Privacy Policy
This Privacy Policy explains how Ludosati SL ("Ludosati", "we", "us" or "our") processes personal data in connection with the Spend Your Habits mobile application (available on the Apple App Store and Google Play, and built with Expo/React Native) and the marketing and support website at https://spendyourhabits.com (together, the "Service").
We have written this policy to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Spanish data-protection law, and to be as transparent as possible about what we do and (just as importantly) what we do not do. Spend Your Habits is a gamified habit tracker: completing self-defined habits earns virtual coins, which you spend on self-defined personal rewards. The coins are virtual only and have no monetary value.
1. Who we are
The controller responsible for the processing of your personal data is:
- Ludosati SL, a Spanish limited company (sociedad limitada)
- Registered office: Calle De Valverde 17, 3C, 28004 Madrid, Spain
- NIF: B19831650
- Company registry: Registro Mercantil de Madrid, Hoja M-826660, Inscripción 1ª
Our full company identification and corporate contact details are set out on the Legal Notice page of our website.
To exercise your privacy rights, ask us a question, or send us a complaint about how we handle your data, please use the forms on our Support page: the contact form for general enquiries and the data-deletion request form for erasure requests. We have deliberately designed this policy so that you never need an email address to reach us: the Support page forms are the single point of contact for all privacy matters.
2. Scope of this policy
This policy covers:
- Your use of the Spend Your Habits mobile app on iOS and Android; and
- Your use of the spendyourhabits.com website, including its contact and data-deletion forms, email marketing, AI support chat, life audit and code-protected plans.
The website is available in English at the root and in Spanish under the /es path. Language selection is expressed through the URL and is not stored.
This policy does not cover third-party services that you may choose to use in connection with the Service and that act as independent controllers, for example the Apple App Store, Google Play, or the identity providers you may use to sign in (Google, Apple). Their own privacy policies govern their processing. Where those parties act as our processors, they are covered here (see Section 5).
3. Data we process
We divide this section into (a) data processed when you visit the website, and (b) data processed when you use the app. The app is local-first: your device database remains authoritative, while an automatic whole-database cloud snapshot provides backup after account creation.
3.1 Website visitors
(a) Contact form and data-deletion request form. When you submit either form, we process the name, email address and message text you provide. These submissions are delivered to our support inbox by Resend, Inc. (a US email-delivery processor), with the reply-to address set to the address you provided so we can respond to you. We use this data to answer your enquiry or to process your deletion request. Deletion requests are reviewed and actioned by a human being (there is no automated deletion pipeline) within the statutory GDPR period (one month, extendable in accordance with Article 12(3) GDPR where a request is complex or where we receive numerous requests).
(b) Email marketing. If you join the waitlist, including when you submit your address to unlock Habit Ranker results, we store your email address and the signup source in a private Google Sheet. The Habit Ranker gate states that it joins the waitlist before you submit. If we begin sending marketing email, we will also process the subscription and unsubscribe status needed to respect your choice. Every marketing email identifies Ludosati and contains a simple, free unsubscribe link. We do not use marketing-email open or click tracking unless this policy is updated before that processing begins.
(c) Website AI chat and life audit. Our website offers AI features to answer product questions, rank habits and create a coaching plan. The support chat processes the messages you type, your interface language, the accepted notice version and the AI responses. The Habit Ranker processes the habit titles, optional goals and frequencies you submit. It keeps the current draft and generated ranking in your browser's local storage for no longer than 24 hours so you can continue or retry, and it never stores your email address or bot-protection token there. The Habit System Creator keeps its answers, AI responses and chat transcript in that browser's local storage for up to 30 days so a refresh can restore the conversation; Start over removes them immediately. Before a life audit or habit ranking starts, you must actively consent to the applicable live processing. The website server sends support-chat and Habit Ranker fields directly to the fixed and allowlisted DeepSeek Open Platform API at api.deepseek.com. DeepSeek states that its services are not designed for sensitive personal data, so do not enter sensitive information in these AI features. DeepSeek may process and store inputs in China, its general policy does not set a fixed retention period for downstream API inputs, and no no-training commitment applies unless separately agreed. DeepSeek's published Privacy Policy says that downstream end-user processing is not covered by that policy. Its Open Platform Terms place end-user disclosure, lawful-basis and delegated-processing duties on the developer. The opening consent covers live AI processing and the Habit Ranker's disclosed local draft. It does not authorize later Plan ID storage. To limit abuse, we apply per-IP usage caps of 20 messages per day and 50 per week.
