Skip to content
Privacy Policy
Last updated: 1 May 2026 | Controller: JP Tax & Asset Management S.L., Marbella
Last updated: 1 May 2026

JP Tax & Asset Management S.L. takes the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with applicable statutory data protection regulations (GDPR, LOPDGDD, BDSG, TDDDG) and this Privacy Policy. This Privacy Policy explains what data we collect, when and for what purpose, how we process it, and what rights you have as a data subject.

1. CONTROLLER WITHIN THE MEANING OF THE GDPR

The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws is:

JP Tax & Asset Management S.L.
SUBZONA 9, SUPERMANZANA J-K-L
29660 Nueva Andalucía, Marbella, Spain
N.I.E.: Z1291857-K
Website: https://jp-tax.es

2. DATA PROTECTION OFFICER (DPO)

If our company has appointed a Data Protection Officer, you can reach them at the contact details listed above. In all other cases, please direct any data protection queries to the controller named in Section 1.

3. GENERAL INFORMATION ON DATA PROCESSING

3.1 Scope of processing
We collect and use personal data of our users and clients only insofar as this is necessary to provide a functional website, deliver our tax advisory services, or fulfil our legal obligations. Any processing beyond this scope takes place only with your express consent or on the basis of statutory authorisation.

3.2 Legal bases for processing
We process personal data on the following legal bases: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(b) GDPR (Contract performance), Art. 6(1)(c) GDPR (Legal obligation), Art. 6(1)(f) GDPR (Legitimate interest), Art. 9(2)(f) GDPR (Establishment, exercise, or defence of legal claims).

3.3 Storage periods
We retain personal data only for as long as is necessary to achieve the purpose of processing or as required by statutory retention obligations. Statutory retention periods include: 10 years for documents with tax relevance (§ 147(3) AO Germany, § 257(4) HGB Germany, Art. 30 Spanish Commercial Code), 6 years for incoming and outgoing business correspondence, 4 years under Spanish tax law general limitation periods (Art. 66 et seq. Ley General Tributaria), 10 years for identification data under anti-money-laundering regulations (Spanish Ley 10/2010), applicant data up to 6 months following the conclusion of the recruitment process. After the relevant period has elapsed, the data will be deleted or anonymised.

4. PROVISION OF THE WEBSITE AND SERVER LOG FILES

Each time our website is accessed, our system automatically collects data and information from the computer system of the requesting device: IP address (in shortened, anonymised form), date and time of access, content of the request, access status / HTTP status code, volume of data transmitted, browser and operating system, referrer URL, hostname of the requesting computer. These data are stored in the log files of our hosting provider. They are not combined with other personal data of the user. Legal basis: Art. 6(1)(f) GDPR. Storage period: maximum 30 days.

5. HOSTING AND CONTENT DELIVERY NETWORK (CDN)

5.1 Onepage GmbH: Our website is hosted on the Onepage GmbH platform. A Data Processing Agreement (DPA) under Art. 28 GDPR has been concluded. Provider: Onepage GmbH, Kasinostr. 19-21, 42103 Wuppertal, Germany. Privacy: https://www.onepage.io/de/datenschutz

5.2 Cloudflare (CDN): To deliver the website, Onepage uses the CDN of Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare accelerates the delivery of static content and protects against abusive access. Your IP address may be transferred to the USA. The transfer takes place on the basis of the EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR and, where applicable, the EU-US Data Privacy Framework based on the European Commission's adequacy decision of 10 July 2023. Privacy: https://www.cloudflare.com/privacypolicy/

6. COOKIES AND SIMILAR TECHNOLOGIES

Cookies and comparable technologies (e.g. localStorage) are used on our website. 6.1 Strictly necessary cookies are essential for the proper operation of the website (Legal basis: § 25(2)(2) TDDDG / Art. 22.2 LSSI-CE in conjunction with Art. 6(1)(f) GDPR). 6.2 Functional and analytics cookies are set only with your express consent (Legal basis: § 25(1) TDDDG / Art. 22.2 LSSI-CE in conjunction with Art. 6(1)(a) GDPR). 6.3 You can adjust or revoke your cookie consent at any time via the cookie banner.

7. CONTACTING US

7.1 By email: When you contact us by email, your details (email address, name, telephone number, content of your message) are stored to handle the enquiry. Legal basis: for contractual relationships Art. 6(1)(b) GDPR; for other enquiries Art. 6(1)(f) GDPR. 7.2 Via contact form: When using our contact form, we process the data entered. Mandatory fields are marked. The data will not be passed on to third parties. 7.3 By telephone and WhatsApp: Connection data are stored. For WhatsApp, the data protection provisions of Meta Platforms Ireland Ltd. additionally apply. For confidential client communication, we recommend using email or encrypted communication channels.

