Privacy Policy
At Bloom The Brand, we take your trust very seriously. That’s why we want to clearly and simply explain how we handle your personal data. On this page, you’ll find all the information about what data we collect, how we use it, and how we protect it when you visit our website or get in touch with us.
DATA PROTECTION INFORMATION
The Data Controller makes this Privacy Policy available to you through the website https://bloomthebrand.com/ (hereinafter, Bloom The Brand or our Website), in order to inform you in detail about how we process your personal data and protect your privacy and the information you provide to us.
If we make any changes to this policy in the future, we will notify you via this same website or through other means so that you can be aware of the new privacy conditions introduced.
This Privacy Policy also applies to the processing of personal data of potential clients for the purpose of sending email marketing, product promotions, and any other activity or event promoted through our Website.
We inform you, in accordance with current Spanish and European regulations on personal data protection on the internet and in compliance with the following regulations:
- Regulation (EU) 2016/679, General Data Protection Regulation (GDPR),
- Organic Law 3/2018 of December 5 on Personal Data Protection and guarantee of digital rights,
- Royal Decree 1720/2007 of December 21, approving the regulations implementing Organic Law 15/1999 of December 13 on Personal Data Protection,
- Law 34/2002 of July 11 on Information Society Services and Electronic Commerce.
WHO IS RESPONSIBLE FOR PROCESSING YOUR DATA?
In compliance with the General Data Protection Regulation (GDPR), we inform you that the data controller of the data collected through this website is Iratxe del Olmo, identified with NIF number 72854275G.
For any queries related to data protection or to exercise your rights, you may contact us via the email address associated with this website: info@bloomthebrand.com.
All information related to our services and conditions is available on the official website: https://bloomthebrand.com.
FOR WHAT PURPOSE DO WE PROCESS THE DATA WE COLLECT FROM YOU ON OUR WEBSITE?
On our website, we generally collect and process your personal data in order to manage the relationship we maintain with you. The main purposes are outlined below:
- For the contracting of services offered on our website, such as brand identity design, web design and development, hosting and maintenance services, copywriting, SEO architecture, illustrations, animations, naming, packaging design, or other services for the development of your brand or website, as well as workshops, courses, and training, your data will be used for management, contracting, billing, and client retention.
- In the case of subscribing to our website, newsletter, or similar services, your data will be used to manage subscriber and user lists, as well as to send relevant information.
- If you request our guides or other resources available on our website, your data will be used to complete the necessary registrations and forms required to access such content.
- When you submit inquiries, suggestions, or complaints, your data will be used to manage and respond to them.
- Your data may also be used to keep you informed about events, offers, products, and services that may be of interest to you through different communication channels, provided that you have given your consent.
- In the case of promotions, giveaways, advertising, etc., your data will be used to facilitate your participation.
- If you wish to collaborate with us or provide services for our Website, your data will be used to manage the resulting relationship.
- In the case of suppliers, your information will be used to manage the existing commercial relationship and to comply with invoicing requirements.
We also inform you about the legal basis applicable to the processing of personal data:
“Article 6 GDPR:
Processing shall be lawful only if at least one of the following applies:
a) the data subject has given consent to the processing of their personal data for one or more specific purposes;
b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
c) processing is necessary for compliance with a legal obligation to which the controller is subject;
d) processing is necessary to protect the vital interests of the data subject or of another natural person;
e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.”
WHAT IS THE LEGAL BASIS FOR PROCESSING YOUR DATA?
The legal basis is the user’s consent to subscribe to our website, without which access to free or paid content will not be possible.
Likewise, your consent for the use of your personal data will have a contractual nature when such data is collected in the context of a contract or the provision of services offered on our website.
Legal obligations related to invoicing and taxation imply our legitimate interest in processing your personal data for the purpose of complying with these obligations.
You are informed that the consent you provide may be withdrawn at any time by exercising your rights as described in this Privacy Policy.
WHAT TYPE OF DATA WILL BE COLLECTED AND USED?
In order to provide you with the contracting and delivery of the services offered on our website or through any other channel, we collect the following data:
- First and last name
- National ID number (DNI), when required for invoicing
- Email address
- Address
- Phone number
- Banking details necessary to process payments
- Information related to the project or service you are interested in, including project descriptions, preferences, objectives, selected services, and estimated start dates
- Materials related to your brand, such as logo, visual identity, images, texts, documents, and any other content necessary for the creation of the website or contracted services
Any additional data required for the above purposes (service contracting and delivery) will always be collected with your prior consent and will be subject to the provisions of this Privacy Policy.
This data is necessary for the provision of our services and does not constitute a legal requirement, but rather a contractual one.
The user guarantees that they hold the necessary rights over the materials provided or that they have obtained the appropriate licenses or permissions for their use. Bloom The Brand is not responsible for the unauthorized use of content provided by the client.
HOW DO WE COLLECT YOUR INFORMATION?
