01Data controller
The controller of your personal data is Calyx Studio, S.L.U. (in formation), the company being constituted in Spain that owns and operates BoardStudio (boardstudio.app).
Note on company status: Calyx Studio, S.L.U. is currently in the process of being incorporated. Once registration with the Spanish Mercantile Registry (Registro Mercantil) is complete, this section will be updated with the final tax identification number (NIF) and registered address. Until then, the operator of record is the founder, Alejandro Guerrero Díaz, in his capacity as administrador único.
- Contact email: hello@boardstudio.app
- Location: Jerez de la Frontera, Cádiz, Spain
- Data Protection Officer: Not appointed (not required at our scale under Art. 37 GDPR). The contact email above reaches the person responsible for privacy matters.
02What we collect
We try to collect as little as possible. Today, on the public site, we process:
| Data | Source | Purpose |
|---|---|---|
| Email address | You submit it via the waitlist form | Send launch updates, beta invitations, and Kickstarter news |
| Language preference | Auto-detected (browser) or manually set (toggle) | Send communications in your preferred language |
| IP address & user agent | Automatically logged when you submit a form | Spam prevention, abuse detection, security audit trail |
| Email engagement | Generated when you open or click our emails | Measure aggregate campaign performance and improve content |
We do not currently collect names, addresses, phone numbers, payment data, or any sensitive category of personal data. If we add features that require additional data (e.g. account creation when the studio app launches), this policy will be updated and you will be informed.
03Why we collect it
- Waitlist communications: tell you when BoardStudio launches on Kickstarter, share early-access opportunities, and pass along build progress.
- Random demo invitations: we will hand out a small number of demo accounts to people on the list. We choose them based on whether you opted in to be a tester.
- Service security: detect and prevent abuse of our forms, infrastructure, and email infrastructure.
- Aggregate analytics: understand what content lands and what doesn't, in aggregate. We do not build behavioral profiles.
04Legal basis
We process your data on the following GDPR Article 6 bases:
- Consent (Art. 6.1.a): when you submit the waitlist form, you actively consent to receive launch communications. You can withdraw at any time via the unsubscribe link in every email — withdrawing has no negative consequence.
- Legitimate interest (Art. 6.1.f): for security and abuse-prevention logging (IP / user agent on form submit). Our interest is operating the site safely; this is balanced against your reasonable expectation that a public form is logged for that purpose.
05Service providers (processors)
We use a small set of third-party providers to operate the service. Each one acts as a data processor on our behalf under a Data Processing Agreement (DPA):
| Provider | Purpose | Data location |
|---|---|---|
| Brevo (Sendinblue Iberia, S.L.U.) | Email list management, double opt-in, transactional emails | European Union |
| Google LLC (Firebase Hosting & Cloud Run) | Static site hosting, API runtime, edge caching | europe-west1 (Belgium); some sub-services may transit to the US |
| MongoDB, Inc. | Backend database (when the studio app launches) | European Union |
For any transfer outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU–US Data Privacy Framework. We do not sell or rent your data to anyone, ever.
06How long we keep it
- Waitlist email: until you unsubscribe, or after 36 months of total inactivity (no opens, no clicks), whichever happens first. After that, we delete or fully anonymize the record.
- Security logs (IP, user agent): 90 days from the date of submission, then automatically rotated.
- Legal-obligation backups: when Spanish law requires (e.g. tax records once we start invoicing), we retain only what is strictly necessary for the legal period.
07Your rights
Under GDPR Articles 15–22 and Spanish LOPDGDD, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten").
- Restrict processing in specific circumstances.
- Data portability: receive your data in a machine-readable format.
- Object to processing based on legitimate interest.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, email hello@boardstudio.app from the address you signed up with, or include a way for us to verify your identity. We respond within 30 days (extendable by 60 days for complex requests, with notice).
Right to lodge a complaint: if you believe we are mishandling your data, you can complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos) at www.aepd.es. We'd appreciate the chance to fix it first via hello@boardstudio.app — but it's your right and we won't stand in the way.
09Children
BoardStudio is not directed at children under 14. We do not knowingly collect personal data from minors under 14. If you believe a minor has provided us their data, contact hello@boardstudio.app and we will delete it.
10Changes to this policy
We will update this page when our processing changes — typically when we add a new service, sign on a new processor, or expand the product. The "last updated" date at the top reflects the latest revision.
For material changes (new processing purposes, new categories of recipients) affecting people already on the waitlist, we will email a heads-up before the change takes effect, and you can withdraw your consent if the new terms don't work for you.
11Contact
Questions, concerns, or rights requests:
- Email: hello@boardstudio.app
- Subject prefix:
[Privacy]— helps us route faster - Response time: within 30 days, usually much faster