Costa Aurea · Property & Asset Management
Privacy Policy
Last updated: 6 August 2026
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal Data to provide and improve the Service. We collect, use, and disclose Your information as described in this Privacy Policy and, where required by applicable law, only where We have a valid legal basis to do so, including Your consent (where consent is required).
Interpretation and Definitions
Interpretation
The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
- Account means a unique account created for You to access Our Service or parts of Our Service.
- Affiliate means an entity that controls, is controlled by, or is under common control with a party, where “control” means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
- Company (referred to as either “the Company”, “We”, “Us” or “Our” in this Privacy Policy) refers to Costa Aurea Capital Partners, S.L., Urbanización Altos de Cortesin, Buzon 14, Carretera de Casares Km.2, 29690 Casares, Málaga.
- Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website, among its many uses.
- Country/State refers to: Spain.
- Device means any device that can access the Service, such as a computer, a cell phone or a digital tablet.
- Personal Data (or “Personal Information”) is any information that relates to an identified or identifiable individual. We use “Personal Data” and “Personal Information” interchangeably unless a law uses a specific term.
- Service refers to the Website.
- Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
- Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
- User means any individual who accesses or uses the Service.
- Website refers to Costa Aurea, accessible from www.costaaurea.com.
- You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Collecting and Using Your Personal Information
Types of Data Collected
Personal Data
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:
- Email address
- First name and last name
- Phone number
- Address, State, Province, ZIP/Postal code, City
Usage Data
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your Device’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of Our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device’s unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
We may also collect information that Your browser sends whenever You visit Our Service or when You access the Service by or through a mobile device.
Tracking Technologies and Cookies
We use tracking technologies (such as cookies) to track the activity and to improve Our Service. The technologies We use may include:
- Cookies or Browser Cookies. A cookie is a small file placed on Your Device. You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of Our Service.
- Web Beacons. Certain sections of Our Service may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit the Company, for example, to count users who have visited those pages and for other related website statistics.
Cookies can be “Persistent” or “Session” Cookies. Persistent Cookies remain on Your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close Your web browser.
Where required by law, We use non-essential cookies (that is, Cookies other than the Necessary / Essential Cookies described below) only with Your consent. You can withdraw or change Your consent at any time using Our cookie preferences tool or through Your browser or device settings. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
We use both Session and Persistent Cookies for the purposes set out below:
Necessary / Essential Cookies. Type: Session Cookies. Administered by: Us. Purpose: These Cookies are essential to provide You with services available through the Website and to enable You to use some of its features. They help to authenticate users and prevent fraudulent use of user accounts. Without these Cookies, the services that You have asked for cannot be provided, and We only use these Cookies to provide You with those services.
Cookies Policy / Notice Acceptance Cookies. Type: Persistent Cookies. Administered by: Us. Purpose: These Cookies identify whether users have accepted the use of cookies on the Website and record the consent choices You have made, so that We can honor those choices on future visits.
Functionality Cookies. Type: Persistent Cookies. Administered by: Us. Purpose: These Cookies allow Us to remember choices You make when You use the Website, such as remembering Your Account login details or language preference. The purpose of these Cookies is to provide You with a more personal experience and to avoid You having to re-enter Your preferences every time You use the Website.
Use of Your Personal Data
The Company may use Personal Data for the following purposes:
- To provide and maintain Our Service, including to monitor the usage of Our Service.
- To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.
- For the performance of a contract: the development, compliance and undertaking of the purchase contract for the products, items or services You have purchased or of any other contract with Us through the Service.
- To contact You: To contact You by email, telephone calls, SMS, or other equivalent forms of electronic communication regarding updates or informative communications related to the functionalities, products or contracted services, including security updates, when necessary or reasonable for their implementation.
- To provide You with news, special offers, and general information about other goods, services and events which We offer that are similar to those that You have already purchased or inquired about. We send such marketing communications only where permitted by applicable law. Where prior consent is required, We will send them only with Your consent. You may opt out or withdraw Your consent at any time by using the unsubscribe link in any marketing email We send or by contacting Us.
