Privacy Policy
Last updated: 24 August 2026
This policy explains what personal data we process at ia-propulsa.com, why, for how long, and what you can do about it. It is written to comply with Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 (LOPDGDD) and Law 34/2002 (LSSI-CE). Section 7 covers data obtained through the LinkedIn APIs and our compliance with the LinkedIn API Terms of Use and Data Storage Requirements.
1. Data controller
| Legal name | Aaron Valor Aparicio, a sole trader operating under the trade name Propulsa |
|---|---|
| Tax ID (NIF) | 49267658W |
| Registered address | C/ Rafael Satorre 12, 03830 Muro de Alcoy (Alicante), Spain |
| infopropulsa.ia@gmail.com | |
| Phone | +34 654 435 761 |
| Website | www.ia-propulsa.com |
We have not appointed a Data Protection Officer, as none of the circumstances in Article 37 GDPR apply. For any privacy matter, please write to the email address above.
2. What data we process
2.1 Data you give us
When you book a consultation or contact us through the forms on our website, we collect:
- Name and email address
- Phone number, together with the country dialling code
- Business name and sector or activity
- Any additional information you choose to write in the free-text field
- Date and time of the appointment you select
We do not request and do not wish to receive special categories of data (health, political opinions, religion, trade union membership, sexual orientation, biometric or genetic data). Please do not include them in free-text fields.
2.2 Conversations with our virtual assistant
Our website includes a conversational assistant. The content of your messages is sent to Anthropic PBC to generate a reply. Please do not enter confidential information, credentials, or third-party data into the chat.
2.3 Browsing data
Our hosting provider automatically logs your IP address, browser and device type, pages visited, and access date and time. These logs are used to keep the service running and to detect security incidents.
2.4 LinkedIn data
If you contact us through LinkedIn, we process the data described in Section 7, subject to the specific limitations set out there.
3. Purposes and legal bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Managing and confirming the consultation you booked, and creating the calendar event | Performance of a contract or pre-contractual measures taken at your request — Art. 6(1)(b) |
| Responding to your enquiries by form, chat or LinkedIn | Pre-contractual measures — Art. 6(1)(b) |
| Providing and invoicing our services if you become a client | Performance of a contract — Art. 6(1)(b), and compliance with tax and accounting obligations — Art. 6(1)(c) |
| Sending you marketing communications about our services | Your consent — Art. 6(1)(a). You may withdraw it at any time |
| Measuring our advertising performance and analysing website usage | Your consent, given through the cookie banner — Art. 6(1)(a) |
| Keeping the site secure and preventing abuse or fraud | Our legitimate interest in protecting our systems — Art. 6(1)(f) |
Providing the data marked as required is necessary for us to handle your request. If you do not provide it, we will not be able to assist you.
4. Retention periods
| Data | Period |
|---|---|
| Enquiries that do not lead to a contract | 12 months from last contact, unless you ask us to delete it sooner |
| Client data and accounting records | 6 years under Art. 30 of the Spanish Commercial Code, and 4 years for tax purposes under the General Tax Act |
| Marketing consent | Until you withdraw it |
| Virtual assistant conversation logs | 90 days |
| Server technical logs | Per our hosting provider's policy, typically 30 days |
| Data obtained via LinkedIn APIs | See Section 7. Substantially shorter periods apply |
5. Who we share it with
We do not sell, rent or trade your personal data. We share it only with the providers we need in order to deliver our service. They act as processors under a written agreement pursuant to Article 28 GDPR:
| Provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | Website hosting and serverless function execution | USA |
| Google Ireland Ltd. / Google LLC | Appointment scheduling via Google Calendar, conversion measurement via Google Ads, and web fonts | Ireland and USA |
| Resend Inc. | Sending confirmation and notification emails | USA |
| Anthropic PBC | Generating virtual assistant responses | USA |
| LinkedIn Ireland Unlimited Company | Messaging and management of our company page | Ireland |
We may also disclose data to public authorities, law enforcement or courts where a legal obligation requires us to do so.
6. International transfers
Some of the providers listed above are located in the United States. These transfers rely on one of the safeguards set out in Chapter V GDPR:
- The European Commission's adequacy decision of 10 July 2023 on the EU–U.S. Data Privacy Framework, where the provider is certified under that framework.
- The European Commission's Standard Contractual Clauses, together with any supplementary measures required, in all other cases.
You may request a copy of these safeguards by writing to our contact email.
7. Data obtained via LinkedIn APIs
Scope of our integration. We use the official LinkedIn APIs for one purpose only: to read and reply to messages and conversations addressed to our own Propulsa company page and profile, through an internal tool used solely by the account owner.
Access is always authorised through LinkedIn's OAuth 2.0 flow and only by the account owner, who is an administrator of the page. We do not access client or third-party accounts.
