LEGAL FRAMEWORK & GDPR

Privacy Policy

At CLEARTORA we treat privacy with the same rigour we apply to the software we build. Below we explain how we handle and protect your personal data.

Our commitment: We do not sell your data or pass it to third parties for advertising. Everything you tell us is used strictly to assess whether your project is technically viable and to deliver our professional services.

1. Data Controller

The controller for data collected through this website is:

  • Name: CLEARTORA Technologies S.L. (en constitución) — a Spanish company in the process of incorporation
  • Activity: Software development, technology consultancy, automation and artificial intelligence agents.
  • Privacy contact: legal@cleartora.com

2. What We Collect, and How

The details of your enquiry let us understand what you need and reply to you:

  • Your enquiry: Name, email address, a description of what you want to improve, your preferred timeframe and your company name if you choose to give it. These details reach us by email at the moment you send them and are not stored in any database. If you'd rather write to us directly, we receive whatever you include in your message.
  • Technical and browsing data: Anonymised IP address, session identifiers, pages visited and UTM parameters showing where you came from — used only for analytics and attribution, and only once you have accepted non-essential cookies.

3. Why We Use It

We process your data for the following legitimate purposes:

  • Technical and operational assessment: Reviewing your enquiry to work out whether a viable, automatable solution exists before proposing a working session.
  • Replying and following up: Answering your enquiry by email and, if we can help, arranging a first 20-minute conversation.
  • Contractual matters: If we go on to work together, setting out the licence, development or service terms, the quotes and any confidentiality agreements that apply.
  • Improving the site: Analysing traffic and performance to keep the website available and technically secure.

The legal grounds that allow us to process your data are:

  • Your consent (Art. 6.1.a GDPR): Given unambiguously when you tick the acceptance box before sending the contact form, or when you accept analytics cookies.
  • Pre-contractual steps (Art. 6.1.b GDPR): When you ask us for a technical proposal, an audit or a development quote.
  • Legitimate interest (Art. 6.1.f GDPR): In keeping our technical infrastructure secure and preventing fraud or abuse of the system.

5. How Long We Keep It

Information submitted through forms is kept only for as long as it takes to deal with your request and follow up on the project you described.

If the enquiry does not lead to a commercial or contractual relationship, the data is deleted within a maximum of 12 months, unless a legal obligation requires us to keep it or you expressly withdraw it sooner.

6. Who Else Is Involved

Cleartora does not sell or pass personal data to third parties for advertising. The only third parties involved are the providers needed to run the website, let you write to us and measure how the site is used — and they are all listed here, one by one.

Hosting and content delivery. The site is served from Cloudflare, Inc. Cloudflare handles the connection data required to deliver the pages and protect them from attack, acting as a data processor.

Aggregate usage measurement. We use Cloudflare Web Analytics, which sets no cookies and does not fingerprint your device. That is why it needs no consent and does not appear in the Cookie Policy table.

Analytics and behaviour analysis, only with your consent. If you accept the statistics category in the banner — and only then — we additionally load:

  • Google Analytics 4, provided by Google Ireland Limited, to see how many people visit the site and which pages they look at.
  • Microsoft Clarity, provided by Microsoft Ireland Operations Limited, which produces heatmaps and anonymous session recordings so we can spot where the site is confusing.

Until you accept, neither of these two services is downloaded to your browser: they never receive your IP address or anything else. If you later withdraw consent, they stop collecting information and their cookies are removed.

Microsoft Clarity recordings mask the contents of the contact form fields — name, company, email and description — so what you type into them is never recorded.

International transfers. Google and Microsoft may process information on servers in the United States. Both, along with Cloudflare, are certified under the EU-U.S. Data Privacy Framework, which the European Commission has recognised through an adequacy decision, and they additionally apply standard contractual clauses. You can avoid any transfer to these providers entirely by rejecting the statistics category.

Email and the contact form. When you submit the form, what you wrote travels encrypted to a Cloudflare service that does nothing but compose an email and deliver it to our inbox. It is not saved in any database or log: it exists only inside that email. Messages sent to addresses on this domain are routed through Cloudflare Email Routing to mailboxes managed by Google.

The form is protected by Cloudflare Turnstile, which tells a person from an automated program without visual puzzles and without tracking you across websites. It is a security measure the form cannot exist without — otherwise it fills with spam — so it always applies and does not depend on your cookie choices.

Data processing agreements under article 28 of the GDPR are, or will be, in place with all of these providers.

7. Your Rights

As the owner of the data, you have the right at any time to:

  • Access: Find out what personal data of yours we are processing.
  • Rectification: Ask us to correct data that is inaccurate or incomplete.
  • Erasure: Ask us to delete your data once it is no longer needed for the purposes it was collected for.
  • Objection: Object to your data being processed for specific purposes.
  • Restriction: Ask us to restrict processing temporarily in particular circumstances.
  • Portability: Receive your data in a structured, commonly used format.

To exercise any of these rights, send a written request confirming your identity to legal@cleartora.com. You also have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if you believe your rights have been infringed.

8. Security Measures

The website is currently in development, ahead of its production deployment. For the final publication on the definitive domain and server, encrypted communications (HTTPS/TLS) will be enabled, along with technical and organisational measures proportionate to the processing involved.

The specific security arrangements will depend on the final infrastructure contracted by the owner, at which point they will be verified and formally documented.

9. Status of This Document

This text reflects the current informational and technical state of the project and is not a finally validated privacy policy. Before the service opens to the public, the website owner must supply and confirm the outstanding essential details: the definitive legal identity (registered name, tax number and address), the hosting and email providers actually contracted, and the activation of security and encryption in the production environment.

Any update arising from those decisions will be reflected on this same page.

10. Language of This Policy

This English text is provided for convenience. The Spanish version is the legally binding one, and it prevails in the event of any discrepancy between the two. You can read it at cleartora.com/es/privacidad/.