1. Home
  2. Privacy Policy

Privacy Policy

Data Controller

The controller responsible for the processing of personal data on this website is:

kurt creative S.L.
Calle Princesa 31
Planta 2, Puerta 2
28008 Madrid
Spain

Represented by its sole administrator (Administrador único):
Kurt Woischytzky

Phone: +34 614 482 484
Email: office@kurtcreative.com

Last updated: September 9, 2026

General Information on Data Processing

We process personal data exclusively in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR), Spanish data protection law including Organic Law 3/2018 (LOPDGDD), and, where applicable, other relevant privacy, telecommunications, and electronic communications laws.

Personal data means any information relating to an identified or identifiable natural person. This may include, for example, your name, email address, telephone number, IP address, contractual and order information, as well as content that you provide to us through forms, email, messaging services, uploads, or other communication channels.

Depending on the processing activity, we rely in particular on the following legal bases:

  • Art. 6(1)(a) GDPR where you have given us your consent;
  • Art. 6(1)(b) GDPR where processing is necessary for the performance of a contract or in order to take steps at your request prior to entering into a contract;
  • Art. 6(1)(c) GDPR where processing is necessary for compliance with a legal obligation;
  • Art. 6(1)(f) GDPR where processing is necessary for the purposes of our legitimate interests or those of a third party, provided that your interests or fundamental rights and freedoms do not override those interests.

Customer, Contract, and Contact Data

In connection with the initiation and performance of business relationships, we may process, in particular, names, company and address information, email addresses, telephone numbers, contractual information, purchased or ordered services, payment and invoice information, and communication content.

The primary legal basis is Art. 6(1)(b) GDPR. Where data must be retained in order to comply with legal obligations, processing is based on Art. 6(1)(c) GDPR.

Usage and Technical Data

When you visit and use our website, technical data may be processed. This may include your IP address, date and time of access, pages and files accessed, referrer information, browser type, operating system, device information, and similar technical data.

This data is processed in particular in order to provide the website technically, ensure its security and stability, analyze errors, and prevent misuse or attacks.

Hosting

Hetzner Online GmbH

Our website and parts of our technical infrastructure are hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.

In this context, Hetzner may process technical connection and server data as well as other data stored or transmitted through the infrastructure provided by Hetzner.

We have entered into a data processing agreement with Hetzner pursuant to Art. 28 GDPR or use the contractual data processing terms provided by Hetzner for this purpose.

The legal basis for this processing is Art. 6(1)(f) GDPR. Our legitimate interest is the secure, stable, and efficient provision of our website and IT infrastructure. Where processing is necessary for the performance of a contract or pre-contractual measures, Art. 6(1)(b) GDPR also applies.

Data Retention

We generally retain personal data only for as long as necessary for the respective processing purpose.

Data may be retained for a longer period where statutory retention obligations apply or where continued storage is necessary for the establishment, exercise, or defense of legal claims.

Business records may in particular be subject to commercial, tax, and accounting retention obligations under Spanish law. Depending on the type of document, business records and supporting documentation may have to be retained for several years, in particular for periods of up to six years.

Once the applicable purpose no longer exists and any statutory retention or limitation periods have expired, personal data will be deleted or anonymized.

Our website uses cookies and, where applicable, comparable technologies such as local storage, pixels, tags, or similar mechanisms.

Technically necessary technologies are used where required to provide features expressly requested by you, ensure website security, or store your privacy and cookie preferences.

Non-essential technologies – in particular those used for analytics, marketing, conversion measurement, affiliate tracking, or loading certain external media – are generally activated only after you have provided prior consent through our consent management system.

The legal basis for consent-based processing is in particular Art. 6(1)(a) GDPR and, with regard to storing or accessing information on your device, Art. 22(2) of the Spanish LSSI and, where applicable, other relevant national laws.

