Skip to content
Privacy

What we collect, and why.

We set no advertising cookies and build no profiles. What we do collect comes down to four things, each of them either because you asked us to do something or because we need to know the site works.

Last updated · 5 August 2026
01

Who we are.

Almost A Lab SL is a company registered in Barcelona, Spain, and is the data controller for this website. For anything in this notice, including access and deletion requests, write to letsbuild@almostalab.io and we will reply within 30 days.

02

What we collect.

Four things, and nothing else:

  • The brief form. Your name, email, company, the project type and scope band you pick, and whatever you write in the message field. Nothing is pre-filled and nothing is inferred.
  • Booking a call. Your name, email and chosen slot, handled by our own Cal.com instance at cal.almostalab.io rather than a third-party scheduler.
  • The free audit. The domain you enter and the public pages we fetch from it. Beacon reads a website, and we do not ask who you are to run a scan.
  • Analytics. Aggregate page views and load performance through Vercel Analytics and Speed Insights, which are cookieless and do not build a profile or follow you to other sites.

We set no advertising or tracking cookies. The only cookies this site sets are the session cookies in our staff-only admin area, which visitors never reach.

03

Why we are allowed to.

When you send a brief or book a call you are asking us to do something, so we process that data to take steps at your request before entering a contract (GDPR Article 6(1)(b)). Analytics and the audit tool run on our legitimate interest in understanding whether the site works and in demonstrating what we build (Article 6(1)(f)). We do not rely on consent for any of it, because we do not do the kind of tracking that would require it.

04

Where it lives.

The site is hosted on Vercel in EU regions (Frankfurt and Dublin). These are the processors that touch data, and what each one sees:

  • Vercel: hosting, plus the aggregate analytics described above.
  • Airtable: where we keep briefs and audit records so we can act on them.
  • Anthropic and OpenRouter: the models that read a scanned site and write the audit summary. They receive the public page content of the domain you submit.
  • Supabase: authentication for our staff-only admin area.
  • Cloudflare: DNS and CDN, including for our product subdomains.

Some of these are US companies. Where data reaches them, the transfer relies on the safeguards in that provider's own data processing terms, such as standard contractual clauses. We publish this list on /security too, and update it when it changes.

05

How long we keep it.

A brief stays on file while the conversation is live, and for as long as the relationship it might become stays plausible. If it goes nowhere, ask us and we delete it. Operational backups roll on a 30-day window and audit logs on 90 days, matching the retention published on our security page. Analytics is aggregate and holds nothing that identifies you.

06

What you can ask for.

Under GDPR you can ask for a copy of what we hold, have it corrected, have it deleted, have processing restricted, take it elsewhere in a portable format, or object to it entirely. One email to letsbuild@almostalab.io covers all of them, and we do not require you to explain why.

If we handle that badly, you can complain to the Agencia Española de Protección de Datos, Spain's supervisory authority, at aepd.es. You do not need to come to us first.

07

Client project data.

This notice covers this website. Inside a client engagement, the contract and data processing agreement we sign govern the data instead. Our standard DPA template is available within 24 hours of asking.

08

Changes.

If what we collect changes, this page changes with it and the date at the top moves to the day we changed it.