Who is responsible for your data
Silurian SL is the data controller for the personal data described in this policy when you visit a Silurian website, contact us, create an account, purchase a service or use Workspace. For services where a customer determines why and how Silurian processes data on its behalf, Silurian may instead act as that customer's processor under the applicable service agreement.
- Controller
- Silurian SL
- VAT number
- ESB86389889
- Postal address
- Portugalete 46, 28223 Madrid, Spain
- Privacy contact
- Secure Privacy & data protection ticket
- Historical AEPD file registration
- 2181343370
The AEPD number is retained for historical transparency. The former Spanish obligation to register personal-data files was abolished when the GDPR became applicable and was replaced by the controller's internal record of processing activities; it is not a current certification or approval.
We apply data minimisation: service, account and security data are used only where needed to deliver the requested relationship, comply with law, protect the platform or support a choice you have made.
Data we use
Identity and account
Name, email, language, country, profile and authentication evidence.
Customer and billing
Company, address, tax profile, orders, invoices, subscriptions and payment status. Card credentials remain with the payment provider.
Support and communications
Messages, tickets, attachments and the preferences needed to respond or send requested information.
Technical and security
IP address, timestamps, session and device signals, audit events and logs used to operate and secure the service.
Where the data comes from
Most data comes directly from you. It may also come from an authorised administrator of your organisation, identity providers when you choose a social sign-in, payment and service providers involved in your transaction, public company or tax registers used for verification, and technical events generated when you use or secure the platform.
Sensitive data and children
Our services are not designed to collect special-category data. Please do not include health, biometric, political, religious or similarly sensitive information in tickets unless it is strictly necessary for your request. Silurian's commercial services are not directed to children, and we do not knowingly create customer accounts for children acting on their own behalf.
Purposes and legal bases
| Purpose | Typical legal basis |
|---|---|
| Provide accounts, orders, subscriptions, support and contracted services | Contract or steps requested before a contract |
| Verify customer, tax and payment information; issue and retain accounting records | Contract and legal obligations |
| Prevent fraud, abuse and unauthorised access; investigate incidents; maintain audit evidence | Legitimate interests in protecting customers, Silurian and the integrity of the service, and legal obligations where applicable |
| Operate, diagnose and improve the reliability and usability of the platform | Contract and legitimate interests, using proportionate and minimised operational data |
| Respond to privacy requests, disputes and regulatory enquiries | Legal obligations and the establishment, exercise or defence of legal claims |
| Send requested service communications | Contract or the action you requested |
| Send optional marketing or load optional analytics, preference or marketing technologies | Your consent, which you may withdraw at any time |
Required information
Fields marked as required are necessary to create the requested account, ticket, order or service, or to meet billing and legal requirements. If you do not provide them, we may be unable to complete that request. Optional fields can be left blank without losing access to unrelated services.
Automated processing and AI
Silurian does not make decisions based solely on automated processing that produce legal or similarly significant effects for you. Automated security and fraud signals may flag activity for restriction or human review. Helpdesk AI may classify, summarise, translate or suggest a draft, but a Silurian agent remains responsible for customer-facing decisions and replies.
Services and providers
This register names the principal external services that may receive personal data in a current Silurian journey. A provider is not given every category of data listed in this policy: it receives only what is needed for the stated journey. Its role may vary between processor, independent controller or separate service supplier according to the service and applicable agreement.
Cloudflare
Network delivery and securityProcesses network and request information needed to deliver Silurian websites, mitigate attacks, manage challenges and protect the origin. Cloudflare-backed products ordered by a customer are a separate service journey.
- Typical data
- IP address, request, device and security signals
- When
- Website delivery or a selected Cloudflare service
Stripe
Payment and fraud preventionProvides secure payment fields, tokenised payment methods, payment status and fraud-prevention controls. Card credentials are submitted directly to Stripe and are not stored by Silurian.
- Typical data
- Contact, billing, transaction, device and fraud signals
- When
- Only during an applicable payment or saved-card journey
Google Identity Services returns an identity credential and basic profile only after you choose Google sign-in. Google Workspace processes customer and end-user data under the applicable Workspace agreement when that product is contracted.
- Typical data
- Identity profile; Workspace account, administrator and service data
- When
- Google sign-in or a contracted Google Workspace service
Netim and domain registries
Domain availability and registrationNetim may be used for domain availability, registration, renewal or transfer. Registrant and contact data may also be sent to the registry responsible for the selected extension where the registration rules require it.
- Typical data
- Domain, registrant/contact, eligibility and transaction data
- When
- Only for a domain search or contracted domain operation
Communications routes
Email, SMS and support deliverySilurian uses its own systems and selected communications routes to deliver requested email, support and one-time SMS notifications. A route receives only the address or number, message and delivery metadata needed for that communication.
- Typical data
- Email address or mobile number, message and delivery status
- When
- When you request or the contracted service requires the communication
Providers, registry operators and communications routes can change as services evolve. Silurian reviews the register when a material integration changes and can provide more specific recipient and transfer information for your account or transaction through the privacy contact route.
Retention and security
We apply the following retention criteria unless a longer or shorter period is required by law, an active dispute, a security investigation or the service contract:
| Record | Retention criterion |
|---|---|
| Account and Workspace profile | While the account or customer relationship is active, followed by the period needed to resolve claims and meet legal obligations. |
| Orders, invoices, tax and accounting evidence | The statutory accounting, tax and commercial retention periods applicable to Silurian. |
| Support tickets and attachments | For the service relationship and a proportionate follow-up or claims period; shorter where the content is no longer needed or deletion is legally appropriate. |
| Security, access and audit events | For the period reasonably needed to detect abuse, investigate incidents, demonstrate authorised actions and defend the platform. |
| Uncompleted forms and temporary uploads | For a short operational recovery and abuse-prevention period, then deleted if no ticket or transaction is completed. |
| Consent record | For the stated consent lifetime and, where necessary, a proportionate period afterwards to demonstrate the choice, withdrawal and version that applied. |
When data is no longer needed, it is deleted, securely isolated until backup rotation completes, or anonymised where practical.
Access controls, encryption in transit, audit evidence, provider boundaries and operational review help protect Silurian services. No internet service can promise absolute security; we investigate and respond to suspected incidents according to their risk.
Your rights
Subject to the conditions in applicable law, you may:
- request access to your personal data and information about its processing;
- correct inaccurate data and complete incomplete data;
- request deletion or restriction of processing;
- object to processing based on legitimate interests or to direct marketing at any time;
- receive portable data where processing is automated and based on consent or contract;
- withdraw consent at any time without affecting processing already carried out lawfully; and
- request human intervention where a legally significant decision would be based solely on automated processing.
We may need to verify your identity and authority before acting, and we will explain if a legal exception prevents all or part of a request. Account controls can handle ordinary profile changes; use the Privacy & data protection ticket route for a formal request.
You may complain to the Spanish Data Protection Agency (AEPD) or another competent supervisory authority, particularly where you habitually live or work or where you believe an infringement occurred. Contacting Silurian first is optional.
Contact and policy changes
Send privacy questions, objections, withdrawal requests or requests to exercise your rights through our secure contact route. The Privacy & data protection category is selected automatically.
Contact Silurian about privacy