Skip to content

Legal

Privacy Policy

A code-specific account of the personal data currently handled by the publication, its protected editorial area and The Business Doer Lab.

Last updated: 28 July 2026

1. Controller

The controller of the processing described here is [NOMBRE O RAZÓN SOCIAL PENDIENTE], tax ID [NIF/CIF PENDIENTE], at [DOMICILIO PENDIENTE].

Privacy requests must be sent to [CORREO DE PRIVACIDAD PENDIENTE]. No Data Protection Officer has been identified or claimed. The identity and contact fields above are mandatory publication blockers.

2. Processing activities found in the project

This table reflects the audited code and database model. It does not describe planned services as if they were active.

FlowDataPurposeLegal basisRetention
NewsletterEmail, status, source, consent and timestampsRecord and manage the newsletter subscription requestedConsent (GDPR Art. 6(1)(a))Until withdrawal, then a suppression period [PLAZOS DE CONSERVACIÓN PENDIENTES DE VALIDACIÓN]
The Business Doer Lab enquiry
Prepared; connected backend migration not active
Name, email, company/project, website, requested study, business brief, objective, industry, market, timing, budget range, optional notes, consent and timestampsReview and respond to the project enquiryConsent as currently implemented; pre-contractual steps may also apply where a quotation is expressly requested (GDPR Arts. 6(1)(a) and 6(1)(b))[PLAZOS DE CONSERVACIÓN PENDIENTES DE VALIDACIÓN]
Protected editorial accountsEmail, authentication identifiers/tokens, profile and administrator roleAuthenticate authorised editors and protect administrationLegitimate interest in securing and operating the publication (GDPR Art. 6(1)(f)); document the balancing assessment before productionFor the authorised relationship and security period [PLAZOS DE CONSERVACIÓN PENDIENTES DE VALIDACIÓN]
Consent settingsCookie-category choices, decision method, policy version and timestampsRemember privacy choicesCompliance with legal obligations and strictly necessary service operation (GDPR Arts. 6(1)(c) and 6(1)(f), LSSI Art. 22.2 exemption)12 months
Infrastructure and securityRequests may generate IP address, device, timestamp and diagnostic/security logs at the hosting or database layerDeliver, monitor and secure the serviceLegitimate interest in secure service operation (GDPR Art. 6(1)(f))Provider and business schedule [PLAZOS DE CONSERVACIÓN PENDIENTES DE VALIDACIÓN]

The Business Lab table and secure submission function exist in a local versioned migration but were not present in the connected backend during this audit, so the current form reports that its secure request channel is not active and does not save an enquiry. This row describes the processing that will begin only after that migration is applied and tested. The project contains no public registration, public comments, payment checkout, active advertising, third-party analytics, behavioural profiling or automated decision-making. The newsletter database can record subscriptions, but no email-delivery provider is connected and the interface does not claim that messages have been sent.

3. Required and optional information

Newsletter email and consent are required to join the list. Fields marked optional in the Business Lab form may be omitted; the remaining fields are required to assess the enquiry. If required information is not supplied, that request cannot be saved or reviewed. Consent for newsletter marketing is separate from a Business Lab enquiry and is never required to submit that enquiry.

4. Recipients and processors

The application uses Lovable Cloud’s Supabase-compatible database, authentication and storage interfaces. Authorised administrators can access subscriber and Business Lab records according to role-based database policies. Google authentication is available only on the protected sign-in page and is contacted when an administrator actively chooses that option.

The processor identity, processing region, data-processing agreement, subprocessors and transfer mechanism must be verified before publication: [REGIÓN, DPA Y SUBENCARGADOS DE LOVABLE CLOUD PENDIENTES DE VERIFICACIÓN]. No data sale or routine disclosure to advertisers is implemented.

5. International transfers

The repository alone does not establish where Lovable Cloud or its subprocessors process data. No international-transfer claim is therefore made. The controller must review the provider contract, processing locations and applicable safeguards—such as an adequacy decision or Standard Contractual Clauses—before publishing a definitive statement. An administrator who elects Google sign-in is also subject to Google’s relevant privacy terms.

6. Retention

The code defines a 12-month lifetime for the local consent preference. Business retention periods for newsletter records, enquiries, accounts and infrastructure logs have not been approved and must not be invented: [PLAZOS DE CONSERVACIÓN PENDIENTES DE VALIDACIÓN]. Once approved, periods should be limited to what is necessary and include any legally required blocking or limitation period.

7. Your rights

Where applicable, you may request access, rectification, erasure, restriction, objection and portability, and you may withdraw consent at any time without affecting earlier lawful processing. Send a verifiable request to [CORREO DE PRIVACIDAD PENDIENTE]. The controller may request only the information reasonably needed to verify identity.

You may also lodge a complaint with the Spanish Data Protection Agency (AEPD), particularly after first contacting the controller about the exercise of your rights.

8. Security and confidentiality

The active data model uses Row Level Security and administrator-only read access for subscriber records. The pending Business Lab migration defines the same isolation for enquiry records, but it must be applied and tested before that form is activated. Protected routes, server-side validation and restricted media-storage policies are also defined. These controls reduce risk but no system can promise absolute security. Access should be reviewed periodically and production secrets must remain outside frontend code and repositories.

9. Children

The publication and Business Lab are aimed at business professionals, not children, and no child-specific service is implemented. If the controller becomes aware that data was collected from a child without a valid basis, it should be removed. Spanish law generally permits consent-based processing from age 14, subject to exceptions and any other legal requirements applicable to the activity.

10. Data origin and automated decisions

Personal information is obtained directly from the person who submits a form or from an authorised administrator during sign-in. The audited code does not make decisions with legal or similarly significant effects solely by automated processing and does not create behavioural profiles.

11. Changes and language

This policy must be updated before a new processor, email provider, analytics service, advertising platform, payment flow, public account system or materially different purpose is activated. The current site is English-only. No translated legal version or prevailing language has been approved; Spanish legal review should decide that point before multilingual publication.