[ Legal ]
Privacy policy
The personal data we decide about: on this website, when you reserve, and when you write to us. Mail in a Skein workspace follows the data processing agreement instead.
Effective 4 October 202601Who is responsible
The controller of your data is Carlos Martínez, a self-employed professional in Spain (NIF 49424598J), Carrer Josep Maria Folch i Torres, 6, 43480 Vila-seca (Tarragona), Spain.
For anything about your data, write to info@skein.email.
02What this policy covers
This policy covers the website, the founder reservation, billing and our emails with you. When your organization uses Skein, the mail, contacts and calendars in its workspace belong to your organization: we process them on its behalf, under the data processing agreement.
03What we collect and why
| Data | Why | Legal basis (GDPR art. 6) | How long |
|---|---|---|---|
| Email address and the team you reserve for | To hold your founder place, confirm it and set up your access | Contract (6.1.b) | While you are a customer, then as billing records |
| Name, billing address, VAT id, payment method | To charge, invoice and prevent fraud. Stripe holds the card; we never see its number | Contract (6.1.b) and legal obligation (6.1.c) | 6 years for accounting and tax records |
| What you write to us | To answer you and handle refunds or requests | Contract (6.1.b) or legitimate interest in answering (6.1.f) | Until the matter is closed, unless it becomes part of a billing record |
| IP address and browser details in server logs | To keep the website secure and working | Legitimate interest in security (6.1.f) | 30 days |
| IP address when you open a payment | To stop automated abuse of the reservation | Legitimate interest in security (6.1.f) | In memory only, 120 seconds at most |
We do not use analytics, advertising or tracking on this website, and we do not sell your data.
04Who we share it with
Only the providers that run the website, payments and email for us, under contracts that bind them to our instructions. The subprocessor list names each one, what it does and where. We disclose data to authorities only when the law requires it.
05Transfers outside the EU
We keep data in the EU where providers allow it. Where a provider or its parent company is outside the EU, the transfer is covered by the EU–US Data Privacy Framework or the European Commission’s Standard Contractual Clauses, as the subprocessor list states for each.
06Your rights
- Access your data and get a copy of it.
- Correct it, or ask us to delete it.
- Restrict or object to how we use it, including any processing based on legitimate interest.
- Take it to another provider (portability).
Write to info@skein.email from your address. We answer within one month. Data we must keep by law, such as invoices, is kept for that period only.
If you think we handle your data wrongly, you can complain to the Agencia Española de Protección de Datos (AEPD).
08Automated decisions
We make no decisions about you by automated means that have legal or similar effects. The Skein agent works on your organization’s mail on its instructions, as the data processing agreement describes.
09Changes
We date every version at the top of this page and email customers before a change that affects them. Carlos Martínez is responsible for this policy.