Galde

Privacy Policy

1. Data controller

  • Company name: Galde Analytics, S.L.
  • Tax ID (NIF): B10641728
  • Registered office: Calle Alameda de Mazarredo, 47, Bajo — 48009 Bilbao (Bizkaia), Spain
  • Commercial Registry: Registro Mercantil de Bizkaia, Volume 6246, Sheet 174, Page BI-82276
  • Email: info@galde.app
  • Telephone: (+34) 688 86 73 94

Data Protection Officer: none appointed, as no case under Article 37 GDPR applies. For any question about your data, write to info@galde.app.

2. What we process and why

ProcessingDataPurposeLegal basis
EnquiriesName, company, email, phone and message contentAnswer requests received by form or emailPre-contractual steps at your request (Art. 6(1)(b) GDPR)
ClientsProfessional contact and billing detailsPerform and administer the services agreementPerformance of a contract (Art. 6(1)(b) GDPR)
Legal dutiesBilling dataComply with tax and accounting obligationsLegal obligation (Art. 6(1)(c) GDPR)
Marketing emailsEmail addressSend content and newsConsent (Art. 6(1)(a) GDPR); for existing clients, on similar services, legitimate interest under Art. 21(2) LSSI
Web analyticsCookie identifier, pages visited, traffic source, approximate device dataUnderstand use of the site in aggregateConsent (Art. 6(1)(a) GDPR and Art. 22(2) LSSI)
Consent recordRandom identifier, categories accepted, date, policy version, IP network prefixDemonstrate the consent given, as Art. 7(1) GDPR requiresLegal obligation (Art. 6(1)(c) GDPR)

The consent record deserves a word, because it is processing that exists to protect you: it stores proof of what you decided about cookies. That is why we keep only the network prefix of your IP address and not the full address — enough to evidence origin, not enough to identify you — and why the identifier is random rather than derived from anything about you.

We do not process special categories of data or data relating to minors.

3. Source of the data

All data comes from the data subject. We do not obtain it from publicly available sources and we do not buy it from third parties.

4. Automated decision-making

We do not take decisions based solely on automated processing, and we do not carry out profiling with legal or similarly significant effects. We do not use artificial intelligence systems to process the data of visitors to this site.

5. Retention periods

DataPeriod
Enquiries that do not lead to a contract12 months from the last contact
Client dataFor the duration of the contract and 4 years thereafter
Invoicing and accounting6 years (Art. 30 Spanish Commercial Code) and 4 years for tax purposes
Newsletter subscriptionUntil consent is withdrawn
Web analytics (Google Analytics 4)14 months
Cookie consent record3 years from withdrawal or replacement of the decision
Galde Governance assessments and reports3 years from the last access

6. Recipients and processors

We do not sell or share personal data with third parties for their own purposes. The providers that deliver services to us do access it, as processors and under a contract compliant with Article 28 GDPR:

ProviderServiceData accessedProcessing location
Vercel Inc.Hosting and delivery of galde.app and Galde GovernanceServer logs, including the IP addressSweden (Stockholm) for server functions; the delivery network serves static content from the node closest to each visitor
SupabaseDatabase: consent record, contact form and Galde Governance assessmentsAll stored dataSweden (Stockholm)
ResendSending contact form and Galde Governance emailsName, email and the content of the message or reportUnited States
Stripe Payments Europe, Ltd.Payment gateway for Galde GovernanceEmail and billing details. Card data is handled by Stripe directly and never passes through our systemsIreland, with processing in the United States by Stripe, Inc.
Anthropic PBCGenerating the written content of Galde Governance reportsQuestionnaire answers, company sector and sizeUnited States
Google Ireland LimitedWeb analytics (Google Analytics 4 and Tag Manager)Cookie identifier and browsing data, only if you accept analyticsIreland, with possible processing in the United States
Google Ireland LimitedCorporate email (Google Workspace)Content of the correspondenceIreland, with possible processing in the United States
Cloudflare, Inc.Domain name serversDNS queries. It does not receive browsing content, as it does not proxy the trafficUnited States
Tax, accounting and payroll advisorsLegal obligationsBilling dataSpain

7. International transfers

Some of our providers process data outside the European Economic Area, mainly in the United States. Every one of those transfers relies on one of these mechanisms, recorded in the processing agreement signed with each provider:

  • The EU–US Data Privacy Framework adequacy decision of 10 July 2023, for providers listed as certified under that framework.
  • Standard Contractual Clauses approved by the European Commission, with the supplementary measures each provider documents, for the rest.

