Website:
Version: 1.0 — October 2026
Language: English
Published site pages: /en/privacy (this page) · /it/privacy (Italian)
LEVEL 1 — Short notice (forms / email)
Controller: Snow Inch S.L. · Tax ID (CIF) B75514133 · C.C San Agustin - Calle las Dalias, 12, Floor 5, Unit 340, 35100 San Bartolomé de Tirajana (Las Palmas), Spain ·
Purposes: to reply to your request and, if we work together, to manage the contract and billing.
Legal bases: pre-contractual steps / performance of a contract (Art. 6.1.b GDPR); legal obligations (Art. 6.1.c); legitimate interest for security and B2B follow-up with contacts who wrote to us (Art. 6.1.f), with a right to object; consent (Art. 6.1.a) for non-essential cookies and optional purposes.
Recipients: we do not sell personal data. We may use providers that help us deliver the service (hosting/cloud, email/CRM/billing/payments, analytics if enabled, logging/support, AI providers), under Art. 28 GDPR contracts.
Rights: access, rectification, erasure, objection, restriction, portability (where applicable), and withdrawal of consent. Email
Full notice:
Cookies: Cookie policy linked in the site footer (or /en/cookie if you publish a first-party page).
LEVEL 2 — Full privacy notice
1. Who the controller is
| Controller | Snow Inch S.L. (“Snowinch”, “we”) |
| CIF | B75514133 |
| Registered office | C.C San Agustin - Calle las Dalias, 12, Floor 5, Unit 340, 35100 San Bartolomé de Tirajana (Las Palmas), Spain |
| Privacy / rights email | |
| Web | |
| DPO | Not appointed |
We process personal data under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Depending on the context we may act as:
- Controller (corporate website, our own B2B clients, Snowinch-branded products);
- Processor when we build or operate white-label software on behalf of a client, under an Art. 28 GDPR agreement. In that case the notice to data subjects is mainly provided by the client as controller.
2. Scope
This notice covers:
- the website
https://www.snowinch.com (including /it and /en pages); - commercial relationships with B2B clients and prospects;
- Snowinch-branded products and apps that link to this page;
- related support channels.
It does not replace client notices when Snowinch acts only as a processor.
3. Purposes and legal bases
| Purpose | Basis | Typical data |
|---|---|---|
| Reply to email / forms / contact requests | Art. 6.1.b / 6.1.f | Name, email, message, company |
| Contract, billing, client administration | Art. 6.1.b and 6.1.c | Contacts, tax data, banking details if needed |
| Snowinch products with user accounts | Art. 6.1.b; 6.1.f (security) | Account, technical usage, support |
| Strictly necessary technical cookies | Art. 6.1.f / service delivery | Technical identifiers |
| Analytics / marketing cookies | Art. 6.1.a (consent) | Cookies / IDs |
| Newsletter / direct marketing | Only if enabled: consent Art. 6.1.a and/or 6.1.f + LSSI | |
| Security, logs, abuse prevention | Art. 6.1.f | Logs, IP, metadata |
| AI features in products | Art. 6.1.b and/or 6.1.a | Content/prompts that may include personal data |
| Legal obligations | Art. 6.1.c | Data required by law |
Automated decisions: we do not make solely automated decisions that produce legal or similarly significant effects (Art. 22 GDPR).
4. Source of data
- From you (email, forms, contract, support, account).
- From your company if you are a B2B contact.
- Generated by use of the service (logs, technical events).
If data are required for a contract or a legal obligation and you do not provide them, we may be unable to deliver the service.
5. Recipients and providers (categories)
We may disclose data to:
- Public authorities where required by law.
- Providers / processors (Art. 28 GDPR), by category:
- Hosting / cloud in the EEA and/or outside the EEA (e.g. Vercel, Netlify, AWS, GCP, Azure, Hetzner, OVH) depending on the project.
- Email / CRM / billing / payments when enabled.
- Analytics if enabled (e.g. Google Analytics or privacy-first alternatives); non-essential cookies only with consent.
- Support / logging / APM depending on the project.
- AI: model APIs (e.g. OpenAI, Anthropic, Google Gemini or others), preferring no-training / minimal retention options when available.
- Advisors (tax, legal, etc.) bound by confidentiality.
We do not sell personal data. A detailed list of sub-processors is kept up to date internally and provided to clients/authorities on request.
6. Transfers outside the EEA
Some providers may process data outside the European Economic Area. When that happens we use: an adequacy decision; Standard Contractual Clauses (SCCs) and supplementary measures if needed; or the EU-US Data Privacy Framework if the recipient is certified.
For details:
7. Retention
| Processing | Criterion |
|---|---|
| Contacts / web enquiries | 12 months from the last useful contact, unless you object or a contract starts |
| Contract / billing | Duration of the relationship + legal retention periods (in Spain typically up to 6 years) |
| Snowinch product user accounts | While the account is active; after closure, deletion or anonymisation within 30 days, unless a legal obligation applies |
| Technical logs | 30–90 days, unless needed for a security investigation |
| Newsletter (if enabled) | Until unsubscribe / withdrawal |
| AI prompts / logs with personal data | Minimum necessary; as a rule no longer than 30 days if not required for the service |
8. Your rights
You may exercise access, rectification, erasure, objection, restriction and, where applicable, portability, and withdraw consent at any time (without affecting prior lawfulness).
How: email
You may also complain to the AEPD:
9. Security
We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR): TLS in transit, access control, secrets management, backups, least privilege, contracts with providers. No system is 100% secure: if you suspect an incident, email
10. Artificial intelligence
Some products or services may use AI features.
- We send to the AI provider only the data needed for the feature.
- Where possible we enable no training / limited retention options.
- If you are a B2B client and Snowinch processes data as a processor via AI, the contract / DPA and your instructions apply.
Do not enter specially protected or confidential data into AI features unless the product and contract allow it.
11. Children
Our corporate B2B services are not directed at children under 14 (LOPDGDD). If we detect a child's data without an adequate legal basis, we delete it.
12. Cookies
We use cookies and similar technologies. Non-essential ones only with your consent. Types and controls: Cookie policy linked in the site footer (currently via iubenda) and/or a dedicated cookie page when published.
Google Analytics (measurement) is active on the site with a default consent setting of denied until you accept.
13. Social media and third-party links
If you interact with our social profiles, those platforms' privacy policies apply. This notice does not cover third-party sites linked from snowinch.com.
14. Changes
We may update this page. The current version is the one published here, with the date below. For material changes we update the page (and, if useful, a notice on the site).
Last updated: October 2026.
15. Contact
Email:
Post: C.C San Agustin - Calle las Dalias, 12, Floor 5, Unit 340, 35100 San Bartolomé de Tirajana (Las Palmas), Spain
