1. Controller
The controller of the processing described here is [NOMBRE O RAZÓN SOCIAL PENDIENTE], tax ID [NIF/CIF PENDIENTE], at [DOMICILIO PENDIENTE].
Privacy requests must be sent to [CORREO DE PRIVACIDAD PENDIENTE]. No Data Protection Officer has been identified or claimed. The identity and contact fields above are mandatory publication blockers.
2. Processing activities found in the project
This table reflects the audited code and database model. It does not describe planned services as if they were active.
| Flow | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Newsletter | Email, status, source, consent and timestamps | Record and manage the newsletter subscription requested | Consent (GDPR Art. 6(1)(a)) | Until withdrawal, then a suppression period [PLAZOS DE CONSERVACIÓN PENDIENTES DE VALIDACIÓN] |
| The Business Doer Lab enquiry Prepared; connected backend migration not active | Name, email, company/project, website, requested study, business brief, objective, industry, market, timing, budget range, optional notes, consent and timestamps | Review and respond to the project enquiry | Consent as currently implemented; pre-contractual steps may also apply where a quotation is expressly requested (GDPR Arts. 6(1)(a) and 6(1)(b)) | [PLAZOS DE CONSERVACIÓN PENDIENTES DE VALIDACIÓN] |
| Protected editorial accounts | Email, authentication identifiers/tokens, profile and administrator role | Authenticate authorised editors and protect administration | Legitimate interest in securing and operating the publication (GDPR Art. 6(1)(f)); document the balancing assessment before production | For the authorised relationship and security period [PLAZOS DE CONSERVACIÓN PENDIENTES DE VALIDACIÓN] |
| Consent settings | Cookie-category choices, decision method, policy version and timestamps | Remember privacy choices | Compliance with legal obligations and strictly necessary service operation (GDPR Arts. 6(1)(c) and 6(1)(f), LSSI Art. 22.2 exemption) | 12 months |
| Infrastructure and security | Requests may generate IP address, device, timestamp and diagnostic/security logs at the hosting or database layer | Deliver, monitor and secure the service | Legitimate interest in secure service operation (GDPR Art. 6(1)(f)) | Provider and business schedule [PLAZOS DE CONSERVACIÓN PENDIENTES DE VALIDACIÓN] |
The Business Lab table and secure submission function exist in a local versioned migration but were not present in the connected backend during this audit, so the current form reports that its secure request channel is not active and does not save an enquiry. This row describes the processing that will begin only after that migration is applied and tested. The project contains no public registration, public comments, payment checkout, active advertising, third-party analytics, behavioural profiling or automated decision-making. The newsletter database can record subscriptions, but no email-delivery provider is connected and the interface does not claim that messages have been sent.
3. Required and optional information
Newsletter email and consent are required to join the list. Fields marked optional in the Business Lab form may be omitted; the remaining fields are required to assess the enquiry. If required information is not supplied, that request cannot be saved or reviewed. Consent for newsletter marketing is separate from a Business Lab enquiry and is never required to submit that enquiry.
4. Recipients and processors
The application uses Lovable Cloud’s Supabase-compatible database, authentication and storage interfaces. Authorised administrators can access subscriber and Business Lab records according to role-based database policies. Google authentication is available only on the protected sign-in page and is contacted when an administrator actively chooses that option.
The processor identity, processing region, data-processing agreement, subprocessors and transfer mechanism must be verified before publication: [REGIÓN, DPA Y SUBENCARGADOS DE LOVABLE CLOUD PENDIENTES DE VERIFICACIÓN]. No data sale or routine disclosure to advertisers is implemented.
5. International transfers
The repository alone does not establish where Lovable Cloud or its subprocessors process data. No international-transfer claim is therefore made. The controller must review the provider contract, processing locations and applicable safeguards—such as an adequacy decision or Standard Contractual Clauses—before publishing a definitive statement. An administrator who elects Google sign-in is also subject to Google’s relevant privacy terms.
6. Retention
The code defines a 12-month lifetime for the local consent preference. Business retention periods for newsletter records, enquiries, accounts and infrastructure logs have not been approved and must not be invented: [PLAZOS DE CONSERVACIÓN PENDIENTES DE VALIDACIÓN]. Once approved, periods should be limited to what is necessary and include any legally required blocking or limitation period.
7. Your rights
Where applicable, you may request access, rectification, erasure, restriction, objection and portability, and you may withdraw consent at any time without affecting earlier lawful processing. Send a verifiable request to [CORREO DE PRIVACIDAD PENDIENTE]. The controller may request only the information reasonably needed to verify identity.
You may also lodge a complaint with the Spanish Data Protection Agency (AEPD), particularly after first contacting the controller about the exercise of your rights.
8. Security and confidentiality
The active data model uses Row Level Security and administrator-only read access for subscriber records. The pending Business Lab migration defines the same isolation for enquiry records, but it must be applied and tested before that form is activated. Protected routes, server-side validation and restricted media-storage policies are also defined. These controls reduce risk but no system can promise absolute security. Access should be reviewed periodically and production secrets must remain outside frontend code and repositories.
9. Children
The publication and Business Lab are aimed at business professionals, not children, and no child-specific service is implemented. If the controller becomes aware that data was collected from a child without a valid basis, it should be removed. Spanish law generally permits consent-based processing from age 14, subject to exceptions and any other legal requirements applicable to the activity.
10. Data origin and automated decisions
Personal information is obtained directly from the person who submits a form or from an authorised administrator during sign-in. The audited code does not make decisions with legal or similarly significant effects solely by automated processing and does not create behavioural profiles.
11. Changes and language
This policy must be updated before a new processor, email provider, analytics service, advertising platform, payment flow, public account system or materially different purpose is activated. The current site is English-only. No translated legal version or prevailing language has been approved; Spanish legal review should decide that point before multilingual publication.