Privacy Policy
Privacy Policy and Data Protection (GDPR)
Version: 1.2
Effective date: 3 August 2026
Last updated: 3 August 2026
0. Purpose and scope of this Policy
This Policy explains what personal data kreawave ("the Service") processes, why, on what
legal basis, for how long, who receives it and what you can do about it. It applies to
everyone who interacts with the Service: visitors to the public website, users of the
free public demo (no account required), registered users and third parties who send us a
notice about content.
**What this Policy does not do.** It does not set commercial conditions. Prices, plans,
allowances, consumption rules (including the rules on regenerating a fragment), the right
of withdrawal and refunds are governed exclusively by the Terms of Service and, in the
detail, by the Refund Policy. Where a commercial matter is mentioned here, it is only
to explain the data it generates; in case of any discrepancy on the commercial matter
itself, the Terms of Service prevail.
Modalities covered. The Service today generates audio. **Image generation is not
deployed in production, and video generation does not exist and is not offered at all**
(Terms of Service §2). This Policy is nevertheless written to cover
audio, image and video so that the safeguards described here apply automatically, in full
and without amendment from the moment either of the other two modalities is enabled. Where
a section describes something that only becomes operative with image or video, it says so
expressly.
1. Data controller
| Field | Value |
|---|---|
| Controller | Pedro Cantueso García de Vinuesa (sole trader, trading as kreawave) |
| Tax ID (NIF) | 45748777Y |
| Registered address | Avenida de la Arruzafa 50, 14012 Córdoba, Spain |
| Privacy contact | [email protected] |
| Postal channel for privacy matters | The registered address above |
| Telephone (customer service) | +34 621 34 26 94 (Monday to Friday, 10:00-14:00 CET) |
Data Protection Officer. The Service has not appointed a Data Protection Officer.
The cases in GDPR Art. 37.1 are not met at present: the core activity of the Service is
speech synthesis, not regular and systematic monitoring of data subjects on a large scale
(Art. 37.1.b), and the special-category processing described in §4.6 (voice biometrics) is
not active (Art. 37.1.c). The Service is likewise not among the entities listed in
Art. 34.1 of Spanish Organic Law 3/2018 (LOPDGDD). The controller **cannot lawfully act as
his own DPO**, because a DPO may not hold a position that leads him to determine the
purposes and means of processing (GDPR Art. 38.6; EDPB/WP29 Guidelines WP243 rev.01; CJEU
judgment of 9 February 2023, X-FAB Dresden, C-453/21). Accordingly, **a DPO will be
appointed, and this Policy updated with the appointment, before voice cloning (§4.6) is
enabled at scale.** In the meantime, all privacy enquiries are handled at the contact
address above.
EU representative. Not applicable. A representative under GDPR Art. 27 is required only
of controllers not established in the Union. The controller is established in Spain, so
no representative is designated. (Earlier versions of this Policy stated otherwise; that
statement was legally meaningless and has been removed.)
Supervisory authority. Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001
Madrid — www.aepd.es.
2. Data protection principles
The Service applies the principles of GDPR Art. 5:
- Lawfulness, fairness and transparency: every processing operation in this Policy has a
declared legal basis, and none is carried out for undisclosed purposes.
- Purpose limitation: data is not reused for purposes incompatible with those declared.
- Data minimisation: only what is strictly necessary is collected. Where a value is needed
only for comparison and never for identification, it is stored hashed rather than in the
clear (see §4.5).
- Accuracy: you may rectify your data at any time from your account or by writing to us.
- Storage limitation: the retention periods in §4 and §9 are enforced by automated jobs, not
by manual housekeeping.
- Integrity and confidentiality: see the measures in §10.
- Accountability: the Service applies data protection by design and by default (GDPR Art. 25)
and maintains an internal Record of Processing Activities (GDPR Art. 30).
