Privacy Policy
In short: your form submission goes into our database — along with IP and user-agent, to filter spam. Analytics and ad tags do not load until you consent, and they stop as soon as you withdraw it. We don’t sell data.
Last updated date:
Who processes the data
The data controller for data submitted through the website is the Amiscon team. Mailing address: Av. d’Aragón, 30, 8th floor, 46021 Valencia, Spain. Contact address for any data-related questions and requests — [email protected].
The client contract is signed by the group legal entity that matches the project’s jurisdiction; its details are stated in the contract itself. This does not affect the processing of data received through the site: the controller is the team listed above.
We have not appointed a separate Data Protection Officer (DPO): under Art. 37 GDPR this is required for large-scale systematic monitoring or processing of special categories of data, and we do neither. The team handles data requests at [email protected], and a person replies, not an autoresponder.
What data is collected
Below is the full list. Not “including” and not “including, but not limited to”: if something is not in the table, it is not in the system either.
| Data | Where they come from | Are they required |
|---|---|---|
| Name, email address | Contact form fields | Yes — without them there’s no one and nowhere to reply |
| Phone or messenger | Contact form field | No, at your discretion |
| Task description | Contact form field | Yes — that is the point of the request |
| IP address, browser user agent | Set by the server when the form is submitted | Collected automatically, spam protection |
| Submission page, form fill time | Determined upon submission | Collected automatically |
| Ad click tags: gclid, fbclid, UTM, first page of the visit, referring site | From the page URL, if you came via an ad or tagged link | Only with your consent |
| Visit stats: pages viewed, referral source, device type, approximate region | Google Analytics | Only with your consent to analytics |
| Events for ad platforms: site visit and form submission | Meta Pixel, Google Ads | Only with your consent to marketing |
| Messages and attachments | Emails, calls, messenger messages | Whatever you choose to share with us |
| Web server logs: IP, time, page address, browser type | Standard hosting logs | Collected automatically |
We do not collect special categories of data under Art. 9 GDPR — health, views, origin — and we ask you not to send them in the task description.
The bottom three rows of the table work only with your consent. Until you respond to the banner, Google and Meta tags do not load on the page at all — not “they load but don’t set cookies,” but they are physically absent from the markup. You can verify this in a minute in developer tools, the Network tab.
Why this data is needed and the legal basis
| Why | What data | GDPR legal basis |
|---|---|---|
| Reply to your request, discuss the task, prepare a proposal | Name, email, phone, task description | Art. 6(1)(b) — steps at your request before entering into a contract |
| Handle correspondence and project work | Contacts, correspondence, project documents | Art. 6(1)(b) — performance of a contract |
| Filter out spam and automated form submissions | IP, user agent, time of submission | Art. 6(1)(f) — legitimate interest: without this, the form turns into a stream of junk and real requests get buried in it |
| Maintain site operations and security | Web server logs | Art. 6(1)(f) — legitimate interest |
| Understand how people use the site: which pages they read, where they leave | Google Analytics statistics | Art. 6(1)(a) — your consent to analytics cookies |
| Understand which ads bring customers, and stop showing them to people who have already reached out | Click tracking tags, Meta Pixel events, and Google Ads | Art. 6(1)(a) — your consent to marketing cookies |
| Meet accounting and tax record-keeping requirements | Data from executed contracts | Art. 6(1)(c) — legal obligation |
On legitimate interest for spam and security, we have to say it plainly: here we weighed our benefit against your privacy and decided in our favor. The balancing test came out like this. IP and user-agent do not reveal anything about you beyond what any server on the internet already sees; we keep them for a short time; the alternative is a CAPTCHA, which collects noticeably more about the visitor and loads a third-party script on every page load. If you disagree with this assessment, you have the right to object — see the section on rights.
We do not run mailings: there is no subscription on the website, and the address you leave in a request is not added to any mailing list.
How long the data is stored
| What | How much | Why so much |
|---|---|---|
| An inquiry that didn’t become a project | 24 months | People often come back with the same request a year later, and the message history saves them from explaining everything again |
| A request marked as spam | 90 days | No reason to keep it longer: in that time you can see whether the rejection was a mistake |
| IP address and user agent of the request | 90 days, then erased from the record | Needed to investigate spam, not for the request itself; the request continues without them |
| Documents and correspondence for completed projects | The period required by the accounting and tax laws of the contract country | Legal obligation; we are not allowed to reduce it |
| Referral tags in your browser | 90 days | Same as the Google Ads attribution window; deleted immediately when consent is withdrawn |
| Analytics and ad system cookies | From 3 to 24 months, the full list is in the cookie policy | The retention periods are set by Google and Meta; withdrawing consent stops their placement |
| Web server logs | The hosting provider’s retention period, usually a few weeks | Technical log, no longer needed after that |
| A record of your banner response | 12 months, then we’ll ask again | Indefinite consent stops being informed |
The timelines are not declarative: deletion of outdated requests and cleanup of IP and user-agent are handled by a scheduled server task, not a person relying on memory.
Before the deadline — at your request. There is one exception: what we must retain under accounting law is not deleted before its retention period ends, and we will say that directly in our reply rather than stay silent.
