Privacy policy
The company is in Dubai and sells into Spain and Latin America. That means your data leaves the European Union, and that the United Arab Emirates has no adequacy decision from the European Commission. I am not hiding it in the small print: it is set out in full in section 6. And if you received an email from us without ever writing to us first, section 2.4 tells you where your address came from and how to stop the emails in one step.
Last updated: August 2026 · Version 1.1
This policy covers what articles 13 and 14 of the GDPR require. It is written so you can understand it without a lawyer sitting next to you. If you still have a question, write to us and we will answer it in writing.
1. Who is the controller of your data
| Detail | Value |
|---|---|
| Data controller | ECOM OLIMPO - FZCO |
| Address | IFZA Business Park, DDP, Dubai, United Arab Emirates |
| Trade licence | Free zone company incorporated in the United Arab Emirates. We send a copy of the trade licence to anyone who asks for it at info@ecom-olimpo.com |
| Contact email, including data rights | info@ecom-olimpo.com |
| Telephone and WhatsApp | +971 58 115 3288 |
| Data Protection Officer | None has been appointed. None of the circumstances in art. 37(1) GDPR apply: we do not carry out regular and systematic monitoring on a large scale and do not process special categories of data on a large scale. |
ECOM OLIMPO - FZCO is subject to the GDPR under article 3(2)(a), because it offers services to people located in the European Union. You have exactly the same rights you would have against a Spanish company.
1.1. Representative in the European Union (art. 27 GDPR)
Article 27 of the GDPR requires companies outside the EU that offer services to people in the EU to designate a representative in the Union in writing. That representative is an additional point of contact, whom you can approach just as you would approach us.
It has not been appointed yet. We would rather say so than pretend otherwise. It is being arranged, and as soon as it exists the details will appear here and in the legal notice. In the meantime this takes nothing away from your rights: you can write to us directly at info@ecom-olimpo.com and complain to the Spanish DPA as explained in section 8.3.
2. What data we process and where it comes from
2.1. Data you give us
- Diagnostic form: name, email address, telephone or WhatsApp number, approximate monthly turnover of your store (in bands), monthly advertising investment capacity (in bands) and the free-text message you choose to write. Also the page you sent the form from and the language.
- Guide download: name and email address.
- Email you send to info@ecom-olimpo.com: here the detail matters, because most policies claim more than they do. The full message and any attachments stay in the mailbox and do not leave it. What our server stores separately is an index containing: your sender address, the subject line, an excerpt of up to 300 characters of the new text in the message, the category assigned by our automated rules, the urgency, how many attachments it carried (the attachments themselves are discarded), the technical message identifier, the date, and a cryptographic fingerprint of your address used to link messages from the same sender. Nothing else. That index lives outside the server's public directory and the server is configured never to serve it over the web.
- WhatsApp: your number and the content of the conversation, which stays in WhatsApp itself.
- Diagnostic call: whatever you tell us during the call and the notes we take. If we were ever going to record a call, we would say so at the start and would only record with your permission.
- Client onboarding: registered or trading name, tax identification number, billing address, contact person and payment details.
2.2. Data collected automatically while you browse
- IP address, browser type and version, operating system, language, screen resolution and device type.
- Pages visited, time on page, traffic source, campaign and ad you came from, and interactions with the page.
- Cookie identifiers and similar technologies, on the terms set out in the Cookie policy.
- Server logs with date, time and requested resource, for security and to detect incidents.
- When you submit the form, an anti-abuse control that limits submissions per IP address. Your IP is not stored in the clear: it is turned into an irreversible hash used only to count submissions in the last hour.
Analytics and advertising data is only collected if you have given your consent in the cookie panel. Server logs and the anti-abuse control are always generated, because you cannot operate a site securely without them.
2.3. Data that reaches us from third parties
- Meta Platforms Ireland Limited, when you fill in an instant contact form inside Facebook or Instagram instead of doing it on our website.
- Public information about your business or your store when we look it up to prepare the diagnostic: your own website, your online store or public registers.
