Skip to content

Legal information

Privacy policy

This site collects personal data only when you submit the contact form. Below: who processes it, why, for how long, and what you can demand at any time.

Version 1.0 · updated September 22, 2026

Controller
Arnau Lafuente Federico
Tax ID
48098296Y
Address
Carrer Bernat Metge, 27, 08100 Mollet del Vallès
Contact email
contacte@arlaf.com

No data protection officer has been appointed: the processing does not meet the thresholds that would require one (GDPR art. 37).

There is a single processing activity across the whole site: the contact form.

Data
Name, email address, service of interest (optional) and the content of the message you write.
Purpose
To handle and reply to your enquiry, and to prepare a quote if you ask for one.
Legal basis
Steps taken at your request prior to entering into a contract (GDPR art. 6.1.b). When you write to hire a service or request a quote, processing your data is necessary to respond to you: no additional consent is required, which is why the form has no tick box.
Retention
As long as needed to handle the enquiry and, if no contractual relationship follows, 12 mesos des de l'últim contacte. If a contract does follow, the data is kept for the duration of the relationship and any applicable statutory limitation periods.
Automated decisions
None. No profiling or automated decision-making is carried out with your data.

No marketing emails or newsletters are sent: this site has no mailing list.

Your data is never sold or handed to third parties. Two providers act as processors — they handle the data on my instructions and under contract:

Web3Forms
Delivers the form message to my inbox. It is the only provider that sees what you write. Your browser never connects to it directly: the form is submitted to arlaf.com and my server relays it, so your IP address never reaches this provider. International transfer covered by: clàusules contractuals tipus de la Comissió Europea, incorporades al contracte d'encarregat del tractament de Web3Forms.
Cloudflare
Hosts the site and provides the cookieless analytics described below. As the host it receives your IP address on every visit, as any web server does. International transfer covered by: certificació EU-US Data Privacy Framework (amb clàusules contractuals tipus com a mecanisme de reserva).

This site uses no advertising, social or tracking cookies, and no localStorage, sessionStorage or other persistent browser storage. That's why you won't find a cookie banner: there is nothing to consent to.

The only cookies that may be set are technical and authentication cookies, exempt from consent under article 22.2 of the LSSI, and only if you access a password-protected area:

__Host-cv_session
First-party · keeps your session open in the CV area · 7 days.
__Host-study_session
First-party · keeps your session open in the study materials area · 7 days.
__Host-admin_session
First-party · content manager session, administrator only · 7 days.
oauth_state
First-party · protects the administrator's sign-in against CSRF attacks · 10 minutes.

For analytics I use Cloudflare Web Analytics, which measures visits and load speed without setting any cookie and without building a profile of you. You can block or delete cookies from your browser settings at any time; the technical ones only affect the protected areas.

You can exercise these rights by writing to contacte@arlaf.com. I will reply within one month at most. You need not justify your reason, and it costs nothing.

  • Access — find out what data of yours I hold and what I do with it.
  • Rectification — have it corrected if inaccurate or incomplete.
  • Erasure — ask for it to be deleted once it is no longer needed.
  • Objection — object to the processing on grounds relating to your particular situation.
  • Restriction — ask me to keep it but stop processing it while a dispute is resolved.
  • Portability — receive it in a structured, commonly used format.

If you believe your request has not been handled properly, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es), the competent supervisory authority.

The whole site is served encrypted over HTTPS. Private areas are protected on the server, with cryptographically signed sessions and a limit on access attempts. The providers listed above are bound by data processing agreements (GDPR art. 28). Should a security breach occur that posed a risk to your rights, I would inform you and notify the AEPD within the statutory 72-hour deadline.