Privacy
Privacy policy
This policy explains what happens to personal data on press42.com. It is written to meet Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD), and it describes what this site actually does rather than what a generic template would say.
Version 2.1 · Last updated
1. Who is responsible for your data
The data controller is:
- Alex Barrera (Press42), sole trader (empresario individual)
- Madrid, Spain
- Email: hello@press42.com
No Data Protection Officer has been appointed, because none of the conditions in Article 37 GDPR apply to this activity. Data protection questions go to the email address above and are handled personally.
2. What this site does not do
It is easier to describe the absences, and you can verify all of them from the page source:
- No advertising, no remarketing, no conversion pixels, no social media trackers.
- No enrichment of your details from third-party databases, and no scoring or ranking of visitors.
- No newsletter, no mailing list, and no marketing email. Writing to me does not subscribe you to anything.
- No web fonts loaded from third parties. Typefaces are served from this server, so visiting the site does not disclose your IP address to a font provider.
- Personal data is never sold, rented, or shared for anyone else's marketing.
There is one thing this site does do that earlier versions of this policy said it did not, and it would be dishonest to bury it. Google Analytics now measures which pages people read. It runs only if you press Accept on the cookie banner, it is switched off until you do, and it is described in full in sections 3.5 and 6. If you rejected it, or ignored the banner, it never loaded.
Apart from that, the only third-party code that runs in your browser is Google reCAPTCHA, and only on the contact page.
3. What is processed, and why
3.1 Contact form enquiries
- Data
- Your name, email address, the service you selected, your company if you fill that optional field, and the content of your message. The notification email also records the IP address the form was sent from, your browser's user-agent string, and the time of submission, so that abuse can be traced.
- Purpose
- Reading your enquiry, replying to it, and preparing a possible engagement.
- Legal basis
- Article 6(1)(b) GDPR: steps taken at your request before entering into a contract. The tick box on the form records that you were shown this policy; it is an acknowledgement, not the legal basis, so withdrawing it does not retroactively make the reply unlawful. Where an enquiry is not pre-contractual at all, the basis is Article 6(1)(f), my legitimate interest in answering people who write to me.
- Retention
- Twelve months from our last exchange if the enquiry does not lead to work, after which the message is deleted. If it does lead to work, for the duration of the engagement and then for the statutory limitation periods that follow it: four years for tax records (Article 66, Ley 58/2003), five years for personal actions (Article 1964, Código Civil), and six years for accounting documentation (Article 30, Código de Comercio).
- Where it is stored
- Nowhere on this website. There is no database and no admin panel. The form composes an email and sends it; your message then lives in an ordinary mailbox like any other email.
3.2 Email you send directly
- Data
- Whatever you choose to put in the email, plus the routing data every email carries.
- Purpose and legal basis
- Corresponding with you. Article 6(1)(b) or 6(1)(f) GDPR, on the same terms as section 3.1.
- Retention
- As in section 3.1.
3.3 Spam and abuse prevention
- Data
- Three mechanisms protect the form. Hidden fields and a timing check look only at the submission itself and involve no personal data. A rate limit stores a SHA-256 hash of your IP address, never the address itself, to count submissions. Google reCAPTCHA v3 collects your IP address, browser and device information, and interaction data, and returns a risk score.
- Purpose
- Keeping the contact form usable and preventing automated abuse of the mail server.
- Legal basis
- Article 6(1)(f) GDPR. My legitimate interest is in a working contact form. The data used is limited, kept briefly, and never used to identify or profile you, which is why that interest is not overridden by your rights. If you would rather not involve Google at all, email me directly instead; the address is in section 1 and reaches the same inbox.
- Retention
- The hashed IP counter expires ten minutes after it is written. reCAPTCHA data is retained by Google under its own policy.
3.4 Web server logs
- Data
- The web server records each request: IP address, date and time, the URL requested, the HTTP status code, the number of bytes served, the referring page, and the user-agent string.
