DATA PROTECTION
Privacy policy
What personal data this website processes, why, on what legal basis, for how long and who sees it, under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Act 3/2018 (LOPDGDD). Version 2.0, dated 5 September 2026, pending ratification by the residents' board.
1. Data controller
Controller: [COMUNIDAD/ASOCIACIÓN — pendiente de acuerdo de junta] (hereinafter, «the Community»), in Vilamarxant (Valencia, Spain). Tax ID: [VERIFICAR]. Address: [VERIFICAR]. Data protection contact: [email protected].
The Community decides what data is processed, why and for how long. The board acts on its behalf: it is not a separate controller.
A correction to the previous version of this text: the property-management firm is not the processor for this website. It does not operate it, does not host it and has no access to its data. What the previous version said was wrong.
There is no data protection officer because in a case such as this one is not required (Article 37 GDPR and Article 34 LOPDGDD). The contact channel is the e-mail address above.
2. Who else processes your data
The Community has no technical resources of its own. These are everyone involved, with their country and their role:
- A resident volunteer (Spain) — data processor. Develops, hosts and maintains the website voluntarily and free of charge, on the Community's instructions. The server sits at his home, in Spain, with an encrypted disk. He does not use the data for any purpose of his own.
- Cloudflare, Inc. (United States) — sub-processor. Publishes the site on the internet: tunnel, security certificates and delivery network. Because of how it works it sees the traffic between your browser and the server, not just your IP address.
- Resend / Plus Five Five, Inc. (United States) — sub-processor. Sends the service e-mails (access link, urgent notices, the status of an issue): it receives your name, your e-mail address and the content of those messages.
- Third parties your browser connects to, not the Community: OpenStreetMap (United Kingdom), OpenTopoMap (Germany), Esri (United States), NASA GIBS (United States), Copernicus EFFIS (European Union) and Open-Meteo (Europe) when you use a map or the wildfire page; and Windy (Czechia), Google (United States) and Blitzortung (Germany) only if you press their viewer's button. They receive your IP address and whatever your browser always sends; some may set their own cookies. They are not the Community's processors: each is answerable for its own processing and has its own policy.
3. International transfers
Cloudflare and Resend are US companies, so data is transferred to the United States. Both declare that they adhere to the EU-U.S. Data Privacy Framework, which the European Commission found adequate in Implementing Decision (EU) 2023/1795; on a subsidiary basis they apply the standard contractual clauses approved by the Commission (Articles 45 and 46 GDPR).
You may request a copy of those safeguards by writing to the contact address.
The map and weather providers your browser connects to are, depending on the case, in the European Union, in other European countries or in the United States. Where the connection depends on a button, the decision is yours; where it is part of the map itself, you are told right underneath it.
4. What data we process
It depends on what you use. This is the full inventory:
- Registration and account: first and last names, e-mail address, phone number (if you give one), the plot you are linked to, your role —owner, resident or authorised person— and any positions you hold.
- Access: the open session, a technical fingerprint of your browser, the cryptographic fingerprint of the magic access link, and the IP address from which that link was requested or a registration request was sent (an anti-abuse measure).
- Activity in the private area: which pages you visit, which documents you download and what actions you take, linked to your account. In the public part, measurement is anonymous and aggregated.
- Community documentation: a record of who downloads each set of minutes or document; minutes record arrears with names (Article 19 of the Horizontal Property Act), so access to them is traced.
- Issues, suggestions and petitions: what you write, where it happened, and any photographs you attach, from which hidden data —including location— is stripped.
- Car sharing: journeys, times, places, contact phone number, seats, the «women only» preference if you tick it, bookings, ratings between driver and passenger and incident reports; plus a copy of every journey published, edited or withdrawn.
- Services directory: the listing you publish (name, trade, phone, e-mail, photos), its ratings, and a record of who contacts each listing and by what channel.
- Time bank, Wanted/Giving away/Swap, lost and found and the book corner: your adverts and their photos, the phone number you choose to display, hour movements, expressions of interest, loans and claims over objects.
- Art and The Memory: the works and stories you submit under your name or an alias, their images, comments and ratings. This content is public.
- Facility bookings: which facility, which day and which slot.
- Votes: your vote in each poll. The count is published in aggregate form.