2.4. Cold outreach: where we got your address
We do commercial prospecting. That is: we write to companies that have not contacted us first, to offer them a free diagnostic. If you received an email from us and had never spoken to us, this is the section for you.
- What data we use: the company's contact address, the company name, the address of its website or store and, where it is publicly stated, the name and job title of the contact person. Nothing else. We do not use personal data outside the professional sphere.
- Where it comes from: publicly accessible sources. Specifically: the company's own website or online store, its public business profiles, sector directories and publicly accessible commercial or professional registers. We do not buy or rent email lists.
- What we tell you in that first email: who we are, why we are writing, the specific source your address came from — not "public sources" in the abstract, but the actual source — and how to ask us never to write again. This is the information required by article 14 of the GDPR and we give it to you in that same message, with a link to this policy.
- How to stop it: reply to that email and say so. That is enough: no forms, no logging in anywhere. Your address goes onto a suppression list and we do not write to you again (section 7.1).
2.5. Data we do not process
We do not ask for and do not want special categories of data: health, political opinions, trade union membership, ethnic origin, sexual orientation, biometric or genetic data. If you send them to us on your own initiative, we delete them. Nor do we process children's data: our services are aimed exclusively at companies, professionals and people over 18.
3. What we use your data for and on what legal basis
Each purpose has its own legal basis. We do not mix them: if you withdraw consent for one, the others continue under their own regime.
| # | Purpose | Data processed | Legal basis (GDPR) |
|---|---|---|---|
| 1 | Handling your request for a diagnostic or for information, contacting you by email or WhatsApp and preparing a proposal | Identification data, contact details and form answers | Art. 6(1)(b) — steps taken at your request prior to entering into a contract |
| 2 | Automatically routing you to the call booking calendar or to the guide download depending on the bands you select | Form answers | Art. 6(1)(b) — pre-contractual steps |
| 3 | Sending you the "our working method" (insured ecommerce) guide you requested | Name and email address | Art. 6(1)(b) — carrying out your request |
| 4 | Sending you commercial communications by email: educational content, news and offers for our services | Name, email address, engagement with the emails | Art. 6(1)(a) — your consent, given via a separate, unticked box. If you are already a client, art. 6(1)(f) legitimate interest for similar products or services, with an unsubscribe option in every email (art. 21(2) of Spanish Law 34/2002) |
| 5 | Measuring how the website is used and which campaigns work (analytics) | Cookie identifiers, browsing data | Art. 6(1)(a) — your consent, collected in the cookie panel. Art. 22(2) of Spanish Law 34/2002 for the storage on your device |
| 6 | Measuring conversions from our ads and showing you targeted advertising on and off the website (remarketing and custom audiences) | Cookie identifiers, browsing events, email address and telephone number in hashed form when sent server-side | Art. 6(1)(a) — your consent, collected in the cookie panel |
| 7 | Providing the contracted service, invoicing it and managing the relationship | Identification, tax, billing and project delivery data | Art. 6(1)(b) — performance of the contract |
| 8 | Complying with legal, accounting and tax obligations | Billing and transaction data | Art. 6(1)(c) — legal obligation |
| 9 | Site security, fraud prevention and blocking automated form submissions | Hashed IP address, logs, technical data | Art. 6(1)(f) — legitimate interest in protecting the service and its users |
| 10 | Keeping evidence to defend ourselves or bring a claim in a dispute | Communications, contract, delivery records | Art. 6(1)(f) — legitimate interest in establishing and defending legal claims |
| 11 | Commercial prospecting: writing for the first time to companies that have not contacted us, to offer them the diagnostic | Company contact address, company name, website and, where publicly stated, name and job title of the contact person | Art. 6(1)(f) — legitimate interest in promoting our services among companies in the sector, recognised by recital 47 of the GDPR. Balancing test in section 3.1. Immediate opt-out in every message |
| 12 | Receiving the email that arrives at info@ecom-olimpo.com, classifying it with automated rules and generating an internal alert so we can answer in time and spot opt-outs and complaints immediately | Sender, subject, excerpt of up to 300 characters, category, urgency, number of attachments, identifier and date | It depends on why you are writing: · If you are replying to one of our outreach emails: art. 6(1)(f) — legitimate interest in managing the response to our own communication and, above all, in detecting without delay who asks to be removed. · If you write to us on your own initiative asking about our services: art. 6(1)(b) — pre-contractual steps at your request. · Rest of the mailbox (suppliers, ordinary administration, email unrelated to the campaign): art. 6(1)(f) — legitimate interest in running the company mailbox |
| 13 | Handling and evidencing opt-out and objection requests, and keeping a suppression list so we do not write to you again | Email address, date and reason for the suppression | Art. 6(1)(c) — legal obligation to give effect to objections to direct marketing (art. 21(3) GDPR and art. 21 of Spanish Law 34/2002), together with art. 6(1)(f) — legitimate interest in being able to prove we complied |
3.1. About the legitimate interests we rely on
For purposes 4 (clients only), 9, 10, 11, 12 and part of 13 we rely on legitimate interest. We have balanced that interest against your rights.
