Privacy Policy
Last updated: March 2026
1. Data Controller
The controller responsible for the personal data collected through this website is AizuaLabs, based in Málaga, Spain.
For any privacy-related query, you can contact us at: info@aizualabs.com
2. Data We Collect
We only collect the data you voluntarily provide through the contact form:
- First and last name
- Email address
- Company name
- Message or project description
We do not collect sensitive data, payment data or banking information through this website.
3. Purpose and Legal Basis of Processing
The data collected is used exclusively to:
- Respond to your inquiry or audit request (legal basis: consent of the data subject, GDPR art. 6.1.a)
- Manage the business relationship and send proposals (legal basis: performance of a contract or pre-contractual measures, GDPR art. 6.1.b)
- Comply with legal obligations where applicable (GDPR art. 6.1.c)
4. Data Retention
Your data will be kept for as long as necessary to handle your inquiry and, in the case of a contractual relationship, for the period required by applicable commercial and tax law (generally 5-6 years from the last transaction).
After that period, the data will be securely deleted.
5. Recipients and Data Sharing
We do not share your data with third parties for commercial purposes. Your data may only be disclosed to:
- Technology service providers acting as data processors under contract, based in the EU or under adequate safeguards. As of this policy, they are:
- Supabase — database and storage.
- Vercel — website hosting and delivery.
- Stripe — payment and subscription processing.
- Resend — transactional email delivery.
- Brevo — newsletter and marketing communications.
- Twilio — voice calls and messaging.
- 360dialog — WhatsApp Business messaging.
- Anthropic and OpenCode — the language models that generate our agents' replies.
- Google — Google Calendar (only if you connect your calendar to a booking agent) and Google Fonts.
- PostHog — website usage analytics, EU-hosted.
- Public authorities when required by law.
If we add or remove a processor in the future, we will update this list.
6. International Transfers
If any technology provider is located outside the European Economic Area, we ensure that such transfer has the adequate safeguards provided for under the GDPR (adequacy decisions, Standard Contractual Clauses, etc.).
7. Your Rights
Under the GDPR (EU Regulation 2016/679) and Spain's LOPDGDD (Organic Law 3/2018), you have the right to:
- Access: request what data of yours we process.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your data when it is no longer necessary.
- Objection: object to processing under certain circumstances.
- Restriction: request that processing be restricted.
- Portability: receive your data in a structured, machine-readable format.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, email info@aizualabs.com stating your name, the right you wish to exercise and a copy of your ID document.
If you believe the processing does not comply with the regulation, you may file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
8. AI Conversational Assistant
This website includes a conversational assistant based on artificial intelligence. When you use it, we process the messages in the conversation and any contact details you voluntarily provide (name, email, phone).
- Purpose: to handle your query, follow up on it and, where applicable, prepare a commercial proposal.
- Legal basis: the taking of steps at your request prior to entering into a contract — writing in the chat is that request — and our legitimate interest in handling and following up on enquiries received (GDPR art. 6.1.b and 6.1.f). Consent is not requested because it is not the applicable basis; you may object to the processing at any time.
- Retention: 12 months from the last message, unless a contractual relationship begins, in which case the periods in section 4 apply.
- Processors and sub-processors: the assistant relies on language-model providers acting as sub-processors, some located outside the European Economic Area, with the safeguards set out in Chapter V of the GDPR (see sections 5 and 6).
- No automated decision-making: the assistant informs and hands over to a person; it does not take automated decisions producing legal effects concerning you or similarly significantly affecting you (GDPR art. 22).
Do not enter passwords, bank or card details, or special category data (health, political opinions, religion, ethnic origin, trade union membership, sex life or sexual orientation) into the chat. The assistant is instructed not to request or process them.
10. Security
We apply appropriate technical and organizational measures to protect your data against unauthorized access, loss, alteration or disclosure, including encryption in transit (HTTPS), access control and periodic security reviews.
11. Changes
We may update this policy periodically to reflect changes in our practices or in applicable regulation. We recommend reviewing it regularly. The date of the last update is shown at the top of this document.