Privacy information · GDPR baseline
Privacy & data protection
This notice explains the current categories of personal data used to operate Memory Continuity. It is an operator-ready baseline for EU/EEA visitors, with UK and international disclosures where relevant.
Principle and Legal Posture
The pilot must comply with the General Data Protection Regulation (GDPR) and applicable Spanish law, including the Spanish Organic Law on Data Protection and Digital Rights Guarantee (LOPDGDD). Memory Continuity operates under strict principles of lawfulness, fairness, purpose limitation, transparency, and data minimization across all family digital archives and public memorial QR links.
Data, purposes, and lawful basis
The service may process administrator account details, authentication identifiers, contribution names and content, media files, technical security information, language preference, consent records, and limited usage analytics if you opt in. Processing is used to provide requested memorial and moderation features, secure the service, comply with legal obligations, manage verified rights requests, and—only where selected—understand aggregate usage. The precise lawful basis must be documented per processing activity by the controller.
Recipients, publication, and transfers
Approved memorial material is intentionally displayed on the selected public memorial. Hosting, authentication, managed storage, analytics, support, and notification providers may process relevant data as processors. Where EEA personal data is transferred outside the EEA, the operator must document the actual safeguard, such as adequacy, standard contractual clauses, or another permitted mechanism.
Your choices and rights
You may request access, correction, deletion, restriction, objection, portability where applicable, or withdrawal of consent. Contributors may request withdrawal of their material; approved content may be removed subject to verification, technical constraints, and legal retention duties. A rights request must be sent to the verified privacy contact in the operator profile. EEA visitors may also complain to their supervisory authority, including the AEPD or APDCAT where relevant.
International visitors
The service does not sell or share personal information for cross-context behavioural advertising unless the operator later enables such activity and updates this notice. California and other non-EEA privacy rights can depend on the controller’s circumstances, thresholds, and processing; a general privacy-request route is available, but jurisdiction-specific rights must be assessed before a specific compliance claim is made.
Operator profile pending confirmation
- Controller
- Operator details pending confirmation
- Registered address
- Registered address pending confirmation
- Privacy contact
- Privacy contact pending confirmation
- Consumer contact
- Consumer contact pending confirmation
- Registration / NIF / CIF
- Registration / NIF / CIF pending confirmation
- Retention
- Retention schedule pending confirmation
- Providers
- Hosting, authentication, storage, analytics, and support vendor list pending confirmation
- Transfers
- International-transfer assessment and safeguards pending confirmation