Data protection
Privacy policy
Last updated: 14 July 2026
1. Data controller
- Controller: Gabriel Pacheco
- NIF/NIE: XXXXXXXXXX
- Address: Barcelona, 08860., España
- Privacy contact: privacidad@pachecogabo.com
2. Data that may be processed
- Data provided during contact: name, email address, message and, optionally, company, website and telephone number.
- Conversation content necessary to respond, find information or prepare an enquiry. You should not include special-category data or unnecessary confidential information.
- Technical and security data: hashed IP address, user agent, date, source page, error logs and events necessary to prevent abuse.
- Preferences stored on the device: language, theme, navigation mode and cookie consent.
- Aggregated measurement data or analytics identifiers where you have given consent.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Answer questions and provide assisted navigation. | Taking steps at the user’s request and legitimate interest in providing and improving the service. |
| Manage enquiries, quotations or project requests. | Pre-contractual steps requested by the data subject and, where appropriate, consent. |
| Prevent spam, abuse, fraud and attacks; maintain technical logs. | Legitimate interest in protecting the website, users and systems. |
| Perform non-essential analytics. | Consent, which can be withdrawn at any time. |
| Comply with legal obligations and handle rights or claims. | Legal obligation and legitimate interest in establishing or defending claims. |
4. Assistant and AI providers
When the assistant is connected to the OpenAI API, messages needed to generate a response, language, page context and relevant content excerpts may be sent to the provider. The API key remains on the server. The system is designed to avoid sending unnecessary information and not to use the model as a direct channel for sensitive actions.
Do not include passwords, bank details, identity documents, medical information or other sensitive data in the chat. The final processing configuration should be documented in the applicable data processing terms with the provider.
5. Recipients and processors
Data is not sold. It may be processed by providers necessary to operate the service, such as web hosting, email, maintenance, consented analytics and artificial intelligence services. It may also be disclosed to public authorities, courts or regulators where legally required.
6. International transfers
Some technology providers may process data outside the European Economic Area. In that case, recognised safeguards will be used, such as adequacy decisions, the EU–US Data Privacy Framework where applicable or Standard Contractual Clauses, together with additional measures where necessary.
7. Retention periods
- Contact enquiries: for the time needed to respond and follow up, and afterwards while liabilities may arise. As an initial criterion, enquiries without a contractual relationship will be reviewed for deletion or anonymisation after 24 months.
- Technical and anti-abuse logs: for short, proportionate periods, normally up to 90 days unless a security incident occurs.
- Cookie preferences: up to 24 months or until you change or delete them.
- Data subject to tax, accounting or contractual obligations: for legally required periods.
8. Your rights
You may request access, rectification, erasure, objection, restriction and portability, and withdraw consent without affecting prior lawfulness. Where applicable, you may also request not to be subject to decisions based solely on automated processing.
To exercise them, write to privacidad@pachecogabo.com stating the right requested and the information needed to identify your request. If you believe the processing infringes data protection law, you may complain to the Spanish Data Protection Agency.
9. Children
The website and professional services are not specifically directed at children under 14. If data sent by a child without required authorisation is detected, steps will be taken to delete it.
10. Security and changes
Reasonable technical and organisational measures are applied, including HTTPS encryption, access control, server-side validation, usage limits and data minimisation. No system is completely infallible. This policy may be updated when functionality, providers or legislation changes.