Legal
Privacy Policy
Last updated: August 2026
1. Data controller
BM DECORACIÓN ESPAÑA SL (“we”), registered at Calle Dublín 21, 29670 Marbella, Málaga, Spain, is the controller of your personal data under Regulation (EU) 2016/679 (the “GDPR”), Spanish Organic Law 3/2018 (“LOPDGDD”) and Portuguese Law 58/2019 (“GDPR-PT”). We sell exclusively to customers in Spain and Portugal; this policy covers both jurisdictions.
No Data Protection Officer (DPO) has been appointed as our primary processing does not reach the thresholds of Article 37 GDPR or Article 34 LOPDGDD. Privacy enquiries: privacy@bmdecor.es.
2. Categories of personal data
We may process the following categories of personal data:
- Identification and contact: name, email, telephone, postal / billing / shipping address, NIF or CIF (when an invoice is requested), language preference. A contact telephone is requested when you place an order so we can reach you about that delivery or collection — for example if the courier cannot get an answer at the door. We use it to fulfil your order and never as a marketing channel: we will not send you commercial messages by telephone, SMS or WhatsApp on the basis of this number.
- Account: AWS Cognito identifier (sub), encrypted password, creation and last sign-in dates, group (Customer / Pros / Employee / Administrator).
- Commercial: order history, basket contents, wishlist, saved Project Palettes, Stripe customer identifier and payment-method token (we never access the full card number) and, for orders invoiced through this website, invoice numbers and PDF copies.
- Professional (Pros): company name, VAT number, project addresses, professional sector.
- Communications: customer-service email content, newsletter-subscription status (including the pending state while a double-opt-in confirmation is awaited), email deliverability events (bounces and spam complaints, which we process to stop further sending to the affected address), and post-purchase follow-up emails (for example, after a colour sample) sent only with your marketing consent. At checkout we also display a notice (art. 21.2 LSSI) that, as our customer, you may receive occasional email offers about our own similar products and services; you can object right there, from your account’s communication preferences, or free of charge via the unsubscribe link in every such email, and we record with your order when the notice was shown and whether you objected. We also keep a record of each service email a member of our team sends you from our admin system — the date, the address it went to, the subject line, the language it was written in and which staff member sent it — so we can account for what we have told you. The message text itself is not kept in that record. Separately from marketing, we record your invoice-delivery choice (art. 63.3 TRLGDCU): whether you have expressly consented to receive your invoices electronically by email, when, through which surface (checkout, your account, or a request you made to our staff) and the exact wording you agreed to — you can revoke it at any time in My Studio → Invoice delivery or by writing to info@bmdecor.es, and invoices then reach you on paper free of charge.
- Technical / device: IP address — kept in full only where it is the record of a consent you gave (newsletter, cookie choices, communication preferences, stock alerts, electronic invoicing) and in our security and CDN access logs for a maximum of 90 days; anonymised in Google Analytics; and reduced to a one-way keyed hash, never stored as an address, in the request rate limiting that protects our public pages — browser, OS, screen size, cookie identifiers, session ID, referring URL, city-level geolocation derived from IP.
- Behavioural (consent-based only): page views, click events, searches, colour viewed, add-to-cart and checkout steps in PostHog; if you sign in or complete an order, this activity is linked to your account identifier and email to measure the full shopping journey. Session recording is currently disabled. Searches are also counted in our own system as a per-word total (see the search-term row in the table below).
- Error monitoring: error traces captured by PostHog Error Tracking, route, breadcrumbs, pseudonymous user identifier.
- Returns and refunds: when you return an order — return reason and free-text description, case classification, defect or transit-damage photos and batch/lot numbers you provide, restock decisions, and the amount refunded.
- Business relationship (CRM): for customers whose history with our shop predates this website, the commercial-relationship record migrated from our former management system (Odoo): the internal reference number that system used for you, your NIF/CIF where invoicing required one, the company you are recorded as a contact of — its name, tax id and your role there — relationship labels carried over from that system (for example, your professional sector), the fact that a member of our sales team is assigned to you, the date you became a customer, the date and number of your purchases with us, and the date of our last recorded contact with you.
- Interaction history: our record of contact with you — the service emails we send you (subject line, date and language, never the message text itself), and notes a member of our team logs about a phone call, an in-store visit, a WhatsApp or SMS exchange: what the conversation was about, what came of it, and when it happened.
- Sales opportunities (projects and jobs): when we are quoting for a decorating project — the project or site name, its location, the estimated value, the date we expect a decision, the stage it has reached in our sales pipeline, and internal notes our team keeps about it. The project may be recorded in your own name, or in the name of a company for which you are the named contact.
- Promises and follow-ups: what a member of our team undertook to do for you and by when — a call to make, a quote to send, a paint-quantity calculation, colour options to prepare — together with the day and time committed to, whether it was completed, and, if the date was moved, the date first promised. It may be recorded in your own name, or in the name of a company for which you are the named contact.
