LEGAL_FRAMEWORK

REGULATORY
COMPLIANCE

All operational protocols governed by European Union General Data Protection Regulation (EU GDPR) 2016/679 and applicable Spanish data protection legislation.

SECTION_01

PRIVACY PROTOCOL

1.1 DATA CONTROLLER IDENTIFICATION

The data controller for all personal data processing activities conducted through this digital interface is velvetnorthdrift, registered at Calle de Alcalá 45, Piso 2 D, Madrid, Spain. All data protection inquiries and data subject requests should be directed to [email protected].

1.2 CATEGORIES OF PERSONAL DATA COLLECTED

We collect and process the following categories of personal data through our operational interfaces:

  • Contact identifiers: full name, email address, telephone number, and physical address as provided during inquiry submission or service engagement.
  • Technical telemetry: IP address, browser configuration, device identifiers, operating system specifications, and referrer URLs collected through standard HTTP header analysis.
  • Behavioral analytics: page interaction patterns, session duration metrics, scroll depth measurements, and navigation pathway analysis collected through first-party analytics instrumentation.
  • Communication records: all correspondence transmitted through our contact forms, email channels, or direct telephone communications is retained for quality assurance and operational audit purposes.

1.3 LEGAL BASIS FOR PROCESSING

All personal data processing activities are conducted under one or more of the following legal bases as defined in Article 6(1) of the EU GDPR:

  • Article 6(1)(a) — Consent: where you have provided explicit, informed, and unambiguous consent for specific processing purposes.
  • Article 6(1)(b) — Contractual necessity: where processing is necessary for the performance of a contract to which you are a party, or for pre-contractual measures taken at your request.
  • Article 6(1)(f) — Legitimate interests: where processing is necessary for our legitimate business interests, including service improvement, fraud prevention, and operational security, provided such interests are not overridden by your fundamental rights.

1.4 DATA RETENTION PERIODS

Personal data is retained only for the duration necessary to fulfill the specific purpose for which it was collected. Contact form submissions and associated correspondence are retained for a maximum period of 24 months from the date of last communication. Technical telemetry data is aggregated and anonymized after 12 months. Financial transaction records are retained for the period required by applicable Spanish tax legislation (minimum 4 years).

1.5 DATA SUBJECT RIGHTS

Under the EU GDPR, you possess the following rights regarding your personal data:

  • Right of Access (Article 15): You may request a copy of all personal data we hold about you.
  • Right to Rectification (Article 16): You may request correction of inaccurate or incomplete data.
  • Right to Erasure (Article 17): You may request deletion of your personal data where there is no compelling reason for continued processing.
  • Right to Restriction (Article 18): You may request restriction of processing in specific circumstances.
  • Right to Data Portability (Article 20): You may request your data in a structured, commonly used, machine-readable format.
  • Right to Object (Article 21): You may object to processing based on legitimate interests at any time.

To exercise any of these rights, contact our data protection officer at [email protected]. We will respond to all legitimate requests within 30 days.

1.6 INTERNATIONAL DATA TRANSFERS

Where personal data is transferred outside the European Economic Area (EEA), we ensure adequate protection through Standard Contractual Clauses (SCCs) approved by the European Commission, or through adequacy decisions as published by the European Commission. No personal data is transferred to jurisdictions without an adequate level of data protection without appropriate safeguards being in place.

1.7 DATA PROTECTION AUTHORITY

If you believe that our processing of your personal data infringes the EU GDPR, you have the right to lodge a complaint with the competent supervisory authority. For data processing activities conducted from our Madrid office, the relevant authority is the Agencia Española de Protección de Datos (AEPD): www.aepd.es

SECTION_02

COOKIE DIRECTIVE

2.1 COOKIE CLASSIFICATIONS

This system deploys the following categories of cookies and similar tracking technologies:

  • Strictly Necessary Cookies: These cookies are essential for the basic functionality of this digital interface. They enable core features such as session management, security token validation, and load balancing. These cookies do not require consent as they are strictly necessary for the provision of the service requested by the user (ePrivacy Directive Article 5(3) exemption).
  • Analytics Cookies: These cookies collect anonymized, aggregated data about how visitors interact with our interface, including pages visited, time spent on each page, navigation patterns, and error encounters. All analytics data is processed using first-party instrumentation and is not shared with third-party analytics providers without explicit consent.
  • Functional Cookies: These cookies enable enhanced functionality and personalization, including remembering your cookie consent preferences and interface configuration settings.

2.2 CONSENT MANAGEMENT

Upon your first visit to this interface, you are presented with a cookie consent banner providing the option to accept or decline non-essential cookies. Your consent choice is stored in your browser's local storage and persists until you modify it. You may change your cookie preferences at any time by clearing your browser's local storage for this domain or by revisiting the consent management interface.

2.3 THIRD-PARTY COOKIE DEPENDENCIES

This interface may deploy third-party cookies through embedded content, including but not limited to Google Maps iframe integrations. Google's use of cookies is governed by Google's Privacy Policy (policies.google.com/privacy). We do not control the data collection practices of third-party services embedded within our interface. Users are advised to review the privacy policies of any third-party services before interacting with embedded content.

