Privacy policy
What data we collect, what we use it for, how long we keep it, and how you can control it. No third-party cookies, no advertising, no profiling.
Last updated: 28 July 2026
This page is a machine translation, pending review by a native-speaking legal reviewer. If in doubt, please refer to the original Spanish version. View the Spanish version
In short: we only process the data you write into the contact form, and we only use it to reply to you. Our analytics are self-hosted, run on our own servers, use no cookies, and cannot identify you. We never sell or share data with anyone for commercial purposes.
1. Data controller
The controller responsible for processing personal data collected through this website is the individual who owns it:
- Controller: Saúl Antonio Díaz Díaz
- Tax ID (NIF): 07271150E
- Address: Montijo, Badajoz (España)
- Email: [email protected]
- Website: https://negocioenlinea.es
NegocioEnLinea.es is the trade name under which the controller operates. Given the volume and nature of the processing described in this policy, appointing a Data Protection Officer is not mandatory; for any privacy-related question, you can contact the controller directly at the email address above.
2. What data we process and why
2.1. Contact form
When you fill in the contact form, we process the data you provide yourself: name, email address, optionally your business name and phone number, and the content of your message. The date and time of submission is recorded alongside it.
The sole purpose is to handle and respond to your enquiry, and to keep up any follow-up communication needed to assess and, where relevant, prepare a work proposal. We do not use this data to send unsolicited marketing, we do not add you to any mailing list, and we do not build profiles.
We ask that you do not include special-category datain your message (health, ideology, trade-union membership, etc.) or third-party personal data that isn't strictly necessary to handle your enquiry.
2.2. Cookie-free web analytics
To understand which content is useful and where visits come from, we use Umami, an open-source analytics tool installed on our own infrastructure. Browsing data is never sent to any advertising platform or third party.
For each visit, we record technical, aggregated information:
- Page visited, date and time, and approximate visit duration.
- Referring page or search engine (referrer) and, if the link includes them, the campaign parameters
utm_source,utm_medium,utm_campaign,utm_contentandutm_term, which tell us what channel you arrived from (a social-media post, for example). - Device type, operating system, browser, screen resolution, language and approximate country.
- Anonymous usage events, such as clicking a call-to-action button or submitting the form. These events never include the content of the form or any data that could identify you — they only indicate that the action happened, and from which channel.
Umami sets no cookies and stores nothing on your device. To distinguish visits without identifying people, it generates a temporary identifier using an irreversible hash function that combines the IP address, the browser, and a random key that rotates daily: the IP address itself is never stored, and the identifier stops being valid after 24 hours. The result is statistical information that, on its own, cannot identify any individual.
2.3. Server technical logs
The infrastructure serving the website generates technical logs (IP address, date and time, resource requested) needed to guarantee its security and availability, and to detect and mitigate abuse or attacks. These logs are kept for a short period and used for no other purpose.
3. Legal basis for processing
- Contact form: your consent (Art. 6(1)(a) GDPR), given expressly by ticking the corresponding box before submitting it, and taking pre-contractual steps at your request (Art. 6(1)(b) GDPR) when your enquiry is aimed at requesting a quote or a service proposal.
- Web analytics and technical logs: the controller's legitimate interest (Art. 6(1)(f) GDPR) in understanding, in aggregate, how the website is used, and in keeping it secure and available. As this processing involves no cookies, no IP storage, no profiling and no sharing with third parties, its impact on your rights and freedoms is minimal.
4. Retention periods
- Form messages: kept for as long as the communication lasts and, afterwards, for a maximum of one year from the last contact, unless the enquiry leads to a service relationship, in which case the applicable legal retention periods apply. If you withdraw your consent, they are deleted sooner.
- Analytics data: kept in aggregate form for a maximum of 24 months, after which it is deleted or kept only as global statistics that cannot be attributed to specific visits.
- Server technical logs: kept for a maximum of 30 days, unless they need to be retained longer for security reasons.
