Bespoke Sound & Vision S.L.

Privacy Policy

This Privacy Policy explains how we collect, use, disclose, protect and retain personal data when you visit our website, contact us, request a quotation, become a customer or supplier, apply for work, or interact with our installation, maintenance and support services.

Last updated: 17 July 2026

Important: This policy applies where Bespoke Sound & Vision S.L. decides why and how personal data is processed. Where we access personal data solely to install, configure, maintain or support a system controlled by a customer, we normally act as that customer’s data processor and follow the customer’s documented instructions and the applicable service or data-processing agreement.

Controller

Bespoke Sound & Vision S.L., CIF B93718872.

Main purposes

Enquiries, quotations, contracts, installations, support, billing, recruitment, security and permitted marketing.

Your control

You may exercise GDPR rights and withdraw consent at any time.

1. Who we are

The controller responsible for the processing described in this policy is:

Bespoke Sound & Vision S.L.
CIF: B93718872
Address: Avda. Virgen del Rocío, 29670 San Pedro de Alcántara, Marbella, Málaga, Spain
Website: http://72.62.31.65/
Email: info@bespoke-sav.es
Telephone / WhatsApp: +34 632 99 37 39

References to “Bespoke”, “we”, “us” or “our” mean Bespoke Sound & Vision S.L.

2. Scope of this policy

This policy applies to personal data relating to:

  • visitors to our website and people who use our online forms;
  • prospective customers, customers, property owners, tenants and their authorised representatives;
  • architects, interior designers, developers, estate agents, project managers and other professional contacts;
  • suppliers, manufacturers, distributors, subcontractors and service providers;
  • job applicants, temporary workers and subcontractor applicants;
  • visitors to our premises where CCTV is in operation; and
  • individuals whose data may be accessed during authorised installation, maintenance, troubleshooting or support activities.

This policy does not replace any project-specific notice, employee privacy notice, CCTV notice, cookie notice, contractual provision or data-processing agreement that applies to a particular activity.

3. Personal data we collect

Depending on the relationship and service, we may process the following categories of personal data:

Identity and contact information

Name, title, company, role, postal address, service address, email address, telephone number, preferred language and communication preferences.

Enquiry, quotation and project information

Requirements, budgets, plans, room layouts, photographs, drawings, property-access arrangements, project contacts, appointments, correspondence, decisions, change requests, warranties and service history.

Contract, payment and accounting information

Contract details, purchase orders, invoices, tax information, payment status, bank or transaction references and records required for accounting, audit, warranty, insurance and legal compliance. We do not intentionally retain full payment-card details where payments are handled by a bank or payment provider.

Technical, network and device information

IP addresses, device identifiers, network topology, equipment serial numbers, system logs, diagnostic records, configuration information, software and firmware versions, fault reports, connectivity information and support-session records.

Security, access-control and smart-system information

Authorised user names, access permissions, entry-system records, alarm or CCTV configuration details, temporary credentials, device tokens and other data needed to install, test or support a system. We seek to minimise access and do not use customer system data for our own unrelated purposes.

Website and cookie information

IP address, browser and device type, pages visited, referral source, date and time, form interactions, security logs, cookie identifiers and analytics or advertising data where the relevant consent has been given.

Recruitment information

CV, work history, qualifications, skills, language abilities, location, driving status, transport availability, references, interview notes, work eligibility and other information voluntarily supplied in connection with an application.

Images, recordings and testimonials

CCTV images at our premises; photographs or video of completed projects; and customer reviews or testimonials. Identifiable project images, customer names or testimonials are used for publicity only with appropriate permission or another valid legal basis.

Special-category and highly sensitive data

We do not normally request special-category data, criminal-record data or unrelated confidential information. Please do not submit such information through general website forms, email or WhatsApp unless it is genuinely necessary and we have agreed a secure method for receiving it.

Data about other people

If you provide personal data about another person, you must have authority to do so and, where required, inform that person about this policy. Please provide only the minimum information necessary.

4. Where personal data comes from

We may obtain personal data:

  • directly from you through our website, telephone, email, WhatsApp, meetings, quotations, contracts, site visits and support communications;
  • from a customer, property owner, authorised representative, architect, designer, developer, estate agent, project manager, employer or other person involved in a project;
  • from suppliers, subcontractors, manufacturers, distributors, logistics providers, insurers and professional advisers;
  • from publicly available professional sources, company websites, business directories, professional networks and social-media profiles where relevant to a genuine business relationship;
  • from devices, systems, servers, applications or logs that we are authorised to access for installation, configuration, diagnostics, maintenance or support; and
  • from cookies and similar technologies, subject to applicable consent requirements.