We collect your personal information through different means, but you will always be informed in advance—generally at the time your data is collected—through informative clauses regarding the data controller, the purpose and legal basis of the processing, the recipients of the data, and the retention period of your information, as well as how you can exercise your data protection rights.
In general, the personal information we process is limited to identification data (first and last name, date of birth, address, ID number, phone number, and email), contracted services, and payment and billing data.
In cases of professional or employment collaboration, we collect academic and professional data in order to fulfill obligations arising from the maintenance of the employment or professional relationship.
The controller of this website also uses social media, which is another way of reaching you. Information collected through messages and communications published may contain personal data that is publicly available online. These social media platforms have their own privacy policies explaining how they use and share your information, so we recommend reviewing them before using such platforms to ensure you agree with how your data is collected, processed, and shared.
Our website collects personal data and information through contact forms available on the site and through published comments, which may be publicly visible.
Through our website, we also collect personal information related to your browsing activity through the use of cookies. To learn clearly and precisely which cookies we use, their purposes, and how you can configure or disable them, please consult our Cookie Policy: https://bloomthebrand.com/cookie-policy
WHAT IS THE USER’S RESPONSIBILITY?
By providing their data through electronic channels, the user guarantees that they are over 14 years of age and that the data provided to the Controller of this website is true, accurate, complete, and up to date. For these purposes, the user confirms that they are responsible for the accuracy of the data provided and that they will keep such information properly updated so that it reflects their real situation, being liable for any false or inaccurate data they may provide, as well as for any direct or indirect damages that may arise.
HOW LONG DO WE KEEP YOUR INFORMATION?
The Controller of this website will only retain your information for the period necessary to fulfill the purpose for which it was collected, to comply with legal obligations, and to address any potential liabilities arising from the fulfillment of the purpose for which the data was collected. This mainly refers to the provision of services advertised on this website or that may be requested by its users.
If you collaborate professionally with us, or wish to become part of our team and apply for one of our job positions, the data provided will become part of our candidate database and will be retained for the duration of the selection process and for a maximum of one year or until you exercise your right to erasure.
If at any time we have collected your data to contact you as a potential user of our services or to respond to a request for information made by you, such data will be retained for a maximum of one year from the time it was collected and will be deleted after this period if no contractual relationship has been established or at the time you request its deletion.
In any case, and as a general rule, we will retain your personal information as long as there is a contractual or professional relationship between us or until you exercise your right to erasure and/or restriction of processing. In such cases, the information will be blocked without being used beyond its storage, as long as it may be necessary for the exercise or defense of claims or in case any type of liability may arise that needs to be addressed.
In particular, any user data published on the website or on social media related to OUR WEBSITE will be retained from the moment the user gives their informed consent until such consent is withdrawn.
Likewise, billing-related data will be retained for a period of 6 years from the date of the last entry recorded in the accounting books, in accordance with the provisions of the Commercial Code.
WHO DO WE SHARE YOUR DATA WITH?
In general, the Controller does not share your personal information, except for disclosures that we are required to make based on legal obligations.
Although this is not considered a data transfer, in order to provide you with the requested service, third-party companies acting as our service providers may have access to your information to carry out the service we have contracted with them. These processors access your data following our instructions and may not use it for any other purpose, maintaining the strictest confidentiality.
Likewise, your personal information will be made available to Public Administrations, Judges, and Courts in order to address any potential liabilities arising from the processing.
To provide these strictly necessary services, we use tools managed by third parties, who apply their own privacy policies. Specifically, we use the following tools and third-party services:
Analytics: Google Analytics and Pixel de Facebook.
Hosting: Siteground
Web platform: WordPress
Email marketing: Klaviyo, Mailchimp y Hubspot.
Payment platforms and methods: Paypal y Stripe.
Forms: Google Forms
Advertising: Google Adsense
INTERNATIONAL DATA TRANSFERS
OUR WEBSITE is built using WordPress software, owned by AUTOMATTIC INC., based in the United States, which involves data transfers.
However, this company adheres to the Privacy Shield, which can be verified at this link. Additionally, the company outlines the privacy principles it adheres to, aligned with the GDPR, including strict guidelines regarding the disclosure of user information to governments, which can be verified at this link.
Our website uses automation and email marketing services from Klaviyo Inc., based in the United States and the United Kingdom, which may involve data transfers. This company adheres to the Privacy Shield, which can be verified at this link. The company is committed not to transferring any data outside the European Union, in compliance with the GDPR. You can review the standards applied at this link.
Our website uses automation and email marketing services from HubSpot Inc., based in the United States, which involves data transfers. This company adheres to the Privacy Shield, which can be verified at this link. The company is certified with the TRUSTe Privacy Certification seal. You can review the standards applied at this link.
Our website also uses automation and email marketing services from Mailchimp (The Rocket Science Group), based in the United States. You can find additional information regarding GDPR compliance guidelines at this link.
