Legal

Privacy Policy

Last updated: 10 July 2026

This Privacy Policy explains how SFERO REAL ESTATE, S.L. (“SFERO”, “we”, “us”) processes personal data of visitors to https://sfero.es (the “Website”) and of clients, owners, buyers, tenants and other individuals in connection with our real estate sales brokerage, residential and commercial leasing, and property development services. It is issued pursuant to Article 13 of the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and Article 11 of Organic Law 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights (“LOPDGDD”), and should be read together with our Legal Notice, Terms and Conditions of Use and Cookie Policy, all available on the Website.

1. Data Controller

Controller: SFERO REAL ESTATE, S.L.

Tax ID (CIF): B75630889

Registered address: Calle Guillem d'Anglesola, 6, escalera B, piso 2, puerta 6, 46022 Valencia, Spain

Companies Register: Registro Mercantil de Valencia, Sección 8, Hoja V-223711, Inscripción 1ª; incorporated on 13 December 2024; sole-shareholder company (unipersonal), sole director Don Oleh Hrechko

Telephone: +34 664 02 87 80

Privacy and general email: [email protected]

Data Protection Officer: the appointment of a Data Protection Officer is not legally required given the scale and nature of the processing carried out by SFERO; data protection queries may be directed to the email above

Website: https://sfero.es

Activity: Real estate sales brokerage, residential and commercial leasing, and property development

Professional licence: No. 4513, Register of Real Estate Intermediation Agents of the Valencian Community (RAICV)

2. What Personal Data We Collect

Depending on the service you request, we may collect the following categories of personal data, directly from you or, where relevant, from the counterparty to a transaction:

  • Identity data: full name, DNI / NIE / passport number, nationality, date of birth.
  • Contact data: postal address, telephone number(s), email address.
  • Financial and solvency data: income information, bank account details and proof of funds, where required by anti-money laundering legislation or for tenancy qualification checks.
  • Property data: address, cadastral reference and characteristics of properties you own, seek to buy, sell or rent.
  • Transactional data: reservation, sale, purchase or lease terms, payment records, and related correspondence.
  • Browsing data: IP address, session identifiers and analytics data collected via cookies (see our Cookie Policy, Section 4).

We do not, as a general rule, collect special categories of personal data (Article 9 GDPR). Where such data becomes necessary in a specific case, we will seek your explicit consent. We do not knowingly collect data from persons under 14 years of age (see Section 8).

3. Purposes, Legal Bases and Retention Periods

a) Enquiries and contact requests

Purpose: to manage and respond to enquiries submitted via contact forms, telephone, email or chat.

Legal basis: legitimate interest of the controller (Art. 6(1)(f) GDPR) and, where applicable, your consent (Art. 6(1)(a) GDPR).

Retention: for the time needed to respond, plus the applicable limitation period for any legal claims (generally 3 years).

b) Pre-contractual and contractual relationship management

Purpose: to formalise and manage sale, purchase, lease and brokerage arrangements, including identity verification, solvency assessment and property qualification checks.

Legal basis: performance of a contract or pre-contractual steps taken at your request (Art. 6(1)(b) GDPR).

Retention: for the duration of the contractual relationship and, thereafter, for the limitation periods applicable under civil, commercial and tax law (generally 5 to 10 years, depending on the obligation).

c) Compliance with legal obligations, including AML/KYC

Purpose: to comply with obligations under anti-money laundering legislation (Law 10/2010, of 28 April, and its implementing Regulation, Royal Decree 304/2014), tax law, and notarial and land-registry rules.

Legal basis: compliance with a legal obligation applicable to the controller (Art. 6(1)(c) GDPR).

As a regulated real estate agent under Law 10/2010, SFERO is legally required, before entering into a professional relationship with a client, to:

  • identify and verify the identity of the client, including, where applicable, the ultimate beneficial owner (UBO) of any corporate client;
  • collect information on the purpose and intended nature of the business relationship, and, where relevant, the origin of funds;
  • apply enhanced due diligence where risk factors so require (for example, politically exposed persons, complex ownership structures, or high-value transactions);
  • report any suspicious transaction to SEPBLAC (the Spanish Financial Intelligence Unit), without informing the client concerned, as required by law (the “no tipping-off” obligation).

