Privacy policy
This policy explains what personal data FenixL collects, why, for how long we keep it and what you can ask us to do with it.
Last updated: August 20, 2026
Contents
Short version: we do not run advertising trackers, we do not profile you and we never sell your data. We only collect what we need to answer you and to run the client portal.
1. Who is responsible
The data controller is FenixL, a web development and artificial intelligence studio operating fully online.
- Trading name: FenixL
- Legal name: [razón social pendiente]
- Tax ID: [identificación fiscal pendiente]
- Registered address: [domicilio pendiente]
- Email: contact@fenixl.com
For any question about this policy or about your data, write to us at the address above. We answer in English or Spanish.
2. What data we collect
a) Contact form and quote requests
When you send the form on the home page we collect your name, your email address, the type of project you selected, the message you write, the language of the page and the date and time. That information is emailed to our inbox so we can reply; it is not stored in a public database.
b) Client portal accounts
If you are a client and we open an account for you at /portal/, we store:
- Identification and contact details: name, email address, company and preferred language.
- Access credentials: your password is never stored as text — only a one-way hash — plus the temporary codes used for two-step verification by email.
- Project data: projects, milestones, tasks, support tickets and the messages exchanged in them.
- Files you upload as deliverables or references, together with their name, size and upload date.
- Billing data: invoices, amounts, concepts, due dates and payment status.
- Activity log of relevant actions inside your projects, and the date of your last sign-in.
c) Technical data
- Our hosting provider keeps standard server logs (IP address, browser, requested page, date) for security and diagnostics.
- To limit brute-force sign-in attempts we store a counter linked to an irreversible hash of your IP address. We cannot recover the original IP from it.
- The blog counts page views as an aggregate number per article. It is not linked to any person.
For cookies and browser storage, see our cookie policy.
3. Why we use it and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Reply to your enquiry and send you a quote | Contact form | Your consent, given when you tick the box before sending. |
| Deliver the contracted project and give you access to the portal | Account, projects, tasks, files, tickets | Performance of the contract between you and FenixL. |
| Issue and keep invoices | Billing data | Legal obligation (accounting and tax rules). |
| Keep accounts secure and prevent abuse | Session data, sign-in attempts, logs | Our legitimate interest in protecting the service and its users. |
| Remember your language choice | Browser storage | Strictly necessary for a feature you requested. |
We do not use your data for automated decision-making or profiling, and we do not send marketing emails unless you specifically ask us to.
4. How long we keep it
- Enquiries that do not become projects: up to 12 months, in case you come back to us.
- Client accounts and project data: for as long as the working relationship lasts, and afterwards while any legal claim remains possible.
- Invoices and accounting records: for the period required by the applicable tax law.
- Sign-in attempt counters: minutes — they are cleared once the lockout window expires.
- Server logs: according to our hosting provider’s retention period.
When you close your account we delete your personal data and the records associated with it, keeping only what the law requires us to keep.
5. Who else has access
We do not sell, rent or trade personal data. We share it only with the providers we need to run the service, and only to the extent required:
- Web hosting: stores the site, the database and the uploaded files.
- Email provider (Spacemail): delivers the messages from the contact form and the portal notifications.
- Public authorities: only when a valid legal request obliges us to.
The typefaces, styles and scripts on this site are served from our own servers. Loading a page does not send your IP address to any third-party font, analytics or advertising network.
The portfolio section links to our clients’ websites. Once you click through, the privacy policy of that site applies, not ours.
6. International transfers
FenixL works with clients worldwide and some of our providers process data outside your country of residence. When data from the European Economic Area is transferred outside it, we rely on the safeguards allowed by the GDPR — an adequacy decision or standard contractual clauses. You can ask us for details about the providers involved in your case.
7. How we protect it
- The whole site runs over HTTPS; traffic is encrypted in transit.
- Passwords are stored as irreversible hashes, never as readable text.
- The portal offers two-step verification by email.
- Sessions use cookies restricted to the site, not readable by scripts.
- Uploaded files are only served to their owner or to FenixL staff, after checking permissions.
- Repeated failed sign-ins temporarily lock the account.
No system is perfectly secure, but if a breach ever affected your data we would notify you and the relevant authority within the legal deadline.
8. Your rights
You can ask us at any time to:
- Access: get a copy of the personal data we hold about you.
- Rectification: correct anything inaccurate or incomplete.
- Erasure: delete your data when we no longer need it.
- Restriction: pause the processing while a dispute is resolved.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on our legitimate interest.
- Withdraw consent: at any time, without affecting what was lawful before.
Write to contact@fenixl.com from the address associated with your data. We reply within 30 days. Exercising these rights is free.
If you are not satisfied with our answer, you can lodge a complaint with the data protection authority of your country. In Spain that is the Agencia Española de Protección de Datos (aepd.es).
9. Minors
Our services are aimed at businesses and professionals. We do not knowingly collect data from minors. If you believe a minor has sent us personal data, contact us and we will delete it.
10. Changes to this policy
If we change how we handle personal data we will update this page and its revision date. When a change is significant and affects clients with an open account, we will also tell them by email.