(d) Code-protected AI plans. The validated importable habit-and-reward plan remains in the browser session unless you separately and explicitly choose Finalize plan and confirm the 30-day storage notice. Only then do we store that exact plan with Supabase. The plan can contain recurring habit and reward text and settings, but not your app account, completion history, coin balance or one-off cards. We generate a unique access code and link. Anyone who has the complete code or link can view and import the plan. The code is not tied to an account and is not proof of identity or ownership, so keep it private and share it only with people you trust. Plans cannot be listed, searched or browsed. The stored plan is immutable and has no ownership, recovery or early-deletion API. It stops being accessible exactly 30 days after creation and is then automatically deleted from active storage by the next daily cleanup.
Optional email and PNG delivery. If you explicitly request delivery during finalization, the website sends your email address, Plan ID, database-owned expiry date and only the PNG files you selected to a private n8n workflow. That workflow uses Gmail to send the message and a private Google Sheet to record the normalized email, Plan ID, delivery time and expiry. Supabase never receives the email, PNG files or delivery status. This optional workflow must not be enabled until n8n is configured not to retain execution inputs or outputs and to retain only redacted operational metadata for a short fixed period. The private Sheet row and sender-controlled Gmail copies are scheduled for deletion after a verified early erasure request for the delivery record or by the first daily cleanup after the plan expires, at most 24 hours later. This does not delete the immutable Supabase plan before its expiry. Google provider backups and the recipient's independent mailbox may retain copies for longer. A delivery failure does not change or extend the plan's fixed 30-day lifetime.
(e) Bot protection: Cloudflare Turnstile. All of our forms and the AI chat are protected against automated abuse by Cloudflare Turnstile (provided by Cloudflare, Inc., US). To perform its bot-detection challenge, Cloudflare receives your IP address and a challenge token. The Turnstile widget is the only third-party script on the site, and it may set strictly necessary Cloudflare cookies or tokens for this purpose (see Section 13).
(f) Security and abuse prevention. We read IP addresses from request headers to apply per-IP rate limiting. For public-tool quotas, we transform identifiers such as an IP address or email address with a secret-keyed HMAC before the rate-limit request leaves our server. Upstash Redis in AWS Frankfurt stores only the resulting opaque identifier, a request count and its automatic expiry. It does not receive the raw identifier or any plan, chat or questionnaire content as rate-limit data. Each counter expires after its applicable limit window, no later than seven days. Other short-lived site counters remain only in server memory. We do not use rate-limit data to build a profile of you. IP addresses and form-submission events also appear in the server logs of our hosting provider Vercel Inc. (US). We additionally use honeypot and timing fields (non-identifying) to screen out bots.
(g) No analytics, advertising or tracking on the website. The website itself sets no cookies of its own. The Habit Ranker uses local storage only for the disclosed 24-hour draft and generated ranking, while the Habit System Creator uses it for the disclosed 30-day transcript. There is no web analytics, no advertising and no cross-site tracking. Fonts are self-hosted, so your browser makes no runtime requests to external font services. Language selection is expressed in the URL (/es) and is not stored.
3.2 App users
(h) Local-first by design. Your habits, completions, streaks, coin ledger, rewards and history are stored in an authoritative local database on your device. After you create an account, the App automatically sends an encrypted-in-transit snapshot of that whole database to our backup provider. Ludosati does not operate a row-by-row product database or routinely inspect the content of your backup. Please note honestly that habit names and content are free text that you define, and could indirectly reveal information about your lifestyle or wellbeing. Spend Your Habits is a self-improvement tool and not a medical service or a source of medical advice.