3. Where your data is stored
Generation infrastructure, the databases and generated files are hosted on the controller's
own hardware in Córdoba, Spain. The Service does not use a third-party object-storage
provider for generated files. The public website is exposed through a reverse proxy in
Falkenstein, Germany and a content-delivery / security layer (see §7); both are inside the
EEA or covered by an appropriate transfer mechanism.
4. Categories of data, legal basis and retention
4.1 Public website and free demo (no account)
The public demo can be used without registering. When you use it, the Service records:
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| IP address, browser user-agent, country code (as supplied by the security layer), number of characters submitted and language requested | Anti-abuse and anti-fraud protection of a free resource; measuring genuine demand for the Service | Legitimate interest (Art. 6.1.f) — protecting a free, unauthenticated resource from automated abuse and understanding traffic | 90 days. Demo records are deleted 90 days after they are written. The IP address is retained for that period solely as an anti-abuse signal and is used for no other purpose |
The text you type into the demo is never stored — only its length in characters. A
first-layer content filter inspects the text in memory to block clearly unlawful requests
(see §6); the text itself is not written to any log or database by the demo.
A separate technical cookie identifies the browser across demo requests so that the free
allowance cannot be reset simply by reloading the page; see §12.
4.2 Account and registration data
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Email address | Authentication, service communications, delivery of account and billing notices | Performance of a contract (Art. 6.1.b) | Until account closure; on closure the address is irreversibly replaced by an anonymous placeholder in the same operation |
| Password hash | Secure authentication (the password itself is never stored) | Performance of a contract (Art. 6.1.b) | Until account closure |
| Email-verification token and password-reset token | Proving control of the mailbox; account recovery | Performance of a contract (Art. 6.1.b) | Verification token: 48 hours. Reset token: 1 hour. Single use |
| Country and, where available, first-level subdivision, derived from your connection | Determining whether the Service may lawfully be offered in your jurisdiction (see §6) and tax territory | Legal obligation (Art. 6.1.c) and legitimate interest (Art. 6.1.f) | Duration of the account |
| Plan, allowance, wallet balance and consumption ledger (per generation and per day) | Operating the contracted service, showing you your own consumption, and supporting billing disputes | Performance of a contract (Art. 6.1.b) | Duration of the account + the statutory limitation periods below |
| Date, time, IP, user-agent and version of each acceptance (Terms, Privacy Policy and, where applicable, biometric consent) | Proving informed acceptance | Legal obligation (Art. 6.1.c) / legitimate interest (Art. 6.1.f) — evidence | Duration of the relationship + 5 years (general limitation period for personal actions, Art. 1964 Spanish Civil Code) |
| Session records: session token, creation and expiry, IP and user-agent | Keeping you logged in; letting you and us detect a session opened from an unexpected place | Performance of a contract (Art. 6.1.b) + legitimate interest (Art. 6.1.f) | Sessions expire 7 days after they are opened and expired rows are deleted by an automated job |
| Voice ratings and saved (favourite) voices | Your personal library and aggregate popularity ranking of catalogue voices | Performance of a contract (Art. 6.1.b) | Duration of the account. The ranking is aggregate and cannot be traced back to an individual |
| Waiting-list email address (only if you subscribed to it before launch) | Notifying you when the Service opened | Consent (Art. 6.1.a) | Until you ask to be removed. The IP is stored hashed and is used only as an anti-spam signal |
4.3 Billing data
Billing is not carried out by the Service. It is carried out by **Paddle.com Market
Limited, which sells to you as Merchant of Record** and is the seller of record for the
transaction (see §7). The Service never receives or stores your card number, card
expiry, CVC or full billing address.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Minimum transaction record: plan or pack purchased, amount, date, Paddle transaction and customer identifiers, and the resulting balance movement | Tax and accounting compliance; support; refund and chargeback handling | Legal obligation (Art. 6.1.c) | 4 years (Art. 66 and 70 Spanish General Tax Act 58/2003, and Art. 6 of the Spanish Personal Income Tax Act) and 6 years for accounting books and supporting documents (Art. 30 Spanish Commercial Code) |
When you start a purchase, the Service transmits to Paddle only your email address and
your internal account identifier, so that Paddle can issue the invoice and so that the
payment can be matched back to your account.
