Privacy Policy

PRIVACY POLICY OF AVISOPREVIO.ES

Last updated: 12 July 2026
1. General information

This Privacy Policy explains how personal data processed through the online service AvisoPrevio.es (hereinafter, the «Service») is collected, used, stored and protected.

AvisoPrevio.es is part of an international system developed by PB Vision iT ltd, which may operate in different countries under different trade names, domains and language versions.

The use of the Service is also subject to the Terms and Conditions and, where applicable, the Cookie Policy.

2. Data controller

The data controller is:

HQ Market sp. z o.o.
ul. Frezerów 3
20-209 Lublin
Poland
Polish tax identification number — NIP: 9462684492

Hereinafter, the «Controller».

The owner and technological provider of the Service is:

PB Vision iT ltd

PB Vision iT ltd may process personal data on behalf of the Controller when it takes part in the development, maintenance, hosting, technical administration or security of the Service, in accordance with the corresponding data-processing agreement.

Contact regarding personal data protection
General contact and user support
3. Scope of application

This Privacy Policy applies to personal data processed in connection with:

  • the registration and maintenance of accounts;
  • the contracting and management of subscriptions;
  • payments and billing;
  • the publication and search of reports;
  • the operation of the comparison and match-detection system;
  • the chat and communications between users;
  • content reports and moderation;
  • contact with the Service;
  • the security and proper functioning of the platform;
  • the use of the website and its features.
4. Categories of personal data processed
4.1. User identification and contact data

The Service may process:

  • first and last name;
  • phone number;
  • email address;
  • locality or country;
  • username;
  • password stored in a protected form;
  • internal account identifiers;
  • information needed to verify the user's identity.
4.2. Company and representative data

For business accounts, the Service may process:

  • company or corporate name;
  • NIF, NIP, CIF, VAT or other tax identification number;
  • company address;
  • professional contact details;
  • first and last name of the authorised person;
  • position, role or relationship with the company;
  • information needed to verify the company's representation.
4.3. Payment and billing data

The Service may process:

  • information about the plan contracted;
  • date, amount and status of the payment;
  • transaction identifier;
  • data needed to issue invoices;
  • history of subscriptions, renewals and cancellations;
  • information received from the payment operator.

Full bank card data is processed directly by the payment operators and is not stored directly by AvisoPrevio.es.

4.4. Technical and security data

The Service may collect:

  • IP address;
  • device type;
  • operating system;
  • browser type and version;
  • date and time of access;
  • session identifiers;
  • login and logout data;
  • activity carried out within the account;
  • information about errors and the operation of the Service;
  • security logs;
  • information related to unauthorised access attempts, fraud or abuse.
4.5. Data contained in reports and searches

Depending on the features used, the Service may process the data entered by users in relation to persons, professionals, companies or other entities, including:

  • name or business name;
  • phone number;
  • email address;
  • locality;
  • business identifiers;
  • links to websites or public profiles;
  • information related to an experience, transaction or collaboration;
  • descriptions, comments and documents provided by the user;
  • data needed to identify possible matches between different reports.

Users must limit the data entered to what is adequate, relevant and strictly necessary for the purpose of the report.

4.6. Communications and chat

The Service may process:

  • messages sent through the chat;
  • communications with support;
  • content reports;
  • claims and requests;
  • documents or evidence attached;
  • information related to dispute resolution or moderation.
4.7. Specially protected data

It is prohibited to enter, unless there is a valid legal basis and it is strictly necessary:

  • health data;
  • racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • trade-union membership;
  • genetic data;
  • biometric data used to identify a person;
  • information about sex life or sexual orientation;
  • other data belonging to special categories.

It is also prohibited to publish passwords, full bank details, full identity document numbers or other data that may compromise a person's safety.

5. Origin of the data

Personal data may be obtained:

  • directly from the user during registration;
  • when the user uses the Service's features;
  • when the user publishes a report or performs a search;
  • through communications, claims or reports;
  • through payment operators;
  • through technical and security providers;
  • automatically during the use of the website;
  • from other users who enter information in a report;
  • from public sources, where their use is legal and necessary.

Where the data has not been obtained directly from the data subject, the Controller shall comply with the information obligations set out in the applicable regulations, unless a legal exception applies.

