Skip to main content
Company logo
About usContact
Client access

Privacy Policy

How we handle the personal data of anyone who visits this site, writes through the contact form, applies for a job, uses the whistleblowing channel or signs in to the private area.

Last updated:25 September 2026

On this page

  1. 1. Who processes your data
  2. 2. Data we collect
  3. 3. What we use it for, and on what legal basis
  4. 4. Who we share it with
  5. 5. International transfers
  6. 6. How long we keep it
  7. 7. Your rights
  8. 8. Minors
  9. 9. Cookies
  10. 10. Security
  11. 11. Contact

1. Who processes your data

The data controller — who decides why and how your data is used — is:

Controller: Imora Servicios S.L.

Tax ID: 51476534G

Registered address: Plaza Doctor Fleming, 4, 05270 El Tiemblo (Avila)

Data protection email: info@imora.es

Data protection: Questions about this policy and requests to exercise your rights are handled at the email address above. If a Data Protection Officer is appointed at any point, their contact details will be published here and notified to the Spanish Data Protection Agency.

2. Data we collect

We collect what you give us in each form and what your use of the site generates. Nothing else: we do not buy lists and we do not obtain your data from third-party sources.

Data you give us

  • Quote request or enquiry: name, name of the community or company, email and/or phone, and the message you write. If you answer them — they are optional — also the qualifying questions: profile (community, property manager or company), service you are interested in, area, expected timeframe and number of properties you manage.
  • Marketing communications: if you tick that box, your consent to receive commercial information about our services. It is a separate box of its own.
  • Source of the enquiry: if you accepted analytics cookies in the cookie notice, the campaign parameters of the address you arrived from (utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid, fbclid), the landing page and the site that linked to us. If you did not accept them, they are neither collected nor sent.
  • Job applications: first and last name, email, phone, town, cover letter, LinkedIn profile if you provide one, and your CV as a PDF. We do not ask for a photograph, date of birth, nationality or ID number.
  • Whistleblowing channel: the facts you report and, if you choose to identify yourself, your name and email. You may file the report anonymously.
  • Clients with a private area: your account details (name, email, community or building managed) and the quotes, invoices and incidents linked to your contract.
  • Resident app: your account, the unit you occupy in the community and the incidents you report through it.

Data collected automatically

  • Usage data: pages visited, time spent and actions taken, only if you accept analytics cookies.
  • Device data: device type, operating system and browser.
  • Approximate location: country and region inferred from your IP address, so we know which areas potential clients visit us from. It is not your exact location and it does not come from GPS.
  • Form protection: when you submit any public form, Cloudflare Turnstile receives your IP address and technical browser data in order to tell people apart from automated submissions. It is essential for the form to work.
  • Maps: pages that show a map request the imagery from an external provider (Esri), which receives your IP address when serving it. It happens as soon as the map is drawn, it is part of displaying the page and it sets no cookies.

3. What we use it for, and on what legal basis

Each purpose has its own legal basis and its own retention period. This is the full list:

PurposeLegal basisRetention
Answering your quote request or enquiry and preparing a proposal.Your consent, art. 6(1)(a) GDPR.1 year from the last contact, unless the enquiry leads to a contract.
Sending you marketing communications about our services.Your express consent, in a separate box: art. 6(1)(a) GDPR and art. 21 LSSI.Until you unsubscribe, from the link in every email.
Recording where the enquiry came from (campaign, referrer) to see which channels work.Your consent, given by accepting analytics cookies: art. 6(1)(a) GDPR and art. 22.2 LSSI.The same as the enquiry it belongs to.
Assessing your application in a recruitment process.Pre-contractual steps at your request, art. 6(1)(b) GDPR.The CV, 6 months; the rest of the application, 1 year.
Keeping your application for future openings (talent pool).Your express consent, art. 6(1)(a) GDPR.12 months from the moment you give it.
Handling a report filed through the whistleblowing channel.Legal obligation, art. 6(1)(c) GDPR and Spanish Act 2/2023.3 months from receipt if no investigation is opened; if one is, for as long as it lasts and as long as needed to document it.
Providing and managing the contracted service and giving you access to the private area.Performance of the contract, art. 6(1)(b) GDPR.For the duration of the contract and, afterwards, the applicable limitation periods.
Meeting accounting, tax and invoicing obligations.Legal obligation, art. 6(1)(c) GDPR.6 years under the Spanish Commercial Code and 4 under the General Tax Act, from the close of the financial year.
Logging access and operations so a security incident can be investigated.Our legitimate interest in protecting the platform and the data in our custody, art. 6(1)(f) GDPR.Audit log 1 year; private-area access log 6 months; inactive sessions 30 days.
Measuring site usage in aggregate in order to improve it.Your consent in the banner, art. 6(1)(a) GDPR and art. 22.2 LSSI.As stated in the cookie policy.
Preventing automated form submissions.Our legitimate interest in protecting ourselves from spam and abuse, art. 6(1)(f) GDPR.Whatever the verification provider applies.

Do you have to give us this data? The fields marked with an asterisk are the ones we need for what you are asking: without them we cannot answer your enquiry or process your application. The rest are optional and leaving them blank has no consequence.

Automated decisions: We do not take automated decisions and we do not build profiles that produce legal effects concerning you or similarly significantly affect you. Decisions about your enquiry, your application or your incident are taken by a person.

Withdrawing consent: Where the basis is your consent you can withdraw it at any time by writing to our data protection address or, for cookies, from the preferences panel. Withdrawing is as easy as giving it and does not affect the lawfulness of processing carried out beforehand.