Additionally, for greater security, where materially possible, we have agreed with our providers that they will use servers located within the EEA to provide the contracted service. If in the future we need to use servers located outside the EU, appropriate measures will be adopted and incorporated into this Privacy Policy, ensuring that such providers are covered by the Privacy Shield agreement or that other adequate safeguards for the protection of personal data are in place.
Furthermore, we would like to inform you that the Privacy Shield is not an indicator of full GDPR compliance, as this framework was invalidated by the Court of Justice of the European Union (CJEU) on July 16, 2020. This is because U.S. companies may be required to provide data from Europe to U.S. authorities. Therefore, companies adhering to this framework do not transfer data to third parties, but may be required to disclose it to U.S. authorities.
WHAT ARE YOUR RIGHTS REGARDING THE PROCESSING OF YOUR DATA AND HOW CAN YOU EXERCISE THEM?
Data protection regulations allow you to exercise your rights of access, rectification, erasure, data portability, objection, and restriction of processing, as well as the right not to be subject to decisions based solely on automated processing of your data, where applicable.
These rights are characterized by the following:
Their exercise is free of charge, except in the case of manifestly unfounded or excessive requests (e.g., repetitive nature), in which case the Controller may charge a fee proportional to the administrative costs incurred or refuse to act.
You may exercise your rights directly or through your legal or voluntary representative.
We are required to respond to your request within one month, although, considering the complexity and number of requests, this period may be extended by an additional two months.
We are obliged to inform you about the means to exercise these rights, which must be accessible and cannot be denied solely because you choose a different method. If the request is submitted electronically, the information will be provided by electronic means where possible, unless you request otherwise.
If the Controller of this website does not act on your request, you will be informed, no later than one month, of the reasons for not taking action and of the possibility of lodging a complaint with a Supervisory Authority.
To facilitate the exercise of these rights, we provide links to the request forms for each of them:
Access request form
Rectification request form
Objection request form
Erasure request form (“right to be forgotten”)
Restriction of processing request form
Data portability request form
Right not to be subject to automated individual decision-making form
To exercise your rights, the Controller provides the following means:
- By written and signed request addressed to the Controller at info@bloomthebrand.com, Ref. Exercise of Data Protection Rights.
- By sending a scanned and signed form to the email address info@bloomthebrand.com, indicating in the subject line Exercise of Data Protection Rights.
In both cases, you must verify your identity by providing a photocopy or scanned copy of your ID or equivalent document, so we can ensure that we only respond to the data subject or their legal representative, who must provide proof of representation.
Additionally, and especially if you believe that you have not obtained full satisfaction in the exercise of your rights, you may lodge a complaint with the national supervisory authority by contacting the Spanish Data Protection Agency (Agencia Española de Protección de Datos), C/ Jorge Juan, 6 – 28001 Madrid. You can obtain more information on the official website of this authority.
To facilitate the exercise of these rights, we provide links to the request forms for each of them:
Erasure request form (“right to be forgotten”)
Restriction of processing request form
Right not to be subject to automated individual decision-making form
To exercise your rights, the Controller provides the following means:
- By written and signed request addressed to the Controller at info@bloomthebrand.com, Ref. Exercise of Data Protection Rights.
- By sending a scanned and signed form to the email address info@bloomthebrand.com, indicating in the subject line Exercise of Data Protection Rights.
In both cases, you must verify your identity by providing a photocopy or scanned copy of your ID or equivalent document, so we can ensure that we only respond to the data subject or their legal representative, who must provide proof of representation.
Additionally, and especially if you believe that you have not obtained full satisfaction in the exercise of your rights, you may lodge a complaint with the national supervisory authority by contacting the Spanish Data Protection Agency (Agencia Española de Protección de Datos), C/ Jorge Juan, 6 – 28001 Madrid. You can obtain more information on the official website of this authority.
HOW DO WE PROTECT YOUR INFORMATION?
The Controller is committed to protecting your personal information.
Reasonably reliable and effective physical, organizational, and technological measures, controls, and procedures are used to preserve the integrity and security of your data and to ensure your privacy.
All our computers are password-protected to prevent unauthorized access.
Likewise, OUR WEBSITE is protected by an SSL certificate that ensures the encryption of data transmitted between the browser and the server. Additionally, it is protected by a Web Application Firewall to prevent any cyberattacks.
In the contracts we enter into with our providers, we include clauses requiring them to maintain confidentiality regarding any personal data they may access as part of the service, as well as to implement the necessary technical and organizational security measures to ensure the ongoing confidentiality, integrity, availability, and resilience of data processing systems and services.
All these security measures are periodically reviewed to ensure their adequacy and effectiveness.
However, absolute security cannot be guaranteed, and no security system is impenetrable. Therefore, in the event that any information under our control is compromised due to a security breach, we will take appropriate measures to investigate the incident, notify the Supervisory Authority, and, where applicable, inform affected users so they can take appropriate action.
PUBLICATION DATE
The privacy policy of this website has been published and is applicable from April 10, 2026, and will be modified whenever necessary to ensure it is always aligned with current legal and business/professional requirements, without prior notice.