Skip to content
Legal Updated September 2026

Privacy Policy

How we handle your personal data at AIGiner. Compliant with the GDPR and the LOPDGDD.

This is a courtesy translation provided for convenience. The Spanish version is the legally binding text.

1. Data controller

Note: AIGiner is not currently required to appoint a formal Data Protection Officer under Art. 37 GDPR (it does not carry out large-scale processing of sensitive data or systematic monitoring). The addresses above are the channels for any query or request regarding data processing.

ItemDetail
Data controllerAIGiner S.L.
Main purposeHandling of contact requests and provision of AI services
Registered addressGran Via de Carles III, 98, 10º, 08028 Barcelona, Spain
Tax ID (CIF)B93819753
Commercial RegistryRegistered with the Barcelona Companies Registry · Sheet B-662372 · Entry 1 · IRUS 1000478196595
Data protection contactprivacy@aiginer.com
Formal requests (GDPR Art. 12/15-22)dpo@aiginer.com

2. Data we collect

AIGiner only collects data that users voluntarily provide through our contact and audit forms:

  • First and last name
  • Email address
  • Phone number (optional)
  • Company name (optional)
  • Number of employees (optional)
  • Message or project description

If you enrol in an AIGiner Academy training course (academy.aiginer.com), we also process the data required to give you access and to certify that you completed it:

  • Your name and email address, which identify your account
  • Your password, which is never stored as such: it is kept irreversibly hashed
  • Your course progress: which modules you have opened and what you wrote in the exercises
  • Your exam result: correct answers, the date you passed and the number of attempts
  • The certificate issued, bearing your name, the company you state and its serial number

If you buy the extended report of the AI law test (aiginer.com/test), we store what is needed to generate your document and to let you download it again:

  • The nine answers you gave in the test. None of them is a special category of data
  • The company name you typed and your email address
  • The record that you agreed to start the download immediately, with its date and time, as required by Article 103(m) of the Spanish consumer protection act
  • The payment identifier and the amount. Card details never reach us: they are handled by Stripe, which also issues the invoice

We may also automatically collect technical data such as IP address, browser type, and pages visited through our anonymized analytics tool (Cloudflare Web Analytics, cookie-free measurement). This information does not allow the identification of any individual user.

We do not collect special category data (health, ideology, ethnic origin, etc.) or data from minors under 14 years of age, which is the age set by Article 7 of the Spanish Data Protection Act (LOPDGDD). If we detect that a minor has provided data without the consent of their parents or guardians, we will delete it immediately.

3. Purpose and legal basis of processing

PurposeLegal basisRetention period
Responding to contact and quote requestsConsent (Art. 6.1.a GDPR)Query resolved + 1 year
Sending information about requested servicesConsent (Art. 6.1.a GDPR)Until consent is withdrawn
Managing the contractual relationship with clientsPerformance of a contract (Art. 6.1.b GDPR)Duration of the contract + 5 years
Compliance with legal obligations (tax, accounting)Legal obligation (Art. 6.1.c GDPR)As required by applicable regulations: min. 6 years (Article 30 of the Spanish Commercial Code) and a 4-year tax limitation period (Article 66 of the General Tax Act)
Granting access to AIGiner Academy courses and certifying who has completed themPerformance of a contract (Art. 6.1.b GDPR)For as long as the account remains active. The certificate issued is kept for as long as it still serves as proof of the training, which is its sole purpose
Generating and re-delivering the extended report of the AI law testPerformance of a contract (Art. 6(1)(b) GDPR)For as long as the download link remains valid. Deleted on request; the payment record is kept under the statutory obligation in the row above
Improving the website through anonymized analyticsLegitimate interest (Art. 6.1.f GDPR)Anonymized data, no time limit

4. Data recipients

AIGiner does not sell, rent, or transfer your personal data to third parties for commercial purposes. Data will only be shared with the following service providers, acting as data processors, and under appropriate safeguards:

ProviderUseSafeguard
Cloudflare, Inc. (Pages + Email Routing + Turnstile)Website hosting, email forwarding, and anti-bot protectionCloudflare's public Data Processing Addendum (DPA) plus the European Commission's Standard Contractual Clauses for transfers to the US
Google LLC (standard Gmail account)Receiving inbound email forwarded from aiginer.comSubject to Google's policies and the EU Standard Contractual Clauses; inbound emails may be processed on Google servers outside the EEA
Resend (Resend, Inc.)Sending outbound emails from @aiginer.com (transactional + authorized marketing)Resend's public DPA and a verified domain with DKIM/SPF/DMARC on aiginer.com
Contabo GmbH (Lauterbourg, France · EU)Dedicated server running AIGiner's API, which processes the website's contact and audit forms and the conversational assistantDedicated server on EU territory under AIGiner's control; no further transfer to third parties
Supabase (data hosted in eu-west-1, Ireland, EU)Database holding the leads received through the website's formsSupabase Data Processing Addendum; data is hosted within the European Union
Cloudflare D1 (Western Europe · EU)AIGiner Academy database: accounts, course progress and issued certificatesCloudflare Data Processing Addendum; data is hosted within the European Union
LLM inference provider on EU sovereign infrastructureGenerates the answers of the website's conversational assistantProcessor established in the European Union, under a processing agreement with zero retention: conversations are neither stored nor used to train models
Cloudflare Web Analytics (Cloudflare, Inc., US, with EU standard contractual clauses)Anonymized, cookie-free web analyticsData stored in the EU, anonymized, with no possible personal identification

5. International transfers

Some of our providers (Cloudflare Inc., Google LLC, Resend Inc.) are headquartered in the United States. Where an international transfer occurs, the framework of the Standard Contractual Clauses adopted by the European Commission (Implementing Decision 2021/914) applies, which, together with each provider's internal policies (Data Processing Addendum), ensures an adequate level of protection.

The critical infrastructure for lead and communication processing resides on servers located within the territory of the European Union: AIGiner’s own server (Contabo, Lauterbourg, France), the leads database (Supabase, Ireland) and the AIGiner Academy data (Cloudflare D1, Western Europe). The conversational assistant is processed entirely within the European Union, with no international transfer.

6. Your rights

Under the GDPR and Organic Law 3/2018 (LOPDGDD), you may exercise the following rights at any time:

RightWhat it allows
AccessFind out what data of yours we process
RectificationCorrect inaccurate or incomplete data
ErasureRequest the deletion of your data
ObjectionObject to processing in certain cases
RestrictionRestrict the processing of your data
PortabilityReceive your data in a structured format

To exercise any of these rights, send us an email to privacy@aiginer.com indicating which right you wish to exercise and attaching a copy of your identity document. We will respond within one month, extendable by two further months for complex requests under Article 12.3 GDPR.

If you believe that the processing does not comply with applicable regulations, you may file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.

7. Security measures

AIGiner has implemented the technical and organizational measures necessary to ensure the security of personal data and to prevent its alteration, loss, unauthorized processing, or access, taking into account the state of the art, the nature of the data stored, and the risks to which they are exposed.

These measures include: HTTPS encryption across all communications, access restricted to authorized personnel only, and periodic reviews of security systems.

8. Changes to this policy

AIGiner reserves the right to modify this Privacy Policy to adapt it to legislative, case-law, or business-practice developments. Changes will be notified on this same page. We recommend reviewing this policy periodically.

Questions about privacy and data protection? Write to privacy@aiginer.com.