// Legal

Privacy Policy

Effective date · 2 November 2026

What changes

  • Named providers. We replace “Stripe or equivalent” with Stripe Payments Europe (Ireland) and add Neon (database, hosted in Frankfurt) and OVH as our email provider.
  • Automation and invoicing. We add our cloud server provider in the EU, which hosts our automation servers (they run scheduled tasks, send internal alerts to the team and prepare the invoice register from payments), and the invoicing platform and tax advisory firm in Spain with which we issue invoices and keep our accounts and tax filings.
  • Google, only with your permission. If you accept campaign measurement in the cookie banner, when you place an order and on each renewal charged in the 90 days after the click we send Google Ireland the click identifier from its ad, the amount and the order reference, and we let it know about refunds. Google processes them under its own terms.
  • What data we process and why. We add account security data (sign-ins, two-step verification and a record that you accepted these documents), campaign measurement data and site analytics, the last two only with your consent. Usage data now reflects what we actually collect: server traffic and power status, not CPU or RAM usage.
  • How long. We used to say that technical logs were kept for a maximum of 12 months; they are now kept for longer. Emails sent, the log of administration actions and the record that you accepted these documents are kept while you have an account and, after that, until the limitation period expires for the legal actions in which they may serve as evidence: as a general rule, 5 years from the closure of your account (or longer if the applicable law sets a longer period), or until an ongoing claim is resolved. Sign-ins are deleted when you delete your account. Campaign measurement data is unlinked from your account 90 days after the click or when you withdraw consent. Enquiries sent through the contact form and quote requests are kept for 24 months from the last contact and are then deleted.
  • Where data is processed. We clarify that the Vercel servers that handle the website and the customer panel are in the USA, and that Neon, Stripe and Google may also process data there, with the safeguards of the EU-US Data Privacy Framework or the Standard Contractual Clauses. You can ask us for a copy of those safeguards.
  • Required data and automated decisions. We explain which data is needed to order and that we do not make solely automated decisions, except that Stripe’s fraud prevention may decline a payment.
  • Exercising your rights. We no longer ask for a copy of your ID document: it is enough to write from your account email, and we only ask for something more if there are reasonable doubts.