4. Who we share it with

We do not sell or rent your personal data. The following have access to it, solely in order to provide us with their service and under a processor agreement signed in accordance with art. 28 GDPR:

  • Hosting and infrastructure: whoever hosts the site, the private area and the database.
  • Email delivery: the service that sends out notices, confirmations and marketing messages.
  • File storage: where attached documents, incident photos and CVs are kept.
  • Analytics: Google, only if you accept analytics cookies.
  • Form protection: Cloudflare, which verifies that whoever submits a form is a person.
  • Field staff assigned to your service: if you are a client, the Imora staff — concierge, maintenance, cleaning or other — who need your contact details or your community's in order to deliver the contracted service.
  • Public authorities: the tax agency, social security, law enforcement and the courts, where a legal rule requires us to provide the data.

The map provider (Esri) is not a processor: it is a third party that receives your IP address when serving the map imagery, like any server the browser requests a file from. Beyond the above there is no disclosure of data. Should there be one in future, it will be announced on this page before it happens.

5. International transfers

Some of the providers above are located in the United States, so part of the processing involves an international transfer. These are the transfers there are, and the safeguard for each:

  • Google (analytics): only if you accept analytics cookies. Google LLC is certified under the EU-US Data Privacy Framework, which the European Commission found to provide an adequate level of protection by decision of 10 July 2023, and standard contractual clauses are in place as an additional safeguard.
  • Cloudflare (form protection): receives your IP address and technical browser data when you submit a form. Cloudflare, Inc. is certified under the same Data Privacy Framework and has standard contractual clauses in place.
  • Esri (maps): receives your IP address when serving the map imagery on pages that show a map. The transfer relies on standard contractual clauses approved by the European Commission.

Beyond these cases we do not transfer personal data outside the European Economic Area. You can ask us for a copy of the safeguards in place by writing to our data protection address.

6. How long we keep it

The retention period for each purpose is in the table in section 3. As a general rule we keep data for as long as the purpose it was collected for lasts and, after that, blocked for the limitation periods of any liabilities that may arise — four years for tax matters, six for commercial matters and whatever applies in employment matters — available only on request from judges, courts or public authorities.

Once those periods have passed we delete the data or anonymise it so that you can no longer be identified from it.

7. Your rights

You may exercise the following rights over your personal data, free of charge:

  • Access: find out what data of yours we process and get a copy.
  • Rectification: correct inaccurate data or complete what is missing.
  • Erasure: ask us to delete it once it is no longer needed (the “right to be forgotten”).
  • Restriction of processing: ask us to keep the data but stop using it while a challenge or an objection is resolved.
  • Portability: receive the data you gave us in a structured, commonly used format, or have us send it to another controller.
  • Objection: object to processing based on our legitimate interest, and in any case to marketing communications.
  • Withdrawal of consent: withdraw at any time any consent you have given, without that affecting the lawfulness of earlier processing.

To exercise any of them write to us at info@imora.es stating which right you are exercising. We may ask you to prove your identity if we have reasonable doubts about who is making the request.

Response time: one month from receipt of your request. If it is particularly complex, or several requests pile up, that period may be extended by two further months, and we will tell you within the first month and explain why.

Lodging a complaint with the supervisory authority: if you believe we have not handled your request properly, or that we are processing your data improperly, you may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid). You do not have to complain to us first, although we would like the chance to sort it out. www.aepd.es

8. Minors

This site is not aimed at minors. In Spain, from the age of fourteen a person may consent to the processing of their data on their own (art. 7 of the Spanish Data Protection Act); below that age the consent of whoever holds parental authority or guardianship is required.

Even so, the contact form asks you to declare that you are of legal age: what is requested there is a service contracted for a community, a building or a company, and there is no sense in processing it with a minor. If we find that we have received a minor's data without the necessary consent, we delete it as soon as we know.

9. Cookies

We use cookies and similar technologies. See our Cookie Policy for details of which ones we use, how long they last and how to accept them, reject them or change your mind later.

10. Security

We apply technical and organisational measures appropriate to the risk, in line with art. 32 GDPR:

  • SSL/TLS encryption on all communications with the site and the private area.
  • Passwords are not stored: what is kept is a cryptographic hash that cannot be reversed.
  • Two-step verification available on internal access.
  • Role-based access: each person sees what they need for their job and nothing more.
  • A log of who consults or changes what, so an incident can be reconstructed.
  • Antivirus scanning of every uploaded file before it is stored.
  • Regular backups and restore testing.

If something goes wrong: we keep an internal register of security breaches. If one of them poses a risk to your rights, we notify the Spanish Data Protection Agency within the 72 hours required by art. 33 GDPR and, where the risk is high, we tell you as well.

To report a security incident, write to info@imora.es.

11. Contact

For any question about this policy, or to exercise your rights, write to us:

Data protection

Email: info@imora.es

Address: Plaza Doctor Fleming, 4, 05270 El Tiemblo (Avila)

  • Careers
  • Blog
  • Contact
  • info@imora.es
  • +34 644 51 40 90
  • Plaza Doctor Fleming, 4, 05270 El Tiemblo (Avila), España
App Logo
Change language
Services
  • Concierge and access control
  • CCTV and Access Control
  • Pool maintenance
  • Cleaning for communities and buildings
  • Gardening and green areas
  • Maintenance for communities and buildings
  • Property managers
Coverage areas
  • Madrid
  • Pozuelo de Alarcón
  • Alcorcón
  • Majadahonda
  • Las Rozas de Madrid
Help
  • Support
  • FAQ
  • File a complaint

© 2026 Imora by NextAura All rights reserved.

  • Privacy policy
  • Terms of use
  • Cookie policy
  • Complaints channel