2.4 COOKIE MANAGEMENT INSTRUCTIONS

You may manage cookie preferences through your browser settings. The following links provide instructions for major browser platforms:

  • Google Chrome: Settings > Privacy and Security > Cookies
  • Mozilla Firefox: Settings > Privacy & Security > Cookies and Site Data
  • Apple Safari: Preferences > Privacy > Manage Website Data
  • Microsoft Edge: Settings > Privacy, Search, and Services > Cookies
SECTION_03

REFUND TERMS

3.1 REFUND ELIGIBILITY CRITERIA

Refund requests are evaluated against the following criteria and are subject to the milestone-based delivery framework established in the service agreement:

  • Pre-Execution Cancellation: If a service engagement is cancelled before any operational work has commenced, a full refund of any advance payment will be processed within 14 business days. Cancellation must be communicated in writing to [email protected].
  • Mid-Execution Cancellation: Where a service has been partially delivered, refund calculations are based on the proportion of completed milestones relative to the total project scope. Completed milestones are non-refundable. Unused pre-paid amounts for undelivered milestones will be refunded within 30 business days.
  • Post-Delivery Disputes: If deliverables materially deviate from the specifications defined in the scoping blueprint, a remediation period of 15 business days will be initiated. If remediation fails to resolve the deviation, a proportional refund will be calculated based on the scope of non-conforming deliverables.

3.2 NON-REFUNDABLE ITEMS

The following are explicitly excluded from refund eligibility:

  • Third-party licensing fees, hosting costs, or domain registration fees incurred on behalf of the client.
  • Custom asset creation (logos, illustrations, copywriting) where the assets have been delivered and accepted by the client.
  • Consultation hours and discovery phase deliverables that have been formally presented and acknowledged.

3.3 REFUND PROCESSING

All approved refunds are processed via the original payment method within 30 business days of refund approval. Refund approval is at the sole discretion of velvetnorthdrift and is based on the evaluation criteria defined in this policy. Clients will receive written confirmation of refund approval or rejection, including the calculation methodology, within 5 business days of refund request submission.

SECTION_04

SERVICE AGREEMENT

4.1 SERVICE SCOPE & BINDING

By accessing, browsing, or utilizing any service offered through this digital interface operated by velvetnorthdrift at Calle de Alcalá 45, Piso 2 D, Madrid, Spain, you enter into a binding agreement with these Terms of Service. If you do not agree with any provision herein, you must immediately cease all use of this interface and its associated services. These terms constitute the entire agreement between the parties and supersede all prior negotiations, representations, or agreements relating to the subject matter.

4.2 PAYMENT & MILESTONES

All service engagements are structured around a milestone-based payment framework. Invoices are generated upon completion of each defined milestone and are payable within 14 calendar days of invoice date. Late payments incur a statutory interest rate of 8% above the European Central Bank base rate, in accordance with EU Directive 2011/7/EU on late payment in commercial transactions. velvetnorthdrift reserves the right to suspend all active service delivery upon expiration of the payment grace period.

4.3 INTELLECTUAL PROPERTY TRANSFER

Upon full payment of all applicable invoices, all intellectual property rights for custom-developed deliverables are transferred to the client. This includes source code, design assets, documentation, and custom configurations created specifically for the client engagement. velvetnorthdrift retains the right to utilize generalized methodologies, frameworks, and non-client-specific code patterns developed during the engagement in future projects. Pre-existing intellectual property, third-party libraries, and open-source components remain governed by their respective licenses.

4.4 CONFIDENTIALITY

Both parties agree to maintain strict confidentiality regarding all proprietary information, technical specifications, business strategies, and financial data disclosed during the course of the engagement. This confidentiality obligation survives the termination of the service agreement for a period of 24 months. Exceptions apply to information that: (a) is or becomes publicly available through no fault of the receiving party; (b) was already known to the receiving party prior to disclosure; or (c) is required to be disclosed by law or regulatory authority.

4.5 LIMITATION OF LIABILITY

To the maximum extent permitted by applicable law, velvetnorthdrift shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising out of or relating to the use of this interface or any services rendered. Our total aggregate liability for any claim arising out of or relating to these terms or any service engagement shall not exceed the total fees paid by the client for the specific service engagement giving rise to the claim during the 12-month period preceding the claim.

4.6 GOVERNING LAW & DISPUTE RESOLUTION

These Terms of Service are governed by and construed in accordance with the laws of Spain and, where applicable, the European Union. Any dispute arising out of or relating to these terms shall first be subject to good-faith mediation. If mediation fails within 30 days, disputes shall be submitted to the exclusive jurisdiction of the courts of Madrid, Spain. Nothing in these terms restricts your statutory rights as a consumer under applicable EU directive transpositions.

4.7 AMENDMENTS

velvetnorthdrift reserves the right to modify these Terms of Service at any time. Material changes will be communicated through a prominent notice on this interface or via direct email communication to registered clients. Continued use of this interface following the posting of amended terms constitutes your acceptance of the modified terms. The "Last Updated" date at the bottom of this page reflects the most recent revision.

Last Updated: January 2026 | velvetnorthdrift | Calle de Alcalá 45, Piso 2 D, Madrid, Spain