4.4 Generation data: prompts, metadata and generated files
This section applies to audio today and, on the same terms, to image and video from the
moment those modules are enabled.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| The text you submit for generation (and, for image/video when enabled, the prompt) | Producing what you asked for; letting you read your own history; investigating abuse reports and moderation incidents | Performance of a contract (Art. 6.1.b) + legitimate interest (Art. 6.1.f) for the abuse purpose | 7 days. After that the text is automatically and irreversibly replaced by a SHA-256 fingerprint of itself: the content is gone; only a value that lets us confirm whether a given text was generated survives |
| Generation metadata: date and time, engine and model, voice used, language, character count, seed, technical parameters, outcome and any error, plus the IP from which the job was submitted | Reproducibility, technical support, queue accounting, abuse prevention | Performance of a contract (Art. 6.1.b) + legitimate interest (Art. 6.1.f) | 90 days, after which the job record is deleted outright |
| Generated files (audio today; image and video when enabled) | Making the result available for you to download and re-download | Performance of a contract (Art. 6.1.b) | 7 days from generation, then automatically deleted from disk by an hourly job. The download link is itself a signed token with the same lifetime |
Retention exception — content subject to a notice. Where a job has been the subject of
a notice-and-action procedure and has been taken down, its text and record are **excluded
from the automatic purges above** and retained as evidence, for as long as necessary to
justify the measure and to allow you to challenge it (GDPR Art. 17.3.b and 17.3.e —
compliance with a legal obligation and the establishment, exercise or defence of legal
claims; Regulation (EU) 2022/2065 — DSA — Arts. 6, 16 and 17).
What is embedded in the file you receive. Every generated file carries an inaudible
watermark and technical provenance metadata (generator, model, licence, voice identifier,
seed and date), as described in the AI Content Disclosure. **Neither the watermark nor
the metadata contains your identity**: the watermark payload is a 16-bit message consisting
of a fixed project tag and a hash of the voice used — not of you, your account or your
IP. It cannot be used to identify you.
4.5 Security, anti-fraud and anti-multi-account data
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Hashed signup IP and hashed browser signature (user-agent, language and platform) captured at registration | Detecting farms of accounts created to abuse the free allowance | Legitimate interest (Art. 6.1.f) — preventing fraud, expressly recognised as a legitimate interest in Recital 47 GDPR | Duration of the account |
| Abuse counters and temporary blocks by account, IP or browser signature | Rate-limiting and stopping repeated attempts to generate prohibited content | Legitimate interest (Art. 6.1.f) | Held in memory and reset within 24 hours |
| Internal alert records generated by a moderation or security incident, containing the account identifier, the IP and an extract of up to 200 characters of the blocked text | Allowing the controller to review the incident, and evidencing the measure taken | Legitimate interest (Art. 6.1.f) and, for child sexual abuse material, legal obligation (Art. 6.1.c) | 12 months, after which the alert record and the 200-character extract are deleted. Where an alert has given rise to a report to a competent authority, the record is kept until that matter is closed (Art. 17.3.b and 17.3.e GDPR) |
Both the signup IP and the browser signature are stored as a keyed hash (HMAC with a
server-side secret). They allow us to compare two registrations; they do not allow us,
or anyone who obtained the database, to reconstruct the original IP or to identify the
device. This is the data-minimisation principle applied in practice (GDPR Art. 5.1.c).
4.6 Voice data — SPECIAL CATEGORY (GDPR Art. 9)
Current status: voice cloning is NOT active. The Service does not accept, store or
process any voice sample uploaded by a user, and therefore **processes no biometric data
today**. The endpoints are disabled at the application level. This section is published in
advance so that the safeguards below are binding and fully in force from the first moment
the feature is enabled — no user voice will be processed before that happens.