6. Purposes of the processing

Personal data is processed for the following purposes:

6.1. Registration and account management
  • create and manage the account;
  • verify the data provided;
  • authenticate the user;
  • allow access to the features;
  • keep the account information up to date;
  • prevent the creation of false or fraudulent accounts.
6.2. Provision of the Service
  • allow the publication and search of reports;
  • display the available results;
  • allow the use of the chat;
  • facilitate features related to anonymous or identified reports;
  • manage the plans and features contracted.
6.3. Payments, subscriptions and billing
  • process payments;
  • manage renewals and cancellations;
  • confirm the transactions carried out;
  • issue invoices;
  • manage refunds, non-payments and claims;
  • comply with tax and accounting obligations.
6.4. Comparison and match detection
  • compare the information entered by users;
  • identify possible relationships between reports;
  • detect reports that may refer to the same person or entity;
  • inform users about possible matches;
  • allow contact between users where the Service's features authorise it.
6.5. Moderation and management of reports
  • receive and analyse reports;
  • check possible breaches;
  • request additional information;
  • mark content as disputed;
  • limit, suspend or remove content;
  • handle appeals against moderation decisions;
  • prevent the publication of illegal or abusive content.
6.6. Security and fraud prevention
  • protect accounts and IT systems;
  • detect unauthorised access;
  • prevent fraud, impersonation, spam and abuse;
  • investigate security incidents;
  • retain evidence related to breaches;
  • protect the rights of the Service and its users.
6.7. User support
  • answer questions;
  • process requests;
  • provide technical assistance;
  • handle claims;
  • inform about incidents and important changes to the Service.
6.8. Compliance with legal obligations
  • respond to requests from authorities and courts;
  • comply with tax, accounting and data-protection obligations;
  • manage the exercise of rights;
  • retain information where there is a legal obligation.
6.9. Improvement and development of the Service
  • analyse the operation of the platform;
  • fix errors;
  • improve the user experience;
  • develop new features;
  • generate internal statistics;
  • assess the security and effectiveness of the comparison mechanisms.

Analyses carried out for this purpose shall be performed, whenever possible, using aggregated, anonymised or pseudonymised data.

6.10. Commercial communications

Where the user has given their consent or another valid legal basis exists, the data may be used to send:

  • commercial information;
  • promotions;
  • Service news;
  • communications about new features.

The user may withdraw their consent at any time.

7. Legal bases for the processing

Depending on the purpose, personal data is processed on the basis of:

7.1. Performance of a contract

The processing is necessary to:

  • register and manage the account;
  • provide the contracted features;
  • manage the subscription;
  • process payments;
  • provide user support.

The legal basis is Article 6(1)(b) of the General Data Protection Regulation.

7.2. Compliance with legal obligations

The processing may be necessary to:

  • comply with tax and accounting obligations;
  • respond to public authorities;
  • manage rights related to personal data;
  • retain legally required documentation.

The legal basis is Article 6(1)(c) of the General Data Protection Regulation.

7.3. Legitimate interest

The Controller may process data where necessary to:

  • protect the Service and its users;
  • prevent fraud, abuse and unauthorised access;
  • moderate content;
  • investigate reports;
  • defend against claims;
  • maintain security logs;
  • improve the operation of the Service;
  • detect possible matches between reports;
  • protect the security and reliability of relationships between users.

The legal basis is Article 6(1)(f) of the General Data Protection Regulation.

The Controller shall carry out, where appropriate, an assessment to verify that its interests do not override the rights and freedoms of the affected persons.

7.4. Consent

Consent may be used as the basis for:

  • sending certain commercial communications;
  • using non-necessary cookies;
  • publishing certain data in an identified manner;
  • applying optional features that require authorisation.

The legal basis is Article 6(1)(a) of the General Data Protection Regulation.

Consent may be withdrawn at any time, without affecting the lawfulness of the processing carried out before its withdrawal.

7.5. Establishment, exercise or defence of claims

Data may be retained and processed where necessary to establish, exercise or defend administrative, judicial or out-of-court claims.

8. Third-party data included in reports

Users may enter data relating to other persons, professionals or company representatives.

The user who enters such data declares that:

  • they have a legitimate basis to use it;
  • the data is relevant to a real experience or relationship;
  • the information is correct to the best of their knowledge;
  • they do not enter excessive or unnecessary data;
  • they do not use the Service to harass, defame, threaten or unjustifiably harm third parties;
  • they keep, where possible, documents or evidence to support their statements.

