Data protection

Privacy policy

Written as a walk through an actual order, because that is the only way most of this makes sense.

Last updated 11 September 2026

Who is holding it

FLOFUM, S.L., a Spanish company with CIF B75621250, offices at Calle Parcerisa 13, Local 1, 08014 Barcelona, trading here as Zespar. Under the GDPR that makes us the controller: our decisions, our responsibility, our problem when it goes wrong.

Reach the person who deals with this at support@zespar.com. We have not appointed a data protection officer, since neither the scale nor the sensitivity of what we do triggers that requirement. Spanish Organic Law 3/2018 applies alongside the Regulation.

An order, from first message to deleted file

Rather than list categories in the abstract, here is what we actually learn about you and when.

  1. You send an enquiry. The form gives us a name, an email address, a phone number for the courier, the destination country, which appliance interests you, and whatever you wrote in the message box. Nothing more, and no card field exists to fill in.
  2. We reply and price it. Your message and our answer sit in the mailbox together. Whoever handles it notes the appliance, the total and the expected delivery day against your name.
  3. You confirm. Now we need the full street address, down to the floor or flat number, because a driver has to find the door and someone has to be behind it holding the money.
  4. The carrier takes over. They get the name, the address, the phone number and the sum to collect. They add their own records: when it was scanned, when it was delivered, whether it was accepted or refused.
  5. It is paid for. The only financial line against you is that the driver collected the agreed amount. No card number exists anywhere, because no card was involved.
  6. If you return it. We ask for an account holder name and an IBAN so the refund can be transferred, use them once, and clear them out when the bank confirms it.
  7. Time passes. Invoices stay as long as Spanish tax law demands. Most of the rest goes long before that. The table further down gives the actual periods.

Separately from all of that, the web server writes a line each time a page is requested: the requesting address, what the browser announced itself as, which page, and when. Those lines exist so that an outage or an attack can be reconstructed afterwards, and nobody opens them on an ordinary day.

What we never ask for: a birth date, a national identity number, a card number. Should any of those turn up in a message anyway, it gets removed rather than kept.

Worth being explicit. No bank, card scheme, gateway or terminal appears anywhere in the sequence above. The money moves once, in notes, between you and a driver. That single fact removes the most sensitive category of data most online shops have to handle.

The legal footing for each piece

Article 6 requires a named basis per purpose. Set out plainly:

What we are doingBasisArticle
Quoting, confirming and delivering an orderPerformance of a contract6(1)(b)
Handling a return, refund or conformity claimPerformance of a contract6(1)(b)
Sanity-checking an address before sending cash-on-delivery goods abroadLegitimate interests6(1)(f)
Discarding automated form submissions, keeping server logsLegitimate interests6(1)(f)
Any cookie beyond those the site needs to runConsent6(1)(a)
Issuing and retaining invoicesLegal obligation6(1)(c)

On the legitimate-interest rows: the point of the check is that a carrier is about to move goods across a border and collect cash for them, and a fake address turns that into a loss for somebody. Nothing in it profiles you, nothing is combined with outside sources, and you can object whenever you like. An objection gets weighed properly rather than waved away.

On consent: there is no mailing list here, no marketing of any kind, and your details are neither sold nor rented to anyone. Withdrawing consent is exactly as easy as giving it was.

The three outsiders

The carrier. Name, address, phone number, amount to collect. A driver cannot do the job without them. They also keep their own delivery record under their own terms.

The hosting provider. Holds the site, the mailbox and the backups as our processor, under a contract that forbids using any of it for their own ends.

The bookkeeper. Sees invoices, and nothing else, under professional confidentiality obligations.

That is the complete list. Anyone else would need a court order or a lawful demand from a competent authority, and would get only what that demand actually covered.

How long each thing lives

RecordRetentionDriven by
Enquiry that went nowhere12 months after the last messageSo you need not repeat yourself if you come back
Invoice and order file6 years from the end of the financial yearSpanish commercial and tax law
Return and conformity correspondence3 years from deliveryCovers the 2 year period plus any argument after it
Refund bank detailsRemoved once the transfer clearsOne payment, one use
Server request logs30 days, then overwrittenSecurity and fault diagnosis
Record of your cookie choice12 monthsProof of what was agreed and when

At the end of a period the record is deleted outright. Where a backup set makes immediate deletion impractical, it is isolated from normal use and disappears at the next rotation.

Where it physically sits

Servers inside the European Union hold the site, the mailbox and the backups, and since we deliver only within the twenty-seven member states an order has no reason to leave the European Economic Area. Were a supplier ever to require processing beyond it, the destination would have to be a country the Commission has found adequate, or the transfer would run on standard contractual clauses. We will tell you which suppliers are involved at any given moment if you write and ask.

Things you can make us do

  • Hand over a copy of everything we hold on you, with an explanation of what it is for
  • Correct anything that is wrong
  • Delete it, except where tax law forces us to keep an invoice, in which case it is locked away rather than used
  • Freeze processing while a disagreement about accuracy is sorted out
  • Object to anything we are doing on legitimate-interest grounds
  • Receive it in a portable, machine-readable form
  • Withdraw a consent, without that unpicking anything done lawfully beforehand

Email the address at the top. You get an answer inside a month. If a request is genuinely intricate we may need up to two months more, and we will say so within that first month rather than letting it drift.

If we handle it badly

Tell us, because the overwhelming majority of these turn out to be a misunderstanding that takes a day to clear up. Beyond that, you are entitled to complain to the Agencia Espanola de Proteccion de Datos in Spain, or to the supervisory authority of the EU country where you live or work. Using us first is not a precondition of either.

When this page moves

It changes when our practice changes, and the date at the top tells you when that last happened. If a change affects you materially and we have your email address, expect a message rather than a silent edit.

Cookie policyContact us

Scroll to Top