Privacy Policy

Last updated: 09/02/2026

1. Who we are

Teammate is a consultancy business operating from Spain.

Teammate is currently in the process of formally establishing its business registration. For the purposes of applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the individual operating under the trade name Teammate acts as the Data Controller.

Contact email: hello@teammate.es


2. The personal data we collect

We may collect and process the following categories of personal data:

a) Data you provide directly

  • Name

  • Email address

  • Company name

  • Phone number

  • Free-text messages or enquiries submitted via website forms

  • Any other information you choose to provide when contacting us or engaging our services

b) Client and project-related data

If you become a client, we may process additional information necessary to deliver our services. This may include, depending on the nature of the engagement:

  • Website and marketing performance data (such as traffic, conversion rates, and related metrics)

  • Business objectives, performance indicators, and operational information

  • Information about internal processes, tools, systems, and costs

  • Other business-related data you choose to share as part of the engagement

This data is processed only to the extent necessary to deliver agreed services.

c) Technical and usage data

When you visit our website, we may automatically collect certain technical information, including:

  • IP address

  • Browser type and version

  • Device and operating system information

  • Pages visited and interactions on the site

  • Referral sources

This data is typically collected through analytics tools and cookies.


3. How we collect personal data

We collect personal data through:

  • Website contact and enquiry forms

  • Embedded calendar booking tools

  • Direct email communication

  • Website analytics and cookies

  • Ongoing communication during client engagements


4. Why we process personal data (legal bases)

We only process personal data where we have a lawful basis under GDPR. Depending on the context, this includes:

a) Legitimate interests

We process personal data where it is reasonably necessary for our legitimate business interests, including:

  • Responding to enquiries and communications

  • Communicating with prospective clients

  • Improving our website and services

  • Managing and delivering client work

These interests do not override your fundamental rights and freedoms.

b) Consent

We rely on your consent where required by law, including:

  • When you submit personal data via website forms

  • When you accept non-essential cookies

You may withdraw your consent at any time.

c) Contractual necessity

If you become a client, we process personal data as necessary to perform our contractual obligations.

d) Legal obligations

We may process personal data where required to comply with legal, accounting, or regulatory obligations.

e) Commercial communications

If you contact us or become a client, we may send communications related to our services. We do not send unsolicited marketing emails. Where required by law, marketing communications will only be sent with your explicit consent, which you may withdraw at any time.


5. Cookies and analytics

We use cookies and similar technologies to operate and improve our website.

We plan to use Google Analytics 4 (GA4) and may also use additional tracking or marketing tools (such as Google Tag Manager, Meta/Facebook Pixel, or LinkedIn Insight Tag) where appropriate.

Where required by law, non-essential cookies will only be used after you have provided consent via a cookie banner or consent tool.

For more information about cookies and how they are used, please see our Cookie Policy.


6. Who we share personal data with

We may share personal data with trusted third parties who act as data processors on our behalf, including:

  • Website hosting and infrastructure providers

  • Analytics and marketing tools

  • Email and communication platforms

  • CRM systems

  • Freelancers or contractors engaged to support client work, where necessary

All such parties are required to process personal data securely and in accordance with applicable data protection laws.

We do not sell personal data.


7. International data transfers

Some of the tools and service providers we use may process personal data outside the European Union.

Where this occurs, we ensure appropriate safeguards are in place, including:

  • The EU–US Data Privacy Framework (where applicable)

  • Standard Contractual Clauses approved by the European Commission

  • Other legally recognised transfer mechanisms


8. How long we keep personal data

We retain personal data only for as long as necessary for the purposes for which it was collected.

  • Enquiry data: retained for up to 24 months if no business relationship is established

  • Client data: retained for the duration of the relationship and for a reasonable period afterwards, taking into account legal, contractual, and operational requirements

We may retain certain data for longer where required by law or for legitimate business purposes.


9. How we protect personal data

We take appropriate technical and organisational measures to protect personal data, including:

  • Secure hosting environments

  • Access controls and authentication measures

  • Use of reputable service providers

  • Encryption and security measures where appropriate

While no system can be guaranteed to be completely secure, we take reasonable steps to protect personal data from unauthorised access, loss, or misuse.


10. Your rights under GDPR

Under GDPR, you have the right to:

  • Access your personal data

  • Request correction of inaccurate or incomplete data

  • Request erasure of your personal data

  • Restrict or object to the processing of your data

  • Request data portability

  • Withdraw consent at any time where processing is based on consent

To exercise any of these rights, please contact us at hello@teammate.es.

For security reasons, we may need to request additional information to verify your identity before responding to certain requests.


11. Complaints

If you believe your data protection rights have been infringed, you have the right to lodge a complaint with the relevant supervisory authority.

As we are established in Spain, the competent authority is:

Agencia Española de Protección de Datos (AEPD)
Website: https://www.aepd.es


12. Children’s data

This website and our services are intended for business professionals only. We do not knowingly collect personal data from children.


13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our practices, services, or legal obligations.

The most current version will always be available on this website, with the effective date shown at the top.