Privacy Policy
Last updated: 23 July 2026
This Privacy Policy explains how Kalebtec Studio S.C handles personal data in connection with the Kalebtec Websites service at websites.kalebtec.com. It's written to comply with the EU General Data Protection Regulation (GDPR) and Spain's Organic Law 3/2018 (LOPDGDD). We keep it short and honest: we collect little, we don't sell your data, and we tell you exactly who touches it.
01 — Who is responsible for your data (Data Controller)
The data controller is:
- Kalebtec Studio S.C (a Spanish Sociedad Civil), operated by Rowin Hernandez and Mari Hernandez.
- CIF/NIF: J26989384
- Registered address: Avenida do Alcalde Portanet, 20, Vigo, Pontevedra 36210, Spain
- Email: hello@kalebtec.com
We haven't appointed a Data Protection Officer, as our processing doesn't meet the thresholds that make one mandatory under Article 37 GDPR. For any privacy question, contact us at hello@kalebtec.com.
02 — What data we collect, why, and our legal basis
We only collect what we need to answer you, take your order, and deliver your website.
- Contact details (your email, and name/company if you give them) — to reply to enquiries and manage your order. Legal basis: steps taken at your request and performance of a contract, Art. 6(1)(b); and our legitimate interest in responding to enquiries, Art. 6(1)(f).
- Enquiry / project content (your brief, requirements, messages) — to understand what you need and deliver the Service. Legal basis: Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interest.
- Payment data — handled by Stripe. We receive confirmation of payment and limited transaction details (amount, date, last 4 digits, billing country). We never see or store your full card number. Legal basis: Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation for tax/accounting records.
- Client console account data (account credentials and identifiers, your order-tracking status, and any messages you exchange with us inside the client console) — to deliver and track your order. This relates to our forthcoming client console. Legal basis: Art. 6(1)(b) performance of a contract.
- Website / hosting logs (IP address, browser and device type, pages requested, timestamps) kept by our hosting provider to run and secure the site. Legal basis: Art. 6(1)(f) legitimate interest in operating and securing our website.
- Analytics data — handled by Vercel Web Analytics, which is cookieless: it processes your IP address and user-agent on the server in hashed and aggregated form, with no cross-site tracking and no profile of you. Legal basis: Art. 6(1)(f) legitimate interest in measuring our site's audience.
We do not run advertising trackers, we do not build marketing profiles, and we do not collect special-category (sensitive) data. Our analytics are cookieless and aggregate only — see our Cookie Policy for the full picture.
03 — Who we share data with (recipients and subprocessors)
We don't sell or rent your data, and we don't share it for anyone's marketing. We rely on a small set of trusted providers ("subprocessors") to run the Service — each processing data only on our instructions, under a data-processing agreement, or as an independent controller for payments:
- Vercel — website hosting and delivery, plus cookieless traffic analytics (hosting logs, aggregate site traffic).
- Stripe — payment processing (payment and billing data). Stripe Payments Europe, Ltd. (Ireland) is the entity for EU customers.
- Fly.io — application hosting for the client console and order tracking (account and order-tracking data).
- Our email provider — client communications (your email address and message content), handled with EU processing or under Standard Contractual Clauses where any transfer outside the EEA is involved.
We may also disclose data where the law requires it (for example, a valid legal request), or to establish or defend legal claims, and we may share data with professional advisers (such as our accountant or legal counsel) under confidentiality. If we ever bring on a new subprocessor, we'll update this list before or when they start.
04 — International data transfers
Our commitment is to EU hosting and data residency for the website and client data, and we use EU regions where the provider offers them. Some providers are, however, headquartered outside the EU (notably in the United States). Where personal data is transferred outside the European Economic Area, we rely on the safeguards required by Chapter V GDPR — the European Commission's Standard Contractual Clauses, and/or an adequacy decision or the provider's certification under the EU–US Data Privacy Framework — so your data keeps its EU-level protection.
You can request a copy of the relevant safeguards by emailing hello@kalebtec.com.
05 — How long we keep your data (retention)
We keep data only as long as we need it:
- Enquiries that don't become orders — kept while we're in contact and deleted within 24 months of our last contact.
- Order and project data — kept for the duration of the engagement and a reasonable period after delivery to support you.
- Invoicing, payment and tax records — kept for the statutory periods required by Spanish tax and commercial law (generally up to 4–6 years — 4 years under the Ley General Tributaria, and up to 6 years under the Código de Comercio for accounting records).
- Hosting and security logs — kept for up to 12 months, then rotated out.
When a retention period ends, we delete or anonymise the data.
06 — Your rights
Under the GDPR and LOPDGDD, you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure ("right to be forgotten"), where the law allows.
- Restriction of processing in certain cases.
- Object to processing based on our legitimate interests.
- Data portability — receive your data in a portable format.
- Withdraw consent at any time where we relied on consent (this doesn't affect processing done before you withdrew).
To exercise any right, email hello@kalebtec.com. We'll respond within one month, as the GDPR requires (extendable by two further months for complex requests, in which case we'll tell you). We may need to confirm your identity first, so we don't disclose your data to someone else.
Right to complain: if you believe we've handled your data wrongly, we'd like the chance to put it right — but you can also lodge a complaint with the Spanish data protection authority, the Agencia Española de Protección de Datos (AEPD), at www.aepd.es, C/ Jorge Juan 6, 28001 Madrid. If you're in another EU country, you may complain to your local supervisory authority instead.
07 — How we protect your data (security)
We use appropriate technical and organisational measures to protect your data, including HTTPS/TLS encryption for everything transmitted between your browser and our servers, access controls, and reputable providers who maintain their own strong security. Payment card data is handled entirely within Stripe's PCI-DSS-compliant environment and never touches our own systems.
No system is perfectly secure, and we can't guarantee absolute security — but we take it seriously and keep our footprint small on purpose.
08 — Children
The Service is aimed at businesses and adults, not children. We don't knowingly collect data from anyone under 14 — the age of valid consent for information-society services under Spain's LOPDGDD (Art. 7), rather than the GDPR default of 16. If you believe a child has given us personal data, contact us and we'll delete it.
09 — Changes to this policy
We may update this policy from time to time. We'll post the new version here and update the "last updated" date. Material changes will be made clear. Please check back occasionally.
10 — Contact
Kalebtec Studio S.C — Kalebtec Websites. Email hello@kalebtec.com · Web websites.kalebtec.com. Full legal identification of the provider is in the Legal Notice (Aviso Legal).