Privacy policy
Last updated: 2026-08-12
Who is responsible for your data
The data controller is Wayne Tomlinson, NIF ESY6523555X, at Partida Benicolada 1-N, 03710 Calpe, Alicante. You can reach us about anything on this page at hola@ineeda.es.
What we collect
- Account details — your name, email address and a hashed password. Never the password itself.
- Listing information — everything you enter about a business you own or claim, including its address, contact details and photographs.
- Reviews, ratings and votes — the content you post and the account it belongs to.
- Messages — what you send us through the contact form, a claim request or a report.
- Newsletter subscription — your email address, if you ask for it.
- Technical data — your IP address, browser and the pages you request. This is recorded to keep the site secure and to enforce rate limits.
- Analytics — if you accept analytics cookies, aggregated usage data through Google Analytics.
- Billing — if you take a paid plan, your subscription and invoice records. Card details are handled entirely by Stripe and never reach our servers.
Why we use it, and on what legal basis
- To run your account, publish your listing and provide a paid plan — because it is necessary to perform our contract with you (art. 6.1.b GDPR).
- To send analytics and advertising cookies — only with your consent (art. 6.1.a GDPR), which you can withdraw at any time.
- To send the newsletter — with your consent, withdrawable from the unsubscribe link in every issue.
- To prevent fraud, spam and abuse, and to keep the directory accurate — our legitimate interest in a service that works and is not overrun (art. 6.1.f GDPR).
- To issue invoices and meet tax and accounting duties — legal obligation (art. 6.1.c GDPR).
Emails to businesses about their listing
Where a business appears in this directory from public sources, we may write once to the contact address it publishes, to tell it the listing exists and offer it the chance to claim, correct or remove it.
We rely on legitimate interest for that single message (art. 6.1.f GDPR, and art. 21.2 LSSI-CE, which permits commercial email about a service similar to one already connected with the recipient's own business). Every such email identifies us, explains where the data came from, and carries a working opt-out. One message is sent per business, and we do not write again if there is no reply beyond the follow-up described in it.
If you would rather not be contacted at all, or want the listing removed, tell us at hola@ineeda.es and we will act on it.
Who else sees your data
- Hetzner Online GmbH — hosting, in Germany.
- Our email provider — to deliver account, claim and newsletter messages.
- Stripe — to take payments and issue invoices for paid plans.
- Google — Analytics and AdSense, only where you have accepted those cookies, and Maps for the address picker.
We may also disclose data where the law requires it.
Transfers outside the EEA
Our hosting and databases are in the European Union. Some suppliers, such as Stripe and Google, may process data outside the EEA; where they do, transfers are covered by the European Commission's standard contractual clauses or an adequacy decision.
How long we keep it
- Account and listing data — while your account is open, and up to 12 months afterwards in case you come back.
- Reviews — they stay published while the listing exists, but are detached from your account if you delete it.
- Contact and claim messages — up to 24 months.
- Invoices and billing records — 6 years, as required by Spanish commercial and tax law.
- Server and security logs — up to 12 months.
- Newsletter — until you unsubscribe.
Your rights
You have the right to ask for access to your data, to have it corrected or erased, to restrict or object to how we use it, and to receive it in a portable format. Where we rely on consent, you can withdraw it at any time without affecting what was done beforehand.
Write to hola@ineeda.es and we will reply within one month. If you are not satisfied, you can complain to the supervisory authority: Agencia Española de Protección de Datos (www.aepd.es).
Security
Passwords are stored only as bcrypt hashes. The site is served over HTTPS, administrator accounts require two-factor authentication, and access to the database is limited to the people who maintain the service.
No system is perfectly secure. If we ever discover a breach that puts your rights at risk, we will notify you and the supervisory authority as the GDPR requires.
Children
This site is not intended for children. You must be at least 14 years old to create an account, which is the age at which Spanish law allows consent to be given directly.
Changes to this policy
If we change how we handle personal data, we will update this page and the date at the top. Significant changes will be announced on the site.