Privacy Policy
The Owner respects the privacy of the users of the website www.kalinaadvisory.com (the “Website”) and is committed to protecting their personal data. This Privacy Policy explains, in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”) and Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the Guarantee of Digital Rights (“LOPDGDD”), who is responsible for the processing of your personal data, what data we process, for what purposes and on what legal basis, with whom we share it, how long we keep it, and the rights available to you.
This Privacy Policy must be read together with the Legal Notices and the Cookie Policy.
- Data controller
- The controller responsible for the processing of the personal data collected through the Website is Sergei Kalina (the “Controller”, “we” or “us”), a self-employed professional practising under the trade name Kalina Advisory.
- The Controller’s identifying and contact details are: NIE Z0753478A; address Calle de la Antracita 10, 28045 Madrid, Spain; email info@kalinaadvisory.com.
- Given the nature, scope, context and purposes of the processing carried out, the Controller is not required to appoint a Data Protection Officer under Article 37 GDPR, and has not appointed one. Any matter relating to the protection of personal data may be addressed to the Controller using the contact details above.
- Categories of personal data we process
- We process only the personal data that is adequate, relevant and limited to what is necessary for the purposes described in this Policy. Depending on your interaction with the Website, we may process the following categories of data:
- identifying data: name and surname;
- contact data: email address, telephone number and postal address where provided;
- professional data: company, position and any other professional information you include in your communications;
- economic and billing data: where a professional engagement is established, the data necessary for the issue of invoices and compliance with tax and accounting obligations;
- data contained in your communications: the content of the messages, queries and documentation you send us; and
- browsing data: technical data relating to your navigation of the Website, in the terms described in the Cookie Policy.
- We do not request or process, through the Website, special categories of personal data (such as data revealing health, ideology, religion, racial or ethnic origin), and we ask you not to provide such data.
- You are responsible for the truthfulness and accuracy of the data you provide, and undertake to keep it up to date. Where you provide personal data of third parties (for example, your employees or contacts), you warrant that you have informed them and obtained their consent for the communication of their data to the Controller for the purposes described in this Policy.
- We process only the personal data that is adequate, relevant and limited to what is necessary for the purposes described in this Policy. Depending on your interaction with the Website, we may process the following categories of data:
- Purposes and legal basis of the processing
- We process your personal data for the following purposes and on the corresponding legal bases under Article 6 GDPR:
- to attend to and respond to the enquiries, requests and communications you send us through the contact form or by email — legal basis: your consent and the application, at your request, of pre-contractual measures (Articles 6(1)(a) and 6(1)(b) GDPR);
- to provide the contracted professional services and manage the client relationship, where a professional engagement is established — legal basis: performance of the contract (Article 6(1)(b) GDPR);
- to issue and manage invoices and to comply with the accounting, tax and other legal obligations to which the Controller is subject — legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR);
- to manage and maintain the security, integrity and proper functioning of the Website — legal basis: the legitimate interest of the Controller in ensuring the security of the Website (Article 6(1)(f) GDPR); and
- where you have expressly consented, to send you information about our services that may be of interest to you — legal basis: your consent (Article 6(1)(a) GDPR), which you may withdraw at any time.
- We do not adopt decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
- We process your personal data for the following purposes and on the corresponding legal bases under Article 6 GDPR:
- Obligation to provide data and consequences of failure to do so
- The personal data we request is necessary for the purposes indicated. Its provision is voluntary; however, the fields identified as required must be completed.
- Failure to provide the required data will prevent us from attending to your enquiry, managing your request or, where applicable, providing the requested service.
- Recipients and data processors
- As a general rule, your personal data will not be communicated to third parties, save where required by law or where necessary for the management of the relationship or the provision of the service.
- In order to provide its services, the Controller may rely on third-party providers who access personal data on its behalf and act as data processors (for example, web hosting and email providers). With each of them the Controller has entered into, or will enter into, a data processing agreement complying with Article 28 GDPR, under which the provider processes the data solely on the Controller’s documented instructions and applies appropriate security measures.