For cold outreach, which is the most arguable one, the balancing goes like this: we write to company contact addresses, in a strictly professional context, about a matter connected to that company's business; the data is minimal and includes no special categories; we do not build profiles or combine it with other sources; we identify in the first message where the address came from; and the opt-out is immediate and permanent. On those terms we consider that our interest does not override your rights. If you consider that in your case it does, object and we stop: we will not argue the balancing test with you.
You can ask us for the full detail of any of these balancing exercises by writing to info@ecom-olimpo.com: we will send it to you.
3.2. About the automatic routing of the form
The diagnostic form decides automatically whether to take you to a calendar to book a call or to the guide download, based on the turnover and investment bands you select. We are telling you because it is an automated process, but it does not produce legal effects concerning you or similarly significantly affect you within the meaning of article 22 of the GDPR: it never denies you a right or closes the door to working with us. If it routes you to the guide and you still want to talk to us, write to us and we will talk.
3.3. About the automatic classification of incoming email
When a message arrives at info@ecom-olimpo.com, a set of automated rules assigns it a category based on the subject line and the text: whether it is an opt-out request, a data protection complaint, genuine interest, a pricing question, a bounce from the recipient's mail server, an out-of-office auto-reply, and so on. That category determines one single thing: whether an alert reaches us straight away or the message waits for the daily review.
It is worth spelling this out, even though nobody requires us to:
- The classification exists to prioritise internal alerts. That is all.
- It produces no legal effects concerning you and does not significantly affect you, so it is not an automated decision within the meaning of article 22 of the GDPR. It grants you nothing and denies you nothing, sets no prices, does not score you as a person and does not decide whether we work with you.
- There is always a person behind it. A human reads and answers the message; the machine only decides the order.
- If the classification gets it wrong — and it does — the worst consequence is that we take a little longer to reply.
- The only category with a real effect is opt-out, and that effect is always in your favour: it takes you out of the mailings.
Even so, you can ask for human intervention, express your point of view or contest any classification by writing to info@ecom-olimpo.com.
3.4. Whether the data is mandatory
The fields marked as mandatory are the minimum we need in order to reply to you. If you do not provide them, we cannot process your request. Everything else is optional and only serves to prepare the conversation better.
4. Joint controllership with Meta for the pixel and custom audiences
When you accept advertising cookies, we install the Meta pixel and send conversion events to Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland). In line with the case law of the Court of Justice of the European Union (cases C-210/16 and C-40/17), at the stage of collecting and transmitting that data ECOM OLIMPO - FZCO and Meta act as joint controllers.
- What we are responsible for: obtaining your consent before activating the pixel, blocking it until then, informing you about this processing, and handling your rights in relation to the data collected from our website.
- What Meta is responsible for: the subsequent processing it carries out with that data in its own systems, the building of audiences and aggregate measurement, in accordance with its own policies.
- Where to exercise your rights: you can approach either of us. If you write to us, we pass on to Meta whatever falls to them.
