Almería is open. North Somerset and London open at the end of 2026. See locations

post Hola Post

Privacy policy

Last updated 1 October 2026

This policy explains what personal data Hola Post collects, why, and what rights you have. It covers our website and our address, mail scanning and notification services in the UK and Spain.

Who we are

The data controller is Hola Money Sociedad Limitada (NIF B26671347), with its registered office at C/ Granada 7, 04820 Vélez-Rubio, Almería, Spain. You can contact us at [email protected].

When a gestoría, accountant or other partner firm signs up its clients, we act as that firm’s data processor for the client data it shares with us, under a data processing agreement.

What we collect

  • Account details: your name, email, phone number, company details and billing information.
  • Identity verification: identity documents and proof of address, which anti-money-laundering law requires us to check before providing an address.
  • Your post: details of each item we receive, and scans of envelopes and contents where you ask us to open them.
  • Spanish notifications: the notices we collect on your behalf, including their content and deadlines.
  • Website data: the information you enter in our forms, and technical data such as your IP address, kept in server logs for security.

Why we use it

  • To provide the service you signed up for (performance of a contract).
  • To verify identity and keep records required by anti-money-laundering law (legal obligation).
  • To reply to enquiries and keep our service secure (legitimate interests).
  • To send you news about our service, only if you have agreed to it (consent). You can unsubscribe at any time.

Who we share it with

We share data only with providers that help us run the service, such as hosting, identity verification, payment and email providers, under contracts that protect your data. We share your post or notifications with people you authorise, such as your accountant or gestor. We may disclose data where the law requires it.

Where your data is stored

Scans and notifications are encrypted and stored in the European Union. Where a provider processes data outside the UK or EU, we use appropriate safeguards such as standard contractual clauses.

How long we keep it

We keep scans and notifications while your account is active and for a short period after it closes so you can download them. Paper post is kept securely for 30 days after scanning, then shredded, unless you ask us to keep or forward it. We keep identity verification records for as long as anti-money-laundering law requires: five years in the UK and ten years in Spain after the end of our relationship.

Cookies

Our website uses only the cookies needed for it to work: a session cookie, a security token for forms and, if you pick a language, a cookie that remembers it. We don’t use advertising or tracking cookies. If that changes, we will ask for your consent first.

Your rights

You can ask to access, correct or delete your data, to restrict or object to how we use it, and to receive a copy in a portable format. Some data, such as identity records, we must keep by law. To use your rights, email [email protected].

If you’re unhappy with how we handle your data, you can complain to the Information Commissioner’s Office (ico.org.uk) in the UK or the Agencia Española de Protección de Datos (aepd.es) in Spain.