Privacy Policy
Last updated: April 2026
Data Controller
The data controller for personal data collected on the Website aurea-andorra.com is: Aurea Gestoria Group Registered office: Andorra la Vella, Principality of Andorra Email: contact@aurea-andorra.com Phone: +33 6 82 28 12 23 For any questions regarding the protection of your personal data, you may contact our Data Protection Officer (DPO) at: contact@aurea-andorra.com. This policy is established in accordance with the Llei qualificada de protecció de dades personals (LQPD) of the Principality of Andorra and, insofar as our services are directed at persons residing in the European Union, Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (GDPR).
Personal Data Collected
In the course of our activities and your use of the Website, we may collect the following categories of personal data: • Identification data: surname, first name, date of birth, nationality, passport or identity document number. • Contact data: email address, telephone number, postal address, current country of residence. • Professional data: professional situation, sector of activity, information relating to your residency or company formation project in Andorra, desired residence type (active or passive). • Financial and asset-related data: documents relating to your financial situation, investment evidence, bank statements and any documents required for preparing your residency file, submitted via the secure client area. • Technical browsing data: IP address, browser type and version, operating system, screen resolution, pages visited, date and time of connection, visit duration, referring URL. • Cookie-related data: session identifiers and language preferences. • Client area data: login credentials, exchange history, uploaded documents, file progress status, notes and comments relating to the support process.
Processing Purposes
The personal data collected is processed for the following purposes: • Management of contact and appointment requests: responding to enquiries submitted via the contact form or by telephone. • Preparation and management of client files: processing residency applications (active or passive), company formation, property acquisition and other administrative procedures with Andorran authorities. • Operation of the secure client area: authentication, document submission and consultation, file progress tracking, communication between the client and Aurea Gestoria Group teams. • Compliance with legal and regulatory obligations: fulfilment of obligations relating to anti-money laundering, identity verification (KYC) and requirements of the competent Andorran authorities. • Service improvement: analysis of Website usage for the purpose of optimising usability, performance and the services offered. • Anonymised statistics: production of aggregated and anonymous statistics on Website traffic and usage that do not allow identification of individual users.
Legal Basis for Processing
Each processing activity is based on one of the following legal grounds, in accordance with the LQPD and the GDPR: • Consent (Article 6(1)(a) GDPR / Article 6 LQPD): when you complete the contact form or voluntarily provide us with information. You may withdraw your consent at any time by contacting us at contact@aurea-andorra.com, without affecting the lawfulness of processing carried out prior to such withdrawal. • Performance of a contract or pre-contractual measures (Article 6(1)(b) GDPR): processing necessary for the management of your residency file, the use of the client area and the provision of agreed services. • Legal obligation (Article 6(1)(c) GDPR): processing necessary for compliance with legal obligations to which Aurea Gestoria Group is subject, including anti-money laundering and counter-terrorist financing regulations, identity verification and accounting and tax obligations. • Legitimate interest (Article 6(1)(f) GDPR): processing necessary for the legitimate interests pursued by Aurea Gestoria Group, such as improving its services, securing the Website and preventing fraud, insofar as these interests do not override your fundamental rights and freedoms.
Data Retention Periods
Personal data is retained for periods proportionate to the purposes for which it was collected: • Contact form data: three (3) years from the last contact with the data subject. • Client files (residency, company formation, real estate): for the duration of the contractual relationship, then ten (10) years after file closure, in accordance with legal obligations regarding the retention of legal and accounting documents in the Principality of Andorra. • Browsing data and technical logs: thirteen (13) months from the date of collection. • Accounting and tax data: ten (10) years from the close of the relevant financial year, in accordance with Andorran accounting obligations. • Cookie-related data: session duration for session cookies; twelve (12) months for language preference cookies. Upon expiry of these periods, data is securely deleted or irreversibly anonymised.
Data Recipients
Personal data collected may be shared with the following categories of recipients: • Internal teams: Aurea Gestoria Group staff authorised to process your file, strictly within the limits of their duties. • Local partners: accountants, notaries, lawyers, tax advisers and other professionals involved in processing your file in the Principality of Andorra. These partners are bound by confidentiality obligations and, where applicable, non-disclosure agreements (NDAs). • Website hosting provider: Vercel Inc. (United States), for the technical purposes of hosting and delivering the Website. • Database and authentication provider: Supabase Inc. (United States), for the secure storage of client area data and authentication management. • Competent authorities: Andorran administrative, tax or judicial authorities, where required by law. Aurea Gestoria Group does not sell, rent or otherwise transfer your personal data to third parties for commercial prospecting, advertising or marketing purposes.
