Legal
Privacy Policy
This document explains, in plain language, what personal data this website processes, for what purpose, for how long, and what rights you have. It does not replace professional legal advice and does not, by itself, guarantee compliance with any regulation.
This English version is provided for informational purposes. In the event of any discrepancy, the Spanish version shall prevail.
1. Data controller
Data controller: Raúl Romero Agüera, Tax ID (NIF) 23312704L, with business address at Calle Milán, n.º 3, 30319 Cartagena, Murcia, Spain. Contact email for enquiries and the exercise of rights: info@raulromero.es.
- Trade name: Raúl Romero — Web & Growth.
- Website: https://raulromero.es
- Legal form: sole trader (self-employed individual, "autónomo" under Spanish law), with no company or agency behind it.
- Country of activity: Spain.
- No Data Protection Officer has been appointed.
2. Personal data processed
The only personal data processed by this website is the data you voluntarily enter in the contact form:
- Name (required).
- Company or project (optional).
- Email address (required).
- Type of service you're interested in (required).
- Estimated budget (optional).
- Message or project description (required).
When the form is submitted, the following is also recorded automatically: the date and time of submission, an internal status for managing the request (for example, "new", "read" or "replied"), and the source of the contact (currently always "web", as it is the only form channel, distinguishing between the Spanish and English versions of the site).
As a security measure against automated submissions (spam), the server temporarily keeps, in memory, a counter of submissions per IP address for a few minutes, to limit the number of consecutive requests. This counter is not stored in any database, is not linked to your name or message, and disappears when the server restarts.
This website does not use cookies or tracking technologies, so no browsing, behavioral or usage-profile data is collected (see the Cookies Policy for more detail).
3. Source of the data
All data comes directly from you, as the data subject, through the contact form. No personal data is obtained from third-party sources or external databases.
4. Purposes of processing
Data from the form is used exclusively to:
- Respond to your enquiry.
- Assess the project or service you're requesting.
- Prepare and send you a proposal or quote.
- Carry out the pre-contractual steps you yourself request by getting in touch.
The general contact form does not subscribe you to any newsletter or marketing list. If sending commercial communications is introduced in the future, a separate, optional, unchecked checkbox will be provided, with its own information and legal basis, independent of this purpose.
5. Legal bases
- Contact form: application of pre-contractual measures at the request of the data subject (Article 6.1.b GDPR). It is not based on your consent, because its purpose is to respond to something you yourself have requested.
- Spam prevention (temporary submission counter): legitimate interest of the controller in protecting the service against abuse (Article 6.1.f GDPR).
6. Mandatory nature of the data
Name, email, service type and message are required: without them, the form cannot be submitted or, therefore, answered. Company/project and estimated budget are optional.
7. Retention periods
- If your enquiry does not lead to a contractual relationship, data is kept for a maximum of 12 months from the last communication with you, unless it needs to be kept for longer to handle or defend against a claim.
- If a contractual relationship is established, data is kept for the duration of that relationship and, afterwards, for the legal periods applicable to the resulting responsibilities and obligations (for example, tax or commercial law).
- Where there is a legal obligation to retain certain data, it will be blocked and used only to comply with that obligation, with no other use.
- Once the above periods have elapsed, data is securely deleted or anonymized.
As of today, there is no automated process for deleting old requests in Supabase yet: cleanup is carried out through periodic manual review by the controller, until an automated mechanism is implemented.
8. Recipients and data processors
Your data is never sold or shared with third parties for commercial purposes. It is only accessed by the technology providers strictly necessary to host the website and manage the form, acting as data processors (Article 28 GDPR):
- Supabase — stores the database containing contact requests.
- Vercel — hosts and runs the website and its server functions.
- Resend — sends the controller an email notification every time a request is received, so it can be answered sooner. Resend processes the name, email, service, budget and message from the request for this purpose; you can consult its privacy policy.
No analytics, advertising or third-party CAPTCHA tool is used on this website: the anti-spam protection is a self-contained mechanism (see section 2).
9. International transfers
The Supabase project and the Vercel execution region used by this website are configured by the controller in Ireland (European Union). Even so, both providers are companies with international infrastructure and support, so data may be processed or accessed outside the European Economic Area:
- Vercel Inc. is headquartered in the United States. Under its Data Processing Addendum, it may transfer data to its sub-processors (which include infrastructure on AWS, Azure and Google Cloud) outside the EEA when necessary, safeguarded with the EU Standard Contractual Clauses (2021) and the UK IDTA. You can consult its Data Processing Addendum and its privacy policy.
- Supabase contractually guarantees that, when the customer specifies a region (such as Ireland, in this case), data is stored and processed primarily in that region. However, its public documentation also references infrastructure and support in the United States, with safeguards through Standard Contractual Clauses. You can consult its Data Processing Addendum, its sub-processor list and its privacy policy.
- Resend (Plus Five Five, Inc.) is headquartered in the United States and, per its own privacy policy, may transfer and maintain information on servers located in the United States. You can consult its privacy policy.
In all cases, any transfer outside the EEA is carried out under Standard Contractual Clauses approved by the European Commission, as a safeguard mechanism recognized by the GDPR.
10. Rights of data subjects
You can exercise, at any time, your rights to:
- Access your personal data.
- Rectify inaccurate data.
- Erasure of your data.
- Object to processing.
- Restrict processing.
- Portability, where applicable.
- Withdraw consent at any time, for processing based on it, without affecting the lawfulness of processing carried out before its withdrawal.
You can exercise these rights by writing to info@raulromero.es. The request should allow you to be identified and the right you wish to exercise to be understood; additional identification information will only be requested when it is genuinely necessary and proportionate.
11. Complaints to the Spanish Data Protection Agency
If you believe that the processing of your data does not comply with applicable regulations, you can file a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos): www.aepd.es.
12. Security
Reasonable technical and organizational measures are applied to protect your data: the form is validated both in the browser and on the server, the connection uses HTTPS, and public access to the database is restricted through Row Level Security policies that only allow inserting new requests, never reading, modifying or deleting them from the browser. No security measure is one hundred percent infallible, so absolute security cannot be guaranteed.
13. Minors
This website is not specifically aimed at minors. If you are a minor, please do not provide us with personal data without the authorization of your parent or legal guardian. If we become aware that a minor's data has been provided without such authorization, we will delete it as soon as we are made aware.
14. Automated decisions and profiling
No decisions are made based solely on automated processing, and no profiles are built from your data.
15. Changes to this policy
This policy may be updated when the services, providers or processing activities described in it change. Relevant changes will be reflected on this same page, along with its update date.
16. Last updated
August 10, 2026.
