Novantrek · Data protection

Privacy policy

Novantrek designs websites, automation and custom systems. Here it explains what data its website processes, why and for how long.

Updated on 10 October 2026

In a nutshell

You do not need to provide any personal data to browse this website, and no first-party cookie is set.

The service pages count visits with an in-house tool: it stores pseudonymised technical data, without cookies or IP addresses, and deletes it after 30 days. You can turn it off with one click in the cookie policy.

The contact form sends nothing by itself: it opens your email program with the message written, and you decide whether to send it.

The questions chat replies with answers written in advance: no artificial intelligence, no storing of the conversation and no sending it to third parties.

No advertising, no pixels and no third-party analytics, fonts or scripts.

1. Data controller

Controller
[ company name or full name ]
Tax ID (NIF / CIF)
[ NIF ]
Registered address
[ address, postcode, town and province ]
Email
info@novantrek.com
Trade name
Novantrek

Novantrek has no data protection officer because its activity is not among the cases that require one (Article 37 of the GDPR and Article 34 of the Spanish LOPDGDD). For any question about your data, write to info@novantrek.com.

3. Visit analytics

The service pages count their visits with Novantrek's own tool. It is not Google Analytics or a third-party service: the program and the database sit in Novantrek's Cloudflare account and the data is not shared with anyone. The legal pages and the games room at novantrek.com/secret are not measured.

What is stored for each visit

  • The pages you open, the approximate length of the visit, how far you scroll on each page (as a percentage) and the last page you view.
  • Where you came from: the address of the referring page, if your browser sends it (for example, a Google search or Instagram), and the campaign, if the link carries one.
  • Which links and buttons you click: the link text, where it leads and the position of the click in the window, as a percentage. If it is a contact button, the fact that you clicked it is noted. Never what you type into a field.
  • Device data: screen and window size, whether it is a touch screen, browser and operating system (without version), main language, time zone, light or dark theme, the connection type your browser reports (4G, Wi-Fi…) and how long the page took to load.
  • If an error occurs on the page: only that it happened and where, never the message, which could contain form data.
  • The approximate location Cloudflare infers from the connection: country, region, city, postcode and approximate coordinates of that city. It is not your address: it is the area your connection exits from, which is often your provider's exchange.
  • The network type, in four groups: "Spanish provider", "other provider", "server network" or "unknown". The name of your provider is not stored.
  • Whether you moved the mouse, touched the screen or pressed a key: a yes or a no, without where, when or how many times; and whether the browser reports that it is being driven by a program. This helps tell a person from a program, and it only ever adds: someone browsing with a keyboard or a screen reader, or who only reads, still counts as a person.

Automated programs and copies of the website

When the visitor is a program (a search engine bot, an artificial intelligence crawler or a tool that copies websites), the full text it identifies itself with, the network it comes from and a sample of the pages it visits are also stored. This is stored only for programs, in a separate table.

If someone publishes a copy of this website on another domain and that copy calls the analytics tool, the name of that domain, the date and how many times are noted. Nothing is stored about the people visiting the copy.

What is never stored

  • No cookies, neither first-party nor third-party.
  • Your IP address. It is used for an instant to calculate a code and then discarded. The counters that curb abuse do not store it either: one uses a code derived from it that expires after ten minutes; the other counts per day and per group of addresses (each group covers 1 in 256), identifies no one and expires at the end of the day. Once expired, they are deleted automatically with the following requests.
  • Nothing you type into a form, nor your name, email or phone number.

How a visit is counted without cookies

With a code calculated from your IP, your browser, a secret key and the date. That way, the five pages you open count as one visit rather than five. Because the date is part of the calculation, the next day the code is different: it is impossible to know that you have come back or to follow you from one day to the next.

None of this includes your name, your email or your IP. It is pseudonymised data: during that same day it could be linked to a specific device, which is why it is deleted after 30 days and you can turn analytics off whenever you like.

Legal basis and how to turn it off

Novantrek's legitimate interest in knowing whether its website works and which pages are useful (Article 6(1)(f) GDPR), using the least intrusive approach that allows it: no cookies, no stored IP, no profiles and no tracking across days.

You can object at any time with the "Turn off analytics" button in the cookie policy, or by opening any page with ?no-medir at the end of the address (?si-medir to switch it back on). If your browser sends the Do Not Track signal, nothing about your visit is measured.

How long it is kept and who sees it

Everything is deleted automatically after 30 days, including the records of programs and copies. Only the Novantrek team consults it, with a username and password, in a private dashboard. This data is not sold, not passed on and not combined with other sources.

So that months can be compared, before deletion only the daily totals are recorded: how many visits there were, where they came from and which pages and contact buttons were used. They are aggregate figures, with nothing about any individual visit, and they are kept for two years.

4. The contact form

The contact forms on this website have no server behind them. When you press the button, your own browser arranges what you have written into a message and opens your email program with it, addressed to info@novantrek.com.

  • What you type is not stored in any database of this website: it stays in your browser until you send the email.
  • It does not go through any intermediate form service: the message leaves from your own email program, with your account.
  • If you close the draft without sending it, it goes nowhere.

The forms in the example websites of the gallery are demonstrations and send nothing.

5. When you email Novantrek

From the moment you send an email to info@novantrek.com, personal data is processed, and the controller is the one named in section 1.

What data

Your email address, the name set in your email program and whatever you tell us in the message: usually your name, your business name, the sector and what you need. It is best not to include sensitive data (health, beliefs, third parties' data) that is not needed to prepare a quote.

What for

To answer your enquiry, prepare a quote for you and, if you become a client, manage the business relationship.

