Penedo Labs

EN ES

Privacy and cookies

What this site collects.

This site is run by Efrén Rodríguez Rodríguez, trading as Penedo Labs, from Galicia, Spain. You can reach me at hello@penedolabs.com about anything on this page.

If you write to me through the form

The form at the foot of the home page sends me your name, your email address, what you said you need, what it has to do, and, if you filled them in, roughly when and your budget range. It arrives as an ordinary email in my inbox and goes nowhere else. It is not written to a database, not passed to any other company, and there is no mailing list attached to it.

The legal basis is Article 6(1)(b) of the GDPR: you asked me for a quote, and answering you is a step taken at your request before a contract. I keep the correspondence for as long as the enquiry is live, and for up to two years afterwards in case you come back; ask me to delete it sooner and I will.

One thing is stored, briefly. So the form cannot be used to send thousands of messages, the server counts how many have come from your IP address in the last hour. What it writes down is a one-way hash of that address and a timestamp, never the address itself, and the file is deleted within the hour. It is not in the email and I never see it.

A second thing is stored, but only when something has gone wrong. If the mail server refuses the message, it is held on the server and retried until it goes, so that a bad hour costs you a message rather than costing you a reply. That copy sits outside the public part of the site, cannot be reached from the web, and is deleted the moment it is sent. In normal use it never exists at all.

The form loads no third party, sets no cookie, and asks nothing of the analytics above. It works with cookies declined and with JavaScript switched off.

If you are a client and I sent you a link to your own page

Clients get a private address of the form /p/?t=… which shows their quote and, once work is under way, how it is going. It is not linked from anywhere and it is not indexed; the address itself is what keeps it private, so treat it like a password and tell me if you want it changed. This section is about that page only. If you have never received such a link, none of it applies to you.

If you accept a quote from that page, four things are recorded: the date and time, your IP address, your browser's user-agent string, and a one-way fingerprint of the exact wording you were shown. The fingerprint is what makes the record worth keeping — it means neither of us can quietly change what was agreed afterwards. The legal basis is Article 6(1)(b) and (f) of the GDPR: performing the contract, and my legitimate interest in being able to prove what was accepted. It is kept for as long as the work could be disputed and is deleted with the rest of your file.

The number of times that page is opened is counted. Three things are stored: a number, the date of the first visit and the date of the most recent one. Your IP address is not stored, there is no tracking pixel, no analytics company is involved, and none of this calls out of the server: it is one more number in the same file that holds your quote. Your IP is used for a moment so that five reloads are not counted as five visits, and it is not written anywhere. It tells me whether it is worth calling you or whether the link never arrived at all. Legal basis: legitimate interest, article 6(1)(f) GDPR.

If you request changes from that page, what you write is stored along with the date, so it is in writing and nothing gets lost along the way. Nothing else: that list holds no IP address and no browser identification.

If you pay from there, the form is drawn by Stripe inside a frame on your own page. Your account or card details go straight to Stripe and never pass through my server: I do not see them, do not store them and could not. Of the transaction I keep whether it was paid, whether it is still processing, and the identifier Stripe gives that session, so that you are not asked again for a payment you already made. Stripe's script loads only when you press the pay button, not when the page opens. Stripe is the controller for the payment data and has its own policy at stripe.com/privacy. Legal basis: article 6(1)(b) GDPR, performance of the contract.

If you upload photos or documents there, they are stored on the server so I can build your site with them. They sit outside the public part of the site, cannot be reached from the web, and are readable only by me. They are deleted when the work is delivered, or sooner if you ask. Nothing is passed to any other company and nothing is used for anything other than your own job.

If you are a prospective client and I wrote to you, I keep your business's public contact details, where I found them, and what we said to each other. The legal basis is legitimate interest in offering a service to a business in my own area. Every commercial message I send carries a link that stops it for good — using it also stops me sending anything by any other channel, and I keep a record of that request precisely so it cannot be undone by accident.

When something breaks

If a page throws an error, or the server cannot send your message, a report goes to Sentry, on their European infrastructure. That report says what broke and where: the page address, the line of code, and your browser and version. It does not contain your name, your email address or anything you typed into the form, and it is not linked to you.

Your browser never contacts Sentry. The report is sent to this site and relayed from the server, so no third-party request is made from your machine and Sentry never sees your IP address. This happens whether or not you accepted cookies, because it is how I find out the site is broken rather than anything to do with measuring visits. The legal basis is legitimate interest: keeping the thing working.

If you decline, nothing happens

No analytics script is downloaded and no cookie is set. The site makes no request to any third party at all. That is the default until you choose otherwise. The one exception is described below and does not affect you unless you are a client: the payment screen on your own page loads Stripe's form, and only once you press to pay.

If you accept

The site loads PostHog and Google Analytics and records how the site is being used. Between them they see:

It does not record your screen, your mouse movements, or the contents of any field. Session recording, dead-click tracking, performance tracking and surveys are all switched off in the configuration. Google Analytics is configured with advertising storage denied and Google Signals off, so nothing here is used to build an advertising profile of you or joined up with your activity on other Google products.

Cookies

Where it goes

Two places, and they are not the same, so it is worth being exact.

PostHog goes to their European infrastructure, hosted in Germany, and stays in the EU.

Google Analytics does not. Google processes it in the United States and in other countries where it operates. The transfer relies on the European Commission's adequacy decision for the EU-US Data Privacy Framework, to which Google LLC is certified, and on standard contractual clauses. Google truncates the last part of your IP address before storing it, so the address itself is not kept. If that transfer is not something you want, declining is the whole of the answer: nothing is requested from Google unless you accept.

Both process it on my behalf and I am the only person with access to either project. I do not sell it, share it, or use it for advertising.

How long it is kept

PostHog data is retained for as long as that project exists. Google Analytics deletes user-level data after 14 months by default; aggregate reports outlive it. If you want yours removed from either, write to me and I will delete it.

Changing your mind

Every page has a Cookies button in the footer. It clears your answer and asks again, so withdrawing is exactly as easy as accepting was. Clearing your browser data for this site has the same effect.

Your rights

Under the GDPR you can ask what I hold about you, ask for it to be corrected or deleted, or object to it being processed. Write to hello@penedolabs.com. If you are not satisfied with my answer you can complain to the Spanish data protection authority, the AEPD.

Last updated 8 September 2026

Back to Penedo Labs