Privacy Policy
What personal data we collect, why we need it, and how you can access, export, or delete it — explained in plain language.
LOADFRONT PRIVACY POLICY
Here’s what data we collect, why, and how you can see it, export it, or delete it whenever you want. We try to keep as little as possible, and to leave the control in your hands.
WHO IS RESPONSIBLE FOR YOUR DATA?
Data controller: LoadFront, S.L. (Tax ID: B13556931)
Data Protection Officer: M Carmen Aguilera (lopd@atico34.com) - Grupo Ático34, S.L.
Contact: privacy@loadfront.com
For full corporate information, see our Legal Notice.
We process your data in accordance with Regulation (EU) 2016/679 (GDPR) and Spain’s Organic Law 3/2018 (LOPDGDD).
WHAT DATA DO WE COLLECT AND WHY?
Data we collect
When you access our website (even without registering):
- IP address (stored in full for 30 days, then only country of origin)
- Browser, operating system, and device information
- Pages visited on our site
When you create an account:
- Email address
- Password (encrypted with a strong algorithm)
When you log in:
- IP address (stored for one year to show your recent sessions and their origin)
When you sign up for paid services (for legal billing purposes):
- Full name
- Tax ID/VAT number as applicable
- Company name (if applicable)
- Postal address
- Payment data (processed directly by our banking providers, never stored by us)
When you register domains (according to the specific TLD’s requirements):
- Contact details required by the domain extension you choose
- Specific requirements and public visibility vary by TLD
When you use our services:
- Access logs and usage of our APIs
- Minimal technical information for threat detection
- Files and content you upload to our services
Communications with you:
- Emails you send us
- Messages through our support ticket system
What do we use your data for?
1. Providing the service
Legal basis: Performance of the contract we have with you
- Creating and managing your account
- Processing payments and billing
- Domain registration and management
- Providing technical support
- Delivering the services you’ve signed up for
2. Commercial communications
Legal basis: Your explicit, granular consent
- Newsletters with relevant content (managed from your panel, or the unsubscribe link in each email)
- Related product offers (optional)
- Communications about security and maintenance (not optional, for security reasons)
You have granular control over each type of communication from your user panel.
Before you have an account:
- If you sign up for the waitlist or “how we build loadfront”, you can unsubscribe any time using the link in each email
- No account or panel needed to exercise this right
- They may include advertising about new services and pricing (article 21 of Spain’s LSSI-CE e-commerce law), only if you gave explicit consent when subscribing
3. Technical operation and security
Legal basis: Our legitimate interest in ensuring the operation and security of the service
- Basic website operation (automatic access logging)
- System security (detection and blocking of unauthorized access)
- Fraud prevention
- Traffic analysis (aggregated, anonymous data)
- Technical improvement of the service
- Protection of other users
4. Optional technical analysis
Legal basis: Your specific consent (you can withdraw it at any time)
- Aggregated browser and country statistics (anonymized data)
- Performance analysis for technical optimization
- Usage studies for new features
You can disable this analysis from your panel without affecting your service.
5. Legal and regulatory compliance
Legal basis: Legal obligation
- Retention of invoices and accounting records (6 years per the Spanish Commercial Code)
- Compliance with tax obligations (4 years per the Spanish General Tax Law)
- Compliance with domain name regulations (according to the specific TLD)
- Responding to requests from competent authorities
HOW LONG DO WE KEEP YOUR DATA?
We apply minimization principles and keep your data for the shortest time possible:
- Billing data: 6 years from issuance (Commercial Code Art. 30)
- Service contracts: 6 years from signup (Commercial Code Art. 30)
- Tax data: 4 years from the end of the filing period (General Tax Law Art. 66)
- Marketing data: Until you withdraw your consent (immediate deletion)
- Access logs: 6 months from generation
- Full IP addresses: 30 days for normal use, then only country of origin
- Security logs: 12 months with full IP; then aggregated, anonymized data
- Support system: Your history remains visible indefinitely; we delete internal data after 12 months
- Emails and communications: 12 months from receipt (unless you request earlier deletion)
- Content you upload: Immediate removal from active systems; removal from backups within a maximum of 90 days, or 12 months if the data was held in an archival copy (see below)
Anonymization: When we delete personal data, we apply irreversible anonymization techniques or complete destruction.