8. PROCESSING OF CLIENT DATA

8.1 Categories of data: Master data (name, address, date of birth, marital status), contact data, identification data (Tax ID, NIE/DNI/Passport), bank details, income, asset, and tax data, corporate data, contractual and engagement documentation, correspondence with authorities and third parties. 8.2 Purposes of processing: Performance of the engagement contract, compliance with legal obligations, anti-money-laundering compliance under Spanish Ley 10/2010 and the German GwG, accounting and invoicing, defence against legal claims. 8.3 Professional confidentiality: As tax advisors, we are bound by professional secrecy under applicable Spanish law, including the rules of the Asociación Española de Asesores Fiscales (AEDAF) and, for German engagements, § 57(1) of the German Tax Advisory Act (StBerG). The duty of professional secrecy continues indefinitely.

9. RECIPIENTS OF YOUR DATA

Your data are only disclosed to the extent necessary and legally permissible: within the firm, to tax and financial authorities (Spanish Tax Agency AEAT, German tax offices, social security bodies), notaries and lawyers, IT service providers and processors with DPAs under Art. 28 GDPR, banks and insurers when expressly instructed, external specialists at the client's request. Data will also be transferred to authorities where we are legally required to do so.

10. INTERNATIONAL DATA TRANSFERS

In principle, your personal data are not transferred to countries outside the European Economic Area (EEA) unless an adequacy decision of the European Commission applies (e.g. EU-US Data Privacy Framework), appropriate safeguards such as the EU Standard Contractual Clauses pursuant to Art. 46 GDPR are in place, you have given your express consent under Art. 49(1)(a) GDPR, or the transfer is necessary for the performance of the contract (Art. 49(1)(b) GDPR). We take into account the standards set by the CJEU in the "Schrems II" judgment.

11. EMBEDDED SERVICES AND THIRD PARTIES

11.1 Google Maps (where applicable): Provider Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When loading a page with an embedded map, your IP address may be transferred to Google in the USA. Legal basis: Consent pursuant to Art. 6(1)(a) GDPR via the cookie banner. Privacy: https://policies.google.com/privacy. 11.2 Fonts are delivered locally via our hosting provider. 11.3 External links: We have no influence on the content or data processing practices of external sites.

12. RIGHTS OF DATA SUBJECTS

You have the following rights against us: Right of access (Art. 15 GDPR), right to rectification (Art. 16 GDPR), right to erasure (Art. 17 GDPR) provided no statutory retention obligations apply, right to restriction of processing (Art. 18 GDPR), right to data portability (Art. 20 GDPR), right to object (Art. 21 GDPR), right to withdraw consent (Art. 7(3) GDPR).

13. RIGHT TO LODGE A COMPLAINT

You have the right under Art. 77 GDPR to lodge a complaint with a supervisory authority. In Spain: Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan, 6, 28001 Madrid, +34 901 100 099, www.aepd.es. In Germany, the competent authority depends on your place of residence: https://www.bfdi.bund.de

14. AUTOMATED DECISION-MAKING AND PROFILING

No decision based solely on automated processing within the meaning of Art. 22 GDPR is made. We do not use profiling within the meaning of the GDPR.

15. USE OF ARTIFICIAL INTELLIGENCE

In the technical creation and maintenance of this website, AI tools are used to a limited extent — for example, for the automatic generation of image descriptions (alt text) to improve accessibility. This processing has no relation to personal data of website visitors. Processing of client data using AI systems within the meaning of the EU AI Act takes place only if you have given your separate consent or if it is necessary for the performance of the contract and compatible with professional confidentiality obligations. We do not use AI systems classified as high-risk under the EU AI Act.

16. DATA SECURITY AND SSL/TLS ENCRYPTION

For security reasons and to protect the transmission of confidential content, this website uses SSL or TLS encryption. We also implement appropriate technical and organisational security measures (TOMs) within the meaning of Art. 32 GDPR to protect your personal data against accidental or intentional manipulation, partial or total loss, destruction, or unauthorised access by third parties.

17. JOB APPLICATIONS

We process applicant data exclusively for the purpose of conducting the recruitment process on the basis of Art. 6(1)(b) GDPR and Art. 88 GDPR in conjunction with § 26 BDSG and applicable Spanish provisions. In the event of rejection, the data will be deleted no later than 6 months thereafter, unless you have consented to longer storage.

18. VALIDITY AND CHANGES TO THIS PRIVACY POLICY

This Privacy Policy is currently in force with the date: 1 May 2026. Due to the further development of our website and offerings, or due to changes in legal or regulatory requirements, it may become necessary to amend this Privacy Policy. The current version is always available on this website.

This Privacy Policy has been carefully prepared in accordance with the GDPR, LOPDGDD, LSSI-CE, BDSG, TDDDG, and applicable case law. For legal certainty in any individual case, we recommend a final review by a lawyer specialised in data protection law.
Adresse
Marbella Lake bloque 7 puerta 6 29660