Where it is capable of identifying a natural person, a voice sample is **biometric data for
the purpose of uniquely identifying a natural person** and therefore a special category of
data (GDPR Art. 9.1, read with Art. 4.14). When the feature is enabled, the following will
apply:
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Reference voice sample uploaded by the user | Computing the voice embedding | Explicit consent (Art. 9.2.a) on top of performance of a contract (Art. 6.1.b), plus a declaration by the user that the voice is their own or that they hold the rights to it | Deleted once the embedding is computed, unless the user expressly chooses to keep it available for re-use |
| Voice embedding | Reproducing that voice in the user's own generations | Explicit consent (Art. 9.2.a) | Until consent is withdrawn, the voice is deleted, or the account is closed |
| A hash of the sample | Traceability, so that a notice about a cloned voice can be matched to the sample that produced it | Legitimate interest (Art. 6.1.f) and legal obligation (Art. 6.1.c) under the DSA | With the voice record |
Safeguards that apply to biometric data:
- Encryption at rest with a dedicated key that is never stored in the code repository, using
Fernet (AES-128-CBC with HMAC-SHA256 authentication), and TLS 1.2 or higher in transit.
*(Earlier versions of this Policy described this as "AES-256". That was inaccurate and has been
corrected: Fernet is specified as AES-128 in CBC mode with an HMAC-SHA256 authentication tag.)*
- No silent fallback. If the cryptographic library is unavailable, the Service refuses to store
the sample rather than storing it in the clear.
- Account exclusivity. An embedding is bound to the account that created it. No other user can
access, list or use it. The Service does not sell it, licence it, publish it in the public
catalogue, or use it to train models or to serve any other customer.
- Minimum access. No frontend access to the raw sample; access limited to the technical
operations strictly required to run the feature.
- Deletion on request. You may delete a cloned voice at any time from your dashboard. Deletion
overwrites the encrypted file before unlinking it, and is permanent and irrecoverable.
- Cascade deletion. Closing your account or exercising your right to erasure purges every
associated sample and embedding immediately, in the same request — not on a later schedule.
- No disclosure to third parties except under a legal obligation or an order from a competent
authority.
- Withdrawal of consent (GDPR Art. 7.3) takes effect immediately and does not affect the
lawfulness of processing carried out before withdrawal.
- Before the feature is enabled, the Service will complete a Data Protection Impact Assessment
(GDPR Art. 35.3.b) and appoint a DPO as stated in §1.
The same regime will apply, without amendment, to any **facial or bodily image of a real
person** processed by the image or video modules if and when those are enabled: such data
is biometric under Art. 9 on exactly the same reasoning, and will be subject to explicit
consent, encryption at rest, account exclusivity and immediate cascade deletion.
4.7 Notice-and-action reports (third parties)
If you send us a notice about content under the DSA procedure, we process your **email
address, your IP address**, the content complained of and the reasons you give. The
legal basis is a legal obligation (GDPR Art. 6.1.c, in conjunction with Arts. 16 and 17
of Regulation (EU) 2022/2065). Reports are retained for as long as necessary to handle the
notice, to justify the decision taken and to defend it, and to detect and prevent abuse of
the notice mechanism itself. The legal basis for that last purpose is our **legitimate
interest** in protecting the Service and third parties from unfounded or automated notices
(Art. 6.1.f GDPR). It is not Art. 23 of Regulation (EU) 2022/2065, which is addressed to
online platforms and does not apply to the Service — see the Notice and Action Procedure
§2 and §14.
4.8 Marketing
The Service does not send newsletters or marketing emails. The emails it sends are
transactional: address verification, password reset, purchase and billing notices, security
and account notices, and notices about a moderation decision affecting you. If commercial
communications are introduced in the future, they will be based on your **prior, freely
given and separate consent** (Art. 6.1.a and Art. 21.1 of Spanish Law 34/2002, LSSI),
withdrawable at any time, and withdrawing it will never stop the transactional emails above.