(i) Account and automatic cloud snapshots. An account is required to use the App. We support authentication via email and password, Google sign-in or Apple sign-in. When creating an account, you actively accept the Terms and this Privacy Policy and expressly consent to the secure cloud backup of the app content you choose to enter, including content that may reveal health or other sensitive information. After account creation, the App automatically sends compressed, encrypted-in-transit snapshots of the whole on-device database to a private Supabase Storage bucket protected by per-user access controls. Supabase Postgres stores the current snapshot pointer and technical integrity metadata. We retain the current snapshot plus up to three recent recovery snapshots and prune older versions. The snapshots are copies; the on-device database remains authoritative. Account deletion removes the account-linked snapshot objects and pointer.
(j) Purchases and subscriptions. If you choose to subscribe, subscriptions are purchased through the Apple App Store or Google Play. Entitlement status is managed for us via RevenueCat, Inc. (US). We receive purchase and entitlement metadata (such as product identifier, store transaction identifiers and entitlement state), but never your full payment card details. Apple and Google handle the payment itself.
(k) App diagnostics and usage. We use Sentry in its EU data region for crash, error and performance diagnostics. Reports may carry your account ID so we can identify and delete account-linked diagnostics, but default PII collection is disabled and user-authored card text and database content are scrubbed. We use TelemetryDeck for privacy-focused product analytics with a random per-install identifier that is not tied to your name, email or account and is not included in cloud snapshots. You can disable both through the App's Share diagnostics setting. InsertAffiliate may process affiliate attribution and store-purchase event data through RevenueCat without advertising identifiers.
(l) In-app AI assistant. The in-app assistant is menu-driven (no free-text chat) and processed by an EU-hosted AI provider with data minimisation. It receives generic catalogue content and structured selections, not your user-authored cards, account identity, usage history or IP address. This is distinct from the website AI chat described in Section 3.1(c).
(m) Notifications. If you enable reminders, the App requests operating-system notification permission. Reminders are scheduled locally on your device only. We use no push-notification service and generate no push tokens.
(n) No advertising or cross-app tracking. The App contains no ads, uses no advertising identifiers (no IDFA or GAID) and does not track you across unrelated companies' apps or websites for advertising. No App Tracking Transparency prompt is required. Apart from notification permission when you enable reminders, the App does not request access to your camera, location, contacts, microphone or photos.
3.3 Summary table
| Flow | Data categories | Recipient(s) | Where |
|---|---|---|---|
| Contact / deletion form | Name, email, message | Resend | Website |
| Email marketing | Email and signup source; subscription and unsubscribe status when mailing begins | Google Sheets; Resend when mailed | Website |
| Website AI processing | Chat messages, habit titles, optional goals, frequencies, replies, language and accepted notice version | DeepSeek Open Platform | Website, China |
| Code-protected AI plan | Habit/reward plan, access code, creation time | Supabase | Website |
| Optional plan delivery | Email, Plan ID, expiry and selected PNG files | Private n8n, Gmail, Google Sheets | Website |
| Bot protection | IP address, challenge token | Cloudflare Turnstile | Website |
| Security / rate limiting | IP and submission events in hosting logs; opaque keyed identifiers, counters and expiry for public-tool quotas | Vercel; Upstash | Website; AWS Frankfurt |
| Local app data | Habits, completions, streaks, coins, rewards, history | None (on device) | Your device |
| Account + cloud snapshots | Login identifier, snapshot files and technical metadata | Supabase | Cloud |
| Purchases (optional) | Purchase/entitlement metadata | RevenueCat, Apple, Google | App/Store |
| Diagnostics and analytics | Account-tagged diagnostics, random per-install analytics ID | Sentry, TelemetryDeck | App |
| Affiliate attribution | Attribution and store-purchase event metadata | InsertAffiliate, RevenueCat | App |
4. Purposes and legal bases
We only process personal data where we have a lawful basis under Article 6(1) GDPR. The table below maps each purpose to its basis.
