Privacy Policy

This is a translation. The legally binding version is the Spanish original, Política de Privacidad. In the event of any discrepancy, the Spanish text prevails.

Last updated: 17 August 2026

This policy explains what personal data we process when you visit yatoday.es or contact us, for what purpose, for how long, and what you can require of us. It is written to comply with Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 (LOPDGDD) and Spanish Law 34/2002 (LSSI-CE).

1. Data controller

Legal nameYatoday, S.L.
Tax ID (NIF)PENDIENTE DE COMPLETAR
Registered addressPENDIENTE DE COMPLETAR
Companies registerPENDIENTE DE COMPLETAR
Email[email protected]
Websiteyatoday.es

Data Protection Officer (DPO). We have not appointed a DPO, because none of the conditions in Article 37(1) GDPR or Article 34 LOPDGDD apply: we are not a public authority, our core activity is not the regular and systematic monitoring of data subjects on a large scale, and we do not process special categories of data on a large scale. For any privacy matter, write directly to [email protected].

2. Summary

QuestionShort answer
Who processes my data?Yatoday, S.L., as controller.
What data?What you give us when you write, plus technical browsing data and — only if you accept — analytics data.
What for?Answering your enquiry, delivering and invoicing our services, keeping the site secure, evidencing your cookie choice and measuring site usage.
On what basis?Your consent, performance of a contract or pre-contractual steps, legal obligations and our legitimate interest.
Who receives it?The providers we need in order to operate (hosting, email, analytics) and public authorities where the law requires. We do not sell it.
For how long?See the table in section 4.
What can I do?Access, rectify, erase, object, restrict, port your data, withdraw consent and lodge a complaint with the AEPD.

3. What data we process and where it comes from

This site has no forms. All identifying data we process comes from you, voluntarily, when you choose to write to us.

a) Data you give us when you get in touch. When you write by email, WhatsApp or Telegram you provide your name or alias, the identifier of the channel you use (email address, phone number or Telegram username), the content of your message, and anything else you choose to include in it (company, project, budget, attachments).

b) Technical browsing data. When any page loads, our hosting provider logs the IP address, the user agent, the date and time, the requested URL and the response code, for content delivery, security and abuse prevention.

c) Data attached to your cookie choice. When you accept or reject cookies we record a random identifier (UUID) generated in your browser, your decision, the version of this consent policy, the categories accepted, the URL where you decided, the language, your user agent and your IP address. This record is kept on our platform ({legal.platformHost}) because Article 7(1) GDPR requires us to be able to demonstrate that we obtained your consent.

d) Analytics data. Only if you accept analytics cookies: Google Analytics 4 cookie identifiers, page views, interaction events, traffic source, device type and approximate location (country/city) derived from an IP address that Google truncates before storing it.

We do not process special categories of data (Article 9 GDPR: health, political opinions, religion, trade union membership, ethnic origin, biometric data, sexual orientation). Please do not include such data in the messages you send us.

PurposeLegal basis (Art. 6 GDPR)Retention
Handling your enquiry or quote request received by email, WhatsApp or Telegram, and following it up in our internal CRMPre-contractual steps at the data subject’s request (Art. 6(1)(b)); legitimate interest in managing and following up the enquiries we receive (Art. 6(1)(f))2 years from the last contact, where the enquiry does not lead to a contract
Delivering the services contracted, managing the relationship and issuing invoicesPerformance of a contract (Art. 6(1)(b)) and compliance with accounting and tax obligations (Art. 6(1)(c))For the duration of the relationship and thereafter 6 years (Art. 30 Spanish Commercial Code) and 4 years for tax purposes (Art. 66 LGT)
Recording and being able to evidence your decision to accept or reject cookies, including the history of changesCompliance with a legal obligation: demonstrating consent (Art. 6(1)(c) read with Art. 7(1) GDPR and Art. 22(2) LSSI-CE)24 months from your last decision, aligned with the maximum validity period for cookie consent
Measuring site usage and improving its content through Google Analytics 4Your consent (Art. 6(1)(a) and Art. 22(2) LSSI-CE)Up to 14 months in Google Analytics, or until you withdraw consent if sooner
Keeping the site and the platform secure, preventing abuse and diagnosing incidents (technical logs, rate limiting)Legitimate interest in keeping the service available, intact and protected against attacks (Art. 6(1)(f))12 months
Handling rights requests and evidencing that they were handledCompliance with a legal obligation (Art. 6(1)(c))3 years from the reply

Where the basis is our legitimate interest, we have carried out the corresponding balancing exercise between that interest and your rights and freedoms. You may request a summary of it by writing to [email protected].

Once these periods expire, the data is deleted or anonymised. In the meantime it may remain blocked, available solely to judges, courts and competent authorities, for the limitation periods of any liabilities (Art. 32 LOPDGDD).

5. Contact via WhatsApp and Telegram

This site offers buttons that open a conversation on WhatsApp or Telegram. Before using them, you should know:

  • The conversation takes place on those services’ infrastructure, not ours. Their operators process your data as independent controllers, under their own policies: WhatsApp and Telegram.
  • We process the content of the conversation and your contact identifier in order to handle your enquiry, for the purposes and periods in section 4.
  • Telegram FZ-LLC is established in the United Arab Emirates, a country with no European Commission adequacy decision. By voluntarily choosing that channel to reach us, the transfer of your data to Telegram relies on Article 49(1)(a) GDPR (explicit consent of the data subject, having been informed of the possible risks arising from the absence of an adequacy decision and of appropriate safeguards). If you prefer to avoid that transfer, email us at [email protected] — always available and equivalent.

6. Cookies

We use strictly necessary cookies, which require no consent, and analytics and measurement cookies, which are only set if you accept them through the banner. Until you decide, Google’s consent mode remains in the denied state by default. You can change your decision at any time from the floating cookie button present on every page.

Full detail — the name of each cookie, who sets it, its purpose and its duration — is in our Cookie Policy.

7. Recipients and processors

We do not sell or disclose your data for commercial purposes. To operate the site and the platform we rely on the following providers, acting as processors under a contract compliant with Article 28 GDPR unless stated otherwise:

ProviderPurposeProcessing locationTransfer safeguard
Cloudflare, Inc. / Cloudflare Ireland Ltd.Static site hosting, CDN, attack protection and file storageEU, with access from the USEU-US Data Privacy Framework (Decision 2023/1795) and Standard Contractual Clauses
Hetzner Online GmbHOur platform servers: application, database, consent store and CRMGermany and Finland (EU)Processing within the EEA; not applicable
Mailgun Technologies, Inc. (Sinch group)Transactional email delivery from the platformProvider’s European regionStandard Contractual Clauses
Google Ireland LimitedGoogle Analytics 4Ireland (EU), with access by Google LLC from the USEU-US Data Privacy Framework and Standard Contractual Clauses
WhatsApp Ireland Limited (Meta group)Messaging channel, if you choose to use itIreland (EU)Independent controller; not applicable
Telegram FZ-LLCMessaging channel, if you choose to use itUnited Arab EmiratesIndependent controller; transfer under Art. 49(1)(a) GDPR (see section 5)
Tax and accounting advisersAccounting, tax and company-law obligationsSpain (EU)Processing within the EEA; not applicable

We may also disclose data to judges, courts, law enforcement, the Spanish Tax Agency and other public authorities where we are under a legal obligation to do so.

8. International transfers

Our core infrastructure is in the European Union. The only transfers outside the EEA are those shown in the table above:

  • United States (Cloudflare, Google): covered by the adequacy decision for the EU-US Data Privacy Framework, to which both providers are certified, and additionally by the Standard Contractual Clauses approved by the European Commission. Note that the validity of that adequacy decision is under judicial review before the Court of Justice of the European Union; should it cease to apply, we would maintain the transfer solely under the Standard Contractual Clauses together with any supplementary measures required.
  • United Arab Emirates (Telegram): a country with no adequacy decision. The transfer relies exclusively on your explicit consent in choosing that channel (Art. 49(1)(a) GDPR), having been informed in section 5 that this entails a level of protection that may not be equivalent to that of the EEA.

You may request a copy of the safeguards applied by writing to

[email protected].

9. Automated decision-making and profiling

We make no automated decisions producing legal effects concerning you or similarly significantly affecting you (Art. 22 GDPR), and we do not carry out profiling for that purpose. The analytics we use is aggregated and statistical.

10. Minors

This site is aimed at professionals and businesses, not minors. We do not knowingly collect data from children under 14 — the age from which Article 7 LOPDGDD allows consent to be given by the child themselves. If we find that we have received data from a child below that age without the consent of their holders of parental responsibility, we will delete it.

11. Data security

We apply the appropriate technical and organisational measures required by Article 32 GDPR, including: TLS encryption of communications across the whole site and API; hosting in data centres located in the European Union; role-based access control and least privilege over the CRM and the database; regular backups; access logging and change logging on consents; and rate limiting to prevent automated abuse.

Should a security breach occur that poses a high risk to your rights, we will inform you without undue delay and notify the AEPD in accordance with Articles 33 and 34 GDPR.

12. Your rights

You may exercise the following rights at any time:

RightWhat it allows
Access (Art. 15)Find out whether we process your data and obtain a copy of it.
Rectification (Art. 16)Correct inaccurate data or complete incomplete data.
Erasure (Art. 17)Ask us to delete your data when it is no longer necessary or you withdraw your consent.
Restriction (Art. 18)Ask us to keep the data but suspend its use while a dispute is resolved.
Portability (Art. 20)Receive the data you gave us in a structured, commonly used format, or ask us to transmit it to another controller.
Objection (Art. 21)Object to processing based on our legitimate interest, on grounds relating to your particular situation.
Withdrawal of consent (Art. 7(3))Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal. For cookies, the floating cookie button is enough.
Not to be subject to automated decisions (Art. 22)Not applicable: we make no such decisions.

How to exercise them. Write to [email protected] stating which right you wish to exercise. Where there is reasonable doubt about your identity, we may ask you for additional information to verify it (Art. 12(6) GDPR). Exercising your rights is free of charge and we will reply within one month, extendable by two further months for complex requests, informing you of the extension.

Complaint to the supervisory authority. If you consider that we have not dealt with your request properly, you may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid — www.aepd.es), without prejudice to contacting us first.

13. Obligation to provide data

Giving us your data is voluntary. There is no legal or contractual obligation to do so. That said, if you choose not to give us your contact details we will not be able to handle your enquiry or provide our services, since they are indispensable in order to reply to you.

14. Changes to this policy

We may update this policy to reflect changes in our processing, in the providers we use or in applicable law. The version in force is always the one published on this page, with the last-updated date shown at the top. Where a change materially affects the purposes or the legal bases, we will increment the cookie consent version so that you are asked again.

15. Language of this document

This document is published in Spanish, English and Russian — the three languages in which this website is offered — so that you can read it in your own (Art. 12(1) GDPR).

The Spanish version is the only prevailing version. The English and Russian versions are translations provided for your understanding; in the event of any discrepancy between them, the Spanish text prevails, as it is the language of the controller, of the contract and of the competent supervisory authority.

Español (prevailing) · English · Русский