5. Purposes and legal bases — summary
| Purpose | Legal basis |
|---|---|
| Providing the contracted Service: generating audio and — when enabled — image and video, and making the result available to you | Performance of a contract (Art. 6.1.b) |
| Managing your account, plan, allowance and consumption ledger | Performance of a contract (Art. 6.1.b) |
| Billing, invoicing, tax remittance and accounting | Legal obligation (Art. 6.1.c); the payment itself is performed by the Merchant of Record (§4.3) |
| Handling refunds, disputes and chargebacks | Performance of a contract (Art. 6.1.b) + legitimate interest (Art. 6.1.f) |
| Content moderation and abuse prevention | Legitimate interest (Art. 6.1.f) — protecting third parties and the Service; and legal obligation (Art. 6.1.c) for child sexual abuse material and for DSA and AI Act duties |
| Security, anti-fraud and anti-multi-account | Legitimate interest (Art. 6.1.f), Recital 47 GDPR |
| Determining whether the Service may lawfully be offered in your jurisdiction | Legal obligation (Art. 6.1.c) + legitimate interest (Art. 6.1.f) |
| Voice cloning (not active) and, if enabled, processing of images of real people | Explicit consent (Art. 9.2.a) in addition to Art. 6.1.b |
| Advertising measurement through the Meta pixel — not operative at the effective date, see §7 and §12 | Consent (Art. 6.1.a) and Art. 22.2 LSSI — never loaded before you accept |
| Complying with legal obligations (tax, DSA, AI Act, CSAM reporting) | Legal obligation (Art. 6.1.c) |
Balancing test for the legitimate-interest grounds. Each of the operations above based
on Art. 6.1.f pursues the prevention of fraud and of harm to third parties; it uses the
least intrusive data available (hashes rather than raw identifiers wherever comparison is
enough); it is subject to short, automated retention periods; and it does not extend to
profiling for advertising or to any decision about you beyond the ones disclosed in §6. You
may object at any time under Art. 21 (see §11).
6. Automated decision-making
The Service makes the following automated decisions, and you are entitled to know about
them (GDPR Arts. 13.2.f, 14.2.g and 22):
- Territorial availability. Both registration and sign-in are refused automatically
— including sign-in with Google — where the country or first-level subdivision reported for
your connection is one in which the Service cannot lawfully operate its current or planned
biometric features. Today this is China and the US State of Illinois. The response is
an HTTP 451 and the reason is legal, not commercial. If you already hold an account, this
means you cannot sign in from those territories; write to [email protected] and
we will help you export your data or close the account. This matches Terms of Service §21.
- Content filter. Text submitted for generation is checked, before generation, against a
deterministic list of patterns denoting hate speech, incitement and indicators of child sexual
abuse material. A match blocks that request. This is a rule-based filter, not a profiling model:
it evaluates the submitted text, not you.
- Temporary block and account suspension. Repeated blocked attempts within a 24-hour window
lead to a temporary block by IP or browser signature (anonymous use) or, for a registered
account, to automatic suspension of the account pending manual review, with notice to you by
email.
Decision 3 produces a significant effect on you, so the safeguards of Art. 22.3 apply: you
have the right to **obtain human intervention, to express your point of view and to contest
the decision** by replying to the notification email or writing to
[email protected]. Decisions 1 and 2 are necessary for entering into or performing
the contract and for compliance with legal obligations (Art. 22.2.a and 22.2.b).
The Service does not carry out profiling for advertising purposes, does not build
behavioural profiles of users, and does not sell or share data for the purpose of
cross-context behavioural advertising.
