Privacy policy

This site uses no cookies, asks you for nothing through a form and does not follow you around the internet. Even so, something is processed, and you have a right to know exactly what.

Last updated:

This is a translation provided for convenience. The legally binding version is the Spanish one: read it here.

Who is responsible for your data

Controller
Alejandro Lledó López
Tax ID (NIF)
71191981N
Address
Calle Los Dados 6, 47009 Valladolid, Spain
Email
alexlledo@me.com
Website
alexlledo.com

There is no data protection officer, because the activity does not meet any of the conditions that require one to be appointed (article 37 GDPR and article 34 LOPDGDD). For anything to do with privacy, write to the address above: I answer myself.

What data I process and where it comes from

What you send me by email. The contact link on this site opens your email program. There is no form and no intermediary: the message travels from your mailbox to mine. What I then process is your name, your email address and whatever you have chosen to tell me —usually what your project is about—. You choose the data; it's worth not including more than you need to.

The server's technical logs. Like any web server, the one hosting this site records every request it receives: date and time, page requested, the address you arrived from, browser and operating system type, and IP address. The IP is anonymised before being stored, so it can tell which country or province someone visited from, but not who they are.

From those logs I produce aggregate visit statistics. They are calculated on my own server, without sending anything to third parties and without placing any file on your device.

And that's it. There are no user accounts, no newsletter, no comments, no chat, no social media pixels, no advertising, no profiling and no automated decisions affecting you.

Cookies: there aren't any

This site installs no cookies of its own or of third parties, and does not use the browser's local storage to track you. That's why you won't see a banner asking for permission: article 22.2 LSSI-CE requires consent to store information on your device, and nothing is stored here.

Visit measurement is done by reading the logs the server generates on its own, which is a different technique and does not require your consent. If that ever changed, the first thing you would see would be a notice asking for it, with declining as easy to reach as accepting.

What I use it for and on what legal basis

To reply to you and prepare a quote. The legal basis is pre-contractual measures taken at your request (article 6.1.b GDPR). You write to me so that we can do something together; processing your message is how I answer you.

To keep the site working and secure, and to know how many people visit. The legal basis is my legitimate interest (article 6.1.f GDPR) in keeping the service standing, detecting abuse and understanding in aggregate which content is of interest. I have weighed that interest against your rights: the data is minimal, the IP is anonymised, it is not cross-referenced with any other source and no profile is built. The impact on your privacy is close to nil.

To meet my tax obligations, if we end up working together. The legal basis is compliance with legal obligations (article 6.1.c GDPR): invoices, record books and the rest of the paperwork that tax and accounting rules impose on me.

How long I keep it

Emails:for as long as the conversation lasts and, if we don't end up working together, for up to a year afterwards, in case you get back in touch. You can ask me to delete the thread sooner and I will.

Data from work already carried out: for the statutory limitation periods, which reach four years for tax matters and five for the personal actions under article 1964 of the Spanish Civil Code. Once those periods have passed, it is deleted.

Server logs: thirty days at most. Beyond that, only aggregate figures survive —visits by page, by country, by month— which cannot identify anyone and are therefore no longer personal data.

Who else has access

I do not sell, rent or share data with anyone for commercial purposes. The only third parties who can access it are the providers I need for this to work, each with a data processing agreement signed in accordance with article 28 GDPR:

IONOS Cloud S.L.U.
Hosting of the website and of the server logs. Location: European Union.
Apple Distribution International Ltd.
Email service (iCloud) where messages are received. Location: Ireland, with possible access from the United States.

Your data could also be disclosed to courts, tribunals or public authorities where a rule obliges me to do so.

Transfers outside Europe

The site and its logs are hosted on servers located in the European Union. Email is received in an iCloud mailbox: the provider is established in Ireland, although access from the United States cannot be ruled out, covered in that case by the adequacy decision for the EU–US Data Privacy Framework or by standard contractual clauses approved by the European Commission.

If what you want to discuss with me is particularly sensitive, say so and we'll find another channel.

What you can require of me

The GDPR gives you a list of rights you can exercise at any time and which cost me nothing to honour:

  • Access: to know what data of yours I hold and what I do with it.
  • Rectification: to correct anything inaccurate.
  • Erasure: to have it deleted once it is no longer needed.
  • Objection: to ask me to stop processing it where I rely on legitimate interest.
  • Restriction: to freeze processing while a disagreement is resolved.
  • Portability: to receive your data in a format you can take with you.

To exercise them, write to me at alexlledo@me.com saying which right you want to exercise. I will only ask you to prove your identity if I have reasonable doubts about who you are. I will reply within one month.

If you think I haven't done things properly, you can complain to the Spanish Data Protection Agency, which is the competent supervisory authority: C/ Jorge Juan 6, 28001 Madrid, or through its electronic office. I'd be grateful if you told me first, but it's your right and you don't have to go through me.

Security

The site is served encrypted over HTTPS and I apply the technical and organisational measures that are reasonable for the volume and nature of what I process: restricted access, strong passwords with two-factor authentication, backups and system updates. No system is invulnerable, but these are the measures that can be expected of an operation this size.

Minors

This site is not aimed at children under fourteen and does not knowingly collect their data. If you are the parent or guardian of a child who has written to me, let me know and I will delete the message.

Changes to this policy

If I change the way I process data, I will update this text and the date shown at the top. It's worth a look if you come back after a long time. The general terms for using the site are in the legal notice.