01Data controller
Controller: Carlos García Álvarez (trading as Velycio). Tax ID (NIF): 45549258N. Address: Carrer Barcelona 33, 3rd floor door 1, Girona, Spain.
Privacy contact: info@velycio.com. No data protection officer has been appointed, as none of the circumstances in Article 37 GDPR or Article 34 LOPDGDD apply.
02What data we handle and where it comes from
Contact details you provide in the website forms: name, email address, company or brand (or professional profile if you apply as a specialist) and the content of your message.
Diagnosis or chat data, when you use them: your shop URL, sales channels, questionnaire answers and the conversation held.
Technical browsing data linked to cookies and similar technologies: IP address, device identifier, pages viewed and traffic source.
We never ask for payment details, login credentials for your platforms or special categories of data (health, beliefs, biometrics). If you send them on your own initiative, we will delete them.
03What we use your data for
Handling your request, answering questions and preparing the proposal or diagnosis you ask for.
Managing the pre-contractual and contractual relationship, including invoicing and meeting tax and accounting obligations.
Assessing applications from specialists who want to join the agency's network.
Maintaining and improving the site: security, preventing form abuse and measuring aggregate usage.
Sending you commercial updates about our services only where you have given separate consent or where there is a prior contractual relationship for similar services. You can unsubscribe at any time.
04Legal basis for each purpose
Consent (art. 6(1)(a) GDPR): contact forms, diagnosis, applications, non-essential cookies and marketing messages.
Performance of a contract or pre-contractual steps (art. 6(1)(b) GDPR): preparing quotes and delivering the services you contract.
Compliance with legal obligations (art. 6(1)(c) GDPR): keeping invoices and tax, company and anti-money-laundering records where applicable.
Legitimate interests (art. 6(1)(f) GDPR): site security, fraud prevention and commercial messages to clients about comparable services, with a prior balancing test and a right to object.
Withdrawing consent is as easy as giving it: email info@velycio.com. Withdrawal does not affect the lawfulness of earlier processing.
05How long we keep it
Enquiries that don't lead to a commercial relationship: up to 12 months from the last contact, then deleted.
Clients: for the term of the contract and, once it ends, the limitation period for related claims (generally 5 years; 6 years for accounting records and 4 years for tax obligations).
Specialist applications: up to 12 months, unless you expressly consent to a longer period for future projects.
Data linked to cookies: the period stated for each type in the cookie policy.
06Who else sees your data
Suppliers acting as processors under a contract signed in line with art. 28 GDPR: site hosting and deployment, email and office software, web analytics, AI tools powering the site assistant, and our accountants or tax advisers.
Processors currently involved: Vercel Inc. (website hosting and delivery), Google Ireland Ltd. (corporate email, through which contact requests are received) and OpenRouter Inc. (processing of the website assistant's conversations). Each one processes data solely to provide its service and under our instructions.
Public authorities and courts where there is a legal duty to disclose.
We never sell or share your data with third parties for advertising purposes.
Vercel Inc. and OpenRouter Inc. are based in the United States. These transfers rely on the standard contractual clauses approved by the European Commission and, where applicable, on the EU-US Data Privacy Framework. You can request a copy of these safeguards by writing to info@velycio.com.
07Your rights
You can exercise your rights of access, rectification, erasure, restriction of processing, objection, portability and not to be subject to solely automated decisions.
Email info@velycio.com stating which right you are exercising. If we cannot identify you with confidence we will ask for proof of identity. We reply within one month, extendable to two if the request is complex.
Exercising these rights is free, except for manifestly unfounded or excessive requests.
08Complaints to the supervisory authority
If you believe we haven't handled your request properly, you can complain to the Spanish Data Protection Agency: C/ Jorge Juan 6, 28001 Madrid, or through its online office at www.aepd.es.
Before that, we'd appreciate an email: almost everything gets sorted in one reply.
09Security and changes to this policy
We apply technical and organisational measures proportionate to the risk: encryption in transit (HTTPS), role-based access control, two-factor authentication on critical tools and incident logging.
If we change this policy substantially we will publish the new version with its update date and, where consent is the legal basis, we will ask you again.