Privacy Policy
Effective Date:
Last Updated:
I. Introduction
This Privacy Policy (the “Policy”) describes the practices of Alex de Borba (hereinafter “I,” “me,” “my,” or the “Owner”) regarding the collection, use, and disclosure of information in connection with your use of the website located at https://alexdeborba.com and any associated content, features, and services offered (collectively, the “Services”). As the sole owner and operator of these Services, I am committed to protecting your privacy and processing your personal information responsibly, transparently, and in compliance with applicable data protection laws.
The structure of this document is intended to provide the clarity and authority found in the legal notices of major publications, ensuring a professional and comprehensive framework. However, the ultimate goal is transparency. Unlike large, impersonal corporations that may have policies perceived as difficult to navigate, this Policy is designed to be a clear and direct communication between me and you, the user. Its purpose is to build trust by explaining my data practices in an accessible manner, recognizing that a strong, direct relationship with users is paramount for an individual service provider.
By accessing or using the Services, you acknowledge that you have read, understood, and agree to the collection, use, and disclosure of your information as described in this Policy. If you do not agree with the terms of this Policy, you should not use the Services.
For the purposes of this Policy, “Personal Information” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. This does not include information that has been aggregated or de-identified so that it can no longer be used to identify a specific person.
II. The Information I Collect
To provide and improve the Services, I collect information in several ways. The specific information I collect depends on how you interact with the Services. The collection practices are detailed below and summarized in the table that follows.
A. Information You Voluntarily Provide
When you interact with the Services, you may choose to provide me with Personal Information directly. The reasons for requesting this information will be made clear to you at the point of collection. This includes:
- Contact Identifiers: I collect your name, email address, phone number, and any other contact details you provide when you fill out a contact form, subscribe to a newsletter, request a consultation, or otherwise communicate with me directly.
- Commercial and Financial Information: If you purchase services from me, I will collect information necessary to process your transaction. This may include your billing address and payment details. Please note that most financial transactions are processed by secure third-party payment processors (e.g., Stripe). In such cases, I do not store your full credit or debit card number but may receive information such as your name, billing address, and transaction confirmation details.
- Content of Communications: I collect the content of any messages, inquiries, feedback, or other information you send to me through contact forms, email, or other communication channels. I advise you not to provide any sensitive personal information that is not explicitly requested.
B. Information Collected Automatically
As you navigate and interact with the Services, I may use automatic data collection technologies to gather certain information about your device, browsing actions, and patterns. This information helps me improve the Services and deliver a more personalized and secure experience. This includes:
- Usage and Device Data: I automatically collect technical information sent by your browser or device when you access the Services. This includes your Internet Protocol (IP) address, browser type and version, device identifiers, operating system, the pages you visit on my site, the time and date of your visit, the time spent on those pages, and other standard web log data.
- Information from Cookies and Tracking Technologies: I use cookies, web beacons (also known as pixels), and similar tracking technologies to collect information about your interaction with the Services. These technologies help enhance your experience, analyze site traffic, and secure the website. A detailed explanation of these technologies is provided in Section IV of this Policy.
C. Information from Third-Party Sources
I may receive Personal Information about you from third-party sources. For example, if you interact with my social media pages or if I use third-party analytics tools, I may receive information from those services. This may include aggregated data or specific information if you have configured your privacy settings on those platforms to permit it.
D. Summary of Personal Information Processing Activities
In accordance with legal requirements such as the California Consumer Privacy Act (CCPA), the following table provides a summary of the categories of Personal Information I may have collected, the sources from which it was collected, the purposes for its collection, and the categories of third parties with whom it may have been shared over the past 12 months.
