Last updated: 15 September 2026
1. Data controller
In accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018, of 5 December, on Personal Data Protection and the guarantee of digital rights (LOPDGDD), the controller responsible for processing the personal data collected through this website is:
- Owner: Daniel de Juan Ramos Hernández
- Tax ID (NIF): 79097257G
- Address: Calle Cruz de Marca, 4, 13, 38207 San Cristóbal de La Laguna, Santa Cruz de Tenerife, Spain
- Contact email: dynamusgrupo@gmail.com
2. Purpose of processing
Personal data submitted through the contact forms, quote requests, video call bookings or blog subscription is processed for the following purposes:
- To manage and respond to enquiries and information requests submitted by the user.
- To provide the contracted services (web design, visual identity, community management, multimedia and AI automation).
- To send commercial communications about our services, only when the user has given express consent to do so.
- To notify subscribers of new blog content, until they request to unsubscribe.
- To measure website traffic in aggregate and to manage the requests received through our internal customer relationship management (CRM) system.
- To respond to enquiries voluntarily raised by the user through the website's virtual assistant (chatbot).
3. Legal basis
The legal basis for processing the data is the consent of the data subject, given by completing and submitting the website's forms (including the blog subscription), as well as, where applicable, the performance of a contract or pre-contractual measures requested by the user.
4. Data collected
The contact and call-request forms collect the following data: name, email address and phone number, as well as any other information the user chooses to include voluntarily in the message. The blog subscription only collects the email address.
In addition, on each visit the website sends our internal CRM the page visited, the referring page (referrer) and a temporary session identifier generated in the browser. That identifier is stored in session storage (sessionStorage), is not a cookie, is deleted when the tab is closed, and does not allow the user to be identified or different visits to be linked. Data submitted through the forms is also stored in that CRM for follow-up.
When the user accepts the privacy policy by submitting a form, or makes a choice in the cookie notice, a record of that acceptance is stored including the exact date and time, what was accepted, the version of the legal text in force at that moment, the browser used, a temporary session identifier and the IP address it was made from. This record has a single purpose: to be able to demonstrate the consent given, as required by Article 7.1 of the GDPR. The legal basis is the legitimate interest in evidencing regulatory compliance, and this data is not used for anything else nor combined with any profile.
The website's virtual assistant (chatbot) processes the messages the user types during the conversation to generate a reply using artificial intelligence, but it does not save the conversation history: nothing is stored on any server or in the user's browser, and it disappears when the page is reloaded or closed. To prevent abuse of the service, a request limit per IP address is also applied, managed by the infrastructure provider itself.
5. Data retention
Personal data will be kept for as long as necessary to handle the user's request or for the duration of the contractual relationship, and subsequently for the periods legally required to address any potential liabilities. Once these purposes have been fulfilled, the data will be deleted or anonymised.
6. Recipients and data processors
The following external providers are used for the website to function correctly; they act as data processors and have their own privacy policies:
- Web3Forms: used to manage and send the website's contact forms.
- Google Calendar: used to schedule video calls and appointments with the Dynamus Grupo team.
- Cloudflare: website hosting, cookieless audience measurement (Cloudflare Web Analytics) providing aggregate statistics that do not identify users, and AI processing (Cloudflare Workers AI) of the messages typed into the virtual assistant (chatbot) to generate a reply, without retaining the conversation history.
- Render: hosting of the internal customer relationship management (CRM) system where the visits and requests described in this policy are recorded.
Dynamus Grupo does not share or sell personal data to third parties for purposes other than those described here, except where legally required.
7. Data subject rights
The user may exercise their rights of access, rectification, erasure, objection, restriction of processing and data portability at any time by sending a request to dynamusgrupo@gmail.com, indicating the right they wish to exercise and attaching, where applicable, the documentation needed to prove their identity. The user also has the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) via www.aepd.es if they believe the processing of their data does not comply with applicable regulations.
8. Security measures
Dynamus Grupo applies reasonable technical and organisational measures within its reach to guarantee the security, confidentiality and integrity of the personal data processed, and to prevent its loss, alteration, or unauthorised access or processing.
9. Minors
This website is not directed at minors under 14 years of age. Dynamus Grupo does not knowingly collect personal data from minors of that age. If you become aware that a minor has provided their data through this website, please report it to dynamusgrupo@gmail.com so it can be removed.
10. Changes to this privacy policy
Dynamus Grupo reserves the right to amend this privacy policy to adapt it to legislative or case-law developments, or to AEPD guidance. Users are advised to review this page periodically.