You can change your decision or withdraw previously granted consent at any time with effect for the future:


Change Cookie Settings or Withdraw Consent

We use Borlabs Cookie, provided by Borlabs GmbH, Hamburger Str. 11, 22083 Hamburg, Germany, to manage and document your cookie and privacy preferences.

Borlabs Cookie stores your choices in a technically necessary cookie. This may include the cookie duration and version, website domain and path, your consent choices, and a randomly generated UID.

The UID stored in the consent cookie is used for the technical assignment of the consent decision. Visitor data itself is not transmitted to Borlabs GmbH solely through the operation of the Borlabs Cookie consent tool.

The legal basis for using the consent management system is Art. 6(1)(c) GDPR in connection with our legal documentation and information obligations, as well as Art. 6(1)(f) GDPR based on our legitimate interest in legally compliant and user-friendly consent management.

Consent and Withdrawal

Where processing is based on your consent, providing that consent is voluntary.

You may withdraw your consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Consent relating to cookies, analytics, marketing, and external media services may in particular be changed through the cookie settings linked above.

Recipients and Disclosure of Data

Disclosure to Third Parties and Processors

Personal data is disclosed to third parties only where there is a valid legal basis for doing so.

This may include service providers that we use for hosting, IT infrastructure, communications, payment processing, automation, analytics, marketing, cloud services, or the delivery of our services.

Where service providers process personal data exclusively on our behalf, we enter into data processing agreements pursuant to Art. 28 GDPR where required.

International Data Transfers

Some of the service providers we use are located outside the European Economic Area or have affiliated companies outside the European Economic Area.

Personal data is transferred to third countries only where the requirements of Art. 44 et seq. GDPR are met. Transfers may in particular be based on an adequacy decision by the European Commission, including the EU-US Data Privacy Framework for appropriately certified U.S. companies, or on the European Commission’s Standard Contractual Clauses and, where appropriate, supplementary safeguards.

Your Data Protection Rights

Subject to the applicable statutory requirements, you have in particular the right to access your personal data, rectify inaccurate data, request deletion or restriction of processing, and – where the legal requirements are met – receive your data in a portable format.

Rectification, Deletion, and Restriction

You may request the correction of inaccurate personal data or the completion of incomplete personal data.

You may also request deletion of your personal data where there is no legal basis requiring further retention. Under the statutory conditions, you may additionally request restriction of processing.

Right to Object

Where we process personal data on the basis of Art. 6(1)(f) GDPR, you may object to such processing at any time on grounds relating to your particular situation.

Where personal data is processed for direct marketing purposes, you may object to such processing at any time without having to provide reasons.

Data Portability

Where processing is based on your consent or a contract and carried out by automated means, you may, under the statutory conditions, request that we provide the relevant personal data in a structured, commonly used, and machine-readable format or transmit it to another controller.

Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority.

The supervisory authority particularly responsible for us is:

Agencia Española de Protección de Datos (AEPD)
Edificio Cuzco IV
Paseo de la Castellana 141, Floor 9
28046 Madrid
Spain

Independently of this, under Art. 77 GDPR you may also lodge a complaint with a supervisory authority in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.

Direct Marketing

We generally send electronic marketing communications only where there is a valid legal basis.

This may in particular be your prior consent. In the case of existing customers, marketing of our own similar products or services may also be permitted under the applicable statutory requirements.

You may object to the use of your personal data for direct marketing at any time. Newsletters and other electronic marketing communications also include an easy way to unsubscribe.

Contact by Email, Telephone, or Other Electronic Communication

If you contact us by email, telephone, messaging service, or another electronic communication channel, we process the data you provide as well as the content of your inquiry.

Where the communication relates to the initiation or performance of a contract, processing is based on Art. 6(1)(b) GDPR.

For other inquiries, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is efficient communication with prospective customers, clients, business partners, and other persons contacting us.

Data Submitted Through Our Website

SSL/TLS Encryption

Our website uses an encrypted HTTPS connection. This helps protect data transmitted through our website against unauthorized access by third parties during transmission.

