Privacy Policy
How Volqer handles personal data. This policy describes what is actually collected and stored by this site — nothing is included here that the site does not do.
- Last updated
- 6 September 2026
Who is responsible
Volqer is operated from Spain. Full company details — registered name, tax number and address — are published here before any payment can be taken on this site. For anything concerning this policy or your data, write to info@volqer.com and a person will answer.
What this site collects
Only what each feature needs to work:
- Running an audit: the website address you submit, and the technical results of analysing it. Website addresses are not personal data in themselves, but they are stored alongside the record.
- Abuse prevention: a one-way salted hash of your IP address. The IP itself is never written to disk. The hash cannot be reversed to recover your IP, and exists solely to enforce the daily limit on free audits.
- Contact and enquiry forms: your name, email address, and anything you choose to write in the company and message fields.
- Booking a call: your name, email address, the time slot you chose, and any notes you add about what to cover.
- Buying a report or a call: an order record with the amount, currency, status and a payment reference. Card details are handled entirely by the payment provider and never reach this site.
What this site does not do
Stated plainly, because it is unusual enough to be worth saying:
- No analytics of any kind. No Google Analytics, no Tag Manager, no Meta pixel, no heatmaps, no session recording.
- No advertising or tracking cookies. No cookies at all are set on visitors — see the Cookie Policy.
- No profiling, no automated decision-making with legal effects, and no attempt to identify you across sites.
- Your data is never sold, rented or shared for anyone else's marketing.
Why we are allowed to hold it
Under Article 6 of the GDPR:
- Performance of a contract — delivering the report you bought, holding the slot you booked, and sending the confirmations that go with them.
- Legitimate interest — replying to an enquiry you sent us, and protecting the service from abuse. The IP hash is the clearest example: it is the least intrusive way we found to stop one visitor exhausting a shared budget.
- Legal obligation — keeping invoicing and accounting records for the period Spanish tax law requires.
Who else processes it
These providers act as processors on our instructions. Each is used for one purpose only:
- Cloudflare — hosting, and the database that stores audits, enquiries, orders and bookings. The database is provisioned in Western Europe, so this data is stored in the EU. Cloudflare also routes email sent to our addresses.
- Resend — sending transactional email (booking confirmations, enquiry notifications). Delivery runs through Amazon SES in the eu-west-1 region.
- OpenAI — used only during a GEO audit. It receives the address and public description of the site being audited, in order to test how AI assistants answer questions about that market. Your name, email or any other personal data is never sent.
- Google PageSpeed Insights — used only during an SEO audit. It receives the address of the site being audited, and nothing else.
- Stripe — payment processing, when a payment is made. Stripe receives your payment details directly; we receive only a reference and the outcome.
OpenAI and Stripe are established in the United States. Transfers rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework and, where applicable, Standard Contractual Clauses.
How long it is kept
- Audit technical data: 90 days, after which it is deleted automatically.
- Enquiries and contact messages: up to 24 months from the last exchange, so a conversation can be picked up again.
- Orders and bookings: 6 years, as required for accounting and tax records.
- Administrator sessions: 12 hours, then deleted.
Your rights
You can ask us at any time to:
- Give you a copy of the personal data we hold about you.
- Correct anything that is wrong.
- Delete it, where we are not required to keep it for accounting.
- Restrict or object to how we use it.
- Receive it in a portable, machine-readable format.
Write to info@volqer.com and you will get an answer within one month. If you are not satisfied, you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (aepd.es).
Security
Traffic is served over HTTPS only. The administrator password is never stored — only an irreversible hash of it. Access links to paid reports are stored as hashes, so a copy of the database cannot be turned back into a working link. IP addresses are hashed with a secret salt before storage.
Children
This site sells business services and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes
This policy will change if what the site does changes. The date at the top of this page tells you when it was last revised. Last updated: 6 September 2026.