LEGAL
Privacy Policy
1. Data Controller
The data controller is JOON DILLMANN, with NIE X0323849D, registered lawyer (abogado) nº 6337 of the Bar Association of the Balearic Islands (Ilustre Colegio de Abogados de les Illes Balears), with professional address at Carrer Sa Mar, 2, 1B, 07100, Sóller, Illes Balears, Spain, contact email and phone .
JOON DILLMANN acts in the legal and digital traffic under the main trade names of “Joon Dillmann”, “Abogado Dillmann”, “Dillmann & Partner”, and may also operate, where appropriate, under other names, brands, distinctive signs or trade names linked to their professional activity, including “Dillmann & Asociados”, “Iustitia Abogados”, hereinafter, jointly, the “Firm”.
When for legal, deontological, contractual, organizational or transparency reasons it is necessary to identify a specific professional responsible for a matter, service, publication, file, action or intervention, such identification will be made in the engagement letter, contract, quote, service sheet, professional profile, contact page, legal notice of the corresponding site or private communication with the data subject.

2. Scope of Application
This Privacy Policy applies to all websites, domains, subdomains, digital platforms, applications, document repositories, wikis, intranets, extranets, private areas, forms, communication channels and other digital environments owned, operated, administered or managed by the Firm, whether they currently exist or are added in the future, unless a different specific policy is expressly published on any of them.
By way of example and without limitation, this policy may apply to the environments associated with dillmann.es, wiki.dillmann.es, dillmann-partner.com, iustitia.com, iuswiki.com and any other present or future domains, subdomains or digital projects linked to the professional, editorial, documentary, technological or knowledge management activity of the Firm.
The use of different names, domains, extensions, linguistic structures or digital brands for organizational, technical, commercial or editorial reasons does not in itself imply a change of data controller, unless expressly indicated in a specific policy, in the corresponding legal notice or in the applicable contractual document.
3. Applicable Regulations
The processing of personal data is carried out in accordance with Regulation (EU) 2016/679, General Data Protection Regulation (GDPR), Organic Law 3/2018 on the Protection of Personal Data and guarantee of digital rights (LOPDGDD), Law 34/2002 on Information Society Services and Electronic Commerce (LSSI), and other Spanish and European regulations that may be applicable depending on the service provided, the type of data processed and the professional sector affected.
4. Categories of Processed Data
Depending on the type of relationship, service or interaction, the Firm may process the following categories of data:
- Identification data: name, surname, DNI, NIE, passport, signature, date of birth, nationality or other equivalent identification data.
- Contact data: postal address, email, telephone, notification addresses and other communication channels provided by the data subject or their representative.
- Professional and representation data: profession, position, entity, firm, company, professional association, powers of attorney, legal or voluntary representation and relationship with the matter or file.
- Economic, financial, banking, tax, registry, cadastral, succession, corporate, urban planning, contractual, procedural or administrative data, when necessary for the provision of the service.
- Data contained in documents provided by clients, potential clients, counterparties, public administrations, registries, notaries, courts, tribunals, communities of owners, property managers, collaborators or other legitimate sources.
- Browsing and usage data: IP address, session identifiers, date and time of access, server logs, pages visited, technical device data, browser, operating system, source references, technical incidents and other metadata generated by the use of the Sites and Digital Environments.
- Account and digital collaboration data: username, alias, credentials, access history, change history, versions, contributions, comments, articles, uploaded files, moderation actions and activity logs in wikis, repositories, private areas, intranets or collaborative tools.
- Data of third parties provided by the user, client or intervener, provided that this is necessary for the management of the matter and there is a sufficient legal basis.
5. Origin of the Data
Personal data may originate from the data subject themselves, their representative, clients who provide third-party data, collaborators and intervening professionals, public registries, notaries, land registries, public administrations, judicial bodies, professional associations, communities of owners, legitimately accessible sources, as well as from browsing, use and participation in the Firm’s Sites and Digital Environments.
6. Purposes of the Processing
Personal data may be processed for the following purposes:
- To attend to queries, requests for information, requests for quotes, contact forms and professional communications.
- To analyze the viability of matters, prepare proposals, quotes, engagement letters and contracts.
- To manage and execute professional assignments of advocacy, mediation, advice, property administration, consulting, training, documentation, knowledge management and any other lawful services linked to the Firm’s activity.
- To manage files, documentation, diaries, appointments, communications, billing, collections, payments and compliance with legal, tax, accounting, professional, deontological and anti-money laundering obligations, where applicable.
- To technically administer the Sites and Digital Environments, guarantee their security, control access, prevent abuse, investigate incidents and maintain backups and logs.
- To create, maintain, suspend or delete user accounts and manage profiles, permissions and roles in wikis, private areas, document repositories, intranets or collaborative platforms.
- To record the traceability of changes, contributions, publications, versions, restorations, deletions and other actions carried out in collaborative or editorial environments.
- To prepare, organize, review and preserve knowledge repositories, doctrinal articles, templates, forms, precedents, working notes, documentary bases and other legal or technical contents, both of public and restricted access.
- To defend the legitimate rights and interests of the Firm and prevent or manage conflicts, claims, security incidents, improper uses or regulatory breaches.
- To send, when there is a sufficient legal basis, informative or professional communications or communications related to the Firm’s services.
