Privacy Policy
At Bloka, we take the protection of your personal data very seriously. This policy describes how we collect, use, and safeguard your information in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and applicable Spanish data-protection legislation, including Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD).
Bloka Technologies S.L., Tax ID (CIF) B-12345678, registered at Calle de la Innovación 1, 28001 Madrid, Spain. Contact: privacidad@bloka.com
We may collect the following categories of personal data: full name, email address, telephone number, residential address, homeowner community details, payment and banking information (for SEPA direct debits), and application usage data (device type, IP address, interaction logs).
We process your data for the following purposes: (a) to provide and maintain the Bloka community-management platform; (b) to send transactional communications related to your community (meeting notices, vote results, fee receipts); (c) to process payments through SEPA direct debit mandates; (d) to improve our product through aggregated, anonymised analytics; and (e) to comply with legal obligations under the LPH and other applicable laws.
We rely on the following legal bases: (a) performance of a contract (Art. 6(1)(b) GDPR) — processing necessary to provide the Bloka service you or your community subscribed to; (b) legitimate interest (Art. 6(1)(f) GDPR) — product improvement through anonymised analytics, provided this does not override your fundamental rights; (c) consent (Art. 6(1)(a) GDPR) — where you have given explicit consent, such as for marketing communications; and (d) legal obligation (Art. 6(1)(c) GDPR) — where processing is required by Spanish law or the LPH.
We retain personal data for as long as your account is active or as needed to provide the service. After account closure, we retain data for the period required by law (typically 5 years for financial records under Spanish commercial law, and 3 years for liability purposes). Anonymised analytics data may be retained indefinitely.
Your data may be shared with: (a) cloud-infrastructure providers located within the European Union; (b) payment processors for SEPA mandate execution; and (c) public authorities when required by law. We do not sell your personal data to third parties.
All data is stored on servers located within the European Union. We do not transfer personal data outside the EEA. Should this change in the future, we will ensure appropriate safeguards are in place in accordance with Chapter V of the GDPR (e.g., Standard Contractual Clauses).
You have the right to: (a) access your personal data (Art. 15); (b) rectify inaccurate data (Art. 16); (c) request erasure (Art. 17, "right to be forgotten"); (d) restrict processing (Art. 18); (e) data portability (Art. 20); (f) object to processing (Art. 21); and (g) not be subject to automated decision-making (Art. 22). To exercise any of these rights, contact us at privacidad@bloka.com. We will respond within 30 days as required by Art. 12(3) GDPR.
If you believe your data-protection rights have been infringed, you have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD) at www.aepd.es.
We implement appropriate technical and organisational measures in accordance with Art. 32 GDPR, including encryption in transit (TLS 1.3) and at rest (AES-256), role-based access controls, regular penetration testing, and incident-response procedures.
Bloka does not make automated decisions that produce legal effects on you or similarly significantly affect you, within the meaning of Article 22 of the GDPR. Automated calculations of fees, quorum and majorities are management support tools always subject to supervision by the responsible property manager.
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the application. Continued use of Bloka after notification constitutes acceptance of the revised policy.