Privacy Policy
Last updated: 25 July 2026
This Privacy Policy explains how Kalebtec Studio S.C handles personal data in connection with the Kalebtec Websites service at websites.kalebtec.com. It's written to comply with the EU General Data Protection Regulation (GDPR) and Spain's Organic Law 3/2018 (LOPDGDD). We keep it short and honest: we collect little, we don't sell your data, and we tell you exactly who touches it.
01 — Who is responsible for your data (Data Controller)
The data controller is:
- Kalebtec Studio S.C (a Spanish Sociedad Civil), operated by Rowin Kaleb Hernández Fagúndez and Marianela Elizabeth Rodríguez Maestre.
- CIF/NIF: J26989384
- Registered address: Avenida do Alcalde Portanet, 20, 4º J, Vigo, Pontevedra 36210, Spain
- Email: hello@kalebtec.com
We haven't appointed a Data Protection Officer, as our processing doesn't meet the thresholds that make one mandatory under Article 37 GDPR. For any privacy question, contact us at hello@kalebtec.com.
02 — What data we collect, why, and our legal basis
We only collect what we need to answer you, take your order, and deliver your website.
- Contact details (your email, and name/company if you give them) — to reply to enquiries and manage your order. Legal basis: steps taken at your request and performance of a contract, Art. 6(1)(b); and our legitimate interest in responding to enquiries, Art. 6(1)(f).
- Enquiry / project content (your brief, requirements, messages) — to understand what you need and deliver the Service. Legal basis: Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interest.
- Phone calls and voicemail (your number, the date and time of the call, any message you leave, and our written note of what was discussed) — to handle enquiries and complaints on the telephone route the law requires us to publish. Legal basis: Art. 6(1)(b) contract or pre-contractual steps; Art. 6(1)(c) legal obligation where it is a complaint (TRLGDCU Arts. 21.2 and 21.3); Art. 6(1)(f) legitimate interests otherwise. We do not record calls and we use no third-party recording, transcription or call-management service: what we discuss on the phone we write down, and it becomes part of your order or complaint file under the same retention periods in section 05.
- Payment data — handled by Stripe. We receive confirmation of payment and limited transaction details (amount, date, last 4 digits, billing country). We never see or store your full card number. Legal basis: Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation for tax/accounting records.
- Client console account data (account credentials and identifiers, your order-tracking status, and any messages you exchange with us inside the client console) — to deliver and track your order. The client console is live today for our first customers, and opens more widely as we go. Legal basis: Art. 6(1)(b) performance of a contract.
- Website / hosting logs (IP address, browser and device type, pages requested, timestamps) kept by our hosting provider to run and secure the site. Legal basis: Art. 6(1)(f) legitimate interest in operating and securing our website.
- Analytics data — handled by Vercel Web Analytics, which is cookieless: it processes your IP address and user-agent on the server in hashed and aggregated form, with no cross-site tracking and no profile of you. Legal basis: Art. 6(1)(f) legitimate interest in measuring our site's audience.
- Product analytics, session replay and error reports — handled by PostHog, and only if you opt in. When you consent, PostHog uses cookies and local storage to record product analytics, session replays, heatmaps, and automatic error reports, so we can see how the site is used and fix what's broken. It is hosted in the EU (
eu.i.posthog.com), so there's no third-country transfer; text you type into forms is masked in session replays; and it runs only after you opt in. Legal basis: your consent, Art. 6(1)(a) GDPR (and Art. 22 LSSI for the cookies and similar storage).
We do not run advertising trackers, we do not build marketing profiles, and we do not collect special-category (sensitive) data. Our Vercel analytics are cookieless, aggregate-only, and always on; our PostHog product analytics (cookies plus session replay) run only if you opt in and stay off until then — see our Cookie Policy for the full picture.
Separately, when an order is confirmed we record it server-side as a conversion and revenue metric — order value, currency, tier and the transaction reference — using no cookies and no personal data; its legal basis is our legitimate interest, Art. 6(1)(f) GDPR, and it is separate from the consent-based PostHog analytics above, which stay opt-in.