| Purpose | Legal basis |
|---|---|
| Answering your contact enquiries | Article 6(1)(b) (steps at your request / performance of a contract) and, where you are not yet a customer, our legitimate interest in responding (Art. 6(1)(f)) |
| Processing data-deletion requests | Article 6(1)(c) (legal obligation to honour your rights) |
| Sending optional email marketing | Article 6(1)(a) (consent), withdrawable through every marketing email |
| Operating live website AI processing and the local ranker draft | Article 6(1)(a) (consent), actively given before the applicable AI feature starts |
| Creating and temporarily storing a code-protected AI plan | Article 6(1)(b) (providing the plan separately requested during finalization); Article 9(2)(a) explicit consent also applies if the finalized plan contains special-category data |
| Sending an optional Plan ID and selected PNG files by email | Article 6(1)(a) (consent), requested separately during finalization |
| Providing the app and account features | Article 6(1)(b) (performance of a contract) |
| Automatic cloud backup | Article 6(1)(b) (performance of a contract); Article 9(2)(a) explicit consent for any special-category content you choose to enter |
| Purchases and subscriptions | Article 6(1)(b) (performance of a contract) |
| Keeping commercial and tax records for purchases | Article 6(1)(c) (legal obligation) |
| Security, rate limiting, bot protection, fraud/abuse prevention | Article 6(1)(f) (legitimate interest in keeping the Service secure and available) |
| Crash reporting and privacy-focused analytics | Article 6(1)(f) (legitimate interest in a stable, improving product) |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms and use only the minimum data necessary (for example, transforming rate-limit identifiers before storing short-lived counters). You may object to legitimate-interest processing as described in Section 8.
Where we rely on consent (email marketing, live website AI processing, optional plan delivery, sensitive information in a finalized stored plan, and any special-category content you choose to include in an app cloud backup), you may withdraw it at any time; withdrawal does not affect the lawfulness of processing before withdrawal. Marketing consent is withdrawn through the unsubscribe link in each marketing email. You can stop live AI processing by ending the chat and remove the Habit Ranker draft with Start new chat. The immutable Plan ID service has no owner, recovery or early-deletion API, so do not finalize content that you may need removed before its fixed 30-day expiry. A request through the contact form can identify and erase a separate optional delivery record when you provide the complete Plan ID, but it does not delete the Supabase plan early. Because cloud backup is an automatic account feature, you can stop that processing and delete the cloud snapshots by deleting your account through the App or the data-deletion form.
Children (Article 8 GDPR). The Service is intended only for users aged 16 or over. We do not operate any parental-consent flow, because under-16s are not permitted to use the Service in the first place. See Section 11.
5. Recipients and service providers
We do not sell your personal data. Depending on the flow, the following companies act as our processors, service providers or independent controllers:
- Resend, Inc. (US): delivery of support, account and optional marketing emails; receives the relevant email address, message content and delivery or unsubscribe status.
- Cloudflare, Inc. (US): bot protection (Turnstile); receives your IP address and a challenge token.
- DeepSeek Open Platform, operated by Hangzhou DeepSeek Artificial Intelligence Co., Ltd. in China: direct support-chat and Habit Ranker inference through the fixed api.deepseek.com endpoint; receives the applicable data described in Section 3.1(c).
- EUrouter: the separate in-app structured assistant described in Section 3.2(l); it does not process the website life audit.
- Private n8n workflow and Google Gmail/Sheets: optional Plan ID and PNG delivery requested during finalization; receive only the data described in Section 3.1(d). This workflow remains unavailable until its private hosting, access and retention controls are configured.
- Vercel Inc. (US): website hosting; IP addresses and submission events appear in server logs.
- Upstash, Inc. (US): public-tool rate limiting; its Redis service in AWS Frankfurt receives only opaque secret-keyed identifiers, request counts and automatic expiry times.
- Supabase, Inc.: authentication, private cloud snapshot storage, technical snapshot metadata and temporary storage of code-protected AI plans.
- Apple / Google: independent controllers for Store purchases and sign-in services under their own privacy notices; they may also process limited data on our behalf for specific service functions.
- RevenueCat, Inc. (US): subscription entitlement management; receives purchase/entitlement metadata.
- Functional Software, Inc. (Sentry): EU-region crash, error and performance diagnostics, including the account ID where needed for support and deletion.
- TelemetryDeck GmbH (EU): privacy-focused product analytics via a random per-install identifier.
- InsertAffiliate: affiliate install attribution in connection with RevenueCat webhooks.
We may also disclose data where required by law, court order or a valid request from a competent authority, or to establish, exercise or defend legal claims.
6. International transfers
Some of our processors are located outside the European Economic Area (EEA). Whenever we transfer personal data internationally, we ensure an appropriate safeguard under Chapter V GDPR is in place.