7.1 What LinkedIn data we process
- Authenticated member data (the account owner): Person ID and Person URN, name, headline and profile picture, together with the access tokens required to maintain the connection.
- Our own organization page data: identifiers, name, and administrative and reporting data for the page itself.
- Data of members who message us: the content of the message they send us and the basic profile data strictly necessary to know who is writing and to reply.
We apply data minimisation: we do not request more fields from the API than are strictly necessary to manage the inbox.
7.2 How long we keep LinkedIn data
We fully comply with the LinkedIn Marketing API Program Data Storage Requirements. Where one of our own retention periods conflicts with a LinkedIn period, we always apply the shorter and more protective one:
| Data type | Maximum period |
|---|---|
| Profile data of members other than the authenticated owner | 24-hour cache. Never stored persistently |
| Member social activity data: posts, comments, reactions and mentions | 48 hours |
| Person IDs and Person URNs | For as long as the integration remains active |
| Authenticated member profile data (the owner) | For as long as the integration remains active |
| Administrative and reporting data for our own page | 1 year |
| Content of messages sent to us | Only as long as needed to handle the conversation and any resulting business relationship, with the sender's consent |
Our storage is designed so that we can identify, segregate and selectively delete LinkedIn-sourced data, as required by Section 4.1 of the LinkedIn API Terms of Use.
7.3 What we never do with LinkedIn data
- We never use it for advertising, sales or recruiting purposes. Specifically, we do not use it to identify sales or marketing prospects, create leads, enhance customer data in a CRM or marketing automation platform, build audience lists, or target advertising.
- We never send mass messages, promotions or unsolicited offers through the API.
- We never sell, rent, lease, disclose, distribute or share member data with any third party.
- We never export member data outside the application, and we never combine it with our own or third-party data to create, supplement, verify or append to user profiles, leads or reference tables.
- We never use it to train artificial intelligence or machine learning models, our own or anyone else's.
- We never display it to anyone other than the administrators of our own page.
7.4 Revocation and deletion
Any LinkedIn member may request deletion of their data by writing to infopropulsa.ia@gmail.com. We action such requests immediately and in any event within 30 days.
We immediately delete all data collected through the APIs when any of the following occurs:
- The owner revokes the application's access from their LinkedIn account settings.
- A member requests deletion of their data.
- A member closes their LinkedIn account.
- We stop using the LinkedIn APIs.
The owner can revoke access at any time via Settings & Privacy → Data privacy → Other applications → Permitted services on LinkedIn.
7.5 Relationship with LinkedIn
LinkedIn is the controller for the data it processes on its own platform, governed by the LinkedIn Privacy Policy. Propulsa is not affiliated with, endorsed by, or acting on behalf of LinkedIn Corporation or Microsoft.
8. Cookies
We use cookies and similar technologies. Strictly necessary cookies require no consent. Advertising cookies are only set if you accept them in our cookie banner, and you can change your choice at any time from the preferences panel. Full details, including the name and lifetime of each cookie, are in our Cookie Policy.
| Type | Provider | Purpose |
|---|---|---|
| Strictly necessary | Vercel | Serving the site, load balancing and abuse protection |
| Advertising | Google Ads | Measuring campaign conversions and attributing visits to the originating ad |
You can also block or delete cookies through your browser settings. Note that disabling strictly necessary cookies may prevent parts of the site from working.
9. Security
We maintain industry-standard technical and organisational measures to protect data against unauthorised access, loss, alteration, disclosure or destruction, in line with Article 32 GDPR and Section 7.1 of the LinkedIn API Terms of Use. These include:
- TLS encryption in transit for all communications.
- Credentials and access tokens stored as encrypted environment variables, never in source code or in the browser.
- Access restricted to the minimum necessary personnel, with two-factor authentication.
- Least-privilege scoping of all third-party API permissions requested.
- Periodic review of access rights and retention periods.
No system is completely secure. If a breach occurs that poses a risk to your rights, we will notify you and report it to the Spanish Data Protection Agency within the 72 hours required by Article 33 GDPR.
10. Your rights
You may exercise the following rights at any time:
- Access: find out what data of yours we process.
- Rectification: correct inaccurate or incomplete data.
- Erasure: ask us to delete data that is no longer necessary.
- Objection: object to processing based on our legitimate interest.
- Restriction: ask us to suspend processing while a complaint is resolved.
- Portability: receive your data in a structured, commonly used format.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
To exercise them, write to infopropulsa.ia@gmail.com stating which right you wish to exercise and attaching proof of identity. We will respond within one month.
If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es.
11. Children
Our services are aimed exclusively at professionals and businesses. They are not directed at children under 14 and we do not knowingly collect their data. If we discover we have received data from a child without the consent of a parent or guardian, we will delete it immediately.
12. Changes to this policy
We may update this policy to reflect changes to our services or to applicable law. The last update date appears at the top of this document. If a change is material, we will notify you by email or through a prominent notice on the website before it takes effect.