- To attend to requests for the exercise of data protection rights.
7. Legal Basis
The legal bases legitimizing the processing will be, depending on each case:
- The execution of a contract or a professional assignment.
- The application of pre-contractual measures at the request of the data subject.
- Compliance with legal obligations.
- The legitimate interest of the Firm in organizing its activity, documenting its professional actions, protecting its systems, guaranteeing the security of its digital environments, maintaining the traceability of contents and improving the quality of the service.
- The consent of the data subject, when it is necessary or appropriate to collect it, especially for certain communications, optional features or non-essential technologies.
When the processing is based on consent, this may be withdrawn at any time without retroactive effects on processing lawfully carried out previously.
8. Domains, Brands and Digital Projects
The Firm may carry out its activity through a plurality of domains, subdomains, brands, portals, vertical sites, microsites, blogs, wikis, document platforms or technological tools, present or future.
Unless a different specific policy is published in a specific environment, this Privacy Policy will be applicable to all of them when they are owned by, managed by or organizationally dependent on the Firm.
9. Collaborative Environments, Wikis and Private Areas
The Firm may have public, semi-public, restricted or internal environments intended for the dissemination of knowledge, legal documentation, internal organization, training, professional coordination or collaboration among authorized users.
In such environments, identification data of users, IP addresses, access logs, edit history, versions, comments, uploaded files, moderation actions and other metadata necessary for system administration, security, traceability, content integrity and service management may be processed.
The creation of accounts, the assignment of permissions and the deletion, suspension or limitation of accesses may be reserved for the system administrators or the persons expressly designated by the Firm.
Participation in collaborative environments does not authorize the publication of illegal, defamatory, inaccurate, confidential contents without sufficient authorization, or materials that violate third-party rights or the regulations on intellectual property, data protection, professional secrecy or unfair competition.
10. Data Retention
The data will be kept for the time necessary to fulfill the purpose for which they were collected and, subsequently, while they must be kept blocked or retained for compliance with legal, deontological, tax, accounting, or archival obligations or for the formulation, exercise or defense of claims.
Logs, access records, editing histories, backups and technical traces may be kept for the time reasonably necessary to guarantee the security, integrity, continuity and auditability of the systems and the contents managed by the Firm.
11. Recipients and Data Processors
In general, personal data will not be communicated to third parties without sufficient legal basis, except when this is necessary for the provision of the service, compliance with legal obligations, the defense of claims or the use of suppliers acting as data processors.
Depending on the type of matter or service, the data may be communicated to, among others, court representatives (procuradores), notaries, registries, public administrations, judicial bodies, financial entities, experts, translators, communities of owners, property managers, technology providers, hosting services, email providers, backups, electronic signature providers, IT support or other intervening professionals.
Where appropriate, the Firm will formalize the contracts required by the regulations in force with its data processors.
12. International Transfers
If for the provision of the service or the technical operation of the Sites and Digital Environments it were necessary to make international data transfers, the Firm will adopt the appropriate guarantees provided for in the applicable regulations.
13. Confidentiality and Professional Secrecy
The Firm will treat personal data with strict confidentiality. Professionals, employees, collaborators and suppliers with access to information will be subject to duties of confidentiality and, where appropriate, to professional secrecy and the deontological obligations that may be applicable.
14. Security Measures
The Firm applies appropriate technical and organizational measures to protect personal data against loss, alteration, unauthorized access, improper disclosure or destruction, taking into account the nature of the data, the state of the art and the existing risks.
However, no security measure can guarantee absolute protection. In the event of a security incident affecting personal data, the Firm will act with due diligence and adopt the necessary measures in accordance with the applicable regulations.
15. Rights of the Data Subjects
The data subject may exercise the rights of access, rectification, deletion, opposition, limitation of processing and portability, under the terms provided for by the applicable regulations, as well as withdraw their consent when the processing is based on it.
To do so, they may send a written request to the email or address indicated in section 1, reasonably proving their identity and indicating the right they wish to exercise.
Likewise, they may file a claim with the Spanish Data Protection Agency (AEPD) or with the corresponding competent supervisory authority.
16. Cookies and Similar Technologies
The Firm’s Sites and Digital Environments may use cookies, local storage, pixels, beacons, scripts, identifiers and similar technologies, proprietary or from third parties, for technical, security, personalization, measurement, analysis or, where appropriate, other specifically indicated purposes.
Detailed information on such technologies, their purpose, duration, legal basis and management options will be collected in the Cookie Policy or in the configuration panel of the specific site or environment.
17. External Links
The Sites and Digital Environments may contain links to third-party pages, platforms or services. The Firm is not responsible for the privacy policies or practices of such third parties, so it is recommended to review their legal texts before providing them with personal data.
18. Minors
The Firm’s services are not primarily directed at minors. If, due to the nature of the matter, it is necessary to process minors’ data, such processing will be carried out in accordance with the applicable regulations and, where appropriate, with the intervention of those who hold their legal representation.
19. Modifications
This Privacy Policy may be modified to adapt it to regulatory, jurisprudential, organizational, technical or functional changes, as well as to the evolution of the Firm’s services, domains, platforms or activities.
The valid version will be the one published at any given time in the corresponding site or digital environment.