Privacy policy
How we process your personal data under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD). Last updated: 2 de octubre de 2026. This is a translation for convenience; in case of discrepancy the Spanish version prevails.
1. Data controller
Aimad el Hammouti, tax ID 47850050E, with address at calle industria 3.
Data protection contact: [email protected]. We have no data protection officer: given the type and volume of data we process, one is not required (Art. 37 GDPR and Art. 34 LOPDGDD). We will reassess this if the scale, tracking, profiling, the data processed or the purposes change.
2. What data we process, why and on what legal basis
Browsing: no account is needed and we do not ask for your name, phone number or address.
Serving pages and security: your IP address is processed transiently to serve the site, protect it and limit abuse (counters that delete themselves within one hour at most). It is not added to the statistics or to the news archive. The hosting provider also receives it when carrying the connection. If someone tries to log into the admin panel, the IP of that attempt is recorded in its security log (limited in size: the oldest entries are overwritten). Basis: legitimate interest in the security of the service (Art. 6(1)(f) GDPR).
Our own cookieless statistics: we count visits, pages viewed, the website you came from, your country (from the network, not your exact location), the type of device and the language. To count unique visitors, a code is derived from the IP and browser with a key that changes every day and is deleted; the code only feeds an approximate counter (HyperLogLog) that does not keep it. This is pseudonymised processing during the day, not anonymous from the outset: from the next day you can no longer be recognised. The IP is not stored. Basis: legitimate interest in knowing how the site is used, with aggregated data.
Contact, error and complaint form: the type of request, your message, the page it refers to and, if you give them, your email and name. The IP is not stored. Please do not include unnecessary data (health, phone numbers, other people's data). In a right-of-reply request, your name (or your entity's) and your text are published next to the story if admissible. Basis: legitimate interest in handling requests and, for rights claims (reply, data protection, intellectual property), compliance with a legal obligation (Art. 6(1)(c) GDPR).
Your cookie choice: a random identifier (pseudonymous data), the version of the notice, what you chose and the date, so that we can prove the consent was valid. It is not used for statistics or to track you. No IP. Basis: legal obligation (Art. 7(1) GDPR).
People who appear in the news: public news stories may contain data about people, mainly public officials. They are processed for information purposes (freedom of information, Art. 85 GDPR), with rules not to name private individuals and prior human review of accusations against identifiable people. To write the summary, the story's text is sent to Google's Gemini API and deleted from our systems after the analysis. You can object or request erasure or correction through the form.
Local preferences (language, theme, filters, map size): stored only in your browser and never sent to us.
We do not take automated decisions about you or build visitor profiles.
3. How long we keep data
IP for abuse limits: one hour at most.
Aggregated statistics: 13 months (they do not identify anyone).
Form requests (errors, replies, complaints, rights): 24 months; they can be deleted earlier if you ask and there is no obligation to keep them.
Outlets' text read by the AI: 48 hours at most (deleted when the story is published).
Cookie consent records: 25 months.
Preferences in your browser: until you clear the site data.
4. Your rights
You can request access, rectification, erasure, objection, restriction and portability using the contact form (type "Data protection") or by writing to [email protected]. We will reply within one month. We may ask you to prove your identity if there are reasonable doubts.
You can withdraw your cookie consent at any time under "Cookie preferences" at the bottom of every page.
If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or with the data protection authority of your country.
California residents: we do not sell or share personal information, and we honour the rights granted by the CCPA/CPRA on request.
5. Children
The service is not aimed at children under 14. In Spain, a child under 14 cannot give consent on their own (Art. 7 LOPDGDD).
We do not ask for your age because we do not need it: the site can be used without providing any data. The only consent-based processing is measurement or advertising cookies.
If we find out that we have received data from a child under 14 without the authorisation of their parents or guardians (for example, a form message), we delete it. Parents or guardians can ask for this at [email protected].
We do not profile children or target advertising at children. The service is not directed at children under 13 in the United States (COPPA).
6. Security
Encrypted connection (HTTPS), servers in the European Union, admin access with two-factor authentication and an activity log, and encrypted backups. If a security breach affecting personal data occurred, we would notify the Spanish Data Protection Agency within 72 hours where required and, if there is a high risk, the people affected.
7. Recipients, processors and international transfers
We do not sell or give away your personal data.
Hosting: OVHcloud (OVH SAS) (España), as data processor under a contract compliant with Art. 28 GDPR.
Artificial intelligence: Google (Gemini API) receives the text of public news stories —which may contain data about the people in them— to write the summary and classify them. It never receives data about visitors or from the forms. With the paid API, Google acts as processor under its data processing terms and may process data in the US under the EU-US Data Privacy Framework.
Backups: encrypted before leaving the server; any provider that stores them only receives encrypted data.