- Purpose
- Operating the site, diagnosing faults, and investigating attacks. These logs are not read routinely.
- Legal basis
- Article 6(1)(f) GDPR: legitimate interest in a site that works and is not compromised.
- Retention
- A maximum of 30 days, after which logs are rotated and deleted.
3.5 Audience measurement, only with your consent
- Data
-
If you accept the cookie banner, Google Analytics 4 records the pages you view and when, the page or
search engine that referred you, your approximate location derived from your IP address at roughly city
level, your device type, browser, screen size, and language, and a randomly generated identifier stored
in a cookie so that several page views can be recognised as one visit. Google states that it does not
store IP addresses in Analytics: the address is used in transit to derive that coarse location and is
then discarded. One custom event,
generate_lead, fires when the contact form submits successfully and carries only which service you picked from the dropdown. Your name, email address, company, and message text are never sent to Google. - Purpose
- Seeing which pages are actually read and which are ignored, so that effort goes into the useful ones. This is aggregate curiosity about the site, not an interest in you individually.
- Legal basis
- Article 6(1)(a) GDPR: your consent, given by pressing Accept, and nothing else. Storing the cookies themselves additionally requires prior consent under Article 22.2 LSSI-CE, which is why the tag stays switched off until you act. Google Consent Mode is set to deny analytics storage by default, so the refusal is the starting state rather than something applied afterwards. You can withdraw at any time under section 6, as easily as you gave it, and withdrawal takes effect immediately.
- Retention
- User-level and event-level data expires in the Google Analytics property 14 months after your last visit. Aggregate reports (visit counts and similar totals that identify nobody) are kept indefinitely.
4. Who else sees your data
Three service providers process data on my behalf, each under a data processing agreement required by Article 28 GDPR. There are no others.
- Hetzner Online GmbH: Server hosting and infrastructure. Nuremberg, Germany (EEA). Privacy terms.
- Fastmail Pty Ltd: Email hosting and delivery of form submissions. Australia, with mail servers in the United States. Privacy terms.
- Google Ireland Limited: reCAPTCHA v3 spam protection on the contact page, and Google Analytics 4 audience measurement where you have consented to it. Ireland, with onward transfer to Google LLC in the United States. Privacy terms.
Beyond these, data is disclosed only where the law requires it: to a court, a public authority, or the police acting within their powers. If I ever need to instruct an accountant or a lawyer on a matter that involves your data, they are bound by their own professional confidentiality duties.
5. International transfers
This site is hosted in Germany, so serving the pages involves no transfer outside the European Economic Area. Two of the processors above do involve one:
- Fastmail is Australian and stores mail on servers in the United States. The transfer relies on Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914.
- Google may transfer reCAPTCHA data, and Analytics data where you have consented to it, to Google LLC in the United States. Analytics traffic from the EEA is collected through Google's European domains and servers first. Both transfers rely on the European Commission's adequacy decision of 10 July 2023 for the EU-US Data Privacy Framework, of which Google LLC is a certified participant, backed by Standard Contractual Clauses.
You can ask me for a copy of the safeguards that apply to either transfer, and I will send you what the providers publish.
6. Cookies and similar technologies
There are three things in this category, and no others.
6.1 Analytics cookies (refused unless you accept)
Accepting the banner lets Google Analytics set two cookies on this domain: _ga, which
distinguishes one browser from another, and _ga_ followed by the measurement stream ID, which
keeps session state. Both last up to two years unless you clear them. Until you press Accept they are not
set at all, because the tag starts in a denied state and the script that would write them does not run.
6.2 The record of your own choice
Your answer to the banner is kept in your browser's local storage under the key
press42-analytics-consent, holding the single word granted or denied. It
never leaves your device and is not readable by anyone else. This one is strictly necessary in the sense of
Article 22.2 LSSI-CE: without it the banner could not remember that you already answered, and would have
to ask on every page, so it does not itself require consent. Clearing your browser storage erases it, and
the banner will simply ask again.