Backups: For technical security reasons, deleted data may remain in encrypted copies for a while. There are two kinds:
- Operational copies: the day-to-day ones, what we would use to restore the service after a failure. Rotated within a maximum of 90 days.
- Archival copies: long-term retention we only keep when a legal obligation requires it or a security investigation is open. Maximum 12 months.
Throughout that time the data stays encrypted and is not used for any processing other than technical recovery.
WHO DO WE SHARE YOUR DATA WITH?
As a Spanish company, we work primarily with national and European providers:
Service providers
Payment processing
- Ruralvia (Spain): Bank payment management - Privacy Policy
- Revolut Spain: Card payments - Privacy Policy
These providers process payment data directly; we don’t share any additional personal information with them.
Technical infrastructure
- Our own servers: Proprietary infrastructure hosted in secure data centers in Spain (GlobalSwitch Madrid)
- Connectivity providers: Only technical routing and traffic data, with no personal content
Domain registration
- Hosting Concepts B.V. (Openprovider, Netherlands): Domain registration and management - Privacy Policy
The specific data required varies depending on the domain you register. Check the specific terms of the domain registration service for each TLD.
Communications
- Acumbamail (Spain): Sending transactional and optional commercial communications - Privacy Policy
Legal and compliance services
- Grupo Ático34, S.L. (Spain): Our Data Protection Officer - Privacy Policy
Advisory and management services
- Suárez-Bárcena Asesores (Spain): Accounting, tax, and administrative advisory services - Privacy Policy
Guarantees: All of these providers:
- Are Spanish companies or have a legal presence in Spain/the EU
- Strictly comply with GDPR and Spanish regulations
- Have signed data processing agreements with us
Authorities
Only when legally required:
- Specific judicial requirements
- Police investigations with a court order
- Tax obligations (accounting data only)
Transparency: We will notify you of any legal request unless expressly prohibited by law.
DATA TRANSFERS
Commitment to European localization
All your information stays within the European Economic Area:
Primary storage: All your data is stored on our servers located in Spain.
European providers: Some specific services (such as domain registration) require providers in other EU countries, always maintaining the same level of GDPR protection.
Limited exception: For certain specific services you deploy outside the EEA, our providers may need to transfer minimal data outside the EU in accordance with specific regulations. In these cases:
- We will specifically inform you during setup
- Only the minimum required data is transferred
- Appropriate protection safeguards are maintained
Localization by design
We clearly distinguish between:
Data we control
Your account, billing, and management data stays in Spanish territory:
- Your account and profile information
- Billing and payment data
- Access logs to our systems
- Support and communication information
- Service management metadata
Content you control
The content you upload to our services is stored on our own hardware at the GlobalSwitch Madrid, Spain datacenter, our only location for now:
- All your content lives there, alongside the rest of our infrastructure
- We have no access to the content of your services
- Once we open more datacenters in the EU, you’ll be able to choose where your infrastructure lives
SHARED RESPONSIBILITY MODEL
As an infrastructure (IaaS) provider, we share responsibilities with you:
What are we responsible for?
Security OF the infrastructure:
- Physical protection of data centers
- Network and server security
- System and hardware updates
- Encryption of data in transit between our systems
- Compliance with regulations for the base infrastructure
Your account data that we control:
- Your profile and billing information
- Access logs to our management systems
- Communications with you
- Metadata necessary for the service to function
What are you responsible for?
Security IN the infrastructure:
- Security configuration of your virtual machines
- Managing users and passwords on your systems
- Operating system updates on your virtual machines
- Encryption of data within your applications
- Firewall and virtual network configuration
Your content and applications:
- All data you store on your services
- Applications and software you install
- Backup configuration for your content
- Regulatory compliance for your specific data
- Managing access for your users to your systems
This separation means we guarantee secure, compliant infrastructure, you decide what data to store and how to protect it, and we both work together for maximum security.
