Privacy policy
Last updated: 7 October 2026
This explains what personal data we process on https://designloop.app and in the client portal, why, and what rights you have. We process as little data as possible. This is a translation; the Spanish version prevails.
1. Controller
- Andrés Ochoa (Designloop)
- Tax ID (NIF): 21080268D
- Address: Calle Ruiz Palacios 39, 28039 Madrid
- Email: hola@designloop.app
- Web: https://designloop.app
2. What data we process
- If you visit the website: the technical data strictly needed to serve and protect it (IP address, browser, pages requested), in server logs. We use no analytics, advertising or tracking cookies.
- If you write to us or book a call: your name, email and whatever you tell us.
- If you are a client or a member of a client's team: name, email, company, language, your activity in the portal (requests, comments, files, links and the call you book) and the notifications we send you.
- Billing data: handled by Stripe. We see the company name, email, subscription status and invoices, but never your full card number.
- Security: access and audit logs (who did what and when) to detect and investigate misuse.
3. Why, and on what legal basis
- Providing the service, managing your account and sending portal notifications: performance of the contract (art. 6.1.b GDPR).
- Invoicing and meeting tax and accounting obligations: legal obligation (art. 6.1.c).
- Keeping the website and portal secure and preventing abuse: legitimate interest (art. 6.1.f).
- Answering your messages and preparing a proposal if you ask: pre-contractual steps at your request (art. 6.1.b).
We do not send marketing without your consent, do not sell data and do not make automated decisions that affect you.
4. How long we keep it
- Account data and portal content: while the relationship lasts. After you leave, content is deleted within 90 days at most (sooner if you ask).
- Large files: deleted automatically after 14 days.
- Invoices and accounting records: 6 years, as required by the Spanish Commercial Code, plus any longer period required by tax law.
- Security logs: as long as needed for their purpose and, in any case, while they may be needed to handle claims.
- Contact messages that do not lead to a contract: up to 12 months.
5. Who we share it with
Only with the providers we need to run the service, which act as processors under contract (art. 28 GDPR):
- Supabase (database, files and sign-in): servers in the European Union (Ireland).
- Cloudflare (website hosting and network): global network; certified under the EU-US Data Privacy Framework and bound by standard contractual clauses.
- Stripe (payments and invoices): Stripe Payments Europe, Ireland. For payment data it is also an independent controller.
- Resend (service emails): United States, under standard contractual clauses.
- Calendly (only if you book a call from the website): United States, certified under the EU-US Data Privacy Framework.
When a provider processes data outside the European Economic Area, it does so with GDPR safeguards (the Data Privacy Framework adequacy decision or standard contractual clauses). We will only disclose data to authorities when the law requires it.
6. Cookies and browser storage
We only use technical cookies that the service needs to work, which do not require consent:
- portal session cookies (sb-…), to keep you securely signed in;
- designloop-locale and designloop-workspace, to remember your language and the workspace you have open;
- on the public website, your browser stores the language you chose and whether you paused the animations (local storage, not sent to anyone).
Fonts are served from our own domain. If you open the calendar to book a call, Calendly may use its own cookies under its policy.
7. Security
We apply appropriate technical and organisational measures: encrypted connections, isolation of each client's data, one-time code sign-in, mandatory two-factor sign-in for the studio, removal of metadata (such as location) from images, an audit log and scheduled deletion of temporary files. If a breach affects you, we will tell you and, where required, the Spanish Data Protection Agency within 72 hours.
8. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to hola@designloop.app. We may ask you to prove your identity. We reply within one month at most.
If you are a member of a client's team, that client is the controller of the data it uploads to the portal about its project; we may forward your request to it.
If you think we have not handled your rights properly, you can complain to the Spanish Data Protection Agency (www.aepd.es) or your local authority.
9. Minors
The service is for businesses and professionals, not for anyone under 18.
10. Changes
If we change this policy in a meaningful way we will tell you by email or in the portal. The date of the latest version is shown at the top.