Privacy policy
1. Introduction
This privacy policy (the "Policy") explains to users of the website milegavia.com (the "Site") how Juan Martín Ramajo (the "Controller", "we" or "us") collects, processes, uses and protects their personal data.
We are committed to processing your data in accordance with Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 on the Protection of Personal Data and guarantee of digital rights (LOPDGDD), and other applicable regulations in Spain.
By accessing the Site, using our services or providing us with your personal data, you acknowledge that you have read this Policy and accept the practices described in it.
2. Definitions
2.1 Personal data: any information relating to an identified or identifiable natural person (Article 4.1 GDPR).
2.2 Processing: any operation performed on personal data, such as collection, recording, organization, storage, use or erasure (Article 4.2 GDPR).
2.3 Controller: the natural or legal person who determines the purposes and means of the processing (Article 4.7 GDPR). In this case, Juan Martín Ramajo.
2.4 Processor: the natural or legal person who processes personal data on behalf of the controller (Article 4.8 GDPR).
2.5 Consent: any freely given, specific, informed and unambiguous indication of the data subject's wishes (Article 4.11 GDPR).
2.6 User / data subject: any natural person who accesses the Site, browses it or purchases a digital resource.
3. Data controller
The controller of the personal data collected through the Site is:
Juan Martín Ramajo, natural person.
Tax ID (NIF): 51234907S
Address: Calle Maqueda, 77, 28024, Madrid, Spain
Email: legavia.es@gmail.com
4. Data we collect
4.1 Identification data: name, email address.
4.2 Browsing data: IP address, browser type and version, operating system, pages visited, time spent, date and time of connection, traffic source (including advertising campaigns), cookies and session identifiers.
4.3 Transaction data: order information (product, date, amount). Payment data is processed exclusively by Shopify Payments and the integrated payment providers; we do not store any bank card data.
4.4 Communication data: the content of messages sent through the contact form or by email.
We do not collect any special category data within the meaning of Article 9 GDPR.
5. How we collect data
5.1 Direct collection: when you complete an order or the contact form.
5.2 Automatic collection: through cookies, the Meta pixel and the Shopify platform's own logs when you browse the Site.
6. Purposes of processing
6.1 Order management: to process your purchase, send the confirmation and give you access to the digital kit you purchased.
6.2 Transactional communications: emails related to your order (confirmation, delivery, support).
6.3 Targeted advertising: to show you ads on Meta (Facebook/Instagram) through the tracking pixel, subject to your prior consent via the cookie banner.
6.4 Basic analytics: to measure the Site's audience and improve how it works.
6.5 Legal and accounting obligations: to keep billing data as required by Spanish tax and commercial regulations.
7. Legal basis for processing
Each processing activity relies on one of the legal bases in Article 6 GDPR: performance of the sales contract (order management), consent (Meta pixel and advertising cookies, which can be withdrawn at any time), and compliance with a legal obligation (invoicing).
8. Retention periods
- Customer data: for as long as the commercial relationship lasts and, afterwards, for the period required by Spanish tax and commercial regulations (up to 6 years).
- Browsing data and cookies: a maximum of 24 months, in line with the guidance of the Spanish Data Protection Agency (AEPD).
- Contact messages: for as long as needed to handle the inquiry and for a maximum of 12 months.
9. Disclosure of data
We do not sell or disclose your personal data to third parties, except to the processors strictly necessary to provide the service (section 10), or where there is a legal obligation to do so (for example, in response to a court order).
10. Processors
10.1 Shopify Inc.
Role: hosting of the Site, payment processing (Shopify Payments) and sending of transactional emails.
Data processed: browsing, order and payment data.
Location: Canada / United States (international transfer with safeguards, see section 13).
10.2 Meta Platforms Ireland Ltd. (Meta pixel)
Role: advertising tracking and audience creation for ads on Facebook and Instagram.
Data processed: browsing data, in pseudonymized form.
Location: European Union / United States (international transfer with safeguards).
10.3 Payment providers
Visa, Mastercard, American Express, Maestro, Union Pay, Apple Pay, Google Pay, Klarna and Shop Pay process payment data directly; the Controller never stores card data.
11. Cookies
11.1 Definition: a cookie is a small text file placed on your device when you visit the Site.
11.2 Types of cookies: technical cookies needed for the Site to work (no consent required) and advertising cookies from the Meta pixel (prior consent required).
11.3 Consent: when you enter the Site, a cookie banner lets you accept, reject or configure non-essential cookies, in accordance with the Spanish LSSI-CE and the GDPR.
11.4 Management: you can change your preferences at any time from the banner itself or in your browser settings.
12. Data security
We apply reasonable technical and organizational measures: encryption of communications over HTTPS, payment processing by PCI-DSS certified providers, and restricted access to personal data. In the event of a personal data breach that poses a risk to your rights, we will notify the Spanish Data Protection Agency (AEPD) within 72 hours, in accordance with Article 33 GDPR.
13. International transfers
Some of your data may be processed outside the European Economic Area by Shopify Inc. (Canada/U.S.) and Meta (U.S.). In these cases we make sure appropriate safeguards are in place: European Commission adequacy decisions, Standard Contractual Clauses, or the provider's participation in the EU-U.S. Data Privacy Framework.
14. Your rights
Under the GDPR and the LOPDGDD, you have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), objection (Art. 21), portability (Art. 20), withdraw your consent at any time, and lodge a complaint with the AEPD.
15. How to exercise your rights
You can exercise these rights by writing to legavia.es@gmail.com. For security reasons, we may ask you to verify your identity. We undertake to respond within one month, which may be extended to two months in complex cases.
15.1 Complaint to the AEPD
If you believe the processing of your data infringes the GDPR, you can lodge a complaint with:
Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan, 6, 28001, Madrid
www.aepd.es
16. Protection of minors
The Site and the resources it offers are intended for an adult audience. We do not knowingly collect data from children under 14, the minimum age of consent set by Article 7 of the LOPDGDD. If we detect data from a minor without the verifiable consent of their parents or guardians, we will delete it as soon as possible.
17. Changes to this Policy
We may change this Policy at any time. The date of the latest update is shown at the top of this page. In the event of substantial changes, we will notify you by email or through a visible notice on the Site.
18. Contact
For any questions about this Policy or to exercise your rights:
Juan Martín Ramajo
Calle Maqueda, 77, 28024, Madrid, Spain
Email: legavia.es@gmail.com