03 — Who we share data with (recipients and subprocessors)
We don't sell or rent your data, and we don't share it for anyone's marketing. We rely on a small set of trusted providers ("subprocessors") to run the Service — each processing data only on our instructions, under a data-processing agreement, or as an independent controller for payments:
- Vercel — website hosting and delivery, plus cookieless traffic analytics (hosting logs, aggregate site traffic).
- PostHog — product analytics, session replay and error tracking, hosted in the EU, running only after your consent, under a data-processing agreement.
- Stripe — payment processing (payment and billing data). Stripe Payments Europe, Ltd. (Ireland) is the entity for EU customers.
- Cloudflare — private storage for the files you upload in your console, their filenames and the labels you give them, plus our retention audit records, which contain no personal data. It acts as our processor under a data-processing agreement; the storage is private, with no public address, and any transfer outside the EEA relies on the EU–US Data Privacy Framework with Standard Contractual Clauses behind it.
- Resend — sending the email we owe you: sign-in links, order confirmations, the notice that your directions are ready or your site is live, and the subscription confirmations and renewal notices the law requires (your email address and the content of the message). It acts as our processor under a data-processing agreement that binds from the moment we opened the account; it is US-based and stores email logs and metadata in the United States, so it relies on the Standard Contractual Clauses and the EU–US Data Privacy Framework.
- Google Workspace — the mailbox behind hello@kalebtec.com, so client correspondence you send or receive by email (your email address and message content). It acts as our processor under Google's data-processing terms, with Standard Contractual Clauses and/or an adequacy decision for any transfer outside the EEA.
We may also disclose data where the law requires it (for example, a valid legal request), or to establish or defend legal claims, and we may share data with professional advisers (such as our accountant or legal counsel) under confidentiality. If we ever bring on a new subprocessor, we'll update this list before or when they start.
04 — International data transfers
Our commitment is to EU hosting and data residency for the website and client data, and we use EU regions where the provider offers them. Some providers are, however, headquartered outside the EU (notably in the United States). Where personal data is transferred outside the European Economic Area, we rely on the safeguards required by Chapter V GDPR — the European Commission's Standard Contractual Clauses, and/or an adequacy decision or the provider's certification under the EU–US Data Privacy Framework — so your data keeps its EU-level protection.
You can request a copy of the relevant safeguards by emailing hello@kalebtec.com.
05 — How long we keep your data (retention)
Here is the whole of it, in a table, because a period nobody can find is not really published. Each row says what we keep, how long, what the clock starts from, and why that period and not a shorter one.
| What it is | How long | Counted from | Why that long |
|---|---|---|---|
| Files and answers you send us — your brief, your logo, photos, brand assets | 6 months | the end of your engagement: when you accept your site or cancel, or when your Care, Care+ or hosting subscription ends, whichever is later | We need them while we're working for you, and for a while after in case you ask for a change. After that we don't, so we delete them. If you're still subscribed the clock hasn't started — you're still working with us. |
| Files and answers on an order that goes quiet — the same brief, logo and brand assets, plus the review notes you sent us, on an order that is never accepted and never cancelled | 12 months | the last time you touched that order — editing your brief, uploading or removing a file, choosing a direction, sending review notes — and it starts again from zero each time. It also starts again if we write to you about that order, because while we are still trying to reach you your files are not abandoned. | We never treat your silence as acceptance, so an order you simply stop replying to never ends, and without this row your files would have no deletion date at all. Twelve months is longer than any window in which you could still pick the project up or ask for your money back. Reaching it deletes what you sent us and nothing else — it does not accept anything on your behalf, it does not close your refund, and it does not hand us your website. |