Providing false, incomplete or misleading identification or financial information is a criminal offence. SFERO is legally obliged to decline instructions, delay a transaction, or terminate a professional relationship where satisfactory identification and due-diligence documentation cannot be obtained.

Retention: as required by each applicable law; generally ten (10) years for anti-money-laundering documentation, counted from the termination of the business relationship.

d) Direct marketing and commercial communications

Purpose: to send information by electronic means (email, SMS, messaging apps) about new listings, promotions or related services that may be of interest to you.

Legal basis: your prior, express and informed consent (Art. 6(1)(a) GDPR and Art. 21 LSSICE) or, if you are an existing client, our legitimate interest in offering similar products or services (Art. 21(2) LSSICE).

Every commercial communication will clearly identify SFERO as the sender and include a simple, free way to opt out. You may withdraw your consent to receive marketing communications at any time by:

  • clicking the unsubscribe link included in every marketing email;
  • emailing [email protected] with the subject line “UNSUBSCRIBE”; or
  • adjusting your communication preferences in your account settings, where applicable.

Opt-out requests are processed within ten (10) business days. Please note that operational communications relating to an active contract or ongoing enquiry (for example, viewing confirmations, contract documents or payment receipts) are not marketing communications and will continue regardless of any marketing opt-out.

Retention: until you withdraw consent or object to the processing.

e) Service improvement and analytics

Purpose: to analyse how users interact with the Website and our services, to improve content and, where consented, to provide personalised property recommendations.

Legal basis: consent (Art. 6(1)(a) GDPR) for any profiling; legitimate interest (Art. 6(1)(f) GDPR) for aggregate, anonymised analytics.

Retention: for the duration of the user relationship or until consent is withdrawn, subject to a maximum of 3 years from the last interaction.

4. Recipients and Data Transfers

We do not sell personal data. It may be disclosed to third parties only in the following circumstances:

  • Public authorities: tax authorities, the Land Registry, notaries, SEPBLAC (the Spanish anti-money-laundering authority) and other bodies, where legally required.
  • Data processors: technology and hosting providers, legal and accounting advisors, and other service providers acting on our behalf, all bound by a data processing agreement under Article 28 GDPR.
  • Financial institutions: only with your express prior consent, for mortgage or financing referrals.
  • Transaction counterparties: buyers, sellers, landlords or tenants, and their notaries or legal representatives, to the extent strictly necessary to complete a transaction.
  • Collaborating agents: other real estate agents or sub-agents involved in the marketing of a specific property, where cooperation is required to complete a transaction, subject to confidentiality obligations.

International transfers: as a general rule, we do not transfer personal data outside the European Economic Area (EEA). Where a data processor is located outside the EEA, the transfer will be subject to an appropriate safeguard, such as European Commission Standard Contractual Clauses (SCCs) or an adequacy decision.

5. Your Rights as a Data Subject

Under Articles 15 to 22 GDPR and Articles 12 to 18 LOPDGDD, you may exercise the following rights at any time:

  • Access: to know what personal data we hold about you.
  • Rectification: to correct inaccurate or incomplete data.
  • Erasure: to request deletion where, among other grounds, data is no longer necessary for the purpose for which it was collected.
  • Objection: to object to processing for specific purposes, including direct marketing.
  • Restriction: to request suspension of processing in certain circumstances.
  • Portability: to receive your data in a structured, commonly used, machine-readable format.
  • Automated decisions: not to be subject to solely automated decisions, including profiling, with significant legal or similar effects.
  • Withdrawal of consent: at any time, without affecting the lawfulness of processing prior to withdrawal.

To exercise your rights, contact us in writing, with a copy of your identity document, at [email protected] or by post at Calle Guillem d'Anglesola, 6, escalera B, piso 2, puerta 6, 46022 Valencia, Spain, for the attention of Data Protection. We will respond within one month of receipt; where the request is complex, this period may be extended by a further two months, with prior notice. If we refuse a request, we will explain why and inform you of your right to lodge a complaint.

Supervisory authority: you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) – www.aepd.es – Calle Jorge Juan 6, 28001 Madrid, if you consider that your personal data has not been processed in accordance with applicable law. We would, however, appreciate the opportunity to address your concerns directly before you approach the AEPD.