6.3 reCAPTCHA, on the contact page only
When the contact page loads, Google reCAPTCHA is fetched from google.com and sets its own cookies in order to tell a person from a bot. Those cookies serve only that security function; they are not used to show you advertising on this site. Under Article 22.2 LSSI-CE, storage strictly necessary to provide a service the user has expressly requested does not require prior consent, and preventing the abuse of a form you have chosen to open falls within that exception. If you would prefer to avoid it entirely, do not open the contact page; emailing hello@press42.com reaches me exactly the same way.
6.4 Changing your mind
Withdrawal is deliberately as easy as consent, as Article 7(3) GDPR requires. The button below clears your stored answer and brings the banner back, and analytics stops immediately. Cookies already set by a previous acceptance are removed through your browser's normal settings, which no website can do on your behalf.
Checking your current setting…
7. Automated decision-making
There is one automated step, and I would rather name it than pretend otherwise. reCAPTCHA returns a score for each submission, and submissions below the threshold are refused. This is not a decision producing legal or similarly significant effects within the meaning of Article 22 GDPR: nothing is decided about you, and no record of the refusal is kept. It occasionally gets it wrong, usually for people on VPNs or older browsers. If it refuses you, email me directly and a human will read it.
No other profiling takes place.
8. Your rights
You can exercise all of the following, free of charge:
- Access (Art. 15): a copy of the personal data I hold about you.
- Rectification (Art. 16): correction of anything inaccurate.
- Erasure (Art. 17): deletion, unless a retention duty in section 3.1 still applies.
- Restriction (Art. 18): processing paused while a dispute is resolved.
- Portability (Art. 20): your data in a structured, machine-readable format.
- Objection (Art. 21): to anything based on legitimate interest, including the logging and anti-spam measures in sections 3.3 and 3.4.
- Withdrawal of consent (Art. 7(3)): at any time, where consent is what a processing relies on. For analytics you do not need to write to me at all: the button in section 6.4 withdraws it immediately.
Write to hello@press42.com and say what you want. I may ask you to confirm your identity if the request does not come from an address I already recognise, which is a safeguard for you rather than an obstacle. You will get a substantive answer within one month, extendable by two further months for complex requests under Article 12(3) GDPR, in which case I will tell you why before the first month is out.
If you are not satisfied, you can complain to the supervisory authority: Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, Spain. aepd.es, electronic office at sedeagpd.gob.es. You are not required to contact me first, though it is usually faster.
9. Where the data comes from, and how it is protected
All personal data here comes directly from you. Nothing is bought from list brokers, scraped, or enriched from third-party sources.
The site is served only over HTTPS, with HSTS enabled. Server credentials and the mail configuration are held outside the public web root and are readable only by the accounts that need them. Enquiries are not stored in any database or CRM, which keeps the amount of data at risk small. Access to the mailbox is protected by a unique password and two-factor authentication. No system is perfect, and if a breach ever occurred that was likely to result in a high risk to you, I would notify you and the AEPD as Articles 33 and 34 GDPR require.
These services are aimed at businesses and professionals. The site is not directed at children, and I do not knowingly collect data from anyone under 14, the age set by Article 7 LOPDGDD.
Giving your name, email address, and a message is necessary for a reply; without them there is no way to answer you. The company and service fields are optional and only help me route the enquiry.
10. Changes to this policy
This is version 2.1, published on . The version shown on this page is always the one in force. If a future change materially affects how your data is handled (a new processor, a new purpose, a longer retention period), the version number and date above will change, and anyone with an open enquiry at the time will be told directly rather than being left to notice it here.
Version 2.1 introduced consent-based Google Analytics. Version 2.0 and earlier stated that this site used no analytics and set no cookies of its own, which was true when written and is no longer true. The change is recorded here rather than quietly edited away, because a privacy policy that revises its own history is worth very little.