Who the data is shared with
We do not sell data or share it for someone else’s advertising. Access is limited to service providers without whom the website and email correspondence would not work. Full list:
| Who | Why | What data they see |
|---|---|---|
| Cloudflare | Site protection and page delivery; determines the country to show the price in a familiar currency | IP address, standard request data |
| The server hosting provider | Website hosting, API, and inquiry database | Everything stored on the server |
| Email provider | Email delivery: a notice to us and a confirmation to you | Email address, name, email content |
| Project management services: task tracker, repository, cloud storage | Project work — only if you become a client | Data required for the project |
| Vimeo | Showreel player — only if you clicked “Play” | IP and player request data, under their own terms |
| Google (Analytics, Ads) | Visit stats and ad performance measurement — only with your consent | Cookie identifier, IP, pages viewed, request event |
| Meta (Facebook, Instagram) | Measuring ad performance and showing ads — only with your consent | Cookie ID, IP, visit and form submission |
The first five are processors: they work under data processing agreements and may not use the data for their own purposes. Google and Meta, for their own products, act as independent controllers, and their own documents apply to their processing — we are responsible for what we transfer and for having your consent for the transfer.
A form submission along with the click ID may be sent to the ad dashboard as a conversion — so the platform learns to bring in similar customers. In that case, it sends the click identifier and the deal event, not your name, email, or task description: the ad system doesn’t need them, and we don’t share them.
Separately: data may be disclosed upon a mandatory request from a government authority if it is lawful and properly issued. We verify such a request, not comply with the first letter we receive.
Transfer outside the EEA
Some vendors from the table above are U.S. companies. Where processing goes beyond the European Economic Area, it relies on one of the mechanisms in Chapter V GDPR: an EU Commission adequacy decision (for U.S. companies — the EU–US Data Privacy Framework) or the EU Commission’s Standard Contractual Clauses.
In plain terms: your data does not go where you would have no rights left. If a provider falls outside reasonable bounds, we either move to standard contractual terms or change the provider.
How the data is protected
The measures are proportionate to the risk, as required by Art. 32 GDPR, and these are concrete steps, not a statement of intent:
- All website and API traffic uses HTTPS; there is no open HTTP.
- Access to the requests database is limited to employees who need it for their work, using named user accounts.
- The form is protected from automated submissions with a hidden honeypot field and a fill-speed check, not a third-party CAPTCHA that would collect more about you than we do.
- Resubmitting the form does not create a duplicate request: each submission has its own idempotency key.
- A request is saved to the database before emails are sent — so a mail provider rejection does not result in a silent loss of the submission.
- We do not ask for more data than needed: a phone number is optional, and the form’s internal fields do not go into the database at all.
If a breach does happen and it threatens your rights, we will notify the supervisory authority within 72 hours, as required by Art. 33 GDPR, and inform you if the risk is high. If you notice an incident before we do, email [email protected] — we’ll address it immediately.
Your rights
Under GDPR, you have the right to:
- get a copy of your data and see exactly what we have (Art. 15);
- correct inaccurate data (Art. 16);
- request deletion (Art. 17);
- restrict processing (Art. 18);
- object to processing based on legitimate interests — for example, to storing IP addresses for spam protection (Art. 21);
- receive your data in a machine-readable format and transfer it to another controller (Art. 20);
- Withdraw consent for analytics and ads in one click — with the “Cookie settings” button in the footer of any page. Withdrawal does not affect the lawfulness of processing before withdrawal, but it stops it going forward and clears the tags from your browser.
To exercise any right, email [email protected]. No separate form, registration, or explanation is required — an email from the address you previously gave us is enough.
We will respond within one month, as required by Art. 12(3) GDPR. If the request is complex and a month isn’t enough, we will notify you within the same period and state the new deadline — the rules allow an extension of up to two more months, and you can’t use it silently. The request is free of charge.
If the email does not come from the address used in the conversation, we will ask you to confirm your identity. This is not bureaucracy: giving data to someone other than the person who provided it is a data breach in itself.
Complaint to the supervisory authority
If you are not satisfied with our response, you have the right to contact a data protection supervisory authority. For our place of registration, this is the Agencia Española de Protección de Datos, aepd.es. You can also file a complaint with the authority in your EU country or where the alleged violation took place — it’s your choice.
We ask, but do not require, that you write to us at [email protected] first: most issues are resolved by email in a couple of days, while a complaint can take months. Contacting us is not a mandatory prerequisite for filing a complaint.
Automated solutions and profiling
We do not make decisions that produce legal or other significant effects for you and are based solely on automated processing (Art. 22 GDPR). Who sees an ad is not such a decision: it does not restrict you in any way.
This should be said plainly, not hidden behind general wording. If you agreed to marketing cookies, Google and Meta ad platforms assign you to audiences under their own rules — that is profiling, and they do it, not us. We do not build our own profiles, and we do not buy or sell lists. Refusing the marketing category stops this transfer; you can also adjust ad delivery on the platforms’ side, in your Google account and in Meta ad settings.
The only automation related to your request is spam filtering: a form submitted faster than a human can physically do it is flagged as spam. It is not deleted and remains visible in the admin panel, and an employee makes the decision. If your request still did not get a response, email us — we’ll handle it manually.
Children
The website is intended for company representatives and is not meant for children. We knowingly do not collect data from people under 16; if such data reached us by mistake, write to us — we will delete it.
Document changes
If the way we process data changes — analytics appears, a new data recipient is added, or a new entry is stored in your browser, — we will update this document and change the date at the top of the page. Material changes will be described as a separate item, not buried in the text.
Changes that affect what we asked your consent for do not take effect right away: we ask for consent again, and the old consent stops applying. We will not silently expand its scope.
Questions about the document
Email us at [email protected] — we’ll reply during business hours (Mon — Fri, 10:00 — 19:00 CET). Other ways to reach us are listed on contacts page.
Av. d’Aragón, 30, 8th floor, 46021 Valencia, Spain




