← All legal documents

Privacy Policy

Version 1.1 · 22 July 2026

This policy explains what personal data we process, why and on which legal basis, when you visit nemolink.app or use NEMO. It is written to be read: no fine print, just like the product — measure without invading.

Controller

{TITULAR} (full identification in the Legal Notice). Contact for anything privacy-related: soporte@enrivasgarcia.com.

Two different roles

We are the CONTROLLER of your data as a NEMO user (account, billing, support, service emails). We are a PROCESSOR regarding the data of your websites' and links' visitors that NEMO measures on your behalf and under your instructions: for that data the controller is you, and our relationship is governed by the Data Processing Agreement (DPA) published at /legal/dpa.

What we process and on which basis

ProcessingDataLegal basisRetention
Account and service provisionEmail, language, content you create (links, tags, integrations)Contract performance (art. 6.1.b GDPR)While the account exists
Subscription and billingPlan state and Stripe customer identifiers (we never store cards)Contract performance and legal obligations (6.1.b and 6.1.c)Account life + tax retention periods
Consent record (forensic proof)Document, version, language, SHA-256 hash of the exact text you saw, server date and time, IP address and user agentLegal obligation to be able to DEMONSTRATE consent (art. 7.1 GDPR, basis 6.1.c) and legitimate interest in defending against claims (6.1.f)For as long as it may be needed to evidence it; SURVIVES account closure, detached from your live identity
Service lifecycle emailsEmail, language and aggregated workspace metricsContract performance (service notices, not third-party marketing)While the account exists
Measurement of your links (on your behalf)Click events with irreversibly pseudonymised IP (truncated hash with daily salt), user-agent, referrer; leads and sales your platforms send usProcessing on your behalf: the basis is determined by you as controllerPer plan: visible for 30 days on Free, the rest VEILED (not visible, not deleted) while your account exists
Security and anti-abuseTechnical logs and bot signalsLegitimate interest (6.1.f): protecting the service and third partiesThe minimum necessary

We never store plain IP addresses in event tables, nor emails in measurement records. Veiled data on the Free plan remains not visible: veiled means not visible, never deleted while your account exists; it is erased with the account, with the sole exception of the consent record described below.

Sub-processors and transfers

We use infrastructure providers under data processing agreements. Product data is hosted in the European Union; where a provider may process data from outside the EU, the transfer relies on its Data Privacy Framework (DPF) certification or on Standard Contractual Clauses (SCCs).

ProviderFunctionData locationMechanism
SupabaseDatabase and authenticationEU (eu-west-1 region, Ireland)SCCs (Supabase DPA)
VercelApplication hosting (EU region)EU; support from the USDPF + SCCs
UpstashRate limitingEU (European region)SCCs
StripePayments and invoicing (merchant of record)EU (Stripe Payments Europe) and USDPF + SCCs
ResendTransactional email deliveryUSSCCs

We will notify you of sub-processor changes as set out in the DPA. We do not sell personal data or use it for third-party advertising.

Your rights

You can exercise at any time your rights of access, rectification, erasure, objection, restriction and portability (and withdraw any consent without retroactive effect) by writing to soporte@enrivasgarcia.com from your account email. We reply within the legal one-month period. You may also lodge a complaint with the Spanish Data Protection Agency (aepd.es).

Security

We apply appropriate technical and organisational measures: encryption in transit, integration credentials encrypted with AES-256-GCM, EU hosting, irreversible pseudonymisation of IPs in events, per-workspace access control (RLS) and logging of administrative access.

Documentary integrity and proof of consent

When you accept our legal documents we record the server date and time, the IP address you accepted from, your browser's user agent, the language the document was shown to you in, its version and the SHA-256 hash of its exact text. We process the IP and the user agent PRECISELY because the GDPR requires us to be able to demonstrate consent: without them, the record would prove very little. We do not use them to profile you or for advertising.

That record survives the closure of your account, detached from your live identity and keeping only what is strictly necessary to evidence what you accepted and when. You can request a copy of your consent records by writing to us.

Cookies

The cookies and similar technologies we use are described in the Cookie Policy (/legal/cookies).

Version history

  • 1.1 (2026-07-22): registro de consentimiento forense — se declaran la IP, el user agent y el hash del texto aceptado, con su base jurídica y su conservación tras el cierre de cuenta (D-LEGAL-2).
  • 1.0 (2026-07-22): versión completa del servicio; sustituye a la política informativa de la web (que cubría solo la captura de email de la landing).