Privacy Policy
Last updated: June 2026
In compliance with Regulation (EU) 2016/679, General Data Protection Regulation (GDPR), and Organic Law 3/2018, of December 5, on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD), NeoWeb agencIA transparently informs you about how we process and protect the personal data we collect through this website.
1. Data Controller
- Owner: Anthony Jair Torres Rosas
- Trade name: NeoWeb agencIA
- NIF: 61731889G
- Address: Isabelita Usera Street, 13, Ground Floor Right, 28026 Madrid (Spain)
- Phone: +34 633 37 52 62
- Email: 1913torres@gmail.com
No Data Protection Officer (DPO) has been appointed because none of the circumstances under Article 37 of the GDPR apply. For any privacy-related questions, you can contact us directly at the email provided.
2. Data we process and how we obtain it
We only process the data you provide us or that is generated by your interaction with the website:
- Contact and identification data: name, email, phone number, and any data you voluntarily include when filling out contact forms, using the savings calculator, requesting the free resource (checklist), or booking an appointment.
- Your business data: sector, size, processes to automate, and needs you describe to us so we can prepare a proposal.
- Conversations with the "Neo" assistant: the content of text and voice messages you exchange with our chatbot, which are stored to provide continuity and improve service. If you provide us with your email or phone number in a conversation, we may recognize you on future visits —even from another device— to greet you by name and pick up where we left off, avoiding asking you for the same information again. You can object to this recognition or request that we forget your data at any time (see section 10).
- Navigation data: IP address, device identifiers, pages visited, and interactions, collected through cookies and similar technologies (see Cookie Policy).
We do not collect special categories of data (health, ideology, etc.). We kindly ask that you do not include this type of information in free text fields.
3. Purposes and legal bases for processing
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| To address your inquiries, requests for information and quotes, and to respond to forms. | Your consent and/or the application of pre-contractual measures at your request (Art. 6.1.a and 6.1.b). |
| To send you the free resource (checklist) you request through the website. | Your consent (Art. 6.1.a). |
| Service and qualification through the "Neo" assistant, including the storage of conversations. | Your consent when starting the conversation and legitimate interest in assisting you (Art. 6.1.a and 6.1.f). |
| Internal analysis and prioritization of requests received through artificial intelligence tools (see section 7). | Legitimate interest in efficiently managing commercial activity (Art. 6.1.f). |
| Management of the contractual relationship and provision of contracted services. | Performance of a contract (Art. 6.1.b). |
| Compliance with tax, accounting, and legal obligations. | Legal obligation (Art. 6.1.c). |
| Sending commercial communications about our services (if you authorize it). | Your consent (Art. 6.1.a); or legitimate interest regarding clients for similar services (Art. 21.2 LSSI). |
| Web analytics, heatmaps, and session recording (Google Analytics, Microsoft Clarity). | Your consent provided in the cookie banner (Art. 6.1.a and Art. 22.2 LSSI). |
4. Retention periods
- Data of interested parties (leads) who do not become clients: up to 2 years from the last contact, unless you request their deletion sooner.
- Client data: during the contractual relationship and, thereafter, during the legal tax and commercial limitation periods (generally, up to 6 years).
- Chatbot conversations: up to 12 months, unless they result in a contractual relationship.
- Cookie and analytics data: according to the duration indicated in the Cookie Policy.
5. Recipients and data processors
We don't sell or transfer your data. To provide the service, we rely on technology providers who act as data processors, with a contract in accordance with Art. 28 GDPR:
| Provider | Purpose |
|---|---|
| Google LLC / Google Ireland (Firebase, Cloud, Analytics, Tag Manager) | Web hosting, database, forms, and analytics. |
| Google (Gemini / Generative AI) | Processing of chatbot conversations and analysis of requests. |
| Microsoft Corporation (Clarity) | Heatmaps and session recordings to improve the website. |
| Resend | Sending transactional emails (free resource, replies). |
| Calendly | Booking and appointment management. |
| Make.com | Internal workflow automation. |
| Telegram | Internal notifications of new requests to the data controller. |
Public administrations and bodies may also access the data when there is a legal obligation.
6. International Transfers
Some of the above providers are located in or process data in the US or other countries outside the European Economic Area. Such transfers are made with the appropriate safeguards provided for in the GDPR, mainly adherence to the EU-US Data Privacy Framework and/or the Standard Contractual Clauses approved by the European Commission. You can ask us for information about the safeguards applied.
7. Automated Decisions and Profiling
We use artificial intelligence tools to analyze and internally prioritize the requests we receive (for example, estimating the sector and potential interest) and so that the "Neo" assistant can better assist you. This involves profiling of a commercial nature.
These analyses do not produce legal effects or significantly affect you similarly: they are an internal aid to management, and the final decision is always made by a person. In any case, you have the right to object to this processing and to request human intervention by writing to us at the indicated email address.
8. Data Security
We implement appropriate technical and organizational measures to protect your data from unauthorized access, loss, or alteration (encryption in transit, access control, and providers that comply with recognized security standards).
9. Minors
This site and its services are aimed at professionals and businesses. They are not intended for minors under 14 years of age, and we do not knowingly collect their data. If we detect that a minor's data has been provided without authorization, we will proceed with its deletion.
10. Your Rights
You can exercise the following rights at any time:
- Access to your personal data.
- Rectification of inaccurate data.
- Erasure ("right to be forgotten").
- Restriction of processing.
- Objection to processing, including profiling.
- Data portability.
- Withdraw your consent, without affecting the lawfulness of prior processing.
To exercise them, write to 1913torres@gmail.com indicating the right you wish to exercise and attaching a document proving your identity. We will respond within a maximum period of one month.
If you believe that the processing does not comply with regulations, you have the right to file a complaint with the Spanish Data Protection Agency (AEPD), www.aepd.es.
11. Changes to this Policy
We may update this Privacy Policy to adapt it to regulatory changes or changes in our services. The current version will always be the one published on this page, with its last update date.