PRIVACY POLICY
POLÍTICA DE PRIVACIDAD
1. Data Controller
- Controller: Samuel Galindo Perelló (trade name: NORLIA.AI)
- Location: Terrassa (Barcelona), Spain
- Contact email: privacy@usenorlia.com
The full tax ID (NIF) and postal address appear in the Legal Notice at usenorlia.com.
2. Data We Process, Purposes and Legal Basis
a) Handling enquiries sent through the website form
- Basis: consent of the data subject (art. 6.1.a GDPR).
- Retention: until the enquiry is resolved, plus 1 additional year.
b) Managing the relationship with clients and contacts who become such
- Basis: performance of a contract (art. 6.1.b GDPR) and legitimate interest (art. 6.1.f GDPR).
- Retention: for the duration of the relationship and applicable legal limitation periods (up to 6 years).
Electronic commercial communications are addressed to legal entities and professionals under article 21.2 of Law 34/2002 (LSSI): there is a legitimate professional interest and a direct relation to the recipient's activity. The first contact identifies the sender and offers a simple, free means of objection; any unsubscribe request is added to an exclusion list.
c) Aggregate measurement of website usage (cookieless analytics)
- Basis: legitimate interest (art. 6.1.f GDPR).
- Retention: aggregated data, with no individual identification.
3. Data We Collect
Identifying and professional contact data (name, position, company, email, phone), the content of the messages you send us, and aggregated browsing data — without individual identification — from cookieless analytics. We do not process special categories of data.
4. Recipients and Data Processors
To provide our services we rely on providers acting as data processors:
- Meta Platforms Ireland Ltd. — WhatsApp Business Platform messaging channel (Cloud API). Contracting entity in Ireland (EU); the Cloud API may process content in the USA — EU-US DPF + SCC (Module 3). Cloud API retention max. 30 days.
- Anthropic, PBC — Conversational AI (Claude); processes the content of conversations. USA — SCC (+ UK/Swiss Addendum). Not DPF-certified.
- Groq, Inc. — Voice-note transcription (Whisper). USA — SCC (+ FADP). Not DPF-certified.
- Google LLC — Google APIs (Calendar and Sheets), accessed on your authorization. USA — EU-US Data Privacy Framework + SCC
- Google Ireland Ltd. — Corporate email (Google Workspace). EU
- Supabase Inc. — Database, authentication and file storage. US-based provider; EU data region — SCC + TIA (UK Addendum where applicable).
- Railway Corp. — Application hosting and database (Postgres/Redis). US-based provider; EU data region — SCC. Infrastructure sub-processors: Google Cloud, Cloudflare.
- Resend, Inc. — Transactional email delivery. USA — EU-US DPF + SCC
- Vercel Inc. — Website hosting. USA — EU-US DPF + SCC
- Asovall — Accounting and tax obligations (tax advisor). Spain (EU)
We may also disclose data to public authorities where a legal obligation exists (e.g. the Spanish Tax Agency).
5. International Transfers
Some providers are located outside the European Economic Area, mainly in the USA (Meta, Google, Anthropic, Groq, Supabase, Railway, Resend and Vercel). These transfers are covered by the EU-US Data Privacy Framework for certified providers and, failing that, by Standard Contractual Clauses (Implementing Decision (EU) 2021/914) accompanied by a transfer impact assessment (TIA). You can request information about the safeguards applied by writing to privacy@usenorlia.com.
6. Cookies
The website uses first-party and third-party technical cookies (Cloudflare) necessary for its operation and security, and aggregated usage analytics (Vercel Analytics) to measure its use statistically. On access, a cookie notice is shown to inform you and obtain your consent; you can manage it and review the details in our Cookies Policy.
7. Your Rights
You may exercise the following rights by writing to privacy@usenorlia.com, proving your identity:
- Access your personal data.
- Rectify inaccurate data.
- Erase your data where applicable.
- Object to processing, including direct marketing.
- Restrict processing.
- Data portability.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
8. Complaint to the Supervisory Authority
If you consider that the processing of your data does not comply with the regulations, you may lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es.
9. Changes to This Policy
We may update this policy to adapt it to regulatory changes or changes in our services. The version in force will always be the one published at usenorlia.com.
1. Responsable del Tratamiento
- Responsable: Samuel Galindo Perelló (nombre comercial: NORLIA.AI)
- Localidad: Terrassa (Barcelona), España
- Correo de contacto: privacy@usenorlia.com
La identificación fiscal (NIF) y la dirección postal completas figuran en el Aviso Legal de usenorlia.com.
2. Datos que Tratamos, Finalidades y Base Jurídica
a) Atender las consultas enviadas a través del formulario de la web
- Base jurídica: consentimiento del interesado (art. 6.1.a RGPD).
