Privacy Policy — Greytide Studio
Legal Documentation

Privacy Policy

Last reviewed: 2026  ·  Greytide Studio S.L.

01

Identity of the Data Controller

In compliance with the General Data Protection Regulation (GDPR) and applicable national legislation, users are informed that personal data collected through this website will be processed by:

Owner: Greytide Studio S.L.

Address: C/ Virgen de la Cabeza, Nº6, 2ºA, C.P. 23008, Jaén, Spain

Tax ID (NIF): B56361447

Email: greytidestudio@greytidestudio.com

The controller guarantees that personal data is processed in accordance with the principles of lawfulness, fairness, transparency, data minimisation, accuracy, and storage limitation.

02

Categories of Data Processed

The activity carried out on the website involves processing different categories of personal data depending on how the user interacts with the site:

  • Identification data: email address
  • Authentication data: access credentials stored in encrypted or pseudonymised form
  • Billing data: address, country, and other data required for invoice issuance
  • Transaction data: purchase history
  • Browsing data: IP address, online identifiers, and usage behaviour

No special categories of personal data are processed.

03

Purposes of Processing

Personal data will be processed for the following clearly defined and legitimate purposes:

  • Managing the creation and maintenance of user accounts
  • Enabling the correct execution of the digital product purchase process
  • Facilitating access to and download of acquired files (STL format)
  • Managing the contractual relationship arising from the purchase
  • Sending communications strictly linked to service operations (confirmations, incidents, support)
  • Complying with legal obligations in fiscal, accounting, and administrative matters
  • Handling incidents, claims, or support requests related to acquired products
  • Sending commercial communications related to products, news, or promotions, provided the user has given explicit consent
  • Verifying correct application of prices, taxes, currency, and commercial conditions based on geographic location, and preventing fraudulent use
  • Maintaining electronic records of acceptance of legal conditions, consents, and transactions for evidential and compliance purposes

Data will not be used for purposes incompatible with those described above.

04

Legal Basis for Processing

Legal BasisApplication
Contract performanceUser account management and purchase of digital products
Legal obligationTax, accounting, and fraud prevention compliance
ConsentNon-essential cookies and future commercial communications
Legitimate interestPlatform security, fraud detection, pricing and tax verification
05

Recipients & Data Processors

Data may be processed by service providers acting as data processors, including:

  • Stripe — payment processing platform
  • Hosting and cloud service providers
  • Analytics tools such as Google Analytics

All processors act under contract in compliance with Article 28 of the GDPR. Users are advised to consult the payment provider's privacy policy for detailed information on the processing of their payment data.

06

International Data Transfers

Some providers may be located in the United States or other countries outside the European Economic Area, which may involve international transfers of personal data. In such cases, the controller will adopt the appropriate safeguards required by applicable regulations, including, where applicable, standard contractual clauses approved by the European Commission.

07

Data Retention Periods

Data will be retained for the time strictly necessary to fulfil the purpose for which it was collected:

  • User data: while the account remains active
  • Billing data: for the legally required periods
  • Browsing data: as set out in the Cookie Policy

Technical records, access logs, consent evidence, and data related to platform transactions may be retained for as long as necessary to ensure service security, address potential legal liabilities, and demonstrate compliance with contractual or regulatory obligations.

Data may be duly blocked during the periods necessary to address potential legal or contractual liabilities.

08

User Rights

Users may at any time exercise their rights of access, rectification, erasure, objection, restriction of processing, and/or data portability by sending a request to greytidestudio@greytidestudio.com, accompanied by a copy of their identity document.

Users have the right to withdraw their consent at any time, without affecting the lawfulness of prior processing.

Users also have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if they consider that the processing of their data does not comply with applicable regulations.

09

Security Measures

The controller has implemented the necessary technical and organisational measures to ensure the security and integrity of personal data, preventing loss, alteration, or unauthorised access. These measures may include authentication mechanisms, encryption, access controls, activity monitoring, and measures to prevent unauthorised access or fraudulent use of the platform.

10

Automated Decision-Making

No automated decisions with significant legal effects will be made on users without human intervention, except where required by law or where necessary for fraud prevention, platform security, or execution of the contractual relationship, in accordance with applicable regulations.

11

Use by Minors

This website is not directed at minors. Use by persons under the age of 18 is strictly prohibited.

We use our own and third-party cookies to improve your browsing experience and show you personalized content. You can accept all, reject all, or manage your preferences. Cookie policy