Privacy Policy
Last updated: May 17, 2025
1. Data Controller and Data Protection Officer (DPO)
HIFICafe (owner: Josep Maria Marimon Soler, sole proprietor with NIF 38129834C, Passatge Borrell 1 3-3, 08005 Barcelona, Spain) is the data controller for personal data collected through the platform.
Controller's contact email: legal@hificafe.org
A Data Protection Officer has been appointed, whom you can contact at: dpo@hificafe.org
2. Personal data we process
| Category | Examples | Source |
|---|---|---|
| Identification | name, surname, ID number, email address | provided by the user |
| Credentials | bcrypt-hashed password | provided |
| Profile data | alias, photo, audio preferences | provided |
| Generated content | comments, ratings, listings, multimedia files | provided |
| Usage data | IP, logs, clicks, time on page, A/B links voted | collected automatically |
| Technical data | device type, OS, browser, cookies | collected automatically |
| Transaction data | payment history, account type | generated by the platform |
3. Purposes and legal bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Account registration and management | Performance of a contract (6.1.b) |
| Provision of comparative voting and publication services | Performance of a contract (6.1.b) |
| Own advertising and newsletters | Explicit consent (6.1.a) |
| Fraud prevention and security | Legitimate interest (6.1.f) |
| Statistical analysis and product improvement | Legitimate interest (6.1.f) |
| Compliance with legal obligations (invoicing, Spanish Information Society Law) | Legal obligation (6.1.c) |
4. Recipients and international transfers
Data may be shared with:
- EU cloud infrastructure providers (hosting, CDN).
- Payment processors within the EEA.
- Analytics and emailing providers located in the USA under Standard Contractual Clauses 2021.
We do not sell or rent personal data.
5. Data retention
- Account data: while you are a user + 5 years (statute of limitations under Spanish Information Society Law).
- Traffic records: 1 year (Art. 7 Spanish Information Society Law).
- Tax documentation: 6 years (Art. 30 Spanish Commercial Code).
- Cookies: see duration table in the Cookie Policy.
6. Automated decisions and profiling
A/B votes generate an audio equipment ranking. The algorithm weights each user's responses to show collective rankings. No decisions with significant legal effects are made solely based on such profiling.
7. User rights
You may exercise access, rectification, erasure, objection, restriction, portability, and withdrawal of consent by sending an email to legal@hificafe.org.
You have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
8. Minors
We do not accept users under 14 years of age. Persons aged 14 to 17 must have parental consent when the activity requires it.
9. Security
We apply TLS 1.3 encryption, bcrypt 12-round password hashing, encrypted backups, and role-based access controls.
10. Changes to the policy
We will publish any changes with the "Last updated" date.
