Privacy Policy
1. Data controller
- Company name: Galde Analytics, S.L.
- Tax ID (NIF): B10641728
- Registered office: Calle Alameda de Mazarredo, 47, Bajo — 48009 Bilbao (Bizkaia), Spain
- Commercial Registry: Registro Mercantil de Bizkaia, Volume 6246, Sheet 174, Page BI-82276
- Email: info@galde.app
- Telephone: (+34) 688 86 73 94
Data Protection Officer: none appointed, as no case under Article 37 GDPR applies. For any question about your data, write to info@galde.app.
2. What we process and why
| Processing | Data | Purpose | Legal basis |
|---|---|---|---|
| Enquiries | Name, company, email, phone and message content | Answer requests received by form or email | Pre-contractual steps at your request (Art. 6(1)(b) GDPR) |
| Clients | Professional contact and billing details | Perform and administer the services agreement | Performance of a contract (Art. 6(1)(b) GDPR) |
| Legal duties | Billing data | Comply with tax and accounting obligations | Legal obligation (Art. 6(1)(c) GDPR) |
| Marketing emails | Email address | Send content and news | Consent (Art. 6(1)(a) GDPR); for existing clients, on similar services, legitimate interest under Art. 21(2) LSSI |
| Web analytics | Cookie identifier, pages visited, traffic source, approximate device data | Understand use of the site in aggregate | Consent (Art. 6(1)(a) GDPR and Art. 22(2) LSSI) |
| Consent record | Random identifier, categories accepted, date, policy version, IP network prefix | Demonstrate the consent given, as Art. 7(1) GDPR requires | Legal obligation (Art. 6(1)(c) GDPR) |
The consent record deserves a word, because it is processing that exists to protect you: it stores proof of what you decided about cookies. That is why we keep only the network prefix of your IP address and not the full address — enough to evidence origin, not enough to identify you — and why the identifier is random rather than derived from anything about you.
We do not process special categories of data or data relating to minors.
3. Source of the data
All data comes from the data subject. We do not obtain it from publicly available sources and we do not buy it from third parties.
4. Automated decision-making
We do not take decisions based solely on automated processing, and we do not carry out profiling with legal or similarly significant effects. We do not use artificial intelligence systems to process the data of visitors to this site.
5. Retention periods
| Data | Period |
|---|---|
| Enquiries that do not lead to a contract | 12 months from the last contact |
| Client data | For the duration of the contract and 4 years thereafter |
| Invoicing and accounting | 6 years (Art. 30 Spanish Commercial Code) and 4 years for tax purposes |
| Newsletter subscription | Until consent is withdrawn |
| Web analytics (Google Analytics 4) | 14 months |
| Cookie consent record | 3 years from withdrawal or replacement of the decision |
| Galde Governance assessments and reports | 3 years from the last access |
6. Recipients and processors
We do not sell or share personal data with third parties for their own purposes. The providers that deliver services to us do access it, as processors and under a contract compliant with Article 28 GDPR:
| Provider | Service | Data accessed | Processing location |
|---|---|---|---|
| Vercel Inc. | Hosting and delivery of galde.app and Galde Governance | Server logs, including the IP address | Sweden (Stockholm) for server functions; the delivery network serves static content from the node closest to each visitor |
| Supabase | Database: consent record, contact form and Galde Governance assessments | All stored data | Sweden (Stockholm) |
| Resend | Sending contact form and Galde Governance emails | Name, email and the content of the message or report | United States |
| Stripe Payments Europe, Ltd. | Payment gateway for Galde Governance | Email and billing details. Card data is handled by Stripe directly and never passes through our systems | Ireland, with processing in the United States by Stripe, Inc. |
| Anthropic PBC | Generating the written content of Galde Governance reports | Questionnaire answers, company sector and size | United States |
| Google Ireland Limited | Web analytics (Google Analytics 4 and Tag Manager) | Cookie identifier and browsing data, only if you accept analytics | Ireland, with possible processing in the United States |
| Google Ireland Limited | Corporate email (Google Workspace) | Content of the correspondence | Ireland, with possible processing in the United States |
| Cloudflare, Inc. | Domain name servers | DNS queries. It does not receive browsing content, as it does not proxy the traffic | United States |
| Tax, accounting and payroll advisors | Legal obligations | Billing data | Spain |
7. International transfers
Some of our providers process data outside the European Economic Area, mainly in the United States. Every one of those transfers relies on one of these mechanisms, recorded in the processing agreement signed with each provider:
- The EU–US Data Privacy Framework adequacy decision of 10 July 2023, for providers listed as certified under that framework.
