Privacy Policy
How we handle your personal data at AIGiner. Compliant with the GDPR and the LOPDGDD.
This is a courtesy translation provided for convenience. The Spanish version is the legally binding text.
1. Data controller
Note: AIGiner is not currently required to appoint a formal Data Protection Officer under Art. 37 GDPR (it does not carry out large-scale processing of sensitive data or systematic monitoring). The addresses above are the channels for any query or request regarding data processing.
| Item | Detail |
|---|---|
| Data controller | AIGiner S.L. |
| Main purpose | Handling of contact requests and provision of AI services |
| Registered address | Gran Via de Carles III, 98, 08028 Barcelona, Spain |
| Tax ID (CIF) | B93819753 |
| Data protection contact | privacy@aiginer.com |
| Formal requests (GDPR Art. 12/15-22) | dpo@aiginer.com |
2. Data we collect
AIGiner only collects data that users voluntarily provide through our contact and audit forms:
- First and last name
- Email address
- Phone number (optional)
- Company name (optional)
- Number of employees (optional)
- Message or project description
We may also automatically collect technical data such as IP address, browser type, and pages visited through our anonymized analytics tool (Cloudflare Web Analytics, cookie-free measurement). This information does not allow the identification of any individual user.
We do not collect special category data (health, ideology, ethnic origin, etc.) or data from minors under 14 years of age. If we detect that a minor has provided data without parental consent, we will delete it immediately.
3. Purpose and legal basis of processing
| Purpose | Legal basis | Retention period |
|---|---|---|
| Responding to contact and quote requests | Consent (Art. 6.1.a GDPR) | Query resolved + 1 year |
| Sending information about requested services | Consent (Art. 6.1.a GDPR) | Until consent is withdrawn |
| Managing the contractual relationship with clients | Performance of a contract (Art. 6.1.b GDPR) | Duration of the contract + 5 years |
| Compliance with legal obligations (tax, accounting) | Legal obligation (Art. 6.1.c GDPR) | As required by applicable regulations (min. 5 years) |
| Improving the website through anonymized analytics | Legitimate interest (Art. 6.1.f GDPR) | Anonymized data, no time limit |
4. Data recipients
AIGiner does not sell, rent, or transfer your personal data to third parties for commercial purposes. Data will only be shared with the following service providers, acting as data processors, and under appropriate safeguards:
| Provider | Use | Safeguard |
|---|---|---|
| Cloudflare, Inc. (Pages + Email Routing + Turnstile) | Website hosting, email forwarding, and anti-bot protection | Cloudflare's public Data Processing Addendum (DPA) plus the European Commission's Standard Contractual Clauses for transfers to the US |
| Google LLC (standard Gmail account) | Receiving inbound email forwarded from aiginer.com | Subject to Google's policies and the EU Standard Contractual Clauses; inbound emails may be processed on Google servers outside the EEA |
| Resend (Resend, Inc.) | Sending outbound emails from @aiginer.com (transactional + authorized marketing) | Resend's public DPA and a verified domain with DKIM/SPF/DMARC on aiginer.com |
| n8n hosted on Contabo (Germany, EU) | Processing of the website's contact and audit forms, internal lead-workflow automation | Dedicated server on EU territory under AIGiner's control; no further transfer to third parties |
| Cloudflare Web Analytics (Cloudflare, Inc., US, with EU standard contractual clauses) | Anonymized, cookie-free web analytics | Data stored in the EU, anonymized, with no possible personal identification |
5. International transfers
Some of our providers (Cloudflare Inc., Google LLC, Resend Inc.) are headquartered in the United States. Where an international transfer occurs, the framework of the Standard Contractual Clauses adopted by the European Commission (Implementing Decision 2021/914) applies, which, together with each provider's internal policies (Data Processing Addendum), ensures an adequate level of protection.
The critical infrastructure for lead and communication processing (n8n, database, Resend domain) resides on servers located within the territory of the European Union (Contabo, Germany).
6. Your rights
Under the GDPR and Organic Law 3/2018 (LOPDGDD), you may exercise the following rights at any time:
| Right | What it allows |
|---|---|
| Access | Find out what data of yours we process |
| Rectification | Correct inaccurate or incomplete data |
| Erasure | Request the deletion of your data |
| Objection | Object to processing in certain cases |
| Restriction | Restrict the processing of your data |
| Portability | Receive your data in a structured format |
To exercise any of these rights, send us an email to privacy@aiginer.com indicating which right you wish to exercise and attaching a copy of your identity document. We will respond within one month, extendable by two further months for complex requests under Article 12.3 GDPR.
If you believe that the processing does not comply with applicable regulations, you may file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
7. Security measures
AIGiner has implemented the technical and organizational measures necessary to ensure the security of personal data and to prevent its alteration, loss, unauthorized processing, or access, taking into account the state of the art, the nature of the data stored, and the risks to which they are exposed.
These measures include: HTTPS encryption across all communications, access restricted to authorized personnel only, and periodic reviews of security systems.
8. Changes to this policy
AIGiner reserves the right to modify this Privacy Policy to adapt it to legislative, case-law, or business-practice developments. Changes will be notified on this same page. We recommend reviewing this policy periodically.