Privacy Policy
Last updated: 21 July 2026
In short: this site collects your email address and nothing else, and only if you type it into the waitlist form. We use it for exactly one thing: telling you when Almenora is available. No cookies, no tracking, no profiling, and we never sell or share your data. Ask us to delete your email at any time and we will.
This is a translation provided for convenience. Almenora is established in Spain and the Spanish version is the legally binding text.
1. Who is the data controller
Controller: Almenora — [TODO: full legal name]
Tax ID (NIF/CIF): [TODO]
Registered address: [TODO], Spain
Privacy contact: privacidad@almenora.com
We have not appointed a Data Protection Officer, as the processing carried out on this website does not meet the thresholds of Article 37 GDPR or Article 34 LOPDGDD. We will revisit this when the product goes live.
2. What we process
| Data | Source | Purpose |
|---|---|---|
| Email address | You type it into the form | To notify you at launch |
Hash of your IP address (ip_hash) | Generated on submission | To rate-limit and prevent form abuse |
| Timestamp, page language, form section | Generated on submission | To know when and from where people signed up |
We do not store your IP address. Before storage it is passed through SHA-256 together with a secret salt (a "pepper") known only to us. The result cannot be reversed to recover the original IP and only lets us see that several submissions came from the same connection.
We neither ask for nor want special category data (health, biometrics, political opinions and so on).
3. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Emailing you when Almenora is available | Your consent, Article 6(1)(a) — given when you submit the form, withdrawable at any time |
| Protecting the form against automated abuse | Legitimate interest, Article 6(1)(f) — keeping the service running and the list clean |
Withdrawing consent is as easy as giving it: email privacidad@almenora.com and we will remove you. Every email we send will also carry a direct unsubscribe link.
4. Retention
We keep your email until whichever comes first: you ask to be removed, or 24 months pass from signup without the product launching. The IP hash is kept for at most 12 months. After those periods the data is deleted.
5. Who else touches your data
We do not sell, rent or share your data. Only the providers needed to run the site are involved, each under an Article 28 data processing agreement:
| Provider | Role | Data location |
|---|---|---|
| Supabase | Database holding the list | European Union |
| Netlify, Inc. | Website hosting and form processing | United States (see section 6) |
| Google Ireland Ltd. (Google Fonts) | Website typefaces | See section 6 |
6. International transfers
- Supabase: the project is hosted in an EU region. Your email does not leave the EEA.
- Netlify, Inc. is a US company. When you submit the form your data passes through its infrastructure before being stored in the EU database. This transfer relies on the European Commission's Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.
- Google Fonts: this site loads its typefaces from Google's servers (
fonts.gstatic.com). To serve the file, Google receives your IP address and the usual technical request data. No cookies are set in the process and we receive nothing back from Google. We are evaluating self-hosting the fonts to remove this connection too.
7. Cookies and tracking
This site uses no cookies. None of our own, none from third parties, no analytics, no advertising, no tracking pixels. That is why there is no cookie banner — there is nothing to consent to. We do not use browser storage to identify you either.
8. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction, portability and withdrawal of consent at any time by emailing privacidad@almenora.com. We will respond within one month.
If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es.
9. Security
We apply the technical and organisational measures required by Article 32 GDPR. Specifically, and because we are a security product and think it fair to spell this out:
- all traffic is encrypted over HTTPS with HSTS enabled;
- data is encrypted at rest in the database;
- the waitlist table has Row Level Security enabled and denies all reads, updates and deletes by default;
- the browser never connects directly to the database and holds no access key;
- no service-role key exists anywhere in this website's code;
- the form is protected by server-side validation and per-connection limits.
If a breach affecting your data occurred, we would notify the AEPD within 72 hours and inform you where there is a high risk to your rights.
10. Automated decision-making
We make no automated decisions and build no profiles from the data collected on this site.
11. Changes
If we change anything material we will update the date above, and if the change affects the purpose you signed up for we will email you before it takes effect.