Νομικά

Privacy Policy

A technical audit of the personal data handled by contact, newsletter, Business Lab, the protected editorial area and hosting layer—including unresolved gaps rather than invented assurances.

Τελευταία ενημέρωση: 29 August 2026

Η παρούσα μετάφραση παρέχεται για διευκόλυνση και απαιτεί νομικό έλεγχο σε αυτήν τη γλώσσα.

1. Controller

The controller of the processing described here is THE BUSINESS DOER LLC, tax ID [TAX IDENTIFICATION NUMBER PENDING], at [REGISTERED OR PROFESSIONAL ADDRESS PENDING].

Privacy requests must be sent to [PRIVACY EMAIL ADDRESS PENDING]. No Data Protection Officer has been identified or claimed. The remaining tax, address and working-contact fields above are mandatory legal-completion blockers.

2. Processing activities verified

This table reflects the source code, database model, anonymous backend checks and a clean-browser production audit performed on 27 August 2026. It does not describe planned services as active.

FlowDataPurposeLegal basis / statusRetention
Newsletter waiting listEmail, consent, timestamp, source containing the privacy-notice version, status and provider-sync fieldsRecord and manage the subscription requestedConsent (GDPR Art. 6(1)(a))Until withdrawal, followed only by an approved suppression period: [RETENTION PERIODS PENDING LEGAL VALIDATION]
The Business Doer Lab enquiryName, email, company/project, website, requested study, brief, objective, industry, market, timing, budget range, optional notes, consent, notice version and timestampsStore, assess and respond to a non-binding project enquiryConsent as currently implemented; steps requested before a possible contract may also apply (GDPR Arts. 6(1)(a) and 6(1)(b)). Counsel must confirm the definitive basis and wording.[RETENTION PERIODS PENDING LEGAL VALIDATION]
Contact messageName, email, selected topic, message, workflow status, source, privacy-notice version and timestampsStore, review and respond to a private messageDepending on the topic: steps requested before a possible contract, compliance with legal obligations for privacy requests, or legitimate interest in managing relevant correspondence (GDPR Arts. 6(1)(b), 6(1)(c) and 6(1)(f)). Counsel must confirm the final mapping and any legitimate-interest assessment.[RETENTION PERIODS PENDING LEGAL VALIDATION]
Protected editorial accounts and CMSEmail, authentication identifiers/tokens, display profile, role, article and media changes, uploader identifier and optional Google OAuth dataAuthenticate editors, manage content and protect administrationLegitimate interest in secure publication operation (GDPR Art. 6(1)(f)); document the balancing assessmentFor the authorised relationship and approved security period: [RETENTION PERIODS PENDING LEGAL VALIDATION]
Public profile and media-metadata readsProfile UUID, display name/avatar and media uploader UUID plus file metadata may be returned by the current anonymous API policiesNo necessary public frontend use was foundPrivacy-hardening is required. A migration is prepared to remove anonymous access, but production application and verification remain pending.[RETENTION PERIODS PENDING LEGAL VALIDATION]
Consent settingsCategory choices, decision method, policy version and decision/expiry timestampsRemember and demonstrate the browser privacy choiceCompliance and strictly necessary service operation (GDPR Arts. 6(1)(c) and 6(1)(f); LSSI Art. 22.2 exemption)12 months
Delivery, logs and securityIP address, request/device metadata, timestamps and diagnostic or security signals; Cloudflare sets the documented __cf_bm security cookieDeliver, diagnose and protect the serviceLegitimate interest in secure service operation (GDPR Art. 6(1)(f)), subject to necessity and a documented balancing assessmentProvider and business schedule: [RETENTION PERIODS PENDING LEGAL VALIDATION]
Lovable project analyticsRandom 30-minute session ID, user agent, locale, inferred country, referrer, path, full URL and page-view timestampVisitor, page-view, source and device analyticsConsent is required. Production currently injects and sends this before consent; this is a disclosed launch blocker, not a claimed lawful implementation.Browser session identifier: 30 minutes observed. Server retention: [RETENTION PERIODS PENDING LEGAL VALIDATION]

Business Lab is active: its table and secure submission function respond in the connected backend, and anonymous users cannot read enquiry rows. The contact module is present in source, but its separate migration must be applied and verified before live submissions can be stored; until then it fails closed with a visible error. It stores messages only and does not send email. The project contains no public comments, checkout, online payment, public paid subscription or automated decision-making. The AdSense account meta tag and /ads.txt declaration exist for site verification, but they load no Google code. Google scripts and ad rendering remain hard-blocked pending a certified CMP and live validation.