You can read Meta's data policy at facebook.com/privacy/policy and control the advertising you see from your account settings.
To be exact about what is signed and what is not: the arrangement between us is the one contained in Meta's own terms, which we accepted when we opened the account; on top of that we have not signed a separate joint controller addendum for custom audiences. The three points above are the essence of that arrangement, published here so that you know who answers for what and can hold us to it.
5. Who else sees your data
We do not sell personal data. We do not disclose it to third parties for their own commercial purposes. It is seen only by the providers we need in order to operate, with access limited to what is strictly necessary.
| Recipient | What for | Role | Where processing takes place |
|---|---|---|---|
| Hostinger International Ltd | Website hosting, domain and mailbox. This is where the full messages and attachments you send us by email actually live | Processor | European Union |
| Meta Platforms Ireland Limited | Pixel, Conversions API, ad measurement and custom audiences | Joint controller (see section 4) | Ireland, with transfers to the US under the EU-US Data Privacy Framework |
| Google Ireland Limited | Google Analytics 4: website usage analytics | Processor | Ireland, with transfers to the US under the EU-US Data Privacy Framework |
| WhatsApp Ireland Limited | Two things: the channel you talk to us on if you choose WhatsApp, and the channel our internal alert about new email travels through, which includes sender, subject and the 300-character excerpt | Processor or independent controller depending on the case | Ireland |
| Legal, tax and accounting advisers | Compliance with obligations and defence of claims | Independent controllers bound by professional secrecy | Depending on the adviser |
| Public authorities and courts | Where there is a legal obligation or a valid request | Independent controllers | Depending on the case |
Two entries you would expect on a list like this are not there, because they do not exist yet: no CRM or call-scheduling tool and no email delivery platform is connected to this website. When you submit the form, our server sends a notice to info@ecom-olimpo.com and keeps a copy of your answers on that same server, the one in the first row of the table. Your data would only reach an outside tool if we connected one, and none is connected. The day we connect one, it goes into this table, with its name and its country, before it receives a single piece of data.
5.1. Who receives nothing
- The incoming email index is not shared with anyone. Our own equipment downloads it to generate the internal alert, and that alert reaches the controller's phone. It does not pass through any analytics provider, any artificial intelligence service or any data enrichment service.
- The geolocation database receives nothing. It is a file installed on our own server (section 12). DB-IP is not a recipient: your IP address and everything else stays with us.
5.2. Data processing agreements (art. 28 GDPR)
Here too we would rather be exact. Article 28 of the GDPR requires a written contract with each processor. Large providers (hosting, advertising, analytics) apply their own standard data processing terms, which we accept when we sign up. What does not yet exist is a data processing agreement reviewed and signed one by one, and we are not going to claim otherwise. It is in progress.
If you want the up-to-date, named list of all active processors, with their location and the safeguards applied, ask for it at info@ecom-olimpo.com and we will send it to you.
6. International data transfers
Read this section in full: it is the part that really affects you. ECOM OLIMPO - FZCO is in Dubai. Your data leaves the European Economic Area for the United Arab Emirates. The United Arab Emirates does NOT have an adequacy decision from the European Commission, which means the Commission has not declared that it offers a level of protection equivalent to the European one.
6.1. What is transferred and why
The data you provide is processed by our team from the United Arab Emirates: that is where the company is and where the service is provided. The transfer is inherent in working with us. It covers everything in section 2: form, email, WhatsApp and the incoming email index.
6.2. What we rely on
- Article 49(1)(b) of the GDPR for transfers necessary to perform the contract between you and us, or to take pre-contractual steps at your request. That is the case when you ask for a diagnostic, write to us or hire us.
- For the onward transfers to the United States carried out by Meta and Google, the EU-US Data Privacy Framework, to which both are certified.
- Measures we do apply in practice: encryption in transit, minimisation of the data that travels (for incoming email the message itself never travels, only the excerpt) and limited access.
