The essentials, in five lines
- You can complete the whole test without giving us any personal data.
- Each purpose is decided separately: there is no single button that authorises everything.
- We use no cookies and no third-party analytics. We do not profile you and we do not track you.
- Everything is hosted in the European Union. There are no international transfers.
- You can withdraw your consent in one click from the footer, under “Manage my consent”.
Controller
ILP Abogados, with contact address info@ilpabogados.com, is the controller of the data described in this policy.
To be completed by the firm before publication: exact corporate name, tax identification number (NIF), registered address, bar registration details and, where applicable, the contact details of the data protection officer.
Purposes, one by one
We ask for your decision on three independent purposes. You may accept one and refuse the other two. Refusing all of them does not limit your use of the tool.
1. Audience measurement
Aggregated, anonymous usage counters, such as how many people complete the assessment or how many reports are requested. Without identifying you, without advertising cookies and without third parties.
What is stored is a daily counter per metric name and a figure. It is not linked to any person, not even to a session: there is no way to reconstruct who did what.
2. Preparation of the report
Using the data you provide to prepare and display on screen your defensibility report. The form fields are name and surname, company, position, professional email address and telephone number, together with your test result.
The tool does not send you any email of its own accord. It prepares the report and shows it to you; any subsequent contact depends on the third purpose.
3. Commercial contact
That ILP Abogados contacts you in relation to your result. This is managed in the firm's internal CRM, ILP LeadOS, hosted in the European Union.
Exactly what is sent to the CRM when you authorise it
If you tick the commercial contact box, the following data, and no other, is transmitted to the internal CRM:
- Your contact details: name and surname, email address, telephone number and company, plus a record identifier built from the random identifier of your session.
- A text summary with your position, your Defensibility Index out of one hundred, the level that corresponds to you and the approximate number of people whose data your company holds, as you have indicated it.
- A priority flag if you have declared that you suffered an incident in the last twenty-four months.
- The rule-by-rule detail of the result, that is, in which blocks of the assessment your ability to prove fares better or worse.
- Your answers to the test and the size data you have provided.
- The practice area (“Data Protection”), the language and the source tool, together with the page and the call to action from which you arrived.
- The date and time of your consent, with the version of the text that was shown to you and its cryptographic fingerprint.
- The origin parameters of the visit (campaign, medium, source, landing page and referring site), if you came from a campaign.
Legal basis
The legal basis for the three purposes is your consent, Article 6.1(a) of Regulation (EU) 2016/679 (GDPR). It is freely given, specific, informed and unambiguous consent: it is requested separately for each purpose, no box is pre-ticked and refusing does not penalise your use of the service.
The technical storage strictly necessary to provide the service you request is covered by Article 22.2 of Law 34/2002 on information society services and electronic commerce (LSSI-CE) and does not require consent. It is explained in the cookie policy.
Recipients and processors
We do not disclose your data to third parties for commercial purposes. We do not sell it. Only the providers strictly necessary for the tool to work are involved:
- Hosting of the site and the application: Vercel, with execution pinned to the Frankfurt region (Germany).
- Database: Neon, managed PostgreSQL, also in Frankfurt (Germany). It stores the evidential record of consents and the aggregated counters.
- Internal CRM ILP LeadOS: the firm's own system, hosted in the European Union. It only receives the data of those who have consented to commercial contact.
All of them act as processors, on behalf of ILP Abogados and following its instructions. Apart from the above, public authorities may access the data where a legal rule so requires.
International transfers
Retention periods
- Your decision on the purposes: for as long as it remains in force and, at most, 24 months. It then expires and we ask you again. It also expires sooner if we change the information text.
- Evidential record of consents: kept for as long as it may be necessary to evidence that you consented, in accordance with Article 7.1 GDPR, and for the applicable limitation periods.
- Report form data: for the time needed to prepare it and show it to you, and thereafter for the time imposed by the firm's legal obligations.
- Data in the ILP LeadOS CRM: for as long as the relationship or the interest in it is maintained and you do not object or withdraw your consent; thereafter, blocked for the applicable limitation periods and then erased.
- Audience counters: these are aggregated figures with no personal data, so they carry no erasure period.
Exactly what is stored in the evidential record
When you accept or refuse a purpose, we store an entry that serves to demonstrate what you decided and on which text. That entry contains only:
- A random session identifier, generated in your browser, which contains no personal data.
- The date and time of the decision.
- The purpose to which it relates and whether it was accepted or refused.
- The language in which the text was shown to you.
- The version of the legal text and a hash of it, that is, a cryptographic fingerprint that makes it possible to prove which specific wording you read.
- The channel from which you decided (for example, the consent panel or the test form).
Acceptance of the no-advice statement is recorded with the same fields and the same scope: random session identifier, date, language, version and hash of the text.
Your rights
You may exercise at any time your rights of access, rectification, erasure, objection, restriction of processing and portability of your data.
To do so, write to info@ilpabogados.com stating the right you are exercising. We will reply expressly within one month, extendable by a further two months on grounds of complexity, notifying you within the first month. We may ask you to prove your identity.
If you consider that we have not dealt with your request properly, you may lodge a complaint with the competent supervisory authority, the Spanish Data Protection Agency (AEPD) (www.aepd.es).
Withdrawing consent
Withdrawing consent must be as easy as giving it. In the footer of any page you will find the “Manage my consent” link: open it and you will be able to change each purpose, or refuse them all at once. The change takes effect immediately.
Withdrawal does not affect the lawfulness of the processing carried out before it. If we had already shown you the report or registered you in the CRM, that processing remained lawful.
Expiry of your decision
Your decisions expire after 24 months, and sooner if we change the information text: in that case we will ask you again, because consent is not carried over between different versions of the text.
Automated decisions
The Defensibility Index is calculated by an algorithm from your answers, but it produces no legal effect on you and does not significantly affect you: it is informational guidance. We do not build profiles and we do not take automated decisions within the meaning of Article 22 GDPR.
Third-party data
The test asks you for the approximate number of people whose data your company holds, not for their identities. Do not enter in the open fields any names, case files or details of people affected by an incident: we do not need them and we must not process them.
Minors
This tool is aimed at professionals and companies. It is not intended for minors and we do not knowingly collect their data.
Changes to this policy
If we amend this policy, we will raise its version number. As consent is not carried over between versions, you will be asked again the next time you enter.
Text version: 2026-08-06-borrador-1.
Text version: 2026-08-06-borrador-1