Last updated: 1 October 2026
At Sergom Consultors we handle a lot of personal data: from people who write to us through the website and, above all, from clients who trust us with their taxes, accounts, payroll or paperwork. This page explains, with as little jargon as possible, what data we collect, why, how long we keep it and what you can do to control it.
1. Who is the data controller
- Controller: CONSULTORIA Y DESARROLLO DE NEGOCIOS BCN, S.L.
- Trading name: Sergom Consultors
- Tax ID (NIF): B55490544
- Address: C/ Dos de Maig, 25, 3r 4a, 08172 Sant Cugat del Vallès (Barcelona), Spain
- Phone: +34 647 955 230
- Email: administracion@sergomconsultors.com
We have not appointed a data protection officer because the law does not require us to. For any privacy matter, write to the email address above.
2. What data we process
- If you contact us through the website, by phone, email, WhatsApp or video call: your name, phone number, email address and whatever you tell us about your enquiry.
- If you are a client: identification and contact details (including your ID document), tax, financial and asset data, bank details, employment and social security data, data about family members when the service requires it (for example, an income tax return or an inheritance) and the digital certificates and powers of attorney you entrust to us.
- Health data, only when the service requires it: sick leave in payroll management or a disability rating to apply a tax deduction.
- If you subscribe to our newsletter: your name and email address.
- If you send us your CV: the data you include in it.
If you give us data about other people (family members, employees, partners or heirs), you must have informed them first and be entitled to share it.
3. Why we use your data and on what legal basis
a) To answer enquiries and call requests received through the website forms, the “Book a call” window, email, phone, WhatsApp or video call.
Legal basis: your consent (Art. 6(1)(a) GDPR) and, if you are enquiring about hiring us, steps taken prior to entering into a contract (Art. 6(1)(b) GDPR).
b) To provide the services you hire us for: tax, accounting, employment, corporate, legal, administrative paperwork, grants, financing, insurance, inheritance, immigration and vehicle services. This includes representing you before public authorities with your digital certificate or the powers you grant us, giving you access to the client area and signing documents electronically.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and compliance with the legal obligations each procedure involves (Art. 6(1)(c) GDPR).
c) To process health data when a procedure requires it.
Legal basis: compliance with employment and social security obligations (Art. 9(2)(b) GDPR) and, in other cases such as disability in an income tax return, your explicit consent (Art. 9(2)(a) GDPR).
d) To comply with anti-money laundering law: identifying you, verifying your identity, understanding your activity and keeping the records.
Legal basis: legal obligation (Art. 6(1)(c) GDPR and Spanish Law 10/2010 of 28 April).
e) To invoice and keep our own accounts.
Legal basis: legal obligation (Art. 6(1)(c) GDPR).
f) To send you marketing communications (newsletter, tax updates, deadline reminders and services) by email, SMS or WhatsApp.
Legal basis: if you subscribed, your consent (Art. 6(1)(a) GDPR). If you are already a client, our legitimate interest in telling you about services similar to those you have hired (Art. 21.2 of Spanish Law 34/2002, LSSI). Either way, you can unsubscribe at any time from any message.
g) To ask you for a review on Google after providing a service.
Legal basis: our legitimate interest in hearing your opinion and improving (Art. 6(1)(f) GDPR). You can object at any time.
h) To assess your application if you send us your CV.
Legal basis: your consent (Art. 6(1)(a) GDPR).
i) To manage our LinkedIn and Instagram profiles and reply to interactions.
Legal basis: your consent when you follow us or write to us. Each network processes data under its own policy; for profile statistics, we are joint controllers with LinkedIn Ireland Unlimited Company and Meta Platforms Ireland Ltd.
We do not make automated decisions or create profiles with your data.
4. When we process data on behalf of our clients
When we keep the accounts, run the payroll or manage the paperwork of a company or self-employed client, we process data about their employees, customers and suppliers on their behalf. In these cases the client is the data controller and Sergom acts as a data processor (Art. 28 GDPR). We always do so under a signed processing agreement that sets out the instructions, confidentiality, security measures and the return or destruction of the data when the service ends.
5. How long we keep your data
- Enquiries that do not become an engagement: one year.
- Clients: for as long as the relationship lasts and then for the legal periods: six years for accounting records (Art. 30 of the Spanish Commercial Code), four years for tax records (General Tax Law), extendable if proceedings are open, four years for employment and social security records, and ten years for anti-money laundering records from the end of the relationship (Art. 25 of Law 10/2010).
- Digital certificates and powers of attorney: for as long as the engagement lasts. When it ends or you revoke the authorisation, we delete them from our systems.
- Health data: only as long as needed for the procedure and as required by the relevant legal obligation.
- Newsletter: until you unsubscribe.
- CVs: one year.
After these periods, we keep the data blocked only while legal liability may arise, and then delete it.
6. Who we share data with
When the service requires it or the law obliges us, we share data with the Spanish Tax Agency, the Catalan Tax Agency, the Social Security General Treasury, the Public Employment Service (SEPE), the Commercial and Property Registries, notaries, local councils and other authorities, courts, and the Executive Service of the Commission for the Prevention of Money Laundering (SEPBLAC) where the law requires. We only share data with banks and insurers when you ask us to arrange financing or insurance, and always with your knowledge.
The following providers may access data as processors, under contract and bound by confidentiality:
- Website hosting and maintenance: Addicional Marketing, S.L.
- Email and cloud storage: Microsoft 365 (Microsoft Ireland Operations Ltd.)
- Newsletter delivery: Acumbamail (Sitelabs Media, S.L.)
- Tax, accounting and payroll software
- Electronic signature platform and client area
- Messaging and video calls, including WhatsApp (WhatsApp Ireland Limited)
We never sell or share your data for marketing purposes.
7. International transfers
Some technology providers, such as Microsoft, WhatsApp, Meta or LinkedIn, may process data outside the European Economic Area, mainly in the United States. In those cases, transfers rely on GDPR safeguards: the European Commission’s adequacy decision on the EU-US Data Privacy Framework, for certified companies, or the standard contractual clauses approved by the Commission.
8. Your rights
You can exercise the following rights at any time:
- Access: find out whether we process your data and get a copy.
- Rectification: correct inaccurate or incomplete data.
- Erasure: ask us to delete it when it is no longer needed.
- Objection: object to certain processing, such as marketing communications or review requests.
- Restriction: ask us to keep it only for specific purposes.
- Portability: receive the data you gave us in a structured, commonly used format.
- Withdraw consent at any time, without affecting earlier processing.
Write to administracion@sergomconsultors.com or by post to the address in section 1, saying which right you want to exercise. We will reply within one month. If we have reasonable doubts about your identity, we may ask you to prove it. We cannot delete some data while a law requires us to keep it; in that case, we will keep it blocked.
If you think we have not handled your data properly, you can file a complaint with the Spanish Data Protection Agency (www.aepd.es). If you prefer, write to us first and we will try to put it right.
9. Security and professional secrecy
We apply technical and organisational measures to protect data against loss, unauthorised access or alteration. The whole team is bound by a duty of confidentiality, and access to clients’ digital certificates and documents is restricted to the people handling each file.
10. Minors
Our online services are not aimed at children under 14. When a service requires data about a minor, such as a family income tax return or an inheritance, it must be provided by their parents or guardians.
11. Changes to this policy
We may update this policy to reflect legal changes or changes to our services. The version in force will always be the one on this page, with the date of the last update.