1. Data controller
Owner: José Noguera Morillas
Address: Avinguda Parc 4, Cornellà de Llobregat, Barcelona, Spain
Email: hola@espressorabbithole.com
Website: https://www.espressorabbithole.com
2. Information and data we collect
2.1 Data you provide directly
When you leave a comment on the blog or subscribe to the newsletter, we collect the information you provide, which may include:
- Name or username
- Email address
- Comment or message content
- Website URL (if you voluntarily include it in the comment form)
2.2 Automatically collected data
When you browse the Site, certain technical data is automatically collected through the tools described in Section 4. This data may include:
- Anonymised IP address
- Browser type and operating system
- Pages visited and time spent
- Traffic source (organic search, referral, direct, etc.)
- Screen resolution and device type
3. Purposes and legal basis for processing
We process your data for the following purposes and on the following legal grounds:
- Comment management: publishing and moderating blog comments. Legal basis: consent (Art. 6(1)(a) GDPR).
- Newsletter: sending communications about new content and blog updates, following voluntary subscription. Legal basis: consent (Art. 6(1)(a) GDPR).
- Web analytics: analysing visitor behaviour to improve the Site. Legal basis: legitimate interest (Art. 6(1)(f) GDPR), with self-hosted processing and IP anonymisation.
- Security and spam prevention: protecting the Site against unauthorised access and abusive content. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
4. Third-party tools and international transfers
4.1 Matomo Analytics (self-hosted)
The Site uses Matomo Analytics in self-hosted mode. This means all analytics data is stored exclusively on our own servers and is not shared with any third party. Visitor IP addresses are anonymised before storage. No international data transfers occur with this tool.
4.2 Google Search Console
We use Google Search Console to monitor the Site’s performance in Google Search results. This tool processes data in aggregate, not at an individual level. Google may process data in accordance with its own privacy policy: https://policies.google.com/privacy
4.3 Comment system
The Site includes a comment system (native WordPress or equivalent) that collects the commenter’s name, email address, and comment content. Email addresses are never made public. Comments may be moderated before publication.
4.4 Newsletter
When the newsletter is launched, we will clearly disclose the email marketing provider used, along with its privacy policy and data transfer terms. Subscription will always be voluntary and can be cancelled at any time.
4.5 Affiliate programmes
The Site participates in affiliate programmes, including Amazon Associates and other affiliate networks. When you click an affiliate link, the merchant’s website may set its own cookies to track any resulting purchase. These third parties have their own privacy policies, for which the owner of this Site bears no responsibility. For Amazon, see: https://www.amazon.com/gp/help/customer/display.html?nodeId=201909010
5. Data retention
- Comments: for as long as the comment remains published, or until you request its removal.
- Newsletter: until you unsubscribe or request deletion of your data.
- Analytics data: up to 13 months from collection, in line with recommended best practices.
- Security logs: up to 12 months.
6. Your rights
Under the GDPR, you may exercise the following rights at any time:
- Access: to know what personal data we hold about you.
- Rectification: to correct inaccurate or incomplete data.
- Erasure: to request deletion of your data when it is no longer necessary.
- Objection: to object to processing based on legitimate interest.
- Restriction: to request that we restrict processing in certain circumstances.
- Portability: to receive your data in a structured, machine-readable format.
- Withdrawal of consent: at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at: hola@espressorabbithole.com
If you are based in the EU/EEA and believe our processing of your data does not comply with applicable law, you have the right to lodge a complaint with your local supervisory authority. In Spain, this is the Agencia Española de Protección de Datos (www.aepd.es).
7. Security
We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss, alteration or disclosure. However, no data transmission system over the internet is completely secure.
8. Changes to this policy
We may update this Privacy Policy periodically. When we do, we will revise the “last updated” date at the top of this document. We encourage you to review this page regularly.