5. Recipients and data processors
We do not share your data with third parties, nor do we sell it. Only the providers strictly necessary to keep the website and email running have access to it, acting as data processors on the controller's behalf:
| Provider | Location | Purpose | Safeguards |
|---|---|---|---|
| Resend, Inc. | United States | Sending and delivering the messages submitted through the contact form. | Data processing agreement in place. International transfers are covered by the Standard Contractual Clauses approved by the European Commission and/or the provider's adherence to the EU-U.S. Data Privacy Framework. |
| Google Ireland Limited / Google LLC | Ireland (EU) and United States | Email service through which the site owner receives and stores messages sent from the form. | Provider adhering to the EU-U.S. Data Privacy Framework for transfers outside the European Economic Area. |
| Cloudflare, Inc. | United States | Content delivery network and secure access tunnel used to publish the website. Processes IP addresses and technical connection metadata for security and availability purposes. | Data processing agreement with Standard Contractual Clauses approved by the European Commission. |
The following, on the other hand, involve no third-party intervention at all:
- Hosting: The website is hosted on the owner's own infrastructure, located in Spain. No external hosting provider is involved.
- Web analytics (Umami): The analytics tool is Umami, open-source software installed and run on the owner's own infrastructure. Browsing data never leaves those servers and is never shared with any advertising platform.
Data may also be disclosed to judges, courts and public authorities where there is a legal obligation to do so.
6. International transfers
Some of the providers listed above are based outside the European Economic Area, in the United States. These transfers take place under the safeguards set out in Chapter V of the GDPR: the adequacy decision covering the EU-U.S. Data Privacy Framework and/or the Standard Contractual Clauses approved by the European Commission, as provided for in the processing agreement signed with each provider.
7. Your rights
You can exercise the following rights at any time:
- Access: find out what data of yours we process.
- Rectification: correct inaccurate or incomplete data.
- Erasure: ask us to delete your data once it is no longer needed.
- Objection: object to processing based on legitimate interest.
- Restriction: request that processing be suspended while a claim is being verified.
- Portability: receive your data in a structured, commonly used format.
- Withdrawal of consent: at any time, without affecting the lawfulness of processing carried out before the withdrawal.
To exercise any of these, simply email [email protected] stating which right you wish to exercise. We may ask you to prove your identity if there are reasonable doubts about who is making the request. We will respond within one month of receiving it at the latest.
No automated decisions are made and no profiling that produces legal effects on you is carried out.
8. Complaints to the supervisory authority
If you believe our processing of your data does not comply with the law, or that we have not properly handled your request to exercise your rights, you can file a complaint with the Spanish Data Protection Agency (AEPD) (C/ Jorge Juan, 6, 28001 Madrid, Spain — www.aepd.es).
9. Cookies
This website does not use analytics, advertising, or third-party cookies, which is why no cookie-consent banner is shown: the obligation to obtain consent (Art. 22.2 of the LSSI-CE) arises when information is stored on or accessed from the user's device — something that does not happen here for analytics purposes.
The only exception is the strictly necessary cookies that the network provider may set for security and proper connection purposes (to distinguish automated traffic, for example). These cookies are exempt from the consent requirement because they are essential to providing the requested service.
No fonts, videos, maps or scripts hosted on third-party servers are loaded either: every resource on the site is served from our own infrastructure. Should this change in the future, this policy will be updated and, where applicable, an appropriate consent mechanism will be added.
10. Security measures
We apply appropriate technical and organisational measures to ensure a level of security matched to the risk, including encrypting communications via HTTPS, restricted and authenticated access to the systems where messages and statistics are stored, and minimising the data requested in the form.
11. Minors
This website's services are aimed at professionals and businesses. We do not knowingly request or process data from minors under 14. If we discover that a minor's data has been provided without the consent of their parent or legal guardian, it will be deleted.
12. Changes to this policy
This policy may be updated to reflect regulatory changes or changes to how the website works. The version in force is always the one published on this page, together with its last-updated date. We recommend reviewing it periodically.
You can also read the website's legal notice.