blog.saulacuna.dev

Legal notice and privacy

Last updated:

1. Site ownership

This site (blog.saulacuna.dev) is personally owned by Saúl Acuña Godoy, hereinafter "the owner". It is part of the saulacuna.dev ecosystem alongside the main site and the portfolio at me.saulacuna.dev. The full legal notice of the ecosystem is published at saulacuna.dev/aviso-legal and applies to this subdomain.

Professional address: Barcelona, Spain. Contact email: [email protected].

For data protection matters only: [email protected].

2. Purpose

blog.saulacuna.dev hosts personal essays on technology, AI and personal growth. Browsing is free and requires no registration.

3. Personal data we process

The blog itself is static and collects no data. The contact, newsletter and erasure forms call the api.saulacuna.dev backend (operated by the same owner), which processes personal data in the following flows:

3.1 Newsletter (double opt-in)

  • Data: email address and, optionally, preferred language.
  • Legal basis: explicit consent (Article 6.1.a GDPR), formalised via double opt-in.
  • Purpose: sending editorial communications related to the blog.
  • Retention: indefinite while the subscription is active. Immediate opt-out via the link in every email or via this page.

3.2 Contact form (when applicable)

  • Data: email address, optional name and message content.
  • Legal basis: pre-contractual measures (Article 6.1.b GDPR) when the message is commercial; legitimate interest (6.1.f) otherwise.
  • Automatic retention: 2 years from message receipt. Daily purge at 03:30 UTC by automated process.

3.3 Backend operational logs

The backend logs technical data (anonymised IPs, response code, route) for up to 30 days for diagnostics. No cross-reference with identities.

4. Processors and transfers

  • Cloudflare, Inc. (USA) — static hosting and CDN for the frontend. International transfer covered by Standard Contractual Clauses (SCC).
  • Resend, Inc. (USA) — transactional email delivery (acknowledgements, double opt-in, unsubscribe and erasure links). SCC and commitment not to use the data for its own purposes. Emails are sent from the technical address [email protected]; the reply-to is set to [email protected], so any reply reaches the data controller directly.
  • Contabo GmbH (Germany) — VPS hosting the backend and PostgreSQL database.
  • GitLab Inc. (USA) — source code storage. Does not process visitor data.

A detailed identification of each processor and its safeguards is available on request at [email protected].

5. User rights (ARSULIPO)

Under GDPR and Spanish LOPDGDD, users may exercise their rights of:

  • Access, Rectification, eraSure, Limitation, objectIon and POrtability.
  • Withdraw consent at any time, without retroactive effect.
  • Lodge a complaint with the Spanish Data Protection Agency (aepd.es) if processing is considered non-compliant.

For complete and automated erasure use the erasure request form — you will receive a tokenised link (valid 24h) that triggers the final deletion.

For other rights: [email protected].

6. Cookies and analytics

The blog sets no first-party cookies. Cloudflare may set strictly necessary cookies for bot mitigation (__cf_bm, cf_clearance), exempt under the ePrivacy directive. If Cloudflare Web Analytics is enabled, only aggregate analytics without personal identifiers are collected — explicit consent is not required.

7. Changes

This policy may be updated at any time. The current version is the one published at this URL. Periodic review is recommended.