Skip to content
Darvano

GDPR

Privacy policy

Last updated: 26 September 2026

This translation is provided for convenience. The Spanish version is the legally binding one and prevails in case of any discrepancy. Read the Spanish version

We explain clearly what personal data we process when you visit the shop, buy or write to us, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

1. Data controller

  • Controller: Darvano
  • Privacy contact: info@darvano.es (subject “Data protection”)

We haven't appointed a data protection officer because it isn't required for our activity.

2. What data we process, why and on what legal basis

PurposeDataLegal basisRetention
Managing your orders and pre-orders: payment, shipping, invoicing, status emailsName, email, phone, address, products, amount, payment method (never the card number)Performance of the contract (art. 6.1.b GDPR) and legal tax and accounting obligations (art. 6.1.c)For the duration of the relationship and then for the legal periods: 6 years (Commercial Code) and 4 years (tax law)
Your customer account: order history and favouritesName, email, password (stored encrypted, never in plain text), favouritesPerformance of the account contract (art. 6.1.b)Until you ask us to delete it. If you don't confirm your email, the account is deleted after 24 hours
Handling withdrawals, returns and the warrantyOrder details, reason, communicationsLegal obligation (art. 6.1.c; Spanish consumer protection law)During the legal warranty (3 years) and the periods for claims
Answering your enquiries (“Write to us” form, email, WhatsApp)Name, email, phone (optional), order number, messageYour request and our legitimate interest in helping you (art. 6.1.b and 6.1.f)Until the enquiry is resolved and 1 more year
Measuring use of the shop with our own statisticsPages viewed, checkout steps, the website or campaign you came from, approximate country and city (worked out from your IP by our server, which doesn't store it), device type, browser and language. To avoid counting you twice on the same day, a code that changes daily and can't be reversed is used. No cookiesLegitimate interest in knowing how the shop is used (art. 6.1.f)13 months; the daily code can no longer be calculated the next day
Knowing which ads, networks or collaborations bring us salesOn your order: where the visit came from (ad, social network, campaign or website) and, if you answer, how you heard about usLegitimate interest in measuring our advertising (art. 6.1.f). Answering is optionalSame as the order
Sending you the newsletter (news and offers) and your welcome codeEmail, language, date and source of sign-up and proof of your consent (double opt-in)Your express consent (art. 6.1.a GDPR and art. 21 LSSI-CE). You can unsubscribe with one click in every emailUntil you unsubscribe. Unconfirmed sign-ups are deleted after 30 days
Letting you know once when a sold-out watch is back or opens for pre-order (“Notify me”)Email, language and the watch you're waiting forYour request and consent (art. 6.1.a)Until we send the alert and 1 more year; at most 2 years if the watch doesn't come back
Asking you, once per order and some days after delivery, what you thoughtScore, comment and, only if you allow it, your first name to publish the reviewLegitimate interest in improving the service (art. 6.1.f). You can object with one click in the email itselfSame as the order
Analytics, ad measurement and personalised advertising with third-party cookiesCookie identifiers, pages and watches viewed, purchases (amount, without your contact details), the ad you came from, device, approximate locationYour consent (art. 6.1.a), which you can withdraw at any timeAccording to the cookie policy
Proving your cookie choiceRandom browser identifier, chosen option and date (no IP)Legal obligation to prove consent (arts. 6.1.c and 7.1)Up to 3 years
Shop security and fraud preventionTechnical access and sign-in logsLegitimate interest (art. 6.1.f)As long as strictly necessary, 1 year at most

Data marked as required in forms is needed to process what you ask for; without it we can't do so. We don't send advertising by email without your prior express consent (art. 21 LSSI-CE). We don't make automated decisions or profile you with legal effects.

3. Who we share your data with

We don't sell your data. We only share it with providers who process it on our behalf, under contract and with GDPR safeguards, or when the law requires it:

  • Web hosting and database: Vercel Inc. and Neon Inc.
  • Payments: Stripe Payments Europe Ltd., PayPal (Europe) S.à r.l. et Cie, S.C.A. and Redsys/your bank for Bizum and card. You enter your payment details on their secure page; they also act as independent controllers to prevent fraud and comply with payment regulations.
  • Sending order and newsletter emails: Resend (Plus Five Five, Inc.).
  • Couriers: name, address and phone to deliver your order.
  • Google sign-in, if you choose it: Google Ireland Ltd.
  • Analytics, only with your consent: Google Tag Manager (Google Ireland Ltd.) and Google Analytics (Google Ireland Ltd.).
  • Public authorities, judges and courts when there's a legal obligation (for example, the Spanish Tax Agency).

4. International transfers

Some of these providers are based or have servers in the United States. Transfers are covered by the adequacy decision on the EU-US Data Privacy Framework (10 July 2023) for participating companies and, failing that, by the standard contractual clauses approved by the European Commission.

5. Your rights

You can ask at any time for access to your data, its rectification or erasure, the restriction of processing, to object to it, the portability of the data you gave us and to withdraw your consent without affecting prior processing. Write to us at info@darvano.es stating which right you're exercising; if needed we'll ask you to prove your identity. We reply within one month at most.

If you think we haven't handled your request properly, you can complain to the Spanish Data Protection Agency (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid) or to the authority of your country.

6. Minors

The shop isn't aimed at children under 14 and you must be an adult to buy. If we detect data of a child under 14 provided without their parents' or guardians' permission, we'll delete it.

7. Security

The website always uses an encrypted connection (HTTPS). Passwords are stored encrypted with an irreversible algorithm, access to the admin panel is restricted and card details never pass through our servers.

8. Cookies

What the shop stores in your browser and how to choose is explained in the cookie policy.

9. Changes to this policy

If we change how we process your data, we'll update this page and show the date of the last update. If the change is significant, we'll let you know.