Privacy Policy
Last updated: 08/27/2026
At HeyMate! we take privacy seriously. This policy explains what personal data we process, for what purpose, on what legal basis, who we share it with, and what rights you have regarding it.
This applies to the website www.heymate.es, the forms and tools available on it, and the communications we maintain with you via email or professional networks.
1. Data Controller
- Data Controller: Gonzalo Cáceres Garzón, a freelance professional operating under the trade name "HeyMate!"
- Tax ID / NIE: Y7225137T
- Address: Artebiondo Estrata nº 5, 48630, Gorliz, Bizkaia, Spain
- Contact email for data protection matters: info@heymate.es
- Data Protection Officer: none has been appointed, as none of the conditions under Article 37 of the GDPR apply. You can direct any privacy-related inquiries to the email address provided.
2. Data we process and its source
We only process the data necessary for each purpose. Depending on the case, this may include:
Data you provide directly
- Identification and contact data: full name, email address, phone number, company, and job title.
- Project data: information about your business, current website, goals, estimated budget, and any other data you voluntarily include in the contact form, budget calculator, or web audit request.
- Contractual relationship data: in the event of a contract, billing, tax, and payment details, as well as information exchanged during the execution of the project.
- Communication data: content of emails, messages, or calls we have with you.
Data collected automatically
- Browsing data: IP address, device and browser type, operating system, language, pages visited, time spent, traffic source, and interactions with the site. These are collected through cookies and similar technologies, in accordance with the Cookie Policy, and only with your consent when required by law.
Fields identified as mandatory in our forms are necessary to process your request; if you do not provide them, we will be unable to process it or respond to you.
We do not intentionally request or process special categories of data (Article 9 of the GDPR). Please do not include this type of information in our forms.
3. Purposes, legal bases, and retention periods
a) Handling requests for information, quotes, and contact
- Purpose: to respond to your inquiry, prepare a proposal, and maintain communication prior to contracting.
- Legal basis: implementation of pre-contractual measures at the request of the data subject (Art. 6.1.b GDPR).
- Retention: during the processing of the application and for up to 12 months after the last contact, unless the relationship results in a contract. After that period, they are deleted or anonymized.
b) Provide contracted services and manage client relationships
- Purpose: project execution, communication during development, support, invoicing, and payment collection.
- Legal basis: performance of a contract (Art. 6.1.b GDPR) and compliance with legal tax and accounting obligations (Art. 6.1.c GDPR).
- Retention: for the duration of the contractual relationship and subsequently blocked for the applicable legal limitation periods: six years for commercial matters (Art. 30 of the Commercial Code) and four years for tax matters (General Tax Law 58/2003).
c) Free website tools (budget calculator and web audit)
- Purpose: to generate the requested result, send it to you, and, if applicable, contact you to discuss it.
- Legal basis: pre-contractual measures at the user's request (Art. 6.1.b GDPR) and, for sending subsequent commercial communications not directly related to the request, your consent (Art. 6.1.a GDPR).
- Retention: up to 12 months from the request, or until you withdraw your consent.
d) Website usage analysis
- Purpose: to understand how the site is used, which content is most useful, and to improve its structure and content.
- Legal basis: your consent, provided through the cookie settings panel (Art. 6.1.a GDPR and Art. 22.2 LSSI-CE).
- Retention: according to the timeframes indicated in the Cookie Policy.
e) Handling the exercise of rights and fulfilling legal obligations
- Purpose: managing your data protection requests and demonstrating regulatory compliance.
- Legal basis: compliance with a legal obligation (Art. 6.1.c GDPR).
- Retention: for the duration of the statute of limitations for any corresponding legal actions.
4. Data recipients
We do not sell your data or share it with third parties for their own commercial purposes.
To operate, we rely on service providers who access personal data as data processors, always under a contract that complies with Article 28 of the GDPR. Depending on the case, these may be:
- Webflow, Inc. (United States): website hosting and management platform, and receipt of form submissions.
- Google Ireland Limited / Google LLC: corporate email and storage for documents and spreadsheets used to record requests received through the website; web analytics (Google Analytics 4) and tag management (Google Tag Manager), the latter only with the user's prior consent.
In addition, your data may be disclosed to the following recipients in compliance with a legal obligation, without them acting as data processors:
- Bizkaia Provincial Tax Authority (Provincial Council of Bizkaia): submission of billing data through the Batuz / TicketBAI system, in accordance with the regional regulations applicable in the Historical Territory of Bizkaia.
- Public Administrations, Courts, and Tribunals, when there is a legal obligation to disclose information.
5. International data transfers
Some of the listed providers are established outside the European Economic Area or may access data from third countries, primarily the United States.
In such cases, the transfer is based on one of the safeguards provided for in Chapter V of the GDPR:
- The EU-U.S. Data Privacy Framework Adequacy Decision. (EU-U.S. Data Privacy Framework), when the provider is certified under that framework.
- The Standard Contractual Clauses approved by the European Commission, supplemented where appropriate with additional security measures following a corresponding transfer impact assessment.
You can request information regarding the guarantees applied to a specific provider by writing to info@heymate.es.
6. Your rights
As the data subject, you may exercise the following rights at any time:
- Access: know what data of yours we process.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request that we delete your data when it is no longer necessary.
- Objection: object to the processing of your data for reasons related to your particular situation, in the cases provided for in Article 21 of the GDPR.
- Restriction: request that we restrict the processing of your data in certain circumstances.
- Portability: receive your data in a structured, commonly used format, or request its transmission to another controller.
- Withdrawal of consent: withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
- Not to be subject to automated decisions: we do not make decisions based solely on automated processing that produce legal effects concerning you.
How to exercise them: send a request to info@heymate.es specifying the right you wish to exercise. We may ask you to verify your identity if there are reasonable doubts. We will respond within one month, which may be extended by two additional months if the request is particularly complex. Exercising these rights is free of charge.
7. Complaints to the supervisory authority
If you believe that the processing of your data does not comply with regulations, or if you are not satisfied with our response, you may file a complaint with the Spanish Data Protection Agency (AEPD):
- Electronic office: https://sedeagpd.gob.es
- Address: C/ Jorge Juan, 6, 28001 Madrid
We would appreciate it if, before contacting the AEPD, you gave us the opportunity to resolve the issue by writing to us at info@heymate.es.
8. Data security
We apply appropriate technical and organizational measures to protect personal data against destruction, loss, alteration, or unauthorized access, in accordance with Article 32 of the GDPR. These include: communication encryption via TLS certificate, access control with two-factor authentication, the principle of least privilege for information access, data backups, and the selection of providers with verified security guarantees.
No system is completely infallible, but we periodically review our measures to maintain a level of security appropriate to the risk.
9. Minors
Our website and services are intended for professionals and businesses. They are not designed for children under 14, and we do not knowingly collect their data. If we discover that we have processed data from a minor without the appropriate authorization, we will proceed to delete it.
10. Accuracy of data
By providing us with your data, you guarantee that it is truthful, accurate, and up to date, and that you are authorized to share it. If you provide us with third-party data (for example, from a colleague at your company), you agree that you have previously informed them of the content of this policy.
11. Changes to this policy
We may update this Privacy Policy to reflect changes in regulations, technology, or our services. The current version will always be published on this page, along with its last updated date. If the changes are significant, we will notify you through an appropriate channel.