Contact Forms

General Contact Form

If you use a contact form on our website, we process the information you enter in order to handle your inquiry and, where applicable, related follow-up communication.

For inquiries related to a contract, the legal basis is Art. 6(1)(b) GDPR. For other contact requests, processing is based on Art. 6(1)(f) GDPR.

Quote Requests

If you request a quote through our website, we process the contact, company, and project information you provide in order to assess your request, prepare a quotation, and communicate with you about the requested service.

The legal basis is Art. 6(1)(b) GDPR.

Callback Requests

If you request a callback, we process in particular your name, telephone number, and, where applicable, your email address and any other information provided by you in order to carry out the requested callback.

The legal basis is Art. 6(1)(b) or Art. 6(1)(f) GDPR depending on the nature of your request.

Job Applications

If you apply for a position with us, we process the application and contact information you provide for the purpose of carrying out the recruitment and selection process.

This may include, in particular, your name, contact information, CV, educational and professional information, qualifications, work samples, and any other information voluntarily provided by you.

The legal basis is in particular Art. 6(1)(b) GDPR with regard to pre-contractual measures related to a potential employment relationship. Where legal obligations apply, Art. 6(1)(c) GDPR may also apply.

If no employment relationship is established, we generally delete application data after completion of the recruitment process once the data is no longer required for the defense of possible legal claims. Longer retention for future vacancies will take place only where an appropriate legal basis exists, in particular your consent.

Registrations and User Accounts

If you create a user account on our website or register for a restricted area, we process the registration, contact, and usage data required for this purpose.

The legal basis is generally Art. 6(1)(b) GDPR.

Webinar Registrations

When you register for a webinar, we process the contact information required to organize and conduct the webinar and to send necessary organizational and content-related information.

Marketing communications beyond the specific webinar are sent only where a separate legal basis exists.

Member Area

Where we provide a member area, we process the registration, contractual, and usage data required to provide access and the agreed functionality.

Courses

When you register for one of our courses, we process the contact, contractual, and, where applicable, progress and usage data required to provide and conduct the course.

Online Shop and Customer Account

We use WooCommerce, operated within our WordPress installation, for functions of our online shop.

In connection with orders, we process in particular your name, billing and, where applicable, shipping address, email address, products or services ordered, prices, payment status, and other information required to process the contract.

The legal basis is Art. 6(1)(b) GDPR. Invoice and accounting data that must be retained by law is stored on the basis of Art. 6(1)(c) GDPR.

The payment providers we use are described separately below.

Newsletter and Email Marketing

Newsletter

We use FluentCRM to manage newsletters, contacts, and email automations. FluentCRM is operated as a WordPress plugin on our own website and server infrastructure. Contact, list, campaign, and automation data managed in FluentCRM is therefore generally stored in our own WordPress database or infrastructure and is not transmitted to the plugin developer solely through our use of FluentCRM.

We generally use a double opt-in process for newsletter subscriptions. We store the registration and subsequent confirmation in order to document the consent provided.

The legal basis for sending newsletters is generally your consent pursuant to Art. 6(1)(a) GDPR.

You can unsubscribe from the newsletter at any time using the unsubscribe link included in each message or by contacting us informally.

Where we analyze personalized newsletter open or click statistics, this is done only where a sufficient legal basis exists. Any consent granted for such analysis may be withdrawn at any time with effect for the future.

Our email and server infrastructure may additionally be used to send the actual emails. Where additional service providers are involved, the corresponding sections of this Privacy Policy also apply.

Social Media

Our website contains links to our profiles on various social media platforms.

Normal external links do not automatically establish a connection to the respective social media platform merely because you visit our website. Only when you click such a link do you leave our website, and the relevant platform provider may process personal data.

We link to our presence on Instagram. For users in the European Economic Area, the provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

When you click the link, Meta’s and Instagram’s respective privacy policies and terms apply.

We link to our presence on LinkedIn. For users in the European Economic Area, the provider is LinkedIn Ireland Unlimited Company, Dublin, Ireland.

