Privacy Policy
Last updated: December 5, 2025
Introduction
At Catalogador, we are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our collection management service, in accordance with the EU General Data Protection Regulation (GDPR) and Spanish data protection laws.
Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the application.
Data Controller
The Data Controller responsible for your personal data is:
Catalogador
Spain
Email: privacy@catalogador.com
Data Protection Contact: dpo@catalogador.com
For any questions regarding data protection, you may contact our Data Protection Officer at the email address above.
Information We Collect
Personal Data
We may collect personally identifiable information that you voluntarily provide when:
- Registering for an account (email address, username, password)
- Using our contact form (name, email, message content)
- Subscribing to our newsletter (email address)
Collection Data
Information you add to your collections, including:
- Item details (titles, descriptions, categories, tags)
- Images you upload
- Loan records and borrower information you create
- Personal notes, ratings, and progress tracking data
Automatically Collected Data (Technical Data)
When you access Catalogador, we may automatically collect:
- Device information (browser type, operating system, device type)
- Usage data (pages visited, features used, time spent)
- IP address (may be anonymized for analytics)
- Referral source (how you arrived at our site)
Legal Basis for Processing (Article 6 GDPR)
We process your personal data under the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Account creation and authentication | Contract performance (Art. 6(1)(b)) - Necessary to provide the service you requested |
| Storing your collection data | Contract performance (Art. 6(1)(b)) - Core service functionality |
| Sending service-related communications | Contract performance (Art. 6(1)(b)) - Necessary for service operation |
| Analytics and service improvement | Legitimate interest (Art. 6(1)(f)) - To improve our services |
| Marketing communications (newsletter) | Consent (Art. 6(1)(a)) - Only with your explicit opt-in consent |
| Analytics cookies | Consent (Art. 6(1)(a)) - Based on your cookie preferences |
| Legal compliance and security | Legal obligation (Art. 6(1)(c)) and Legitimate interest (Art. 6(1)(f)) |
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process your requests and manage your account
- Send you technical notices and support messages
- Respond to your comments, questions, and requests
- Analyze usage patterns to improve user experience (with appropriate legal basis)
- Protect against fraudulent or unauthorized activity
- Comply with legal obligations
- Sell your personal data to third parties
- Use your data for targeted advertising
- Share your collection data with anyone without your explicit consent
- Make automated decisions that significantly affect you
- Profile you for marketing purposes without consent
Data Storage & Security
Your data is stored securely using industry-standard encryption and security measures. We implement:
- HTTPS/TLS encryption for all data transmission
- Secure password hashing (passwords are never stored in plain text)
- Regular security audits and penetration testing
- Access controls and role-based authentication
- Regular backups with encrypted storage
- Staff training on data protection
While we implement appropriate technical and organizational measures to protect your information, no electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to maintaining appropriate protection standards.
International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place:
- Adequacy decisions: Transfers to countries the European Commission has determined provide adequate protection
- Standard Contractual Clauses (SCCs): EU-approved contractual terms that provide appropriate safeguards
- Data Processing Agreements: Binding agreements with third-party processors
Our primary data storage is within the European Union. If you would like more information about international transfers, please contact us.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this privacy policy, or as required by law.
| Data Type | Retention Period |
|---|---|
| Account data | Duration of account + 30 days after deletion request |
| Collection data | Duration of account + 30 days after deletion request |
| Contact form submissions | 2 years from submission |
| Analytics data | 26 months (anonymized) |
| Legal/compliance records | As required by applicable law (typically 6-10 years) |
When you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain certain information for legal obligations or legitimate business purposes.
Your Rights Under GDPR
Under the EU General Data Protection Regulation and Spanish data protection law, you have the following rights regarding your personal data:
Right to Information (Art. 13-14)
Be informed about how your data is collected and usedRight of Access (Art. 15)
Request a copy of your personal data we holdRight to Rectification (Art. 16)
Request correction of inaccurate or incomplete dataRight to Erasure (Art. 17)
"Right to be forgotten" - request deletion of your dataRight to Restriction (Art. 18)
Request limited processing of your dataRight to Data Portability (Art. 20)
Receive your data in a portable, machine-readable formatRight to Object (Art. 21)
Object to processing based on legitimate interestsRight to Withdraw Consent
Withdraw consent at any time (where processing is based on consent)How to Exercise Your Rights
To exercise any of these rights, please contact us at privacy@catalogador.com or use our contact form.
We will respond to your request within one month. This period may be extended by two further months where necessary, taking into account the complexity and number of requests.
Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. In Spain, this is:
Agencia Española de Protección de Datos (AEPD)
Spanish Data Protection Agency
C/ Jorge Juan, 6, 28001 Madrid
Website: www.aepd.es
Phone: +34 901 100 099
Third-Party Services
We may use third-party services that process personal data:
| Service | Purpose | Data Processed |
|---|---|---|
| Microsoft Azure | Cloud hosting and storage | All application data |
| Azure Application Insights | Application monitoring and analytics | Technical data, usage patterns |
| SendGrid | Email delivery | Email addresses, message content |
| External Metadata APIs | Book/movie information lookup | Search queries (ISBNs, titles) |
All third-party processors are bound by Data Processing Agreements (DPAs) that ensure GDPR compliance. We encourage you to review their privacy policies.
Children's Privacy
In accordance with Article 8 of the GDPR and Spanish law (LOPDGDD), Catalogador is not intended for children under 14 years of age. We do not knowingly collect personal information from children under 14.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@catalogador.com. We will take steps to delete such information from our systems.
Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. When we make material changes:
- We will update the "Last updated" date at the top of this page
- We will notify registered users via email for significant changes
- We may display a prominent notice on our website
We encourage you to review this privacy policy periodically. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy, your personal data, or wish to exercise your rights, please contact us:
General Privacy Inquiries: privacy@catalogador.com
Data Protection Officer: dpo@catalogador.com
Or use our contact form.
We aim to respond to all privacy-related inquiries within 72 hours, and to formal rights requests within one month as required by GDPR.
GDPR Privacy Highlights
- EU-based data storage - Your data stays in the European Union
- No data selling - We never sell your personal information
- Full GDPR rights - Access, rectify, delete, or port your data
- Encryption - All data transmitted over HTTPS/TLS
- Cookie consent - Non-essential cookies require your consent
- Data export - Download your data in portable format anytime
- Account deletion - Delete your account and data within 30 days
Your Rights at a Glance
Under EU GDPR, you have the right to: