This Privacy Policy explains how Andrea Sacca Consulting SLU ("we", "us", "SlowFastBrand") processes personal data of visitors and users of the website slowfastbrand.com (the "Service"), in compliance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD).
1. Data Controller
Andrea Sacca Consulting SLU
Calle Antonio Maria Manrique 3, 35011 Las Palmas de Gran Canaria, España
NIF: ESB76271824
Contact: privacy@slowfastbrand.com
2. Data we collect
- Waitlist data: email address, consent flags, timestamp, user-agent.
- Communication data: messages you send us by email.
- Technical data: IP address, browser, device, pages visited (via analytics if you consent).
3. Purposes and legal bases
- Managing the private beta waitlist and sending related updates — consent (Art. 6(1)(a) GDPR).
- Optional marketing communications — consent, revocable at any time.
- Providing and securing the Service — legitimate interest (Art. 6(1)(f) GDPR).
- Complying with legal and accounting obligations — legal obligation (Art. 6(1)(c) GDPR).
4. Retention
Waitlist data is retained until the beta ends or you request deletion. Marketing data is retained until you withdraw consent. Data required for legal or accounting purposes is retained for the periods required by Spanish law.
5. Recipients and processors
We use trusted third-party processors bound by data-processing agreements, including our cloud infrastructure (Supabase / Amazon Web Services, EU region) and email delivery providers. We do not sell your personal data.
6. International transfers
Data is primarily stored within the European Economic Area. Where transfers outside the EEA occur, we rely on Standard Contractual Clauses approved by the European Commission.
7. Your rights
You have the right to access, rectify, erase, restrict, port and object to the processing of your personal data, and to withdraw consent at any time. To exercise these rights, contact privacy@slowfastbrand.com. You may also lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es).
8. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction.
9. Changes
We may update this Policy from time to time. The "Last updated" date at the top reflects the most recent revision.