Privacy Policy
Version 1.0 — 17 August 2026
This is an English rendering of the Spanish «Política de Privacidad», which is the primary legal version. In case of divergence, the Spanish version prevails.
1. Data controller
MELLISMA LABS S.L. — NIF B88896873 — Calle Creueta, 3, 08870 Sitges (Barcelona), Spain — business@mellisma.com. Mellisma has not appointed a Data Protection Officer, as the conditions of Art. 37 GDPR and Art. 34 LOPDGDD do not apply; you may exercise your rights and raise any privacy query at the email above.
2. What we process, why, and on what basis
| Processing | Data subjects | Data | Source | Purpose | Lawful basis (Art. 6 GDPR) | Retention |
|---|---|---|---|---|---|---|
| Contact form | Contact persons of interested companies | Name, work email, company, website (optional), challenge description, area, estimated budget, timeline, preferred language and channel | The data subject | Assessing and responding to the enquiry; preparing a possible proposal | 6(1)(b) — pre-contractual measures at the data subject's request; for contextual data not strictly necessary, 6(1)(f) legitimate interest in managing B2B enquiries | Up to 12 months from last interaction; if a client relationship follows, the "clients" processing applies |
| Direct business correspondence (email) | B2B contacts | Professional contact data and correspondence content | The data subject / their organisation | Managing the commercial or pre-contractual relationship | 6(1)(b) where the person requests services; 6(1)(f) legitimate interest in ordinary B2B communication | Duration of the relationship + applicable limitation periods |
| Client administrative contacts | Client personnel | Identification, professional contact, invoicing | The client | Contract performance and administration; invoicing | 6(1)(b); tax/accounting obligations: 6(1)(c) | Contract term + statutory periods (commercial 6 years, tax 4 years, Spain) |
| Technical and security logs | Site and contact-endpoint users | Technical request metadata (IP, user agent, timestamps, request IDs) | Generated by our systems | Security, fraud/abuse prevention (e.g. rate limiting), diagnostics | 6(1)(f) legitimate interest in information security (documented balancing available) | Max. 12 months, unless an incident requires longer |
| Compliance records | Persons exercising rights; incidents | Minimal identification and traces of the exercise/incident | The data subject / systems | Handling rights requests; demonstrating compliance; incident management | 6(1)(c) and 6(1)(f) | Limitation periods of the corresponding actions |
We make no automated decisions with legal effects and no Art. 22 profiling through the Site. There is no marketing processing at launch: we send no unsolicited commercial communications (Art. 21 LSSI-CE) and no marketing consent exists. If offered in future, it would be a separate, optional, un-ticked and withdrawable choice.
About the form checkbox: the required checkbox operates as confirmation that you have read this Policy. The lawful basis for processing your enquiry is not consent but the pre-contractual measures and legitimate interests set out above; the checkbox is therefore not a revocable consent, without prejudice to all your rights (section 5).
Form fields marked as required are necessary for us to handle your enquiry; without them we cannot process it. Beyond that, there is no statutory or contractual obligation to provide us with data.
3. Recipients and processors
We do not sell or share personal data with third parties for their own purposes. The following access data as processors (Art. 28 GDPR), only as necessary:
- Cloudflare, Inc. — hosting of the Site and the contact endpoint (CDN and edge compute).
- A transactional email provider delivering form notifications to Mellisma's inbox — to be designated before production launch; this Policy will be updated with its identity.
The contact endpoint does not store submissions: it forwards them as a notification to Mellisma's inbox and responds to you; technical metadata is retained per the table above. Disclosures to public authorities may occur where legally required (6(1)(c)).
4. International transfers
Our infrastructure providers may process data outside the EEA (notably the USA). Such transfers rely on a European Commission adequacy decision (including the EU-U.S. Data Privacy Framework for certified entities) and/or the Standard Contractual Clauses (Decision 2021/914), with supplementary measures where appropriate. Information about current safeguards: business@mellisma.com.
5. Your rights
You may exercise the rights of access, rectification, erasure, objection, restriction and portability, and withdraw any consent given, by writing to business@mellisma.com with the reference "Data protection". We will respond without undue delay and at the latest within one month (extendable under Art. 12(3) GDPR). You may lodge a complaint with the Agencia Española de Protección de Datos (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid).
6. Security
We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR): encryption in transit, minimisation (the form asks only what is needed), access controls, rate limiting, structured logging without submission content, and periodic review. No system is infallible; where required, breaches are notified under Arts. 33–34 GDPR.
7. Children
The Site and Mellisma's services are aimed at businesses and professionals; they are not directed at minors and we do not knowingly process their data.
8. Updates
Updates to this Policy are published on this page with their version date. Material changes affecting ongoing processing will be highlighted.