saulacuna.dev
Privacy policy
Last updated:
This policy describes how the controller processes the personal data that the user
provides when using this site and its subdomains (saulacuna.dev,
me.saulacuna.dev, blog.saulacuna.dev).
1. Controller
Saúl Acuña Godoy, together with the professional-services cooperative that acts as the billing entity for selected external collaborations. The cooperative's full identification details are provided to the client at the proposal or invoice stage.
Contact: [email protected] (data-protection officer / preferred channel for rights requests) or [email protected].
2. Data we collect and from where
Contact form on saulacuna.dev
When the user starts a conversation from the messaging bubble, we collect:
- Name (required): identifies the conversation partner.
- Email (required): reply channel.
- Message (required): the body of the inquiry.
- Service of interest (optional, auto-filled when initiated from a service card).
- IP address and submission timestamp: stored as technical data for abuse prevention and as origin evidence in case of incident.
We do not store additional device data, geolocation or persistent identifiers. The form includes anti-abuse measures that are transparent to the user and operate without persistent browser cookies.
General browsing
Site analytics are handled by a cookieless, aggregated service provided by the CDN provider, which does not identify individual users and does not perform fingerprinting. We do not use behavioural analytics nor advertising profiling services.
3. Purposes and legal basis
| Purpose | Legal basis |
|---|---|
| Reply to the user's message and maintain the precontractual conversation. | GDPR Art. 6.1.b (precontractual measures). |
| Send an acknowledgement email confirming receipt of the message and outlining the next steps of the conversation. | GDPR Art. 6.1.b (precontractual measures). |
| Performance of the engagement once a service is formalised. | GDPR Art. 6.1.b (contract performance). |
| Comply with legal obligations (invoicing, accounting, tax). | GDPR Art. 6.1.c (legal obligation). |
| Send communications about blog posts, service updates and promotions only if you have given explicit consent by subscribing (double opt-in). | GDPR Art. 6.1.a (consent, revocable at any time). |
| Site security and fraud prevention (anti-bot service). | GDPR Art. 6.1.f (legitimate interest). |
If you decide to subscribe to the newsletter, you'll do so explicitly from a public form on the blog. We never add you without your consent. After subscribing, you'll receive a verification email with a single-use link to confirm it (double opt-in). Until you confirm that link, no further communication will be sent.
It's important to distinguish between two different actions:
- Unsubscribe from the newsletter: you stop receiving communications. Your address is kept on a suppression list to prevent accidentally re-adding it in future imports. This is not a data deletion.
- Request full erasure (right to be forgotten, GDPR Art. 17): your data is deleted from all systems (contact messages and, if applicable, subscriptions). See section 6.
Except for the case above, we do not process data for profiling, nor share it with third parties for advertising. There are no automated decisions with legal effects on the user.
4. Retention
- Contact messages: 730 days (~2 years) from last activity. A scheduled job purges them automatically when they expire. The data subject can request erasure before that window at any time (section 6).
- Newsletter subscribers: the address is kept while the subscription is active. After a voluntary unsubscribe, the address remains on a suppression list to prevent it from being re-added by mistake. If you want it fully removed, exercise the right of erasure (section 6).
- Billing data of contracted services: kept for the minimum period required by tax and commercial regulations (at least 6 years from the closing of the accounting period).
- Technical communications and operational logs: maximum rotation 90 days.
5. Recipients and processors
Contact-form data is processed in the following environments:
- Owner's internal systems, hosted by a cloud provider with EEA location. The submission is kept in internal storage for history and later review by the owner.
- External messaging provider headquartered outside the EEA, used by the owner as a real-time notification channel for incoming messages. The international transfer relies on Standard Contractual Clauses (SCC).
- Transactional email provider headquartered in the United States, handling the acknowledgement email, subscription verification emails and rights-management emails (erasure, access). The actual delivery happens from infrastructure located in the European Union (Ireland). The processor relationship relies on Standard Contractual Clauses (SCC) and, where applicable, the EU-US Data Privacy Framework.
- Web infrastructure providers (CDN, static hosting and anti-abuse services), adhering to the EU-US Data Privacy Framework and/or with Standard Contractual Clauses (SCC) in force for international transfers.
The owner can provide individual identification of each processor on request, through the contact channel listed in section 1. We do not perform deliberate international transfers beyond those technically required by the providers used.
6. User rights
Under GDPR and LOPDGDD, the user has the right to:
- Access: know what personal data we hold about you.
- Rectification: correct inaccurate data.
- Erasure ("right to be forgotten"): delete data when no longer needed.
- Restriction of processing.
- Portability: receive your data in a structured, reusable format.
- Objection: object to processing for reasons related to your situation.
There are two equivalent ways to exercise these rights, your choice:
- Manual: email [email protected] with your name, the email address you used to contact us, and the right you're exercising.
- Self-service: when publicly available, you'll be able to initiate an erasure request from a dedicated web page. You'll receive a verification link in your inbox; once confirmed, the data associated with your email is deleted automatically.
In both cases, we respond within the legal one-month window from the verification of your identity.
If you believe the processing infringes your rights, you can lodge a complaint with the Spanish Data Protection Authority (www.aepd.es).
7. Security
We apply appropriate technical and organisational measures to safeguard data: in-transit encryption, authenticated access control for administrative panels, credential rotation, environment separation, and rate limiting to prevent abuse of the contact form.
8. Minors
This site is not directed at minors under 14. We do not deliberately request or process minors' data.
9. Changes and new processors
This policy is reviewed periodically. When we incorporate new processors, partners or external providers with access to your data, this policy will be updated accordingly. The "last updated" date always appears at the top of the document, so any change is visible.
If changes materially affect processing (new purpose, new legal basis, additional international transfer), they will be announced with sufficient advance notice on the site itself and, where legally required, by direct communication to subscribed data subjects.
For information on cookies and similar technologies, see the Cookie policy. For provider identification, see the Legal notice.