Acceptance of a report by the system does not mean that the Controller confirms its truthfulness.

The Controller may limit, block or delete data where it considers it to be unnecessary, excessive, incorrect, illegal or contrary to another person's rights.

Persons whose data has been included in the Service may contact the Controller to exercise their rights or request a review of the content.

9. Comparison system and automated processing

AvisoPrevio.es uses analytical tools and automated mechanisms to compare the data entered in reports and searches.

The system may analyse matches based, among other elements, on:

  • names;
  • phone numbers;
  • email addresses;
  • localities;
  • business identifiers;
  • links;
  • other data provided by users.

The result of the analysis only indicates the existence of a possible match.

It does not confirm that two reports necessarily refer to the same person or entity and does not prove the truthfulness of the published statements.

The system does not make decisions producing legal effects on a person, or decisions similarly significantly affecting them, based solely on automated processing.

Users must verify the information before making economic, professional, personal or legal decisions.

10. International nature of the processing

AvisoPrevio.es is part of an international system that may be available in different countries, domains and language versions.

Data may be processed within this system to:

  • provide the contracted features;
  • compare information;
  • identify possible relationships between reports;
  • ensure security;
  • prevent the fraudulent use of different national versions;
  • provide technical assistance.

Access to data between different versions of the system shall be limited to what is necessary for the provision of the Service and shall be subject to security measures and access control.

11. Recipients of the data

Personal data may be communicated or made available to:

  • PB Vision iT ltd, when acting as technological provider;
  • hosting and IT infrastructure providers;
  • software maintenance and development providers;
  • payment operators, such as Stripe or other available operators;
  • email and communications providers;
  • security, technical-analysis and fraud-prevention providers;
  • accounting, tax and legal service providers;
  • public authorities, courts and competent bodies;
  • other entities where there is a legal obligation or a valid legal basis.

Providers processing data on behalf of the Controller shall be subject to contractual obligations of confidentiality, security and data protection.

Personal data is not sold to third parties.

12. International data transfers

Whenever possible, data shall be processed within the European Economic Area.

Where a provider processes data from a country located outside the European Economic Area, the safeguards provided by the regulations shall apply, such as:

  • an adequacy decision adopted by the European Commission;
  • standard contractual clauses;
  • binding corporate rules;
  • other legally recognised safeguards.

Where applicable, the user may request additional information about the safeguards applied by writing to:

13. Anonymous publication

The Service may allow users to publish reports or use certain features anonymously with respect to other users.

Anonymous publication means that the author's identity is not shown publicly or to other users, unless the author decides to identify themselves.

Anonymous publication does not mean that the Controller has no information about the account from which the content was published.

The author's data may be used to:

  • ensure security;
  • prevent abuse;
  • handle reports;
  • defend claims;
  • comply with legal obligations;
  • respond to valid requests from competent authorities.

The user's identity shall not be revealed to other users unless:

  • there is the user's consent;
  • it is necessary to provide a requested feature;
  • there is a legal obligation;
  • a competent authority or court so orders;
  • there is another valid legal basis.
14. Retention periods

Personal data shall be retained only for the time necessary to fulfil the purpose for which it was collected.

14.1. Account data

Retained while the account remains active and subsequently for the period necessary to handle claims, prevent abuse and comply with legal obligations.

14.2. Subscription and payment data

Retained for the periods required by the applicable tax, accounting and commercial regulations.

14.3. Reports and content

Retained while they remain published or while they are necessary to provide the Service's features.

After deletion, certain data may be retained in a limited way where necessary to:

  • defend claims;
  • evidence moderation decisions;
  • prevent new abusive publications;
  • comply with legal obligations.
14.4. Communications and claims

Retained for the time necessary to process the request and subsequently for the legal claim periods.

14.5. Technical and security logs

Retained for the period necessary to detect incidents, prevent fraud and ensure the security of the Service.

14.6. Data processed on the basis of consent

Processed until the data subject withdraws their consent, without prejudice to the retention necessary to evidence that consent was correctly given.

Once the corresponding periods have ended, the data shall be deleted, anonymised or blocked where required by law.