- To manage Your requests: To attend and manage Your requests to Us.
- For business transfers: We may use Your Personal Data to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by Us about Our Service users is among the assets transferred.
- For other purposes: We may use Your information for other purposes, such as to facilitate rental management, coordinate property maintenance, and manage property marketing campaigns, as well as data analysis, identifying usage trends, determining the effectiveness of Our promotional campaigns, and evaluating and improving Our Service, products, services, marketing and Your experience.
Property Data and Photographs
We collect property information including photos, descriptions, and location details to manage rental listings. Photos are published on Airbnb, Booking.com, VRBO, and CostaAurea.com. Owners retain copyright, while Costa Aurea holds usage rights via “Autorización de Publicidad”. Owners can request data deletion or removal from platforms at any time.
Data Sharing With Third-Party Platforms
We share data with third-party platforms as follows:
- Airbnb, Booking.com, VRBO: We share property data, guest data, and payment information.
- CostaAurea.com: We share property data only.
Please note that these platforms act as Data Processors, and we do not control their individual privacy policies.
Guest Data
We collect guest data from Airbnb and Booking.com check-ins. This information is used for cleaning services, maintenance, and emergency contact purposes. Data is retained according to platform policies, typically 2 years. Please be aware that Costa Aurea is not responsible for data collected directly by these platforms.
Your GDPR Rights
Under the GDPR, You have the following rights regarding Your personal data:
- Right to access Your data.
- Right to rectify inaccurate data.
- Right to erasure (“right to be forgotten”).
- Right to restrict processing.
- Right to data portability.
- Right to object to processing.
- Right to withdraw consent.
To exercise these rights, please contact us at legal@costaaurea.com.
Sharing of Your Personal Data
We may share Your Personal Data in the following situations:
- With Service Providers: We may share Your Personal Data with Service Providers to monitor and analyze the use of Our Service, and to contact You.
- For business transfers: We may share or transfer Your Personal Data in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.
- With Affiliates: We may share Your Personal Data with Our affiliates, in which case We will require those affiliates to honor this Privacy Policy.
- With other users: If Our Service offers public areas, when You share Personal Data or otherwise interact in the public areas with other users, such information may be viewed by all users and may be publicly distributed outside the Service.
- With Your consent: We may disclose Your Personal Data for any other purpose with Your consent.
Text Messages Privacy Notice
You have the option to receive text (SMS) messages from Us. If You opt in to text messages, We will send You updates, notifications, and other communications as described below. When You opt in, We will collect and store the information You provide in connection with text messaging, such as Your phone number, the date and method of Your consent, and message delivery and read information.
No mobile information will be shared with or sold to third parties or affiliates for marketing or promotional purposes. The phone numbers and consent records We collect for texting are never shared with anyone for any purpose, except the Service Providers that technically have to handle them to deliver the texts.
Consent to receive text messages is not a condition of any purchase or use of Our Service. If You consent to receive SMS from Us, You agree to receive text messages from Us related to customer care and support, account notifications, delivery notifications, authentication messages, security alerts, and marketing and promotional offers.
Reply STOP to opt out. Reply HELP for support. Message and data rates may apply. Messaging frequency may vary. Carriers are not liable for delayed or undelivered messages.
Retention of Your Personal Data
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. Different categories of data are retained for different periods, as detailed below.
Owner and Proprietor Data
Active contract period. Name, contact information and property address are retained for the duration of the service agreement. Bank account details are retained only while active and are deleted upon contract termination. ID verification, such as passport scan and NIF, is retained during the contract plus 6 months, for dispute resolution. Communication history is retained during the contract plus 24 months, for disputes and legal claims.
