Privacy policy
How we collect, use and protect your personal data when you use YourWeb4Free.
Last updated:
1. Who is responsible for your data
The controller of the personal data collected through this service is:
- Legal entity
- Digiworks Spain, S.L.U.
- Company / tax number
- B54020219
- Registered address
- Avenida San Rafael 11, local 2, 03580 L'Alfàs del Pi (Alicante), Spain
- Contact email
- privacy@yourweb4free.com
- Trading name
- YourWeb4Free (yourweb4free.com)
We have not appointed a data protection officer. If an appointment later becomes mandatory or is made voluntarily, their contact details will be published here.
2. What data we process
We process only what the service needs to work. Specifically:
2.1. Account data
- Your email address, which identifies your account.
- Your name, if you choose to give it — it is optional.
- Your password, which we never store in the clear: we keep only a bcrypt hash, so we cannot read or recover your password.
- Your interface language preference.
- Account creation and last-update timestamps, and when you accepted these documents.
2.2. Content you provide
- The description of your business and any other instructions you type into the generator or the editor.
- The content of the website that is produced: copy, page structure, design settings, colours and fonts.
- Logos and other images you upload (PNG, JPG, SVG or WEBP, up to 2 MB per file).
- The domain you connect or request, if you use that feature.
- The site owner's details you enter for its legal notice (name or company name, tax ID, address and email).
- The support requests you send us.
A practical note: please do not put other people's personal data — customer records, health information, or any special category under Article 9 GDPR — into the descriptions you type. The service is not designed to handle special category data.
2.3. Usage and technical records
- A log of each AI operation we run for you: the operation type, the model used, the input and output, whether it succeeded or failed, any error message, the cost charged against your allowance, and the timestamp.
- An anonymous identifier set as a cookie for visitors who do not yet have an account, so we can cap free generations per visitor and prevent abuse.
- Ordinary web server records (IP address, user agent, timestamps) kept for security and troubleshooting.
2.4. Payment data (paid plans only)
When you take a plan, the payment provider collects your card details, your name or company name, your billing address and, if you give it, your VAT or tax number, to charge you and issue the invoice. We never see or store full card details: we keep the customer identifier, the plan and the subscription status.
2.5. Data about visitors to the sites you publish
When someone writes to you through your site's contact form, or leaves a review through the link you send them, we process their data on your behalf as a processor: you are the controller (section 11 of the terms of service). We do not keep the text of the message: we email it to you and keep only the date, the page it came from and the address it was sent to. We also count visits to your sites in aggregate (page, kind of referrer, and mobile or desktop), with no cookies and without storing IP addresses.
We do not build advertising profiles, we do not sell personal data, and we do not use your data to make automated decisions that produce legal effects for you.
3. Why we process it, and on what legal basis
Each activity rests on a legal basis under Article 6(1) GDPR:
- Creating and running your account, and providing the service
- Performance of a contract (Art. 6(1)(b)). Without this data we cannot give you access or keep the site you build.
- Generating and editing your website content with AI
- Performance of a contract (Art. 6(1)(b)). This is the core thing you ask us to do when you describe your business.
- Logging AI usage and enforcing free-tier limits
- Legitimate interests (Art. 6(1)(f)) in preventing abuse, controlling costs, and keeping the free tier available to everyone.
- Security, fraud prevention and debugging
- Legitimate interests (Art. 6(1)(f)) in the integrity and availability of the service.
- Answering your support requests
- Performance of a contract (Art. 6(1)(b)). We keep the conversation with your account so we can follow it up and resolve it; only our team sees it.
- Service messages (outages, changes to these documents)
- Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).
- Marketing about our own services
- Consent (Art. 6(1)(a)) where required, or our legitimate interest in marketing similar services to existing customers. You can object at any time, and every message includes a way to opt out.
- Charging for paid plans, invoicing, accounting and tax records
- Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).
4. AI processing and the third-party model provider
YourWeb4Free generates your website content using large language models from Anthropic, PBC, through their API. We want you to know exactly what leaves our systems and what does not.
What is sent to Anthropic
- The business description you write and the editing instructions you type.
- The content of the sections you ask us to rewrite or translate.
- Our own system instructions, which shape the format and tone of the response.
What is not sent
- Your password or its hash.
- Your email address or account identifier, unless you type them into the text you ask us to generate from.
- The logo files you upload.
- Billing details.
Anthropic acts as a processor on our behalf under Article 28 GDPR and the commercial terms applicable to their API. Their servers are located outside the European Economic Area; these international transfers rely on the Standard Contractual Clauses approved by the European Commission, together with the provider's own supplementary measures.
The data processing agreement with the AI provider must be signed and filed, the transfer mechanism in force must be verified, and the provider must be entered in the record of processing activities.