15. Rights of data subjects

Data subjects may exercise the following rights:

  • right of access to their data;
  • right to rectification of incorrect data;
  • right to erasure;
  • right to restriction of processing;
  • right to object;
  • right to portability;
  • right to withdraw consent;
  • right not to be subject to solely automated decisions where the legal requirements are met;
  • right to lodge a complaint with a supervisory authority.

Requests must be sent to:

The request must make it possible to identify the data subject and specify the right they wish to exercise.

Where there are reasonable doubts about the identity of the applicant, the Controller may request additional information strictly necessary to confirm their identity.

The exercise of rights is free of charge, except in cases of manifestly unfounded, excessive or repetitive requests provided for by law.

The erasure of data may be limited where its retention is necessary to comply with a legal obligation, protect the rights of third parties or establish, exercise or defend claims.

16. Complaints to the supervisory authority

Where a person considers that their data is being processed contrary to the regulations, they may lodge a complaint with the competent data-protection authority.

In Spain, the competent authority is:

Spanish Data Protection Agency — AEPD

Before lodging a complaint, the person may contact the Controller through:

17. Mandatory or voluntary nature of the data

Providing personal data is voluntary.

However, certain data is necessary to:

  • create an account;
  • verify the user;
  • contract a subscription;
  • make a payment;
  • publish a report;
  • use the chat;
  • receive support;
  • use certain features.

Where the necessary data is not provided, it may be impossible to create the account or provide the requested service.

Mandatory fields shall be identified during the registration or contracting process.

18. Data security

The Controller applies appropriate technical and organisational measures to protect personal data against:

  • unauthorised access;
  • loss;
  • alteration;
  • destruction;
  • improper disclosure;
  • fraudulent use;
  • processing contrary to the intended purpose.

These measures may include:

  • access control;
  • authentication systems;
  • encryption of communications;
  • password protection;
  • pseudonymisation;
  • activity logging;
  • backups;
  • incident monitoring;
  • permission limitation;
  • security-breach response procedures.

No IT system can guarantee absolute security. The user must also protect their login data and not share their password with third parties.

19. Security breaches

When a personal data security breach occurs, the Controller shall:

  • assess its nature and scope;
  • take measures to limit its effects;
  • document the incident;
  • notify the competent authority where legally necessary;
  • inform the affected persons where there is a high risk to their rights and freedoms.
20. Minors

The Service is intended exclusively for persons over 18 years of age.

Minors are not allowed to create accounts, contract subscriptions or publish reports.

Where the Controller becomes aware that it has collected data from a minor without a valid legal basis, it shall take the necessary measures to delete it or restrict its processing.

21. Cookies and similar technologies

AvisoPrevio.es may use cookies and similar technologies to:

  • allow the website to function;
  • keep the user's session;
  • remember certain preferences;
  • ensure security;
  • analyse the operation of the Service;
  • measure the use of the platform;
  • carry out advertising activities where there is consent.

Strictly necessary cookies may be used without consent where they are essential to provide the requested service.

Analytical, advertising or third-party cookies that require consent shall not be installed before the user has made a valid choice.

Detailed information is available in the Cookie Policy and in the cookie settings panel.

22. Links and external services

The Service may contain links to websites, profiles or services managed by third parties.

The Controller does not control the privacy policies or activities carried out by such entities.

Before providing data to an external service, the user must consult its own terms and privacy policies.

23. Organisational changes and change of controller

In the event of corporate reorganisation, merger, acquisition, transfer of activity or change of the responsible entity:

  • the processing shall be carried out on a valid legal basis;
  • the continuity of individuals' rights shall be guaranteed;
  • users shall be informed where required;
  • data shall only be transferred to the extent necessary;
  • the new controller shall assume the corresponding obligations from the effective date of the change.
24. Amendments to the Privacy Policy

The Controller may amend this Privacy Policy where necessary due to:

  • legislative changes;
  • new guidelines from the authorities;
  • organisational changes;
  • the incorporation of new features;
  • changes in the purposes or means of the processing;
  • security improvements.

The updated version shall be permanently available at AvisoPrevio.es.

Where the changes are relevant, users shall be informed by email, through a notice within the account or through a visible communication in the Service.

The date of the last update shall appear at the beginning of the document.

25. Contact

To exercise rights or make enquiries relating to personal data:

For general, technical or Service-operation enquiries: