Privacy policy
Who handles your data when you write to us through this website, what for, on what legal basis, who else sees it and how you can stay in control. In line with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Act 3/2018 (LOPDGDD).
Last updated: August 4, 2026
Data controller
The controller decides why and how your data is processed, and is who you should contact about anything to do with it:
- Owner
- Marc Casanova Beteta
- Tax ID (NIF)
- 21006994J
- Registered address
- Plaza del Olivar 3, 4º Izq., 07003 Palma de Mallorca (España)
- Contact email
- mcasanova@msenystudio.com
- Phone
- 663 13 82 23
- Website
- www.msenystudio.com
What data we collect
Only what you give us in the contact form. This website creates no accounts, sells nothing and builds no commercial profiles.
- Name
- Required: without it we don’t know who we’re replying to.
- Email address
- Required: it is how we get back to you.
- Phone
- Optional, only if you would rather we called.
- Company and company size
- Optional. They help us understand the context of your enquiry before we answer.
- Service and area of interest
- What you pick in the first two steps of the form.
- Details of your case
- Free text, optional. Keep it to the point: avoid special-category data (health, beliefs, trade union membership) and third-party data you have no permission to share.
- Browsing language
- So we reply in the language you wrote to us in.
- IP address and technical browser data
- We don’t ask for these, but they exist: Cloudflare receives them when checking that the submission isn’t a bot, and they appear in the server’s technical logs. They are not used to identify you and are not stored alongside the rest of the form.
The AI test and the hours calculator run entirely inside your browser: your answers never reach a server. If you jump from there to the form, all that carries over is the outcome — the profile and the suggested service — to write your first sentence for you, and you can delete it before sending anything.
What we use it for, and on what legal basis
Every processing activity has a specific purpose and a legal basis behind it:
- Answering your enquiry — consent (art. 6(1)(a) GDPR)
- Reading your case, replying and, if it fits, preparing a proposal. You give it by ticking the box on the form, and you can withdraw it whenever you like.
- Keeping the form spam-free — legitimate interest (art. 6(1)(f) GDPR)
- Using Cloudflare Turnstile to check that a person is sending the form. Without that check the inbox would be unusable; the impact on your privacy is minimal and it is used for nothing else.
- Measuring use of the website — consent (art. 6(1)(a) GDPR)
- Aggregate statistics through Google Analytics 4 via Google Tag Manager, only if you accept the analytics category in the banner. Reject it and nothing loads.
- Keeping the service secure — legitimate interest (art. 6(1)(f) GDPR)
- Technical hosting logs, to spot incidents, errors and abuse.
There is no automated decision-making or profiling with legal effects on you. We send no newsletters or bulk marketing either: if we ever did, we would ask for separate, specific consent.
How long we keep it
Only as long as it is needed, and as long as the law requires:
- Enquiries that don’t become work
- Kept while the conversation lasts and for up to a year afterwards, in case you pick the thread back up. After that they are deleted.
- Enquiries that do become work
- They become part of the contractual relationship and are kept for its duration and for the applicable commercial and tax limitation periods.
- The record of your cookie choice
- Up to 24 months, the maximum the Spanish DPA recommends before asking again.
You can ask us to delete it sooner at any time.
Who else handles your data
We neither sell nor share your data. To work at all, this website relies on providers acting as processors: they handle the data on our behalf, on our instructions and under their own data processing terms.
- Vercel — hosting
- Serves the pages and runs the function that processes the form. It handles the submission transiently, just long enough to turn it into an email, and keeps technical access logs.
- Resend — email delivery
- Turns what you write into the email that reaches our inbox. It is the only intermediary that sees the content of your enquiry.
- Cloudflare — anti-fraud check (Turnstile)
- Checks that a person, not a bot, is submitting the form. To do so it receives your IP address and technical browser data.
- Google — analytics (Analytics 4 via Tag Manager)
- Aggregate usage statistics. It only comes into play if you accept the analytics category; reject it and no Google resource loads.
Data may also be disclosed to courts, tribunals and public authorities where the law requires it.
International transfers
Some of those providers are US companies or run infrastructure outside the European Union, so your data may be processed outside the European Economic Area.
Where that happens, the transfer relies on the EU–US Data Privacy Framework — the European Commission’s adequacy decision of 10 July 2023 — or, failing that, on the standard contractual clauses approved by the Commission, together with the additional measures each provider documents.
Your rights
The GDPR gives you these rights over your data, and exercising them is free:
- Access
- To know what data of yours we hold and what we do with it.
- Rectification
- To correct anything inaccurate or incomplete.
- Erasure
- To ask us to delete it once it is no longer needed.
- Objection
- To object, on grounds relating to your particular situation, to processing based on legitimate interest.
- Restriction
- To ask us to keep the data but not use it while a disagreement is resolved.
- Portability
- To receive the data you gave us in a structured, commonly used format, or to have us send it to another controller.
- Withdrawing consent
- At any time, without affecting the lawfulness of processing carried out before you withdrew it.
To exercise them, write to the contact email shown at the top of this page saying which right you want to exercise; we may ask you to prove your identity. We will reply within one month at most.
If you believe we have not handled your request properly, you can complain to the Spanish Data Protection Agency, the competent supervisory authority in Spain: www.aepd.es
Security
We apply reasonable technical and organisational measures: encryption in transit (HTTPS) across the whole site, an anti-fraud check on the form, restricted access to the inbox where enquiries land, and providers that meet industry security standards.
No system is infallible. Should a security breach pose a high risk to your rights, we would tell you and notify the supervisory authority within the legal deadlines.
Children
This website is aimed at companies and professionals. It is not intended for children under fourteen and we do not knowingly collect their data. If we find we have received a child’s data without their guardian’s authorisation, we will delete it.
Changes to this policy
We may update it if the services, the providers or the law change. The version in force is always the one published on this page, with its last-updated date above; where a change affects something you consented to, we will ask you again.