Privacy policy
What we collect, why we are allowed to hold it, who else sees it, and how to make us delete it. In plain English, because a policy nobody can read protects nobody.
Last updated: 28 August 2026
Who runs this site
Krelo is a one-person studio. The site and every service on it are operated by the individual named below, who is also the data controller for anything you send through it.
- Provider
- Iñaki Larrea Beracoechea, trading as Krelo
- Tax ID (NIF)
- 72836185S
- Registered address
- Calle Proa 3, 2º, 35016 Las Palmas de Gran Canaria, Spain
- info@krelo.marketing
- +34 618 161 140
- Website
- krelo.marketing
The short version. This site has no analytics, no advertising pixels and no tracking cookies. Nothing you do here is recorded unless you fill in the contact form and press send. If you never send the form, we never learn anything about you beyond what any web server necessarily sees.
What we collect, and only when you send it
The only way this site collects personal data is the contact form. When you submit it, these fields travel to us:
- What you type: name, email address, phone number, company, website, the service you are interested in, and your message.
- Where you came from: the UTM parameters in the link you clicked, the referring page and the first page you landed on. Your browser holds these for the duration of the visit and sends them only if you submit the form. If you leave without submitting, they are discarded when you close the tab.
- Your IP address and the time of submission, recorded by the server that receives the form. This is what lets us tell a real enquiry from an automated one.
We do not ask for, and you should not send us, payment card details, government ID numbers or any special category of data (health, beliefs, biometrics and the like) through this form.
Why we are allowed to hold it, and for how long
The legal basis is your request: you contacted a business asking to be contacted back, which under Article 6(1)(b) GDPR is processing necessary to take steps at your request before entering into a contract.
We keep enquiries for 24 months from your last contact with us, then delete them. If you become a client, the contractual and accounting records are kept for 6 years, which is the retention period Spanish commercial and tax law imposes on the invoices behind them.
Who else sees it
Your enquiry is not sold, rented or shared for anyone else's marketing. It is handled by these providers, each of which processes it only to deliver the service we use them for:
- Cloudflare (USA / global network) — hosts this site and the endpoint that receives the form, and stores the enquiry.
- Resend (USA) — delivers the notification email.
- CallMeBot — delivers a WhatsApp notification so an enquiry is not missed.
- Google Fonts (Google Ireland / USA) — the typefaces on this page are requested from Google's servers, which means Google sees the IP address of every visitor loading them. This happens on page load, before you interact with anything.
- Cloudflare cdnjs — serves the animation library, with the same consequence for your IP address.
Transfers to providers outside the European Economic Area rely on the European Commission's Standard Contractual Clauses or, where applicable, an adequacy decision.
Cookies and browser storage
This site sets no cookies. There is no analytics, no Google Analytics, no Meta pixel, no advertising or remarketing tag, and no consent banner because there is nothing to consent to.
Two small values are kept in your own browser and never sent anywhere on their own:
krelo.seen— remembers that you have already watched the opening animation, so you are not shown it again.krelo.src— holds the campaign parameters described above for the duration of the visit, so they can accompany the form if you choose to send it.
Clearing your browser's site data removes both.
Your rights
You can ask us to give you a copy of what we hold about you, correct it, delete it, restrict what we do with it, hand it over in a portable format, or object to the processing. Write to info@krelo.marketing and we will answer within one month.
You do not have to go through us: if you think we have handled your data badly you can complain directly to the Spanish supervisory authority, the Agencia Española de Protección de Datos (aepd.es).
Security, and what we will not pretend
Data is transmitted over HTTPS and stored on infrastructure with access controls. No system is immune. If a breach ever affects your data and creates a real risk to you, we will notify the supervisory authority within 72 hours and tell you directly, as the GDPR requires.
Children
This site sells business services and is not directed at anyone under 16. We do not knowingly collect their data. If you believe a child has sent us something, write to us and we will delete it.
Changes
If this policy changes we update the date at the top of the page. Material changes affecting people who have already contacted us are notified by email.