We do not claim to have signed Standard Contractual Clauses or carried out a transfer impact assessment, because today we do not have them. What supports the transfer today is article 49(1)(b), the one described above. If we later adopt a different instrument, it will be stated here with its date and you will be able to request a copy.
6.3. What this means for you
That the level of protection in the destination country may not be equivalent to the European one and that, in an adverse scenario, exercising your rights or obtaining judicial redress against improper access could be harder than within the European Union. We are telling you because you have the right to know before you leave us a piece of data, not after.
7. How long we keep your data
| Situation | Retention period |
|---|---|
| You requested information and we never signed anything | 24 months from your last active contact. After that, it is deleted. This includes the copy of the form held on our server |
| You downloaded the guide and did not give marketing consent | 24 months from the download |
| You gave consent for commercial communications | For as long as you do not withdraw it. After you unsubscribe we keep only the evidence of the consent and of the unsubscribe for 3 years, the limitation period for very serious infringements under art. 72 of Spanish Organic Law 3/2018 |
| Incoming email index (sender, subject, excerpt, category) | 90 days. The index is stored in one file per day and, once the period expires, the whole file is deleted. Every deletion is written to a purge log, so it can be proved |
| Email suppression list (people who asked not to receive any more emails) | Indefinite, for as long as we carry out outreach. Only your address, the date and the reason. The explanation is right below, in section 7.1 |
| Full messages and attachments in the info@ mailbox | Kept in the mailbox for as long as they are needed for the relationship and then deleted along with the rest of the contact data |
| You are or have been a client | For the whole contractual relationship and, afterwards, blocked for the limitation period of the claims arising from the contract |
| Invoicing, accounting and tax | For as long as the tax and accounting rules that apply to each invoice require |
| Server and security logs | 12 months |
| Form anti-abuse control (hashed IP address) | 1 hour |
| WhatsApp conversations | 24 months from the last message |
| Cookies | See the duration of each one in the Cookie policy |
7.1. Why the suppression list does not expire
It is the only indefinite period in the whole table and it deserves an explanation, because at first glance it looks like the opposite of what you asked for when you opted out.
If we applied the general period and deleted the suppression list after 24 months, we would be deleting the only record that stops us writing to you again. With the list empty, your address would show up again in a public source, we would write to you again, and your opt-out would have been worthless. In other words: complying with the retention period would cause exactly the infringement the opt-out is meant to prevent.
So we keep it for as long as the outreach activity lasts, and with the bare minimum: your email address, the date and the reason. Nothing else. It is not used for any other purpose, not enriched and not shared. Articles 17(3)(b) and 21(3) of the GDPR support keeping this record in order to give effect to your own objection. If we ever stop doing cold outreach, the list is destroyed.
If you would rather your address were not on that list either, say so and we will delete it; but then we cannot guarantee you will not receive an email from us again, and it is only fair that you know that before deciding.
When any of the other periods expires, the data is deleted or irreversibly anonymised. During the blocking period it remains available only to judges, courts and public authorities in order to deal with outstanding liabilities.
8. Your rights
As the data subject, you have the following rights and can exercise them free of charge, whenever you want and without giving reasons:
| Right | What you can do |
|---|---|
| Access | Find out whether we process data about you and obtain a copy of it, including your entry in the email index if you have written to us |
| Rectification | Correct inaccurate data or complete incomplete data |
| Erasure ("right to be forgotten") | Ask us to delete it when it is no longer necessary or you withdraw consent |
| Objection | Object to processing based on legitimate interest, including cold outreach. If you object to direct marketing, we stop processing your data for that purpose immediately and without exception |
| Restriction | Ask us to freeze the processing while a challenge is resolved |
| Portability | Receive the data you provided to us in a structured, commonly used format, or ask us to send it to another controller |
| Human intervention | Ask for a person to review any automated classification or routing, express your point of view and contest it (sections 3.2 and 3.3) |
| Withdraw consent | At any time, without affecting the lawfulness of processing carried out before the withdrawal |
| Know where your data came from | If you did not give it to us yourself, ask us for the specific source we obtained your address from (art. 14(2)(f)) |
8.1. How to exercise them, step by step
- Write to info@ecom-olimpo.com with the subject line "GDPR rights". Post to the address in section 1 works too.
