Legal information
Privacy policy
Last updated:
This policy explains how we process the personal data of people who visit solai.es, write to us through the form or use the website analysis tool and its assistant. It complies with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on the protection of personal data and digital rights (LOPDGDD).
Data controller
SolAI is the trade name of a business project being incorporated in Marbella (Málaga, Spain). Contact: info@solai.es.
The full identification details of the owner will be published on this page as soon as the company is incorporated.
What data we process and where it comes from
We only process the data you give us directly or that is generated when you use the site:
- Enquiry form: name, email and message; company and phone if you choose to add them. The message reaches us by email through Resend and is stored in our enquiries database (leads).
- Website analysis tool: the address of the site you enter; the technical results of reading that public site (pages, texts, technical signals); the AI-generated analysis; the messages you write in the chat; the profile the assistant records from those messages (name, role, company, team size, the tools you use, the needs and goals you describe, budget and timeline if you mention them, and your email and phone if you give them); the indicative project estimate; and, if you provide an email address, the emails that are sent (the report to you and a notification to our team).
- Security: a hash (a non-reversible digest) of your IP address, used to limit the number of analyses and messages per visitor and to prevent abuse.
- Technical logs of the hosting provider: IP address, browser, date and time and pages requested, generated automatically when the site is served.
Third-party data on the analysed websites
The website you analyse and the public sources consulted may contain data about identifiable people, for example the name of a business owner. That data is processed only to prepare the analysis you requested, is limited to public professional information and is kept together with the analysis for the period stated below. By entering an address you declare that you are entitled to analyse that site.
We do not obtain data about you from any other source.
What we use the data for and on which legal basis
Each processing activity relies on one of the bases in Article 6 of the GDPR:
- Answering your enquiry and preparing a proposal: pre-contractual steps taken at your request (Article 6(1)(b)).
- Providing the analysis of your website and the conversation with the assistant: your consent, which you give by using the tool (Article 6(1)(a)). You can withdraw it at any time without affecting the processing already carried out.
- Security, usage limits and abuse prevention: our legitimate interest in protecting the service (Article 6(1)(f)).
- Commercial follow-up by email about your enquiry or your analysis: pre-contractual steps and legitimate interest (Articles 6(1)(b) and 6(1)(f)). We only write to you about what you raised with us; we send no newsletters or third-party advertising, and you can ask us to stop writing at any time.
Who has access to your data
We do not sell or share your data. Only our team and the providers we need to run the service have access to it. They act as processors under a contract that complies with Article 28 of the GDPR:
- Vercel Inc.: hosting of the site and the application, and technical logs.
- Supabase Inc.: the database where analyses, conversations and enquiries are stored, with servers in the United States (AWS us-east-1 region).
- Google LLC: Gemini API. To generate the analysis and the assistant's replies we send Google the text of the analysed website, the research notes and the chat messages.
- Resend Inc.: email delivery (enquiries, reports and notifications).
- Google (Google Workspace): the team's mailboxes.
International transfers
Some of these providers process data outside the European Economic Area, in particular in the United States. Those transfers are covered by the standard contractual clauses approved by the European Commission and/or by the EU-US Data Privacy Framework where the provider is certified. You can ask us for more information about these safeguards at info@solai.es.
We may also disclose data to the authorities where a legal obligation requires it.
How long we keep the data
Current retention periods:
- Website analyses and conversations with the assistant: 12 months from creation.
- Enquiries and contact details (leads): 24 months from the last contact. If a contract follows, they are kept for the duration of the relationship and the statutory limitation periods.
- IP address hash in the usage-limit log: 30 days. The hash associated with an analysis is kept together with that analysis.
- Hosting technical logs: for the short period applied by the provider.
Your rights
You can exercise your rights of access, rectification, erasure, restriction of processing, portability and objection, and withdraw any consent you have given, at any time by writing to info@solai.es with the subject “Data protection”. We may ask you to confirm your identity in order to handle your request. We reply within one month at most.
If you believe we have not handled your data correctly, you can lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es). We would appreciate it if you wrote to us first so we can try to resolve it.
Automated decisions
The analysis of your website, the assistant's replies and the project estimate are generated automatically with artificial intelligence models and are for information only. We take no automated decisions that produce legal effects on you or affect you in a similarly significant way: any commercial proposal is reviewed and confirmed by a member of the team.
Minors
The site and its services are aimed at businesses and professionals and are not intended for children under 14. If we become aware that we have collected data from a child under 14 without the required authorisation, we will delete it.
Security
We apply technical and organisational measures appropriate to the risk: encrypted communications (HTTPS), database access restricted to the application server, an administration area protected by authentication, and providers with recognised security certifications.
Changes to this policy
We may update this policy when the services, the providers or the law change. The version in force, with its update date, is the one published on this page.
