Privacy Policy
2026-08-21
Controller
Qold AI — operated by NamelyDigital — Maurice Kumar C/ Esperanza 17, 3B, 07590 Capdepera, Illes Balears, Spain Email: hello@qold.ai · Phone: +34 631 400 042 NIF: ESY6376024R
What we process
Contact form: the details you submit — your name, phone number and email, on the real-estate page also the optional company name, your message and the consent you give — are sent to our server, stored in our database and also emailed to us, solely to handle your inquiry. Legal basis: your explicit consent (Art. 6(1)(a) GDPR) and pre-contractual steps (Art. 6(1)(b) GDPR). Lead records in our database are deleted automatically after 12 months — or earlier on request — unless statutory retention applies.
Model Creator: if we send you the link to our Model Creator, the attributes you select for a possible AI model (such as gender, hair, eyes, build, heritage, age and height) are transmitted together with your contact details and stored alongside your inquiry. They describe a fictional character to be produced — they are not data about you, and we do not derive any assumption about you from them. Same legal bases and the same 12-month deletion as any other inquiry.
Server logs: our hosting provider records technical access data (IP address, timestamp, requested URL) for security and operation (Art. 6(1)(f) GDPR). Logs are deleted on a regular schedule.
Analytics: Google Analytics 4 runs only after your consent (Art. 6(1)(a) GDPR) with IP anonymisation. You can withdraw consent at any time via “Cookie settings” in the footer.
Business clients & client portal
If we enter a business relationship, we process the data needed to deliver and invoice our services: your company and contact details, project notes, the email correspondence we send you from our system (recorded in a send log for our records), and — where a client-portal account is created for you — your login email plus the project updates, documents, contracts and invoices we make available to you there. Legal bases: performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in orderly project and billing administration (Art. 6(1)(f) GDPR). Tax and commercial law require us to retain invoices and related records for the statutory periods (generally up to 6 years). Portal accounts and their files are stored by Supabase (Auth, Storage; eu-central-1) on our behalf, access is restricted to you, and we delete them once the business relationship ends and no retention duty remains.
Partner & affiliate applications
If you apply to become a partner or affiliate, we process the details you submit — company/brand name, contact name, phone and email, optionally your website, and your pitch — to review your application. Legal basis: pre-contractual steps (Art. 6(1)(b) GDPR) and, where you're approved, performance of the resulting partner/affiliate agreement. If your application is rejected, we delete these records within 6 months unless you ask us to remove them sooner. If approved, the data becomes part of the partner/affiliate portal account described above (project/commission tracking, invoice uploads for affiliates), retained for the duration of that relationship plus applicable statutory periods.
Business contacts we approach directly (Art. 14 GDPR)
Where we contact a company on our own initiative, we did not receive the data from that company. This section is the disclosure Art. 14 GDPR requires.
Source: business contact details the company publishes on its own website — normally the legally mandated legal notice (Impressum/Aviso Legal), otherwise the contact page given there. We do not buy address lists.
Categories: company name, the business contact person and their role, the business email address and phone number published there, the website, the industry we assign the company to, and a short internal note on why the company is relevant to us.
Legal basis: our legitimate interest in addressing potential business customers (Art. 6(1)(f) GDPR). Weighing this up: the details are business contact details that the company is legally obliged to publish, the message concerns that company's own professional activity, no special categories of data are involved, there is no automated evaluation of personal aspects and no scoring, and a single reply is enough to stop any further contact.
Right to object: you may object at any time to being contacted for direct marketing, without giving reasons (Art. 21(2) GDPR). We then stop immediately — there is no assessment on our side.
Retention: we delete contact records at these deadlines, counted from the last contact — for records never used, from when we created them: – never used: after 6 months. – written to, no reply: after 24 months. – conversation closed as lost, after 12. – became a business relationship: we keep the contact record as the link to your client file, and delete it together with that file. If you object, we reduce the record immediately to what a suppression needs — name, role, phone, website and our internal notes are cleared on the spot; the address moves to the suppression list and the remainder follows the deadlines above.
Separately from the record: the message we sent you is kept in our send log for 24 months — recipient address, subject and the text of the message itself, so that we can show what was sent, when and to whom. Ask us and we delete it — for messages that belong to an ongoing business relationship, within the periods that apply to those. Not to be confused with the retention of invoices: the invoice itself falls under tax and commercial law periods, the message announcing it does not.
If you object, we keep your email address on a suppression list beyond all of that — nothing else, and for the sole purpose of never contacting you again. Deleting it would defeat your objection.
You also have every right listed under “Your rights” below, including access and erasure.
Recipients
Processors in the EU: our hosting provider, and Supabase (PostgreSQL, Auth, Storage, Edge Functions; eu-central-1) which stores contact-form submissions, client records and portal files on our behalf under a data-processing agreement. Email delivery (our correspondence and portal invitations) is handled by Brevo (Sendinblue SAS, France, RCS Paris 498 019 298) or, as a fallback, handed to our mail server by a Supabase Edge Function — whichever is configured processes the content of those messages on our behalf. Spam protection: Cloudflare (Turnstile) when you submit the form. Only with consent: Google Ireland Ltd. (Google Analytics). If we send you a Stripe payment link for an invoice, we transmit the invoice title and number to Stripe Payments Europe, Ltd. (Ireland) to generate that link, before you ever visit Stripe's page; if you then choose to pay via that link, Stripe processes the payment details (card/bank) you enter directly on its own page — we never see or store those, only the resulting payment status. Transfers to third countries within the Google/Cloudflare/Stripe/Brevo services rely on EU standard contractual clauses.
Shared presentations
Proposals and showcases we prepare for you are published under an unguessable random address and are marked as non-indexable, so search engines do not list them. Anyone who has the full link can open the page, so please treat it as confidential. The page is not personalised, sets no cookies and measures nothing; the images it shows are delivered through links that expire. Ask us and we take the page offline immediately — the link then stops working.
Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection, plus the right to withdraw consent at any time. Contact: hello@qold.ai.
You may lodge a complaint with the Spanish supervisory authority (AEPD, www.aepd.es).
No automated decision-making
No profiling or automated decision-making takes place on this website.