7. Recipients, processors and international transfers
Personal data is never sold, and is never transferred to third parties for their own
commercial purposes. It is shared only as follows:
| Recipient | Role under GDPR | What it receives | Location and transfer safeguard |
|---|---|---|---|
| Paddle.com Market Limited — Merchant of Record | Independent controller, not a processor. Paddle is the seller of record: it decides the purposes and means of processing your payment data, under its own privacy policy (paddle.com/legal/privacy) | Your email address, your internal account identifier, and the payment and billing data you give it directly. The Service never sees your card data | United Kingdom (UK adequacy decision) and group entities in the USA, Ireland and Canada. Transfers outside the EEA rely on the European Commission's Standard Contractual Clauses and, where applicable, adequacy decisions |
| Cloudflare, Inc. | Processor (Art. 28) | Connection metadata (IP, user-agent, country) passing through the security and delivery layer, and the anti-bot challenge shown at registration and on the demo | USA — EU-US Data Privacy Framework and/or Standard Contractual Clauses |
| Hetzner Online GmbH | Processor (Art. 28) | Hosts the public reverse proxy and stores the encrypted off-site copy of the databases. The backup is encrypted with AES-256-CBC before it leaves the controller's premises; Hetzner holds ciphertext and never the key | Falkenstein, Germany — inside the EEA, no international transfer |
| Resend, Inc. | Processor (Art. 28) | Your email address and the content of transactional emails (verification, reset, billing and account notices) | USA — EU-US Data Privacy Framework certification and a published Data Processing Addendum |
| Google Ireland Ltd. / Google LLC | Independent controller for the sign-in itself; source of data for us | Only if you choose "Continue with Google". Google tells us your verified email address; we do not receive your Google password, contacts or any other profile data | Ireland / USA — adequacy for Ireland; EU-US Data Privacy Framework and SCCs for the USA |
| Meta Platforms Ireland Ltd. | Joint controller with the Service for the collection and transmission of pixel data (CJEU judgment of 29 July 2019, Fashion ID, C-210/16, applied to embedded third-party tools) | Only if you press "Accept" on the cookie banner. If you press "Decline", or simply ignore the banner, nothing is loaded and nothing is sent. Status at the effective date: not operative. The Service's own content-security policy does not allow the pixel's script origin, so the tag does not execute and no data reaches Meta even after you accept. If it is ever made operative, this Policy and the Cookie Policy will be updated and consent will be asked again beforehand. See Cookie Policy §5 | Ireland / USA — EU-US Data Privacy Framework and SCCs. See §12 and the Cookie Policy |
| Competent authorities (National Police, Civil Guard, Public Prosecutor's Office, INCIBE, AEPD, courts) | Recipients under a legal obligation | Only what the specific legal obligation or order requires | Spain / EU |
| CSAM hash-matching provider | Processor (Art. 28) — not yet contracted | Hashes only, never the content | No such transfer takes place today, because the image module (§4.4) is disabled. The provider will be contracted, bound by an Art. 28 agreement and named in this Policy before that module is enabled |
No third-party object storage. Generated audio — and, when enabled, image and video —
is stored on the controller's own infrastructure in Spain for the retention window in §4.4
and then deleted. No cloud storage provider holds your generated content.
No AI training on your content. Your prompts, your generated files and (when the
feature exists) your voice samples are not used to train, fine-tune or evaluate any
model, and are not shared with any model provider for that purpose.
8. Reliance on legal grounds outside the EEA
The Service is offered from Spain and is governed by Spanish law. Where you are located
outside the EEA, we still apply this Policy to you as our baseline standard, without
prejudice to any additional rights your own law may give you.
9. Retention — summary table
| Data | Period |
|---|---|
| Generated files (audio; image and video when enabled) | 7 days, then automatically deleted |
| Download links (signed tokens) | 7 days, matching the file |
| Text of your prompt | 7 days, then irreversibly replaced by a SHA-256 fingerprint |
| Generation metadata, including the submission IP | 90 days, then the record is deleted |
| Content and records subject to a notice-and-action decision | Excluded from the above; retained as evidence for as long as necessary (§4.4) |
| Login sessions | 7 days, then deleted by an automated job |
| Email-verification token / password-reset token | 48 hours / 1 hour, single use |
| Account and profile data | Until closure; the email address is anonymised in the closure operation itself |
| Proof of acceptance of the Terms and this Policy | Relationship + 5 years (Art. 1964 Civil Code) |
| Billing records | 4 years (tax) and 6 years (commercial accounting) |
| Voice samples and embeddings (not active) | Until withdrawal of consent, deletion of the voice, or closure of the account — purged immediately in all three cases |
| Demo logs | 90 days |
| Internal moderation and security alert records | 12 months, longer only where the matter has been reported to a competent authority |
These periods are the maximum time we keep each category, and we do not extend them except
where a specific legal obligation or an open claim requires it, in which case the exception
is stated in the row itself. The purges of login sessions and of generated files run
automatically every hour.
