Privacy Policy

Last Updated: August 2026

Website: https://daniel-ir.eu

Hosting Platform: Squarespace


1. General Information & Data Protection

As the operator of this website and online shop, I act as the "Data Controller" under the General Data Protection Regulation (GDPR).

Because this website operates as a personal portfolio and an independent digital store that does not engage in large-scale data monitoring or process sensitive categories of information, no Data Protection Officer (DPO) is legally required. Any inquiries regarding your data privacy can be sent directly to the contact email listed on my Legal Notice page.


2. Types of Personal Data Collected

When you visit or interact with this website, data is collected in three ways: voluntarily when provided via contact forms, automatically by our hosting infrastructure, and contractually when you purchase a digital product.

A. Data Provided Voluntarily (Contact Form & Newsletter)

If you choose to communicate with me or opt-in to updates, the following data is collected:

  • Contact Form: Full Name / Name alias, Email Address, and the content of your message.
  • Newsletter Opt-In: If you check the "Sign up to receive news and updates" box at checkout, your email address is saved for marketing communications.

B. Data Collected for E-Commerce (Digital Orders)

When you purchase a digital product from the shop, we collect the minimal information necessary to fulfill our contract with you and deliver the software:

  • Email Address (for delivering the digital product, receipts, and order notifications)
  • Order History and Purchase Details
  • Note: While our checkout primarily asks for your email, the secure payment gateway (in the "Payment" step) will collect necessary billing information to process the transaction and comply with fraud-prevention and tax laws. We do not store your credit card details on our servers.

C. Data Collected Automatically (Device & Infrastructure Logs)

When accessing the website, your browser automatically transmits technical connection details required to load the page. This data includes:

  • IP Address (truncated/anonymized where applicable)
  • Device Type and Operating System
  • Browser Type and Version
  • Referral URL
  • Date, time, and duration of the visit

3. Purpose of Data Processing

The technical and personal data processed on this website is used strictly for the following purposes:

  1. Order Fulfillment & E-Commerce (Art. 6(1)(b) GDPR): To process payments, deliver digital downloads (e.g., desktop programs) to your email, handle refunds, and provide customer support.
  2. Legal & Tax Compliance (Art. 6(1)(c) GDPR): To maintain accurate accounting and billing records as required by Spanish and EU tax laws.
  3. Communication & Marketing: Responding to inquiries or sending news and updates (only if you have explicitly opted in during checkout).
  4. Technical Functionality & Security: Ensuring the website loads securely and protecting against unauthorized access, spam, and cyberattacks.

4. Third-Party Services & Technologies Used

To keep this website online and capable of processing digital orders, we partner with specialized technical service providers ("Data Processors"):

A. Squarespace (Website Hosting & E-commerce Platform)

  • Provider: Squarespace Ireland Limited, Leorg House, Ship Street Great, Dublin 8, Ireland.
  • Purpose: Cloud Hosting, E-commerce Infrastructure, and Analytics.
  • Privacy Policy: https://www.squarespace.com/privacy

B. Payment Processors (e.g., Stripe / PayPal / Squarespace Payments)

  • Purpose: Processing financial transactions securely.
  • Details: When you make a purchase, your payment data is sent directly to our integrated payment processors. They adhere strictly to PCI-DSS standards.

C. Google Fonts & Adobe Fonts (Typography Delivery)

  • Providers: Google Ireland Limited / Adobe Systems Software Ireland Limited.
  • Purpose: Web Font Delivery System.

D. Usercentrics (Consent Management)

  • Provider: Usercentrics GmbH, Sendlinger Str. 7, 80331 Munich, Germany.
  • Purpose: Legal Consent Log and Cookie Banner Administration.

5. International Data Transfers (Outside the EEA)

Some third-party providers operate infrastructure within the United States. Consequently, technical and transactional data may be transferred outside the European Economic Area (EEA). To ensure data security, these providers rely on standard contractual clauses approved by the European Commission and maintain active certification under the EU-U.S. Data Privacy Framework (DPF).


6. Consent & Cookie Management

This website utilizes a Consent Management Platform (Cookie Banner). Essential cookies (like those required to process secure payments) are strictly necessary and do not require consent. Analytics cookies are restricted by default and will only deploy if you explicitly click "Accept." You may withdraw your consent at any time by clearing your browser cookies.


7. Data Security Measures

To safeguard your information, this website employs robust security practices:

  • SSL/TLS Encryption (HTTPS): All communication, especially checkout and payment processing, is strictly encrypted.
  • PCI-DSS Compliance: All payment processing partners are fully compliant with the Payment Card Industry Data Security Standard.

8. Your Rights Under the GDPR

As an EU citizen or visitor, you possess full rights regarding your personal data. You have the right to Access, Rectification, Erasure, Restriction, Data Portability, and Objection.

Please note: The "Right to be Forgotten" (Erasure) is not absolute. Under Spanish tax and commercial law, we are legally required to retain transaction and billing records for a minimum of 4 to 6 years, even if you request the deletion of your data.

To exercise your rights, please contact me via the details on the Legal Notice page, or contact your national Data Protection Authority (in Spain, the AEPD).