Skip to content
Díaz Oliva

Privacy policy

What data is collected, what for, how long it is kept and what rights you have.

Last updated: August 30, 2026

This policy explains how the personal data collected through diazoliva.com is processed, in accordance with Regulation (EU) 2016/679 (GDPR) and Ley Orgánica 3/2018 (LOPDGDD, the Spanish data protection and digital rights act).

1. Data controller

  • Controller: Díaz Oliva
  • Registered address: Calle Alzina 52, 28044 Madrid, Madrid, España
  • Email: contacto@diazoliva.com

The owner's full name and tax ID are set out in the legal notice, reachable from the footer of every page on this site.

No data protection officer has been appointed, as none of the circumstances set out in article 37 of the GDPR apply.

2. What data is processed and for what purpose

2.1 Building and saving your website

  • Data: email address and the content you write into your own website (business name, town, text and any contact details you choose to publish on it, such as a phone number or an address).
  • Purpose: to save your website, create the associated project and give you access to keep editing it and to publish it.
  • Legal basis: pre-contractual measures taken at the request of the data subject and performance of the contract (art. 6.1.b GDPR).
  • Consequence of not providing it: without an email address, your website cannot be saved and you cannot be given access to it.

While you are editing, the draft lives in your browser. It is sent to the server to render the preview, which returns the page and does not store it: nothing is stored in your name until you ask for the sign-in link. If you close the tab without asking for it, the draft stays on your own device only.

When you ask for the link, your site travels with it. It is stored against your email address so that you can open the link wherever you like, including on another device, and find your site intact. It is kept for one hour at most, which is how long the link lasts, and it is deleted as soon as it is saved to your account or as soon as it expires.

2.2 Contact form and enquiries by email

  • Data: name, email address, telephone number (optional) and whatever you include in your message.
  • Purpose: to deal with your enquiry.
  • Legal basis: legitimate interest in replying to those who contact us (art. 6.1.f GDPR), or pre-contractual measures if your enquiry is aimed at entering into a contract.
  • Retention period: 24 months from the moment you send it, whether or not you have had a reply.

Your enquiry is stored so it can be dealt with, not merely forwarded: it is kept in our systems so we can reply to you, find it if you write again and know whether it has already been answered. When you send it you get an email with a copy of what you wrote, which is your record of having sent it. You can ask us to delete it before the period is up by replying to that same email.

2.3 Client management and invoicing

  • Data: identification, tax and billing details.
  • Purpose: provision of the contracted service, issuing invoices and complying with accounting and tax obligations.
  • Legal basis: performance of the contract (art. 6.1.b) and compliance with legal obligations (art. 6.1.c).

2.4 Security and activity logs

  • Data: IP address, browser identifier and the date and time of relevant actions (saving a website, contact form submissions, client area sign-ins, publications and payments).
  • Purpose: preventing form abuse, keeping a record of the actions taken on each project and being able to investigate security incidents.
  • Legal basis: legitimate interest in system security and in being able to evidence contractual activity (art. 6.1.f GDPR).

2.5 Client area access

  • Data: email address and a log of sign-ins.
  • Purpose: giving you access to your websites, the content editor and your plan through a sign-in link sent to your email, without a password.
  • Legal basis: performance of the contract (art. 6.1.b GDPR).

2.6 Registering a domain in your name

  • Data: name and surname or company name, postal address, telephone number, email address and, for the extensions that require it (.es among them), an identification document.
  • Purpose: registering the domain you have ordered and having you recorded as the registrant with the relevant registry, and keeping those details up to date while the registration is in force.
  • Legal basis: performance of the contract (art. 6.1.b GDPR).
  • Consequence of not providing them: these are the details the registry itself requires, so without them the domain cannot be registered.
  • Recipients: the registrar the application goes through, which acts as a processor and is listed in section 5, and the registry for the extension concerned (Red.es for .es domains, and the operator of each extension for the rest), which processes them in its own right as a controller.
  • Period: six years from the order, which is the period for contract documentation. An order abandoned without being paid is deleted after seven days.

What gets published is not ours to decide. Some of these details may appear in the relevant registry's public lookups, and how much is published is set by the rules of each extension, not by the provider. This data is only collected if you order a domain registration: checking whether a name is free requires none of it, and if you buy the domain yourself you give the details to your own registrar and they never come through here.

The card is kept on file at the gateway so that renewals can be charged. The registration renews every year unless you cancel the renewal, so when you order it the payment gateway keeps the payment method you provided for that purpose, and the ordering screen says so before you pay. Your card details are held by the gateway, which is listed in section 5: no card number is stored here, only the payment reference and whether it shows as paid. When you cancel the renewal from your area, that payment method stops being used for that domain.