After contract termination. Owner name and contact are retained 24 months, for dispute resolution and referrals. Financial records, such as invoices and payments, are retained 6 years, as a minimum requirement of Spanish tax law. Property photos are retained 12 months for archival purposes, then deleted on request. Assessment reports are retained permanently as a historical record, anonymized where possible.
Tax and compliance. NIF and tax identification are retained a minimum of 6 years, as required by the Spanish tax authority. Income records are retained a minimum of 6 years, for tax and audit purposes.
Guest and Tenant Data
Short-term rental guests, during the stay. Name, contact and payment information are active, as required for check-in, support and emergency contact. House rules acknowledgment is active, for enforcement.
Short-term rental guests, after checkout. Guest data is retained a maximum of 24 months, for review verification, dispute resolution and guest blocking. Guest reviews and ratings are retained permanently, linked to property history and anonymized after 3 years. Payment records are retained 6 years, as Spanish tax and accounting records. Damage reports and photos are retained 3 years, for liability, claims and dispute resolution.
Long-term rental tenants. The lease agreement is retained 6 years after the lease ends, as required by Spanish law. Tenant contact information is retained during the lease plus 12 months. Payment records are retained 6 years, under tax law. Maintenance and repair requests are retained 3 years after the lease ends. Damage assessments are retained 6 years, for liability and insurance claims.
Analytical and Usage Data
Website analytics. IP addresses, device type, pages visited and session duration are retained 24 months. User behaviour patterns are retained 24 months, then aggregated or anonymized and retained indefinitely. Heatmaps and click data, if collected, are retained 12 months.
Server logs. Access logs are retained 90 days, for security and performance monitoring. Error logs are retained 12 months. Security event logs are retained 24 months, for intrusion detection and forensics.
Communication and Support Data
Email communications. Guest inquiries and support tickets are retained 24 months after resolution. Owner service requests are retained 24 months after resolution. Unopened marketing emails are retained until unsubscribe plus 6 months.
Phone call recordings, where applicable. Recorded calls are retained 30 days for quality assurance, then deleted. Call logs, metadata only, are retained 12 months.
Chat transcripts. Live chat support is retained 24 months, for quality assurance and staff training. WhatsApp messages are retained 24 months, for guest support and documentation.
Marketing and Preferences Data
Newsletter subscriptions. Email address, subscribe date and preferences are retained while subscribed. Unsubscribe requests are retained 12 months, to prevent re-adding. Engagement data, such as open rate and clicks, is retained 12 months.
Marketing consent records. Consent timestamp and method are retained for the duration of consent plus 24 months after withdrawal. Opt-out preferences are retained indefinitely, in order to honour opt-out requests.
Financial and Transactional Data
Payment records. Invoice details are retained 6 years, for Spanish VAT and tax compliance. Payment method is retained 3 years, for PCI-DSS compliance. Full card numbers are never retained, only the last four digits. Refund records are retained 6 years. Chargeback and dispute records are retained a minimum of 6 years, for liability protection.
Deposit and guarantee records. Security deposit amount, date and holder are retained 6 years, under the Spanish Ley de Arrendamientos Urbanos. Return documentation is retained 6 years, for disputes.
Legal and Compliance Data
Contracts and agreements. Signed agreements are retained 6 years after the contract ends, as required by Spanish law. Amendments and modifications are retained 6 years. Termination notices are retained 6 years.
Dispute resolution. Complaint documentation is retained until resolved plus 3 years, for legal claims. Mediation records are retained 6 years. Legal correspondence is retained a minimum of 6 years, matching the statute of limitations for claims.
Compliance and audit. GDPR compliance records are retained 3 years, as an audit trail. Data protection impact assessments are retained indefinitely, for policy reference. Sub-processor agreements are retained for the duration plus 6 years after termination.
How Data Is Deleted
When a retention period expires, Costa Aurea deletes Personal Data using the following methods.
Active deletion. Data is removed from the live database. Backup copies are scheduled for routine deletion, at most 90 days after active deletion.
