Privacy policy
How we handle your data under the GDPR, which providers are involved and how to exercise your rights. With the Article 28 agreement for your own clients’ data.
Data controller
Mindset & Code is the trading name under which Guillermo Úbeda Garay provides process automation, data analysis and software development services. Registered as a business in Spain. Contact: contacto@mindset-code.com. Address for notices: C/ del Centre, 5 BX, 08820 El Prat de Llobregat (Barcelona), Spain.
Applicable legal framework
We serve clients from Spain, and personal data is governed by Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD). If you are outside the European Economic Area and your country grants you additional guarantees, we apply the more protective of the two standards.
Data we process
From the website: what you type into the contact form — name, email and message — along with the page you wrote from, which tells us which service you mean without having to ask. If you buy a fixed-price engagement here, we also keep the evidence of what you accepted: the exact text of the terms you saw, its SHA-256 hash, the date and the IP address it was accepted from. That is what lets us demonstrate your consent, as article 7(1) GDPR requires. When you sign a document in the portal we keep the equivalent proof of that signature: the name and identity document you declared, the date and time, the SHA-256 hash of the exact text shown to you, and the IP address and browser you signed from. The last two stay in our records and are NOT printed on the PDF: what appears instead is a verification code that summarises them through a calculation with a private key, so that you can hand the document to a bank, a public body or the other party without revealing where you connect from. Without that proof the electronic signature could not stand if anyone disputed it, so it is kept for as long as the document remains valid; you can ask us for a copy at any time. If you use the client portal: your email, your signed-in session and the documents you upload. From the professional relationship: identification and billing data, and whatever is needed to do the contracted work — access to your systems, data files, documents you send us. When we automate a process or build a dashboard, those files may include third-party data — your clients, your suppliers or your staff — which we process solely on your behalf and under the Article 28 processing agreement.
Purposes and legal basis
Answering your enquiry and sending you a proposal: your consent. Providing the service you contracted: performance of the contract. Issuing invoices, keeping the books and retaining documentation: legal obligation. Retaining evidence of the electronic signature — date, IP, browser and document hash: performance of the contract, and the accountability principle in Article 5(2) GDPR, which requires us to be able to demonstrate what we process and on what consent. We do not use your data for profiling and we take no automated decisions about you.
When we act on a client's behalf
When we automate one of your processes, build a dashboard from your data or maintain your website, we process personal data for which you are the controller and we are the processor: your clients’, your suppliers’ or your staff’s. That relationship is governed by a data processing agreement (Article 28 GDPR) signed before we start: it sets the instructions, confidentiality, security measures, the sub-processor regime and what happens to the data at the end. If you need the template before contracting, we will send it to you.
How long we keep it
Enquiries that do not lead to a contract are deleted after 12 months. Client documentation is kept for as long as the relationship lasts and afterwards for the legal periods: four years of tax limitation and six years of retention for commercial books and records. When an engagement that handled your own clients’ data ends, the data is returned or deleted according to what you chose in the processing agreement, and access is revoked.
Who we share it with
With Stripe, which processes payments: it receives your email address and your card details directly, without passing through this site, and processes them under its own responsibility as a payment institution. With Google (Firebase), which underpins access to the client portal and the database behind its projects; the documents you upload to the portal are NOT held by Google but on our own server. With nobody else: we do not sell or transfer data for commercial purposes, and there is no authority to which we file anything on your behalf.
International transfers
We work from Spain. Two of our providers have a US parent company: Google, which underpins portal access, and Stripe, which processes payments. Both contract with European Economic Area clients through their Irish subsidiaries and cover transfers outside the EEA under the Chapter V GDPR safeguards — an adequacy decision or standard contractual clauses — on the terms of their own data processing addenda. If you would rather your data did not leave the EEA, tell us before contracting and we will arrange the service accordingly: the portal and the payment gateway are the only two pieces that depend on them, and both have alternatives.
Your rights
You may request access, rectification, erasure, objection, restriction of processing and portability, and withdraw your consent at any time, by writing to contacto@mindset-code.com. We will answer within one month. If you are not satisfied, you may complain to the Spanish Data Protection Agency (aepd.es), as well as go to court. Exercising these rights is free of charge.
Security
We encrypt the site’s communications and access to the client portal, we limit who can see each file and we keep an access log. Your files and your credentials are handled in systems with access control, not in open shared folders or email threads, and any access you grant us to your systems is revoked when the work ends. Should a breach occur that poses a risk to your rights, we will tell you and notify the authority within the 72 hours the GDPR sets.
Artificial intelligence
We use artificial intelligence as a working tool, and we think you are entitled to know where — and above all where not. Where we do: to write and translate the blog articles and the text on this site, and to write and review code. Everything published goes through human review before it ships, and editorial responsibility rests with Guillermo Úbeda Garay. That review is precisely the condition article 50(4) of Regulation (EU) 2024/1689 on artificial intelligence — applicable since 2 August 2026 — requires in order not to have to label each text. Where we do not: on your data behind your back. A client’s files and documentation are not sent to an artificial intelligence provider unless the contracted service requires it and we tell you so in writing beforehand. When that happens, the data is pseudonymised first on our own machines — tax number, name and account numbers stripped out — and we use providers contractually bound not to train their models on it. This site has no chatbot: if you write through the form or by WhatsApp, a person answers. We do not profile you and we take no automated decisions about you, neither on the site nor in the service. And one rule that is not up for negotiation: whatever comes out of an AI tool is a draft. No code, no report and no text is delivered or put into production until a person has read it in full and signed it.
Cookies and browser storage
This site stores two kinds of thing in your browser, and only one of them asks you first. What it does not ask about, because it does not need to. Four technical preferences that never leave your device and do not identify you: the language, whatever you have added to your selection of engagements, the opt-out marker if you have asked not to be counted, and your own answer to the cookie notice. If you sign in to the client portal, Firebase also keeps your session so you do not have to type the password on every page. All of that is either necessary for the site to work or a preference you chose yourself, so it is exempt from prior consent under article 22.2 of Spanish Act 34/2002. It does not ask about the visit count either, because we do that with our own counter hosted on our server: it sets no cookies, stores neither your IP address nor any identifier, and cannot recognise you across two visits. It keeps working whatever you answer. If you would still rather not appear in it, go to mindset-code.com/?sinmedir=1 and we will stop counting this browser; to undo it, ?sinmedir=0. What it does ask about: Google Analytics 4. It arrives through Google Tag Manager and does set first-party cookies on this domain —_ga and _ga_2VC2ERK0WT, both lasting two years— holding a random identifier that can tell visitors apart. That is exempt from nothing, so it is not installed unless you press «Accept» in the notice shown on arrival, and rejecting it takes exactly the same single click as accepting. Google receives the page you are on, the time, the language, the device type and an estimated country; the IP address is used for that estimate and Google discards it without storing it. Advertising signals stay denied at all times, including when you accept: there is no remarketing and no data is shared with the ad network. The legal basis is your consent (article 6.1.a GDPR). How to change your mind: «Cookie preferences» at the foot of any page reopens the notice so you can decide again. Withdrawing consent is as easy as giving it, carries no consequence, and clearing your browser data has the same effect.