Privacy Policy
How we handle your personal data at AIGiner. Compliant with the GDPR and the LOPDGDD.
This is a courtesy translation provided for convenience. The Spanish version is the legally binding text.
1. Data controller
Note: AIGiner is not currently required to appoint a formal Data Protection Officer under Art. 37 GDPR (it does not carry out large-scale processing of sensitive data or systematic monitoring). The addresses above are the channels for any query or request regarding data processing.
| Item | Detail |
|---|---|
| Data controller | AIGiner S.L. |
| Main purpose | Handling of contact requests and provision of AI services |
| Registered address | Gran Via de Carles III, 98, 10º, 08028 Barcelona, Spain |
| Tax ID (CIF) | B93819753 |
| Commercial Registry | Registered with the Barcelona Companies Registry · Sheet B-662372 · Entry 1 · IRUS 1000478196595 |
| Data protection contact | privacy@aiginer.com |
| Formal requests (GDPR Art. 12/15-22) | dpo@aiginer.com |
2. Data we collect
AIGiner only collects data that users voluntarily provide through our contact and audit forms:
- First and last name
- Email address
- Phone number (optional)
- Company name (optional)
- Number of employees (optional)
- Message or project description
If you enrol in an AIGiner Academy training course (academy.aiginer.com), we also process the data required to give you access and to certify that you completed it:
- Your name and email address, which identify your account
- Your password, which is never stored as such: it is kept irreversibly hashed
- Your course progress: which modules you have opened and what you wrote in the exercises
- Your exam result: correct answers, the date you passed and the number of attempts
- The certificate issued, bearing your name, the company you state and its serial number
If you buy the extended report of the AI law test (aiginer.com/test), we store what is needed to generate your document and to let you download it again:
- The nine answers you gave in the test. None of them is a special category of data
- The company name you typed and your email address
- The record that you agreed to start the download immediately, with its date and time, as required by Article 103(m) of the Spanish consumer protection act
- The payment identifier and the amount. Card details never reach us: they are handled by Stripe, which also issues the invoice
We may also automatically collect technical data such as IP address, browser type, and pages visited through our anonymized analytics tool (Cloudflare Web Analytics, cookie-free measurement). This information does not allow the identification of any individual user.
We do not collect special category data (health, ideology, ethnic origin, etc.) or data from minors under 14 years of age, which is the age set by Article 7 of the Spanish Data Protection Act (LOPDGDD). If we detect that a minor has provided data without the consent of their parents or guardians, we will delete it immediately.
3. Purpose and legal basis of processing
| Purpose | Legal basis | Retention period |
|---|---|---|
| Responding to contact and quote requests | Consent (Art. 6.1.a GDPR) | Query resolved + 1 year |
| Sending information about requested services | Consent (Art. 6.1.a GDPR) | Until consent is withdrawn |
| Managing the contractual relationship with clients | Performance of a contract (Art. 6.1.b GDPR) | Duration of the contract + 5 years |
| Compliance with legal obligations (tax, accounting) | Legal obligation (Art. 6.1.c GDPR) | As required by applicable regulations: min. 6 years (Article 30 of the Spanish Commercial Code) and a 4-year tax limitation period (Article 66 of the General Tax Act) |
| Granting access to AIGiner Academy courses and certifying who has completed them | Performance of a contract (Art. 6.1.b GDPR) | For as long as the account remains active. The certificate issued is kept for as long as it still serves as proof of the training, which is its sole purpose |
| Generating and re-delivering the extended report of the AI law test | Performance of a contract (Art. 6(1)(b) GDPR) | For as long as the download link remains valid. Deleted on request; the payment record is kept under the statutory obligation in the row above |
| Improving the website through anonymized analytics | Legitimate interest (Art. 6.1.f GDPR) | Anonymized data, no time limit |
4. Data recipients
AIGiner does not sell, rent, or transfer your personal data to third parties for commercial purposes. Data will only be shared with the following service providers, acting as data processors, and under appropriate safeguards:
| Provider | Use | Safeguard |
|---|---|---|
| Cloudflare, Inc. (Pages + Email Routing + Turnstile) | Website hosting, email forwarding, and anti-bot protection | Cloudflare's public Data Processing Addendum (DPA) plus the European Commission's Standard Contractual Clauses for transfers to the US |
| Google LLC (standard Gmail account) | Receiving inbound email forwarded from aiginer.com | Subject to Google's policies and the EU Standard Contractual Clauses; inbound emails may be processed on Google servers outside the EEA |
| Resend (Resend, Inc.) | Sending outbound emails from @aiginer.com (transactional + authorized marketing) | Resend's public DPA and a verified domain with DKIM/SPF/DMARC on aiginer.com |
| Contabo GmbH (Lauterbourg, France · EU) | Dedicated server running AIGiner's API, which processes the website's contact and audit forms and the conversational assistant | Dedicated server on EU territory under AIGiner's control; no further transfer to third parties |
| Supabase (data hosted in eu-west-1, Ireland, EU) | Database holding the leads received through the website's forms | Supabase Data Processing Addendum; data is hosted within the European Union |
| Cloudflare D1 (Western Europe · EU) | AIGiner Academy database: accounts, course progress and issued certificates | Cloudflare Data Processing Addendum; data is hosted within the European Union |
| LLM inference provider on EU sovereign infrastructure | Generates the answers of the website's conversational assistant | Processor established in the European Union, under a processing agreement with zero retention: conversations are neither stored nor used to train models |
| Cloudflare Web Analytics (Cloudflare, Inc., US, with EU standard contractual clauses) | Anonymized, cookie-free web analytics | Data stored in the EU, anonymized, with no possible personal identification |
5. International transfers
Some of our providers (Cloudflare Inc., Google LLC, Resend Inc.) are headquartered in the United States. Where an international transfer occurs, the framework of the Standard Contractual Clauses adopted by the European Commission (Implementing Decision 2021/914) applies, which, together with each provider's internal policies (Data Processing Addendum), ensures an adequate level of protection.
The critical infrastructure for lead and communication processing resides on servers located within the territory of the European Union: AIGiner’s own server (Contabo, Lauterbourg, France), the leads database (Supabase, Ireland) and the AIGiner Academy data (Cloudflare D1, Western Europe). The conversational assistant is processed entirely within the European Union, with no international transfer.
6. Your rights
Under the GDPR and Organic Law 3/2018 (LOPDGDD), you may exercise the following rights at any time:
| Right | What it allows |
|---|---|
| Access | Find out what data of yours we process |
| Rectification | Correct inaccurate or incomplete data |
| Erasure | Request the deletion of your data |
| Objection | Object to processing in certain cases |
| Restriction | Restrict the processing of your data |
| Portability | Receive your data in a structured format |
To exercise any of these rights, send us an email to privacy@aiginer.com indicating which right you wish to exercise and attaching a copy of your identity document. We will respond within one month, extendable by two further months for complex requests under Article 12.3 GDPR.
If you believe that the processing does not comply with applicable regulations, you may file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
7. Security measures
AIGiner has implemented the technical and organizational measures necessary to ensure the security of personal data and to prevent its alteration, loss, unauthorized processing, or access, taking into account the state of the art, the nature of the data stored, and the risks to which they are exposed.
These measures include: HTTPS encryption across all communications, access restricted to authorized personnel only, and periodic reviews of security systems.
8. Changes to this policy
AIGiner reserves the right to modify this Privacy Policy to adapt it to legislative, case-law, or business-practice developments. Changes will be notified on this same page. We recommend reviewing this policy periodically.