OcTYAI

Privacy policy

Last updated: 20 August 2026

This policy explains what personal data is processed when you contact us, why, and for how long. It is short because this website collects very little: it has no forms that send data to a server, no user accounts and no basket.

Data controller

Controller
OcTYAI
Address
Sant Joan Despí, 08970, Barcelona, España
Email
info@octyai.com
Website
octyai.com

What data is processed, and where it comes from

This website sends no data to any server of ours. The contact form transmits nothing: when you press the button, your email client opens with the message already written and you decide whether to send it. Until you do, what you typed never leaves your device.

So the only personal data processed is what you choose to provide when getting in touch:

What it is used for

To answer your enquiry, prepare a quote and, if the project goes ahead, manage the contractual relationship and the resulting tax and accounting obligations.

It is not used to send you advertising unless you have subscribed, no profiling or automated decision-making is carried out about you, and it is neither sold nor shared with third parties for commercial purposes.

Legal basis

Your consent, given when you write to us voluntarily (GDPR art. 6(1)(a)), and pre-contractual steps taken at your request when you ask for a quote (art. 6(1)(b)).

If a contract is signed, the basis is its performance (art. 6(1)(b)) and compliance with the owner's legal obligations (art. 6(1)(c)).

How long it is kept

Enquiries that do not lead to a project are kept for as long as the conversation lasts and, afterwards, for one year in case you get back in touch.

If there is a contract, data is kept for the duration of the relationship and, once it ends, for the statutory limitation periods: six years for commercial and accounting records (art. 30 of the Spanish Commercial Code) and four years for tax obligations (art. 66 of the General Tax Act).

Who else sees your data

Data is not disclosed to third parties except where legally required. Some providers do act as processors, each with its own policy:

Transfers outside the European Union

Some of these providers are US companies or may process data outside the European Economic Area. Where that happens, the transfer relies on the EU-US Data Privacy Framework or on the standard contractual clauses approved by the European Commission.

Your rights

You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability at any time, and withdraw any consent you have given, without affecting the lawfulness of processing carried out beforehand.

To do so, write to the email address shown above stating which right you wish to exercise. You may be asked to prove your identity. You will receive a reply within one month.

If you believe your data has not been handled properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es), C/ Jorge Juan 6, 28001 Madrid.

Security and minors

Reasonable technical and organisational measures are applied to protect the data. The site is always served encrypted (HTTPS).

The services on this site are aimed at businesses and professionals, not at children under fourteen.

Cookies

This site uses a single first-party cookie, to remember whether you accepted the notice, plus audience measurement that installs no cookies. The detail is in the Cookie policy, linked in the footer of every page.

Changes to this policy

This policy may be updated if the services or the applicable rules change. The version in force is the one published on this page, bearing the date shown above.

Back to home