2.7 Addresses we stop writing to

  • Data: the email address, the reason we stopped writing to it (the destination server rejected it permanently, or the person who received it marked the message as spam) and how many such notices have arrived.
  • Purpose: to stop sending email to an address that rejects it or whose owner does not want it, and to prevent those sends from damaging the deliverability that the rest of the service depends on, including other clients' sign-in links.
  • Legal basis: legitimate interest (art. 6.1.f GDPR). The processing consists precisely of stopping processing: what it prevents is that you keep being written to.
  • Retention: twenty-four months from the last notice received.

Less is kept than would be needed to write to you. Your name is not kept, nor the content of what was sent to you, nor a delivery log: only the address and why it is not written to again. If you believe your address is on that list by mistake, write to us and it will be removed.

3. How your website is composed: without artificial intelligence

Your data is not sent to any artificial intelligence provider. The structure that comes out of the short form (which pages there are, which sections each one has and in what order) is decided by written rules that run on our own servers. The text that appears is generic scaffolding for you to replace in the editor.

No automated decisions are taken that produce legal effects concerning you or that similarly significantly affect you within the meaning of article 22 of the GDPR: what is composed is a starting point that you edit and then publish or discard as you see fit.

We recommend that you do not include special categories of data (article 9 of the GDPR) in the text of your website: it is content meant to be published, and publishing it puts it within anyone's reach.

4. Retention periods

Data Period
Drafts you never save They live in your browser until you save or discard them
Draft waiting for you to open the sign-in link 1 hour, and deleted sooner if you open the link or discard it
Contacts with no subsequent contract 24 months, after which they are anonymised
Contact form enquiries 24 months from sending, answered or not
Contract and invoicing data 6 years (art. 30 of the Código de Comercio, the Spanish commercial code) and the applicable tax limitation periods
Registrant details for a registered domain 6 years from the order. An order abandoned without payment, 7 days
Payment method kept on file to renew a domain Kept by the gateway for as long as the domain keeps renewing. On cancelling the renewal it stops being used
Access and audit logs 24 months

Once these periods have elapsed, the data is deleted or anonymised. In the case of accounting records, the financial record is kept but is dissociated from the identity of the data subject.

5. Recipients and international transfers

The following providers are used to deliver the service. They act as processors, and the contract required by article 28 of the GDPR has been signed with each of them:

Provider Purpose Location Safeguard
Cloudflare, Inc. Hosting and serving the site, including the prebuilt HTML Red global de servidores, con matriz en Estados Unidos Adequacy decision (EU-US Data Privacy Framework) with standard contractual clauses as a fallback
Supabase Inc. Database and file storage Unión Europea (Frankfurt), con posible acceso desde Estados Unidos Standard contractual clauses approved by the European Commission
Stripe Payments Europe, Ltd. Payment processing and opening your shop's payments account Irlanda, con transferencias a Estados Unidos Adequacy decision (EU-US Data Privacy Framework) with standard contractual clauses as a fallback
Hosting Concepts B.V. (OpenProvider) Registering ordered domains in the client's name Países Bajos (Unión Europea) No international transfer: the data does not leave the European Economic Area
Resend (Plus Five Five, Inc.) Transactional email delivery Estados Unidos, con opción de alojamiento en la Unión Europea Adequacy decision (EU-US Data Privacy Framework) with standard contractual clauses as a fallback
Plausible Insights OÜ Site audience measurement, without cookies or identifiers Unión Europea No international transfer: the data does not leave the European Economic Area

If you order a domain registration, the registrant details are also disclosed to the registry for the extension concerned. That registry does not act as a processor but as a controller in its own right, with its own processing and publication rules, set by the terms of each extension. Section 2.6 sets this out.

In addition, your data may be disclosed to the tax authorities and to banks where there is a legal obligation to do so.

You can request a copy of the safeguards applying to international transfers by writing to contacto@diazoliva.com.

6. Your rights

You can exercise the following rights at any time:

  • Access: to find out what data is processed.
  • Rectification: to correct inaccurate data.
  • Erasure: to request deletion when the data is no longer necessary.
  • Restriction: to request that processing be restricted.
  • Objection: to object to processing based on legitimate interest.
  • Portability: to receive your data in a structured, commonly used format.
  • Withdrawal of the consent given, without affecting the lawfulness of the processing carried out beforehand.

To exercise them, write to contacto@diazoliva.com stating which right you wish to exercise. You will receive a reply within one month at the latest.

If you believe the processing does not comply with the law, you can lodge a complaint with the Agencia Española de Protección de Datos, the Spanish data protection authority (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid).

7. Security

Appropriate technical and organisational measures are applied in accordance with article 32 of the GDPR: encryption in transit and at rest, identity-based access control, daily backups, access logging and separation of environments.

The database and files are hosted on servers located in the European Union (Frankfurt, Germany). The remaining providers, their locations and the applicable safeguards are listed in section 5.

8. Minors

The services offered are aimed exclusively at adults. Data relating to children under 14 is not knowingly collected.

9. Changes to this policy

This policy may be updated to reflect changes in the law or in the services provided. The date of the last update appears at the top of the document.