| Your sign-offs and consents — the exact wording you approved, when, and from which email | 7 years | the day your site is delivered and accepted | The law puts the burden of proving what you agreed on us, not on you (TRLGDCU Art. 98.9). A fault can appear up to 2 years after delivery and be claimed for 5 years after that, so 7 years is the outer edge of that window. It is a few lines of text, not your files. |
| Invoices, payments and tax records | At least 6 years | the close of the financial year the invoice belongs to (31 December) | This one we cannot shorten and cannot delete on request: the Código de Comercio (Art. 30) requires six years, and Spanish tax law adds its own period on top. Asking us to erase an invoice is the one request we have to refuse, and Art. 17(3)(b) GDPR is why. |
| Enquiries that never became orders | 12 months | the last time we were in touch | Long enough to pick a conversation back up a season later. After that there is no reason to still have your email, so we do not. |
| Sign-in artefacts — sessions, magic links, rate-limit counters | 31 days at most | the moment each one is created | Most are far shorter: a sign-in link lasts 15 minutes, a session 15 minutes, a stay-signed-in token 14 days. They expire on their own; nothing has to run for them to go. |
| Hosting and security logs | Up to 12 months | the moment of the request | Kept to run the site and spot abuse, then rotated out by our hosting provider. |
| The final backup after a subscription ends | 30 days | the day your subscription ends | So a rushed move cannot lose anything. Then it is deleted. |
What actually deletes it. A job runs every day, works out what has fallen due, and files a record of what it covered and of what it could not, so we can show you what happened rather than assert it. The private storage your files sit in expires them on its own, whether or not anything else runs, and that part is working today. The half of the job that removes the records themselves is built but not switched on yet; until it is, each run record says so and the deletion on the due date is a review we run and log. The periods in the table above bind us whichever of the two performs them. You can delete any of your files yourself, from your console, while your brief is still open. Invoices are deliberately excluded from all of that — see the row above.
You can also ask us to delete something before its period is up, and we do it — that is your right under Art. 17 GDPR and it is in section 06. The only things we will refuse are the two rows where the law requires us to keep them, and we will tell you which and until when rather than just saying no.
06 — Your rights
Under the GDPR and LOPDGDD, you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure ("right to be forgotten"), where the law allows.
- Restriction of processing in certain cases.
- Object to processing based on our legitimate interests.
- Data portability — receive your data in a portable format.
- Withdraw consent at any time where we relied on consent (this doesn't affect processing done before you withdrew).
To exercise any right, email hello@kalebtec.com. We'll respond within one month, as the GDPR requires (extendable by two further months for complex requests, in which case we'll tell you). We may need to confirm your identity first, so we don't disclose your data to someone else.
Right to complain: if you believe we've handled your data wrongly, we'd like the chance to put it right — but you can also lodge a complaint with the Spanish data protection authority, the Agencia Española de Protección de Datos (AEPD), at www.aepd.es, C/ Jorge Juan 6, 28001 Madrid. If you're in another EU country, you may complain to your local supervisory authority instead.
07 — How we protect your data (security)
We use appropriate technical and organisational measures to protect your data, including HTTPS/TLS encryption for everything transmitted between your browser and our servers, access controls, and reputable providers who maintain their own strong security. Payment card data is handled entirely within Stripe's PCI-DSS-compliant environment and never touches our own systems.
No system is perfectly secure, and we can't guarantee absolute security — but we take it seriously and keep our footprint small on purpose.
08 — Children
The Service is aimed at businesses and adults, not children. We don't knowingly collect data from anyone under 14 — the age of valid consent for information-society services under Spain's LOPDGDD (Art. 7), rather than the GDPR default of 16. If you believe a child has given us personal data, contact us and we'll delete it.
09 — Changes to this policy
We may update this policy from time to time. We'll post the new version here and update the "last updated" date. Material changes will be made clear. Please check back occasionally.
10 — Contact
Kalebtec Studio S.C — Kalebtec Websites. Email hello@kalebtec.com · Web websites.kalebtec.com. Full legal identification of the provider is in the Legal Notice (Aviso Legal).