Privacy Policy
The Owner respects the privacy of the users of the website www.kalinaadvisory.com (the “Website”), and of the clients and other individuals whose personal data it processes, and is committed to protecting their personal data. This Privacy Policy explains, in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”) and Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the Guarantee of Digital Rights (“LOPDGDD”), who is responsible for the processing of your personal data, what data we process, for what purposes and on what legal basis, with whom we share it, how long we keep it, and the rights available to you.
This Privacy Policy must be read together with the Legal Notices and the Cookie Policy.
- Data controller
- The controller responsible for the processing of the personal data collected through the Website is Sergei Kalina (the “Controller”, “we” or “us”), a self-employed professional practising under the trade name Kalina Advisory.
- The Controller’s identifying and contact details are: NIE Z0753478A; address Calle de la Antracita 10, 28045 Madrid, Spain; email info@kalinaadvisory.com.
- Given the nature, scope, context and purposes of the processing carried out, the Controller is not required to appoint a Data Protection Officer under Article 37 GDPR and Articles 34 to 37 of the LOPDGDD, and has not appointed one. Any matter relating to the protection of personal data may be addressed to the Controller using the contact details above.
- Categories of personal data we process
- We process only the personal data that is adequate, relevant and limited to what is necessary for the purposes described in this Policy. Depending on your interaction with the Website or your engagement of our services, we may process the following categories of data:
- identifying data: name and surname;
- contact data: email address, telephone number and postal address where provided;
- professional data: company, position and any other professional information you include in your communications;
- economic and billing data: where a professional engagement is established, the data necessary for the issue of invoices and compliance with tax and accounting obligations;
- data contained in your communications: the content of the messages, queries and documentation you send us;
- browsing data: technical data relating to your navigation of the Website, in the terms described in the Cookie Policy; and
- identity-verification and compliance data: where an engagement so requires, copies of identity documents (passport, NIE), beneficial-ownership information and source-of-funds information, processed to comply with client due diligence and anti-money-laundering obligations.
- We do not request or process, through the Website, special categories of personal data (such as data revealing health, ideology, religion, racial or ethnic origin), and we ask you not to provide such data.
- You are responsible for the truthfulness and accuracy of the data you provide, and undertake to keep it up to date. Where you provide personal data of third parties (for example, your employees, contacts or beneficial owners), you warrant that you have informed them and obtained their consent, where required, for the communication of their data to the Controller for the purposes described in this Policy.
- We process only the personal data that is adequate, relevant and limited to what is necessary for the purposes described in this Policy. Depending on your interaction with the Website or your engagement of our services, we may process the following categories of data:
- Purposes and legal basis of the processing
- We process your personal data for the following purposes and on the corresponding legal bases under Article 6 GDPR:
- to attend to and respond to the enquiries, requests and communications you send us through the contact form or by email — legal basis: your consent and the application, at your request, of pre-contractual measures (Articles 6(1)(a) and 6(1)(b) GDPR);
- to provide the contracted professional services and manage the client relationship, where a professional engagement is established — legal basis: performance of the contract (Article 6(1)(b) GDPR);
- to issue and manage invoices and to comply with the accounting, tax and other legal obligations to which the Controller is subject — legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR);
- to carry out client due diligence, identity verification, sanctions screening and source-of-funds checks and to comply with anti-money-laundering obligations — legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR), in particular under Law 10/2010, of 28 April, on the prevention of money laundering and the financing of terrorism;
- to manage and maintain the security, integrity and proper functioning of the Website — legal basis: the legitimate interest of the Controller in ensuring the security of the Website (Article 6(1)(f) GDPR); and
- where you have expressly consented, to send you information about our services that may be of interest to you — legal basis: your consent (Article 6(1)(a) GDPR), which you may withdraw at any time.
- We do not adopt decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
- We process your personal data for the following purposes and on the corresponding legal bases under Article 6 GDPR:
- Obligation to provide data and consequences of failure to do so
- The personal data we request is necessary for the purposes indicated. Its provision is voluntary; however, the fields identified as required must be completed, and, in the case of an engagement, the identity-verification information required by anti-money-laundering legislation must be provided.
- Failure to provide the required data will prevent us from attending to your enquiry, managing your request or, where applicable, providing the requested service.
- Recipients and data processors
- As a general rule, your personal data will not be communicated to third parties, save where required by law or where necessary for the management of the relationship or the provision of the service.
- In order to provide its services, the Controller may rely on third-party providers who access personal data on its behalf and act as data processors (for example, web hosting and email providers). With each of them the Controller has entered into, or will enter into, a data processing agreement complying with Article 28 GDPR, under which the provider processes the data solely on the Controller’s documented instructions and applies appropriate security measures.
- Where the delivery of the services so requires, personal data may also be shared with the licensed partner firms (for example, law, tax or corporate-services firms) engaged to perform regulated services. The role of each partner (controller, joint controller or processor) is determined by the actual nature of the processing, and appropriate data-protection terms are agreed with each of them. Some of these partners are located outside the EEA, in which case the section “International transfers” below applies.
