Privacy Policy
Last updated: 2026-07-31
Introduction
This Privacy Policy explains how GPDC PROPERTIES S.L.U ("we", "us", "our") processes personal data collected through https://twinshores.capital and related services.
It should be read together with our Cookie Policy, which describes the tracking technologies used on the site.
We apply the principles of the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA) and other applicable privacy laws.
Data controller
Data controller: GPDC PROPERTIES S.L.U
Registered address: CALLE DEL BRUC NÚMERO 149, LOCAL
BARCELONA
BARCELONA 08037
Spain
Business / tax identifier: B75308999
Contact email for privacy matters: info@twinshores.capital
Website: https://twinshores.capital
To exercise any of the rights described below, contact us using the details above.
Categories of personal data
- Identification and contact data you voluntarily provide (name, email, phone, company, message and any additional fields exposed in our forms).
- Technical and usage data collected automatically (IP address, user agent, operating system, language, pages visited, referral source and timestamps).
- Pseudonymous identifiers and aggregated metrics generated by analytics tools and marketing pixels.
Purposes of processing
- Respond to your enquiries, manage quote requests and provide the services you request.
- Keep the site secure, reliable and available, and prevent fraud or abuse.
- Measure aggregate site usage and improve content and performance.
- Send marketing communications or newsletters where you have consented or a prior commercial relationship exists.
- Comply with legal obligations regarding accounting, tax and data protection.
Legal basis for processing
- Consent (GDPR Art. 6(1)(a)): for marketing communications, non-essential cookies and, where applicable, personalised content.
- Performance of a contract (GDPR Art. 6(1)(b)): to respond to requests, provide the services and process payments.
- Legitimate interest (GDPR Art. 6(1)(f)): to keep the site secure, prevent fraud and improve our services — always balanced against your fundamental rights.
- Legal obligation (GDPR Art. 6(1)(c)): to keep tax and accounting records and respond to lawful requests from competent authorities.
Third-party processors
We share data with technical service providers acting as processors under contracts compliant with GDPR Art. 28. Typical categories include:
Each provider publishes its own privacy policy. You can request an up-to-date list of processors by writing to info@twinshores.capital.
- Infrastructure & CDN (for example Cloudflare, Supabase, Vercel) — hosting, database, bot protection.
- Analytics & measurement (for example Google Analytics) — aggregated usage statistics.
- Advertising & marketing (for example Meta Pixel, Google Ads) — conversion measurement and audiences.
- Transactional email providers (for example Resend, SendGrid, Postmark) — sending notifications and newsletters.
International data transfers
Some providers are based outside the European Economic Area (for example in the United States). When personal data is transferred outside the EEA we rely on the European Commission's Standard Contractual Clauses or an equivalent adequacy framework (such as the EU-US Data Privacy Framework), and apply additional technical and organisational measures where necessary.
How long we keep your data
- Contact form submissions: as long as needed to handle the enquiry and up to 24 months afterwards, unless a subsequent commercial relationship exists.
- Newsletter subscriptions: until you unsubscribe (link in every email) or after 24 months of inactivity.
- Technical and security logs: up to 12 months, unless retention is required to investigate incidents.
Security measures
We apply technical and organisational measures proportionate to the risk: TLS encryption in transit, encryption at rest in managed databases, role-based access control, password hashing (bcrypt/argon2), encrypted backups and audit logging. No system is 100% secure; we will notify you without undue delay of any breach affecting your data where required by law.
Children's data
The site is not directed to children under 16 (or the lowest age allowed in your country) and we do not knowingly collect personal data from children without verifiable parental consent. If you believe a child has provided us with data, contact info@twinshores.capital and we will delete it.
Automated decision-making
We do not make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. If this changes we will inform you and obtain consent where applicable.
Changes to this policy
We may update this policy to reflect legal, technical or business changes. The current version is always published on this page together with the date of the latest update. We will notify you through the usual channels when changes are material.
Contact
Questions about this policy or about how we process your data? Write to info@twinshores.capital.
