1.Data controller
The data controller is Online Apps S.L., Spanish tax ID B02749505, registered office at Carrer de Marbella 17, local 48, 07610 Palma de Mallorca (Illes Balears), España, email [email protected].
You may write to that address about any matter relating to the processing of your personal data.
This English text is provided for convenience. In the event of any discrepancy, the Spanish version published on this same website prevails.
2.What data we process and where it comes from
- Data provided in the contact form: full name, email address and, optionally, company and phone number, together with the content of your message, the service you are interested in and an indicative budget.
- Technical connection data: IP address, browser type and language, needed to provide the service, protect it against abuse and prevent automated mass submissions through the form.
- Professional contact details of clients and suppliers: those needed to manage the contractual relationship, invoicing and tax obligations.
We do not collect special categories of data (health, beliefs, membership, etc.) and we do not process children's data through this site.
3.Purposes and legal basis
- Answering enquiries sent through the form or by email: the data subject's consent (art. 6(1)(a) GDPR) and pre-contractual steps taken at the data subject's request (art. 6(1)(b)).
- Managing the contractual relationship with clients and suppliers, including invoicing: performance of a contract and compliance with legal obligations (art. 6(1)(b) and 6(1)(c)).
- Keeping the site secure and preventing abuse of the form: the controller's legitimate interest (art. 6(1)(f)).
- Sending commercial communications about our own services to existing clients or to those who requested information: legitimate interest or consent, with the right to object at any time.
We do not make automated decisions producing legal effects on individuals, and we do not build profiles from the data submitted through the form.
4.Data processed on behalf of our clients
When we manage a client's advertising campaigns, website, social profiles or measurement systems, we may access personal data of that client's users. In those cases we act as a processor, not as a controller: we process the data solely on the client's documented instructions and under the processing agreement required by article 28 GDPR.
Access to a client's advertising, analytics or social media accounts is always granted by the client over accounts they own, and is revoked when the relationship ends.
5.Retention periods
- Contact form enquiries: while the request is being handled and, afterwards, for up to one year, unless the enquiry leads to a contractual relationship.
- Client and invoicing data: for the duration of the relationship and the applicable statutory limitation periods (generally six years for commercial matters and four for tax matters in Spain).
- Technical security data: only as long as necessary for the security purpose, as a rule no more than twelve months.
6.Recipients and processors
We do not disclose personal data to third parties except where legally required. We do use service providers acting as processors under a signed agreement:
- Hosting and infrastructure provider for the website, with servers located in the European Union.
- Cloudflare, Inc., for content delivery network, security and email sending services, covered by the standard contractual clauses approved by the European Commission.
- Accounting and professional service providers, to comply with accounting and tax obligations.
Where a provider involves an international data transfer, it is carried out with the appropriate safeguards set out in Chapter V of the GDPR (adequacy decision or standard contractual clauses).
7.Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to [email protected], stating the right you wish to exercise and enclosing a copy of a document proving your identity.
Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out beforehand. If you believe your request has not been properly handled, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
8.Information security
We apply appropriate technical and organisational measures to protect personal data against destruction, loss, alteration or unauthorised access: encryption in transit via TLS, role-based access control, regular backups and periodic review of the permissions granted to providers.
9.Changes to this policy
We may update this policy to reflect legal changes or new processing activities. The version in force is always the one published on this page, showing its last update date.
Questions about this document? Write to [email protected].