Legal · Privacy Policy
Privacy Policy
What we collect, why, and how long we keep it. Nothing leaves the EEA, and nothing is sold.
01Who is responsible for your data
For your account and billing data, the data controller is Hola Money S.L., NIF B26671347, C/ Granada 7, 04820 Vélez-Rubio, Almería, Spain. Contact: privacy@cleverotter.eu.
For the content you host and the Visitors to your Sites, you are the controller and we are your processor. Those arrangements are set out in our Data Processing Agreement.
We have not appointed a Data Protection Officer, as we are not required to. CONFIRM: still true as you grow
02What we collect, and why
Our legal bases are: performance of a contract for account, authentication and usage data; legal obligation for invoices and tax records; and legitimate interests for security logs and abuse prevention, where our interest in keeping the Service secure is balanced against your rights.
We do not collect special category data, and we do not use your data for automated decision-making or profiling.
03What we do not do
We do not sell your data. We do not share it with advertisers. We do not inject analytics, tracking scripts or cookies into the Sites you host, and we do not build profiles of your Visitors.
Our marketing website sets no cookies at all. The dashboard sets a single session cookie, strictly necessary to keep you logged in, plus a CSRF token. Neither is used for tracking and neither requires consent.
04Visitors to hosted sites
When someone visits a Site we host, our servers process their IP address and request details in order to serve the response and to protect the Service from abuse. We aggregate this into counts for billing.
Request logs containing IP addresses are retained for 14 days and then deleted. Aggregated counts, which do not identify anyone, are retained for billing and capacity planning.
If your Site collects personal data itself, that is your responsibility as controller, and your own privacy notice must cover it.
05Who we share it with
We use a small number of providers, all within the EEA:
We may also disclose data where legally required, or to establish or defend legal claims. We will tell you first unless prohibited from doing so.
06International transfers
Your data does not leave the European Economic Area as part of normal operation. Servers and object storage are in Germany; backups are in France. If that ever changes we will update this notice and rely on an appropriate transfer mechanism under Chapter V of the GDPR.
07How long we keep it
08Your rights
You have the right to access your data, to correct it, to have it erased, to restrict or object to processing, to data portability, and to withdraw consent where we rely on it.
Exercise any of these by emailing privacy@cleverotter.eu. We will respond within one month. We will not charge you, and we will not make the Service worse for you because you asked.
If you are not satisfied you may complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos (aepd.es), or to the authority where you live.
09Security
Data is encrypted in transit with TLS and at rest in object storage. Passwords are hashed and never stored in recoverable form; deploy tokens are stored only as hashes. Administrative access is restricted, key-based and logged.
If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the AEPD within 72 hours and tell you without undue delay where the risk is high.
10Changes
We will post any change here and update the version above. For changes that materially affect how we handle your data, we will email you at least 30 days beforehand.
Questions about this document
Ask a person, not a form.
We would rather answer a question before you sign up than argue about a clause afterwards.