Skip to content
YourWeb4Free

Privacy policy

How we collect, use and protect your personal data when you use YourWeb4Free.

Last updated:

1. Who is responsible for your data

The controller of the personal data collected through this service is:

Legal entity
Digiworks Spain, S.L.U.
Company / tax number
B54020219
Registered address
Avenida San Rafael 11, local 2, 03580 L'Alfàs del Pi (Alicante), Spain
Contact email
privacy@yourweb4free.com
Trading name
YourWeb4Free (yourweb4free.com)

We have not appointed a data protection officer. If an appointment later becomes mandatory or is made voluntarily, their contact details will be published here.

2. What data we process

We process only what the service needs to work. Specifically:

2.1. Account data

2.2. Content you provide

A practical note: please do not put other people's personal data — customer records, health information, or any special category under Article 9 GDPR — into the descriptions you type. The service is not designed to handle special category data.

2.3. Usage and technical records

2.4. Payment data (paid plans only)

When you take a plan, the payment provider collects your card details, your name or company name, your billing address and, if you give it, your VAT or tax number, to charge you and issue the invoice. We never see or store full card details: we keep the customer identifier, the plan and the subscription status.

2.5. Data about visitors to the sites you publish

When someone writes to you through your site's contact form, or leaves a review through the link you send them, we process their data on your behalf as a processor: you are the controller (section 11 of the terms of service). We do not keep the text of the message: we email it to you and keep only the date, the page it came from and the address it was sent to. We also count visits to your sites in aggregate (page, kind of referrer, and mobile or desktop), with no cookies and without storing IP addresses.

We do not build advertising profiles, we do not sell personal data, and we do not use your data to make automated decisions that produce legal effects for you.

3. Why we process it, and on what legal basis

Each activity rests on a legal basis under Article 6(1) GDPR:

Creating and running your account, and providing the service
Performance of a contract (Art. 6(1)(b)). Without this data we cannot give you access or keep the site you build.
Generating and editing your website content with AI
Performance of a contract (Art. 6(1)(b)). This is the core thing you ask us to do when you describe your business.
Logging AI usage and enforcing free-tier limits
Legitimate interests (Art. 6(1)(f)) in preventing abuse, controlling costs, and keeping the free tier available to everyone.
Security, fraud prevention and debugging
Legitimate interests (Art. 6(1)(f)) in the integrity and availability of the service.
Answering your support requests
Performance of a contract (Art. 6(1)(b)). We keep the conversation with your account so we can follow it up and resolve it; only our team sees it.
Service messages (outages, changes to these documents)
Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).
Marketing about our own services
Consent (Art. 6(1)(a)) where required, or our legitimate interest in marketing similar services to existing customers. You can object at any time, and every message includes a way to opt out.
Charging for paid plans, invoicing, accounting and tax records
Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).

4. AI processing and the third-party model provider

YourWeb4Free generates your website content using large language models from Anthropic, PBC, through their API. We want you to know exactly what leaves our systems and what does not.

What is sent to Anthropic

What is not sent

Anthropic acts as a processor on our behalf under Article 28 GDPR and the commercial terms applicable to their API. Their servers are located outside the European Economic Area; these international transfers rely on the Standard Contractual Clauses approved by the European Commission, together with the provider's own supplementary measures.

The data processing agreement with the AI provider must be signed and filed, the transfer mechanism in force must be verified, and the provider must be entered in the record of processing activities.

We keep a record of each AI operation — including its input and output — so we can diagnose failures, handle complaints about generated content, and track usage. Please bear in mind that language models can produce mistakes, inaccurate claims or invented details. You should review generated content before publishing it, particularly anything stating prices, opening hours, contact details or claims about your business.

5. Who else sees your data

We do not share your data with third parties for their own purposes. We do rely on providers that process it on our behalf, in the following categories:

Where a provider processes data outside the European Economic Area, the transfer relies on the EU-US Data Privacy Framework, where the provider is certified, or on the Standard Contractual Clauses approved by the European Commission.

For each provider, the signed processing agreement and the applicable transfer safeguard must be verified, and this list kept up to date.

We may also disclose data to courts, law enforcement and public authorities where we are legally required to do so.

6. How long we keep it

We keep data for as long as our relationship with you lasts, and afterwards for whatever period the law requires:

A concrete period is still to be set for AI operation logs not linked to any site (for example, analyses run by a visitor who never creates an account) and for technical security logs.

7. Your rights

Under the GDPR you have the following rights, free of charge:

Access
Find out what data we hold about you and get a copy of it.
Rectification
Have inaccurate data corrected and incomplete data completed.
Erasure
Ask us to delete your data when it is no longer needed or when you withdraw consent, subject to any legal duty to retain it.
Restriction
Ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
Portability
Receive the data you gave us in a structured, commonly used, machine-readable format, or have us transmit it to another controller where technically feasible.
Objection
Object to processing based on our legitimate interests on grounds relating to your particular situation, and to direct marketing in all cases.
Withdrawing consent
Withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.

Some of these you can exercise yourself in “Your account”: there you can correct your details, download a copy of your data and delete the account.

For anything else, email privacy@yourweb4free.com from the address on your account, or otherwise with proof of identity. We will respond within one month, extendable by two further months for complex requests — we will tell you if we need the extension.

If you are a visitor to a website built with our service, the controller of your data is the business that owns that site: contact it using the details in its legal notice. If you write to us instead, we will pass your request on to it.

If you believe we have not handled your request properly, you can complain to our lead supervisory authority, the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es. You may also complain to the supervisory authority in your own country of residence. We would appreciate the chance to put things right first.

8. Security

We apply technical and organisational measures appropriate to the risk. These include encryption of traffic in transit (HTTPS), password storage using a salted key-derivation function (bcrypt), access control scoped to each account and organisation, and an ownership check before any site can be modified.

We do not claim to hold any security certification (ISO 27001, SOC 2 or otherwise), because we do not hold one. If we obtain one, we will say so explicitly here.

No system is perfect. If a personal data breach occurs that is likely to result in a high risk to your rights, we will tell you without undue delay and notify the supervisory authority under Articles 33 and 34 GDPR.

9. Children

The service is aimed at people running a business or profession and is not intended for children. We do not knowingly collect data from children. If we find that an account has been created in breach of this, we will delete it.

10. Changes to this policy

We may update this policy to reflect changes to the service or the law. The last-updated date appears at the top. If a change materially affects your rights, we will tell you by email or by a prominent notice in the service before it takes effect.

Questions?

If you have any questions about this document, about how we handle your data, or about the terms of the service, get in touch and we'll answer.

hola@yourweb4free.com