Legal Information
Complete legal documentation for DigitalGrowthFlows services and data handling practices.
Privacy Policy
Effective Date: 1 January 2026
DigitalGrowthFlows ("we," "our," or "us"), operating from Calle Triana 10, 35002 Las Palmas de Gran Canaria, Spain, is committed to protecting the privacy and personal data of our website visitors and service clients in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR").
1. Data Controller
The data controller responsible for processing your personal data is DigitalGrowthFlows, located at Calle Triana 10, 35002 Las Palmas de Gran Canaria, Spain. You may contact us regarding data processing matters at [email protected].
2. Data We Collect
We may collect and process the following categories of personal data:
- Identity Data: Full name, username, or similar identifiers.
- Contact Data: Email address, telephone number, and billing/delivery address.
- Technical Data: Internet Protocol (IP) address, browser type and version, time zone setting, operating system, and platform.
- Usage Data: Information about how you use our website and services, including page views and navigation patterns.
- Communication Data: Records of any correspondence you send to us via email, forms, or other channels.
3. Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract Performance: Processing necessary for the performance of a contract to which you are a party, or for taking steps at your request prior to entering into a contract (Article 6(1)(b) GDPR).
- Legitimate Interest: Processing necessary for our legitimate interests (or those of a third party), provided your interests and fundamental rights do not override those interests (Article 6(1)(f) GDPR).
- Consent: Where you have given explicit consent for specific processing purposes (Article 6(1)(a) GDPR).
4. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Service-related data is retained for a maximum of 5 years following the conclusion of the service engagement, unless a longer retention period is required by law.
5. Data Security
DigitalGrowthFlows implements appropriate technical and organisational measures to ensure the security of your personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These measures include encryption of data in transit, access controls, and regular security assessments.
6. Your Rights
Under the GDPR, you have the following rights:
- Right of Access (Article 15) — Obtain confirmation of whether we process your data and request a copy.
- Right to Rectification (Article 16) — Request correction of inaccurate personal data.
- Right to Erasure (Article 17) — Request deletion of your data where no compelling reason for continued processing exists.
- Right to Restrict Processing (Article 18) — Request restriction of processing under certain conditions.
- Right to Data Portability (Article 20) — Receive your data in a structured, commonly used, machine-readable format.
- Right to Object (Article 21) — Object to processing based on legitimate interests or direct marketing.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.
7. International Data Transfers
Your personal data may be transferred to, and processed in, countries outside the European Economic Area (EEA). Where such transfers occur, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.
8. Changes to This Policy
We reserve the right to update this Privacy Policy at any time. Material changes will be communicated via our website or direct email. We encourage you to review this policy periodically.