Privacy Policy

Last updated: January 15, 2024

Stable Tech ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or interact with our services, in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

Data Controller

The data controller responsible for your personal data is:

Stable Tech S. L.

Avenida de la Ilustración 18

50019 Zaragoza

Spain

Email: [email protected]

Scope of this Policy

This Privacy Policy applies to:

  • Visitors to our website (thestabletech.com)
  • Individuals who contact us via our contact form, email, or other channels
  • Prospective clients requesting information about our services

This policy does not apply to:

  • Products or applications we develop for clients (which are covered by separate agreements)
  • Internal employee data (covered by employment agreements and internal policies)
  • Third-party websites linked from our site (please review their privacy policies)

What Data We Collect

We collect the following types of personal data:

Contact & Communication Data

When you contact us through our website or email, we collect:

  • Full name
  • Work email address
  • Company name (optional)
  • Project type and budget range (when provided via contact form)
  • Project description and any information you choose to share in your message

Usage & Analytics Data

We collect data about how you interact with our website through PostHog analytics:

  • Pages visited and time spent on pages
  • Click events and user interactions
  • Device information (browser type, operating system, screen resolution)
  • Approximate geographic location (country or region level)
  • Referrer information (how you arrived at our site)
  • Session duration and frequency of visits
  • Pseudonymous identifiers (not linked to your real identity)

Server & Infrastructure Logs

Our hosting provider automatically logs:

  • IP addresses
  • HTTP request data (URLs accessed, user agents)
  • Timestamps of requests
  • Error logs for troubleshooting

Cookies & Similar Technologies

We use cookies and similar tracking technologies. For detailed information, please see our Cookies Policy.

How We Use Your Data

We use your personal data for the following purposes:

  • Responding to inquiries: To answer your questions, provide information about our services, and maintain communication with prospects and clients.
  • Preparing proposals: To understand your project requirements and prepare accurate quotes and service proposals.
  • Improving our services: To analyze website usage patterns and identify areas for improvement in our website and service offerings.
  • Analytics and product decisions: To understand how visitors interact with our content and make data-driven decisions about our website and marketing.
  • Security and fraud prevention: To detect and prevent malicious activity, spam, and abuse of our services.
  • Legal compliance: To comply with applicable laws, regulations, and legal processes.

Analytics & Tracking (PostHog)

We use PostHog for website and product analytics. PostHog helps us understand how visitors use our website, which pages are most valuable, and how we can improve user experience.

What PostHog Collects

PostHog collects:

  • Page views, navigation paths, and session recordings (if enabled)
  • Click events and user interactions
  • Device and browser information
  • Approximate location (country/region, not precise geolocation)
  • Pseudonymous user identifiers (distinct IDs that don't reveal your identity)

Data Processing Details

PostHog as Data Processor: PostHog acts as a data processor on our behalf.

IP Address Handling: Yes, we anonymize IP addresses.

PostHog's Privacy Policy: For more information about how PostHog processes data, see their privacy policy .

For detailed information about cookies set by PostHog, see our Cookies Policy.

Data Sharing & Processors

We share your personal data with trusted third-party service providers who act as data processors on our behalf. These processors are contractually obligated to process data only according to our instructions and to implement appropriate security measures.

Our Data Processors

PostHog

Purpose: Website analytics and product analytics. Tracks user behavior, page views, events, and user flows to help us understand how visitors use our website and improve user experience.

Type: analytics

Location: United States (US Cloud deployment) or European Union (EU Cloud deployment)

Retention: 30 days

Privacy Policy: https://posthog.com/privacy

Cloudflare Pages

Purpose: Website hosting and content delivery. Provides the infrastructure to serve website content to visitors.

Type: hosting

Location: United States (US Cloud deployment) or European Union (EU Cloud deployment)

Retention: 30 days

Privacy Policy: https://www.cloudflare.com/privacypolicy/

Calendly

Purpose: Meeting scheduling and calendar management. Allows prospects and clients to book discovery calls and meetings with our team.

