Privacy Policy
Version 1.1 · 22 July 2026
This policy explains what personal data we process, why and on which legal basis, when you visit nemolink.app or use NEMO. It is written to be read: no fine print, just like the product — measure without invading.
Controller
{TITULAR} (full identification in the Legal Notice). Contact for anything privacy-related: soporte@enrivasgarcia.com.
Two different roles
We are the CONTROLLER of your data as a NEMO user (account, billing, support, service emails). We are a PROCESSOR regarding the data of your websites' and links' visitors that NEMO measures on your behalf and under your instructions: for that data the controller is you, and our relationship is governed by the Data Processing Agreement (DPA) published at /legal/dpa.
What we process and on which basis
| Processing | Data | Legal basis | Retention |
|---|---|---|---|
| Account and service provision | Email, language, content you create (links, tags, integrations) | Contract performance (art. 6.1.b GDPR) | While the account exists |
| Subscription and billing | Plan state and Stripe customer identifiers (we never store cards) | Contract performance and legal obligations (6.1.b and 6.1.c) | Account life + tax retention periods |
| Consent record (forensic proof) | Document, version, language, SHA-256 hash of the exact text you saw, server date and time, IP address and user agent | Legal obligation to be able to DEMONSTRATE consent (art. 7.1 GDPR, basis 6.1.c) and legitimate interest in defending against claims (6.1.f) | For as long as it may be needed to evidence it; SURVIVES account closure, detached from your live identity |
| Service lifecycle emails | Email, language and aggregated workspace metrics | Contract performance (service notices, not third-party marketing) | While the account exists |
| Measurement of your links (on your behalf) | Click events with irreversibly pseudonymised IP (truncated hash with daily salt), user-agent, referrer; leads and sales your platforms send us | Processing on your behalf: the basis is determined by you as controller | Per plan: visible for 30 days on Free, the rest VEILED (not visible, not deleted) while your account exists |
| Security and anti-abuse | Technical logs and bot signals | Legitimate interest (6.1.f): protecting the service and third parties | The minimum necessary |
We never store plain IP addresses in event tables, nor emails in measurement records. Veiled data on the Free plan remains not visible: veiled means not visible, never deleted while your account exists; it is erased with the account, with the sole exception of the consent record described below.
Sub-processors and transfers
We use infrastructure providers under data processing agreements. Product data is hosted in the European Union; where a provider may process data from outside the EU, the transfer relies on its Data Privacy Framework (DPF) certification or on Standard Contractual Clauses (SCCs).
| Provider | Function | Data location | Mechanism |
|---|---|---|---|
| Supabase | Database and authentication | EU (eu-west-1 region, Ireland) | SCCs (Supabase DPA) |
| Vercel | Application hosting (EU region) | EU; support from the US | DPF + SCCs |
| Upstash | Rate limiting | EU (European region) | SCCs |
| Stripe | Payments and invoicing (merchant of record) | EU (Stripe Payments Europe) and US | DPF + SCCs |
| Resend | Transactional email delivery | US | SCCs |
We will notify you of sub-processor changes as set out in the DPA. We do not sell personal data or use it for third-party advertising.
Your rights
You can exercise at any time your rights of access, rectification, erasure, objection, restriction and portability (and withdraw any consent without retroactive effect) by writing to soporte@enrivasgarcia.com from your account email. We reply within the legal one-month period. You may also lodge a complaint with the Spanish Data Protection Agency (aepd.es).
Security
We apply appropriate technical and organisational measures: encryption in transit, integration credentials encrypted with AES-256-GCM, EU hosting, irreversible pseudonymisation of IPs in events, per-workspace access control (RLS) and logging of administrative access.
Documentary integrity and proof of consent
When you accept our legal documents we record the server date and time, the IP address you accepted from, your browser's user agent, the language the document was shown to you in, its version and the SHA-256 hash of its exact text. We process the IP and the user agent PRECISELY because the GDPR requires us to be able to demonstrate consent: without them, the record would prove very little. We do not use them to profile you or for advertising.
That record survives the closure of your account, detached from your live identity and keeping only what is strictly necessary to evidence what you accepted and when. You can request a copy of your consent records by writing to us.
Cookies
The cookies and similar technologies we use are described in the Cookie Policy (/legal/cookies).
Version history
- 1.1 (2026-07-22): registro de consentimiento forense — se declaran la IP, el user agent y el hash del texto aceptado, con su base jurídica y su conservación tras el cierre de cuenta (D-LEGAL-2).
- 1.0 (2026-07-22): versión completa del servicio; sustituye a la política informativa de la web (que cubría solo la captura de email de la landing).