Privacy Policy
www.strongabogados.com
This Privacy Policy governs the processing of personal data collected through the website www.strongabogados.com and in the course of the provision of professional services, in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
1. Data controller
- Name: Strong Law and Compliance LLC, operating in Spain through Strong Law and Compliance, Sucursal en España (Spanish branch).
- Tax identification: US921916330.
- Registered office: 7901 4th St N, Suite 300, Saint Petersburg, Florida 33702, United States.
- Establishment in Spain: Gran Vía 6, 4th floor, Madrid, Spain.
- Contact email and exercise of rights: info@stronglc.com.
- Telephone: +34 932 155 393.
- Website: www.strongabogados.com.
The controller has a permanent establishment in the European Union, and the processing of personal data is therefore subject to the GDPR pursuant to its Article 3(1), regardless of the place of incorporation of the entity. As a company incorporated in the State of Florida (United States), the controller also observes the Florida Information Protection Act (Section 501.171, Florida Statutes) as regards information security and the notification of security breaches.
2. Personal data we process
We process only the data that the user or client provides voluntarily and those strictly necessary for the provision of the service:
- Identification and contact data: name and surname, identity document or passport number, postal address, email address and telephone number.
- Professional and corporate data: company name, tax identification number, position and company ownership details where the client is a legal entity.
- Financial and billing data: those necessary for the issuance of invoices and the management of payments.
- Data arising from the professional file: the information provided by the client for the handling of the matter entrusted.
- Browsing data: those described in the Cookie Policy, processed only with the user's consent.
3. No processing of special categories of data
The controller does not collect or process special categories of personal data within the meaning of Article 9 of the GDPR. In particular, no data concerning health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sexual life, or genetic or biometric data are processed.
Where the handling of a matter requires information of this nature to be provided, such information is exchanged directly between the client and the relevant public authority, body or third party, and is not incorporated into the controller's processing systems. The website forms do not request data of this nature, and users are asked to refrain from including such data in free-text fields.
4. Purposes of processing
- To respond to enquiries, requests for information and contact requests submitted through the website forms.
- To manage and perform the professional services engaged, including the administrative, accounting and tax management arising from the contractual relationship.
- To issue invoices and manage the collection of fees for the services.
- To comply with the legal obligations applicable to the controller, including client identification and anti-money-laundering obligations.
- To send informative communications regarding services similar to those already engaged or, failing that, where the user has given consent.
- To manage communications received through the whistleblowing channel.
The fields marked as mandatory in the forms are necessary in order to deal with the request; failure to complete them will prevent the request from being processed.
5. Client identification (KYC)
In compliance with anti-money-laundering and counter-terrorist-financing legislation, the controller applies customer due diligence and client identification measures ("know your customer" or KYC). For that purpose it may request valid identity documents, proof of address and, in the case of legal entities, information on their ownership structure and beneficial owners. The commencement and continuation of the provision of services are conditional upon the satisfactory completion of these verifications. The documentation obtained in this context is processed for the sole purpose of complying with that legal obligation.
6. Legal basis for processing
- Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR): to deal with requests for quotations and to provide the services engaged.
- Compliance with a legal obligation (Art. 6(1)(c) GDPR): for tax, accounting and invoicing obligations, client identification (KYC) and the management of the whistleblowing channel.
- Legitimate interest (Art. 6(1)(f) GDPR): to send communications about similar services to clients with a prior contractual relationship, and to ensure the security of information systems.
- Consent of the data subject (Art. 6(1)(a) GDPR): to send commercial communications to non-clients and for the use of non-essential cookies. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out beforehand.
7. Retention periods
Personal data will be retained for as long as the professional or contractual relationship is maintained and, once terminated, for a period of ten (10) years, having regard to the retention obligations arising from anti-money-laundering legislation and to the limitation periods for any liability arising from the services provided. Once that period has elapsed, the data will be securely deleted or irreversibly anonymized.
Data processed on the basis of consent will be retained until such consent is withdrawn. Browsing data will be retained for the periods indicated in the Cookie Policy.
8. Recipients and processors
Personal data are not disclosed to third parties, except in the following cases:
- Public authorities, courts and tribunals: where the disclosure is necessary for the handling of the matter entrusted or is required by a legal obligation.