DATA DELETION AND BACKUPS
How do we delete your data?
This is different from cancelling a service: when you cancel, under our Terms and Conditions you have a 30-day grace period to export your data before permanent deletion. If instead you exercise your right to erasure here, there’s no grace period: request an export first if you need one, because once erasure is requested, we delete everything.
When you request data deletion or exercise your right to erasure:
Immediate deletion
- Active systems: Data is immediately deleted from our primary databases
- Blocked access: Once deleted, it can no longer be accessed or used
Complete deletion
- Backups: Data may remain in encrypted backups during our backup cycles
- Timeframes:
- Operational copies (the day-to-day ones, used to restore after a failure): maximum 90 days
- Archival copies (only when a legal obligation requires it or a security investigation is open): maximum 12 months
- Protection: During this time, backups are fully encrypted and protected
Why do these timeframes exist?
Backups are essential for:
- Service continuity
- Protection of other users
- System integrity
Important: Data in backups is not processed or used except for technical recovery in the event of serious incidents.
YOUR RIGHTS
You have full control over your personal data:
Right of access
You can download a complete report of all your data from your user panel or request it from us.
Your support history: Always visible from your panel, regardless of our internal retention periods.
Right of rectification
You can correct your data directly from your panel, or contact us for data you can’t edit yourself.
Right of erasure (“right to be forgotten”)
- Deletion from active systems: Immediate, from your panel
- Complete deletion: May take up to 90 days (12 months if the data is held in an archival copy)
- Data subject to legal obligations: Deleted once the mandatory retention period ends
- Data in aggregated statistics: Irreversibly anonymized
Right to restriction
You can temporarily suspend the processing of your data while we resolve a dispute.
Right to portability
You can download your data in multiple standard formats:
- Account data: structured format
- Uploaded content: Original files + metadata
- Configurations: standard format depending on the type
- Service history: standard format
- Connection logs: standard format
You can choose the most convenient format from your panel.
Right to object
You can object to processing for:
- Direct marketing: Always (immediate effect)
- Optional analytics: Always (without affecting the service)
- Security measures: Only if there’s no risk to other users or systems
Important: You cannot object to processing that is necessary for providing the contracted service or complying with legal obligations.
Right to withdraw consent
Granular controls from your panel:
- Newsletters (individually managed)
- Commercial offers
- Optional usage analytics
- Non-essential cookies
How to exercise your rights?
- User panel: For most operations (immediate)
- Email: privacy@loadfront.com (response within 48 to 72 business hours)
- Data Protection Officer: lopd@atico34.com (for specialized inquiries)
Identity verification: We verify your identity through account authentication or an official document.
Response time: A maximum of 30 calendar days from receipt of your request. In complex cases, we may extend this by 60 more days (90 total), informing you of the reason.
Completely free: Exercising these rights is free of charge. We may only charge a reasonable fee if your requests are manifestly unfounded, excessive, or repetitive.
Complaints: You can file a complaint with the Spanish Data Protection Agency (www.aepd.es) if you’re not satisfied.
AUTOMATED DECISIONS
We use some automated systems, but always with human oversight for important decisions:
Automated security systems
- IP blocking: Based on attack patterns (you can request a manual review)
- Spam detection: On forms (manual review available)
- Usage limits: To prevent abuse (escalated to human review when necessary)
Operational systems
- Service suggestions: Based on your usage (you can disable this from your panel)
- Payment fraud detection: For security purposes (with manual review and escalation)
Guarantee: No significant decision affecting your service (permanent suspension, cancellation, dispute resolution) is made without human review. You can always request that a person review any automated decision.
SECURITY MEASURES
Technical measures implemented
- Encryption for data at rest and in transit
- Mandatory two-factor authentication for employees
- Firewalls, intrusion detection systems, network segmentation
- 24x7 monitoring with automated alerts
- Encrypted backups
Certifications and standards
We work following industry best practices:
- GDPR/LOPDGDD: Full compliance with European and Spanish regulations
- Security standards: Measures based on recognized frameworks
- IaaS best practices: Industry standards for cloud infrastructure providers
- Internal audits: Periodic GDPR compliance reviews
You can request detailed information about our security measures by contacting our team.