On what legal basis

Taking steps at your request prior to entering into a contract (Article 6(1)(b) GDPR). If a project is signed, the performance of the contract and, for invoices, compliance with legal obligations (Article 6(1)(c)).

Which route the message takes

The message leaves from your email provider. When it reaches info@novantrek.com, it is received by Cloudflare's email forwarding service, which delivers it to the controller's mailbox. Email travels encrypted between servers when both support it, which is the norm, but not end to end: to send sensitive documents, say so in your first message and a suitable channel will be agreed with you.

6. The questions chat

The "¿Alguna duda?" (Any questions?) button on the Spanish-language service pages opens an automatic responder with answers written in advance by Novantrek. It does not use artificial intelligence or any language model.

What data and where it goes

When you send a question, your browser sends the latest messages of the conversation and the page you are on to a program on novantrek.com, hosted on Cloudflare, so it can answer the question specific to that page. The program picks an answer and returns it. It does not store the question or the answer, does not use your IP and sends nothing to third parties. When you close the tab, the conversation disappears.

To discuss your case, the channel is info@novantrek.com: it is best not to type personal, medical or banking data in the chat.

On what legal basis

Your consent, when you write and send the question (Article 6(1)(a) GDPR). If you write nothing, nothing is sent.

The games room assistant

The games room at novantrek.com/secret, which is not linked from the rest of the website, has an assistant prepared to use Google's Gemini model, with images and PDFs. It is currently switched off and sends nothing to Google. This section will be updated before it is switched on. The games run inside your browser and only store your high scores there.

The domain check (cybersecurity)

At novantrek.com/en/ciberseguridad/verificar, when you press “Check”, your browser sends the domain and email you type to a novantrek.com program. It uses them to calculate the verification code and checks whether that code is published on the domain (DNS record, file or tag). It does not store the domain or the email and sends nothing to third parties, except the DNS query, which only carries the domain name. Legal basis: your consent when you press the button (Art. 6.1.a GDPR) and, if you hire us, preparing the contract (6.1.b).

7. Summary of processing

WhatDataLegal basisRetention
Visiting the websiteIP and technical connection data, in Cloudflare's logsLegitimate interest (6(1)(f)): security and operationCloudflare's technical log periods
Visit analyticsPseudonymised technical data (section 3), without IP or cookiesLegitimate interest (6(1)(f))30 days (daily totals, two years)
Contact formNone: the text stays in your browser until you send the email——
Questions chatYour question, only to answer itConsent (6(1)(a))Not kept
Writing by emailYour address, your name and what you say in the messagePre-contractual steps (6(1)(b))One year from the last contact if no project follows
Being a clientContact and billing detailsContract (6(1)(b)) and legal obligation (6(1)(c))Tax and commercial periods: up to 6 years
Preferences in your browserLight or dark theme and, if you ask for it, that your visits are not measuredThey stay on your device: Novantrek does not receive themUntil you delete them

8. Who else processes the data

Data is not sold or passed on to third parties for advertising purposes. One provider is involved:

  • Cloudflare, which hosts the website, the analytics database and the programs behind the analytics tool and the chat, and forwards the email that reaches info@novantrek.com. Its parent company is in the United States, so there may be international data transfers; according to the provider itself, these are covered by the safeguards in Chapter V of the GDPR (standard contractual clauses and its participation in the EU-US Data Privacy Framework).

Google currently receives no data from this website: it would only receive data from the games room assistant if it is ever switched on, and this policy would be updated first.

In addition, data may be disclosed to the tax authorities, courts or law enforcement when required by law and, if you are a client, to the accounting firm that keeps the books, as a data processor and only for what is relevant.

9. Retention periods

  • Visit analytics: 30 days, after which it is deleted automatically. Daily totals, which identify no one, are kept for two years.
  • Enquiries that do not lead to a project: one year from the last message, in case you pick up the conversation again; after that they are deleted.
  • Clients: for as long as the relationship lasts and, afterwards, for the tax and commercial limitation periods, which reach six years for accounting records.
  • Hosting technical logs: those applied by Cloudflare in its service.

10. Your rights

You may exercise the rights the GDPR grants you at any time:

  • Access: find out what data about you is processed.
  • Rectification: correct any that is wrong.
  • Erasure: ask for it to be deleted when it is no longer needed.
  • Objection: object to processing based on legitimate interest, such as visit analytics.
  • Restriction: ask for it to be kept but not used while a complaint is resolved.
  • Portability: receive your data in a commonly used format.

To exercise them, write to info@novantrek.com stating which right you wish to exercise. If your identity needs to be verified, only what is strictly necessary will be requested. You will receive a reply within the one-month period set by the GDPR.

If you believe your data has not been handled properly, you can lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, calle Jorge Juan 6, 28001 Madrid; www.aepd.es).

11. Minors

Novantrek's services are aimed at companies, professionals and adult individuals, and the website is not intended for children under fourteen. If you notice that data from a minor has been collected, write to info@novantrek.com and it will be deleted.

12. Security

The website is always served over HTTPS, so traffic between your browser and the server is encrypted. The pages are static files. Visit analytics data is kept for 30 days (daily totals, two years) in a Cloudflare database that only the Novantrek team consults, with a username and password. Service keys are stored as hosting secrets and never reach the browser.

Emails and working documents are kept on devices with protected access, with reasonable measures against unauthorised access, loss or alteration.

Websites and applications that Novantrek develops for its clients are hosted on the same infrastructure. That data is processed on behalf of each client and is explained in the privacy policy of each website.

13. Changes to this policy

This policy is updated when the services, the providers or the regulations change, and always before switching on any tool that processes data in a different way. The version in force is the one published on this page, with its date at the top.

About this translation

This English text is a translation provided for guidance only. In case of doubt, the Spanish text prevails.