Privacy policy
Privacy Policy
At We are Sorensen SL (hereinafter, "Sorensen") we are committed to protecting the privacy of the users of the website https://sorensen.ai and to complying with the current regulations on personal data protection, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation, "GDPR") and the Spanish Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
This policy explains how we collect, use, and protect your personal data when you visit our website or interact with us.
1. Data controller
- Owner: We are Sorensen SL
- NIF/CIF: B19968528
- Address: Badajoz, 38-40, bajos, 08005 Barcelona (Spain)
- Email: [email protected]
- Data Protection Officer (DPO): Sorensen has no legal obligation to appoint a DPO.
2. What data we process and for what purpose
We process the personal data that you provide us directly through website forms, email, or any other means of communication, as well as data collected automatically through cookies and similar technologies (see the Cookies Policy).
The purposes for which we process your data are the following:
a) Management of inquiries and contact requests. When you write to us through the contact form or by email, we process your data (name, email address, company, message, and any other information you provide) to respond to your inquiry and manage the related communication.
b) Business relationship management and provision of services. If you purchase or request information about our products (Larsson, Brevity, Longity, Chatbots, etc.) or projects, we process your data to prepare quotes, formalize contracts, provide the agreed services, invoice, and comply with the resulting legal, accounting, and tax obligations.
c) Sending commercial communications and newsletters. If you subscribe, we process your data to send you information about updates, products, projects, events, and contents from Sorensen's blog. You may unsubscribe at any time.
d) Statistical website analysis. If you consent, we use analytical cookies to understand how you use the website and to improve its performance and content.
e) Social media management. If you interact with us through our profiles on social networks, the processing of your data will be governed by the terms and privacy policies of each platform, without prejudice to the fact that Sorensen may process the public information of your profile to respond to your interactions.
3. Legal basis for processing
The legal basis for processing your data, depending on the purpose, is:
- Consent of the data subject (Art. 6.1.a GDPR): for sending commercial communications, subscribing to the newsletter, and using non-technical cookies.
- Performance of a contract or application of pre-contractual measures (Art. 6.1.b GDPR): for managing inquiries, preparing quotes, and providing the contracted services.
- Compliance with a legal obligation (Art. 6.1.c GDPR): for compliance with tax, accounting, commercial, and any other applicable regulations.
- Legitimate interest (Art. 6.1.f GDPR): for managing website security and sending communications to current clients regarding products and services similar to those originally contracted, in accordance with Art. 21.2 of the LSSI-CE.
Consent may be withdrawn at any time, without affecting the lawfulness of the processing carried out prior to its withdrawal.
4. Data retention period
We will keep your data for the time strictly necessary to fulfill the purposes for which they were collected:
- Contact inquiries: the time necessary to respond to the inquiry and, subsequently, for one year in case of additional communications.
- Contractual relationships: for the duration of the contract and, once finalized, during the legal limitation periods for legal actions (generally 5 years for civil obligations and up to 6 years for commercial and tax obligations).
- Commercial communications and newsletters: until you withdraw consent or unsubscribe.
- Cookies: the periods indicated in the Cookies Policy.
Once these periods have elapsed, the data will be securely deleted or anonymized.
5. Data recipients
Your personal data will not be transferred to third parties, except:
- When necessary to comply with a legal obligation.
- To service providers (data processors) who support us in our business activity, such as web hosting providers, email services, customer relationship management (CRM) tools, newsletter delivery, or analytics services. These providers process data on behalf of Sorensen and are subject to the corresponding data processing agreements in compliance with Art. 28 of the GDPR.
International data transfers
Some of the service providers we use may be located outside the European Economic Area (EEA) — for example, in the United States. In these cases, Sorensen guarantees that the transfer is carried out with the appropriate safeguards provided by the GDPR, such as:
- The recipient's adherence to the EU-U.S. Data Privacy Framework (where applicable).
- The signing of Standard Contractual Clauses approved by the European Commission.
- Other appropriate safeguards according to Articles 44 to 49 of the GDPR.
You can request more detailed information about these transfers through the email address provided in section 1.
6. Rights of the data subjects
In accordance with the GDPR and the LOPDGDD, you have the following rights regarding your personal data:
- Access: to know what data of yours we process and for what purpose.
- Rectification: to request the correction of inaccurate or incomplete data.
- Erasure (right to be forgotten): to request the deletion of your data when they are no longer necessary.
- Objection: to object to the processing of your data for reasons related to your particular situation.
- Restriction of processing: to request the restriction of processing in certain cases.
- Portability: to receive your data in a structured, commonly used, and machine-readable format, and to transmit them to another controller.
- Withdrawal of consent: at any time, without retroactive effects.
- Not to be subject to automated individual decisions that produce legal effects on you.
You can exercise these rights by sending a written request to the email address [email protected] or by postal mail to the address indicated in section 1, enclosing a copy of your identity document or any other means that allows verifying your identity.
Right to lodge a complaint with a supervisory authority. If you consider that the processing of your data does not comply with the regulations, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), located at Calle Jorge Juan, 6, 28001 Madrid, or through its website: https://www.aepd.es.
7. Source of data
The personal data we process come directly from the data subject or their legal representative. We do not collect data from third-party sources without prior notification.
8. Security measures
Sorensen has adopted the necessary technical and organizational measures to guarantee the security, integrity, and confidentiality of personal data, and to prevent their alteration, loss, unauthorized processing, or access, in accordance with the state of technology, the nature of the data, and the risks to which they are exposed.
9. Minors
The services offered through the website are directed at individuals over 14 years of age. Sorensen does not knowingly collect data from minors under this age. If we detect that we have collected data from a minor without valid parental consent, we will delete them as soon as possible.
10. Amendments to this policy
Sorensen reserves the right to modify this Privacy Policy to adapt it to new legislation, case law, or changes in its practices. In the event of material amendments, users will be informed through the website or by other appropriate means.
Last updated: June 18, 2026