REGULATORY
COMPLIANCE
All operational protocols governed by European Union General Data Protection Regulation (EU GDPR) 2016/679 and applicable Spanish data protection legislation.
PRIVACY PROTOCOL
1.1 DATA CONTROLLER IDENTIFICATION
The data controller for all personal data processing activities conducted through this digital interface is velvetnorthdrift, registered at Calle de Alcalá 45, Piso 2 D, Madrid, Spain. All data protection inquiries and data subject requests should be directed to [email protected].
1.2 CATEGORIES OF PERSONAL DATA COLLECTED
We collect and process the following categories of personal data through our operational interfaces:
- —Contact identifiers: full name, email address, telephone number, and physical address as provided during inquiry submission or service engagement.
- —Technical telemetry: IP address, browser configuration, device identifiers, operating system specifications, and referrer URLs collected through standard HTTP header analysis.
- —Behavioral analytics: page interaction patterns, session duration metrics, scroll depth measurements, and navigation pathway analysis collected through first-party analytics instrumentation.
- —Communication records: all correspondence transmitted through our contact forms, email channels, or direct telephone communications is retained for quality assurance and operational audit purposes.
1.3 LEGAL BASIS FOR PROCESSING
All personal data processing activities are conducted under one or more of the following legal bases as defined in Article 6(1) of the EU GDPR:
- —Article 6(1)(a) — Consent: where you have provided explicit, informed, and unambiguous consent for specific processing purposes.
- —Article 6(1)(b) — Contractual necessity: where processing is necessary for the performance of a contract to which you are a party, or for pre-contractual measures taken at your request.
- —Article 6(1)(f) — Legitimate interests: where processing is necessary for our legitimate business interests, including service improvement, fraud prevention, and operational security, provided such interests are not overridden by your fundamental rights.
1.4 DATA RETENTION PERIODS
Personal data is retained only for the duration necessary to fulfill the specific purpose for which it was collected. Contact form submissions and associated correspondence are retained for a maximum period of 24 months from the date of last communication. Technical telemetry data is aggregated and anonymized after 12 months. Financial transaction records are retained for the period required by applicable Spanish tax legislation (minimum 4 years).
1.5 DATA SUBJECT RIGHTS
Under the EU GDPR, you possess the following rights regarding your personal data:
- —Right of Access (Article 15): You may request a copy of all personal data we hold about you.
- —Right to Rectification (Article 16): You may request correction of inaccurate or incomplete data.
- —Right to Erasure (Article 17): You may request deletion of your personal data where there is no compelling reason for continued processing.
- —Right to Restriction (Article 18): You may request restriction of processing in specific circumstances.
- —Right to Data Portability (Article 20): You may request your data in a structured, commonly used, machine-readable format.
- —Right to Object (Article 21): You may object to processing based on legitimate interests at any time.
To exercise any of these rights, contact our data protection officer at [email protected]. We will respond to all legitimate requests within 30 days.
1.6 INTERNATIONAL DATA TRANSFERS
Where personal data is transferred outside the European Economic Area (EEA), we ensure adequate protection through Standard Contractual Clauses (SCCs) approved by the European Commission, or through adequacy decisions as published by the European Commission. No personal data is transferred to jurisdictions without an adequate level of data protection without appropriate safeguards being in place.
1.7 DATA PROTECTION AUTHORITY
If you believe that our processing of your personal data infringes the EU GDPR, you have the right to lodge a complaint with the competent supervisory authority. For data processing activities conducted from our Madrid office, the relevant authority is the Agencia Española de Protección de Datos (AEPD): www.aepd.es
REFUND TERMS
3.1 REFUND ELIGIBILITY CRITERIA
Refund requests are evaluated against the following criteria and are subject to the milestone-based delivery framework established in the service agreement:
- —Pre-Execution Cancellation: If a service engagement is cancelled before any operational work has commenced, a full refund of any advance payment will be processed within 14 business days. Cancellation must be communicated in writing to [email protected].
- —Mid-Execution Cancellation: Where a service has been partially delivered, refund calculations are based on the proportion of completed milestones relative to the total project scope. Completed milestones are non-refundable. Unused pre-paid amounts for undelivered milestones will be refunded within 30 business days.