International Data Transfers
In connection with the hosting of the Website and data storage, some of your personal data may be transferred to the United States, where the servers of our technical service providers are located: • Vercel Inc. (Website hosting) — United States • Supabase Inc. (database and authentication) — United States These transfers are governed by EU Standard Contractual Clauses (SCCs) adopted by the European Commission, in compliance with the requirements of the GDPR and the recommendations of the Andorran Data Protection Agency (Agència Andorrana de Protecció de Dades — APDA). Aurea Gestoria Group ensures that these providers implement appropriate safeguards to maintain an adequate level of protection for your personal data in accordance with applicable regulations.
Your Rights
In accordance with the LQPD and, where applicable, the GDPR, you have the following rights over your personal data: • Right of access (Article 15 GDPR): to obtain confirmation that your data is being processed and to receive a copy thereof. • Right to rectification (Article 16 GDPR): to request the correction of inaccurate or incomplete data. • Right to erasure (Article 17 GDPR): to request the deletion of your data, subject to legal retention obligations. • Right to data portability (Article 20 GDPR): to receive your data in a structured, commonly used and machine-readable format, or to request its transfer to another controller. • Right to restriction of processing (Article 18 GDPR): to request the temporary suspension of processing of your data in the circumstances provided for by law. • Right to object (Article 21 GDPR): to object at any time to the processing of your data based on legitimate interest. • Right to withdraw consent: to withdraw at any time any consent you have given, without affecting the lawfulness of processing carried out prior to withdrawal. To exercise any of these rights, please send your request together with proof of identity to: contact@aurea-andorra.com. We undertake to respond within thirty (30) days. You also have the right to lodge a complaint with the competent supervisory authority: Andorran Data Protection Agency (Agència Andorrana de Protecció de Dades — APDA) C/ Prat de la Creu, 59-65 AD500 Andorra la Vella, Principality of Andorra Website: https://www.apda.ad
Data Security
Aurea Gestoria Group implements appropriate technical and organisational measures to ensure the security, confidentiality and integrity of your personal data and to protect it against unauthorised access, alteration, disclosure or accidental or unlawful destruction. These measures include: • Encryption of communications via TLS/SSL protocol for all exchanges between your browser and the Website. • Strict access controls on client area data, based on Row Level Security (RLS) policies at the Supabase database level. • Secure client area authentication with session and access token management. • Access to personal data restricted to duly authorised staff and service providers bound by confidentiality obligations. • Regular security audits and ongoing assessment of protective measures. In the event of a personal data breach likely to pose a high risk to the rights and freedoms of data subjects, Aurea Gestoria Group undertakes to notify the APDA without undue delay and, where appropriate, to inform the affected individuals in accordance with applicable regulations.
Cookie Policy
The Website uses only strictly necessary technical cookies for its operation. The cookies used are as follows: • Session cookie (client area authentication) — Name: sb-access-token / sb-refresh-token — Purpose: maintaining the authentication session for the secure client area — Duration: session duration (deleted upon browser closure or logout) — Type: strictly necessary technical cookie • Language preference cookie — Name: NEXT_LOCALE — Purpose: recording the user's chosen browsing language — Duration: 12 months — Type: technical preference cookie No advertising, analytics, behavioural profiling or social media cookies are placed on your device. No data collected via these cookies is shared with third parties for commercial purposes. As these cookies are strictly necessary for the provision of the service expressly requested by the user, they are exempt from the requirement for prior consent in accordance with applicable regulations.
Data Relating to Minors
The Website and the services offered by Aurea Gestoria Group are not intended for persons under the age of eighteen (18). We do not knowingly collect personal data from minors. If we become aware that personal data of minors has been inadvertently collected, we will delete such data without undue delay. If you are a parent or legal guardian and believe that your child has provided us with personal data, please contact us at contact@aurea-andorra.com.
Amendments to the Privacy Policy
Aurea Gestoria Group reserves the right to amend, supplement or update this privacy policy at any time, in particular to comply with any legislative, regulatory, judicial or technical developments. The version in force is the one accessible on the Website at the date of consultation. The date of last update is indicated at the top of this page. In the event of a material change, users with a client area account will be notified by electronic notification. Users are advised to review this policy regularly to stay informed of any changes.
Contact — Data Protection
For any questions, information requests or to exercise your rights regarding the protection of your personal data, you may contact us: Aurea Gestoria Group Data Protection Officer (DPO) Registered office: Andorra la Vella, Principality of Andorra Email: contact@aurea-andorra.com Phone: +33 6 82 28 12 23 We undertake to process your request within thirty (30) days of receipt. This period may be extended by a further two (2) months in view of the complexity and number of requests, in which case you will be informed of such extension.