Additional protection guarantees
- Professional civil liability insurance: €300,000 in coverage specific to cloud services (Hiscox)
- Regular audits: Periodic GDPR compliance evaluations. Third-party security audits are planned, but not yet in place.
Organizational measures
- Staff: Annual training, confidentiality agreements
- Access: Principle of least privilege, audited logs
- Incidents: A documented and tested response plan
Breach notification
- To authorities: Within 72 hours maximum
- To you: Within 72 hours if there’s a high risk to your rights
- Transparency: An annual public report on incidents (aggregated data)
COOKIES
We only use essential technical cookies for the basic operation of our website. We don’t use third-party cookies, advertising tracking, or share browsing information with other companies.
For complete information about our cookies, see our Cookie Policy.
MINORS
Under Spanish legislation (LOPDGDD), our services are available to people aged 14 or older.
For minors under 14: Verifiable parental consent is required. Contact privacy@loadfront.com for the verification process.
For minors aged 14-18: They may consent independently, but we recommend parental supervision, especially for paid services.
Verification: If we detect users under 14 without parental consent, we temporarily suspend the account until the corresponding authorization is obtained.
UPDATES TO THIS POLICY
Transparent change process
When we make changes:
Minor changes
- Typo or formatting fixes
- Link updates
- Clarifications that don’t change the meaning
- New providers within the EEA
We bump the minor version (1.0 to 1.1, for instance) and the effective date, with an update note on this page.
Significant changes
- New data processing activities
- New providers outside the EEA
- The option to reject changes (you might need to cancel incompatible services)
We bump the major version (1.3 to 2.0, for instance) and notify you by email and in your control panel 30 days in advance.
Version history
We’ll publish a public record of significant changes on our corporate blog once it’s live.
LIABILITY LIMITATION IN DATA PROTECTION
Without prejudice to the limitations established in our Terms and Conditions, and with regard to the processing of personal data:
Specific limitations
To the maximum extent permitted by Spanish law:
Damages arising from security breaches: Our maximum liability is limited to the total amount you paid us in the 12 months prior to the incident.
Security-related interruptions: We are not liable for temporary interruptions necessary to implement security measures or respond to incidents.
User content: We are not liable for content you upload to our services, nor for the consequences of any personal data processing you carry out using our infrastructure.
Force majeure
We will not be liable for breaches arising from:
- Cyberattacks directed by third parties
- Failures of essential providers (connectivity, payments)
- Requirements from authorities with retroactive effects
- Natural disasters or events beyond our reasonable control
Jurisdiction
For resolving disputes related to this policy:
- If you're a consumer: The courts of your domicile will have jurisdiction, under consumer protection regulations.
- If you're a business or professional: The courts of Ciudad Real will have jurisdiction.
- In both cases: With express waiver of any other jurisdiction that might otherwise apply.
IMPACT ASSESSMENTS
We carry out data protection impact assessments when:
- We introduce new high-risk processing activities
- We implement new processing technologies
- We significantly change our services
- Specific regulations require it
If you’re a business customer and need information about our assessments for your own DPIAs, you can request it via privacy@loadfront.com.
CONTACT AND TRANSPARENCY
Contact channels
- Privacy inquiries: privacy@loadfront.com
- Exercising your rights: privacy@loadfront.com (priority response in 48-72 business hours)
- Data Protection Officer: lopd@atico34.com
For full corporate information, see our Legal Notice.
Transparency reports
Once our corporate blog is live, we’ll publish there annually:
- Aggregated statistics on the exercise of rights
- Number of requests from authorities (aggregated data)
- Security incidents (with no personal data)
- Improvements implemented in data protection
We design our systems with privacy by design and by default.
Effective date
© 2026 LoadFront, S.L. All rights reserved.
This document is permanently available at https://www.loadfront.com/legal/privacy-policy/