Sabemos.AI
SABEMOS.AI

Privacy Policy

Last updated: May 2026

At Sabemos AI, we believe privacy is a fundamental right. This policy explains exactly what data we collect, why we collect it, how long we keep it, and what rights you have. We've written this in plain language because legal jargon doesn't help anyone.

1. Who We Are

Sabemos AI is an AI consulting and development company based in Barcelona, Spain. When you use our website (sabemos.ai) or engage our services, we are the data controller responsible for your personal information. You can reach our team at connect@sabemos.ai for any privacy-related questions.

2. Information We Collect

We only collect information that serves a clear purpose:

  • Contact Information: Name, email address, phone number, company name, and job title when you fill out our contact forms, book a consultation, or subscribe to our newsletter. We need this to respond to you and provide our services.
  • Project Information: Business information, requirements, and data you share with us during consulting engagements. This is necessary to deliver the services you've hired us for.
  • Website Analytics: Anonymous usage data including pages visited, time on site, and general location (country level). We use this to improve our website. This data cannot identify you personally.
  • Cookies: Essential cookies for website functionality and optional analytics cookies (only with your consent). See our Cookie section below for details.

3. How We Use Your Information

We use your information only for legitimate purposes:

  • To respond to your inquiries and provide requested information (legal basis: legitimate interest)
  • To deliver consulting and development services you've engaged us for (legal basis: contract performance)
  • To send you newsletters and updates, only if you've opted in (legal basis: consent)
  • To improve our website and services based on usage patterns (legal basis: legitimate interest)
  • To comply with legal obligations such as tax and accounting requirements (legal basis: legal obligation)

4. Data Retention: How Long We Keep Your Information

We don't keep your data forever. Here are our retention periods:

  • Contact form submissions: 2 years from last contact, then deleted
  • Newsletter subscribers: Until you unsubscribe, then deleted within 30 days
  • Client project data: Duration of engagement plus 3 years (for warranty and legal purposes), then securely deleted or returned to you
  • Financial records: 7 years as required by Spanish tax law
  • Website analytics: 14 months (anonymized data)

You can request early deletion at any time, except where we have legal obligations to retain data.

5. Who We Share Data With

We do not sell your data. Ever. We only share information with:

  • Google Analytics: Anonymous website usage data (you can opt out via cookie settings)
  • Cal.com: When you book meetings through our calendar system
  • Email service providers: To send newsletters you've subscribed to
  • Cloud hosting: Our website and data are hosted on secure, GDPR-compliant infrastructure
  • Legal authorities: Only when required by law, and we'll notify you unless legally prohibited

All service providers are bound by data processing agreements and must meet our security standards.

6. Data Security

We implement strong technical and organizational measures to protect your data: encrypted connections (HTTPS) for all data transmission, secure cloud infrastructure with regular security audits, access controls limiting who can see your information, regular backups and disaster recovery procedures. While no system is 100% secure, we take every reasonable precaution. If we ever experience a data breach affecting your personal information, we will notify you within 72 hours as required by GDPR.

7. Your Rights

You have significant rights over your data. Here's what you can do:

  • Access: Request a copy of all personal data we hold about you
  • Correction: Ask us to fix any inaccurate information
  • Deletion: Request we delete your data (the "right to be forgotten")
  • Portability: Receive your data in a machine-readable format
  • Object: Stop us from processing your data for marketing or based on legitimate interests
  • Restrict: Limit how we use your data while disputes are resolved
  • Withdraw Consent: Change your mind about any consent-based processing at any time

To exercise any right, email connect@sabemos.ai. We'll respond within 30 days (usually much faster). These rights are free to exercise.

8. Cookies

Our website uses minimal cookies:

  • Essential cookies: Required for the website to function. Cannot be disabled.
  • Analytics cookies: Help us understand how visitors use our site. Only set with your consent.

You can manage your cookie preferences through our cookie banner or your browser settings. The site works fine without analytics cookies.

9. International Transfers

Our primary data processing occurs within the European Economic Area (EEA). Some service providers (like Google Analytics) may process data outside the EEA. When this happens, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

10. Children's Privacy

Our services are designed for businesses and professionals. We do not knowingly collect personal information from anyone under 16 years of age. If we learn we have collected such information, we will delete it promptly.

11. Changes to This Policy

We may update this policy to reflect changes in our practices or legal requirements. Material changes will be highlighted at the top of the page and, for existing clients, communicated via email. The "Last updated" date will always reflect the current version.

12. Questions or Complaints

We want to resolve any concerns directly. Please contact us first at connect@sabemos.ai. If you're not satisfied with our response, you have the right to lodge a complaint with the Spanish Data Protection Authority (Agencia Española de Protección de Datos) or your local supervisory authority.

Email: connect@sabemos.ai

We typically respond to privacy requests within 48 hours.