This policy explains what personal data is processed when you visit infocrypto.site, for what purposes, for how long, who else is involved and what you can do about it. The site is operated from Spain, so the processing described here is governed by Regulation (EU) 2016/679 (the GDPR) and by Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD). In short: the site has no user accounts, sells no data and collects directly only what you send us by email; everything else depends on your consent.
Data controller
- Controller: [TO COMPLETE: full name of the owner]
- Tax ID: [TO COMPLETE: tax identification number]
- Address: [TO COMPLETE: full postal address]
- Email: contacto@infocrypto.site
- Website: https://infocrypto.site
No data protection officer has been appointed, since none of the circumstances set out in article 37 of the GDPR or article 34 of the LOPDGDD applies.
What data is collected, and how
Data you provide. If you write to contacto@infocrypto.site, we process your email address, the name or alias you sign with and the content of your message, attachments included. Please do not include special category data, identity documents, private keys, recovery phrases or banking details: we do not need them and, if we receive them, we will delete them.
Browsing data collected by third parties. If you accept advertising or analytics cookies, those providers may process cookie identifiers, IP address, device, browser, operating system, language, page visited, referrer and approximate location derived from the IP address. The third party collects this from your browser; this site has no access to individual-level information, only, where applicable, to aggregated reports.
Server logs. The hosting provider generates access logs (IP address, date and time, resource requested, response code and user agent) which are necessary to deliver the service and to prevent attacks. The site carries out no profiling and takes no automated decisions: personalisation of ads is done by Google, and only if you consent.
Purposes and legal bases
1. Answering your enquiries. Legal basis: performance of the relationship established when you contact us (article 6(1)(b) GDPR). Without your contact details we could not reply.
2. Correcting content errors when a reader points out a wrong figure, and 3. protecting the security of the site through technical logs against unauthorised access and automated abuse. Legal basis for both: legitimate interests (article 6(1)(f)), as recognised in recital 49 of the GDPR.
4. Audience measurement. Analytics cookies, where used, tell us which pages are read and how people reach them. Legal basis: your consent (article 6(1)(a) GDPR, together with article 22.2 of the Spanish LSSI implementing the ePrivacy rules).
5. Advertising and personalised advertising. The site is funded by Google AdSense advertising. Legal basis: your consent, given through the banner shown on your first visit.
6. Legal obligations. Retention and disclosure of data where required by law or by a competent authority (article 6(1)(c) GDPR).
You may withdraw your consent for purposes 4 and 5 at any time, without affecting the lawfulness of processing carried out beforehand; how to do so is explained in the cookie policy.
Retention periods
- Emails: up to twelve months from the last communication, then deleted.
- Correspondence about published corrections: three years, to evidence the origin and date of the correction.
- Rights requests: three years from resolution, as proof that they were handled.
- Server logs: typically between thirty and ninety days. [TO COMPLETE: period under the contract with the hosting provider]
- Cookies: the lifetimes stated in the cookie policy, with a maximum of twenty-four months for the consent record.
Where a legal obligation or an ongoing claim exists, data is blocked and kept available to courts, tribunals and public authorities for the applicable limitation period.
Recipients and processors
Personal data is neither sold nor shared for commercial purposes. The following providers are involved:
- Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), which provides AdSense and, where applicable, Analytics. For AdSense it acts largely as an independent controller of the advertising data; for Analytics, as a processor on this site's behalf.
- Hosting: [TO COMPLETE: company name and registered address of the provider], acting as a processor under the contract required by article 28 of the GDPR.
- Email: [TO COMPLETE: mailbox provider], which hosts the messages you send us.
- Public authorities, courts and tribunals, where there is a legal obligation.
International transfers
Some providers operate infrastructure outside the European Economic Area. Any international transfer relies on the EU-US Data Privacy Framework, for which the European Commission adopted an adequacy decision on 10 July 2023, where the provider is certified under it; or otherwise on the standard contractual clauses of Implementing Decision (EU) 2021/914, together with any supplementary measures found necessary after assessing the law of the destination country. You can request information about these safeguards at contacto@infocrypto.site.
Personalised advertising and Google
Google and its partners use cookies and identifiers to serve and measure ads: they cap how often you see the same ad, detect fraudulent clicks, measure campaign effectiveness and, if you consent, select ads based on interests inferred from the pages you visit, here and across Google's network.
- How Google uses information from sites that use its services: https://policies.google.com/technologies/partner-sites
- Ad settings for your account, where personalisation can be turned off: https://myadcenter.google.com/
If you do not give consent, or you withdraw it, you will still see advertising, but it will not be based on an interest profile; non-personalised ads may still require limited measurement and anti-fraud cookies, as Google explains. This site uses no affiliate links, so there is no conversion tracking.
Your rights
The GDPR grants you the following rights, free of charge:
- Access: to know whether we process data about you, which data, for what purposes, for how long and to whom it is disclosed, and to obtain a copy.
- Rectification: to have inaccurate data corrected and incomplete data completed.
- Erasure (the "right to be forgotten"): to request deletion when the data is no longer necessary or when you withdraw consent.
- Objection: to object, on grounds relating to your particular situation, to processing based on legitimate interests; we will stop unless compelling grounds override your interests.
- Restriction: to ask that your data be retained but not used, for instance while a contested item is verified.
- Portability: to receive the data you provided in a structured format, or to have it transmitted to another controller, where processing is automated and based on consent or contract.
- Withdrawal of consent: to revoke consent given for analytics or advertising cookies, without retroactive effect.
- Not to be subject to automated decisions producing legal effects. This site takes none.
How to exercise them. Write to contacto@infocrypto.site stating which right you are exercising and what you are asking for. If your identity is not apparent from your message, we may ask for documentation proving it, used for that purpose only. We reply within one month, extendable by a further two months where the request is complex, which we would tell you about within the first month.
Complaint to a supervisory authority. If your request is not handled properly, or you believe the processing breaches the rules, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) (C/ Jorge Juan, 6, 28001 Madrid), through its electronic office at www.aepd.es, which is the authority supervising this site. If you are in another EU or EEA country, you may instead lodge your complaint with your own national supervisory authority or with the authority of the place where the alleged infringement occurred. It is free of charge and does not require you to have written to us first, though we would be glad of the chance to resolve matters directly.
Security measures
Measures appropriate to the risk are applied (article 32 GDPR): HTTPS across the whole site, a mailbox with a strong password and two-step verification, least-privilege access, up-to-date software and backups. The site is static and holds no user database, which greatly reduces the attack surface. In the event of a personal data breach posing a risk to your rights, the Spanish Data Protection Agency will be notified within seventy-two hours and, where the risk is high, the affected individuals as well.
Children
The content is aimed at adults. We do not knowingly process data from children under fourteen, the age from which article 7 of the Spanish LOPDGDD allows a child to consent on their own behalf; other EU countries set that threshold anywhere between thirteen and sixteen under article 8 of the GDPR. If you know that a child has given us data without their guardians' authorisation, write to us and we will delete it.
Changes to this policy
This policy may be updated to reflect regulatory changes, new providers or modifications to the site. The version in force is the one published here, with its date in the heading. Where a change affects the purposes or the legal bases, consent will be sought again if the rules require it. For any question, write to contacto@infocrypto.site; see also the legal notice and the cookie policy.