Category | Examples | Source(s) of Collection | Business or Commercial Purpose(s) for Collection | Categories of Third Parties with Whom Information is Shared or Disclosed |
---|---|---|---|---|
Identifiers | Name, Email Address, Phone Number, IP Address, Online Identifiers. | Directly from you via contact forms, account registration, or other communications; automatically from your device via server logs and analytics tools. | To respond to your inquiries; provide, manage, and secure the Services; process transactions; communicate with you; analyze website usage. | Technology Service Providers (e.g., hosting, security); Analytics Providers; Payment Processors. |
Personal Information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) | Name, address, telephone number, financial information. | Directly from you when you purchase a service or communicate with me. | To fulfill service requests; process payments; communicate with you; maintain records as required by law. | Payment Processors; Financial Institutions. |
Commercial Information | Records of services purchased, obtained, or considered; payment and billing information. | Directly from you during a transaction; from my payment processing partners. | To process payments; fulfill service orders; provide customer support; maintain financial and transaction records. | Payment Processors; Financial Institutions. |
Internet or other similar network activity | Browsing history, search history, information regarding your interaction with the website, applications, or advertisements. | Automatically from your device via cookies and other tracking technologies. | To improve and personalize the Services; monitor and analyze trends and usage; ensure the security and integrity of the Services. | Analytics Providers; Technology Service Providers. |
Geolocation Data | Approximate location derived from your IP address. | Automatically from your device. | For security purposes (e.g., fraud detection); to analyze website traffic patterns by region. | Analytics Providers; Security Service Providers. |
Inferences drawn from other personal information | A profile reflecting your preferences, characteristics, or interests based on your website activity. | Derived from your Internet or network activity. | To personalize your experience and the content or services offered to you. | Analytics Providers (if applicable). Export to Sheets |
III. How and Why I Use Your Information (Legal Basis for Processing)
I collect and use your Personal Information for specific, legitimate purposes. Under data protection laws such as the General Data Protection Regulation (GDPR), I must have a valid legal basis for each processing activity. The purposes for which I use your information and the corresponding legal bases are as follows:
-
To Provide and Manage the Services: I use your information to operate the website, deliver the services you have requested, process your transactions, and manage your account or relationship with me.
- Legal Basis (GDPR): The processing is necessary for the performance of a contract with you.
-
To Communicate with You: I use your contact information to respond to your inquiries, provide customer support, and send you important transactional or administrative messages, such as payment confirmations, service updates, or security alerts.
- Legal Basis (GDPR): The processing is necessary for the performance of a contract with you and serves my legitimate interests in providing responsive and effective customer service.
-
For Marketing and Promotional Purposes: With your permission, I may use your contact information to send you marketing communications about my services, content, or special offers that I believe may be of interest to you. You can opt out of these communications at any time.
- Legal Basis (GDPR): Your consent.
-
For Analytics and Improvement: I analyze information about how you use the Services to understand user behavior, monitor trends, and improve the website’s functionality, content, and overall user experience.
- Legal Basis (GDPR): My legitimate interests in maintaining and improving my Services and developing new offerings.
-
For Security and Fraud Prevention: I use information to monitor for and prevent security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, and enforce my terms and policies.
- Legal Basis (GDPR): My legitimate interests in protecting my business, property, and users, and in some cases, to comply with a legal obligation.
-
To Comply with Legal Obligations: I may process your information to comply with applicable laws, regulations, court orders, subpoenas, or other legal processes, or in response to lawful requests by public authorities.
- Legal Basis (GDPR): The processing is necessary for compliance with a legal obligation.
IV. Cookies and Other Tracking Technologies
The Services use cookies and similar technologies to function effectively, enhance your experience, and gather information about how the website is used.
-
What Are These Technologies?
- Cookies: Small text files placed on your device’s browser when you visit a website. They store information about your preferences and activity. Cookies can be “session” cookies (which expire when you close your browser) or “persistent” cookies (which remain on your device for a set period or until you delete them).
- Web Beacons (Pixels): Tiny electronic images embedded in a webpage or email. They can be used to track your interactions, such as whether you have opened an email or clicked on a link.
- Log Files: Standard files that record events that occur on the website, collecting data such as your IP address, browser type, and timestamps.
-
How I Use These Technologies:
- Strictly Necessary: These are essential for the website to function correctly and securely. They are used for tasks like managing your session and protecting against security threats. These cookies do not require your consent.
- Performance and Analytics: These technologies help me understand how visitors interact with the Services by collecting and reporting information anonymously. This allows me to analyze traffic, identify popular content, and improve the website. For example, I use Google Analytics for this purpose.
- Functionality: These are used to remember choices you have made (such as language preferences) and provide enhanced, more personal features.
- Targeting or Advertising: These cookies may be set through my site by advertising partners. They may be used by those companies to build a profile of your interests and show you relevant advertisements on other sites.
-
Specific Third-Party Services:
- Google Analytics: I use Google Analytics to help analyze website traffic and user behavior. Google Analytics uses cookies to collect this data. For more information on how Google uses data when you use its partners’ sites or apps, visit Google’s Privacy & Terms page. You can opt out of being tracked by Google Analytics across all websites by installing the Google Analytics Opt-out Browser Add-on.
- Embedded Content (e.g., YouTube, Vimeo): Pages on this site may include embedded content, such as videos. Embedded content from other websites behaves in the exact same way as if you have visited the other website. These external sites may collect data about you, use their own cookies, and embed additional third-party tracking.
- Your Choices and How to Opt-Out: You have control over the use of cookies. Most web browsers allow you to manage your cookie preferences through their settings. You can set your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, some parts of the Services may not function properly. Additionally, where applicable, you can manage your preferences through a cookie consent banner provided on the website.
V. Disclosure of Your Information
I do not sell your Personal Information for monetary consideration. I only share your information with third parties in the limited circumstances described below. As a sole proprietor, I do not have “affiliates” or a “corporate family” with which to share data; my disclosures are limited to the necessary operational partnerships that allow me to provide the Services to you.
- Service Providers: I may share your information with third-party vendors, consultants, and other service providers who perform services on my behalf. These may include providers of website hosting, payment processing, data analysis, email delivery, and other technology services. I enter into contracts with these service providers that require them to keep your information confidential and use it only for the purpose of providing their services to me.
- Legal Requirements and Safety: I may disclose your information if I believe in good faith that it is necessary to:
- (a) comply with a legal obligation, subpoena, court order, or other lawful request by public authorities;
- (b) protect and defend my rights, property, or safety;
- (c) prevent or investigate possible wrongdoing or fraud in connection with the Services; or
- (d) protect the personal safety of users of the Services or the public.
- Business Transfer: In the event that I sell, transfer, or merge all or a portion of my business or assets (which is unlikely as a sole proprietorship but legally required to disclose), your Personal Information may be among the assets transferred. I would provide you with notice before your Personal Information is transferred and becomes subject to a different privacy policy.
- With Your Consent: I may disclose your Personal Information for any other purpose with your explicit consent or at your direction.
VI. Data Security and Retention
Data Security
I am committed to protecting your Personal Information. I implement and maintain reasonable administrative, technical, and physical security measures designed to protect the information I collect from loss, theft, misuse, and unauthorized access, disclosure, alteration, and destruction. These measures include, where appropriate, data encryption and access controls. However, please be aware that no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, I cannot guarantee its absolute security.
Data Retention
I will retain your Personal Information only for as long as is necessary to fulfill the purposes for which it was collected, as outlined in this Privacy Policy. The criteria used to determine my retention periods include: the length of time I have an ongoing relationship with you and provide Services to you; whether there is a legal obligation to which I am subject (for example, certain laws require me to keep records of your transactions for a set period); and whether retention is advisable in light of my legal position (such as in regard to applicable statutes of limitations, litigation, or regulatory investigations). When your Personal Information is no longer needed for these purposes, I will take reasonable steps to securely delete or anonymize it. For example, content you delete may be scheduled for permanent deletion from my systems within 30 days, unless I am legally required to retain it.
VII. Your Privacy Rights and Choices
You have certain rights and choices regarding your Personal Information. The rights available to you depend on your location. I am committed to facilitating the exercise of these rights regardless of where you live.