When data is not obtained directly from you, we will provide the information required by law within the applicable period unless an exemption applies.

5. Purposes and legal bases

We process personal data only where a lawful basis applies. The principal activities are set out below.

ActivityPurposeTypical dataLegal basis
Enquiries and quotationsRespond, assess requirements, arrange visits, prepare designs and quotations, and take steps requested before a contract.Identity, contact, property, project and communication data.Steps at your request before entering a contract; performance of a contract; and legitimate interests in managing genuine business enquiries.
Project deliveryDesign, supply, install, configure, commission, document and hand over cinema, audio, lighting, networking, automation, access-control, security and related systems.Contact, property, technical, access, contractual and project data.Performance of a contract; legal obligations; and legitimate interests in safe, efficient project management.
Support, warranties and aftercareDiagnose faults, provide remote or on-site support, maintain equipment, manage warranties and document work completed.Contact, device, network, log, configuration and service-history data.Performance of a contract; legal obligations; and legitimate interests in service quality, security and dispute prevention.
Customer administrationManage appointments, communications, contracts, payments, credit control, invoicing, accounting, tax, audit, insurance and legal claims.Identity, contact, contractual, financial and correspondence data.Performance of a contract; legal obligations; and legitimate interests in business administration and protecting legal rights.
Suppliers and subcontractorsSource products and labour, manage orders, delivery, access, quality, payments, compliance, insurance and project coordination.Business contact, contract, payment, qualification and access data.Performance of a contract; legal obligations; and legitimate interests in managing suppliers and projects.
Website operation and securityDeliver the website, detect misuse, prevent fraud and cyber incidents, troubleshoot faults and maintain evidence where necessary.IP address, device, browser, logs and security-event data.Legitimate interests in providing a secure and reliable website; legal obligations where applicable.
Analytics and non-essential cookiesMeasure website use, improve content and, where enabled, assess campaign performance.Cookie identifiers, device, browsing and interaction data.Consent, except where a technology is strictly necessary and another lawful basis applies.
Marketing and professional outreachSend relevant news, offers or service information; maintain professional relationships; and avoid contacting people who have opted out.Business contact, relationship, preference and campaign data.Consent; existing-customer rules where legally permitted; and legitimate interests for proportionate business-to-business relationship management, subject to electronic-marketing law and the right to object.
Project photography and testimonialsPublish approved photographs, videos, testimonials or case studies on our website, portfolio, social media or promotional material.Images, video, name, testimonial and project details.Consent or another documented lawful basis. We will respect agreed confidentiality and anonymisation requirements.
RecruitmentAssess applications, communicate with candidates, check experience and eligibility, select workers and protect legal rights.CV, qualifications, location, work eligibility, references and interview records.Steps before a contract; legal obligations; legitimate interests in recruitment; and consent where specifically required.
CCTV at our premisesProtect people, property and installations, and investigate incidents.Images and incident records.Legitimate interests in security and, where applicable, legal obligations.
Legal and regulatory mattersRespond to lawful requests, enforce agreements, manage complaints, defend claims and comply with court, tax, regulatory or law-enforcement requirements.Any relevant category, limited to what is necessary.Legal obligations; legitimate interests in protecting rights; and establishment, exercise or defence of legal claims.

Legitimate interests

Where we rely on legitimate interests, we assess the necessity and proportionality of the processing and balance our interests against the rights and reasonable expectations of the individual. You may object to processing based on legitimate interests as explained below.

Consent

Where processing is based on consent, consent is optional and may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

Requirement to provide data

Some information is necessary to prepare a quotation, enter into or perform a contract, comply with law, deliver equipment, access a site safely or provide support. If required information is not supplied, we may be unable to provide the relevant service. Optional fields will be identified where practical.

Automated decisions and profiling

We do not make decisions producing legal or similarly significant effects solely by automated means. We may use limited segmentation, such as customer type or service interest, to organise communications, but not to make significant automated decisions about individuals.

6. Smart-home, security and technical systems

Controller and processor roles

Customers normally determine the purposes for which their CCTV, access-control, alarm, networking, automation and smart-home systems process personal data. When Bespoke accesses such data only to deliver authorised technical services, the customer is normally the controller and Bespoke acts as a processor or service provider.