- Moderation: reports, warnings, mutes, closures and sanctions, with their reason.
- Consents: which terms you accept, reject or revoke, in which version, in which language you read them, a cryptographic fingerprint of the exact text you saw, the date, your IP address and a fingerprint of your browser.
- Administration: a log of administrators' actions —publishing, editing, changing roles, deactivating— with the person affected.
- No health, religious, ideological, ethnic-origin or sexual-orientation data is processed. Bear in mind, even so, that what you freely write in a help advert or a story may reveal it: write only what is necessary.
5. Where the data comes from
Almost always from you. There are three exceptions worth knowing about, which the law requires us to disclose (Article 14 GDPR):
- The urbanisation's register comes from the roll that the property-management firm provides to the board. If you have an account you never asked for, your data —name, surname, e-mail and phone— came from there. You may object, correct it or ask to be removed by writing to the contact address.
- What another neighbour publishes about you: who an object was handed to, an hour movement in the time bank, a story or comment that names you, a car-sharing report, or a photograph you appear in. Whoever publishes must have your permission; if something of yours appears without it, write in and it will be removed (channel in section 8 of the Legal notice).
- Listings of outside professionals entered by the board with their professional contact details.
6. What it is used for and on what legal basis
Each processing operation has its legal basis. Most importantly: running the community does not rest on your consent, but on the law. You were not asked for permission to appear in the register because none was needed, and so you cannot «withdraw» it either; and your access to the private area never depends on accepting processing that is not necessary (Article 7.4 GDPR).
- Register, accounts, minutes, notices, documents, meeting calls and access traceability — compliance with a legal obligation of the community (Article 6.1.c GDPR and Articles 9 and 16 to 20 of the Horizontal Property Act).
- Your access account and the service e-mails (access link, urgent notices, the status of your issue) — the same legal compliance, being the means of carrying it out (Article 6.1.c), and the community's legitimate interest in having a channel (Article 6.1.f).
- Each module you activate —car sharing, time bank, lost and found, Wanted/Giving away/Swap, book corner, bookings, votes— performance of that module's terms, which you accept before using it (Article 6.1.b).
- Publishing openly your directory listing, your phone number, your works or stories, or a photograph in which you can be identified — your consent, asked for separately, with no pre-ticked boxes and revocable at any time (Article 6.1.a).
- Security, anti-abuse and internal statistics —sending limits, the administration log, usage measurement inside the private area— the community's legitimate interest in a service that works and can be audited (Article 6.1.f). You may object and your particular case will be considered.
- Complying with a request from a court, the police or a public authority — legal obligation (Article 6.1.c).
- Defending the community against a claim — legitimate interest and the exercise of legal actions (Article 6.1.f).
7. Who sees your data
The previous version of this policy said that data «is not disclosed to third parties». That was false, and it is corrected here: this website exists precisely so that neighbours can see things about one another, and part of it is public on the internet. This is what each of them sees:
- Anyone, without an account and from the internet: the services directory listings published openly, with the phone number or e-mail their author chose to show; the works in the Art gallery and the stories in The Memory, with their author's name or alias; the front-page photos and texts; the map points; and the petitions to the Town Council. Search engines may index all of it.
- Other neighbours with an account: your name and plot when you take part in a module; your phone number in car-sharing journeys and in any lost-and-found item you publish; your time-bank and Wanted/Giving away/Swap adverts; your works, stories and comments; and your ratings.
- Those who administer the community —board, management and portal administrators—: the register, registration requests, issues, suggestions, the consent history, reports and sanctions, and the document access log.
- The providers in section 2, as processors, and solely in order to provide their service.
- Courts, police and public authorities where they lawfully request it. In car sharing, the copy of each journey is kept precisely so that such a request can be met.
- No data is sold, nothing is disclosed for advertising purposes, and there are no automated decisions or profiling producing legal effects on you.
8. How long it is kept
This table is not written by hand: it comes from the very file that carries out the deletions, so that what is published and what the software does can never again say different things.
«As long as the account exists» means for as long as you are an owner, resident or authorised person; after deregistration the data is kept for five years, the limitation period for civil claims (Article 1964 of the Civil Code), and is then deleted.