A. How to Exercise Your Rights
To exercise any of the rights described below, please submit a verifiable request to me by emailing privacy@alexdeborba.com. I will respond to your request within the time frames required by applicable law. I may need to verify your identity before processing your request, which may require you to provide additional information.
B. Your Rights as a Resident of the European Economic Area (EEA), United Kingdom (U.K.), or Switzerland
If you are a resident of the EEA, United Kingdom, or Switzerland, you have the following rights under the GDPR:
- The Right of Access: You have the right to request a copy of the Personal Information I hold about you.
- The Right to Rectification: You have the right to request that I correct any inaccurate or incomplete Personal Information.
- The Right to Erasure (The “Right to be Forgotten”): You have the right to request the deletion of your Personal Information under certain conditions.
- The Right to Restrict Processing: You have the right to request that I restrict the processing of your Personal Information under certain conditions.
- The Right to Data Portability: You have the right to receive the Personal Information you have provided to me in a structured, commonly used, and machine-readable format and to transmit it to another controller.
- The Right to Object: You have the right to object to the processing of your Personal Information where it is based on my legitimate interests.
- Rights in Relation to Automated Decision-Making: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects on you.
You also have the right to lodge a complaint with a data protection authority in your jurisdiction.
C. Your Rights as a Resident of California
If you are a resident of California, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
- The Right to Know: You have the right to request that I disclose what Personal Information I collect, use, disclose, and sell or share.
- The Right to Delete: You have the right to request the deletion of your Personal Information that I have collected from you, subject to certain exceptions.
- The Right to Correct: You have the right to request that I correct inaccurate Personal Information that I maintain about you.
- The Right to Opt-Out of Sale or Sharing: You have the right to direct me not to “sell” or “share” your Personal Information. I do not sell your Personal Information for money. However, the use of certain third-party analytics or advertising cookies may be considered a “sale” or “sharing” under California law. You may opt out of this activity by managing your cookie preferences through my consent management tool (if available) or by enabling a Global Privacy Control (GPC) signal on your browser, which I will honor as a valid request to opt out.
- The Right to Limit Use and Disclosure of Sensitive Personal Information: You have the right to direct me to limit my use of your sensitive personal information to that which is necessary to perform the services or provide the goods reasonably expected by an average consumer.
- The Right to Non-Discrimination: You have the right not to be discriminated against for exercising any of your CCPA rights. I will not deny you services, charge you different prices, or provide you a different level or quality of services for exercising your rights.
VIII. International Data Transfers
The Services are hosted and operated in the United States. If you are accessing the Services from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States, where my servers are located and my central database is operated. Data protection laws in the U.S. may be different from those in your country of residence.
If you are a resident of the EEA, U.K., or Switzerland, I will take appropriate safeguards to protect your Personal Information when it is transferred outside of these regions. This includes relying on legal mechanisms such as the European Commission’s Standard Contractual Clauses (SCCs) with my service providers to ensure that your data receives an adequate level of protection.
IX. Children’s Privacy
The Services are not intended for or directed at individuals under the age of 16. I do not knowingly collect Personal Information from children under 16. If I become aware that I have inadvertently collected Personal Information from a child under the age of 16, I will take steps to delete such information from my files as soon as possible.
X. Links to Other Websites
The Services may contain links to other websites that are not operated by me. If you click on a third-party link, you will be directed to that third party’s site. I have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services. I strongly advise you to review the privacy policy of every site you visit.
XI. Changes to This Privacy Policy
I may update this Privacy Policy from time to time to reflect changes in my practices, technology, legal requirements, or other factors. When I make changes, I will update the “Last Updated” date at the top of this Policy. If I make material changes, I will provide you with more prominent notice, such as by posting a notice on the website or sending you an email. I encourage you to review this Policy periodically to stay informed about how I am protecting your information.
XII. How to Contact Me
If you have any questions, comments, or concerns about this Privacy Policy or my data practices, or if you wish to exercise your privacy rights, please do not hesitate to contact me.
- Name: Alex de Borba
- Email for Privacy Inquiries: mail@alexdeborba.com