We keep a record of each AI operation — including its input and output — so we can diagnose failures, handle complaints about generated content, and track usage. Please bear in mind that language models can produce mistakes, inaccurate claims or invented details. You should review generated content before publishing it, particularly anything stating prices, opening hours, contact details or claims about your business.
5. Who else sees your data
We do not share your data with third parties for their own purposes. We do rely on providers that process it on our behalf, in the following categories:
- AI model provider: Anthropic, PBC (United States), as described above.
- Hosting and infrastructure provider, which runs the application and the database: Hetzner Online GmbH (Germany), with the servers in Nuremberg (EU); the database with Neon (Neon, Inc.), hosted in Frankfurt (EU).
- Network, security and storage: Cloudflare, Inc. Traffic passes through its network, which protects and speeds up the service; it stores the images you upload (Cloudflare R2), checks on the sign-up form that you are a person and not a bot (Cloudflare Turnstile), and measures visits to the public pages without cookies and with aggregated data (Cloudflare Web Analytics), as described in the cookie policy.
- Transactional email provider, for service messages and for forwarding the messages from your contact forms: Resend (United States).
- Payment provider, for paid plans only: Stripe Payments Europe, Ltd. (Ireland). Full card details are handled by the payment provider; we do not store them.
Where a provider processes data outside the European Economic Area, the transfer relies on the EU-US Data Privacy Framework, where the provider is certified, or on the Standard Contractual Clauses approved by the European Commission.
For each provider, the signed processing agreement and the applicable transfer safeguard must be verified, and this list kept up to date.
We may also disclose data to courts, law enforcement and public authorities where we are legally required to do so.
6. How long we keep it
We keep data for as long as our relationship with you lasts, and afterwards for whatever period the law requires:
- Account data and the content of your sites: while the account is active. When you delete the account or a site, it is erased, apart from anything we are legally required to keep.
- Support requests: while the account is active; they are deleted with it.
- AI operation logs: while the site they belong to exists. When it is deleted, what was sent to and received from the model is erased, and only the cost and usage figures are kept, with no content.
- Encrypted backups: they delete themselves within 30 days.
- Application error logs: 30 days.
- Anonymous identifier cookie: one year.
- Invoices and accounting records: six years, under Article 30 of the Spanish Commercial Code, and any longer period tax law requires.
- Technical security logs: for no longer than their purpose requires.
A concrete period is still to be set for AI operation logs not linked to any site (for example, analyses run by a visitor who never creates an account) and for technical security logs.
7. Your rights
Under the GDPR you have the following rights, free of charge:
- Access
- Find out what data we hold about you and get a copy of it.
- Rectification
- Have inaccurate data corrected and incomplete data completed.
- Erasure
- Ask us to delete your data when it is no longer needed or when you withdraw consent, subject to any legal duty to retain it.
- Restriction
- Ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Portability
- Receive the data you gave us in a structured, commonly used, machine-readable format, or have us transmit it to another controller where technically feasible.
- Objection
- Object to processing based on our legitimate interests on grounds relating to your particular situation, and to direct marketing in all cases.
- Withdrawing consent
- Withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.
Some of these you can exercise yourself in “Your account”: there you can correct your details, download a copy of your data and delete the account.
For anything else, email privacy@yourweb4free.com from the address on your account, or otherwise with proof of identity. We will respond within one month, extendable by two further months for complex requests — we will tell you if we need the extension.
If you are a visitor to a website built with our service, the controller of your data is the business that owns that site: contact it using the details in its legal notice. If you write to us instead, we will pass your request on to it.
If you believe we have not handled your request properly, you can complain to our lead supervisory authority, the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es. You may also complain to the supervisory authority in your own country of residence. We would appreciate the chance to put things right first.
8. Security
We apply technical and organisational measures appropriate to the risk. These include encryption of traffic in transit (HTTPS), password storage using a salted key-derivation function (bcrypt), access control scoped to each account and organisation, and an ownership check before any site can be modified.
We do not claim to hold any security certification (ISO 27001, SOC 2 or otherwise), because we do not hold one. If we obtain one, we will say so explicitly here.
No system is perfect. If a personal data breach occurs that is likely to result in a high risk to your rights, we will tell you without undue delay and notify the supervisory authority under Articles 33 and 34 GDPR.
9. Children
The service is aimed at people running a business or profession and is not intended for children. We do not knowingly collect data from children. If we find that an account has been created in breach of this, we will delete it.
10. Changes to this policy
We may update this policy to reflect changes to the service or the law. The last-updated date appears at the top. If a change materially affects your rights, we will tell you by email or by a prominent notice in the service before it takes effect.
Questions?
If you have any questions about this document, about how we handle your data, or about the terms of the service, get in touch and we'll answer.