Privacy policy
Last updated: 14 September 2026
This policy sets out how [RAZÓN SOCIAL], trading as Italica, handles the personal data of people who visit italicainsurance.com or write to us.
1. Data controller
- Company: [RAZÓN SOCIAL]
- Tax ID (NIF): [NIF]
- Registered office: [DOMICILIO SOCIAL]
- Phone: [TELÉFONO]
- Email: hello@italicainsurance.com
- Data protection contact: [DELEGADO DE PROTECCIÓN DE DATOS O CONTACTO DPD]
Italica is an independent insurance broker operating in Spain as an insurance intermediary. Its registration with the Spanish insurance regulator (Dirección General de Seguros y Fondos de Pensiones, DGSFP) is in progress. The remaining corporate and regulatory details appear in the legal notice.
2. What data we handle and where it comes from
- Technical data from your visit. IP address, date and time of the request, the resource requested, the response code, browser and device type. Your browser generates this data when it asks for the page, and our hosting provider receives it.
- Data you give us in the form or by email. Your name, your email address and, where you give them, your company, your phone number and whatever you put in the message: role, line of business, or details of the risk you are asking about.
We buy no databases and obtain no data about you from third parties. Please leave special categories of data, such as health data, out of your message until we ask for them and explain why.
3. Why we use your data, and on what legal basis
3.1. Browsing the site
This site is static and hosted by Cloudflare, Inc., a United States company with a global server network. Cloudflare processes IP addresses and technical connection data to deliver the page, route traffic and protect the site against attacks.
Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in keeping the site available and secure. The processing goes no further than serving a web page requires.
3.2. Fonts served by Google Fonts
The site loads its typefaces from Google servers at fonts.googleapis.com and fonts.gstatic.com. When it does, your browser sends your IP address and technical request data to Google LLC.
Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in presenting the site with consistent typography. If you would rather avoid that connection, block the Google domains in your browser. The page still works using the fonts installed on your device.
3.3. The contact form and email
The form at the foot of the page collects your name and email address and, where you choose to give them, your company, your phone number and a message about what you need to insure. Each submission is stored in a Cloudflare D1 database together with the date and an irreversible hash of your IP address, which serves only to curb automated submissions: we do not store the IP address itself. At the same time, Resend delivers the contents of the submission to us by email so that we can reply.
When you write to hello@italicainsurance.com, we use your data to read your message, reply to you and, if you ask for one, prepare an insurance proposal.
Legal basis: steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR) where your enquiry concerns quoting or arranging insurance. For anything else, such as sending you marketing you did not ask for, we will ask for your consent (Art. 6(1)(a) GDPR), and you can withdraw it at any time. The form's tick box records your express acceptance of this policy before each submission.
3.4. What we do not do
The only form on the site is the contact form described above. We run no analytics tools, no tracking pixels and no advertising. We set no first-party or third-party cookies for measurement or marketing. We build no profiles and take no automated decisions producing legal effects on you. The cookie policy covers this in detail.
4. Recipients and international transfers
We do not sell your data or share it for commercial purposes. The following parties may access it:
- Cloudflare, Inc., our hosting and security provider and the host of the D1 database that stores form submissions, acting as a processor.
- Resend, Inc., which delivers the email notification of each form submission to us, acting as a processor.
- Our email provider, which receives and stores the messages you send us.
- Google LLC, for the processing described in section 3.2.
- Public authorities and courts, where the law requires us to hand data over.
Cloudflare and Google are based in the United States. According to the information published by each provider, their transfers rely on the EU-US Data Privacy Framework and, as a further safeguard, on standard contractual clauses approved by the European Commission. Ask us and we will share the information we hold on this point.
When you request a quote or arrange cover through us, we will pass the necessary data to the insurers we approach for that risk. Where the law requires it, we will also pass data to the DGSFP and to the Consorcio de Compensación de Seguros, the Spanish state insurance compensation body. We will tell you before we send anything.
5. Retention
Technical hosting logs are kept for the short periods our provider sets for service security.
Form submissions, emails and related documents are kept for as long as our relationship lasts and, afterwards, for the applicable limitation periods. Insurance intermediation also carries the periods imposed by insurance distribution rules and, where relevant, anti-money-laundering rules. Specific period: [PLAZO DE CONSERVACIÓN PENDIENTE DE REVISIÓN JURÍDICA].
If your enquiry leads nowhere, we delete the message once the limitation period for any related claim has passed.
6. Your rights and how to exercise them
The GDPR gives you these rights:
- Access to the data we hold about you.
- Rectification of inaccurate data.
- Erasure where the data is no longer needed.
- Objection to processing based on our legitimate interest.
- Restriction of processing in the cases the law provides.
- Portability of the data you gave us.
- Withdrawal of consent at any time, without affecting the lawfulness of processing carried out before.
Write to hello@italicainsurance.com and say which right you are exercising. Where we have reasonable doubts about who is making the request, we will ask you to prove your identity. We reply within one month, extendable by two further months for complex requests. Exercising these rights costs you nothing.
7. Complaints to the Spanish data protection authority
If you believe we have not handled your request properly, you can complain to the Agencia Española de Protección de Datos (AEPD) at https://www.aepd.es. You may also raise it with us first, though you are under no obligation to do so.
8. Security
We apply measures proportionate to the risk: TLS encryption across the site, access control on our mailboxes and other systems, strong authentication for the team, and review of the providers that process data on our behalf. No system is immune. If a breach poses a high risk to your rights, we will tell you and notify the AEPD as the GDPR requires.
9. Children
This site addresses companies and professionals. We do not offer services to anyone under [EDAD MÍNIMA: 14 O 16 AÑOS, A CONFIRMAR] years of age, and we do not knowingly process their data. If we receive data from a minor without the authorisation of a parent or guardian, we will delete it. Tell us at hello@italicainsurance.com if you know of such a case.
10. Changes to this policy
We will update this policy when our processing, our providers or the applicable rules change. The date at the top identifies the current version. If a change affects you materially and we hold your email address, we will let you know.
This policy is governed by Regulation (EU) 2016/679 (GDPR) and by Spanish Organic Law 3/2018 on the protection of personal data and the guarantee of digital rights (LOPDGDD).