Skip to content

What we do with your data, in plain language

We sell systems that handle other people's data. A studio that is vague about its own is not worth trusting with yours, so this page is written to be read rather than to be survived.

The short version. You can use this whole website without telling us anything. If you write to us, we use what you send to answer you and to scope the work, and nothing else. If you ask for the open source repos, we use your email to send them. If you also tick the box for updates, we send you about one email a month, and only then. We do not sell your data, and we delete it when it has stopped being useful to either of us.

GDPR and spanish law Updated 5 October 2026 English and spanish

~17 min read

Who is responsible for it

The data controller is the person behind AEIA Studios.

Trading name: AEIA Studios Legal person: Boris Griggs NIF: Y4826126G Address: 67 Cortijuelo, Villanueva del Trabuco, 29313, Malaga, Spain Email: hi [at] aeia.dev Telephone: +34 671 229 475

We have not appointed a data protection officer. A business of our size doing what we do is not required to have one, and pretending otherwise would be theatre. Write to hi [at] aeia.dev and a person answers.

The full entity details are on the legal notice.

What we collect, and why

Four situations. That is the whole list.

  1. You email or phone us

    What: whatever you send, plus your address or number, plus what we write back. There is no contact form: you write from your own mail app.

    Why: to answer you, to have the conversation, to remember it and, if you decide to go ahead, to scope the work.

    On what legal basis: if you are asking about working with us, this is a step taken at your request before a contract, which is the basis in Article 6(1)(b) of the GDPR. If you are writing about something else, we rely on our legitimate interest in running our own inbox, Article 6(1)(f): in plain words, we need to read, sort and answer what people send us. Either way you can tell us to delete it and we will.

    How long: two years after the last message if the enquiry goes nowhere, which covers any question or dispute about it. If it turns into work, it is kept for as long as we work together and then for 6 years, only for legal claims and for tax and accounting records, with access restricted. The table below has the detail.

  2. You ask for the repos

    What: your email address and which repos you picked (Motion, Router, Harness; at least one). To keep the form safe from abuse we also use your IP address, but we store it only as a salted hash and delete that after 24 hours. The form sets no cookies.

    Why: to send you the links to the repos you picked. That mail carries nothing else, no promotion.

    On what legal basis: your request, which is the basis in Article 6(1)(b) of the GDPR. Picking at least one repo and sending the form is what starts it. The IP address hash is different: we use it on the basis of our legitimate interest in keeping the form safe from abuse, Article 6(1)(f) of the GDPR. We keep it for 24 hours only.

    How long: 12 months from the request, so we can answer your questions about what we sent.

  3. You tick the box for updates

    What: your email address, and a record that you agreed: the time, the version of the form, the language, and the exact words next to the box.

    Why: to send you occasional updates by email, about one a month. Nothing is sent until you click the confirmation link in a first mail. If you never click it, you get nothing.

    On what legal basis: your consent, Article 6(1)(a) of the GDPR, and the Spanish law on electronic commerce (LSSI-CE), Articles 21 and 22. The box is never ticked for you and never bundled with the repos. You can ask for the repos without it.

    How long: until you unsubscribe, which is one click in any update, or a reply saying stop. After that we keep only the proof of your consent for 90 days, so we can show we acted on what you chose. If you never click the confirmation link, we delete the request after 7 days.

  4. You only read the site

    What: almost nothing. We count pages viewed, where visitors arrived from, rough country, browser, operating system and screen width, using GoatCounter, an analytics service that sets no cookies and does not build a profile of you. We cannot tell who you are from it and we do not try. Your browser loads GoatCounter's counting script from GoatCounter's servers, so it does contact them when a page opens.

    GoatCounter is a hosted service, so GoatCounter keeps the counts, not us. It is run by Martin Tournoij in Ireland, and its data is stored on servers at Hetzner Online GmbH in Finland and Germany. We keep GoatCounter's per-pageview collection switched off, so it stores totals and not a record of each visitor, and we keep its language collection off too. It uses your IP address to work out your country but does not store it, and it stores nothing in your browser. To count a repeat visit once, it keeps your IP address and browser details in memory for up to eight hours, and not in its database. It says it shares no information with third parties.

    Separately, the web server keeps a log of requests, including IP addresses, which is how any web server works and what makes it possible to investigate an attack.

    On what legal basis: legitimate interest, Article 6(1)(f), in knowing whether the website works and in keeping it up.

    How long: our host, Infomaniak, keeps these logs for about a week (it sets the period, at least 7 days, and it cannot be changed), and we keep no copy of them.

