Privacy policy
What data this site processes, what for, on what legal basis and for how long.
Draft of 29 July 2026. Effective date: <pedir al cliente>.
Draft document. The controller’s details and the retention periods, marked as <pedir al cliente>, are pending, along with a legal review before publication.
1. Data controller
| Controller | <pedir al cliente> |
|---|---|
| Tax ID | <pedir al cliente> |
| Registered address | <pedir al cliente> |
| Privacy email | <pedir al cliente> |
| Data protection officer | <pedir al cliente> |
2. Summary of processing
| Processing | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Contact form | Name, email, phone (optional), subject and message | Answering the enquiry | Consent, Art. 6(1)(a) | <pedir al cliente> |
| DMCA form | Name, content address, email, phone, subject and message | Processing the notice and keeping a record | Legal obligation, Art. 6(1)(c) | <pedir al cliente> |
| Server logs | IP address, date and time, requested resource, browser and operating system | Security, error diagnosis and abuse prevention | Legitimate interest, Art. 6(1)(f) | <pedir al cliente> |
| Dynamic code scans | Scan count, date and time, approximate country deduced from the IP, operating system and device type | Giving statistics to the code’s creator and detecting automated traffic | Legitimate interest, Art. 6(1)(f) | <pedir al cliente> |
| Payments | Email and payment data processed by Stripe; the site never receives the card number | Charging the one-time payment and delivering the purchase | Performance of a contract, Art. 6(1)(b) | <pedir al cliente> |
3. Form data
The contact and DMCA forms ask only for what is needed to reply or to process the notice. The phone is optional on the contact form and required on the DMCA form, because the notice procedure requires a direct means of contact.
That data is not used for advertising or newsletters, is not shared with third parties for commercial purposes, and is not cross-referenced with any other information.
4. Static codes: what is not stored
Static codes are generated in your browser. The text, the web address, the Wi-Fi password or the contact card details you type into the editor are not sent to any server of this site and are not stored. They disappear when you close the tab.
5. Dynamic codes: scan data
This section applies only to dynamic codes, which work through a redirect hosted on a server. The plain-language explanation of what gets recorded when a dynamic QR code is scanned is in the FAQ, and the QR code types page shows which ones are dynamic and which never touch a server. Each time someone scans one of these codes, the redirect can record:
- The scan count, total and by date and time, to know how many times the code has been used and when.
- The approximate country, deduced from the IP address. The country is kept, not the exact address or the specific city.
- The operating system of the device, deduced from the user agent string the browser sends.
- The device type: phone, tablet or computer.
What it is used for. So that whoever created the code can see whether their campaign works, and to detect automated traffic or abuse of the redirect. Nothing else.
What is not done. The person scanning is not identified. No advertising profile is built from that data, it is not sold, not shared with advertisers, and not cross-referenced with the person’s activity on other sites. The redirect installs no cookies or identifiers on the scanner’s device, so the count requires no on-device consent under Article 22.2 of the Spanish Law 34/2002.
The IP address. It is personal data even without a name attached. It is used at the moment of the scan to deduce the country and to prevent abuse. The full IP is kept for <pedir al cliente>; after that period only the per-country aggregate is kept.
How long it is kept. Scan detail is kept for <pedir al cliente>. Aggregate figures are kept while the dynamic code stays active, and are deleted when the code is deleted.
Legitimate interest balancing. The processing rests on the code creator’s interest in measuring their own campaign. It is limited to technical and aggregate data, cannot identify anyone, and has no effect on the person scanning. You can request the full assessment by writing to <pedir al cliente>.
6. Server logs
Like any web server, the one serving these pages keeps technical logs of requests: IP address, date and time, requested resource, response code and user agent. They are used to keep the service running, resolve incidents and detect attacks. They are not used for profiling. Retention period: <pedir al cliente>.
7. Payments
The one-time payment is processed by Stripe, an external payment provider. Your card number is entered in an environment controlled by Stripe: this site never receives it and never stores it. What the site keeps is the record needed to deliver the purchase and meet invoicing and accounting obligations.
Stripe processes payment data under its own terms and privacy policy, including the fraud prevention checks that payment regulation requires. Retention of purchase records: <pedir al cliente>, subject to the periods that tax law imposes.
8. Recipients and processors
- Site hosting provider: <pedir al cliente>.
- Email provider: <pedir al cliente>.
- Stripe, as payment provider, under its own terms and policies.
- Public administrations, courts and law enforcement where there is a legal obligation to provide the information.
There are no other disclosures. In particular, no data is sold and none is shared with data brokers.
9. International transfers
Payment processing means that Stripe, headquartered in the United States, may access personal data. Those transfers rely on the adequacy decision applicable to that country or, failing that, on standard contractual clauses approved by the European Commission. The location of the hosting and email servers is <pedir al cliente>.
10. Your rights
You can exercise the rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw any consent you have given, without affecting the lawfulness of prior processing.
To exercise them, write to <pedir al cliente> stating which right you want to exercise. Reasonable proof of identity may be requested. A reply will be given within one month at most, extendable under Article 12 of the GDPR.
If you believe your request was not handled correctly, you can complain to the Spanish Data Protection Agency (AEPD), calle Jorge Juan 6, 28001 Madrid, online office at sedeagpd.gob.es.
11. Security
The site is served over HTTPS. Reasonable technical and organisational measures protect the data, with access limited to the people who need it. No system is infallible: if a breach posing a risk to your rights occurred, it would be notified under Articles 33 and 34 of the GDPR.
12. Minors
The service is not specifically aimed at minors. Under Article 7 of the Spanish Organic Law 3/2018, consent for processing the data of children under fourteen requires the authorisation of the holder of parental authority or guardianship.
13. Changes to this policy
This policy may be updated if the processing, the providers or the regulations change. The current version is always the one published on this page, dated at the top.