Privacy Policy

Last updated: 4 January 2026

In the event of any discrepancy, inconsistency or difference in interpretation between this English translation and the original Spanish version, the Spanish version shall prevail.

This Privacy Policy explains how Oh My Lock! (hereinafter, the “Data Controller”) processes the personal data of users and/or customers (hereinafter, the “User”) when they access and use ohmylock.com and its subdomains (hereinafter, the “Website”), as well as when they purchase services, submit enquiries or subscribe to commercial communications.

1. Identity of the Data Controller

  • Company: León Lockers, S.L. (trading as Oh My Lock!)
  • Tax Identification Number (CIF): B75771055
  • Registered office: C/ Mariano Domínguez Berrueta, 11 – Ground Floor – 24003 León, Spain
  • Privacy contact email: info@ohmylock.com

2. Scope

This Privacy Policy applies to personal data collected through the Website, contact forms, booking and purchasing processes, customer service messaging, newsletter subscriptions and, where applicable, the Data Controller’s official social media profiles linked from the Website.


3. Types of Personal Data We Process

Depending on how the User interacts with the Website and our services, we may process the following data:

  • Identification and contact details: first name, surname, email address and telephone number.
  • Transaction data: product or service purchased, amount, currency, payment method and payment status. Full payment card details are processed, where applicable, by the payment service provider.
  • Booking and service usage data: date and time, location or facility, locker or module number, incidents and support requests.
  • Website browsing and usage data: IP addresses, online identifiers, cookies or similar technologies — see our Cookie Policy — pages visited, time spent on the Website and recorded events.
  • Commercial preferences: subscription to communications and categories of interest.
  • Support and customer service data: messages and any attachments voluntarily submitted by the User.

We do not intentionally request special categories of personal data within the meaning of Article 9 of the GDPR. Please do not send sensitive information unless it is strictly necessary to handle your request and is submitted through an appropriate channel.


4. Purposes of Processing and Legal Bases

PurposeLegal basis
Managing enquiries submitted through forms or contact channels.The Data Controller’s legitimate interest in responding to requests under Article 6(1)(f) GDPR and/or taking pre-contractual measures under Article 6(1)(b) GDPR.
Processing bookings or purchases and providing the services, including smart lockers and associated support.Performance of a contract or pre-contractual measures under Article 6(1)(b) GDPR.
Invoicing, accounting and compliance with legal obligations, including tax and consumer-protection requirements.Compliance with legal obligations under Article 6(1)(c) GDPR.
Sending electronic commercial communications about similar products or services where there is a previous relationship or consent has been given.Legitimate interest under Article 21.2 of the LSSI and/or consent under Article 6(1)(a) GDPR.
Improving the Website, maintaining security, preventing fraud and carrying out basic aggregated analytics.Legitimate interest under Article 6(1)(f) GDPR.
Managing incidents and providing after-sales support.Performance of a contract under Article 6(1)(b) GDPR and legitimate interest under Article 6(1)(f) GDPR.

Where processing is based on consent, the User may withdraw their consent at any time without affecting the lawfulness of processing carried out before its withdrawal. Consent may be withdrawn using the mechanisms provided in each communication or by contacting the Data Controller.


5. Data Retention

Personal data will be processed for as long as necessary to fulfil the purposes described above. It will then be retained in a restricted form for the legally established periods required to address potential liabilities:

  • Contractual relationship and services: for the duration of the relationship and for up to six years in relation to commercial books and documentation, and four years in relation to tax obligations, calculated from the most recent transaction.
  • Enquiries: for up to 12 months from the most recent interaction.
  • Commercial communications: until the User unsubscribes or objects to the processing. Consent records will be retained for as long as necessary to demonstrate compliance.
  • Website analytics and cookies: for the periods described in the Cookie Policy.

6. Recipients and Data Processors

In addition to the Data Controller, personal data may be accessed by service providers acting as data processors. Data processing agreements are entered into with these providers in accordance with Article 28 of the GDPR.

These providers may include, without limitation:

  • Website hosting and maintenance providers, including hosting and technical support services.
  • Booking platforms or property management systems, where applicable.
  • Payment platforms, such as Stripe Payments Europe, Ltd. or any other providers used by the Data Controller. Full payment card details are processed directly by these platforms and not by the Data Controller.
  • Communication and email-marketing tools, including transactional email and newsletter services.
  • Website analytics providers, using appropriate privacy settings.
  • Customer support providers, including ticketing or chat systems, where applicable.

Personal data may also be disclosed where required by law, including to public authorities, courts, law enforcement agencies or other competent bodies, or where necessary for the performance of a contract, including disclosures to insurers, banks or fraud-prevention providers. No other disclosures of personal data are expected.


7. International Data Transfers

Where service providers located outside the European Economic Area are used, the Data Controller will implement appropriate safeguards, such as an adequacy decision issued by the European Commission, Standard Contractual Clauses or other legally recognised mechanisms.

Additional information about these safeguards may be requested by contacting the Data Controller through the privacy email address.


8. Individual Rights

The User may exercise the following rights under the GDPR and the Spanish Organic Law on Personal Data Protection and the Guarantee of Digital Rights:

  • Access: the right to know which personal data we process.
  • Rectification: the right to request the correction of inaccurate or incomplete data.
  • Erasure: the right to request the deletion of personal data where legally applicable.
  • Objection: the right to object to certain processing activities, including direct marketing.
  • Restriction: the right to request the restriction of processing in certain circumstances.
  • Data portability: the right to receive personal data in a structured format and/or have it transmitted to another data controller where technically possible.
  • Withdrawal of consent: the right to withdraw consent at any time where consent is the legal basis for processing.

How to exercise your rights: send a written request to info@ohmylock.com or to the Data Controller’s registered address, specifying the right you wish to exercise. Where necessary, you may be asked to provide a copy of an identity document. Where you are acting on behalf of another person, you must also provide proof of representation.

Supervisory authority: should you have any concerns or disagreements regarding the processing of your data, you may lodge a complaint with the Spanish Data Protection Agency — Agencia Española de Protección de Datos, AEPD — at www.aepd.es.


9. Information Security

The Data Controller applies appropriate technical and organisational measures to protect personal data, taking into account the state of the art, the nature of the data and the associated risks. These measures include access controls, encryption in transit using HTTPS/TLS, password policies, backups and incident-recording procedures. Nevertheless, no system can be guaranteed to be completely secure. Users should also take reasonable measures to protect their personal information and devices.


10. Minors

The Website and its services are not intended for children under the age of 14. Where the processing of a minor’s personal data without valid authorisation is detected, the Data Controller will take reasonable and prompt steps to delete the data.


11. Social Media

The Data Controller may maintain official profiles on social media platforms. The processing of followers’ personal data is governed by this Privacy Policy and by the terms and privacy policies of each platform. Personal data will not be extracted from social media without informed consent.


12. Automated Decision-Making

We do not carry out automated decision-making that produces legal or similarly significant effects for the User. We do not conduct profiling beyond the basic segmentation of communications according to the User’s relationship with us and stated preferences, based on legitimate interest or consent.


13. Cookies

The use of cookies and similar technologies is explained in our Cookie Policy, where Users can configure and manage their consent preferences.


14. Changes to the Privacy Policy

The Data Controller may amend this Privacy Policy to reflect legislative developments or changes in its data-processing activities. Any amendments will be published on this page together with the relevant update date. Users are advised to review this Privacy Policy periodically.


15. Contact

For any questions regarding privacy or the processing of personal data, please contact us at info@ohmylock.com or write to the Data Controller at its registered address.