A known gap: deactivating an account today changes its status but does not yet automatically anonymise everything published; full erasure is handled manually when you ask for it. It is logged as pending in the community's internal register.
- 12 months — Website usage statistics: which page was visited, when and —only inside the private area— which neighbour visited it. There are no tracking cookies and your IP address is not stored.
- 6 months — Open sessions: the identifier of your sign-in and a browser fingerprint, so as to keep you signed in without asking you for the access link again.
- 24 hours — Magic access links: the cryptographic fingerprint of the link (never the link itself) and the IP address it was requested from, in order to curb abuse.
- 24 hours — Anti-abuse counters: how many times an access link has been requested or a registration request sent from an e-mail address or an IP address within the last hour.
- As long as the account exists and 5 years after deregistration — Registration requests: the data you entered when asking for access, the version of the Terms you accepted and who decided the request.
- 30 days — IP address from which a registration request was sent (an anti-abuse item, no longer needed once the request is decided).
- 5 years — Administration log: which action each administrator performed, on what and when (publishing, editing, changing roles, deregistering…).
- 5 years — Content takedown requests: the address reported, the reason, who submitted it with their name and email, and how it was resolved. Anyone may file one, with or without an account.
- 5 years — Who downloaded each community document and when. The minutes list arrears with names (Article 19 of the Horizontal Property Act), so access to them is traced.
- 12 months — Contact log of the Services Directory: which listing was contacted, by which channel and when (with your name only if you were signed in).
- 5 years — Car-sharing log: a copy of every journey published, edited or withdrawn, with the data it held at that moment —including the contact phone number—, available to the authorities should they request it.
- As long as the account exists and 5 years after deregistration — Consent history: which terms you accepted, refused or withdrew, in which version and on which date.
- As long as the account exists and 5 years after deregistration — Your account: first name, surname, e-mail address, phone number, the plot you are linked to, the posts you hold in the community and any moderation measures applied to you.
- As long as the account exists and 5 years after deregistration — Time bank: your adverts offering or asking for help and the movements of hours you take part in.
- As long as the account exists and 5 years after deregistration — Lost and found: the posting, its photos, the contact phone number you chose to show and the claims received.
- As long as the account exists and 5 years after deregistration — Wanted / Giving away / Swap: your adverts, their photos and other neighbours' expressions of interest.
- As long as the account exists and 5 years after deregistration — Services Directory: the service listing (name, phone number, e-mail address, photos) and the ratings it receives.
- As long as the account exists and 5 years after deregistration — Car sharing: the journeys you publish, the bookings, the ratings between driver and passenger and the incident reports.
- As long as the account exists and 5 years after deregistration — Book Corner and Reading Club: the books you offer, the loans, the ratings and the club's comments.
- As long as the account exists and 5 years after deregistration — Issues: what you reported (description, location, photos) and the history of how it was resolved.
- As long as the account exists and 5 years after deregistration — Facility bookings: which facility, which day and which time slot you booked.
- As long as the account exists and 5 years after deregistration — Suggestions box: what you sent in and the board's reply to it.
- As long as the account exists and 5 years after deregistration — Art Gallery and The Memory: the works and stories published with their author's name or alias, their images and the ratings and comments received.
- As long as the account exists and 5 years after deregistration — Community votes: your vote in each consultation.
- No time limit: it is part of the community's archive — Institutional publications: notices, documents and minutes, front-page content, map points, petitions to the Town Council and business listings. The only personal data is who published or edited them.
- As long as the account exists and 5 years after deregistration — Legacy directory of professionals (name, trade, phone number, e-mail address), removed from the website and replaced by the Services Directory.
9. Your rights
You may exercise the rights of access, rectification, erasure, objection, restriction and portability, and withdraw any consent you have given, by writing to [email protected]. State what you are asking for; if you write from your account's e-mail address, you do not need to send a copy of your ID.
You will get an answer within one month of the request being received, extendable by two further months if the case is complex, in which event you will be told of the extension and its reasons (Article 12.3 GDPR).
Portability covers what is processed on the basis of your consent or a module's terms, not the register, which is processed under a legal obligation.
If you believe your data has not been handled properly you may complain to the Spanish Data Protection Agency (www.aepd.es), regardless of whether you would rather write to us first.
