Last updated: 27 July 2026.
Privacy policy
In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), and Spanish Organic Law 3/2018 of 5 December on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD), we provide below information on the processing of your personal data.
01. Who is the controller of your personal data?
The controller of your personal data is Mirlo Legal, S.L.P. (hereinafter, “Mirlo”), with NIF B23887888, registered address at Claudio Coello 33, Ground Floor C, 28001 Madrid, Spain, and contact telephone number +34 919 517 221.
This Privacy Policy provides information on how we use your personal data in your capacity as a user of this Website and its associated contact channels.
For any query concerning the processing of your personal data, or to exercise your rights, you may contact Mirlo at privacy@mirlo.legal.
02. Personal data we process, legal basis and purposes
2.1 Data relating to browsing the Website
Simply by browsing the Website, the servers hosting it automatically record certain information, specifically: browser type, operating system and the IP address used to access the Website.
In addition, we use technical cookies, which are exempt from the requirement for express consent under Article 22.2 LSSI. A detailed list and explanation of how they work is available in our Cookie Policy.
The legal basis for creating server log files is Article 6(1)(f) GDPR, namely the controller’s legitimate interest.
This legitimate interest lies in ensuring the proper operation of our Website, conducting security analyses and protecting against third-party threats, as well as protecting the information contained on our Website. This also benefits you by enabling safe and fast browsing and continuous security analysis to prevent and stop denial-of-service attacks.
Providing these data is inherent in browsing the Website. Therefore, if you do not wish to provide them, you should refrain from using the Website.
2.2 Analytics cookies
When you accept our analytics cookies —which are provided by the Squarespace platform on which the Website is built— certain information is collected and recorded. Further information is available in our Cookie Policy.
The legal basis for processing these data is Article 6(1)(a) GDPR, namely your consent as a user. You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal. Acceptance of these cookies is entirely voluntary: refusing them does not prevent you from browsing the Website.
2.3 Data provided through our contact channels
If you contact Mirlo through the email addresses provided on this Website (including privacy@mirlo.legal) or through our LinkedIn profile, we will process your identification and contact data, together with any other information you voluntarily include in your communication, for the purpose of responding to your query or request and, where applicable, managing the exercise of your data protection rights.
The legal basis for this processing is taking pre-contractual steps at your request (Article 6(1)(b) GDPR) where your query relates to our professional services; compliance with legal obligations (Article 6(1)(c) GDPR) where the matter concerns the exercise of rights; and, in all other cases, our legitimate interest in responding to communications received (Article 6(1)(f) GDPR).
Please do not include special categories of personal data (for example, health data) or unnecessary third-party information in your initial communications, unless this is essential for us to deal with your request. Providing your identification and contact details is necessary for us to respond; if you do not provide them, we will be unable to deal with your communication.
03. International transfers of personal data and other disclosures of personal data
The Website is built and hosted on the Squarespace provider platform (Squarespace Ireland Ltd., with data processing by Squarespace, Inc., a US entity), which acts as Mirlo’s data processor. This entails an international transfer to the United States of America of the browsing data described in this Policy (server logs and, where applicable, data derived from analytics cookies).
In addition, for the management of corporate email —including the privacy@mirlo.legal account through which the rights recognised in this Policy may be exercised— Mirlo uses Microsoft 365 services, provided by Microsoft Ireland Operations Ltd. as data processor. Although these services are generally provided from data centres located in the European Union, their use may involve limited international transfers of personal data to the United States of America in favour of Microsoft Corporation.
These transfers are covered by the European Commission adequacy decision of 10 July 2023 concerning the EU-U.S. Data Privacy Framework, adopted pursuant to Article 45 GDPR, as both Squarespace, Inc. and Microsoft Corporation are certified under that framework.
In addition, should that framework cease to apply, both providers have entered into the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 with their customers, as an appropriate safeguard pursuant to Article 46(2)(c) GDPR.
Further information is available in the privacy policies of both providers (https://www.squarespace.com/privacy and https://privacy.microsoft.com), and their certifications may be verified at https://www.dataprivacyframework.gov.
In addition, if you use the LinkedIn contact service, you may share data with that platform. In that case, we recommend that you review its privacy policy to understand the scope of the processing: https://es.linkedin.com/legal/privacy-policy.
Finally, no other disclosures will be made to third parties unless required by a legal obligation applicable to Mirlo, for example to public authorities or courts.
04. Retention of your personal data
We will retain your personal data for the following periods, depending on the relevant category:
– Server logs (browsing data) will be retained for a maximum period of twelve (12) months from collection for security purposes.
– Data derived from cookies will be retained for the periods specified for each cookie in our Cookie Policy.
– Data provided through our contact channels will be retained for the time necessary to deal with your query or request and, thereafter, for the statutory limitation period applicable to any legal liabilities that may arise.
In all cases, once the purpose for which the data were collected has been fulfilled, we will keep your data duly blocked until the limitation period for any potential legal liabilities arising from the processing has expired.
05. Your rights in relation to your personal data
Where the processing of your personal data is based on consent, you have the right to withdraw your consent at any time.
In addition, to the extent applicable, you are entitled to exercise the following rights:
- Right of access: to confirm whether we are processing your personal data and exactly which personal data are being processed, together with the processing operations carried out on them.
- Right to rectification: to correct your personal data where they are inaccurate or to update them.
- Right to erasure: to request deletion of your personal data where possible.
- Right to request restriction of the processing of your personal data: where the accuracy, lawfulness or necessity of the processing is disputed, in which case we may retain the data for the establishment, exercise or defence of legal claims.
- Right to data portability: where the legal basis authorising us to process the data is a contractual relationship or consent.
- Right to object: to request that your personal data no longer be processed on grounds relating to your particular situation. In such cases, we will cease processing your data unless we have compelling legitimate grounds or the processing is necessary for the establishment, exercise or defence of legal claims.
You may exercise these rights, or request further information about them, by emailing privacy@mirlo.legal.
We will respond to your request within a maximum of one month from receipt, extendable by a further two months depending on the complexity and number of requests. In that case, we will inform you of the extension and the reasons for it within the first month (Article 12(3) GDPR).
If you receive no response, consider that your request has not been properly addressed, or believe that your data have been processed unlawfully, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, https://www.aepd.es/es).
06. What we do to keep your personal data secure
Mirlo applies appropriate technical and organisational measures to ensure a level of security appropriate to the risk of the processing it carries out, in accordance with Article 32 GDPR, taking into account the state of the art, implementation costs and the nature, scope, context and purposes of the processing.
All our personnel have undertaken to treat your data with the utmost confidentiality.
Nevertheless, technical security in an environment such as the Internet is not impenetrable and malicious acts by third parties may occur, although Mirlo uses all means reasonably available to prevent them.
07. Amendments to this data protection information
Mirlo may amend this data protection information to adapt it to the legislation in force from time to time or to changes in the processing of personal data. In the event of substantial changes, we will notify you through a prominent notice on this Website. The last-updated date shown in the header will allow you to identify the version in force at any time.