At Cuatralbo, we understand that privacy and the protection of your personal data are essential. We handle all the information you provide with responsibility, transparency, and respect, in accordance with applicable data protection laws in the United States, particularly those of the State of Maryland, and, where relevant, with the General Data Protection Regulation (GDPR) for users residing in the European Union. This Privacy Policy clearly explains how we collect, use, retain, and protect your personal data when you access and use our platform.
Our community is mainly composed of expatriates living in the United States, although users may sometimes access content from Spain or other countries.
Collection and Use of Personal Data
When you register as a user, participate in surveys, attend events, submit data through forms, or engage in other activities within our platform, we collect and process your personal data solely to provide you with the informational and participatory services for which the platform has been designed (without direct sales of products or services by Cuatralbo). This includes managing your account, tracking your participation, and assigning points that may be redeemed for benefits or discounts. Points are always managed by third-party partners. Cuatralbo does not intervene in transactions nor assume responsibility for such products or services. We never request or process particularly sensitive data, such as medical, ethnic, or sexual information.
The data we collect comes exclusively from you, with your express consent, and never from external sources. Such data may include your name, email address, country or state of residence, language preferences, activity history within the platform, and technical information such as your IP address, browser type, or browsing data collected through cookies. You can configure your browser to reject cookies, although this may affect the operation of some features of the website.
We process your data based on the principles of lawfulness, fairness, and transparency. Your information is used solely for the purposes clearly defined and accepted by you upon registration. We do not sell, rent, or share your personal data with third parties for their own commercial purposes. We only share information with technological providers who help us deliver our services, such as analytics tools or cloud storage services. These providers always operate under confidentiality agreements and only when necessary. If you access an external offer, you may be redirected to the provider’s website, and in that case, the privacy policy of that site will apply independently. Cuatralbo is not responsible for the privacy practices of such external sites.
Security Measures
At Cuatralbo, we implement appropriate technical and organizational measures to safeguard your personal information against loss, misuse, unauthorized access, alteration, or destruction. This includes encryption of communications through secure protocols (HTTPS/TLS), access controls based on roles and confidentiality agreements with authorized staff, secure storage in servers and cloud services that meet recognized security standards, regular backups and recovery procedures, as well as internal monitoring and audits to detect unauthorized access or technical vulnerabilities. In the event of a security breach compromising your personal data, we will notify you without undue delay and, where legally required, also inform the relevant authorities within the established deadlines.
International Data Transfers
Cuatralbo’s servers and primary infrastructure are hosted in the United States (AWS us-east-1). If you access our platform from the European Union (EU), the European Economic Area (EEA), or other jurisdictions with data protection laws, please be aware that your personal data will be transferred to, stored, and processed in the United States.
We rely on the EU–U.S. Data Privacy Framework (DPF) as the legal basis for transferring personal data from the EU/EEA to the United States. Our hosting provider, Amazon Web Services, Inc. (AWS), is certified under the DPF, which provides appropriate safeguards for these transfers.
Analytics data collected through Matomo, our self-hosted analytics platform, is likewise processed on servers in the United States. All transfers are carried out in compliance with applicable data protection laws. Where required, we may also use the European Commission’s Standard Contractual Clauses (SCCs) to ensure that personal data receives a level of protection equivalent to that guaranteed within the EU.
We implement appropriate technical and organizational measures to protect personal data during transmission and storage, including encryption, strict access controls, and secure communication protocols.
Billing of Professional Services
If we are required to issue invoices for professional services, we will only request the essential data necessary for this purpose and will retain it for the period legally required under tax regulations. We will never use this data for other purposes, such as marketing or promotions, without your additional consent.
Users’ Rights
Registered users have the right to access, rectify, delete, restrict, or object to the processing of their data, as well as to request portability of their data, when such rights apply under the relevant legislation (GDPR in the EU or state-level privacy laws in the U.S., such as the CCPA in California or the VCDPA in Virginia).
To exercise these rights, you may email us at info@cuatralbo.com