- —Post-Delivery Disputes: If deliverables materially deviate from the specifications defined in the scoping blueprint, a remediation period of 15 business days will be initiated. If remediation fails to resolve the deviation, a proportional refund will be calculated based on the scope of non-conforming deliverables.
3.2 NON-REFUNDABLE ITEMS
The following are explicitly excluded from refund eligibility:
- —Third-party licensing fees, hosting costs, or domain registration fees incurred on behalf of the client.
- —Custom asset creation (logos, illustrations, copywriting) where the assets have been delivered and accepted by the client.
- —Consultation hours and discovery phase deliverables that have been formally presented and acknowledged.
3.3 REFUND PROCESSING
All approved refunds are processed via the original payment method within 30 business days of refund approval. Refund approval is at the sole discretion of velvetnorthdrift and is based on the evaluation criteria defined in this policy. Clients will receive written confirmation of refund approval or rejection, including the calculation methodology, within 5 business days of refund request submission.
SERVICE AGREEMENT
4.1 SERVICE SCOPE & BINDING
By accessing, browsing, or utilizing any service offered through this digital interface operated by velvetnorthdrift at Calle de Alcalá 45, Piso 2 D, Madrid, Spain, you enter into a binding agreement with these Terms of Service. If you do not agree with any provision herein, you must immediately cease all use of this interface and its associated services. These terms constitute the entire agreement between the parties and supersede all prior negotiations, representations, or agreements relating to the subject matter.
4.2 PAYMENT & MILESTONES
All service engagements are structured around a milestone-based payment framework. Invoices are generated upon completion of each defined milestone and are payable within 14 calendar days of invoice date. Late payments incur a statutory interest rate of 8% above the European Central Bank base rate, in accordance with EU Directive 2011/7/EU on late payment in commercial transactions. velvetnorthdrift reserves the right to suspend all active service delivery upon expiration of the payment grace period.
4.3 INTELLECTUAL PROPERTY TRANSFER
Upon full payment of all applicable invoices, all intellectual property rights for custom-developed deliverables are transferred to the client. This includes source code, design assets, documentation, and custom configurations created specifically for the client engagement. velvetnorthdrift retains the right to utilize generalized methodologies, frameworks, and non-client-specific code patterns developed during the engagement in future projects. Pre-existing intellectual property, third-party libraries, and open-source components remain governed by their respective licenses.
4.4 CONFIDENTIALITY
Both parties agree to maintain strict confidentiality regarding all proprietary information, technical specifications, business strategies, and financial data disclosed during the course of the engagement. This confidentiality obligation survives the termination of the service agreement for a period of 24 months. Exceptions apply to information that: (a) is or becomes publicly available through no fault of the receiving party; (b) was already known to the receiving party prior to disclosure; or (c) is required to be disclosed by law or regulatory authority.
4.5 LIMITATION OF LIABILITY
To the maximum extent permitted by applicable law, velvetnorthdrift shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising out of or relating to the use of this interface or any services rendered. Our total aggregate liability for any claim arising out of or relating to these terms or any service engagement shall not exceed the total fees paid by the client for the specific service engagement giving rise to the claim during the 12-month period preceding the claim.
4.6 GOVERNING LAW & DISPUTE RESOLUTION
These Terms of Service are governed by and construed in accordance with the laws of Spain and, where applicable, the European Union. Any dispute arising out of or relating to these terms shall first be subject to good-faith mediation. If mediation fails within 30 days, disputes shall be submitted to the exclusive jurisdiction of the courts of Madrid, Spain. Nothing in these terms restricts your statutory rights as a consumer under applicable EU directive transpositions.
4.7 AMENDMENTS
velvetnorthdrift reserves the right to modify these Terms of Service at any time. Material changes will be communicated through a prominent notice on this interface or via direct email communication to registered clients. Continued use of this interface following the posting of amended terms constitutes your acceptance of the modified terms. The "Last Updated" date at the bottom of this page reflects the most recent revision.
Last Updated: January 2026 | velvetnorthdrift | Calle de Alcalá 45, Piso 2 D, Madrid, Spain