Anonymization. Personal identifiers such as name, email and phone are removed. Data is converted to anonymous statistics, with no individual identifiable. Anonymized data may be retained indefinitely for historical and analytical purposes.
Encrypted deletion. Where data remains in an encrypted backup, the encryption keys are destroyed and the data becomes irrecoverable.
Exceptions, Data Retained Beyond Standard Periods
Costa Aurea may retain Personal Data longer than stated above where one of the following applies.
- Legal obligation. Required by Spanish law, covering tax, labour and consumer protection, or by EU law. For example, tax records are retained a minimum of 6 years under Spanish tax law.
- Legal claim or dispute. Data necessary to establish, exercise or defend a legal claim is retained until the dispute is resolved plus 3 years.
- Owner or user explicit request. Where You ask Us to retain Your data for reference purposes, it is retained as requested, with the option to delete at any time.
- Technical limitations. Data existing in encrypted backup systems is scheduled for deletion per the backup retention policy, typically 90 days, and is not restored except for disaster recovery or legal obligations.
- Fraud prevention and security. Fraudulent activity records are retained indefinitely, to prevent repeat offences. Security incident data is retained a minimum of 3 years, for forensic analysis and threat intelligence.
Your Right to Request Early Deletion
You may request deletion of Your data before the standard retention period expires, subject to legal obligation exceptions, to active disputes or claims, and to Costa Aurea’s discretion where the data is necessary for ongoing obligations.
To request early deletion, email legal@costaaurea.com with the subject “Request for Early Data Deletion”, stating your reason. Costa Aurea will respond within 30 days with an approval or refusal and an explanation.
Your Transparency Rights
You have the right to know what data is retained and for how long, to request information about Your data retention timeline, to receive confirmation of deletion, and to be notified if a retention period is extended.
To check Your data retention status, email legal@costaaurea.com with the subject “Request for Data Retention Information”. Response timeline is 30 days.
Third-Party Data Processors and Sub-Processors
Costa Aurea uses third-party services to manage personal data. These parties act as Data Processors under the GDPR. They process data only on Costa Aurea’s instruction and must comply with GDPR requirements.
| Service category | Purpose | Data shared | Location | GDPR status |
|---|---|---|---|---|
| Website analytics provider | Website traffic and usage analytics | IP address, device type, pages visited, duration | EU / US | DPA signed |
| Cloud document storage | Document storage, contracts and invoices | Property data, owner and guest names, addresses | EU / US | DPA signed |
| CRM platform | Lead tracking and pipeline management | Owner contact information, interest, service tier | US | DPA and SCCs signed |
| Workflow automation software | Automated data transfer between internal systems | Data from internal records | US | DPA and SCCs signed |
| Rental distribution platforms | Rental platform distribution | Property description, photos, amenities, guest reviews | Global | Independent platforms |
| Transactional email provider | Transactional emails | Owner and guest email addresses | EU | DPA signed |
| Tax and accounting advisor | Tax and accounting services | Property income data, owner NIF, expenses | Spain | Professional confidentiality |
US-based services: Costa Aurea has executed Standard Contractual Clauses to ensure adequate data protection compliance.
Your Rights Regarding Sub-Processors
You have the right to object to any sub-processor. If You object, Costa Aurea will attempt to arrange an alternative. If no alternative exists, Costa Aurea must terminate the service. You will be notified of sub-processor changes 30 days in advance.
Costa Aurea may add or remove sub-processors as services evolve. We will update this list within 14 days of any change, notify existing owners by email if a new processor accesses their data, and provide 30 days’ notice before adding sub-processors that pose new data protection risks.
