Legal document
Privacy Policy
Last updated: [DATE] — Template v1
Template pending review. Fill in every field marked [PLACEHOLDER] and have a lawyer review it before publishing the site. This version is written to accurately reflect what the website does today (no backend); as soon as a server, CRM or analytics tools are connected, sections 2 and 5 will need to be updated. The company is domiciled in Spain and processes personal data under EU/Spanish law (GDPR, LOPD-GDD) — references below (AEPD, Spanish courts, etc.) apply regardless of the language of this page.
01 Data controller
- Controller: [FULL LEGAL NAME] (Funding Fast)
- Tax ID (NIF/CIF): [TAX ID]
- Registered address: [FULL ADDRESS]
- Privacy contact: admin@fundingfast.io
- Data Protection Officer (DPO): [DPO NAME AND CONTACT, OR "NOT APPOINTED — VERIFY WHETHER MANDATORY GIVEN THE VOLUME AND TYPE OF DATA PROCESSED"]
02 What data we collect and how
Contact form
If you fill in the form in the "Contact" section, we collect the data you voluntarily enter: name, company, email, and your message describing your situation or the challenge you want to solve.
Important note on the site's current state: as of today, this site has no backend server of its own. When you submit the form, this data is not transmitted to any server operated by [LEGAL NAME]; the form simply opens your default email client with a pre-drafted message addressed to admin@fundingfast.io, and it is you who decides whether to send it. From that point on, we treat your data like any other email we receive. [This section must be rewritten as soon as a backend or CRM is implemented that receives and stores form data directly.]
Booking a meeting (Calendly)
The contact button also opens Calendly in a new tab so you can book a 30-minute session. Calendly, Inc. directly collects the data you provide (name, email, time slot, etc.) under its own privacy policy, which you can review on its website. [LEGAL NAME] receives the booking confirmation but does not manage or store that data in its own systems.
Browsing and technical preferences
The site stores a single technical preference in your browser (via localStorage, not a cookie): whether you selected light or dark mode. This data does not identify the user, is never transmitted to any server, and is not used for analytics or advertising purposes. See the Cookies Policy for more detail.
[Update this section if Google Analytics, Meta Pixel, a CRM, server-side form submission, or any other tool that collects personal data is added in the future.]
03 Purpose and legal basis for processing
- Purpose: to respond to your contact or strategic diagnostic request, and to manage the booking of the corresponding session.
- Legal basis: your consent, given by voluntarily filling in and submitting the form or booking a session (Art. 6.1.a GDPR), and/or the performance of pre-contractual measures at your request (Art. 6.1.b GDPR).
04 Retention period
Data will be retained [DEFINE PERIOD — e.g. "for as long as necessary to handle the request and, thereafter, until deletion is requested" or a specific period], and in any case for the periods legally required to address potential liabilities.
05 Recipients and third parties
We do not share your data with third parties except where legally required. However, the following providers are involved in operating the website:
- Hosting: IONOS (shared hosting) — [SPECIFY THE EXACT SERVER LOCATION PER THE IONOS CONTRACT]
- Calendly, Inc. (booking management — U.S.) [SPECIFY THE INTERNATIONAL TRANSFER MECHANISM APPLIED BY CALENDLY, E.G. STANDARD CONTRACTUAL CLAUSES]
- Google Fonts (Google Ireland Ltd.) — the site loads the Inter and IBM Plex Mono typefaces from Google's servers, which means your browser makes a request to Google when visiting the site. [RECOMMENDED: self-host the fonts to remove this transfer entirely — a purely technical change, available on request.]
06 Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability at any time by writing to admin@fundingfast.io. You also have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if you believe the processing of your data does not comply with applicable regulations.
07 Security measures
[LEGAL NAME] applies the necessary technical and organizational measures to ensure the security of personal data and to prevent its alteration, loss, unauthorized processing or access. [Detail specific measures once a real backend/CRM exists — e.g. encryption, access controls, backups.]
08 Changes to this policy
This privacy policy may be updated to reflect legislative developments or changes in how the website operates. Users are advised to review it periodically.