10. Technical and organisational security measures (GDPR Art. 32)
- In transit: TLS 1.2 or higher throughout, with HTTP Strict Transport Security, and a strict
Content-Security-Policy that only permits the specific third-party endpoints listed in §7.
- At rest: voice samples (when the feature is enabled) encrypted with a dedicated key using
Fernet (AES-128-CBC + HMAC-SHA256); off-site backups encrypted with AES-256-CBC with a key that
never leaves the controller's premises; passwords stored only as a hash produced by a modern
password-hashing function (Argon2id, or bcrypt as an accepted alternative) — the Service
refuses to start in production if only a development-grade hash is available.
- Pseudonymisation by design: signup IP and browser signature stored as keyed hashes; prompt
text replaced by a fingerprint after 7 days; a closed account's email address replaced by an
anonymous placeholder.
- Access control: the databases are not reachable from the internet; the origin server is not
directly exposed, only through the reverse proxy of §7; administrative powers are held per named
account, so every administrative action is attributable and individually revocable.
- Session hygiene: authentication cookies are HttpOnly, Secure and SameSite=Lax; suspending an
account invalidates all of its live sessions in the same transaction.
- Backups: taken daily, integrity-verified after being written, copied off-site encrypted, and
checked byte-for-byte against the local copy after transfer. A failed backup raises an alert.
- Automatic deletion: the retention windows in §9 are executed by scheduled jobs, and a job's
deletion is recorded so that it cannot be silently skipped.
- Logging: security and moderation incidents are recorded in an internal alert log that the
controller can review.
No system is perfectly secure. If a personal data breach occurs that is likely to result in
a risk to your rights and freedoms, the Service will notify the AEPD within 72 hours
(GDPR Art. 33) and, where the risk is high, will notify you directly without undue delay
(GDPR Art. 34), in accordance with its internal breach protocol.
11. Your rights
You may exercise the following rights free of charge by writing to
[email protected], or by post to the address in §1, with sufficient
information for us to identify you:
| Right | What it means | Our deadline |
|---|---|---|
| Access (Art. 15) | Confirmation of whether we process your data, and a copy of it | 1 month, extendable by 2 further months where the request is complex (Art. 12.3) |
| Rectification (Art. 16) | Correction of inaccurate or incomplete data | 1 month |
| Erasure (Art. 17) | Deletion of your data where it is no longer necessary or you withdraw consent | 1 month |
| Restriction (Art. 18) | Freezing processing while a dispute about accuracy or lawfulness is resolved | 1 month |
| Portability (Art. 20) | Receiving the data you provided, in a structured, commonly used, machine-readable format | 1 month |
| Objection (Art. 21) | Objecting to processing based on legitimate interest, on grounds relating to your particular situation | 1 month; we stop unless we demonstrate compelling legitimate grounds that override your interests |
| Human review of an automated decision (Art. 22.3) | Obtaining human intervention, stating your point of view and contesting the decision described in §6 | Without undue delay |
| Withdrawal of consent (Art. 7.3) | For biometric data and for the advertising pixel; does not affect prior lawful processing | Immediate |
Self-service. Two of these rights are also available directly in your account, with no
waiting period: exporting your data in JSON (profile, subscription, consents, daily
usage, wallet and top-up history, and your job metadata) and deleting your account. The
deletion operation, in a single request: cancels any live subscription so you cannot be
charged again, purges any biometric data, replaces the text of your past prompts with their
fingerprints, deletes all live sessions and anonymises your email address.