What Data Is Shared Where
| Recipient | Receives | Does not receive |
|---|---|---|
| Airbnb, Booking.com, VRBO | Property information, photos, pricing | Owner’s personal address, phone, financial details |
| Guest, before booking | Property description, photos, amenities, host name | Financial information, security codes, WiFi password |
| Guest, after booking | Check-in instructions, WiFi password, emergency contacts | Owner’s personal address, financial details, other guests’ information |
| Costa Aurea Team | All relevant data for management | Bank account numbers, unless the owner provides them for payment |
| External legal counsel | Contract and agreement information, service issues requiring legal review | Guest financial data, security codes, passwords |
International Data Transfers
Some sub-processors are located outside the EU. Costa Aurea has executed appropriate data protection agreements, including Standard Contractual Clauses for US-based processors, supplementary measures such as encryption, access controls and data minimization, and adequacy decisions where available.
If You have concerns about international transfers, contact legal@costaaurea.com. You may request a list of all sub-processors handling Your data, details of any international transfers, a copy of data protection agreements, and removal or correction of data from any sub-processor.
How to Exercise Your GDPR Rights
Under the GDPR You have specific rights over Your personal data: the right of access, rectification, erasure, restriction of processing, data portability, objection, withdrawal of consent, and the right to lodge a complaint with the Spanish Data Protection Authority.
How to Submit a Data Subject Request
Step 1, prepare your request. Include Your full name, email address, property reference (CAP-XXX) or owner ID (CAO-XXX) if applicable, a clear description of which right You are exercising, and the specific data You are requesting.
Step 2, submit to Costa Aurea. Send Your request to legal@costaaurea.com, using a subject line such as “GDPR Data Access Request”.
Step 3, identity verification. Costa Aurea will ask for verification to ensure You are the data subject. Acceptable verification includes a copy of a national ID such as a passport or driver’s licence, or confirmation from a registered email address, or another reasonable verification method.
Step 4, Costa Aurea response. Costa Aurea will respond within 30 calendar days of receiving a complete request. If the request is complex, Costa Aurea may extend the deadline by up to 60 additional days, with notification. No fee is charged, except in cases of manifestly unfounded or excessive requests.
Right of Access, Article 15
You may request a complete copy of all personal data Costa Aurea holds about You. Costa Aurea provides a copy of Your profile, all communications with You, payment records and invoices, service history and reviews, any special categories of data if applicable, and a list of sub-processors who have accessed Your data. Timeline is 30 days, extendable to 60 days if complex.
Right to Rectification, Article 16
You may request correction of inaccurate, incomplete or outdated data, for example a misspelled name, a changed phone number, an outdated address or an incorrect email. Costa Aurea will correct Your data, update all records and sub-processors, and notify You of the correction, at no cost. Timeline is 30 days.
Right to Erasure, Article 17
You may request deletion of Your personal data. Legitimate reasons include that the data is no longer necessary for the stated purpose, that You withdraw consent, that You object to processing and no legal basis overrides, that data was collected unlawfully, or that there is a legal obligation to erase.
Costa Aurea can erase marketing preferences and communications, profile information after a contract ends, and optional data You provided. Costa Aurea must retain tax records for a minimum of 6 years under Spanish law, contractual records during the contract plus 3 years after, dispute resolution documentation, evidence of payment for 6 years or more, and insurance and compliance records as legally required. Timeline is 30 days, with an explanation if full erasure is not possible.
Right to Restrict Processing, Article 18
You may ask Costa Aurea to limit how Your data is used, for example to process Your data only for essential property management with no marketing. Costa Aurea will flag Your data as restricted, notify sub-processors, continue essential processing only, and confirm when restrictions are lifted. Timeline is 30 days.
Right to Data Portability, Article 20
You may request Your data in a portable format for transfer to another service. You receive Your personal data exported to CSV or PDF, in a structured, machine-readable format, covering all data You provided to Costa Aurea. Data created by Costa Aurea, such as internal notes and assessment scores, and aggregated or anonymized data, are not included. Timeline is 30 days.
Right to Object, Article 21
You may object to the processing of Your data for specific purposes, such as marketing, profiling or automated decision-making, or sharing with a specific sub-processor. Costa Aurea will acknowledge within 30 days and will cease the objected processing unless a legal basis overrides.