- Personal data may also be communicated to public administrations, authorities and bodies where required by an applicable legal obligation (for example, to the tax authorities or under anti-money-laundering legislation).
- International transfers
- Where the delivery of the services requires the involvement of partner firms located outside the EU/EEA personal data may be transferred to those partners solely for the purpose of delivering the requested services.
- Any such transfer is carried out subject to the appropriate safeguards required by Chapter V of the GDPR, in particular the Standard Contractual Clauses adopted by the European Commission or, where applicable, an adequacy decision or another safeguard permitted by the GDPR. You may request further information on the safeguards applied, and a copy where available, by writing to info@kalinaadvisory.com.
- Personal data collected solely through the Website (for example, data submitted through the contact form) that does not relate to such an engagement is processed within the EEA.
- Retention period
- We retain your personal data only for as long as necessary to fulfil the purpose for which it was collected and, thereafter, duly blocked in accordance with Article 32 of the LOPDGDD, for the periods during which any liability may arise from the processing.
- In particular: (i) data relating to enquiries that do not give rise to a contractual relationship is deleted once the corresponding communication has concluded; (ii) accounting and commercial documentation is retained for six years in accordance with Article 30 of the Commercial Code (Código de Comercio); (iii) documentation with tax relevance is retained for the limitation periods provided for in Article 66 of the General Tax Law (Law 58/2003); and (iv) identity documents (passport copies, NIE) and other personal data obtained in the course of an engagement that do not form part of mandatory accounting records are securely and irreversibly deleted no later than five years after the end of the engagement, in accordance with Article 32 of the LOPDGDD and the limitation period for personal actions under Article 1964 of the Civil Code (Código Civil).
- Each category of data is retained only for its respective applicable period, after which it is securely deleted or anonymised.
- Source of the data
- As a general rule, the personal data we process is provided directly by you, through the Website or in the course of our professional communications.
- Where we lawfully obtain your contact details from another source — for example, a professional referral, a public professional directory or a business card you have provided — we process the categories of data described above for the purpose of contacting you in a professional context, on the basis of our legitimate interest, and we inform you of the processing in accordance with Article 14 GDPR.
- Confidentiality and security measures
- The Controller treats personal data with the utmost confidentiality and professional discretion.
- The Controller has implemented the technical and organisational measures appropriate to the risk, in accordance with Article 32 GDPR, to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, and has procedures in place to deal with any security breach and, where legally required, to notify it to the competent supervisory authority and to the affected data subjects.
- Minors
- The Website and its services are not directed at minors. In accordance with Article 7 LOPDGDD, the processing of the personal data of a minor may be based on their consent only where they are over 14 years of age; for minors under that age, consent must be given by a parent or legal guardian.
- The Controller does not knowingly process the personal data of minors under 14. Should the Controller become aware that it holds such data without the corresponding authorisation, it will delete it without delay.
- Processing through social media
- Where the Controller maintains profiles on social networks, it acts as controller in respect of the data of the followers and users who interact with those profiles, for the purpose of managing its professional presence and responding to interactions.
- The processing carried out within each platform is also governed by the terms of use and privacy policies of the platform concerned, over which the Controller has no control; we recommend that you review them.
- Your rights
- You may exercise the following rights in relation to your personal data (Articles 15 to 22 GDPR, as developed by Articles 12 to 18 of the LOPDGDD), free of charge:
- right of access, to obtain confirmation as to whether we are processing your data and, if so, a copy of it;
- right of rectification of inaccurate or incomplete data;
- right of erasure (“right to be forgotten”) of your data where the conditions provided for by law are met;
- right to restriction of processing in the cases provided for by the GDPR;
- right to object to processing based on legitimate interest and, in particular, to direct marketing;
- right to data portability, to receive your data in a structured, commonly used and machine-readable format; and
- right to withdraw, at any time, any consent given, without affecting the lawfulness of the processing carried out before its withdrawal.
- You may exercise the following rights in relation to your personal data (Articles 15 to 22 GDPR, as developed by Articles 12 to 18 of the LOPDGDD), free of charge:
- How to exercise your rights
- You may exercise these rights by writing to info@kalinaadvisory.com, indicating the right you wish to exercise and enclosing a copy of a document evidencing your identity.
- We will respond to your request within the period established by law (as a general rule, one month from receipt, extendable by two further months in the cases provided for in the GDPR, of which we will inform you).
- If you consider that the processing of your personal data does not comply with applicable legislation, or that your rights have not been properly satisfied, you are entitled to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos — AEPD, C/ Jorge Juan 6, 28001 Madrid; www.aepd.es), without prejudice to any other administrative or judicial remedy.
- Changes to this Privacy Policy
- The Controller may update this Privacy Policy to reflect changes in its processing activities or in applicable legislation.
- Any change will be published on this page with its corresponding update date and, where the change is significant, notified by appropriate means. We recommend reviewing this Policy periodically.
Last updated: 1 August 2026