Privacy Policy

Version 1.0 — 17 August 2026

This is an English rendering of the Spanish «Política de Privacidad», which is the primary legal version. In case of divergence, the Spanish version prevails.

1. Data controller

MELLISMA LABS S.L. — NIF B88896873 — Calle Creueta, 3, 08870 Sitges (Barcelona), Spain — business@mellisma.com. Mellisma has not appointed a Data Protection Officer, as the conditions of Art. 37 GDPR and Art. 34 LOPDGDD do not apply; you may exercise your rights and raise any privacy query at the email above.

2. What we process, why, and on what basis

ProcessingData subjectsDataSourcePurposeLawful basis (Art. 6 GDPR)Retention
Contact formContact persons of interested companiesName, work email, company, website (optional), challenge description, area, estimated budget, timeline, preferred language and channelThe data subjectAssessing and responding to the enquiry; preparing a possible proposal6(1)(b) — pre-contractual measures at the data subject's request; for contextual data not strictly necessary, 6(1)(f) legitimate interest in managing B2B enquiriesUp to 12 months from last interaction; if a client relationship follows, the "clients" processing applies
Direct business correspondence (email)B2B contactsProfessional contact data and correspondence contentThe data subject / their organisationManaging the commercial or pre-contractual relationship6(1)(b) where the person requests services; 6(1)(f) legitimate interest in ordinary B2B communicationDuration of the relationship + applicable limitation periods
Client administrative contactsClient personnelIdentification, professional contact, invoicingThe clientContract performance and administration; invoicing6(1)(b); tax/accounting obligations: 6(1)(c)Contract term + statutory periods (commercial 6 years, tax 4 years, Spain)
Technical and security logsSite and contact-endpoint usersTechnical request metadata (IP, user agent, timestamps, request IDs)Generated by our systemsSecurity, fraud/abuse prevention (e.g. rate limiting), diagnostics6(1)(f) legitimate interest in information security (documented balancing available)Max. 12 months, unless an incident requires longer
Compliance recordsPersons exercising rights; incidentsMinimal identification and traces of the exercise/incidentThe data subject / systemsHandling rights requests; demonstrating compliance; incident management6(1)(c) and 6(1)(f)Limitation periods of the corresponding actions

We make no automated decisions with legal effects and no Art. 22 profiling through the Site. There is no marketing processing at launch: we send no unsolicited commercial communications (Art. 21 LSSI-CE) and no marketing consent exists. If offered in future, it would be a separate, optional, un-ticked and withdrawable choice.

About the form checkbox: the required checkbox operates as confirmation that you have read this Policy. The lawful basis for processing your enquiry is not consent but the pre-contractual measures and legitimate interests set out above; the checkbox is therefore not a revocable consent, without prejudice to all your rights (section 5).

Form fields marked as required are necessary for us to handle your enquiry; without them we cannot process it. Beyond that, there is no statutory or contractual obligation to provide us with data.

3. Recipients and processors

We do not sell or share personal data with third parties for their own purposes. The following access data as processors (Art. 28 GDPR), only as necessary:

  • Cloudflare, Inc. — hosting of the Site and the contact endpoint (CDN and edge compute).
  • A transactional email provider delivering form notifications to Mellisma's inbox — to be designated before production launch; this Policy will be updated with its identity.

The contact endpoint does not store submissions: it forwards them as a notification to Mellisma's inbox and responds to you; technical metadata is retained per the table above. Disclosures to public authorities may occur where legally required (6(1)(c)).

4. International transfers

Our infrastructure providers may process data outside the EEA (notably the USA). Such transfers rely on a European Commission adequacy decision (including the EU-U.S. Data Privacy Framework for certified entities) and/or the Standard Contractual Clauses (Decision 2021/914), with supplementary measures where appropriate. Information about current safeguards: business@mellisma.com.

5. Your rights

You may exercise the rights of access, rectification, erasure, objection, restriction and portability, and withdraw any consent given, by writing to business@mellisma.com with the reference "Data protection". We will respond without undue delay and at the latest within one month (extendable under Art. 12(3) GDPR). You may lodge a complaint with the Agencia Española de Protección de Datos (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid).

6. Security

We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR): encryption in transit, minimisation (the form asks only what is needed), access controls, rate limiting, structured logging without submission content, and periodic review. No system is infallible; where required, breaches are notified under Arts. 33–34 GDPR.

7. Children

The Site and Mellisma's services are aimed at businesses and professionals; they are not directed at minors and we do not knowingly process their data.

8. Updates

Updates to this Policy are published on this page with their version date. Material changes affecting ongoing processing will be highlighted.