Privacy

Last updated: August 2026

We keep this simple. This site belongs to a small studio. The only way you share personal data with us here is by choosing to contact us, through the contact form, by email, by phone or on WhatsApp. This page explains what we collect, why, and what you can ask us to do with it.

Who is responsible for your data

Kodable, a small studio established in Spain. Full legal identification is on the legal notice. For anything about your data, write to info@kodable.ai. We are the ones who read it. There is no big team behind the scenes.

What we collect

We only collect what you choose to send us when you get in touch. Through the contact form on this site, that is:

  • Your name
  • Your business name (optional)
  • Your email address and/or phone number, so we can reply
  • The message you write us about your project

If you email, call or message us directly instead of using the form, we receive whatever details you include there. We don't ask for, and you should never send us, sensitive data (health, ID numbers, payment card details) through these channels.

Why we collect it

For one reason: to reply to you and talk about the work you're asking about. If we go on to work together, we keep your contact details so we can stay in touch about your project and any care plan we agree. We do not use your details to send marketing or newsletters.

The legal basis

When you contact us about a possible project, the legal basis is taking steps at your request before entering a contract (and your consent in sending the message). Once we work together, the basis becomes performance of our contract. This follows the EU GDPR (RGPD) and Spain's data protection law (LOPDGDD).

How it's stored and for how long

Your message reaches us by email and we keep it in our email account and ordinary business records. We keep enquiries that don't turn into work for up to about a year, in case you come back to us, and then delete them. If we do work together, we keep what we need for as long as our relationship lasts and for the period the law requires afterwards (for example, invoicing records). You can ask us to delete your data sooner. See your rights below.

We don't sell your data

We never sell, rent or trade your personal data. We don't share it with advertisers. The only people who ever touch it are the service providers we use to run the studio, listed next.

Third parties we rely on

To run this site and reply to you, we use a small number of trusted providers who process data on our behalf:

  • A web hosting provider (Vercel) that serves this site and passes your contact-form message to us.
  • An email provider, where we receive and store your message and reply to you.
  • A database provider (Supabase) that stores consultation-booking slots, so we don't double-book you.
  • A CRM (HubSpot), where we keep the contact details of people and businesses we're talking to, so follow-ups don't fall through the cracks.

These providers only process your data to provide their service to us, under their own data-protection terms. Some are based in the United States; those transfers are covered by the EU standard contractual clauses or the EU-US Data Privacy Framework. We'll give you the full current list on request.

Cookies and analytics

This site sets no cookies. The banner you see is informational: with nothing to consent to, it only stores one anonymous flag so it doesn't reappear once you close it. We measure visits only in aggregate, with cookieless tools that can't recognise you across visits. The details are on the cookies page.

If we contacted you first (business outreach)

Besides replying to people who write to us, we sometimes reach out to businesses we think we can help. For that we collect business contact details from public sources, such as a business's own website or public listings like Google Maps: trade name, category, address, publicly listed phone and email, and sometimes the owner's name where the business publishes it. We use this only to show the business what we could build for it (often a personalised demo page) and to follow up; we keep it organised in our CRM. When we send a demo link, we can see that the page was opened (time, approximate city and device type), so we know whether to follow up or leave you alone.

If you're on the receiving end and want none of this: one email or reply is enough. We'll delete your details from our pipeline and not contact you again.

Visitors and clients in the United States

We also work with businesses in the US. Everything above applies to you too: we treat the GDPR standard as our floor for everyone, wherever you are. In US terms: we do not sell or share your personal information (as those words are defined in state privacy laws like the California CPRA), we don't use it for targeted advertising, and we honour access, correction and deletion requests from anyone, in any state, without needing to check whether a local law obliges us to. Our commercial emails always identify us and include a working way to opt out (CAN-SPAM); one reply is enough to never hear from us again.

Your rights

Under the GDPR you can ask us, at any time, to:

  • Access: get a copy of the data we hold about you
  • Rectify: correct anything that's wrong or out of date
  • Erase: delete your data when we no longer need it
  • Restrict or object: limit how we use it

To use any of these, just email info@kodable.aiand we'll sort it out, usually within a few days. If you think we've handled your data wrongly, you can also complain to the Spanish data protection authority (Agencia Española de Protección de Datos, AEPD).

A note in plain language

This is a plain-language privacy notice for a small studio. We wrote it to be read, not to hide behind. If anything here is unclear, or you want the formal version of any point (legal bases, retention tables, provider list), email us and we'll send it.