3. Required and optional information

Newsletter email and the separate, unchecked newsletter consent are required to join the waiting list. Fields explicitly marked optional in Business Lab may be omitted; the remaining fields are required to assess and respond to that enquiry. Name, email, topic and message are required in the general contact form. If required information is not supplied, the relevant request cannot be saved. Do not include sensitive personal data, confidential material or unnecessary information about other people. The contact form presents privacy information without turning acceptance of this policy into a bundled marketing or generic-consent requirement.

4. Newsletter and commercial communications

The site currently records a pending newsletter request but has no email-delivery provider. No message should be sent until the sender details, processor terms, retention schedule and simple free unsubscribe mechanism are operational. Every future commercial email must identify the sender and provide a working unsubscribe route.

Consent evidence currently includes the email, boolean consent, time and a source field containing the privacy-notice version. The direct database-insert fallback has been removed, so signup fails closed if the validated server function is unavailable. A double-opt-in decision and re-subscription behaviour remain to be approved before delivery starts.

5. Recipients and processors

Authorised administrators can access subscriber, Business Lab and contact-message records under role-based database policies. Lovable Cloud/Supabase-compatible services provide database, authentication and storage. Lovable hosting delivers the application and currently injects project analytics. Cloudflare provides edge delivery and bot protection. Google is contacted only when an administrator actively chooses Google sign-in.

The processor entities, roles, agreements, regions, subprocessors and transfer mechanisms must be verified: [LOVABLE CLOUD/SUPABASE AND CLOUDFLARE ENTITIES, ROLES, DPAS, REGIONS, SUBPROCESSORS AND TRANSFER SAFEGUARDS PENDING VERIFICATION]. No active advertiser or email-delivery provider receives user data. External editorial images are technically possible but none were present in the audited published records; future remote images must be approved, proxied or hosted locally before use because loading one can expose request data to its host.

6. International transfers

The repository does not establish all processing countries or contractual safeguards for Lovable, its Supabase-compatible services, Cloudflare or their subprocessors. No definitive adequacy or transfer claim is therefore made. The controller must verify locations and the applicable mechanism—such as an adequacy decision or Standard Contractual Clauses—and confirm whether any US recipient relied upon is actually certified under the EU-US Data Privacy Framework. An administrator choosing Google sign-in is also subject to Google’s terms.

7. Retention

The application defines a 12-month lifetime for the local consent record, and the injected analytics script uses a 30-minute browser session identifier. Business retention for subscribers, contact messages, enquiries, accounts, media records, analytics events and infrastructure logs has not been approved and must not be invented: [RETENTION PERIODS PENDING LEGAL VALIDATION]. The final schedule must limit each purpose, include deletion or anonymisation and define any legally required blocking period.

8. Your rights and withdrawal

Where applicable, you may request access, rectification, erasure, restriction, objection and portability. You may withdraw consent without affecting earlier lawful processing. Send a verifiable request to [PRIVACY EMAIL ADDRESS PENDING]; this address must become operational before newsletter delivery or a final legal launch. The controller may request only what is reasonably necessary to verify identity.

You may lodge a complaint with the Spanish Data Protection Agency (AEPD), particularly after first contacting the controller. Cookie choices can be changed from “Configure cookies” in the footer, subject to the hosting-analytics limitation disclosed in the Cookie Policy.

9. Security and confidentiality

Newsletter and Business Lab rows use Row Level Security and administrator-only read access; public submissions go through validated database functions. The contact migration applies the same pattern, grants no anonymous table access and limits administrator edits to workflow status, but those controls are not effective until that migration is applied and verified in the live backend. Protected routes require a session and administrator role, storage uploads are restricted, and the application sends security headers. A separate privacy-hardening migration removes unnecessary anonymous reads of profiles and media metadata; it also requires live application and verification. These controls reduce risk but cannot promise absolute security. Access, OAuth registration rules, production secrets, migrations and incident procedures require periodic review.

10. Children

The publication and Business Lab target business professionals, not children, and no child-specific service is implemented. If data is knowingly collected from a child without a valid basis, it should be removed. Spanish law generally permits consent-based processing from age 14, subject to exceptions and any stricter rules applicable to the activity.

11. Data origin and automated decisions

Form and account information comes directly from the person submitting it or signing in. Technical data is generated by the browser, hosting, database and security layers. The audited code does not make decisions with legal or similarly significant effects solely by automated processing and does not create behavioural advertising profiles.

12. Changes and language

This policy and the consent version must change before a new email provider, analytics service, advertising platform, embed, payment flow, public account system or materially different purpose is activated. The current site is English-only. No translated legal version or prevailing language has been approved; Spanish counsel must decide that before multilingual publication.