1. DATA CONTROLLER
Identity: OCTAVIO ORTEGA ESTEBAN
Spanish Tax ID (NIF): ES03892442Z
Address: C/ Concilios de Toledo, 2, portal 6, 4B
Contact Email: octavio@kerchak.com
Activity: Licensed Psychologist and Cyberpsychology Educator
Country of Establishment: Spain
2. DATA PROTECTION OFFICER
Not applicable (data processing volume does not require a DPO under Spanish law).
3. DATA PROCESSING PRINCIPLES
In accordance with GDPR and Spanish LOPDGDD, we apply the following principles:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
4. CATEGORIES OF DATA COLLECTED
4.1. Data you provide directly:
- Name and surname
- Email address
- Phone number (optional)
- Blog comments
- Contact form messages
- IP address
4.2. Data collected automatically:
- Cookies (see Cookie Policy)
- Browsing data
- Device type
- Operating system
- Browser used
- Pages visited
- Visit duration
4.3. Data we DO NOT collect:
- Special category data (health, sexual orientation, political opinions)
- Financial or banking data
- Data from minors without parental consent
5. PURPOSES AND LEGAL BASIS
Purpose | Legal Basis | Retention Period |
---|---|---|
Respond to contact requests | Consent (Art. 6.1.a GDPR) | 1 year from last contact |
Manage blog comments | Consent (Art. 6.1.a GDPR) | Duration of blog existence |
Send newsletter | Consent (Art. 6.1.a GDPR) | Until unsubscription |
Website analytics | Legitimate interest (Art. 6.1.f GDPR) | 2 years |
Legal compliance | Legal obligation (Art. 6.1.c GDPR) | As required by law |
Security and spam prevention | Legitimate interest (Art. 6.1.f GDPR) | 6 months |
6. DATA RECIPIENTS
6.1. Categories of recipients:
- Service providers (processors):
- Google LLC (Analytics, AdSense) – USA
- Clouding.io – EU
- Cloudflare (CDN and security) – USA
6.2. Data is only shared with public authorities when legally required.
6.3. We do not sell or share your data for commercial purposes.
7. INTERNATIONAL TRANSFERS
Some services involve transfers outside the EEA:
- Google (USA): Standard Contractual Clauses
- Cloudflare (USA): Standard Contractual Clauses
All transfers include appropriate safeguards under GDPR.
8. YOUR RIGHTS
Under GDPR, you have the following rights:
- Right of access (Article 15 GDPR)
- Right to rectification (Article 16 GDPR)
- Right to erasure (“right to be forgotten”) (Article 17 GDPR)
- Right to restriction of processing (Article 18 GDPR)
- Right to data portability (Article 20 GDPR)
- Right to object (Article 21 GDPR)
- Right to withdraw consent
- Right to lodge a complaint
To exercise your rights:
- Email: octavio@kerchak.com
- Mail: C/ Concilios de Toledo 2, portal 7, 4B
- Include a copy of your ID
Response time: Maximum 1 month
9. DATA SECURITY
Technical and organizational measures implemented:
- SSL/TLS encryption
- Strong passwords
- Restricted data access
- Regular backups
- GDPR training
- Security updates
10. MINORS
- Website intended for persons over 16
- Parental consent required for under 16
- Immediate deletion of minor data without consent
11. DATA RETENTION
Data is retained according to the periods specified in Section 5. After this, data is deleted or anonymized.
12. COOKIES
See our Cookie Policy for detailed information.
13. CHANGES TO THIS POLICY
We reserve the right to modify this policy. Significant changes will be notified on the website.
14. SUPERVISORY AUTHORITY
You may lodge a complaint with:
- Spain: Spanish Data Protection Agency (AEPD) – www.aepd.es
- Your country: Find your local Data Protection Authority at edpb.europa.eu