Right to Withdraw Consent, Article 7
You may withdraw consent for data processing You previously agreed to. Costa Aurea will cease the processing You consented to, while processing based on legal obligation continues. Effect is immediate.
Right to Lodge a Complaint
If You are dissatisfied with Costa Aurea’s response, You may lodge a complaint with the Spanish Data Protection Authority (AEPD), at www.aepd.es, by email to contacto@aepd.es, by phone on +34 901 100 099, or at C/ Jorge Juan 6, 28001 Madrid, Spain. If You reside elsewhere in the EU, You may contact your national data protection authority. Filing a complaint is free.
Important Notes
- Verification required. Costa Aurea will verify Your identity before processing requests, to prevent unauthorized access to other people’s data.
- Free requests. The first request per year is free. Subsequent requests may incur a reasonable administrative fee if manifestly unfounded or excessive.
- Assistance available. If You need help submitting a request, contact legal@costaaurea.com and Costa Aurea will guide You.
- Data Protection Officer. Costa Aurea does not currently have a dedicated Data Protection Officer. For complex data protection questions, contact legal@costaaurea.com.
Transfer of Your Personal Data
Your information, including Personal Data, is processed at the Company’s operating offices and in any other places where the parties involved in the processing are located. This means that this information may be transferred to, and maintained on, computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ from those of Your jurisdiction.
Where required by applicable law, We will ensure that international transfers of Your Personal Data are subject to appropriate safeguards and, where relevant, supplementary measures. The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy, and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place.
Delete Your Personal Data
You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You. Our Service may give You the ability to delete certain information about You from within the Service.
You may update, amend or delete Your information at any time by signing in to Your Account, if You have one, and visiting the account settings section. You may also contact Us to request access to, correct, or delete any Personal Data that You have provided to Us. Please note, however, that We may need to retain certain information when We have a legal obligation or lawful basis to do so.
Disclosure of Your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.
Law Enforcement
Under certain circumstances, the Company may disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities, such as a court or a government agency.
Other Legal Requirements
The Company may disclose Your Personal Data in the good-faith belief that such action is necessary to comply with a legal obligation, to protect and defend the rights or property of the Company, to prevent or investigate possible wrongdoing in connection with the Service, to protect the personal safety of users of the Service or the public, or to protect against legal liability.
Security of Your Personal Data
The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage, is 100% secure. While We strive to use commercially reasonable means to protect Your Personal Data, We cannot guarantee its absolute security.
Children’s and Minors’ Privacy
The Service is not directed to, and We do not knowingly collect Personal Information from, anyone under the age of 16.
If You are a parent or guardian and You believe Your child has provided Us with Personal Information, please contact Us. If We become aware that We have collected Personal Information from anyone under the age of 16, We will take steps to remove that information from Our servers as soon as reasonably possible.
Some countries and states set a higher age at which an individual can consent to the processing of their own Personal Information. Where We rely on consent as a legal basis and the law applicable to a user sets an age higher than 16, We may require the consent of that user’s parent or guardian before We collect and use their Personal Information.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us. If You click on a third-party link, You will be directed to that third party’s site. We strongly advise You to review the Privacy Policy of every site You visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party sites or services.
Changes to This Privacy Policy
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page.
We will let You know by email or by a prominent notice on Our Service prior to the change becoming effective, and update the “Last updated” date at the top of this Privacy Policy. You are advised to review this Privacy Policy periodically. Changes are effective when they are posted on this page.
Contact Us
If You have any questions about this Privacy Policy, You can contact Us:
- By email: legal@costaaurea.com
- By phone: +34 623 624 444
- By visiting this page on Our website: www.costaaurea.com/privacy-policy
Costa Aurea Capital Partners, S.L. · hello@costaaurea.com · +34 623 624 444
© 2026 Costa Aurea Capital Partners, S.L. All rights reserved.