What data of yours we process, what for, who else handles it, and what you can require of us at any time.
Last updated: 23 August 2026
We are not required to appoint a data protection officer (article 37 GDPR): we carry out no large-scale systematic monitoring and process no special categories of data. Requests go to the address above and a person answers them.
When you check a domain. The name you type, your IP address, the date and time, and the result of the bot check. They serve to answer the query and to apply the per-IP limits that stop a script from exhausting the service.
When you subscribe. Payment happens on Stripe, not here. From Stripe we receive your name, email address, phone number, billing address, tax number or VAT ID, the country of the card and the customer and subscription identifiers. Your card number never passes through our servers and we never see it.
When we set up your site. We keep the IP address the purchase came from and the country derived from it. This is not telemetry: the VAT rules for electronically supplied services require two non-contradictory pieces of evidence of the customer’s country, and this is one of them.
From public sources. To build your site we use what your business already publishes on its Google Business Profile: name, address, phone, opening hours, photos and publicly visible reviews. We only ever look at the listing of the business that hires us.
When you write to us. The content of your emails, WhatsApp messages or panel tickets, with whatever you choose to put in them.
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the service: building and maintaining your site, giving you the panel and handling your change requests | Art. 6(1)(b) — performance of the contract. If you are the contact person at a corporate customer, art. 6(1)(f) — our legitimate interest in managing the relationship |
| Registering and renewing the domain, and transferring it when you ask | Art. 6(1)(b) — performance of the contract |
| Collecting the fee, issuing invoices and keeping the accounts | Art. 6(1)(c) — legal obligation (Spanish tax and commercial law) |
| Evidencing your country for VAT on electronically supplied services | Art. 6(1)(c) — legal obligation |
| Preventing abuse of the search: per-IP limits and the bot check | Art. 6(1)(f) — our legitimate interest in keeping the service standing and our registrar bill predictable |
| Telling you about changes to the service, the price or these terms | Art. 6(1)(b) — performance of the contract |
| Telling you about similar services while you are a customer | Art. 6(1)(f) — legitimate interest, within article 21.2 LSSI. Every message carries an unsubscribe link, and unsubscribing does not affect the service |
We take no automated decisions with legal effect on you and build no profiles. The bot check can reject a search; that decides nothing about you, and you can always write to us instead.
Only the suppliers the service actually needs, each under an article 28 GDPR processing agreement and only for what is stated here:
| Supplier | What for | Where | Safeguard |
|---|---|---|---|
| Stripe Payments Europe, Ltd. | Collecting the subscription, invoicing and tax | Ireland (EU), accessed from Stripe, Inc. in the US | Standard contractual clauses and Data Privacy Framework |
| Name.com, Inc. | Registering, renewing and transferring the domain | United States | Standard contractual clauses |
| Cloudflare, Inc. | The bot check (Turnstile) on the domain form | United States and EU | Standard contractual clauses and Data Privacy Framework |
| OVH SAS | The server that runs the site, the panel and the backups | Francia (Unión Europea) | Processing agreement |
| Our accountants | Bookkeeping and tax filings | Spain | Legal obligation and processing agreement |
We also disclose data to the Spanish tax authority and other public bodies where a rule requires it. We do not sell data and do not hand it to third parties for advertising: we never have, and it is not part of the business model.
About WHOIS. The domain is registered in the name of Missing Title S.L., so the details in the registry and in public WHOIS and RDAP lookups are ours, not yours. When you ask for the transfer to your own account, you become the registrant and the publication rules of the relevant registry apply to you.
The US suppliers in the table above involve transfers outside the European Economic Area. They rely on the standard contractual clauses approved by the European Commission and, where the entity is certified, on the adequacy decision for the EU-U.S. Data Privacy Framework. Write to us and we will send you a copy of the safeguards.
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability at any time, and withdraw consent where processing relies on it, without affecting the lawfulness of processing before withdrawal. Write to andrey@vitrina.business saying which right you are exercising; if there is reasonable doubt about who is writing, we will ask for something that proves your identity.
We reply within one month, extendable to two if the request is complex — and we would tell you before that first month runs out. Exercising a right is free.
If you think we have got it wrong, you can complain to the Spanish Data Protection Agency (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid), though we would appreciate the chance to fix it first.
If your site carries a contact form or anything else that collects data from your customers, that data is yours: you are the controller and we are the processor. That processing is governed by the article 28 GDPR processing terms that form part of the Terms and conditions, under which we undertake to process it only on your instructions, keep it confidential, and return or delete it when the relationship ends.
The Google listing information we publish on your site is what your business already makes public there. If you would rather something did not appear, say so and we take it down.
All traffic is encrypted with HTTPS, panel access is per-person and password-protected, administrative access is limited to whoever needs it, and we take regular backups. No system is infallible: if a breach occurred that posed a high risk to your rights, we would tell you and notify the supervisory authority within the GDPR deadlines.
If what we do with data changes, this page changes, and the date above reflects it. When a change matters to active customers, we also tell them by email.
This is a translation of the Spanish text for your convenience. In the event of any discrepancy, the Spanish version prevails, as the company is Spanish and the service is supplied from Spain.