Legal information
Legal notice and privacy policy
This page brings together the identification details required by Spanish Law 34/2002 (LSSI-CE) and the information on the processing of personal data required by Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Last updated: 10 August 2026
This is a courtesy translation. The binding version of this notice is the Spanish one, available at trustedlineage.com/privacidad. It is governed by Spanish law and addressed to the Spanish supervisory authority. In the event of any discrepancy between the two texts, the Spanish version prevails.
1. Identification of the owner
In compliance with article 10 of Law 34/2002, on information society services and electronic commerce:
- Owner of the website
- Gregorio Torrealba (natural person)
- Contact email address
- contacto@trustedlineage.com
- Name of the project
- AI Data Lineage Mapper
- Nature of the site
- Informational website for a project in a validation phase
This website is an informational page for a software project developed in a personal capacity and currently in a validation phase. No products or services are sold through this site: there is no online contracting, no prices, no payments and no order processing. Its only function is to describe the project and allow interested organisations to get in touch.
Once the project begins economic activity, this information will be extended with the tax and address details that become mandatory, and the corresponding terms of contract will be published.
2. Data controller
The controller of the personal data collected through this website is Gregorio Torrealba, in a personal capacity, at the contact email address given in the previous section.
For any matter relating to data protection, or to exercise your rights, you can write to privacidad@trustedlineage.com. No data protection officer has been appointed, as none of the circumstances in article 37 of the GDPR applies.
3. Data we process
3.1. Data you provide
Only what you voluntarily enter in the contact form:
- Name.
- Company.
- Work email address.
- Job title or role (optional).
- The main need you select.
- Message (optional).
- Whether or not you request a demo of the product.
We do not request special categories of data (article 9 of the GDPR). We ask that you do not include personal data of third parties or confidential information about your organisation in the message.
3.2. Technical data from your visit
The hosting provider records in its server logs the IP address, the date and time of the request, the URL requested and the browser user agent. These records are used exclusively to provide the service, detect incidents and protect the infrastructure against abuse.
3.3. What we do not do
- We do not use cookies or equivalent tracking technologies.
- We do not use web analytics tools or advertising pixels.
- We do not build profiles or take automated decisions.
- We do not sell or transfer data to third parties for commercial purposes.
4. Purpose
We process the form data in order to:
- Handle and answer your request.
- Assess how the product fits your architecture and prepare a demo if you ask for one.
- Maintain the communication arising from that request, including preparing a proposal.
We will not use your address to send you commercial communications unrelated to the reason for your enquiry without informing you first.
5. Legal basis
- Consent (article 6.1.a of the GDPR): given by ticking the acceptance box and submitting the form. You can withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.
- Legitimate interest (article 6.1.f of the GDPR): for communication between professionals about a product directly related to the activity of the company you represent, and for infrastructure security in the case of the server logs.
- Performance of a contract or pre-contractual steps (article 6.1.b of the GDPR): if the conversation moves towards a proposal or a pilot.
The fields marked as required are necessary in order to handle the request; if you do not provide them, we will not be able to reply.
6. Retention period
We keep the form data for as long as necessary to handle your request and, afterwards, for a maximum of 12 months so that the conversation can be picked up again, unless you ask for erasure before that.
If the relationship leads to a contract, the data will be kept for its duration and, thereafter, for the applicable statutory limitation periods in tax, accounting and commercial matters.
Server logs are kept for the period defined by the hosting provider for security and diagnostic purposes.
7. Recipients and data processors
No data is disclosed to third parties except where legally required, and it is not transferred or sold for commercial purposes. To run the site we rely on providers acting as data processors, under a contract compliant with article 28 of the GDPR:
- Web hosting and content delivery network: Cloudflare, Inc. (Cloudflare Pages), United States.
- Storage of requests: Cloudflare D1, a database created with European jurisdiction, which guarantees that the data is processed and stored in the European Union.
- Notification of new requests: Resend, with its sending region set to Ireland (EU). It only carries an internal notification with the request identifier; it does not receive your name, your email address or your message.
- Form protection: Cloudflare Turnstile, to tell people apart from automated bots. It processes the IP address and technical browser signals for the sole purpose of that verification.
- Contact email: Cloudflare Email Routing to forward messages addressed to this domain, and Google Ireland Limited (Gmail) as the destination mailbox where they are read and answered.