The optional n8n, Gmail and private Google Sheet delivery workflow must not be activated until its hosting region, access controls, Google account terms and applicable transfer safeguard have been reviewed and configured. If that workflow creates a restricted transfer, we will apply the appropriate Chapter V GDPR safeguard before enabling it.
The support chat and Habit Ranker send data directly to DeepSeek in China after the active consent described above. DeepSeek's public Open Platform terms do not provide a public DPA, SCC commitment or fixed downstream API retention term.
Where a US recipient's current EU-US Data Privacy Framework certification covers the relevant transfer, we rely on the European Commission's adequacy decision for that framework. This applies to the covered services of Resend, Cloudflare, Vercel and Sentry while their certifications remain active and applicable.
The Upstash Redis database stores its rate-limit content in the AWS Frankfurt region selected by Ludosati. Upstash, Inc. is based in the US, and its data-processing agreement incorporates the European Commission's Standard Contractual Clauses (SCCs) for restricted transfers and provides for the Data Privacy Framework where applicable.
For other restricted transfers, including transfers to RevenueCat and any transfer for which a provider's certification does not apply, we rely on the European Commission's Standard Contractual Clauses (SCCs) incorporated into the relevant data-processing agreement, together with supplementary measures where appropriate. Supabase processes data in the project region selected by Ludosati but may use non-EEA corporate support or subprocessors under its DPA and SCCs. Apple and Google explain their international transfers in their own privacy notices when they act as independent controllers.
You may request information about the safeguard relevant to a particular transfer through our contact form.
7. Retention
We keep personal data only for as long as necessary for the purposes described above.
- Contact and deletion-request submissions: retained while we handle the request and afterwards only for the applicable legal limitation period where needed to demonstrate compliance or establish, exercise or defend legal claims.
- Email marketing: the active subscription is retained until you unsubscribe or we end the marketing list. After unsubscribe, we keep the minimum email and suppression evidence needed to honour your choice and demonstrate compliance, but we do not send further marketing.
- AI chat messages: the support chat is not persisted after the live conversation. The Habit System Creator's answers, AI responses and transcript remain in that browser for up to 30 days from the run and Start over deletes them immediately. Each request carries the version of the notice you actively accepted, but we do not create a separate identity-linked chat-consent profile.
- Habit Ranker browser draft: the current habit titles, optional goals, frequencies, stage and generated ranking remain only in that browser for no longer than 24 hours from the start of the run. Start new chat removes them immediately. The email address and Turnstile token are never included.
- Code-protected AI plans: accessible for exactly 30 days after creation, then rejected by the lookup and automatically deleted from active storage by the next daily cleanup. A plan is not tied to your app account and the immutable sharing service has no owner, recovery or early-deletion API.
- Optional plan delivery: when the private workflow is enabled and you request it, the Google Sheet row and sender-controlled Gmail copies are scheduled for deletion after a verified early erasure request for the delivery record or by the first daily cleanup after the plan expires, at most 24 hours later. This does not delete the immutable Supabase plan before its expiry. n8n must retain no execution inputs or outputs and only redacted operational metadata for a configured short fixed period. Google provider backups and the recipient's mailbox may retain copies for longer.
- Rate-limit data: public-tool counters in Upstash contain only an opaque secret-keyed identifier, request count and expiry. They expire automatically after the applicable window, no later than seven days. Other transient site counters remain in server memory only.
- Server logs: retained for the hosting provider's configured short operational and security period, no longer than 30 days unless a specific security incident or legal obligation requires preservation.
- On-device app data: retained on your device until you delete it or uninstall the app; this is entirely under your control.
- Cloud snapshots: the current snapshot plus up to three recent recovery snapshots are retained while your account exists; older versions are pruned. Account deletion removes the snapshot objects and pointer from active storage, subject to limited provider disaster-recovery copies that age out under the provider's backup cycle.
- Diagnostics and analytics: retained under the configured Sentry and TelemetryDeck retention periods. Disabling Share diagnostics stops new collection; account deletion requests deletion of Sentry data keyed to your account ID.
- Purchase records: retained for the statutory commercial and tax record-keeping periods applicable in Spain, including records that RevenueCat, Apple or Google must retain independently.
