Privacy policy
Last updated: 30 June 2026
At Kivotech we take the privacy of your data seriously. This policy explains what personal data we process, for what purpose, on what legal basis and which rights you can exercise, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
Data controller
- Controller: Kivotech — [Company name or full name of the owner]
- Tax ID / ID number: [Owner’s tax ID / ID number]
- Registered address: [Registered tax address]
- Email address: asesoramientos.repetto@gmail.com
What data we process
We only process the data you voluntarily provide through the contact form, together with certain technical data associated with your request:
- Form data: name, business name (optional), phone number (optional), email address, project type, approximate budget (optional) and the content of the message.
- Technical data: IP address and user agent (browser/device) at the time of submission, together with the date of receipt, for security purposes and to prevent abuse (spam).
We do not request special categories of data. Please do not include sensitive information in the message field that is not necessary to handle your request.
Purpose of the processing
- To handle and respond to the enquiries and quote requests you send us.
- To manage the pre-contractual relationship and, where applicable, the delivery of the requested services.
- To ensure the security of the Website and prevent fraudulent or automated submissions.
We do not use your data to send you unsolicited commercial communications, nor do we build profiles for advertising purposes.
Legal basis
- Your consent (art. 6.1.a GDPR), given when you submit the form and, where applicable, accept this policy.
- The application of pre-contractual measures at the data subject’s request (art. 6.1.b GDPR), when your request is aimed at contracting our services.
- Our legitimate interest (art. 6.1.f GDPR) in ensuring the security of the Website and preventing fraudulent use.
Data retention
We will keep your data for as long as necessary to handle your request and, if a commercial relationship is formalised, for its duration and for the periods required by law (for example, in tax and commercial matters). Once no longer necessary, the data will be duly deleted or blocked. If your enquiry does not lead to a contractual relationship, we will delete your data within a reasonable period unless you ask us otherwise.
Recipients and data processors
We do not share your data with third parties, except where legally required. To provide the service we rely on technology providers acting as data processors, with whom we maintain the corresponding contracts under art. 28 GDPR:
- Hosting provider: the infrastructure on which the Website is published (e.g. Vercel Inc.).
- Database: storage of contact messages (e.g. Supabase).
- Email delivery: email notification service for incoming requests (e.g. Resend).
Some of these providers may be located outside the European Economic Area. In that case, international transfers are covered by the appropriate safeguards laid down in the GDPR (European Commission standard contractual clauses or recognised adequacy frameworks). Please check and keep this list of providers up to date according to the services actually contracted.
Your rights
You may exercise the following rights at any time by writing to asesoramientos.repetto@gmail.com, stating the right you wish to exercise and attaching, if necessary, a document proving your identity:
- Access: find out what data of yours we process.
- Rectification: correct inaccurate or incomplete data.
- Erasure: ask us to delete your data (“right to be forgotten”).
- Objection and restriction: object to the processing or request its restriction in certain cases.
- Portability: receive your data in a structured, commonly used format.
- Withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.
If you believe that the processing of your data does not comply with the regulations, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
Security
We apply reasonable technical and organisational measures to protect your data against loss, misuse or unauthorised access, including per-IP request limits and filtering of automated submissions.
Changes to this policy
We may update this privacy policy to reflect regulatory changes or new services. The version in force will always be the one published on this page, together with the date of its update.