- Say which right you are exercising. One sentence is enough: "send me a copy of my data", "delete everything", "stop emailing me". No form and no particular format required.
- Do not send us a copy of your ID up front. If you write from the same address you originally contacted us with, that is normally enough. We will only ask for more if there are reasonable doubts about who you are, and we will tell you exactly what and why.
- We acknowledge receipt and reply within one month of receiving the request, extendable by two further months if it is complex. If we need the extension, we tell you within the first month and explain why.
- If we cannot grant something, we tell you why and remind you that you can complain to the Spanish DPA.
If you write to us from info@ or from a company mailbox, bear in mind that the message goes through the circuit in section 2.1: an excerpt will sit in the index until it is purged after 90 days.
8.2. Unsubscribing from commercial communications
Every commercial email we send carries a one-step way out that does not ask you to log in. If it is an outreach email, simply replying and saying so is enough: our rules detect it as an opt-out request, an immediate alert reaches us and your address goes onto the suppression list described in section 7.1.
8.3. Complaining to the supervisory authority
If you believe we have not handled your rights properly or that we process your data improperly, you can lodge a complaint with the competent data protection authority.
In Spain that is the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es. Complaints are filed free of charge through its electronic portal, using a digital certificate, Cl@ve, or without electronic identification following the procedure set out on its website, and you do not need a lawyer. If you live in another European Union Member State, you can go to the supervisory authority of your country. If you live in Latin America, to the data protection authority that applies under your national law.
You do not have to complain to us first in order to go to the AEPD. But if you write to us first, we will try to resolve it.
9. Security: what there is and what there is not
We prefer a short, true list to a long one we cannot prove. A policy that promises security it does not have protects nobody and, if something goes wrong, it is evidence against us.
What we apply today:
- Encryption in transit via HTTPS/TLS across the whole site. The data entry points reject any request that does not arrive encrypted.
- Minimisation for incoming email: neither the full message nor the attachments are stored, only an excerpt capped at 300 characters.
- The data store lives outside the server's public directory and, on top of that, the server is configured never to serve those files over the web.
- Each internal service uses its own secret credential: if one leaks, it does not open the others.
- The form limits submissions per IP address, filters bots, and stores the IP as an irreversible hash rather than in the clear.
- Automatic deletion of the email index after 90 days, with every purge logged.
- Access limited to the people who need it to do the work.
What we do not have, put plainly: the incoming email index is not encrypted at rest. We hold no security certifications of any kind and no external audit. There is no data protection officer (section 1) and no EU representative appointed yet (section 1.1). And we are not going to list backups, two-factor authentication on the tools that hold data, or role-based access control among our measures: they will appear here once we have checked exactly how each of them is set up and written it down, and not a day before.
No system is invulnerable. If a security breach occurs that poses a high risk to your rights, we will notify you without undue delay, and we will also report it to the supervisory authority where required, in accordance with articles 33 and 34 of the GDPR.
10. Children
Our services are aimed exclusively at companies, professionals and people over 18. We do not knowingly collect children's data. If we find that we have received data from a child, we delete it. If you are a parent or guardian and believe a child has given us data, write to us and we will delete it.
11. Changes to this policy
We may update this policy when our processing, our providers or the applicable law change. The version in force is the one published here with its date. If the change is substantial and affects processing based on your consent, we will tell you and, where appropriate, ask for your consent again.
12. Geolocation and third-party attribution
This site detects the visitor's country in order to show the version in their language and the pricing for their market. Resolution happens entirely on our own server, against a file of IP ranges installed on it: the IP address is not passed to any third party and is not stored. It uses the IP Geolocation by DB-IP database, published under a CC BY 4.0 licence.
Detection only runs on a first visit and never on search engines. Your language choice, if you use the switcher, always takes precedence and is remembered in your browser. You can disable detection by adding ?nogeo to any address.