Deleting your Spend Your Habits account does not cancel an Apple or Google subscription. It removes account-linked Supabase data and requests deletion of account-linked Sentry diagnostics, but it does not automatically remove a code-protected plan or data still stored locally on a device.
8. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten");
- Restrict processing in certain circumstances;
- Data portability: receive certain data in a structured, commonly used, machine-readable format;
- Object to processing based on our legitimate interests;
- Withdraw consent at any time where processing is based on consent (email marketing, live website AI processing, optional delivery, sensitive content in a finalized plan and special-category content in cloud backups), without affecting the lawfulness of prior processing. The immutable plan and early-deletion limitation described in Sections 3.1(d), 4 and 7 still applies.
We do not carry out any automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
How to exercise your rights. Please use the forms on our Support page: the contact form or, for erasure, the data-deletion form. We may need to take reasonable steps to verify your identity before acting, to protect your data from unauthorised disclosure. We will respond within one month, extendable by up to two further months for complex or numerous requests, in which case we will inform you.
Note that most of your app data lives on your device: you can exercise access, portability and erasure over that data directly by viewing, exporting (where available) or deleting it, or by uninstalling the app.
9. Complaints to a supervisory authority
If you believe we have processed your personal data unlawfully, you have the right to lodge a complaint with a supervisory authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD), www.aepd.es. You may also complain to the supervisory authority in your EU country of residence, place of work or the place of the alleged infringement. We would, of course, appreciate the chance to address your concerns first via the Support page.
10. Users outside the EEA
10.1 California residents (CCPA / CPRA)
If you are a California resident, the following applies. In the past 12 months we have collected the following categories of personal information, depending on which features you use:
- Identifiers (name, email address, IP address, per-install or account identifiers);
- Internet or other electronic network activity (form submissions, chat messages, rate-limiting signals);
- Commercial information (subscription/entitlement metadata);
- Customer records (contact-form content and code-protected habit-and-reward plans); and
- Diagnostics (crash, error and performance information linked to an account where applicable).
We do not "sell" your personal information and do not "share" it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA, and we do not engage in targeted advertising. You have the right to know, delete, correct, and to non-discrimination for exercising your rights. Exercise these rights via the Support page forms.
10.2 United Kingdom
If you are in the United Kingdom, the UK GDPR applies and mirrors the protections described above. You may lodge a complaint with the UK Information Commissioner's Office (ICO).
10.3 Other jurisdictions
If you access the Service from another jurisdiction, your local data-protection laws may grant you rights similar to those above. We aim to honour valid requests consistent with applicable law; please contact us through the Support page.
11. Children
The Service is not directed at children and is intended only for users aged 16 or over. We do not knowingly collect personal data from anyone under 16, and we operate no parental-consent mechanism because under-16s may not use the Service. If you believe a person under 16 has provided us with personal data, please notify us through the Support page and we will delete it.
12. Security
We implement proportionate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure. These include our local-first architecture, private per-user cloud storage, row-level access controls, encryption in transit, bot protection and rate limiting. A code-protected plan is intentionally accessible to anyone with its complete code, so the code's confidentiality depends partly on how you share it. No method of transmission or storage is ever completely secure, however, and we cannot guarantee absolute security.
13. Cookies and similar technologies
The spendyourhabits.com website sets none of its own cookies. The Habit Ranker stores its disclosed draft and generated ranking in local storage for no longer than 24 hours. The only cookies or tokens that may be set are the strictly necessary cookies/tokens used by Cloudflare Turnstile to perform bot protection on the forms and AI chat. Because these are strictly necessary for a service you have requested, they do not require a consent banner under the ePrivacy rules. We use no advertising or analytics cookies on the website whatsoever.
14. Changes to this policy
We may update this policy from time to time, for example when backup or account features change or when we engage a new processor. When we do, we will revise the "Last updated" date at the top. For material changes, we will take reasonable steps to bring them to your attention through the Service or the website before they take effect. We encourage you to review this policy periodically.
15. How to contact us
For any question about this policy or your personal data, or to exercise your rights, please use the forms on our Support page:
- General enquiries: the contact form
- Data-deletion requests: the deletion form
Our full company identification is available on the Legal Notice page of our website. Ludosati SL is the controller responsible for your personal data as described in Section 1.
