ASTURAWEB / WEBSITE INFORMATION
Privacy policy
What happens to your data when you visit the website or contact us about a project.
Privacy enquiries
- Data controller
- Alex Aun
When you contact us
The project brief collects your name, email, language and answers for your chosen project: its type, goals and relevant context. Company, phone, current website, budget, timing and notes are optional. It also records the public source page without private parameters and a request identifier. We use this information to respond and take pre-contractual steps you request. It does not subscribe you to marketing, and these answers are not sent to analytics.
Netlify Forms receives and stores submitted enquiries and supports notifications to hola@asturaweb.com. Netlify provides hosting and form processing. A recorded enquiry does not, by itself, prove delivery of an email notification. While you prepare the brief, its draft stays in this tab until submission, deletion or expiry after 24 hours; saving a draft does not transmit it. Please do not include sensitive data.
The WhatsApp link opens an external service with an editable message. It does not send it automatically. WhatsApp’s own terms apply; you can choose email instead.
- Legal basis for each processing activity
- Responding to a project enquiry and preparing a proposal: pre-contractual steps at your request (GDPR Article 6(1)(b)). Other enquiries and service security: legitimate interests in answering communications and preventing abuse (Article 6(1)(f)). Optional analytics and advertising attribution rely on consent (Article 6(1)(a)). Legal obligations are handled under Article 6(1)(c).
When you use Astura Check
The diagnostic starts when you submit a public address. The server queries the page, certificate and three standard public files. Public RDAP services receive the domain for registration data; MDN HTTP Observatory and Cloudflare receive it for HTTP protections and DNS records. MDN retains a public check history. Do not submit addresses containing private information.
The application stores public technical results in Netlify Blobs and reuses recent ones to avoid repeated queries. It keeps a daily counter using an HMAC identifier calculated from the IP address and date: pseudonymisation, not guaranteed anonymity. The counter does not store or return the original IP. Expired entries are invalidated on access and a scheduled process removes old ones.
No account or email is required. Astura Check uses no AI, browser geolocation or fingerprinting. This describes the application, not technical logs retained by Netlify or external providers.
Hosting and external connections
Netlify hosts the site, processes the form and runs Astura Check. Connections expose technical data such as IP address, requested URL and connection details needed to provide and protect the service. Porkbun provides domain registration and DNS; it does not receive the brief. Google Meet is used only for arranged meetings and is not a physical address.
On site protection routes, Netlify may return the visitor’s IP address, request time and request identifier to that same visitor. This response is not stored in shared caches; the application does not create a visit database. It does not access the provider’s geolocation data or request the browser’s location.
Those screens also display, only in your browser, its language, browser and OS family, time zone and screen dimensions. The application neither sends these fields to a tracking service nor turns them into a persistent identifier.
Instagram, TikTok, WhatsApp and email only open when you use their links. No social feed, advertising pixel or external chat is embedded in the website.
Retention and providers
- Retention periods
- Enquiries are retained for as long as needed to answer them and follow up the requested proposal. Once an enquiry is closed, its necessity is reviewed and unnecessary copies, including those in the forms dashboard, are deleted. If a contract or retention obligation arises, access is restricted and only necessary records are kept for the applicable legal periods. Security logs are processed separately for their purpose; deleting a brief does not imply deletion of those logs.
- Email provider
- Netlify Forms handles form notifications to hola@asturaweb.com. Direct email remains available as an alternative.
- Messaging and enquiry management
- Email and scheduled video meetings, such as Google Meet. WhatsApp is an external option opened only at the visitor’s request.
- Hosting and technical logs
- Netlify: hosting, forms, functions and technical logs necessary to operate and protect the service. Access to enquiries is limited to the controller and providers needed to handle them.
- Processors and international transfers
- Netlify, Inc. processes form data as a processor, including in the United States and through its subprocessors. Its processing agreement incorporates standard contractual clauses for transfers that require them. You can consult the agreement and recipients below or request a copy of the safeguards at hola@asturaweb.com. Communication providers and optional Google services may involve transfers under their terms; the Cookie Policy describes those optional services.
Provider safeguards
Your rights
You may request access, rectification or deletion and, where applicable, restriction, objection or portability. You may withdraw consent-based processing. Write to us explaining what you need; we will only ask for the information necessary to handle your request.
You may also lodge a complaint with the Spanish Data Protection Agency.
If anything is unclear, let’s talk.
hola@asturaweb.com