- Standard Contractual Clauses approved by the European Commission, with the supplementary measures each provider documents, for the rest.
Where each thing is processed, specifically:
- Hosting (Vercel). Server functions are pinned to Stockholm (Sweden), next to the database, so ordinary processing happens inside the European Union. The delivery network serves static content from the node closest to each visitor, without processing personal data beyond the technical request log. Support access by Vercel Inc. from the United States is a transfer, covered by its processing agreement.
- Database (Supabase). The project is hosted in Stockholm (Sweden), inside the European Economic Area, so storage is not an international transfer. The provider's support access from the United States is one, and relies on the standard contractual clauses in its processing agreement.
- Email (Resend). Processes data in the United States, under the processing agreement signed with the provider.
- Reports (Anthropic). The model that drafts the content runs in the United States. What is sent are the questionnaire answers and company details, not identifying data beyond what is needed to produce the report. Anthropic participates in the EU–US Data Privacy Framework, and its commercial terms incorporate standard contractual clauses and exclude the use of the data for training models.
- Payments (Stripe). The contracting entity is Irish; the group also processes data in the United States. Stripe is certified under the EU–US Data Privacy Framework and its data transfers addendum forms part of the contract.
- Analytics and corporate email (Google). Analytics only runs if you accept it.
If you would like a copy of the safeguards applied to any of these transfers, you can request it at info@galde.app.
8. Your rights
You may exercise the rights of access, rectification, erasure, objection, restriction and portability, and withdraw consent at any time without affecting the lawfulness of prior processing. For cookies, you can do so from the Cookie preferences link in the footer.
Write to info@galde.app or to Calle Alameda de Mazarredo, 47, Bajo — 48009 Bilbao, stating the right you are exercising and enclosing proof of identity. We will respond within one month.
You may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan, 6 — 28001 Madrid; www.aepd.es).
9. Security
We apply technical and organisational measures appropriate to the risk: encryption in transit via TLS, encryption at rest in the database, least-privilege access control, row-level security and regular backups.
10. Galde Governance
Galde Governance (governance.galde.app) is a product of Galde Analytics, S.L. We are the controller on that subdomain too, which is why it is covered by this same policy. As the processing is different from the website's, we set it out separately.
| What we process | Purpose | Legal basis |
|---|---|---|
| Email address, company name, sector and size | Identify your assessment, send you the report and give you later access through a link | Performance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR) |
| Maturity questionnaire answers | Calculate your score and generate the report content | Performance of a contract (Art. 6(1)(b) GDPR) |
| Email and billing details, on the paid tier | Charge for the Governance Blueprint and issue the invoice | Performance of a contract and legal obligation (Art. 6(1)(b) and 6(1)(c) GDPR) |
| Anonymised scores, without company or contact details | Build the sector benchmark shown in the reports | Legitimate interest (Art. 6(1)(f) GDPR), using data that no longer identifies anyone |
Use of artificial intelligence. The written content of the Governance Blueprint is drafted by an Anthropic language model from your answers and the calculated score. It is not an automated decision with legal effects: it is an analysis document you decide whether to act on, and the score itself is a deterministic formula, not an estimate produced by the model. Your answers are not used to train models.
Retention. Assessments and their reports are kept for three years from the last time you access them, so you can retrieve them and compare your progress. Invoices follow the tax periods in the table in section 5. The sector benchmark keeps only anonymised data, with no time limit, because it is no longer personal data.
Payments. Your card details are handled entirely by Stripe. We never see them, never store them and they never pass through our servers.
11. Changes to this policy
Any amendment will be published here. If a change affects purposes or legal bases we will notify you and, where appropriate, ask for fresh consent. For cookies, a change to the declaration causes the notice to be shown again automatically.
Last updated: 14 September 2026