Privacy policy
Last updated:
The short version
We collect very little. If you fill in our contact form we store your name, email, optional company and your message, so we can reply and keep track of the conversation. Our CRM is software we host ourselves, in the European Union. We do not use cookies, we do not track you across sites, we do not build advertising profiles, and we never sell or rent personal data.
The rest of this page is the detail the GDPR requires us to give you.
Who is responsible for your data
The controller is the entity identified in our legal notice. For any question about this policy, or to exercise any of the rights described below, write to hola@disruptivecats.com and we will answer within one month, as the GDPR requires. In practice, within a working day.
We have not appointed a Data Protection Officer, because the scale and nature of our processing does not require one under Article 37 GDPR.
What we collect, and why
Contact form. Name, email address, company (optional) and your message. We use this to reply to you, to assess whether we can help, and to keep a record of the enquiry. Legal basis: performance of, or steps preparatory to, a contract (Art. 6(1)(b) GDPR), and our legitimate interest in responding to business enquiries and keeping a coherent record of them (Art. 6(1)(f)).
Technical logs. Our hosting provider processes your IP address, browser user-agent, requested URL and timestamp in order to serve the page, filter abuse and keep the service secure. Legal basis: our legitimate interest in the security and integrity of the service (Art. 6(1)(f)).
Audience measurement. We use Cloudflare Web Analytics, which is cookieless and does not fingerprint visitors or track them between sites. It gives us aggregated counts (pages viewed, referrers, country, device class), not individual profiles. Legal basis: our legitimate interest in understanding whether our site works (Art. 6(1)(f)).
We do not ask for special category data and you should not send it to us through the contact form. We do not use personal data to train AI models.
Who else processes it
We keep the list short deliberately, and we host our own CRM rather than hand your data to a third-party sales platform. Each of these acts as a processor under a data processing agreement:
- Cloudflare, Inc.: hosting, CDN, DDoS protection and cookieless analytics for this website. US-headquartered; processing relies on Standard Contractual Clauses and Cloudflare's EU data localisation commitments.
- Railway Corp.: the infrastructure on which we run our own CRM instance. Our deployment is in Railway's EU region (Amsterdam), so enquiry data is stored in the European Union. Railway is US-headquartered, so its own administrative access relies on Standard Contractual Clauses.
- Resend: transactional email delivery. This is a fallback path only: it processes your enquiry solely in the event that the write to our CRM fails, so that a message is never silently lost. US-headquartered, under Standard Contractual Clauses.
- Twenty: the CRM application itself is open-source software we self-host. It is not a third-party service and no data is shared with the Twenty project.
International transfers
Your enquiry data is stored in the European Union. However, three of the processors above are US-headquartered companies, which means personal data may be accessible from outside the EEA for support and administration.
Those transfers are covered by the European Commission's Standard Contractual Clauses, supplemented where relevant by each provider's participation in the EU-US Data Privacy Framework and by technical measures including encryption in transit and at rest. You can ask us for details of the safeguards in place at any time.
How long we keep it
We do not keep data indefinitely just because storage is cheap.
- Enquiries that do not become an engagement: up to 24 months from your last contact, then deleted. We keep them this long because business conversations frequently restart.
- Enquiries that become a client relationship: for the duration of the relationship, then as required by Spanish commercial and tax law, generally six years for accounting records under the Código de Comercio, and four years for tax purposes.
- Technical logs: short retention periods set by our hosting provider, typically days.
- Analytics: aggregated only, and not linked to you.
Your rights
Under the GDPR you can ask us to:
- confirm whether we hold data about you, and give you a copy (access);
- correct anything inaccurate or incomplete (rectification);
- delete your data (erasure), where we have no overriding obligation to keep it;
- pause processing while a dispute is resolved (restriction);
- hand your data to you or another provider in a portable format (portability);
- stop processing based on legitimate interest (objection).
How to exercise them, and how to complain
Email hola@disruptivecats.com. We may need to confirm your identity before acting, but only to the extent necessary. Exercising these rights is free; we will not charge you or make it awkward.
If you think we have handled your data badly, please tell us first, because we would rather fix it. You also have the right to complain directly to the Spanish supervisory authority, the Agencia Española de Protección de Datos (aepd.es, C/ Jorge Juan 6, 28001 Madrid), or to the supervisory authority where you live or work.
Security
Everything is served over TLS. Our CRM runs in the EU with row-level access control, so records are restricted per user rather than per page. Secrets are held in our hosting provider's encrypted store and never committed to source control. The contact form is protected by validation and a honeypot rather than a third-party CAPTCHA, which avoids sending your data to an additional processor.
No system is perfectly secure. If we ever suffer a breach that is likely to result in a risk to your rights, we will notify the AEPD within 72 hours and tell you directly where the GDPR requires it.
Children
This site is aimed at businesses and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has sent us personal data, tell us and we will delete it.
Changes to this policy
If we change how we process personal data we will update this page and move the date at the top. Where a change materially affects you and we hold your contact details, we will tell you directly rather than relying on you noticing.