Where each thing is processed, specifically:

  • Hosting (Vercel). Server functions are pinned to Stockholm (Sweden), next to the database, so ordinary processing happens inside the European Union. The delivery network serves static content from the node closest to each visitor, without processing personal data beyond the technical request log. Support access by Vercel Inc. from the United States is a transfer, covered by its processing agreement.
  • Database (Supabase). The project is hosted in Stockholm (Sweden), inside the European Economic Area, so storage is not an international transfer. The provider's support access from the United States is one, and relies on the standard contractual clauses in its processing agreement.
  • Email (Resend). Processes data in the United States, under the processing agreement signed with the provider.
  • Reports (Anthropic). The model that drafts the content runs in the United States. What is sent are the questionnaire answers and company details, not identifying data beyond what is needed to produce the report. Anthropic participates in the EU–US Data Privacy Framework, and its commercial terms incorporate standard contractual clauses and exclude the use of the data for training models.
  • Payments (Stripe). The contracting entity is Irish; the group also processes data in the United States. Stripe is certified under the EU–US Data Privacy Framework and its data transfers addendum forms part of the contract.
  • Analytics and corporate email (Google). Analytics only runs if you accept it.

If you would like a copy of the safeguards applied to any of these transfers, you can request it at info@galde.app.

8. Your rights

You may exercise the rights of access, rectification, erasure, objection, restriction and portability, and withdraw consent at any time without affecting the lawfulness of prior processing. For cookies, you can do so from the Cookie preferences link in the footer.

Write to info@galde.app or to Calle Alameda de Mazarredo, 47, Bajo — 48009 Bilbao, stating the right you are exercising and enclosing proof of identity. We will respond within one month.

You may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan, 6 — 28001 Madrid; www.aepd.es).

9. Security

We apply technical and organisational measures appropriate to the risk: encryption in transit via TLS, encryption at rest in the database, least-privilege access control, row-level security and regular backups.

10. Galde Governance

Galde Governance (governance.galde.app) is a product of Galde Analytics, S.L. We are the controller on that subdomain too, which is why it is covered by this same policy. As the processing is different from the website's, we set it out separately.

What we processPurposeLegal basis
Email address, company name, sector and sizeIdentify your assessment, send you the report and give you later access through a linkPerformance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR)
Maturity questionnaire answersCalculate your score and generate the report contentPerformance of a contract (Art. 6(1)(b) GDPR)
Email and billing details, on the paid tierCharge for the Governance Blueprint and issue the invoicePerformance of a contract and legal obligation (Art. 6(1)(b) and 6(1)(c) GDPR)
Anonymised scores, without company or contact detailsBuild the sector benchmark shown in the reportsLegitimate interest (Art. 6(1)(f) GDPR), using data that no longer identifies anyone

Use of artificial intelligence. The written content of the Governance Blueprint is drafted by an Anthropic language model from your answers and the calculated score. It is not an automated decision with legal effects: it is an analysis document you decide whether to act on, and the score itself is a deterministic formula, not an estimate produced by the model. Your answers are not used to train models.

Retention. Assessments and their reports are kept for three years from the last time you access them, so you can retrieve them and compare your progress. Invoices follow the tax periods in the table in section 5. The sector benchmark keeps only anonymised data, with no time limit, because it is no longer personal data.

Payments. Your card details are handled entirely by Stripe. We never see them, never store them and they never pass through our servers.

11. Changes to this policy

Any amendment will be published here. If a change affects purposes or legal bases we will notify you and, where appropriate, ask for fresh consent. For cookies, a change to the declaration causes the notice to be shown again automatically.

Last updated: 14 September 2026