Twin Shores Capital
HomeAboutGlobal BrokerageMarket OpportunityLocal Operating Partner in Spain
Contact us
Contact us
HomeAboutGlobal BrokerageMarket OpportunityLocal Operating Partner in SpainContact us
Contact usinfo@twinshores.capital

Privacy Policy

Last updated: 2026-07-31

Introduction

This Privacy Policy explains how GPDC PROPERTIES S.L.U ("we", "us", "our") processes personal data collected through https://twinshores.capital and related services.

It should be read together with our Cookie Policy, which describes the tracking technologies used on the site.

We apply the principles of the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA) and other applicable privacy laws.

Data controller

Data controller: GPDC PROPERTIES S.L.U

Registered address: CALLE DEL BRUC NÚMERO 149, LOCAL
BARCELONA
BARCELONA 08037
Spain

Business / tax identifier: B75308999

Contact email for privacy matters: info@twinshores.capital

Website: https://twinshores.capital

To exercise any of the rights described below, contact us using the details above.

Categories of personal data

  • Identification and contact data you voluntarily provide (name, email, phone, company, message and any additional fields exposed in our forms).
  • Technical and usage data collected automatically (IP address, user agent, operating system, language, pages visited, referral source and timestamps).
  • Pseudonymous identifiers and aggregated metrics generated by analytics tools and marketing pixels.

Purposes of processing

  • Respond to your enquiries, manage quote requests and provide the services you request.
  • Keep the site secure, reliable and available, and prevent fraud or abuse.
  • Measure aggregate site usage and improve content and performance.
  • Send marketing communications or newsletters where you have consented or a prior commercial relationship exists.
  • Comply with legal obligations regarding accounting, tax and data protection.

Legal basis for processing

  • Consent (GDPR Art. 6(1)(a)): for marketing communications, non-essential cookies and, where applicable, personalised content.
  • Performance of a contract (GDPR Art. 6(1)(b)): to respond to requests, provide the services and process payments.
  • Legitimate interest (GDPR Art. 6(1)(f)): to keep the site secure, prevent fraud and improve our services — always balanced against your fundamental rights.
  • Legal obligation (GDPR Art. 6(1)(c)): to keep tax and accounting records and respond to lawful requests from competent authorities.

Third-party processors

We share data with technical service providers acting as processors under contracts compliant with GDPR Art. 28. Typical categories include:

Each provider publishes its own privacy policy. You can request an up-to-date list of processors by writing to info@twinshores.capital.

  • Infrastructure & CDN (for example Cloudflare, Supabase, Vercel) — hosting, database, bot protection.
  • Analytics & measurement (for example Google Analytics) — aggregated usage statistics.
  • Advertising & marketing (for example Meta Pixel, Google Ads) — conversion measurement and audiences.
  • Transactional email providers (for example Resend, SendGrid, Postmark) — sending notifications and newsletters.

International data transfers

Some providers are based outside the European Economic Area (for example in the United States). When personal data is transferred outside the EEA we rely on the European Commission's Standard Contractual Clauses or an equivalent adequacy framework (such as the EU-US Data Privacy Framework), and apply additional technical and organisational measures where necessary.

How long we keep your data

  • Contact form submissions: as long as needed to handle the enquiry and up to 24 months afterwards, unless a subsequent commercial relationship exists.
  • Newsletter subscriptions: until you unsubscribe (link in every email) or after 24 months of inactivity.
  • Technical and security logs: up to 12 months, unless retention is required to investigate incidents.

Security measures

We apply technical and organisational measures proportionate to the risk: TLS encryption in transit, encryption at rest in managed databases, role-based access control, password hashing (bcrypt/argon2), encrypted backups and audit logging. No system is 100% secure; we will notify you without undue delay of any breach affecting your data where required by law.

Children's data

The site is not directed to children under 16 (or the lowest age allowed in your country) and we do not knowingly collect personal data from children without verifiable parental consent. If you believe a child has provided us with data, contact info@twinshores.capital and we will delete it.

Automated decision-making

We do not make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. If this changes we will inform you and obtain consent where applicable.

Changes to this policy

We may update this policy to reflect legal, technical or business changes. The current version is always published on this page together with the date of the latest update. We will notify you through the usual channels when changes are material.

Contact

Questions about this policy or about how we process your data? Write to info@twinshores.capital.

CONNECT

Your partner in real estate investment.

info@twinshores.capital
Privacy PolicyCookie PolicyTerms of Service

© 2026 All rights reserved.

Designed by wedoprogress