Your data

Privacy policy

Last updated: 27 September 2026 · This is a translation for information purposes; the Spanish version is the legally binding one.

In two lines: if you write to me through the form, I keep your details only to reply to you and discuss your project. I don't sell them to anyone, I don't send you advertising and you can ask me to delete them whenever you like.

1. Who processes your data

ControllerSilvia Espadas Nieves (Shyn Design)
Tax ID (NIF)43113208F
AddressCarretera Gradefes, 15 · 24162 Villafañe (León), Spain
Emailhola@shyndesign.com

2. What data I collect and why

If you fill in the contact form

What I collectName, business name, your website address, email, phone, the service you're interested in, the guide budget and whatever you tell me in the message.
If you arrived from an ad, which ad is also stored, to know which one works. It's a short word that says nothing about you (for example fb-mallorca).
WhyTo reply to you, carry out the free review of your website if you asked for it, answer your questions and, where appropriate, prepare a quote.
Legal basisYour consent, given by ticking the box (Art. 6(1)(a) GDPR), and the performance of pre-contractual measures at your request (Art. 6(1)(b) GDPR).
How longFor as long as the conversation lasts and one more year afterwards in case we get back in touch. If we end up working together, the legal retention periods for invoicing apply (6 years, Art. 30 of the Spanish Commercial Code).

Fields marked with an asterisk are required: without them I can't reply to you. The rest are optional.

If I wrote to you first

Sometimes I write to businesses that don't know me, when I see something on their website that is costing them customers. In that case you didn't give me your details: I took them from your own website or from your public listing in the official tourism register, only the business email or phone that you yourself published. I write to you on the basis of legitimate interest, to offer a professional service related to your business, and at most three times. If you reply "no thanks" or ask me not to write again, your email and phone go onto an exclusion list and I won't write to you again even if your business appears on another list. If you don't reply, your details are deleted after a year.

If you request a call

On the appointment page I ask for your business, your name, a phone number or email, and what is causing you trouble, to prepare those twenty minutes. With that I create your record, put the appointment in my calendar and receive a notification on my phone (see section 3). If you cancel, the cancellation is recorded.

If you email me

I process the data you provide in the message, for the same purpose and for the same periods.

Technical visit data

The server hosting this website keeps technical logs (IP address, date and time, browser) for security and to diagnose incidents. This is a standard technical obligation of any hosting and is based on the legitimate interest of keeping the service secure (Art. 6(1)(f) GDPR).

When you submit the form, your IP is also stored with the message, as an anti-fraud measure and to prevent automated submissions.

How I count visits

To know whether this website is useful to anyone, I count visits with my own system, hosted on this same server. I don't use Google Analytics or any third-party tool, and no cookie is set.

For each visit, only the following is stored:

Your IP address is not stored. To avoid counting the same person ten times on the same day, an irreversible code is calculated combining the date with connection data. That code changes every day and does not allow you to be identified, your visits on one day to be linked with the next, or anyone to know who you are.

That is why this count does not require your prior consent: it is based on the legitimate interest of knowing how the site is used (Art. 6(1)(f) GDPR) and does not involve tracking people. Even so, if your browser sends the "Do Not Track" or "Global Privacy Control" signal, absolutely nothing is recorded.

3. Who it is shared with

Notifications to my phone. When you write, request an appointment or the assistant handles an enquiry, I receive a notification via Telegram with the business name and the subject. It never includes your phone, your email or what you wrote: I look at that in my dashboard, which is on my server in Spain. Telegram FZ-LLC is based outside the European Union; that is why the notification contains the bare minimum.

I do not sell, rent or pass on your data to anyone for commercial purposes.

Only the providers needed for this to work have access to it, acting as data processors and bound by contract to confidentiality:

ProviderWhyWhere
Raiola Networks, S.L. Web hosting and email Spain (European Union)

And little else: this website is built without external services. The fonts, styles and icons are hosted on our own server, so your browser does not connect to Google or any other company when you visit it.

Tax advisers or accountants could also have access if we invoice, as could the competent authorities where there is a legal obligation.

4. Artificial intelligence

Shyn Design uses artificial intelligence tools to support its work (layout, code review, text drafts). Since this raises reasonable questions, here is a clear explanation:

This website's assistant

This is a separate processing operation, independent of everything above. It only affects people who choose to write in the chat window. If you don't write anything, none of your data is processed.

The assistant answers questions about Shyn Design's services and prices and collects the basics of an enquiry (what business you have, what you need and, only if you provide it, a phone or email so that Silvia can write to you). It is not a person: it is an automatic AI assistant, and this is stated in the window itself, as required by Regulation (EU) 2024/1689.

From each conversation, only what you write and what the assistant replies are stored, together with the enquiry details you have given and a random session code so the thread isn't lost. The conversation expires after 6 hours without writing and the chat starts from scratch. Your own browser also stores a random code with no personal data, which only serves to know that a new enquiry comes from the same browser as a previous one; you can delete it by clearing the site data. It is kept for 90 days on this website's server and then deleted.

If the notification doesn't arrive. When you leave a phone number or email, a notification is sent to Silvia so she can reply. If that notification fails to go out because of an email error, the content is saved on this website's server so that your enquiry isn't lost and Silvia can still reply. It is kept for the same time as the rest (90 days) and then deleted automatically.

Who sees it. Only Silvia, from a private password-protected dashboard that cannot be accessed from outside. Nobody else has access.

Who processes it. To understand what you write and draft the reply, the text of the conversation is sent to Anthropic PBC (USA), the provider of the language model, under its commercial terms for businesses: it does not use those conversations to train its models. Your IP address and no other data from your visit are sent to it.

What it doesn't do. It doesn't finalise quotes, sign anything, handle payments or ask for bank details or identity documents. Never write card details, passwords or your ID number in the chat. You can close the window at any time and write via WhatsApp, email or the form, without going through the assistant.

5. Your rights

You can exercise these rights at any time, free of charge:

To exercise them, write to me at hola@shyndesign.com stating which right you wish to exercise. I will reply within one month at the latest.

If you believe I have not handled your request properly, you can complain to the Spanish Data Protection Agency (AEPD): www.aepd.es.

6. Security

This website runs over an encrypted connection (HTTPS) and I apply reasonable technical and organisational measures to protect your data. Even so, no system is infallible; if a security breach affecting your rights occurred, it would be notified as required by Article 33 GDPR.

7. Minors

The services on this website are aimed at people over 18. Data from minors is not knowingly collected.

8. Changes

This policy may be updated if the services or the law change. The date at the top always tells you which version is in force.