Privacy policy
This site processes as little personal data as it can. Below is exactly what that amounts to, why, how long it is kept, and what you can require of me.
1. Who is responsible
Chu Van Ngoc, a private individual based in Phú Thọ, Vietnam, publishes https://spainpulse.com and is the data controller within the meaning of the General Data Protection Regulation (GDPR). That means I decide what personal data is processed, for what purpose, and how.
Privacy enquiries go to hello@spainpulse.com. I answer them myself; there is no support department in between.
This site is a personal project. It is not operated through a registered company, and it is not a Spanish business — I am neither established in Spain nor established anywhere else in the European Union. None of that reduces your rights, for the reason set out immediately below.
Why the GDPR applies even though I am outside the EU
Article 3(2) GDPR extends the Regulation to controllers outside the Union where they offer services to, or monitor the behaviour of, people who are in the Union. This site is written for people living in or moving to Spain, so it falls within that scope and I treat it as fully subject to the GDPR. Being based in Vietnam is a disclosure, not an exemption.
Vietnam is not covered by a European Commission adequacy decision. In practice the only personal data that reaches me personally is email you choose to send — the server logs sit with the hosting provider in the location described in section 7, and the calculators transmit nothing at all. When you email me, the contents of that message are necessarily read in Vietnam. That transfer happens because you initiated the correspondence and is limited to what you chose to send.
EU representative (Article 27)
Article 27 GDPR normally requires a controller outside the Union to designate a representative within it. The same article exempts processing that is occasional, does not involve large-scale processing of special categories of data or of criminal-offence data, and is unlikely to result in a risk to the rights and freedoms of individuals.
No representative has been designated, on the basis that this site relies on that exemption: it has no accounts, no contact form, no advertising, no profiling, and no special-category data, and the only personal data processed is short-lived server logs and correspondence you initiate. If the site's processing ever grows beyond that — a user account system, a mailing list, advertising — a representative will be designated and named here first.
No data protection officer has been appointed. That is not required here: no special categories of personal data are processed and there is no large-scale systematic monitoring of individuals.
2. Starting principles
This policy describes not only what happens, but what deliberately does not:
- You do not need an account to use anything on this site.
- The calculators run entirely in your own browser; what you type never reaches the server.
- Without your consent, no third-party script loads at all — no analytics, no advertising, no tracking pixels.
- There is no contact form, so no submission database exists to be breached.
- Personal data is never sold or rented, to anyone.
- No user profiles are built.
3. What data is processed
3.1 What you enter into the calculators
The calculators perform their work in JavaScript inside your own browser. Salary figures, property prices, earnings forecasts — none of it is transmitted to the server and none of it is stored. Close the tab and it is gone. I have no access to it at any point, because it never arrives.
3.2 Technical data (server logs)
Like almost every web server, this one records each request automatically. Those logs contain:
- your IP address;
- the date and time of the request;
- the page or file requested;
- the HTTP status code and amount of data sent;
- your browser and operating system (user agent);
- the referring page, if you arrived via a link.
An IP address counts as personal data under the GDPR. These records are used solely to keep the site working, diagnose faults and recognise abuse such as automated attacks. They are not linked to individuals and are not used to analyse visitor behaviour.
3.3 What you send me by email
If you write to me, I process your email address, your name insofar as you give it, and the contents of your message — for the sole purpose of answering you. You are not added to any mailing list.
3.4 Preferences stored locally
Your cookie choice is stored in your own browser's local storage under the
name spulse_consent. It holds only your choice — accept or
refuse — and no personal data. It is never transmitted to the server.
3.5 What is not processed
I do not ask for and do not process: your NIE or NIF, bank details, or any special category of personal data such as health, religion, political opinions, ethnic origin, sexual orientation or biometric data. If you send such information by email unprompted, it is deleted once your message has been dealt with.
4. Purposes, legal bases and retention
The GDPR requires a purpose and a lawful basis for every processing activity. Here they are.
| Processing | Purpose | Legal basis (art. 6 GDPR) | Retention |
|---|---|---|---|
| Server logs | Keep the site running, fix faults, prevent abuse | Legitimate interests (1(f)) | Maximum 6 months |
| Email correspondence | Answering your question or request | Legitimate interests (1(f)) | Maximum 24 months after resolution |
| Privacy requests | Demonstrating your request was handled correctly | Legal obligation (1(c)) | Maximum 24 months |
| Cookie choice | Respecting your choice without asking repeatedly | Necessary for the service requested | Until you clear your browser storage |
| Analytics cookies | Seeing which pages are used, to know what to expand | Consent (1(a)) | See the cookie policy |
Where legitimate interests are relied on, that interest has been weighed against your privacy. For server logs, the interest in a working and secure site outweighs a limited intrusion, because the records are kept briefly and not linked to individuals. If you disagree with that balance you may object — see section 9.
5. Cookies and similar techniques
Without consent, only strictly necessary storage is used. Every other cookie or similar technique is placed only after you have actively agreed. If you refuse, the relevant script is not loaded and no connection to the party concerned is made — refusal is not merely a flag that is later ignored.
A full inventory is in the cookie policy.
