Identity of the Data Controller
In compliance with the General Data Protection Regulation (GDPR) and applicable national legislation, users are informed that personal data collected through this website will be processed by:
Owner: Greytide Studio S.L.
Address: C/ Virgen de la Cabeza, Nº6, 2ºA, C.P. 23008, Jaén, Spain
Tax ID (NIF): B56361447
Email: greytidestudio@greytidestudio.com
The controller guarantees that personal data is processed in accordance with the principles of lawfulness, fairness, transparency, data minimisation, accuracy, and storage limitation.
Categories of Data Processed
The activity carried out on the website involves processing different categories of personal data depending on how the user interacts with the site:
- Identification data: email address
- Authentication data: access credentials stored in encrypted or pseudonymised form
- Billing data: address, country, and other data required for invoice issuance
- Transaction data: purchase history
- Browsing data: IP address, online identifiers, and usage behaviour
No special categories of personal data are processed.
Purposes of Processing
Personal data will be processed for the following clearly defined and legitimate purposes:
- Managing the creation and maintenance of user accounts
- Enabling the correct execution of the digital product purchase process
- Facilitating access to and download of acquired files (STL format)
- Managing the contractual relationship arising from the purchase
- Sending communications strictly linked to service operations (confirmations, incidents, support)
- Complying with legal obligations in fiscal, accounting, and administrative matters
- Handling incidents, claims, or support requests related to acquired products
- Sending commercial communications related to products, news, or promotions, provided the user has given explicit consent
- Verifying correct application of prices, taxes, currency, and commercial conditions based on geographic location, and preventing fraudulent use
- Maintaining electronic records of acceptance of legal conditions, consents, and transactions for evidential and compliance purposes
Data will not be used for purposes incompatible with those described above.
Legal Basis for Processing
| Legal Basis | Application |
|---|---|
| Contract performance | User account management and purchase of digital products |
| Legal obligation | Tax, accounting, and fraud prevention compliance |
| Consent | Non-essential cookies and future commercial communications |
| Legitimate interest | Platform security, fraud detection, pricing and tax verification |
Recipients & Data Processors
Data may be processed by service providers acting as data processors, including:
- Stripe — payment processing platform
- Hosting and cloud service providers
- Analytics tools such as Google Analytics
All processors act under contract in compliance with Article 28 of the GDPR. Users are advised to consult the payment provider's privacy policy for detailed information on the processing of their payment data.
International Data Transfers
Some providers may be located in the United States or other countries outside the European Economic Area, which may involve international transfers of personal data. In such cases, the controller will adopt the appropriate safeguards required by applicable regulations, including, where applicable, standard contractual clauses approved by the European Commission.
Data Retention Periods
Data will be retained for the time strictly necessary to fulfil the purpose for which it was collected:
- User data: while the account remains active
- Billing data: for the legally required periods
- Browsing data: as set out in the Cookie Policy
Technical records, access logs, consent evidence, and data related to platform transactions may be retained for as long as necessary to ensure service security, address potential legal liabilities, and demonstrate compliance with contractual or regulatory obligations.
Data may be duly blocked during the periods necessary to address potential legal or contractual liabilities.
User Rights
Users may at any time exercise their rights of access, rectification, erasure, objection, restriction of processing, and/or data portability by sending a request to greytidestudio@greytidestudio.com, accompanied by a copy of their identity document.
Users have the right to withdraw their consent at any time, without affecting the lawfulness of prior processing.
Users also have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if they consider that the processing of their data does not comply with applicable regulations.
Security Measures
The controller has implemented the necessary technical and organisational measures to ensure the security and integrity of personal data, preventing loss, alteration, or unauthorised access. These measures may include authentication mechanisms, encryption, access controls, activity monitoring, and measures to prevent unauthorised access or fraudulent use of the platform.
Automated Decision-Making
No automated decisions with significant legal effects will be made on users without human intervention, except where required by law or where necessary for fraud prevention, platform security, or execution of the contractual relationship, in accordance with applicable regulations.
Use by Minors
This website is not directed at minors. Use by persons under the age of 18 is strictly prohibited.