Privacy Policy
This policy explains how CVR Nautical collects, uses and protects the personal data of anyone who contacts us through this website. We have written it to be read, not to be skipped. If anything here is unclear, write to us and we will explain it in plain terms.
Who is responsible for your data
CVR Nautical
Registered name: [PENDIENTE DE COMPLETAR]
Tax ID (NIF/CIF): [PENDIENTE DE COMPLETAR]
Registered address: [PENDIENTE DE COMPLETAR], Marbella, Málaga, Spain
Email: contact@cvrnautical.com
Telephone: +34 615 19 72 29
CVR Nautical is the data controller for the personal data collected through this website, within the meaning of Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
What we collect
We only collect what we need to answer you and, if it goes ahead, to build your vessel:
Data you give us. Through our contact, commission, partnership and configurator forms: your name, email address, telephone number where you provide it, and whatever you choose to tell us about your project — vessel type, length, intended use, features, budget range, timeline and any brief you write.
Data collected automatically. Our server keeps standard access logs, which include your IP address, the date and time of the request, the pages served and your browser’s user agent. These logs exist to keep the site running and secure.
We do not collect special categories of data (health, beliefs, biometrics), and we ask you not to send them to us through these forms.
Why we use it, and on what legal basis
To answer your enquiry and prepare a quotation. Legal basis: steps taken at your request prior to entering into a contract (Art. 6.1.b GDPR). Without this data we simply cannot reply to you.
To manage a build or refit contract, should one be signed. Legal basis: performance of that contract (Art. 6.1.b GDPR).
To keep the website secure and functioning. Legal basis: our legitimate interest in preventing abuse and diagnosing faults (Art. 6.1.f GDPR).
To meet our legal, accounting and tax duties. Legal basis: compliance with a legal obligation (Art. 6.1.c GDPR).
We do not send marketing emails, we do not build commercial profiles, and we do not take automated decisions that produce legal effects concerning you. If we ever introduce a newsletter it will be on a separate, explicit opt-in.
How long we keep it
If your enquiry does not lead to a project, we keep it for up to two years from our last exchange, so that we can pick up the conversation if you come back to us, and then we delete it.
If it becomes a contract, we keep the file for the duration of the works and afterwards for as long as any liability can be claimed — including the periods required by Spanish commercial and tax law, which for accounting records is six years (Art. 30 of the Código de Comercio) and four years for tax purposes (Art. 66 of the Ley General Tributaria).
Server access logs are rotated and deleted on a short cycle by our hosting provider.
Who else sees it
We do not sell your data and we do not share it for anyone else’s marketing. It is handled by the providers we need in order to operate, each acting as our processor under a contract that meets Art. 28 GDPR:
Our hosting provider, which stores the website and its database on servers located in the European Union.
Google Ireland Ltd., whose Google Workspace service handles our email. Messages sent through the site’s forms reach us as email and are therefore stored there. Google may process data outside the European Economic Area; those transfers are covered by the European Commission’s Standard Contractual Clauses and by Google’s certification under the EU–US Data Privacy Framework.
Beyond that, we would only disclose data where the law obliges us to — for instance to a court, the tax authority or the State security forces.
Your rights
You may at any time ask us to give you access to your data, correct it, delete it, restrict how we use it, or hand it over in a portable format. You may also object to processing we carry out on the basis of legitimate interest, and withdraw any consent you have given, without that affecting what we did lawfully beforehand.
Write to contact@cvrnautical.com stating what you want to exercise. We will reply within one month. We may need to confirm your identity first, so that we do not hand your data to somebody else.
If you believe we have handled your data badly, you are entitled to complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos (C/ Jorge Juan 6, 28001 Madrid — www.aepd.es). We would rather you told us first and gave us the chance to put it right.
Security
The site is served over HTTPS, access to the administration area is restricted and protected by credentials, and form submissions are stored in a database that is not publicly reachable. No system is perfect: if a breach ever occurred that put your rights at risk, we would notify the AEPD and, where required, you, within the deadlines set by Art. 33 and 34 GDPR.
Minors
This website and our services are directed at adults. We do not knowingly collect data from anyone under 18. If you believe a minor has sent us personal data, write to us and we will delete it.
Changes to this policy
If we change how we handle personal data we will update this page and change the date below. Where the change is significant we will say so clearly rather than rely on you noticing.
Last updated: 6 August 2026