Privacy Policy
Last updated: 12 August 2025
1) Data Controller
RGSTACK — Roberto Gaspari
Canary Islands, Spain · [email protected]
2) What data we process
- Contact emails you send us (name, email, message content, attachments) — processed to reply to you.
- Technical logs collected by the hosting/server for security and diagnostics (e.g., IP address, date/time, URL, user-agent, HTTP status). No profiling.
We do not request special category data. Please avoid sending sensitive health, financial or ID numbers unless strictly necessary.
3) Purposes & legal bases (GDPR)
- Answering your requests — Art. 6(1)(b) performance of (pre-)contract, or 6(1)(f) legitimate interest to operate and respond.
- Security & diagnostics — Art. 6(1)(f) legitimate interest to protect the service and prevent abuse.
- Legal compliance — Art. 6(1)(c) where retention is required by law.
4) Retention
- Contact emails: for the time needed to handle your request and up to 24 months (or longer if a contract exists/starts).
- Server logs: typically 30–180 days, unless needed to investigate incidents or comply with law.
5) Recipients & processors
We may share data with trusted providers acting as processors only as necessary to run this site/services:
- Hosting/server (infrastructure and security).
- Email provider (to receive/send your emails).
- CDN/firewall (if used) for DDoS protection and availability.
These providers process data under contracts and follow GDPR safeguards.
6) International transfers
If providers are located outside the EEA, transfers occur using appropriate safeguards (e.g., Standard Contractual Clauses). Details available on request.
7) Your rights
You can request access, rectification, erasure, restriction, portability and object to processing, by emailing [email protected]. You also have the right to lodge a complaint with the Spanish Data Protection Authority (Agencia Española de Protección de Datos — AEPD).
8) Security
We apply reasonable technical and organizational measures (least privilege, updates, backups, network safeguards). No automated decision-making or profiling.
9) Children
Our services are intended for adults. We do not knowingly process children’s data.
10) Changes
We may update this policy; the latest version is always published on this page.
Contact
Email: [email protected]