- Records carried over from our previous system (archive only): until 2026 our shop ran on a business system we are now retiring. Before switching it off we have been copying its records into our own private archive so that the shop does not lose its memory of your account: a small number of free-text working notes our staff had written on customer records — practical working knowledge such as access arrangements at a site, who to ask for, or what went wrong on a previous job — the sales-opportunity records alongside them (the project or job, its stage, its estimated value and the dates), and, from August 2026, a complete backup of that system's business records, including your orders and till purchases there, payments, appointment and meeting records, and the correspondence we exchanged with you. This archive is kept in cold storage only: no part of our website or admin system reads it, it is not shown to staff, and nothing is decided from it. You can ask us for a copy of what it holds about you, or ask us to delete the parts that are not tax records, at privacy@bmdecor.es.
We do not knowingly process special-category data (Article 9 GDPR) nor collect official identification numbers beyond NIF/CIF for invoicing.
3. Purposes and legal bases
| Purpose | Legal basis | Retention |
|---|---|---|
| Account creation and authentication | Contract (6.1.b) | Until account closure |
| Order management and delivery | Contract (6.1.b) | 6 years (Art. 30 Commercial Code) |
| Tax and accounting compliance | Legal obligation (6.1.c) — Law 58/2003 | 6 years |
| Stripe payment and fraud prevention | Contract (6.1.b) + legitimate interest (6.1.f) | Per Stripe DPA |
| Customer service | Legitimate interest (6.1.f) | 3 years from last contact |
| Newsletter / marketing | Consent (6.1.a) — opt-in | Until unsubscribe; unconfirmed sign-up requests (double opt-in) are never mailed and lapse |
| Analytics (PostHog) | Consent (6.1.a) — Art. 22.2 LSSI-CE | 12 months |
| Error monitoring (PostHog Error Tracking) | Legitimate interest (6.1.f) | 90 days |
| Saved Project Palettes | Contract (6.1.b) | Until account deletion |
| Trade account terms and pricing | Contract / pre-contractual (6.1.b) | 4 years |
| Returns, refunds and guarantee claims | Contract (6.1.b) + legal obligation (6.1.c) — consumer guarantee | 24 months after the return is resolved; reason text and photos deleted on erasure |
| Advertising and remarketing (Google Ads) | Consent (6.1.a) — Art. 22.2 LSSI-CE | 90 days (Google Ads _gcl_au); conversion/audience data per Google Ads settings |
| Sales-counter quotes (presupuestos) | Contract / pre-contractual (6.1.b) | Unconverted quotes: contact details anonymised 24 months after last activity; converted quotes follow the invoice retention (6 years) |
| Service emails sent to you by our team | Contract (6.1.b) + legitimate interest (6.1.f) | 6 years (audit log — the record of the send only, never the message text) |
| Customer record kept for your orders (including checkout without an account) | Contract (6.1.b) + legitimate interest (6.1.f) | 6 years, alongside the order it belongs to (Art. 30 Commercial Code); deleted on erasure |
| Invoice-delivery choice (electronic invoice with your express consent, art. 63.3 TRLGDCU) | Legal obligation (6.1.c) — consumer law requires us to obtain, record and honour your express consent before sending invoices electronically, and to keep the free paper route available | While your choice stands (on your customer record); the change history is kept as audit rows for 6 years; the consent recorded with each order follows the order's 6-year retention |
| Identity record for high-value cash payments by non-residents (ID document type, number and country of tax residence) | Legal obligation (6.1.c) — Ley 7/2012 art. 7 permits cash of €1,000–€10,000 only from non-resident individuals and requires us to keep the supporting evidence | 5 years minimum (Ley 7/2012 art. 7.Cinco), kept with the sale's fiscal records (6 years, Art. 30 Commercial Code); cannot be erased earlier — it is the legal justification for having accepted the payment |
| Customer-relationship history migrated from our former management system (Odoo) — see "Business relationship (CRM)" above | Legitimate interest (6.1.f) — continuity of service to existing customers | Kept while the customer relationship lasts; deleted or anonymised if you request erasure |
| Keeping a record of our contact with you, so anyone on our team can pick up where the last conversation left off | Legitimate interest (Art. 6(1)(f)) — running a coherent customer service | Kept while the customer relationship lasts; deleted if you request erasure |
| Managing the projects and jobs we are quoting for (our sales pipeline) | Legitimate interest (Art. 6(1)(f)) — managing our commercial relationship and following up on work you have asked us to price; performance of a contract (Art. 6(1)(b)) where you have requested a quotation | Kept while the project is live and for a bounded period after it closes. A project recorded in your own name is deleted if you request erasure; where the project belongs to a company and you are only its named contact, your link to it is removed and the company's commercial record remains |