When you click the link, LinkedIn may process data and may also transfer data to affiliated companies outside the European Economic Area.

We link to our presence on TikTok. For users in the European Economic Area, TikTok Technology Limited in Ireland and TikTok Information Technologies UK Limited are in particular involved in providing the platform service.

When you click a TikTok link, TikTok’s applicable privacy terms apply.

We use WhatsApp Business to communicate with prospective customers, clients, and business partners. For users in the European Economic Area, the service is provided in particular by WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

If you contact us through WhatsApp, your telephone number, profile information, communication metadata, and the content you send may be processed.

The legal basis is Art. 6(1)(b) GDPR for contract-related communication and Art. 6(1)(f) GDPR for other business communication.

Personal messages and calls through WhatsApp are generally protected by end-to-end encryption. Independently of this, WhatsApp processes various technical and usage data.

We link to our YouTube channel. The service is provided by Google; for users in the European Economic Area, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, is in particular responsible.

More detailed information about processing carried out in connection with our own social media profiles is provided in our separate Privacy Policy for Social Media Channels.

External Media

YouTube Videos

We embed videos from YouTube on our website.

YouTube content is blocked through our consent management system and is generally loaded only after you have consented to the relevant category or service.

Only after you provide consent is a connection established to servers operated by Google or YouTube. In this context, your IP address, device and browser information, information about the page accessed, and other usage data may be processed.

If you are simultaneously logged into your Google or YouTube account, Google may be able to associate the visit with your user account.

The legal basis for loading embedded YouTube content is your consent pursuant to Art. 6(1)(a) GDPR.

You may withdraw your consent at any time through our cookie settings.

Google Services

Google Analytics 4

We use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics enables us to analyze how our website is used. This may include information about page views, sessions, interactions, scrolling, clicks, downloads, devices and browsers used, approximate geographic information, and other usage data.

Google Analytics is activated only after you have provided prior consent to the relevant processing.

The legal basis is Art. 6(1)(a) GDPR.

Google uses IP addresses, among other things, to determine an approximate geographic region. For users in the European Economic Area, IP addresses are not logged or permanently stored in Google Analytics after the processing required for this purpose.

Google may also process data outside the European Economic Area. Where personal data is transferred to the United States, such transfers may in particular be based on the EU-US Data Privacy Framework or other appropriate safeguards.


Disable Google Analytics or Change Cookie Settings

Google Ads

We use Google Ads to advertise our services through Google’s advertising network and to measure the effectiveness of our advertising activities.

Where cookies, local storage technologies, or other tracking mechanisms are used for this purpose, they are activated only after you have provided consent.

The legal basis is Art. 6(1)(a) GDPR.

Google Ads Conversion Tracking

Google Ads Conversion Tracking enables us to measure whether users perform specific actions on our website after interacting with one of our advertisements, for example submitting an inquiry, registering, or placing an order.

This may involve processing information relating to the advertisement, website visit, completed conversion, device information, and cookie or other pseudonymous identifiers.

Conversion tracking is activated only after the relevant consent has been provided. The legal basis is Art. 6(1)(a) GDPR.

We use Google’s designated consent and consent-mode signals where required for the Google services we use.

Google Workspace

We use Google Workspace and related Google Cloud services for business communications, email, calendars, documents, spreadsheets, presentations, file sharing, and, where applicable, video and audio communications.

The contractual entity for relevant Google Cloud services in the European Economic Area may in particular be Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland.

In connection with these services, contact and communication data, documents, files, contractual information, calendar information, and other content processed by us within the relevant services may be processed.

The legal basis is, depending on the context, Art. 6(1)(b) or Art. 6(1)(f) GDPR and, where processing is legally required, Art. 6(1)(c) GDPR.

Where Google acts as a processor, the applicable data processing terms agreed with Google apply.

