Privacy policy
Last updated: September 2026
Data controller
Grupo Fern S.L., NIF 3601663Y, Calle de Felipe Campos 9, 28002 Madrid. Email: hola@grupofern.com. Telephone: +34 607 39 38 15.
No data protection officer has been appointed, as the conditions of article 37 GDPR do not apply. For any privacy matter you can write to the email address above.
What data we process and where it comes from
We process the data you provide to us directly. We do not buy data or obtain it from third parties, and this site does not use tracking cookies.
When you browse, technical data (IP address, user agent, page visited and timestamp) is additionally processed in our hosting provider's server logs and in the cookieless aggregate metrics described in the cookie policy.
- Espira contact form: name, organisation, type of space, city, email and — if you choose to provide them — telephone and message.
- Fern Development form: name, email, property address or neighbourhood and — if you choose to provide them — telephone, floor area, condition and message.
- Direct contact by WhatsApp, email or telephone: your contact details and the content of your message.
Why we process it and on what legal basis
We use your data to answer your enquiry and, where relevant, prepare the technical visit, proposal or valuation you requested. The legal basis is pre-contractual measures taken at your request (art. 6.1.b GDPR); the form checkbox confirms you have read this policy.
The forms also include technical anti-spam measures (a hidden field and a timestamp, which are not stored and are not linked to your identity), based on our legitimate interest in keeping the service secure (art. 6.1.f GDPR).
Measuring the site's audience and performance and keeping technical server records likewise rest on our legitimate interest in operating and protecting the service (art. 6.1.f GDPR).
We do not use your data for advertising, we do not sell it, we do not build profiles and we make no automated decisions.
Fields marked as optional can be left blank; the rest are necessary for us to handle your enquiry.
Recipients and processors
We do not share your data with third parties. To operate the site we use two providers acting as data processors under contract pursuant to article 28 GDPR:
- Formspree, Inc. (USA): the platform that receives contact-form submissions and forwards them to us by email.
- Vercel Inc. (USA): website hosting and cookieless performance metrics.
International transfers
Formspree and Vercel process data in the United States. Vercel is certified under the EU–US Data Privacy Framework, covered by the European Commission's adequacy decision of 10 July 2023. Transfers to Formspree are safeguarded by the European Commission's standard contractual clauses (art. 46.2.c GDPR), incorporated into its data-processing agreement.
If you write to us on WhatsApp, that service is provided by WhatsApp Ireland Ltd. under its own terms and privacy policy.
How long we keep your data
- Enquiries that do not lead to a contractual relationship: deleted within twelve months of the last contact.
- Enquiries that lead to a pre-contractual or contractual relationship: for the duration of the relationship and, afterwards, for the applicable legal limitation periods.
- Technical hosting records (server logs): the short periods set by the hosting provider.
Your rights
You can exercise the following rights at any time by writing to hola@grupofern.com or by post to Calle de Felipe Campos 9, 28002 Madrid, providing proof of identity. We will reply within one month.
- Access to your data.
- Rectification of inaccurate data.
- Erasure (the “right to be forgotten”).
- Objection to processing.
- Restriction of processing.
- Data portability.
Complaints to the supervisory authority
If you believe the processing does not comply with the law, you can lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es), without prejudice to any other remedy available to you.
Minors
This site is not aimed at children under fourteen and we do not knowingly process their data. If we detect data provided by a minor without due authorisation, we will delete it.
Security
We apply technical and organisational measures appropriate to the risk (art. 32 GDPR): TLS encryption in transit, restricted access to the contact inboxes and minimisation of the data we request.
Changes to this policy
Any change will be published on this page, updating the date shown at the top. Significant changes will be highlighted visibly.