| Customer stage — we work out nightly whether you are mid-project, quiet or overdue for a repaint, from how often and how recently you have bought from us and in which product category. Staff see one word (new, active, at risk, lapsed, won back) so they know who to look after; you never see it and nothing about your price, your products or your rights depends on it | Legitimate interest (6.1.f) — running a small specialist shop that remembers its own customers. We use only your purchase record with us; we never buy or add data from anywhere else. You can object at any time and you do not have to give a reason: switching off marketing emails also stops us working out when to contact you next, not just the emails themselves. A full written assessment of this balancing exercise is available on request | Only the current value on your customer record — we keep no history of past stages — and it is deleted outright when your record is erased |
| Archive of our previous business system — the working notes our staff had written on customer records, the sales-opportunity records (project, stage, estimated value, dates) and, from August 2026, a complete backup of that system's business records (your orders and till purchases there, payments, appointments and our correspondence with you), copied into our own private storage before that system was switched off so the shop does not lose its memory of your account | Legitimate interest (6.1.f) — not losing years of our own business records and working knowledge at a forced system change. The archive is held in cold storage: no part of our website or admin reads it, no member of staff is shown it, and no decision is taken from it. The parts that are not tax records are not covered by the 6-year rule, and you can ask us to delete them at any time. A full written assessment of this balancing exercise is available on request | Until we decide whether to bring this material into our current system, and reviewed when the old system is finally closed out. Deleted on request — we remove the material from every copy of the archive, including earlier snapshots and previous file versions |
| Counting the words typed into the shop's search, so we can see which ones find nothing and add them to the shop's search vocabulary. A total per word, per part of the site — no visitor, session or device identifier is stored with it, and there is no way to reconstruct what any one person searched for | Consent (6.1.a) — the same Analytics consent as the cookie notice. Searches typed by our own staff at the shop counter are counted under legitimate interest (6.1.f) instead: they are our staff using our own internal tool, and the count still identifies nobody | 90 days, after which the figures delete themselves automatically |
4. Data processors and recipients
We rely on the following data processors:
- Amazon Web Services EMEA SARL — cloud infrastructure (AWS Amplify, Lambda, DynamoDB, S3, Cognito, Secrets Manager, KMS, CloudFront). Primary processing region: Ireland (eu-west-1). Safeguards: AWS DPA and EU Standard Contractual Clauses for any sub-processor outside the EEA. Certifications: ISO 27001 and SOC 2.
- Amazon Web Services SES — transactional email (order confirmations, password resets, withdrawal acknowledgements). Region: eu-west-1. Safeguard: AWS DPA.
- Stripe Payments Europe Ltd — payment processing (PSP), card tokenisation and fraud prevention. Region: Ireland; sub-processors at Stripe, Inc. (US). Safeguards: Stripe DPA, EU Standard Contractual Clauses, and EU-US Data Privacy Framework (DPF) where applicable; PCI-DSS Level 1. We never access your full card number.
- PostHog Inc. — product analytics. Hosting region: European Union (Frankfurt, Germany — PostHog EU Cloud); PostHog is a US-incorporated provider, and its DPA with EU Standard Contractual Clauses covers any residual access from outside the EEA. Activated only with your explicit consent. With your consent, if you sign in or complete an order we link your account identifier and email to your browsing activity to measure the full shopping journey; this analytics profile is deleted through the same account-erasure process as the rest of your data. Supplementary measures: IP anonymisation, PII exclusion, automated PII filtering on autocapture.
- PostHog Error Tracking — error monitoring built into the same PostHog project as analytics (not a separate provider). Error traces are auto-captured from the browser and from Lambda; PII is filtered before send; session recording is off. Basis: legitimate interest (Article 6.1.f) for diagnostics and security.
- Carrier (last-mile delivery) — the courier assigned to your shipment receives only the data strictly necessary for delivery (name, address, phone, order weight). The carrier is listed in your shipping email.
- Accountancy / gestoría — an external advisor in Spain processes invoicing data for tax filings under a confidentiality agreement.
- Google Ireland Ltd / Google LLC — Google Analytics (web analytics, enabled only with your Analytics consent), Google Ads (advertising measurement and remarketing, enabled only with your Advertising consent: with that consent we share ad-interaction signals — the ad_storage, ad_user_data and ad_personalization signals under Google Consent Mode v2 — so Google can attribute conversions and build audience lists; we do NOT send hashed customer identifiers, i.e. Enhanced Conversions are not used), Google Tag Manager (loads the above tags in a consent-aware way; sets no cookies of its own), Google Customer Reviews (post-purchase rating survey: if you opt in, we share your email, order number and estimated delivery date so Google can send you the survey), and Google Merchant Center (product catalogue for Google Shopping). Region: USA. Safeguards: EU Standard Contractual Clauses and the EU–US Data Privacy Framework (DPF); IP anonymisation in Analytics.
