Privacy policy
What personal data this website collects, why, and what you can do about it. In short: we only use what you send us to reply to you, and the site does not track you.
Last updated: Placeholder, To complete: date this policy was last updated
This page contains placeholders that must be completed and legally reviewed before launch.
1.Who is responsible for your data
#The data controller is the owner of the Neyroline website. The full owner details are in the legal notice.
- Controller
- Placeholder, To complete: full legal name of the owner or company
- Trading name
- Neyroline
- Tax ID (NIF/CIF)
- Placeholder, To complete: NIF or CIF
- Address
- Placeholder, To complete: registered address
- Phone
- +34 673 87 62 38
- Data protection officer
- Placeholder, To complete: confirm whether one is required; if not, remove this line
2.What data we collect
#We only collect what you choose to send us, plus the technical data needed to deliver the website.
When you use the contact form
The contact form asks for the following, and sends it to us by email:
- Your name
- Your email address
- Your company (optional)
- Your current website (optional)
- The type of project
- Your preferred timeline (optional)
- Your message
To limit abuse of the form, the server also keeps your IP address in its working memory to count recent submissions. It is not stored with your inquiry, is never written to disk and is cleared when the server restarts.
Please do not include sensitive information, such as health data, in your message.
When you email or call us
We receive the details you choose to share, such as your name, email address or phone number, and the content of your message.
When you visit the website
The server that delivers this website may automatically record technical data, such as your IP address, browser type, the pages requested and the time of each request. Placeholder, To complete: hosting provider: confirm which server logs it keeps and what they contain
What we do not collect
This website does not use analytics, advertising or tracking tools, marketing pixels or social media plugins. Its fonts are served from this website itself, so your browser does not contact Google Fonts or any other font service when you visit.
3.Why we use it and on what basis
#We use your data only for these purposes, each with its legal basis under the GDPR:
- Replying to a project inquiry
- Answering your message and, if you ask for one, preparing a proposal. Basis: taking steps at your request before entering into a contract (Article 6(1)(b) GDPR).
- Replying to other messages
- Answering questions that are not about a project. Basis: our legitimate interest in responding to people who contact us (Article 6(1)(f) GDPR).
- Keeping the website working and secure
- Using technical logs to deliver the website and protect it from abuse. Basis: our legitimate interest in running a secure website (Article 6(1)(f) GDPR).
- Legal obligations
- If you become a client, keeping the records that tax and accounting law requires. Basis: legal obligation (Article 6(1)(c) GDPR).
We do not sell your data, and we do not use it for automated decision-making or profiling. You do not have to give us any data, but without a way to contact you we cannot reply.
4.Who receives your data
#We do not share your data with anyone for their own purposes. To run this website and reply to you, we use service providers that process data on our behalf:
- Email delivery. Messages sent through the contact form are delivered to our inbox by an email delivery provider. Placeholder, To complete: confirm the provider (planned: Resend) and link its privacy policy
- Email inbox. Our mailbox is provided by Google (Gmail). Placeholder, To complete: confirm Google’s role and the terms that apply to the mailbox
- Hosting. Placeholder, To complete: hosting provider, its location and a link to its privacy policy
We may also disclose data where the law requires it, for example to public authorities or courts.
5.International transfers
#Some of the providers above may process data outside the European Economic Area (EEA). Any such transfer must be covered by a safeguard recognised by the GDPR, such as an adequacy decision of the European Commission or its standard contractual clauses.
Placeholder, To complete: list each provider that transfers data outside the EEA and the safeguard it relies on
6.How long we keep it
#We keep your data only for as long as we need it for the purpose it was collected for:
- Inquiries that do not lead to a project: Placeholder, To complete: retention period for inquiries that do not lead to a project
- Client records: for the duration of the project, then for as long as tax and accounting law requires. Placeholder, To complete: retention period for client records
- Server logs: Placeholder, To complete: retention period set by the hosting provider
When data is no longer needed, we delete it, or keep it blocked for as long as the law requires before deleting it.
7.Your rights
#Under the GDPR and the Spanish data protection law (LOPDGDD), you can:
- Access
- Ask for a copy of the personal data we hold about you.
- Rectification
- Ask us to correct data that is inaccurate or incomplete.
- Erasure
- Ask us to delete your data.
- Restriction
- Ask us to limit how we use your data.
- Portability
- Receive the data you gave us in a structured, commonly used format, or have it sent to another organisation.
- Objection
- Object to us using your data on the basis of our legitimate interests.
- Withdraw consent
- Where we rely on your consent, withdraw it at any time. This does not affect anything done before.
To use any of these rights, email us at contact.neyroline@gmail.com and tell us which right you want to exercise. We may ask you to confirm your identity. We will reply within one month, which the GDPR allows us to extend by two further months for complex requests. Exercising your rights is free.
Right to complain
If you think we have not handled your data properly, you can complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD) at www.aepd.es. We would appreciate the chance to put things right with you first.
9.Security
#This website is served over an encrypted connection (HTTPS). We limit access to your data to what is needed to reply to you, and we choose providers that apply appropriate security measures. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10.Changes to this policy
#We may update this policy when the website, our providers or the law change. The date at the top of this page shows when it was last updated. If a change is significant, we will say so clearly on this page.