Privacy policy
Last updated: 13 September 2026This policy explains what personal data ConsultorIA collects through this website and Skyline, our infrastructure viewer, why, for how long, who it is shared with and how you can exercise your rights under the General Data Protection Regulation (GDPR) and the Spanish Organic Law 3/2018 (LOPDGDD).
1. Data controller
- Company
- [Legal name]
- Tax ID
- [NIF]
- Address
- [Registered address]
- hola@consultoria.com
2. What data we process and why
Contact form and email
When you send us a request we receive your name, work email, company and the message you write. The form opens your own email client, so the message travels through your email provider and reaches our mailbox. We use it to answer your request and, if you decide to go ahead, to prepare a proposal.
Legal basis: your consent (art. 6.1.a GDPR) and the steps needed before entering into a contract (art. 6.1.b).
Skyline account
If you create an account in Skyline we store your email, name, company and a hash of your password. If you sign in with Google or LinkedIn we receive the name and email those services share with us; we do not receive your password from them. We use this data to identify you, keep your session open and show you your own scans.
Legal basis: performance of the service you requested (art. 6.1.b).
Data you analyse in Skyline
To run a scan you give Skyline read-only credentials or roles for your cloud accounts, or upload Terraform plans. The inventory, cost estimates and security findings that result are stored with your account so you can revisit them. We use them only to produce your reports; we do not use them for any other purpose or share them with third parties. We recommend read-only roles with an external ID and removing them when you are done.
Legal basis: performance of the service (art. 6.1.b). If these files contain personal data of other people, you are responsible for having a valid basis to share them.
Server logs
Our servers record the IP address, browser identifier, requested page and timestamp of each request. We keep them to protect the service against abuse and to diagnose failures.
Legal basis: our legitimate interest in keeping the service secure and working (art. 6.1.f).
3. How long we keep it
- Contact requests: twelve months after our last exchange, unless a project starts, in which case they become part of the client file.
- Skyline account and scans: while the account exists. You can delete scans at any time and ask us to delete the account; we remove it within thirty days.
- Server logs: ninety days.
- Invoicing and contract records: the period required by tax and commercial law, currently six years.
4. Who receives the data
We do not sell or rent personal data. The following providers process it on our behalf under data processing agreements:
- Amazon Web Services, which hosts the website, Skyline and its database in its Ireland region, inside the European Union.
- Our email provider, which stores the messages you send us.
- Google or LinkedIn, only if you choose to sign in with them, and only for authentication.
Some of these providers may process data outside the European Economic Area. In that case the transfer is covered by the European Commission's standard contractual clauses or by an adequacy decision such as the EU-US Data Privacy Framework.
5. Your rights
You can ask us at any time to access, rectify or erase your data, to restrict or object to its processing, to receive it in a portable format and to withdraw consent you gave earlier. Write to hola@consultoria.com from the address we have on file, or attach a copy of an identity document if you write from another one. We answer within one month.
If you believe we have not handled your data correctly you can lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
6. Cookies
This public website does not set cookies and does not load analytics, tracking scripts or resources from third parties; fonts are served from our own domain. Skyline sets a single technical session cookie that keeps you signed in. It is strictly necessary for the service, so it does not require consent, and it is deleted when you sign out or when it expires.
7. Security
All traffic is encrypted with TLS. Passwords are stored hashed. Cloud credentials you provide are used in memory only for the scan you request and are never stored; Skyline also refuses credentials that can write. Access to production systems is restricted to the people who operate the service.
8. Changes
If we change this policy we will publish the new version on this page and update the date at the top. Substantial changes affecting Skyline users will also be announced by email.
See also the legal notice.