- Orac NV (Orac Décor · Noël & Marquet) — when your order contains Orac Décor or Noël & Marquet items, the manufacturer dispatches them to you directly from its factory and receives only the data strictly necessary for that dispatch (name, delivery address and the items to send — or our shop address for Click & Collect orders). Legal basis: performance of the purchase contract (art. 6.1.b GDPR). Region: Belgium (EU).
We do not sell or rent personal data to third parties for their own marketing.
5. International transfers
Analytics data is hosted by PostHog inside the EU (Frankfurt, Germany) and does not constitute an international transfer. When data is transmitted outside the European Economic Area — primarily to Stripe sub-processors and Google in the US — we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) supplemented with the safeguards required by the CJEU's Schrems II ruling (Case C-311/18). These measures include encryption in transit, pseudonymisation, and contractual restrictions on access by foreign authorities. Where Stripe or Google rely on the EU-US Data Privacy Framework, we also rely on that adequacy decision.
6. Your rights
Under Articles 15-22 GDPR and the LOPDGDD, you have the following rights:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure (“right to be forgotten”) — request deletion, subject to retention periods imposed by tax law.
- Portability — receive your data in a structured, commonly used and machine-readable format, and transmit it to another controller.
- Restriction of processing in the cases provided for by law.
- Objection to processing based on legitimate interest, including objection to direct marketing.
- Withdrawal of consent at any time, without affecting the lawfulness of prior processing.
- Not to be subject to automated decisions with legal effects (Article 22).
You can exercise your access and erasure rights directly from your account settings:
- Download my data — one-click exercise of the right of access (Article 15). Returns a JSON file with every piece of personal data we hold about you, including order history, basket, newsletter subscription, submitted enquiries, and the Cognito profile.
- Delete my account — one-click exercise of the right of erasure (Article 17). Anonymises your order history (the accounting record of each purchase, including the header of any invoice issued for it, is retained for the 6-year period required by the AEAT), fully deletes your basket, newsletter subscription and submitted enquiries, and removes your user record from Cognito. We email you a confirmation in Spanish summarising what was deleted and what was retained.
For the remaining rights — rectification, restriction, objection, portability of data not included in the JSON export — write to privacy@bmdecor.es. We may request proof of identity to verify your request and will respond within one month, extendable by two months for complex requests (Article 12 GDPR).
7. Automated decisions
We do not make fully automated decisions with legal or significant effects. Stripe applies automated fraud filtering (Stripe Radar) to authorise or decline payments; this is a legitimate-interest process operated by the processor and not a decision made by us. You can contact us to obtain a human review of any payment declined for fraud reasons.
8. Minors
Our service is not directed at persons under 14 (the digital-consent age in Spain under Article 7 LOPDGDD). We do not knowingly collect personal data from minors under 14. If you believe a minor has provided us with data, write to privacy@bmdecor.es and we will delete it.
9. Security
Under Article 32 GDPR we apply technical and organisational measures appropriate to the risk: TLS for all traffic, AWS Cognito for password encryption, AWS KMS for encryption at rest, least-privilege IAM, AWS CloudWatch for security logging and alerting, and AWS WAF with rate limiting on the public site. Our CDN (cdn.bmdecor.es) keeps access logs (including IP addresses) for security monitoring and incident investigation, retained for a maximum of 90 days. Changes to our AWS infrastructure, and administrative changes made directly to our database outside the website, are recorded in an administrative audit log (the action, the identifier of the record changed, the account responsible and its IP address), with a maximum retention of 90 days; that log records our own staff's administrative activity, not customer activity. Internal access to personal data is restricted to authorised staff under confidentiality obligations.
10. Cookies
We use essential cookies to maintain your session and shopping cart. Analytics cookies (PostHog and Google Analytics) and advertising cookies (Google Ads) are enabled only with your explicit, category-specific consent via the cookie banner — you can accept or reject Analytics and Advertising independently — in line with Article 22.2 LSSI-CE and the AEPD's 2024 Cookie Guide. See our Cookie Policy for the full inventory.
11. Supervisory authorities
You have the right to lodge a complaint with the supervisory authority of your country of residence, without first contacting us.
Spain — Agencia Española de Protección de Datos (AEPD):
- Address: C/ Jorge Juan, 6, 28001 Madrid
- Phone: 901 100 099 / 91 266 35 17
- Web: www.aepd.es
Portugal — Comissão Nacional de Proteção de Dados (CNPD):
- Address: Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa
- Phone: +351 213 928 400
- Web: www.cnpd.pt
12. Changes to this policy
We may update this policy to reflect operational, legal or technical changes. The “Last updated” date in the header reflects the latest change. Material changes are notified by email and consent is re-obtained via the cookie banner when consent is the affected legal basis.