Privacy
Privacy Policy
Information on the processing of personal data, under Regulation (EU) 2016/679 and Spanish Organic Law 3/2018 of 5 December.
1. Data controller
In fulfilment of the duty to inform laid down in Article 13 of Regulation (EU)
2016/679 of the European Parliament and of the Council of 27 April 2016, the
General Data Protection Regulation (hereinafter, the “GDPR”), and in Spanish
Organic Law 3/2018 of 5 December on the Protection of Personal Data and
guarantee of digital rights (hereinafter, the “LOPDGDD”), the User is informed
that the controller of the personal data collected through the website
jakobsaalfrank.com (hereinafter, the “Website”) is Jakob Saalfrank, of
Barcelona, Spain, email address
contact@jakobsaalfrank.com.
No Data Protection Officer has been appointed, none of the circumstances set out in Article 37 of the GDPR being present. The address given above deals with any matter concerning personal data.
2. Data processed and purposes
The Website is personal and informational in nature. It carries no forms, it allows no user registration, and it markets no products or services. Only the processing operations described below are carried out.
2.1. Browsing the Website. The Website is hosted on Cloudflare infrastructure, which records every request in its server logs: the User’s IP address, the date and time, the page requested and the browser type. An IP address constitutes personal data, which is why the User is informed of this. That record is created on the server and not on the User’s device. The purpose is to deliver the Website, to keep it available, and to protect it against attack and abuse.
2.2. Selection of the language version. When the home page is accessed, the server reads the language preference sent by the User’s browser and the country Cloudflare infers from the connection, for the sole purpose of offering the version of the Website in the corresponding language. That information is used at the moment of the request and is not stored, whether on the server or on the User’s device.
2.3. Communications addressed to the Owner. The addresses published on the
Website are ordinary mailto: links. Where the User sends a message, the data
processed are those the User chooses to include in it, typically a name, an
email address and the reason for writing. The purpose is to read and answer
that communication.
3. Legal basis
The processing described in sections 2.1 and 2.2 rests on the Owner’s legitimate interest in operating, keeping available and protecting his own website, and in presenting it in the User’s language, under Article 6(1)(f) of the GDPR.
The processing described in section 2.3 rests on steps taken at the request of the data subject prior to entering into a contract, under Article 6(1)(b) of the GDPR, and, where the communication bears no relation to a possible contractual relationship, on the Owner’s legitimate interest in answering those who write to him, under Article 6(1)(f) of the GDPR.
4. Retention period
Server logs are retained by Cloudflare for a short period under its own retention policy. The Owner does not download them, does not store them and does not analyse them.
Email correspondence is retained for as long as the communication retains its purpose and, thereafter, for the applicable limitation periods. Correspondence with no continuing purpose is deleted.
5. Recipients of the data
Personal data are not disclosed to third parties save where the law so requires. The following entities act as processors, on the Owner’s behalf and on his instructions:
- Cloudflare, which hosts the Website and retains its server logs.
- Google, which provides the Owner’s email service through Google Workspace.
No advertising activity is carried on, no data are shared for third-party marketing purposes, and no personal data are sold.
6. International data transfers
The entities named in the preceding section are, or are owned by, companies in the United States, so the data may be processed there. Those transfers are covered by the Standard Contractual Clauses approved by the European Commission and, where the provider is certified, by the EU-US Data Privacy Framework. The User may request a copy of the applicable safeguards at the address given in section 1.
7. Cookies and storage on the device
The Website uses no cookies, whether its own or those of third parties, stores no information on the User’s device and accesses no information already stored on it, whether through local storage, session storage or any equivalent technique. The circumstances contemplated in Article 22.2 of Spanish Law 34/2002 of 11 July on Information Society Services and Electronic Commerce therefore do not arise, so no consent is obtained and no notice to that effect is displayed.
The Website carries no analytics tools, no tag managers, no advertising pixels and no session recording. Typefaces and images are served from the Website’s own domain.
8. Third-party content loaded at the User’s request
The home page may display posts from LinkedIn, Instagram and X. That content is not loaded together with the page. The User sees a notice and a button, and nothing is requested from those platforms until the User presses it.
Where the User presses the button, the platform concerned will receive the User’s IP address, browser details and the fact that the User was on this page, and may store information on the device under its own terms. That processing is carried out by each platform as controller, and not by the Owner. Each notice also carries an ordinary link to the corresponding profile.
9. Automated decisions and profiling
No profiling of the User is carried out, and no decisions are taken based solely on automated processing which produce legal effects concerning the User or similarly significantly affect the User.
10. Security measures
The Website is served exclusively over an encrypted connection. It has no database, no private area and no registration system, so no account of the User’s exists. Personal data sent by the User reside in the Owner’s email accounts, which are protected by access control and multi-factor authentication.
11. Rights of the data subject
The User may exercise the rights of access, rectification, erasure, restriction of processing, objection and data portability, and may withdraw consent given where the processing rests on it, by sending a request to contact@jakobsaalfrank.com with “Data protection” in the subject line. A request is answered within one month of receipt and there is no charge for exercising these rights.
The User may also lodge a complaint with the Agencia Española de Protección de Datos, the supervisory authority competent in Spain, at C/ Jorge Juan, 6, 28001 Madrid, and at www.aepd.es. Approaching the Owner first is not a precondition.
12. Minors
The Website is not directed at children under fourteen, the age of digital consent in Spain under Article 7 of the LOPDGDD, and no data are knowingly collected from persons below that age.
13. Amendments to this policy
This policy is amended when the processing it describes changes, and the date of last update shown at the foot changes in the same act.
Last updated: . The Spanish version of this policy is the authoritative one.