Data protection
Privacy policy
Written as a walk through an actual order, because that is the only way most of this makes sense.
Last updated 11 September 2026
Who is holding it
FLOFUM, S.L., a Spanish company with CIF B75621250, offices at Calle Parcerisa 13, Local 1, 08014 Barcelona, trading here as Zespar. Under the GDPR that makes us the controller: our decisions, our responsibility, our problem when it goes wrong.
Reach the person who deals with this at support@zespar.com. We have not appointed a data protection officer, since neither the scale nor the sensitivity of what we do triggers that requirement. Spanish Organic Law 3/2018 applies alongside the Regulation.
An order, from first message to deleted file
Rather than list categories in the abstract, here is what we actually learn about you and when.
- You send an enquiry. The form gives us a name, an email address, a phone number for the courier, the destination country, which appliance interests you, and whatever you wrote in the message box. Nothing more, and no card field exists to fill in.
- We reply and price it. Your message and our answer sit in the mailbox together. Whoever handles it notes the appliance, the total and the expected delivery day against your name.
- You confirm. Now we need the full street address, down to the floor or flat number, because a driver has to find the door and someone has to be behind it holding the money.
- The carrier takes over. They get the name, the address, the phone number and the sum to collect. They add their own records: when it was scanned, when it was delivered, whether it was accepted or refused.
- It is paid for. The only financial line against you is that the driver collected the agreed amount. No card number exists anywhere, because no card was involved.
- If you return it. We ask for an account holder name and an IBAN so the refund can be transferred, use them once, and clear them out when the bank confirms it.
- Time passes. Invoices stay as long as Spanish tax law demands. Most of the rest goes long before that. The table further down gives the actual periods.
Separately from all of that, the web server writes a line each time a page is requested: the requesting address, what the browser announced itself as, which page, and when. Those lines exist so that an outage or an attack can be reconstructed afterwards, and nobody opens them on an ordinary day.
What we never ask for: a birth date, a national identity number, a card number. Should any of those turn up in a message anyway, it gets removed rather than kept.
Worth being explicit. No bank, card scheme, gateway or terminal appears anywhere in the sequence above. The money moves once, in notes, between you and a driver. That single fact removes the most sensitive category of data most online shops have to handle.
The legal footing for each piece
Article 6 requires a named basis per purpose. Set out plainly:
| What we are doing | Basis | Article |
|---|---|---|
| Quoting, confirming and delivering an order | Performance of a contract | 6(1)(b) |
| Handling a return, refund or conformity claim | Performance of a contract | 6(1)(b) |
| Sanity-checking an address before sending cash-on-delivery goods abroad | Legitimate interests | 6(1)(f) |
| Discarding automated form submissions, keeping server logs | Legitimate interests | 6(1)(f) |
| Any cookie beyond those the site needs to run | Consent | 6(1)(a) |
| Issuing and retaining invoices | Legal obligation | 6(1)(c) |
On the legitimate-interest rows: the point of the check is that a carrier is about to move goods across a border and collect cash for them, and a fake address turns that into a loss for somebody. Nothing in it profiles you, nothing is combined with outside sources, and you can object whenever you like. An objection gets weighed properly rather than waved away.
On consent: there is no mailing list here, no marketing of any kind, and your details are neither sold nor rented to anyone. Withdrawing consent is exactly as easy as giving it was.
The three outsiders
The carrier. Name, address, phone number, amount to collect. A driver cannot do the job without them. They also keep their own delivery record under their own terms.
The hosting provider. Holds the site, the mailbox and the backups as our processor, under a contract that forbids using any of it for their own ends.
The bookkeeper. Sees invoices, and nothing else, under professional confidentiality obligations.
That is the complete list. Anyone else would need a court order or a lawful demand from a competent authority, and would get only what that demand actually covered.
How long each thing lives
| Record | Retention | Driven by |
|---|---|---|
| Enquiry that went nowhere | 12 months after the last message | So you need not repeat yourself if you come back |
| Invoice and order file | 6 years from the end of the financial year | Spanish commercial and tax law |
| Return and conformity correspondence | 3 years from delivery | Covers the 2 year period plus any argument after it |
| Refund bank details | Removed once the transfer clears | One payment, one use |
| Server request logs | 30 days, then overwritten | Security and fault diagnosis |
| Record of your cookie choice | 12 months | Proof of what was agreed and when |
At the end of a period the record is deleted outright. Where a backup set makes immediate deletion impractical, it is isolated from normal use and disappears at the next rotation.
Where it physically sits
Servers inside the European Union hold the site, the mailbox and the backups, and since we deliver only within the twenty-seven member states an order has no reason to leave the European Economic Area. Were a supplier ever to require processing beyond it, the destination would have to be a country the Commission has found adequate, or the transfer would run on standard contractual clauses. We will tell you which suppliers are involved at any given moment if you write and ask.
Things you can make us do
- Hand over a copy of everything we hold on you, with an explanation of what it is for
- Correct anything that is wrong
- Delete it, except where tax law forces us to keep an invoice, in which case it is locked away rather than used
- Freeze processing while a disagreement about accuracy is sorted out
- Object to anything we are doing on legitimate-interest grounds
- Receive it in a portable, machine-readable form
- Withdraw a consent, without that unpicking anything done lawfully beforehand
Email the address at the top. You get an answer inside a month. If a request is genuinely intricate we may need up to two months more, and we will say so within that first month rather than letting it drift.
If we handle it badly
Tell us, because the overwhelming majority of these turn out to be a misunderstanding that takes a day to clear up. Beyond that, you are entitled to complain to the Agencia Espanola de Proteccion de Datos in Spain, or to the supervisory authority of the EU country where you live or work. Using us first is not a precondition of either.
When this page moves
It changes when our practice changes, and the date at the top tells you when that last happened. If a change affects you materially and we have your email address, expect a message rather than a silent edit.