legal
Privacy Policy
Last updated: April 2025
Controller Identity
- Data Controller: Promptfields ([Full Legal Name of Autónomo])
- NIF / VAT ID: [ESX1234567Y]
- Registered Address: [Fiscal Address, Spain]
- Email: privacy@promptfields.com
- Website: https://promptfields.com
- Supervisory Authority: Agencia Española de Protección de Datos (AEPD) — www.aepd.es
Scope
This Policy applies to personal data processed by Promptfields when you:
- Visit promptfields.com or any associated landing page.
- Subscribe to the Promptfields newsletter or download a lead magnet.
- Book a discovery call via Cal.com or a similar scheduling tool.
- Engage Promptfields as a client for CRM, RevOps, or automation services.
- Purchase a digital product through Gumroad or a connected platform.
- Contact Promptfields via email, LinkedIn, or web form.
Categories of Personal Data Processed
| Category | Examples | Source |
|---|---|---|
| Identification data | Full name, job title, company, country | Provided by you |
| Contact data | Email, phone, LinkedIn URL, business address | Provided by you |
| Billing data | VAT ID, fiscal address, IBAN, invoice records | Provided by you |
| Commercial data | Discovery call notes, project scope, deliverables | Provided by you / generated in delivery |
| Technical data | IP address, browser type, device, cookies | Collected automatically |
| Usage data | Pages visited, time on page, referral source | Collected automatically |
| Marketing data | Newsletter subscription, email engagement | Provided by you / generated via tracking |
Promptfields does not knowingly collect data from children under 16, nor does it process special categories of data (health, political opinions, religion, biometrics) in the ordinary course of business.
Purposes & Legal Bases for Processing
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Providing consulting, CRM, and automation services | Contract performance — Art. 6(1)(b) |
| Issuing invoices and complying with Spanish tax law | Legal obligation — Art. 6(1)(c) |
| Responding to inquiries and discovery call requests | Pre-contractual measures — Art. 6(1)(b) |
| Sending newsletters and marketing emails | Consent — Art. 6(1)(a) |
| Website analytics and performance monitoring | Legitimate interest / consent — Art. 6(1)(f) / (a) |
| Fraud prevention and IT security | Legitimate interest — Art. 6(1)(f) |
| Legal claims, disputes, and regulatory cooperation | Legal obligation / legitimate interest — Art. 6(1)(c)(f) |
Data Retention
- Invoicing & tax records: 6 years (Spanish Commercial Code, Art. 30) and up to 10 years for anti–money-laundering obligations.
- Client project data: Duration of the engagement plus 5 years for civil liability claims (Código Civil, Art. 1964).
- Marketing data: Until consent is withdrawn or after 24 months of inactivity.
- Website analytics: Up to 14 months.
- Inquiry emails with no engagement: 12 months.
After expiry, data is securely deleted or fully anonymised.
Recipients & Data Processors
Promptfields shares personal data only with carefully selected processors bound by a Data Processing Agreement (DPA) in accordance with GDPR Art. 28.
Promptfields does not sell personal data and does not share it with third parties for their own marketing purposes.
International Data Transfers
When data is transferred outside the European Economic Area (EEA), Promptfields relies on one of the following safeguards under GDPR Chapter V:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy Decisions for countries recognised by the EU (e.g., UK, Switzerland).
- EU–US Data Privacy Framework where applicable.
A copy of the applicable safeguards can be requested at privacy@promptfields.com.
Your Rights under GDPR
- Right of access — obtain a copy of your personal data.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure — request deletion, subject to legal retention obligations.
- Right to restriction of processing — limit how your data is used.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interest or direct marketing.
- Right to withdraw consent — at any time, without affecting the lawfulness of prior processing.
- Right not to be subject to automated decision-making — that produces legal or similarly significant effects.
To exercise any right, email privacy@promptfields.com with proof of identity. Requests are answered within 30 days (extendable by 60 days for complex cases per Art. 12(3)).
You also have the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD) at www.aepd.es or your local EU supervisory authority.
Cookies & Tracking Technologies
The Promptfields website uses the following categories of cookies:
- Strictly necessary cookies — required for site operation (no consent needed).
- Analytics cookies — anonymised usage statistics (consent required).
- Marketing cookies — retargeting and campaign measurement (consent required).
You can accept, reject, or update your cookie preferences via the cookie banner or the "Cookie Settings" link in the site footer.
Security Measures
Promptfields applies technical and organisational measures proportionate to the risks identified, in line with GDPR Art. 32:
- Encrypted data in transit (TLS 1.2+) and at rest where supported.
- Multi-factor authentication (MFA) on all business-critical accounts.
- Principle of least privilege on client CRM and automation access.
- Password manager (1Password / Bitwarden) for credential storage.
- Regular backups and tested restore procedures.
- Data Processing Agreements (DPAs) with every sub-processor.
- Incident response plan aligned with the 72-hour breach notification duty (Art. 33).
Data Breach Notification
In the event of a personal data breach likely to result in a risk to the rights and freedoms of individuals, Promptfields will:
- Notify the AEPD within 72 hours of becoming aware of the breach.
- Inform affected data subjects without undue delay where the risk is high.
- Document the breach, its effects, and the remedial actions taken.
Automated Decision-Making & AI
Promptfields uses AI tools (including LLMs such as Ollama, OpenAI, and Anthropic models) to support lead scoring, content generation, and workflow automation. These tools:
- Do not make final decisions that produce legal or similarly significant effects without human review.
- Are configured to avoid training on client data where provider settings permit.
- Are covered by the applicable DPA with each AI provider.
You may request human review of any AI-assisted output that affects you.
Changes to this Policy
Promptfields may update this Policy to reflect changes in legislation, services, or processors. The current version and its "Last updated" date are always available at promptfields.com/privacy. Material changes will be communicated via email or a prominent notice on the website.