For these assignments, we apply the following principles:

  • access is limited to authorised personnel and to what is necessary for the agreed task;
  • remote access is used only when authorised and technically justified;
  • customer credentials should be unique, shared securely and changed after installation or when access is no longer required;
  • temporary passwords, access links and diagnostic exports are removed or returned when no longer needed;
  • customer data is not used for advertising, profiling or unrelated purposes;
  • subcontractors receive access only where necessary and subject to confidentiality and data-protection obligations;
  • security incidents are escalated to the customer without undue delay where Bespoke is acting as processor; and
  • the customer remains responsible for operating the system lawfully, providing notices, managing users, setting retention periods and responding to data-subject requests unless the contract states otherwise.

Where a project may involve systematic monitoring, biometric identification, large-scale surveillance, extensive location tracking or other high-risk processing, the customer should obtain appropriate legal advice and, where required, complete a data-protection impact assessment before deployment. Bespoke may request written confirmation of the customer’s instructions and compliance arrangements before enabling high-risk features.

7. Marketing communications

We may send marketing by email, SMS, WhatsApp or similar electronic channels only where permitted by applicable law, for example where you have consented or where an existing-customer exception applies to similar services. Each electronic marketing message will include a simple method to opt out.

We may contact professional business contacts about relevant services where we have a proportionate legitimate interest in developing or maintaining a business relationship, but we will also comply with the rules governing electronic commercial communications. You may object at any time.

When you unsubscribe, we may retain limited information on a suppression list so that we can respect your choice and avoid sending further marketing. This suppression record is not used for other purposes.

8. Cookies and online technologies

Our website may use cookies, pixels, local storage and similar technologies. Strictly necessary technologies may operate without consent where legally permitted. Analytics, advertising, social-media or other non-essential technologies must remain disabled until the required consent has been obtained.

You can accept, reject or manage non-essential cookies through the website’s consent controls and withdraw consent as easily as it was given. Browser settings may also allow you to delete or block cookies, although this can affect website functionality.

For detailed information about the cookies in use, their providers, purposes and durations, please read our Cookie Policy and use the permanent “Cookie Settings” control displayed on the website.

Do Not Track: Browser “Do Not Track” signals are not interpreted consistently across the industry. We therefore rely on our consent-management controls and applicable legal requirements.

9. Who receives personal data

We do not sell personal data. We disclose it only where necessary, proportionate and lawful. Recipients may include:

  • authorised Bespoke personnel and approved subcontractors;
  • website hosting, email, cloud storage, CRM, customer-support, cybersecurity, backup and IT providers;
  • accounting, invoicing, banking, payment, debt-recovery and audit providers;
  • manufacturers, distributors, warranty providers, couriers and logistics companies where needed to supply, register, deliver, repair or replace equipment;
  • architects, designers, developers, project managers and other project participants where authorised or necessary;
  • professional advisers, including lawyers, accountants, insurers and consultants;
  • analytics, advertising, social-media and embedded-content providers where the relevant consent has been given;
  • public authorities, courts, regulators, tax authorities, law-enforcement bodies or emergency services where disclosure is required or permitted by law; and
  • a buyer, investor or adviser in connection with a genuine corporate transaction, subject to appropriate confidentiality and data-protection safeguards.

Service providers acting on our behalf are required to process data only under appropriate instructions, confidentiality duties and security obligations. Some recipients, such as banks, couriers, manufacturers, social networks or public authorities, may act as independent controllers for their own legally defined purposes.

10. International data transfers

Some technology, cloud, communications, analytics or support providers may process data outside the European Economic Area. Where personal data is transferred internationally, we use a lawful transfer mechanism as required, such as:

  • an adequacy decision adopted by the European Commission;
  • European Commission standard contractual clauses;
  • another legally recognised safeguard or derogation; and
  • supplementary technical, contractual or organisational measures where appropriate.

You may contact us for information about the applicable safeguards. Certain commercially confidential or security-sensitive details may be redacted where legally permitted.

11. How long we retain personal data

We retain data only for as long as reasonably necessary for the purpose collected, including contractual, warranty, security, tax, accounting, insurance, dispute and legal requirements. Typical periods are:

Record typeTypical retention
Unsuccessful or inactive enquiries and quotationsNormally up to 24 months after the last meaningful contact, unless a shorter period is appropriate, a dispute exists, or you ask us to retain the details for a future project.
Customer contracts, project and service recordsFor the relationship and afterwards for warranty, limitation, insurance, audit and legal-claim periods. Core commercial records may be retained for at least six years where required by Spanish commercial law.
Invoices, accounting and tax recordsFor the legally required accounting and tax periods, generally including six years for commercial documentation and at least four years for ordinary tax-prescription purposes, subject to extensions, interruptions or special rules.
Supplier and subcontractor recordsFor the relationship and applicable accounting, tax, warranty, insurance, compliance and legal-claim periods.
Support logs and diagnostic dataFor the time needed to resolve the issue, document the service and protect system security, then deleted, anonymised or incorporated into the relevant service record as appropriate.
Temporary credentials and access tokensOnly for as long as required for the authorised work. They should be revoked, rotated, returned or securely deleted when no longer needed.
Marketing dataUntil consent is withdrawn, an objection is made, the relationship becomes inactive under our retention criteria, or continued use is no longer justified. A minimal suppression record may be retained afterwards.
Recruitment recordsFor the recruitment process and normally up to 12 months afterwards, unless a shorter period is appropriate, retention is required for a legal claim, or you expressly agree to a longer talent-pool period.
Website and security logsNormally up to 12 months, unless needed for an active security investigation, legal claim or statutory requirement.
CCTV at our premisesDeleted within a maximum of one month unless footage must be preserved for an incident and provided to the competent authority as required by law.
Consent, objection and rights-request recordsFor as long as needed to demonstrate compliance and manage or defend possible claims.

When a retention period expires, data is deleted, anonymised or securely archived and access-restricted where continued retention is legally required. Backup copies are removed through the normal backup-rotation cycle unless preservation is necessary for security or legal reasons.

12. Security measures

We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Depending on the risk and system, measures may include:

  • role-based and least-privilege access controls;
  • strong authentication and multi-factor authentication where available;
  • encryption in transit and, where appropriate, at rest;
  • secure credential handling and password rotation;
  • device, network, malware and vulnerability controls;
  • logging, monitoring, backup and recovery procedures;
  • confidentiality obligations and staff or subcontractor training;
  • supplier due diligence and contractual safeguards;
  • incident-response and breach-assessment procedures; and
  • data minimisation, access review and secure deletion.

No method of transmission, storage or system operation is completely risk-free. We therefore cannot guarantee absolute security, but we review safeguards in light of the nature of the data, available technology, implementation cost and the likelihood and severity of risk.

Please do not send passwords, alarm codes, identity documents, bank details or other sensitive information through ordinary email or general website forms unless specifically requested and a suitable secure channel has been agreed.

13. Your data-protection rights

Subject to the conditions and limits in applicable law, you may have the right to:

  • Access your personal data and receive information about its processing;
  • Rectify inaccurate or incomplete data;
  • Erase data where there is no lawful reason to continue processing it;
  • Restrict processing in certain circumstances;
  • Object to processing based on legitimate interests and object at any time to direct marketing;
  • Port data you supplied to us where processing is based on consent or contract and carried out by automated means;
  • Withdraw consent at any time where consent is the legal basis;
  • Request human intervention and challenge a significant decision based solely on automated processing, if such processing applies; and
  • Complain to the competent supervisory authority.

How to exercise your rights

Send your request to info@bespoke-sav.es with the subject line “Data Protection Request”, or write to our postal address. Please state which right you wish to exercise and provide enough information for us to locate the relevant records.

We may request proportionate proof of identity where necessary to prevent unauthorised disclosure. Do not send a full identity document unless specifically requested; where a copy is necessary, irrelevant information should be obscured where possible.

We will respond without undue delay and normally within one month. This period may be extended by up to two additional months for complex or numerous requests, in which case we will explain the extension. Rights may be restricted where an exemption applies or where data must be retained to comply with law or establish, exercise or defend legal claims.

Requests are normally free of charge. A reasonable fee may be charged, or a request refused, where permitted by law because it is manifestly unfounded or excessive.

14. Children’s data

Our website and services are directed to adults and business users and are not designed for children. A person under 14 should not submit personal data through the website without the authorisation of a parent or legal guardian. If we learn that personal data has been submitted unlawfully by a child, we will take appropriate steps to delete it.

16. Changes to this policy

We may update this policy to reflect changes in our services, technology, suppliers, legal requirements or processing activities. The current version will be published on this page with its effective date. Where a change materially affects existing processing, we will provide additional notice where required.

17. Contact and complaints

For privacy questions, rights requests or concerns, contact:

Bespoke Sound & Vision S.L.
Avda. Virgen del Rocío, 29670 San Pedro de Alcántara, Marbella, Málaga, Spain
Email: info@bespoke-sav.es
Telephone: +34 632 99 37 39

You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD): www.aepd.es.

We encourage you to contact us first so that we can investigate and attempt to resolve the matter promptly.

This public policy should be read together with applicable contracts, quotation terms, project documentation, cookie notices, CCTV notices and any specific data-processing agreement.

'''path = Path("/mnt/data/bespoke-privacy-policy-elementor.html") path.write_text(html, encoding="utf-8")print(f"Created: {path}") print(f"Characters: {len(html):,}")