What survives account deletion, and why. A pseudonymous account row is kept so that
records we are legally obliged to retain — proof of acceptance of the Terms, billing
records, and any evidence relating to a notice-and-action decision — remain internally
consistent. It contains no clear-text email and no other directly identifying data. A keyed
hash of your former email address is also kept for the sole purpose of preventing the same
mailbox from claiming the free introductory allowance repeatedly; it permits comparison
only, never re-identification.
Complaints. If you believe your rights have been infringed, you may lodge a complaint
with the Spanish Data Protection Agency (AEPD) — C/ Jorge Juan 6, 28001 Madrid,
www.aepd.es — or with the supervisory authority of your country of residence, at any time
and without needing to contact us first.
12. Cookies and similar technologies
The Service uses the following, described in full in the Cookie Policy
(https://kreawave.com/legal/cookies):
- Strictly necessary, exempt from consent under Art. 22.2 LSSI: the session cookie that keeps
you logged in; the short-lived cookies used during a "Continue with Google" sign-in; and a
browser identifier used to apply the free demo allowance to a browser rather than to a page
reload.
- Third-party technical: the anti-bot challenge (Cloudflare Turnstile) on the demo and
registration forms, and Paddle's own storage during checkout.
- Advertising, consent-only: one Meta (Facebook) pixel, used to measure the performance of
the Service's own advertising. It is not loaded until you press "Accept" on the banner. Your
choice is stored locally in your browser, not in a cookie sent to us, and you can change it by
clearing your browser's site data for kreawave.com.
This is a correction. Versions 1.1 and earlier of this Policy stated that the Service
used "no web analytics or advertising cookies of any kind". That statement was wrong: an
opt-in Meta pixel is present in the site's code. It is corrected here and in the Cookie
Policy. The Service uses no web analytics product (no Google Analytics, Plausible,
Fathom or equivalent).
Status of the Meta pixel at the effective date: not operative. The tag is present in the
site's code and is offered behind the consent banner, but the Service's own
content-security policy does not allow its script origin, so the script never executes and
**no Meta cookie is stored on your device and no data is transmitted to Meta, even if you
press *Accept***. This is stated identically in the Cookie Policy §5. If the pixel is ever
made operative, this Policy and the Cookie Policy will be amended in the same change, the
banner will be shown to you again and your consent will be asked for afresh before anything
is loaded.
13. Children
The Service is not directed at minors and may not be used by them. An account may only
be created, and a contract only entered into, by a person aged 18 or over, or the higher
minimum age of their jurisdiction, as stated in Terms of Service §3 and in **Acceptable
Use Policy §2.2**. We do not knowingly process the personal data of a person under 18.
Art. 7 of Organic Law 3/2018 (LOPDGDD) sets 14 as the age at which a data subject may
consent, on their own, to the processing of their personal data. That provision governs
consent to processing; it does not entitle a minor to contract for this Service, which
we prohibit on contractual grounds.
If we learn that an account belongs to a person under 18, we close it, delete the associated
personal data without undue delay and refund in full any amount paid through it. If you
believe a minor has registered, write to [email protected].
14. Changes to this Policy
This Policy may be amended. **Every substantive amendment raises the version number and the
effective date at the top of this document**; the version in force when you accepted is the
one recorded against your account. Significant changes affecting your rights or the purposes
of processing will be notified by email or by a notice inside the platform before they take
effect. The current version is always available at https://kreawave.com/legal/privacy.
15. Contact
- Privacy and data protection: [email protected]
- Postal address: Pedro Cantueso García de Vinuesa, Avenida de la Arruzafa 50, 14012 Córdoba, Spain
- Telephone: +34 621 34 26 94 (Monday to Friday, 10:00-14:00 CET)
- Supervisory authority: Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es
Enquiries received through any of these channels are answered within a maximum of **15
calendar days** (Art. 21.3 TRLGDCU, as amended by Law 10/2025), without prejudice to the
GDPR deadlines in §11, which prevail for the exercise of data-protection rights.