Audio and Podcasts

Spotify Embeds

We may embed audio content provided by Spotify AB, Regeringsgatan 19, 111 53 Stockholm, Sweden.

Where embedded Spotify content establishes a connection to Spotify, such content is generally loaded only after you provide the relevant consent through our consent management system.

After activation, Spotify may receive information such as your IP address, browser and device information, the page accessed, and other usage data. If you are logged into Spotify, Spotify may be able to associate the visit with your user account.

The legal basis for activation is Art. 6(1)(a) GDPR.

Google Reviews via Trustindex

We use Trustindex to display publicly available Google reviews on our website. The provider is Trustindex Ltd., Nyari Pal utca 15, 2724 Ujlengyel, Hungary.

The reviews displayed may contain, in particular, the reviewer’s name or display name, profile image, review text, star rating, and date of the review, to the extent that such information is publicly available on the relevant review platform.

When external Trustindex content is loaded, technical information such as your IP address, browser and device information, and information about the website accessed may be transmitted to Trustindex and, where applicable, other integrated services.

We therefore load external Trustindex content only after the relevant consent has been provided through our consent management system, where the specific integration establishes a connection to external Trustindex or Google servers.

The legal basis for such external connections is Art. 6(1)(a) GDPR. Our interest in displaying customer reviews and transparently informing visitors about experiences with our services also constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR.

Security and Anti-Spam Services

Google reCAPTCHA

Where we use Google reCAPTCHA on individual forms, the service is intended to protect our website against automated submissions, spam, and abusive access.

This may involve processing, in particular, your IP address, browser and device information, date and duration of access, and information about user interactions.

Where the specific implementation of reCAPTCHA involves storing or accessing non-essential information on your device or further transmitting personal data to Google, the service is activated only after you have provided the relevant consent.

The legal basis in such cases is Art. 6(1)(a) GDPR.

Payment Providers

PayPal

If you choose PayPal as your payment method, the data required to process the payment is transmitted to PayPal.

For users in the European Economic Area, the provider is in particular PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg.

The data transfer is necessary in order to process the payment requested by you. The legal basis is Art. 6(1)(b) GDPR.

PayPal also processes certain data relating to payment processing, fraud prevention, and compliance with its own legal obligations under its own responsibility as a data controller.

Stripe

If you use a payment method provided through Stripe, the data required to process the payment is transmitted to Stripe.

For accounts outside North and South America, the relevant contractual entity is in particular Stripe Payments Europe, Limited in Ireland.

Depending on the specific processing activity, Stripe may process personal data both as a processor acting on our behalf and as an independent controller.

The legal basis for processing required to carry out the payment is Art. 6(1)(b) GDPR.

Cloud, Database, and IT Infrastructure

Self-Hosted Supabase

We use Supabase in a self-hosted installation for certain database and backend functions.

The relevant Supabase instance is operated on our own or otherwise controlled server infrastructure. Personal data is therefore not transmitted to Supabase Inc. or the provider of the managed Supabase cloud service solely as a result of our use of the Supabase software.

Our self-hosted Supabase installation is used in particular for the structured storage and processing of data required for our web applications, automations, and digital services.

The legal basis for processing carried out within this infrastructure depends on the original purpose of the respective data processing and may in particular be Art. 6(1)(b), (c), or (f) GDPR.

Amazon Web Services

Where we use Amazon Web Services (AWS) for individual technical functions or services, personal data may be processed within AWS infrastructure.

For customers in the European Economic Area, Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg, is in particular involved in the contractual relationship.

The categories of personal data processed depend on the relevant AWS service and may include technical data, files, communications, or business information.

Where AWS acts as a processor, processing takes place on the basis of the applicable data processing terms agreed with AWS.

Other Services We Use

n8n

We use n8n to automate processes and connect different internal systems and external services.

For this purpose, we use n8n Cloud, provided by n8n GmbH, Novalisstr. 10, 10115 Berlin, Germany.

