or guardian and believe that a minor has provided us with data, please inform us at legal(at)unored(dot)es.
15. Modifications to this Policy
We may update this Privacy Policy to adapt it to changes in legislation, case law, supervisory authority criteria or our own processing activities. The version in force will always be the one published on this page, indicating its date of last update. Where the changes are substantial, we will inform you by an appropriate means before they take effect.
16. Applicable law
This Policy is governed by Regulation (EU) 2016/679, by Ley Orgánica 3/2018, de 5 de diciembre, by Ley 34/2002, de 11 de julio, and by the remaining Spanish and European Union legislation that may be applicable.