6. Security Measures

Pursuant to Article 32 GDPR, SFERO has implemented technical and organisational measures appropriate to the risk, including:

  • Encryption of data in transit using the HTTPS/TLS protocol.
  • Access controls, with multi-factor authentication for internal systems.
  • Regular backup and disaster-recovery procedures.
  • Staff training and awareness on data protection.
  • Periodic risk assessments and vulnerability testing.
  • A documented procedure for detecting, reporting and managing personal data breaches, including notification to the AEPD within 72 hours where required by Article 33 GDPR.

7. Data Breach Notification

In the event of a personal data breach likely to result in a risk to the rights and freedoms of individuals, SFERO will notify the AEPD without undue delay and, where feasible, within 72 hours of becoming aware of the breach (Article 33 GDPR). Where the breach is likely to result in a high risk, affected data subjects will also be notified without undue delay (Article 34 GDPR).

8. Minors

The Website is not directed at persons under 14 years of age. In accordance with Article 8 GDPR and Article 7 LOPDGDD, the processing of data belonging to persons under 14 requires the consent of the holder of parental authority or legal guardianship. If we become aware that we have collected data from a person under 14 without the required consent, we will delete it without delay. Users warrant that they are at least 14 years old or have obtained the necessary parental consent.

9. Cookies

The use of cookies and similar technologies on the Website is governed by our Cookie Policy, which allows you to configure your preferences in line with the criteria published by the AEPD.

10. Artificial Intelligence Transparency Notice

SFERO may use AI-assisted tools to support certain activities, such as automated property-matching or valuation estimates, personalised property recommendations, or customer-support features. Where such tools are used, they are subject to human review, and SFERO does not make decisions producing legal or similarly significant effects on individuals based solely on automated processing (Article 22 GDPR). You may request human intervention in relation to any AI-assisted process affecting you, express your point of view, and contest any automated-assisted decision, by contacting [email protected]. This notice will be updated to describe specific tools as they are deployed.

11. Record of Processing Activities (ROPA)

In accordance with Article 30 GDPR, SFERO maintains an internal Record of Processing Activities documenting its personal data processing operations. This record is available to the AEPD upon request and is reviewed periodically, or whenever a new processing activity is introduced or an existing one changes materially.

12. Data Protection Officer

As indicated in Section 1, the appointment of a Data Protection Officer is not currently mandatory for SFERO, given the scale and nature of its processing activities, and data protection queries may be directed to [email protected]. Should SFERO appoint a Data Protection Officer in the future, whether voluntarily or because it becomes legally required under Articles 37 to 39 GDPR and Article 34 LOPDGDD, that appointment and the DPO's contact details will be published in this Section.

13. Digital Services Act (DSA)

To the extent that the Website were to operate as an online platform within the meaning of Regulation (EU) 2022/2065 (Digital Services Act) – for example, by hosting content generated by third parties – SFERO would provide the transparency and content-moderation mechanisms required by that Regulation, including a channel for reporting unlawful content and an appeal mechanism for content decisions. At present, the Website functions as an informational and brokerage site rather than a platform hosting third-party generated content; this Section will be expanded should that scope change.

14. Modifications

SFERO may amend this Privacy Policy at any time to reflect changes in applicable law, its processing activities or its services. The version published on the Website at the time of each visit shall apply.

15. Applicable Law and Jurisdiction

This Privacy Policy is governed by Spanish law. Any dispute arising from its interpretation or application shall be submitted, with an express waiver of any other jurisdiction, to the Courts of Valencia, unless mandatory applicable law establishes a different competent forum, in particular for consumer disputes.

Declaration of Legal Compliance

This document has been drafted with a view to ensuring compliance with: Regulation (EU) 2016/679 (GDPR); Organic Law 3/2018 (LOPDGDD); Law 34/2002 (LSSICE); Law 10/2010 on the prevention of money laundering and terrorist financing; Regulation (EU) 2022/2065 (Digital Services Act), to the extent applicable; Regulation (EU) 2024/1689 (EU AI Act), to the extent applicable; and other Spanish sectoral real estate legislation, informed by the current guidance of the AEPD.

This document forms part of a single legal framework together with the Legal Notice, Terms and Conditions of Use and Cookie Policy of SFERO REAL ESTATE, S.L. In the event of any inconsistency between these documents on a specific matter, the more specific document shall prevail.