Type: scheduling

Location: United States (US Cloud deployment) or European Union (EU Cloud deployment)

Retention: 30 days

Privacy Policy: https://calendly.com/privacy

Web3Forms

Purpose: Contact form submission handling. Receives and forwards contact form submissions from the website.

Type: other

Location: United States (US Cloud deployment) or European Union (EU Cloud deployment)

Retention: 30 days

Privacy Policy: https://web3forms.com/privacy

We do not sell personal data. We never sell, rent, or trade your personal information to third parties for their marketing purposes.

International Data Transfers

Some of our data processors may be located outside the European Economic Area (EEA) or Switzerland. When we transfer personal data to countries that do not provide an adequate level of data protection, we ensure appropriate safeguards are in place.

Transfer Mechanisms

We rely on the following mechanisms for international data transfers:

  • Standard Contractual Clauses (SCCs): EU Commission-approved contract terms that provide safeguards for data transfers.
  • Adequacy Decisions: Where the EU Commission has determined that a country provides adequate data protection.
  • Processor Guarantees: Some processors (like PostHog) offer EU cloud hosting options to keep data within the EEA.

You have the right to obtain information about the safeguards we have in place for international transfers. Please contact us using the details below.

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal obligations.

Retention Periods

Contact Form Submissions:

3 months from the date of last communication. After this period, data is deleted unless there is a legitimate business reason to retain it (e.g., ongoing project or contractual relationship).

Analytics Data (PostHog):

30 days, after which it is automatically deleted from PostHog's systems.

Server Logs:

30 days (typically 30-180 days) for security and troubleshooting purposes.

Client Project Data:

Retained for the duration of the project and 3 years afterward to comply with legal and tax obligations.

You can request deletion of your data at any time by contacting us, subject to legal obligations that may require us to retain certain information.

Your Rights under GDPR

Under the GDPR, you have the following rights regarding your personal data:

Right of Access (Article 15)

You can request a copy of the personal data we hold about you and information about how we process it.

Right to Rectification (Article 16)

You can request that we correct inaccurate or incomplete personal data.

Right to Erasure / "Right to be Forgotten" (Article 17)

You can request deletion of your personal data in certain circumstances, such as when it is no longer necessary for the purposes for which it was collected.

Right to Restriction of Processing (Article 18)

You can request that we limit how we use your data in certain situations, such as while we verify the accuracy of data you have contested.

Right to Data Portability (Article 20)

You can request to receive your data in a structured, commonly used, machine-readable format and have it transmitted to another controller.

Right to Object (Article 21)

You can object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Where we rely on consent, you can withdraw it at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.

Right to Lodge a Complaint

You have the right to lodge a complaint with your local data protection supervisory authority if you believe we have violated your data protection rights.

How to Exercise Your Rights

To exercise any of these rights, please contact us at [email protected] . We will respond to your request within one month, as required by GDPR. In complex cases, we may extend this period by up to two additional months and will inform you of the extension.

We may need to verify your identity before processing your request to ensure the security of your personal data.

Security Measures

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

Our Security Practices Include:

  • Encryption of data in transit (HTTPS/TLS)
  • Access controls and authentication mechanisms
  • Regular security assessments and updates
  • Secure hosting infrastructure with reputable providers
  • Contractual obligations with processors to maintain security standards
  • Regular backups and disaster recovery procedures

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If you become aware of any security breach, please contact us immediately.

Children's Data

Our website and services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16.

If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that information as soon as possible.

If you are a parent or guardian and believe your child has provided us with personal data, please contact us at [email protected] .

Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational, legal, or regulatory reasons.

When we make material changes to this policy, we will:

  • Update the "Last updated" date at the top of this page
  • Notify you via email if we have your contact information (for significant changes)
  • Post a notice on our website homepage (for significant changes)

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us:

Stable Tech S. L.

Avenida de la Ilustración 18

50019 Zaragoza

Spain

Email: [email protected]

For privacy-specific inquiries: Please include "Privacy Request" or "GDPR Request" in your email subject line to ensure prompt handling.