How long we keep things

Short by default Longer only for work, the law and legal claims

WhatHow longWhy that long
An email enquiry that goes nowhereTwo years from the last message between usLong enough to cover a question or a dispute about it, short enough that we are not sitting on a filing cabinet of other people's business problems
A request for the repos12 months from the requestSo we can answer questions about what we sent
An updates request you never confirmed7 daysIf you never click the link, you get nothing and we keep nothing
Your email for updatesUntil you unsubscribeYou asked for them; you can stop them in one click
Proof of your consent to updates90 days after you unsubscribeSo we can show we did what you chose
The IP hash used against abuse24 hoursOnly to stop one source flooding the form
Work: mail with clients, and anything that becomes a contract, plus invoices and project filesFor as long as we work together, then 6 years, kept only for legal claims, tax and accounting records, with access restrictedPart of this the law sets for us, and the rest is so we can answer a claim about the work
Mail connected to a claim or dispute that is threatened or under wayUntil it is settled, then deleted on the normal clock aboveIf someone raises a claim, we need the history, and so might a court
Analytics: the counts held by GoatCounterGoatCounter states no fixed periodA count of how many people read a page is not about any one of them
Server logsAbout a week, set by our host; we keep no copySecurity, and nothing else

When a retention period ends, the record is deleted rather than archived somewhere quieter. For mail, the deletion happens in the mailbox itself, through an automated rule, so the periods above are carried out and not just promised. The one exception is the claim or dispute row: we do not delete mail that is connected to a claim or dispute that is threatened or under way until it is settled.

Who else touches it

Every provider that handles your details is named here, so here they are. Each one processes data on our instructions and is not allowed to use it for anything of its own.

Infomaniak Network SA hosts this website and our email, and it is where the repo requests and update sign-ups are stored, on our own hosting. It also sends the mail. So our mail provider handles anything you send to hi [at] aeia.dev, and the links and updates we send you. No other service sees what you give the repo form.

GoatCounter counts visits to this website for us, which makes it our processor for that. It is a cookieless analytics service, run by Martin Tournoij in Ireland, rather than a tool that sends your visit to an advertising company.

What we never do with it

We never sell it. Not to a data broker, not to a partner, not as part of anything.

We never send you updates you did not tick for. Writing to us or asking for the repos does not put you on any list. Updates need their own box, which is never pre-ticked, a click on a confirmation link, and unsubscribing is one click.

We never use it to advertise to you. There is no advertising pixel on this site and no audience being built from your visit.

We never make an automated decision about you. No scoring, no profiling, no software deciding whether you are worth a reply.

What you can make us do

These are your rights under the GDPR, written as what they get you.

  1. See it. Ask what we hold about you and we send you a copy.
  2. Correct it. If something is wrong, tell us and we fix it.
  3. Delete it. Ask and we delete it, unless the law requires us to keep a specific record, in which case we tell you which one and why.
  4. Pause it. Ask us to stop using it while a disagreement is sorted out.
  5. Take it. Ask for it in a format you can hand to someone else.
  6. Object. Where we are relying on our legitimate interest, tell us to stop and we will unless we have a reason we can defend.
  7. Change your mind. Where you gave consent, such as the box for updates, you can withdraw it in one click from any update email, or by writing to us, and that does not undo anything that was lawful before you withdrew it.

How. Email hi [at] aeia.dev. No template, no fee. Write "delete what you have on me" and that is a valid request.

How fast. Within one month. If it is complicated we will tell you inside that month and tell you how much longer it will take.

Proving who you are. If we cannot tell from your email that you are who you say you are, we will ask one question to check. That is to stop somebody else asking for your data, not to make it difficult.

If you think we have got this wrong

Tell us first. hi [at] aeia.dev, and a person who works here answers. We would rather fix it than be reported for it.

You can also complain to the Spanish data protection authority, the Agencia Española de Protección de Datos, at www.aepd.es. You do not have to come to us first, and complaining to them costs you nothing.

Three smaller things

Children. This site sells business services and is not aimed at children. We do not knowingly collect anything about anyone under 18. If you think we have, write to us and we will delete it.

Security. Access to what you send is limited to the people who work here and the processors named above. We do not describe our security arrangements in detail, because a published list of what protects something is also a list of what to get past.

Cookies. This site sets none, and it has its own page: the cookie policy.

Changes to this page

When we change it, the date at the top changes. If a change is significant, we say what changed rather than quietly reissuing the page and hoping nobody rereads it.

Tell us how your business runs

The work that takes most of your week is the place to start.