6. Recipients and processors
Personal data is shared only where necessary:
- OVHcloud (OVH SAS), the hosting provider. It operates the servers the site runs on and therefore has access to the logs. The servers are located in the United Kingdom (Erith data centre). OVHcloud (OVH SAS) acts as a processor under article 28 GDPR and is bound by the data processing agreement forming part of its terms of service.
- The email provider, for receiving and sending messages via hello@spainpulse.com.
- Competent authorities, where legally required — for instance under a court order.
Personal data is not sold and is not made available for third parties' commercial purposes.
7. Transfers outside the EEA
There are two separate transfers to describe here, because the servers and the person running the site are in different countries.
7.1 Hosting — the United Kingdom (Erith data centre)
The servers are located in the United Kingdom (Erith data centre). Since the United Kingdom left the European Union it sits formally outside the European Economic Area.
The European Commission has adopted an adequacy decision for the United Kingdom. The level of protection there is therefore treated as equivalent to the EU's, and transfer is permitted without additional standard contractual clauses. Server logs enjoy, in principle, the same protection as they would within the EU.
Should that decision lapse, I will put another valid basis in place — standard contractual clauses with supplementary safeguards, or moving the servers to a member state within the EEA.
7.2 Correspondence — Vietnam
I read and answer email from Phú Thọ, Vietnam. When you write to me, the content of your message is accessed from Vietnam, which is not covered by a European Commission adequacy decision.
I am telling you this plainly rather than leaving it in the small print, because it is the honest limit of what a one-person site abroad can offer. Three things narrow the exposure:
- the transfer only happens if you choose to email me — there is no form, no account and no newsletter that would move your data without a deliberate act on your part;
- it is limited to what you decided to put in the message, and I ask you not to send documents or identification numbers;
- correspondence is deleted once the matter is dealt with, per the retention table above.
In GDPR terms this is a transfer necessary for the purpose you contacted me for, made at your initiative. If you would prefer no data to leave the EEA at all, the answer is simply not to email me: every page on this site is fully usable without ever contacting me, and the calculators send nothing anywhere.
If analytics or advertising from a party outside the EEA is ever deployed, it will be stated here before it goes into use.
8. Security
Appropriate technical and organisational measures are taken to protect personal data against loss and unlawful processing:
- all connections to the site are encrypted via HTTPS;
- server access is limited to those who genuinely need it and uses key-based authentication;
- the operating system and server software receive security updates regularly;
- as little data as possible is collected in the first place, so there is simply little to protect.
The site runs on a virtual server at OVHcloud (OVH SAS). That provider is responsible for physical data centre security and the underlying infrastructure; management and security of the server itself is mine.
No measure offers absolute certainty. If you spot a vulnerability, please report it to hello@spainpulse.com. Such reports are taken seriously and appreciated.
9. Your rights
Under the GDPR you have the following rights regarding your personal data:
- Access (art. 15) — find out what data is processed about you.
- Rectification (art. 16) — have inaccurate data corrected.
- Erasure (art. 17) — have your data deleted, unless it must be retained by law.
- Restriction (art. 18) — have processing paused.
- Objection (art. 21) — object to processing based on legitimate interests.
- Portability (art. 20) — receive your data in a common format.
- Withdrawing consent (art. 7(3)) — as easy as giving it; earlier processing remains lawful.
Send requests to hello@spainpulse.com. I respond within one month. If a request is complex that period may be extended by two months, and I will tell you within the first month. There is no charge.
To avoid disclosing data to the wrong person, I may ask for additional information supporting your request. I will not ask for a copy of your identity document.
In practice: because there are no accounts, no contact form and the calculators run locally, in most cases there is no data here that identifies you. The honest answer to an access request will usually be that nothing of yours is held.
10. Minors
This site is not directed at children and does not knowingly collect their data. Under Spanish law the age of consent for information society services is fourteen. If you are a parent or guardian and believe data about your child is being processed here, get in touch and it will be deleted.
11. No automated decision-making
No decisions are taken based on automated processing that produce legal effects or similarly significantly affect you, and no profiling within the meaning of article 22 GDPR is carried out.
12. External and affiliate links
Pages here link to external websites, such as official bodies and cited sources. Following such a link takes you off this site, and that party's privacy policy applies. I am not responsible for the content or data processing of other websites.
No affiliate links are in use at the time of writing. If that changes, it will be disclosed at the point where the link appears. With such a link the receiving party can determine that you arrived via this site; what they then process is described in their own policy.
13. Data breaches
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, it will be reported to the Spanish supervisory authority within 72 hours of discovery. Where the risk is high, affected individuals will also be informed directly, as article 34 GDPR requires.
14. Changes
This policy may be amended, for instance when new functionality is added or when the law requires it. The date at the top of this page shows when it was last substantively revised.
For significant changes — a new purpose, or a new category of recipient — consent will be sought again where that is required.
15. Contact and complaints
Questions about this policy or about how your data is handled? Email hello@spainpulse.com or use the contact page.
If you are not satisfied with the response, you have the right to lodge a complaint with a data protection supervisory authority. Because I am not established in the EU, there is no single "lead" authority for this site — you may complain to the authority in the EU or EEA country where you live, where you work, or where you believe the problem occurred. The European Data Protection Board maintains a list of national authorities.
Readers in Spain, who are most of this site's audience, would go to the Agencia Española de Protección de Datos (AEPD).