- Personal data may also be communicated to public administrations, authorities and bodies where required by an applicable legal obligation (for example, to the tax authorities).
- International transfers
- The Controller does not carry out international transfers of personal data. All processing, including that carried out by its data processors, takes place within the European Economic Area (EEA).
- Should it become necessary in the future to use providers that process data outside the EEA, the Controller will adopt the appropriate safeguards provided for in Chapter V GDPR (such as an adequacy decision of the European Commission or the Standard Contractual Clauses) and will update this Policy accordingly.
- Retention period
- We will retain your personal data for as long as necessary to fulfil the purpose for which it was collected and, thereafter, duly blocked, for the periods required to meet any legal obligations and to address any liability that may arise from the processing.
- In particular: data relating to enquiries that do not give rise to a contractual relationship will be deleted once the corresponding communication has concluded; and data relating to professional engagements will be retained for the duration of the relationship and, subsequently, for the periods required by applicable tax, accounting and commercial legislation (as a general rule, up to six years), after which it will be securely deleted or anonymised.
- Source of the data
- As a general rule, the personal data we process is provided directly by you, through the Website or in the course of our professional communications.
- Where we lawfully obtain your contact details from another source — for example, a professional referral, a public professional directory or a business card you have provided — we process the categories of data described above for the purpose of contacting you in a professional context, on the basis of our legitimate interest, and we inform you of the processing in accordance with Article 14 GDPR.
- Confidentiality and security measures
- The Controller treats personal data with the utmost confidentiality and professional discretion.
- The Controller has implemented the technical and organisational measures appropriate to the risk, in accordance with Article 32 GDPR, to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, and has procedures in place to deal with any security breach and, where legally required, to notify it to the competent supervisory authority and to the affected data subjects.
- Minors
- The Website and its services are not directed at minors. In accordance with Article 7 LOPDGDD, the processing of the personal data of a minor may be based on their consent only where they are over 14 years of age; for minors under that age, consent must be given by a parent or legal guardian.
- The Controller does not knowingly process the personal data of minors under 14. Should the Controller become aware that it holds such data without the corresponding authorisation, it will delete it without delay.
- Processing through social media
- Where the Controller maintains profiles on social networks, it acts as controller in respect of the data of the followers and users who interact with those profiles, for the purpose of managing its professional presence and responding to interactions.
- The processing carried out within each platform is also governed by the terms of use and privacy policies of the platform concerned, over which the Controller has no control; we recommend that you review them.
- Your rights
- You may exercise the following rights in relation to your personal data, free of charge:
- right of access, to obtain confirmation as to whether we are processing your data and, if so, a copy of it;
- right of rectification of inaccurate or incomplete data;
- right of erasure (“right to be forgotten”) of your data where the conditions provided for by law are met;
- right to restriction of processing in the cases provided for by the GDPR;
- right to object to processing based on legitimate interest and, in particular, to direct marketing;
- right to data portability, to receive your data in a structured, commonly used and machine-readable format; and
- right to withdraw, at any time, any consent given, without affecting the lawfulness of the processing carried out before its withdrawal.
- You may exercise the following rights in relation to your personal data, free of charge:
- How to exercise your rights
- You may exercise these rights by writing to info@kalinaadvisory.com, indicating the right you wish to exercise and enclosing a copy of a document evidencing your identity.
- We will respond to your request within the period established by law (as a general rule, one month from receipt, extendable by two further months in the cases provided for in the GDPR, of which we will inform you).
- If you consider that the processing of your personal data does not comply with applicable legislation, or that your rights have not been properly satisfied, you are entitled to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos — AEPD, C/ Jorge Juan 6, 28001 Madrid; www.aepd.es), without prejudice to any other administrative or judicial remedy.
- Changes to this Privacy Policy
- The Controller may update this Privacy Policy to reflect changes in its processing activities or in applicable legislation.
- Any change will be published on this page with its corresponding update date and, where the change is significant, notified by appropriate means. We recommend reviewing this Policy periodically.
Last updated: 1 August 2026