8. International transfers
Hosting is provided through Cloudflare, Inc., a US entity operating a global content delivery network, so the processing associated with serving the pages may take place outside the European Economic Area. That transfer is covered by the data processing agreement signed with Cloudflare, which incorporates the standard contractual clauses approved by the European Commission.
The data you submit through the form does not leave the European Union. It is stored in a Cloudflare D1 database created with European jurisdiction, which guarantees that processing and storage take place within the EU.
The notification service is configured with its sending region in Ireland, so the associated processing also takes place within the European Union. In addition, by design it receives no personal data about the data subject: the notification contains only the numeric identifier of the request and the type of need selected. As the provider has a US parent company, any access from outside the EEA is covered by its data processing agreement with standard contractual clauses.
The mailbox from which enquiries are answered is provided by Google Ireland Limited. Google is part of the EU-US Data Privacy Framework and additionally offers standard contractual clauses in its data processing agreement.
Regardless of the above, this website loads no resources hosted by third parties, so simply visiting it does not involve disclosing your IP address to any provider other than the hosting one.
9. Cookies and third-party resources
This website does not use cookies. No first-party or third-party cookies are set, and no browser local storage is used to identify or track visitors. That is why no consent banner is shown: there is nothing to consent to.
No fonts, maps, embedded videos, libraries or analytics tools are loaded from
third-party servers. The only exception is Cloudflare Turnstile, the
anti-bot system on the contact form, which loads its script from
challenges.cloudflare.com. It has been configured
without pre-clearance cookies, so it verifies the browser through a
single-use token and stores nothing on your device.
If analytics, a chat widget, a third-party hosted form or external fonts are added in the future, this section will need updating and a cookie policy will have to be published with its corresponding prior consent banner (article 22.2 of the LSSI).
10. Your rights
As the data subject you can exercise the following rights:
- Access: to know what data we process about you.
- Rectification: to correct inaccurate or incomplete data.
- Erasure: to request its deletion.
- Objection: to object to processing based on legitimate interest.
- Restriction: to ask for processing to be restricted.
- Portability: to receive your data in a structured format.
- Withdrawal of consent: at any time.
To exercise them, write to privacidad@trustedlineage.com stating which right you wish to exercise. We may ask you to prove your identity. We will reply within a maximum of one month.
If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es), the competent supervisory authority in Spain.
11. Security
Technical and organisational measures are applied to protect the data against destruction, loss, alteration or unauthorised access. All communication with this site is encrypted using HTTPS/TLS, and access to the data received is limited to the owner of the site.
No measure guarantees absolute security. Should a security breach occur that poses a risk to your rights, we will notify you and report it to the supervisory authority as provided for in articles 33 and 34 of the GDPR.
12. Intellectual property and trademarks
The contents of this website —text, design, code and graphics— as well as the AI Data Lineage Mapper software are owned by Gregorio Torrealba, the author of the project, and are protected by intellectual and industrial property law. Their reproduction, distribution or transformation is not authorised without prior written consent.
Amazon Web Services, AWS, Amazon S3, AWS Glue, AWS Lambda, AWS Step Functions, Amazon Redshift, Amazon Athena, Amazon EventBridge, Amazon SQS, AWS CloudFormation and Amazon CloudWatch are trademarks of Amazon.com, Inc. or its affiliates. They are mentioned purely descriptively, to identify the services the product is compatible with. The owner of this site is not affiliated with Amazon Web Services, nor is this site sponsored or endorsed by that company. All other product names and trademarks mentioned belong to their respective owners.
The screenshots and product views shown on this site correspond to a demonstration environment with fictitious data; they do not reflect any client's information.
13. Changes to this policy
This policy may be updated to reflect regulatory changes or new features of the site. The version in force is always the one published on this page, with its last updated date in the header. If the changes substantially affect the processing of data already collected, we will inform the people concerned.
14. Applicable law
This information and the use of this website are governed by Spanish law, with jurisdiction of the courts and tribunals applicable under the legislation in force. Any future contractual relationship will be governed by the terms specifically agreed for it.
This document follows the structure and content usually required by the GDPR, the LOPDGDD and the LSSI-CE, but it does not replace legal advice. It should be reviewed by a professional before publication, particularly the sections on retention, data processors and international transfers.