This policy explains how we process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, GDPR), Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) and Law 34/2002 (LSSI-CE). We have written it in plain language. If anything is unclear, just ask us.
1. Data controller
- Controller: Clearline Digital Solutions, trading as Clearline Digital Solutions ("Clearline", "we")
Given the nature and scale of our processing, we are not required to appoint a Data Protection Officer. You can contact us directly about any data protection matter.
2. Data we process
Data you give us
- Contact and enquiry data: name, business name, type of business, phone number, email address and the content of your messages.
- Project data: texts, photos, logos, menus, prices, property details and other material you send us to build your website, and your feedback.
- Access data: where you choose to share them, details needed to connect your domain, Google page, WhatsApp or other services. We never ask for banking passwords.
- Billing data: billing name, NIF, address, invoices and payment records. We do not see or store full card details.
Data collected automatically
- Server logs: our hosting provider records technical data when you visit, such as IP address, browser type, pages requested and date and time, to keep the website secure and investigate faults or misuse.
- No tracking: this website does not use analytics, advertising or tracking cookies. See our Cookie policy.
Data from other sources
When preparing a proposal for a business, we may consult information that business has made public, such as its name, address, phone number, opening hours, website and public Google listing.
How the enquiry form works
The enquiry form does not store anything on our server. When you press send, your details are placed into a WhatsApp message or email on your own device, which you then choose to send. We receive it through WhatsApp or our email provider.
3. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Replying to your enquiry, preparing a free mockup and sending you a quote | Pre-contractual measures taken at your request (art. 6.1.b) and your consent when you contact us (art. 6.1.a) |
| Designing, building, launching, hosting and supporting your website | Performance of a contract (art. 6.1.b) |
| Invoicing, accounting and tax obligations | Compliance with legal obligations (art. 6.1.c), including the Spanish Commercial Code and tax legislation |
| Keeping this website and our systems secure | Legitimate interest in protecting our website, clients and visitors (art. 6.1.f) |
| Sending information about our services | Your consent (art. 6.1.a), or our legitimate interest where you are an existing client (art. 6.1.f and art. 21.2 LSSI-CE) |
| Showing completed client websites in our portfolio | Legitimate interest in showing our work (art. 6.1.f). Clients can object at any time |
| Handling complaints and legal claims | Legitimate interest in defending our rights (art. 6.1.f) and legal obligations (art. 6.1.c) |
Providing the data marked as required is necessary to reply to you or to provide our services. We do not make decisions based solely on automated processing, including profiling, that produce legal effects on you.
4. Commercial communications
In line with article 21 of the LSSI-CE, we only send commercial communications by email, WhatsApp, SMS or other electronic means if you have given your prior consent, or if you are an existing client and the communication relates to services similar to those you have contracted. Every communication will include a simple, free way to opt out. You can also object at any time by contacting us, and we will keep the minimum data needed to respect your decision.
5. Recipients
We do not sell your data. We only share it where necessary with:
- Service providers acting as processors: WhatsApp (Meta Platforms Ireland Ltd.), our email provider, our hosting provider (such as Railway), our accounting advisers (gestoría) and our bank or payment provider, under contracts that comply with article 28 GDPR.
- Public authorities: the Spanish Tax Agency (AEAT), courts, law enforcement or other authorities, when required by law.
- A future acquirer: if our business is sold or restructured, subject to this policy.
6. International transfers
Some providers, such as Meta and Railway, may process data outside the European Economic Area, including in the United States. Where this happens, transfers are protected by an adequacy decision of the European Commission, such as the EU-US Data Privacy Framework for certified companies, or by the Standard Contractual Clauses approved by the European Commission, with additional safeguards where needed.
7. How long we keep data
- Enquiries that do not lead to a contract: up to 12 months after our last contact.
- Client data: for the duration of our relationship, and afterwards blocked and kept only for the periods required by law, such as 6 years for accounting records (article 30 of the Commercial Code), 4 years for tax purposes (General Tax Law) and the limitation period for legal claims.
- Marketing: until you withdraw consent or object.
- Server logs: for a short period in line with our hosting provider's settings.
When data is no longer needed, it is blocked as required by article 32 LOPDGDD and then securely deleted.
8. Your rights
You can exercise the following rights at any time, free of charge:
- Access your personal data;
- Rectification of inaccurate or incomplete data;
- Erasure of your data when it is no longer needed or you withdraw consent;
- Objection to processing based on legitimate interest, and to direct marketing;
- Restriction of processing in certain cases;
- Portability of data you provided to us, in a structured, commonly used format;
- Withdrawal of consent, without affecting processing carried out before withdrawal;
- Not to be subject to decisions based solely on automated processing.
To exercise your rights, contact us, indicating which right you wish to exercise. We may ask you to verify your identity. We will reply within one month, which may be extended by two further months for complex requests, in which case we will tell you why.
If you believe your rights have not been respected, you can file a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es. We would appreciate the chance to resolve your concern first.
9. Security
We apply appropriate technical and organisational measures to protect personal data, including encrypted connections (HTTPS), strong passwords and two-factor authentication on our accounts, and access limited to people who need it. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the AEPD and, where required, you, in accordance with articles 33 and 34 GDPR.
10. Minors
Our services are aimed at businesses and professionals. We do not knowingly process data of people under 14, the age of digital consent in Spain (article 7 LOPDGDD).
11. Data of our clients' customers
When we build or host a website for a client, the client is the controller of the personal data collected through its own website, such as bookings or enquiries from its customers. Where we access that data on the client's behalf, we act as a processor under a data processing agreement that meets article 28 GDPR, included in our Terms of service. Each client website must have its own privacy policy. If you are a customer of one of our clients, please contact that business about your data.
12. Changes to this policy
We may update this policy to reflect legal or operational changes. The date at the top shows when it was last updated. Significant changes will be made clear on this website or communicated to you directly.