Depending on the relevant workflow, n8n may process and transmit between connected systems data including contact information, customer information, project information, order information, content data, and communication data.

n8n Cloud currently stores its cloud data within the European Union. Cloud infrastructure for European customers is operated within the EU, including in Frankfurt.

We use n8n only for workflows for which an appropriate data protection legal basis exists. Depending on the processing, this basis may in particular be Art. 6(1)(b) GDPR for performing contracts or taking pre-contractual measures, or Art. 6(1)(f) GDPR based on our legitimate interest in efficient, secure, and automated business processes.

Where n8n processes personal data on our behalf, the processing is governed by a data processing agreement.

Where an n8n workflow accesses other external service providers, the corresponding sections of this Privacy Policy regarding those providers also apply.

OpenAI

We use services provided by OpenAI for certain AI-powered functions, automations, and, where applicable, our chatbot.

For customers in the European Economic Area, the business relationship is provided in particular through OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland.

Depending on the relevant feature, text, requests, document content, or other information required for the relevant workflow may be transmitted to OpenAI.

We use OpenAI only for data whose processing is permitted for the relevant purpose and, where possible, limit transmitted information to what is necessary.

Data processed through the OpenAI business or API services used by us is not used by OpenAI by default to train its general models unless an explicit opt-in or other authorization is provided.

The legal basis is, depending on the relevant application, Art. 6(1)(b) or Art. 6(1)(f) GDPR. Where specific consent is required, processing is based on Art. 6(1)(a) GDPR.

Data may also be processed in the United States. Applicable international transfer mechanisms, including adequacy decisions and Standard Contractual Clauses, apply where required.

AssemblyAI

We use the AssemblyAI API for certain transcription and speech-recognition functions. The provider is AssemblyAI, Inc., 169 Madison Ave, STE 38365, New York, NY 10016, USA.

Where audio or video content is processed through AssemblyAI, the data transmitted may include audio recordings, voices, spoken content, transcripts, timestamps, speaker assignments, and other technical information required to perform the transcription.

AssemblyAI generally processes such customer data under its contractual data protection terms as a processor or subprocessor. For certain account and usage data, AssemblyAI may act as an independent controller.

The legal basis for processing initiated by us is, depending on the context, Art. 6(1)(b) GDPR where transcription forms part of a service requested by you, or Art. 6(1)(f) GDPR for internal business processing.

AssemblyAI is based in the United States. Transfers of personal data from the European Economic Area may in particular rely on the EU-US Data Privacy Framework and the Standard Contractual Clauses provided for in AssemblyAI’s Data Processing Addendum.

We transmit only the content required for the relevant transcription task and take available data minimization, retention, and deletion options into account when configuring the service.

Publitio

We may use Publitio to provide or embed media content. The provider is Publitio, based in Novi Sad, Serbia.

Where embedded Publitio content establishes a connection to the provider’s servers, such content is generally loaded only after you have provided the relevant consent through our consent management system.

After activation, your IP address, browser and device information, and information about the page accessed may be transmitted to Publitio.

The legal basis is Art. 6(1)(a) GDPR.

As Serbia is not part of the European Economic Area, any necessary transfer of personal data takes place only in accordance with Art. 44 et seq. GDPR, in particular on the basis of appropriate contractual safeguards.

SliceWP and Affiliate Tracking

We use SliceWP to manage our affiliate program.

If you visit our website through an affiliate link, SliceWP may store an affiliate or referral identifier so that a later purchase can be attributed to the referring affiliate.

SliceWP is operated within our WordPress installation. Referral information is therefore generally associated with orders within our own website infrastructure.

Because affiliate tracking is not necessary for the basic operation of our website, the relevant tracking is activated only after the required consent has been provided.

The legal basis is Art. 6(1)(a) GDPR.

Changes to this Privacy Policy

We may update this Privacy Policy if our website, the services we use, our processing activities, or applicable legal requirements change.

The current version will be published on this website. Previously granted consent will not be retroactively changed merely because this Privacy Policy is updated.