Legal
Privacy Policy
Last updated: 29 July 2026
01 Who we are
Metrics Advisory SLU is the data controller for the personal data described in this policy.
Carrer de la Llacuna 11
AD500 Andorra la Vella · Principat d'Andorra
NRT: L-722346-A
privacy@metricsadvisory.com
02 What this policy covers
This policy explains how we handle personal data collected through this website and in the course of our commercial relationships.
When we run advertising campaigns for a client, we may process personal data on that client's instructions as a processor. That processing is governed by the data processing agreement signed with the client, not by this policy. Contact the advertiser concerned to exercise your rights over that data.
03 Which law applies to us
We are established in the Principality of Andorra and subject to Andorran data protection law â Llei 29/2021, qualificada de protecció de dades personals â under the supervision of the Andorran Data Protection Agency (APDA).
Most of our clients and campaigns involve the European Union. Whenever we offer services to, or monitor the behaviour of, people located in the EU, we also apply the EU General Data Protection Regulation (GDPR). Where the two frameworks differ, we apply the stricter of the two.
The European Commission has recognised Andorra as providing an adequate level of protection for personal data (Commission Decision 2010/625/EU). Personal data may therefore be transferred from the European Union to us without additional safeguards such as standard contractual clauses.
04 What we collect
Data you give us. Through the contact form: first name, last name, business email address, telephone number, company, website, vertical, budget range and the content of your message.
Data collected automatically. Our hosting provider records IP address, browser type, pages requested and timestamps in server logs, for security and availability purposes.
This site sets no analytics or advertising cookies unless you consent through the cookie banner. See the Cookie Policy.
05 Why we use it, and on what legal basis
- To reply to your enquiry and evaluate a possible commercial relationship — your consent, given when you tick the box on the form.
- To negotiate, conclude and perform a contract with you — performance of a contract.
- To keep the site secure and available — our legitimate interest in protecting our systems.
- To meet accounting, tax and record-keeping obligations — legal obligation.
06 How long we keep it
- Enquiries that do not lead to a relationship: 24 months from the last contact.
- Client and supplier records: for the duration of the relationship and 6 years afterwards, to meet Andorran accounting and tax obligations.
- Server logs: up to 12 months.
After these periods the data is deleted or irreversibly anonymised.
07 Who we share it with
We do not sell personal data. We disclose it only to:
- our hosting, email and CRM providers, acting as processors under written contract;
- professional advisers, auditors and insurers, bound by confidentiality;
- public authorities and courts, where we are legally required to do so.
08 Transfers outside Andorra
Some of our providers are established in the European Union or in third countries. Where data leaves Andorra we rely on an adequacy decision, on standard contractual clauses, or on another safeguard permitted by law. Write to us for a copy of the safeguards in place.
09 Your rights
You may ask us at any time to give you access to your data, correct it, delete it, restrict or object to its processing, or provide it in a portable format. Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of what came before.
Write to privacy@metricsadvisory.com. We answer within one month. We may ask you to confirm your identity first.
10 Complaints
If you believe we have handled your data improperly, you may lodge a complaint with the Andorran Data Protection Agency (APDA), Carrer Doctor Vilanova 15-17, AD500 Andorra la Vella — apda.ad.
If you are located in the European Union, you may also complain to the supervisory authority of your country of residence.
11 Security
We apply technical and organisational measures appropriate to the risk: encrypted transport (HTTPS), access control, and internal access granted on a need-to-know basis. No system is perfectly secure, but we take these obligations seriously and review them periodically.
12 Changes to this policy
We update this page when our practices change and revise the date at the top. Where a change materially affects you, we will say so on the home page.