Privacy policy
What we do with what you type into the contact form, and with what is collected inside the application.
Last updated: 3 September 2026
Who handles your data
| Controller | Daniel Ruiz Gómez |
| Tax ID (NIF) | 47538109F |
| Address | Camino Los Sifones 19, 41580 Casariche (Seville), Spain |
| info@buildyo.es |
No data protection officer has been appointed, as none of the cases in Article 37 GDPR apply.
This is a translation for convenience. The Spanish version is the binding one, and it prevails in the event of any discrepancy.
What data we handle, and where it comes from
What you type into the contact form:
- Name and company (required)
- Email address (required)
- Phone and website (optional)
And one more thing you do not type: a technical fingerprint of your connection, to stop the form from being submitted automatically. We do not store your IP address, but a code derived from it with an irreversible function and a secret key, which cannot be turned back. It does not identify you, does not track you, is not combined with anything else, and is deleted after 24 hours. The basis for handling it is our legitimate interest (Article 6(1)(f) GDPR) in keeping the form usable for the people who need it.
No data is collected by any other means on these pages: there is no analytics and there are no tracking pixels. The form includes a hidden field that helps detect automated submissions and collects no data about you. We do not handle special categories of data — health, beliefs, biometrics — and we do not ask you for any.
What we use it for
For one thing only: getting in touch and showing you Buildyo, because that is what you asked for by sending the form. Specifically, replying to you, arranging a demonstration, and carrying on whatever sales conversation follows.
It is not used to send you third-party advertising, and it is neither shared nor sold to anyone.
On what legal basis
Your consent (Article 6(1)(a) GDPR), given by ticking the box on the form. It is freely given and can be withdrawn: write to us at any time, and that will not affect what was processed before you withdrew it.
If the conversation moves towards a contract, further processing also rests on taking steps at your request prior to entering into it (Article 6(1)(b)).
How long we keep it
One year from the last contact, if it does not lead to becoming a customer. After that it is deleted.
If you do become a customer, your data is then handled as part of that contractual relationship and kept for as long as it lasts, plus the periods required by tax and commercial law.
Once you are a client: accepting the contract
This policy does not cover these pages alone. Inside the application, when an account holder accepts the Terms of Service and their Annex I, we store — besides who accepted and when — the IP address and the browser it was done from.
They serve one purpose only: being able to prove that the acceptance happened and who made it. The lawful basis is our legitimate interest (Article 6.1.f GDPR) in being able to evidence the contract between us. They are used for nothing else: no analytics, no profiling, no tracking.
They are kept for as long as the contractual relationship lasts, plus five years — the limitation period for contractual claims in Spain. After that they are deleted.
What a developer enters into the application about its buyers is not covered here: for that data the developer is the controller and we are the processor, and what governs it is the Data Processing Agreement they accept on the way in.
Who else sees it
Nobody who does not need to. The providers involved, as processors and only in order to provide their service:
| Provider | What for | Where it is |
|---|---|---|
| Supabase | The database where the form is stored | European Union (Paris) |
| Vercel | Hosting for this site | United States, served from a global network |
| Google Workspace | The email we reply to you from | European Union / United States |
| Resend | The internal notification we receive when you submit the form | United States |
A data processing agreement under Article 28 GDPR is in force with all four. There is no other disclosure: barring a legal obligation, your data does not leave there.
Transfers outside the European Economic Area
Some of the providers above are US companies. Where that involves an international transfer, it relies on the standard contractual clauses approved by the European Commission and, where applicable, on the EU-US Data Privacy Framework adequacy decision for participating providers.
Your rights
You may exercise, free of charge and at any time:
- Access: find out what we hold about you.
- Rectification: correct anything that is wrong.
- Erasure: have it deleted.
- Objection and restriction of processing.
- Portability: take it away in a machine-readable format.
- Withdraw consent, as set out above.
How: write to info@buildyo.es saying which right you are exercising. We may ask for a copy of an identity document, purely to make sure it is you and not somebody else asking for your data.
If you believe your request was not handled properly, you may complain to the Spanish Data Protection Agency (www.aepd.es), C/ Jorge Juan 6, 28001 Madrid.
Automated decisions
No automated decisions are made about you, and no profiling is carried out.
Changes to this policy
If it changes, the new version is published here with its date. If the change affects something substantial about how we handle your data, anyone affected is told.