- Conservación: hasta resolver la consulta y 1 año adicional.
b) Gestionar la relación con clientes y contactos que se conviertan en tales
- Base jurídica: ejecución de contrato (art. 6.1.b RGPD) e interés legítimo (art. 6.1.f RGPD).
- Conservación: durante la relación y los plazos legales de prescripción aplicables (hasta 6 años).
Las comunicaciones comerciales por vía electrónica se dirigen a personas jurídicas y profesionales al amparo del artículo 21.2 de la Ley 34/2002 (LSSI): existe interés profesional legítimo y relación directa con la actividad del destinatario. En el primer contacto se identifica al remitente y se ofrece un medio sencillo y gratuito de oposición; toda solicitud de baja se incorpora a una lista de exclusión.
c) Medición agregada del uso de la web (analítica sin cookies)
- Base jurídica: interés legítimo (art. 6.1.f RGPD).
- Conservación: datos agregados, sin identificación individual.
3. Datos que Recogemos
Datos identificativos y de contacto profesional (nombre, cargo, empresa, email, teléfono), el contenido de los mensajes que nos envíes y datos de navegación agregados —sin identificación individual— procedentes de la analítica sin cookies. No tratamos categorías especiales de datos.
4. Destinatarios y Encargados de Tratamiento
Para prestar nuestros servicios recurrimos a proveedores que actúan como encargados de tratamiento:
- Meta Platforms Ireland Ltd. — Canal de mensajería WhatsApp Business Platform (Cloud API). Entidad contratante en Irlanda (UE); la Cloud API puede procesar contenido en EE. UU. — EU-US DPF + SCC (Módulo 3). Retención en Cloud API máx. 30 días.
- Anthropic, PBC — IA conversacional (Claude); procesa el contenido de las conversaciones. EE. UU. — SCC (+ UK/Swiss Addendum). No adherida al DPF.
- Groq, Inc. — Transcripción de notas de voz (Whisper). EE. UU. — SCC (+ FADP). No adherida al DPF.
- Google LLC — APIs de Google (Calendar y Sheets), a las que se accede con tu autorización. EE. UU. — EU-US Data Privacy Framework + SCC
- Google Ireland Ltd. — Correo corporativo (Google Workspace). UE
- Supabase Inc. — Base de datos, autenticación y almacenamiento de ficheros. Proveedor en EE. UU.; región de datos UE — SCC + TIA (UK Addendum donde proceda).
- Railway Corp. — Alojamiento de la aplicación y base de datos (Postgres/Redis). Proveedor en EE. UU.; región de datos UE — SCC. Subencargados de infraestructura: Google Cloud, Cloudflare.
- Resend, Inc. — Envío de correo transaccional. EE. UU. — EU-US DPF + SCC
- Vercel Inc. — Alojamiento del sitio web. EE. UU. — EU-US DPF + SCC
- Asovall — Obligaciones contables y fiscales (gestoría). España (UE)
Asimismo, podremos comunicar datos a las Administraciones Públicas cuando exista una obligación legal (p. ej. a la Agencia Tributaria).
5. Transferencias Internacionales
Algunos proveedores están ubicados fuera del Espacio Económico Europeo, principalmente en EE. UU. (Meta, Google, Anthropic, Groq, Supabase, Railway, Resend y Vercel). Dichas transferencias se amparan en el EU-US Data Privacy Framework para los proveedores certificados y, en su defecto, en Cláusulas Contractuales Tipo (Decisión de Ejecución (UE) 2021/914) acompañadas de una evaluación de impacto de la transferencia (TIA). Puedes solicitar información sobre las garantías aplicadas escribiendo a privacy@usenorlia.com.
6. Cookies
La web utiliza cookies técnicas, propias y de terceros (Cloudflare), necesarias para su funcionamiento y seguridad, y analítica agregada de uso (Vercel Analytics) para medir su utilización de forma estadística. Al acceder se muestra un aviso de cookies para informarte y recabar tu consentimiento; puedes gestionarlo y consultar el detalle en nuestra Política de Cookies.
7. Tus Derechos
Puedes ejercer los siguientes derechos escribiendo a privacy@usenorlia.com, acreditando tu identidad:
- Acceso a tus datos personales.
- Rectificación de datos inexactos.
- Supresión de tus datos cuando proceda.
- Oposición al tratamiento, incluida la prospección comercial.
- Limitación del tratamiento.
- Portabilidad de tus datos.
- Retirar el consentimiento en cualquier momento, sin que ello afecte a la licitud del tratamiento previo.
8. Reclamación ante la Autoridad de Control
Si consideras que el tratamiento de tus datos no se ajusta a la normativa, puedes presentar una reclamación ante la Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es.
9. Cambios en esta Política
Podemos actualizar esta política para adaptarla a cambios normativos o de nuestros servicios. La versión vigente será siempre la publicada en usenorlia.com.