- Financial institutions: for the management of collections and payments arising from the contractual relationship.
- Hosting provider: IONOS, which provides the dedicated server service as a processor, under a contract complying with Article 28 of the GDPR.
- Digital analytics and advertising providers: Google (Google Analytics and Google Ads), only where the user has accepted the corresponding cookies, on the terms described in the Cookie Policy.
The firm's internal management systems, including the Tempo platform, are operated exclusively by the Spanish branch's own staff, who are bound by a duty of confidentiality and subject to the access controls described in section 10.
9. International data transfers
The controller's hosting infrastructure relies on dedicated servers provided by IONOS. That provider's European data centres are located in Logroño (Spain), Frankfurt am Main and Berlin (Germany) and Paris (France), and hold ISO 9001 and ISO 27001 certification, as well as physical security measures including biometric access control, video surveillance and permanent security staff.
Data subjects may request information on the safeguards applied by contacting the address indicated in section 1.
10. Security measures
The controller has adopted appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR. These include:
- Hosting on a dedicated server, with separation of environments and control of the security configuration.
- Encryption of communications using the TLS protocol and encryption of data at rest where appropriate.
- A backup policy providing for up to four redundant copies, subject to periodic restoration testing.
- Profile-based access control, with individual credentials, strong authentication and activity logging.
- Duty of confidentiality and data protection training for staff with access to the information.
- A security breach management procedure providing for notification to the Spanish Data Protection Agency within seventy-two hours and, where appropriate, to the data subjects, as well as the notifications required by the Florida Information Protection Act.
Notwithstanding the above, users should be aware that security measures on the internet are not absolutely impregnable.
11. Professional secrecy
All information relating to the matters entrusted to the firm is covered by the lawyer's duty of professional secrecy, which is of indefinite duration and which the controller applies in its strictest interpretation. This duty extends to all of the firm's staff and survives the termination of the professional relationship. Accordingly, the controller will not provide information about a client's matters to third parties, even where those third parties invoke rights recognized by data protection legislation, save with the client's express consent or pursuant to a lawfully issued court order.
12. Rights of data subjects
Data subjects may exercise the following rights:
- Access to their personal data.
- Rectification of inaccurate or incomplete data.
- Erasure of data where they are no longer necessary for the purposes for which they were collected.
- Objection to processing on grounds relating to their particular situation.
- Restriction of processing in the cases provided for in Article 18 of the GDPR.
- Portability of the data provided, in a structured and commonly used format.
- Withdrawal of consent given, at any time.
The exercise of these rights is free of charge and may be carried out by request addressed to info@stronglc.com, or by post to Gran Vía 6, 4th floor, Madrid, Spain, or to 7901 4th St N, Suite 300, Saint Petersburg, Florida 33702, United States, enclosing a copy of a document evidencing the identity of the applicant.
The exercise of these rights may be limited where necessary for compliance with the controller's legal obligations or where the duty of professional secrecy described in section 11 applies.
Data subjects are also entitled to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es), in particular where they consider that they have not obtained satisfaction in the exercise of their rights.
13. Automated decision-making and profiling
The controller does not take decisions based solely on automated processing which produce legal effects concerning data subjects or similarly significantly affect them, nor does it carry out profiling for that purpose.
14. Whistleblowing channel
The website provides a whistleblowing channel through which infringements and irregular conduct may be reported. The information received is processed in strict confidence and with the safeguards for the protection of the reporting person provided for in the applicable legislation, with access limited to the persons expressly designated to manage it.
15. Cookies
The website uses its own and third-party cookies on the terms described in the Cookie Policy, accessible from the website itself. Non-essential cookies are installed only with the user's prior consent, which may be withdrawn at any time from the privacy preferences management panel.
16. Minors
The services offered on the website are not directed at minors. The controller does not knowingly collect data from minors through the website.
17. Amendments to this Policy
The controller may amend this Privacy Policy in order to adapt it to legislative or case-law developments or to changes in the processing operations carried out. The version in force will at all times be the one published on the website, indicating the date of its last update.
Last updated: 8/8/2026