1. Data controller
Owner: José Enrique Ibarra
Website: ciberseguridad.joseenrique.es
Email: info@joseenrique.es
This site provides AI cybersecurity consulting services: security audits, Zero Trust strategy, AI-powered SOC and regulatory compliance (NIS2, DORA, GDPR).
2. Data we collect
2.1 Contact form and email
If you use the contact form or email us, we collect your name, email address and message content, used solely to respond to your enquiry.
2.2 AI assistant (chat widget)
🤖 Claude AI Assistant
- We do not store conversations in any of our own databases.
- Processed by Anthropic. Conversations are processed in real time via the Claude API (Anthropic, Inc., USA): anthropic.com/privacy
- Voice. Speech-to-text conversion is performed in your browser via the native Web Speech API, without sending audio to our servers.
- WhatsApp. If you tap the WhatsApp button, you will be redirected to Meta's app, subject to their own terms.
- Recommendation: Do not share passwords, bank details or sensitive information in the chat.
2.3 Google Fonts
This site loads fonts from Google Fonts (fonts.googleapis.com), which may result in Google logging your IP address. More info: policies.google.com/privacy
2.4 Analytics
Only if you accept analytics cookies, we use audience measurement tools to understand how the site is used. Data is anonymous and aggregated.
3. Legal basis for processing
- Contact: explicit consent when submitting the form (Art. 6.1.a GDPR)
- AI assistant: legitimate interest in user support (Art. 6.1.f GDPR)
- Analytics: consent via cookie banner (Art. 6.1.a GDPR)
- Google Fonts: legitimate interest in providing appropriate visual experience (Art. 6.1.f GDPR)
4. Data retention
- Contact: until the enquiry is resolved, maximum 2 years
- AI assistant conversations: not stored in our systems
- Analytics data: maximum 26 months depending on tool configuration
5. International transfers
Anthropic, Inc. is based in the United States. Data processing via the AI assistant involves an international transfer covered by EU Standard Contractual Clauses (Art. 46 GDPR).
6. Your rights
Under GDPR, you can exercise the following rights by emailing info@joseenrique.es with a copy of your ID:
- Access: find out what data we hold about you
- Rectification: correct inaccurate data
- Erasure: request deletion of your data
- Objection: object to processing
- Portability: receive your data in a structured format
- Restriction: request that we limit processing
You may also lodge a complaint with the Spanish Data Protection Agency (AEPD) or your local supervisory authority.
7. Changes to this policy
We may update this policy at any time. Substantial changes will be communicated via a notice on the website.
See also: Legal Notice · Cookie Policy