Home · Privacy

Privacy policy

Last updated: 19 May 2026

Plain summary

We're a small studio. We collect the bare minimum — what you tell us through the contact form, plus aggregate, cookieless usage stats. No cookies, no ad trackers, no selling data. Below is the full version.

1. Who we are

Onda ("we", "us") is a web design studio based in Spain, operating the site agencyonda.com. For any question about your data or this policy, contact us via the form on the home page.

2. What personal data we collect

Contact form — when you submit it we receive your name, email, optional phone and the message you write. If you message us on WhatsApp instead, that conversation is handled by WhatsApp under its own terms.

Cookieless visitor analytics — a privacy-first measurement tool we built. It does NOT use cookies and does NOT store any persistent identifier. For each visit it records the pages loaded, scroll depth, language, broad device type (mobile/tablet/desktop), referrer site and a country-level location best-effort from your IP. To count unique visitors without identifying you, we generate a one-way SHA-256 hash of your IP + browser User-Agent + a secret salt that rotates every day. The hash cannot be reversed back to your IP, and rotating the salt daily means the same person appears as a fresh visitor the next day.

Server logs — our hosting provider records standard access logs (IP, timestamp, URL) for security and operations.

We do NOT use advertising or marketing cookies, social-network tracking pixels, browser fingerprinting, ad networks, or anything that follows you across the web. We do not sell or rent your data.

3. Why we process it and our legal basis (GDPR Art. 6)

Contact-form messages — to reply to your enquiry, prepare a quote and follow up. Basis: steps prior to a contract (Art. 6(1)(b)) and our legitimate interest in answering enquiries (Art. 6(1)(f)).

Cookieless analytics — to understand how visitors find and use the site so we can improve it. Basis: legitimate interest (Art. 6(1)(f)). Because the measurement is cookieless and uses no persistent identifier, AEPD/EDPB guidance treats it as consent-exempt audience measurement, which is why this site has no cookie banner.

Security and logs — to keep the site available and safe. Basis: legitimate interest.

4. Who we share it with

We use a small number of trusted services so the site works: Resend (resend.com) sends us the email notification when you submit the contact form; Neon (neon.tech) stores cookieless analytics events; Render (render.com) hosts the website; Google Fonts (gstatic.com) delivers web fonts when you load the page; unpkg.com delivers a small icon library. Where any of these involves data leaving the EEA, we rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses approved by the European Commission.

5. Cookies and similar technologies

This site uses no advertising or analytics cookies. The only client-side storage is a short-lived sessionStorage value (a tab session ID for analytics, deleted when you close the tab) and, optionally, a localStorage value to remember your language choice. These are not transmitted to anyone and are not used to track you across sites.

6. How long we keep your data

Contact-form messages: up to 24 months after our last contact, unless you ask us to delete them earlier. Analytics events: up to 14 months at row level; aggregate, anonymous statistics may be kept longer. Server logs: typically a few weeks, as set by our hosting provider.

7. Your rights under GDPR (Articles 15–22)

Access — ask what we hold about you. Rectification — ask us to correct it. Erasure ("right to be forgotten") — ask us to delete it. Restriction or objection — ask us to limit or stop a particular processing. Portability — get a copy of the data you gave us in a portable format.

To use any of these rights, message us through the contact form. We answer within 30 days. If you think we have not handled your data properly, you can complain to the Spanish Data Protection Authority (AEPD): www.aepd.es.

8. Children

This site is aimed at business owners. We do not knowingly collect data from anyone under 16.

9. Changes

If we change this policy in any meaningful way, we'll update the "Last updated" date at the top and, where appropriate, mention it on the site.

10. Contact

For any privacy question or request, contact us via the form on the home page.

Get a quote