10. Minors
No accounts are opened for children under fourteen: below that age processing is lawful only with the consent of whoever holds parental authority or guardianship (Article 7 of Organic Act 3/2018). Minors appear, where applicable, as authorised users on an adult's account, and that adult answers for their use.
Images of minors: they are not published without the written consent of both parents or guardians, and they are not published in the part open to the internet even where such consent exists. Even with permission, any image that could harm the child is removed (Article 4.3 of Organic Act 1/1996).
Either parent may request removal at any time, without giving reasons, and it is done immediately.
11. Security
Measures in place today: end-to-end encrypted connections; access through a single-use link that expires after one hour, with no stored passwords; permissions always checked on the server; session cookies unreachable by the page's scripts; attempt limits; an AES-256 encrypted disk on the server; an unprivileged container; removal of hidden data from photographs; sanitisation of published content; a log of administration actions; and backups that are verified by restoring them (integrity check and row counts).
Measures that depend on the board and are not yet settled: the data processing agreement, the record of processing activities, the risk analysis and an off-site backup. They are logged as pending in the community's internal register.
No system is infallible, and this one is hosted in a private home. That risk will be put to the board so that it either expressly accepts it or decides to move the site to professional hosting.
12. If there is a data breach
If an incident affects your data, the Community will assess it and, where it poses a risk to your rights, will notify the Spanish Data Protection Agency within a maximum of 72 hours (Article 33 GDPR). If the risk is high, it will also tell you, without undue delay and in plain language (Article 34).
Every incident, notified or not, is logged internally with what happened, its effects and the measures taken.
If you spot a security flaw, please write to [email protected]: it is appreciated, and no reprisals are taken against anyone reporting in good faith.
13. Cookies and connections to third parties
This website uses two cookies, both technical: one keeps your session in the private area and the other remembers the language you chose. There are no advertising, analytics or tracking cookies, first-party or third-party; strictly necessary cookies need no consent, which is why you will not see a cookie banner: there is nothing to consent to.
Usage measurement in the public part is anonymous and aggregated, without cookies and without storing your IP address. Inside the private area, since you are identified by the session cookie, your activity is linked to your account for running the community and for internal statistics (Article 6.1.f); those events are deleted after twelve months, as the table in section 8 states.
The Windy, Google traffic and Blitzortung lightning viewers do not load until you press their button; beforehand you are told which provider it is, which country it is in and that it will receive your IP address. Your choice is remembered only for the current visit, without any cookie.
Maps do load when you open them, because they are the content itself: when you use them, your browser requests the imagery from OpenStreetMap, OpenTopoMap, Esri, NASA GIBS and Copernicus EFFIS, and the wildfire page queries the Open-Meteo forecast. All of them receive your IP address. Each map says so right underneath.
14. Consent log
Before using the private area and each of its features —Services Directory, Time Bank, «Coming and going», Lost and found, «Wanted/Giving away/Swap», Art and Exhibition, The Memory of Monte Horquera, votes, issue reports and the suggestions box— you are shown their terms and must expressly accept them.
For each acceptance, rejection or revocation we store: which terms, in which version, in which language you read them, a cryptographic fingerprint of the exact text you were shown, the date and time, your IP address and a fingerprint of your browser. What you do inside your session is never stored: only the fact of the consent. The text fingerprint makes it possible to prove, years later, exactly what it was that you accepted.
This log is neither modified nor deleted: it is the proof that the processing was consented to (Article 7.1 GDPR). It is kept for as long as your account exists and for five years after deregistration.
You can see what you have accepted at any time and revoke it from your profile; if you revoke something, you will have to accept it again the next time you use that feature. Withdrawing consent is as easy as giving it (Article 7.3 GDPR).
Those who administer the community may consult this history for management and audit purposes, under the same access controls as the rest of the administrative data.
15. Changes to this policy
This policy may be updated. Every version carries a number and a date, and the version in force is always the one published on this page.
Changes affecting essentials —new processing, new recipients, longer retention— are announced at least 30 days in advance through a notice on the site and an e-mail to account holders, and the private-area terms will have to be accepted again.
Status of this document: drafted from an internal audit of the website's own source code, without review by a qualified lawyer and pending ratification by the board, which must also settle the controller's exact name, tax ID and registered address — the points marked [VERIFICAR].
Montehorquera