Privacy policy
Last updated: 4 September 2026
This policy explains what personal data I process when you use ferrerponseti.com, why, who I share it with and what you can require from me. It follows Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
1. Data controller
- Controller: Pau Ferrer Ponseti
- Tax ID (NIF): ES416027737M
- Registered address: Carrer de Torroella, 2, 1A, 17200 Palafrugell, Girona, España
- Contact and privacy email: pau@ferrerponseti.com
No data protection officer is appointed: the activity does not meet any of the criteria in Article 37 GDPR. Privacy enquiries are handled at the address above.
2. What data I process and where it comes from
- What you send through the contact form: name, email address, company or website and the message itself. Required fields are the minimum needed to reply.
- What you write by email or LinkedIn: whatever data you choose to include.
- Browsing data: cookie identifiers, IP address, device, browser, pages viewed and traffic source. Only if you accepted the relevant cookies.
- Billing data, if we end up working together: company name, tax ID, registered address and payment details.
I do not buy databases, do not profile you with legal effects, do not make automated decisions about you and do not process special categories of data. The calculators in the resources section run entirely in your browser: the figures you enter are never sent to a server.
3. Purposes, legal bases and retention
| Purpose | Legal basis | Retention |
|---|---|---|
| Answering your enquiry and preparing a possible proposal | Art. 6(1)(b) GDPR: pre-contractual steps at your request | 2 years from the last contact, unless a contract begins |
| Delivering and managing contracted services | Art. 6(1)(b) GDPR: performance of a contract | Duration of the relationship plus 4 years for potential claims |
| Invoicing and accounting or tax obligations | Art. 6(1)(c) GDPR: legal obligation | 6 years (Spanish Commercial Code) and 4 years (General Tax Law) |
| Measuring site usage to improve content and performance | Art. 6(1)(a) GDPR: your consent in the cookie banner | Up to 14 months in Google Analytics 4; 1 year in Microsoft Clarity |
| Measuring ad campaign performance and remarketing | Art. 6(1)(a) GDPR: your consent in the cookie banner | Between 90 days and 2 years depending on the cookie, see the cookie policy |
| Sending clients information about similar services | Art. 6(1)(f) GDPR and Art. 21.2 LSSI: legitimate interest in the commercial relationship | Until you object or unsubscribe |
Where the basis is consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal. For cookies, simply open the preferences panel.
4. Who else sees your data
I do not sell or trade your data. I share it only with the providers I need to run the service, each bound by a data processing agreement under Article 28 GDPR:
| Provider | What for | Location and safeguards |
|---|---|---|
| Cloudflare, Inc. | Site hosting, CDN and attack protection | United States, under EU Standard Contractual Clauses |
| Formspree, Inc. | Receiving and delivering contact form submissions | United States, under EU Standard Contractual Clauses |
| Sanity AS | Content management system (stores no visitor data) | Norway (EEA) and United States, under EU Standard Contractual Clauses |
| Google Ireland Ltd. | Web analytics (Google Analytics 4) and campaign measurement (Google Ads) | Ireland, with transfers to the US under the EU-US Data Privacy Framework |
| Microsoft Ireland Operations Ltd. | On-site behaviour analysis (Microsoft Clarity) | Ireland, with transfers to the US under the EU-US Data Privacy Framework |
| Meta Platforms Ireland Ltd. | Ad campaign measurement and audiences (Meta pixel) | Ireland, with transfers to the US under the EU-US Data Privacy Framework |
| Email service provider | Running the professional mailbox where I receive and answer your messages | European Union or United States with adequate safeguards |
Your data may also be disclosed to the tax authority, banks or an accountant where a legal or accounting obligation requires it.
Google Ads enhanced conversions
If you accept marketing cookies, the Google Ads tag reads the email address you type into the contact form, applies a SHA-256 hash to it inside your own browser and sends only that result to Google. Your email address in the clear never leaves your device this way.
Google matches that hash against the account data it already holds so the conversion can be attributed to the campaign that produced it. This is the feature Google calls enhanced conversions. It exists to measure which ads work, not to tell me more about you than the form already does.
Legal basis: your consent (Art. 6(1)(a) GDPR), the same consent you give by accepting the marketing category. Reject it and the tag is never loaded, so no hash is ever sent. You can withdraw consent at any time from the cookie preferences panel.
5. International transfers
Some of the providers above process data outside the European Economic Area, mainly in the United States. Those transfers rely on the EU-US Data Privacy Framework adequacy decision or, failing that, on the European Commission's Standard Contractual Clauses, together with additional technical measures such as encryption in transit.
6. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability at any time, and withdraw any consent given. You can also object to receiving commercial communications.
Write to pau@ferrerponseti.com stating which right you want to exercise. I will reply within one month. I may ask you to prove your identity if I have reasonable doubts about who is making the request.
If you believe your request was not handled properly, you can lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid, www.aepd.es).
7. Security
The site is served entirely over HTTPS. I apply technical and organisational measures proportionate to the risk: restricted access to mailboxes and dashboards with two-step verification, least-privilege access at providers, and periodic access reviews. No system is infallible, but I handle your data the way I expect mine to be handled.
8. Minors
The site is aimed at professionals and companies. I do not knowingly collect data from children under 14. If I find I have received a minor's data without their guardians' consent, I will delete it.
9. Changes to this policy
If I change providers, purposes or legal bases, I will update this page and its revision date. Where the change affects consent-based processing, I will ask you again.