Legal document

Privacy Policy

Last updated: 8 September 2026

This policy explains who processes your personal data when you deal with us, for what purpose, for how long, and what you can do about it. It also explains, in a section of its own, how we handle the information we access through Google APIs when managing our clients' Google Business Profiles.

1. Data controller

Legal entityALMA DIGITAL FOOD SEARCH, S.L.
Trading nameLlegando Al Mundo
Tax ID (NIF/CIF)B22511596
Registered addressCarrer d'Aribau 127, planta 2, puerta 2, 08036 Barcelona, Spain
Emailcontacto@llegandoalmundo.com
Phone624 026 790
Websitehttps://llegandoalmundo.com

2. What data we process and why

2.1. If you contact us

We process the name, email address, phone number and message content you send us, solely in order to reply and, where appropriate, prepare a proposal.

2.2. If you are a client

We process the identifying and tax details of the restaurant and of the contact person, the data required to deliver the contracted service, and billing data.

2.3. If you are a candidate or collaborator

We process the data contained in the CV or proposal you send us, in order to assess it.

3. Google data we access on behalf of our clients

In one line: when we manage a restaurant's Google Business Profile, that data belongs to the restaurant. We act as a data processor on their behalf, with their explicit and revocable authorisation, and we use that information for nothing else.

3.1. How we obtain access

Each restaurant owner grants us access as an administrator or manager of their Google Business Profile from their own Google account. We never request or store our clients' passwords, and access can be revoked at any time from within the Google profile itself, without needing to ask us.

3.2. What information we access

3.3. What we use it for

Solely to deliver the service contracted by that client: keeping their profile up to date, publishing their content, replying to their reviews and producing performance reports for them.

3.4. Google API Services User Data Policy

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, with respect to data obtained through the Google Business Profile APIs:

3.5. Where it is stored and for how long

The information is held in our internal management tool, hosted on servers located within the European Union, with restricted access protected by an individual password for each member of the team. When a client ends the relationship, we revoke our access to their profile and delete the associated data within a maximum of thirty days, except for data we are legally required to retain.

4. Who we share data with

We do not sell or trade personal data. It is accessed only by the providers we need in order to operate, all of them bound by a data processing agreement:

Where a provider processes data outside the European Economic Area, the transfer relies on the Standard Contractual Clauses approved by the European Commission or on an adequacy decision.

5. Cookies

This website does not use cookies, whether first-party or third-party, nor analytics tools, tracking pixels, or fonts and resources loaded from external servers. We do not need to ask for your consent because we collect nothing while you browse.

6. Your rights

You may exercise at any time your rights of access, rectification, erasure, objection, restriction of processing, data portability, and the right not to be subject to automated individual decision-making.

To do so, write to contacto@llegandoalmundo.com stating which right you wish to exercise and attaching proof of identity. We will respond within one month at the latest.

If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (aepd.es), C/ Jorge Juan 6, 28001 Madrid, Spain.

If you are a customer of a restaurant we manage and wish to exercise your rights over data appearing on its Google profile or its social channels, please contact the restaurant directly: in that case the restaurant is the data controller and we are only the processor.

7. Security

We apply technical and organisational measures proportionate to the risk: individual username and password for each user, encryption in transit via HTTPS, daily backups, access logging, and periodic review of the permissions granted. No system is infallible, but should a breach affecting your data occur, we would notify you and report it to the supervisory authority in accordance with Articles 33 and 34 GDPR.

8. Minors

Our services are aimed at businesses and at adults. We do not knowingly collect data from children under the age of fourteen.

9. Changes to this policy

If we change this policy we will publish the new version here, with its date. Where the change is substantial and affects active clients, we will notify them by email.