Privacy & cookies
Your privacy, in plain language.
MC²Digital uses only the information needed to respond to enquiries and understand the overall use of this website. We do not sell personal information or use advertising trackers.
Who is responsible?
MC²Digital is responsible for the personal information described in this notice. Questions or privacy requests can be sent to info@mc2digital.eu or made by telephone on +34 683 379 926.
When you contact us
When you submit the contact form, the name, work email address, organisation and message you provide are sent to MC²Digital through our transactional email provider, Resend. We use this information to respond to your enquiry, discuss a possible engagement and maintain relevant business correspondence. The legal basis is our legitimate interest in responding to business enquiries and, where applicable, taking steps at your request before entering into a contract.
The website does not store the content of your enquiry in its analytics database. Proportionate request and security data may be processed temporarily in operational logs and for rate limiting so that we can deliver, protect and troubleshoot the service. Enquiries that do not lead to an engagement are normally deleted after 24 months; information connected with a client relationship may be retained longer as described below.
Website hosting and analytics
This website is hosted using OpenAI Sites. Sites records high-level traffic information automatically, including unique visitors and page views over time. MC²Digital also records aggregate daily counts for consultation call-to-action use, form starts, provider-accepted enquiries and failed submissions, together with privacy-safe source and automation classifications. These measurements help us understand whether the website is useful, improve its performance and distinguish credible human activity from bots or scanners.
The analytics database does not contain the name, email address, organisation, message or IP address submitted through the contact form. Technical requests and logs may be processed by the hosting provider and other service providers needed to operate, secure, measure and deliver the website and its email service. We have not added Google Analytics, advertising pixels or behavioural marketing tools. OpenAI states that Sites does not currently offer data-residency controls. More information is available in OpenAI’s privacy policy.
Cookies
The public MC²Digital website does not set its own analytics, advertising or personalisation cookies. Restricted client areas use a strictly necessary, secure session cookie after sign-in so that authorised users can remain authenticated. We will introduce a consent choice before adding any non-essential technology that requires it. The hosting service may also use technology needed to deliver, protect and measure the website; this notice will be updated if the site’s cookie use changes.
Restricted client services
Some invitation-only areas support client diagnostics or workshops. These services may process an authorised participant’s business contact details, role, organisation, access records and the responses they choose to provide. Authentication records and a strictly necessary session cookie are used to protect access.
That information is used to provide the agreed service, preserve a participant’s progress, prepare relevant workshop outputs and administer access. The applicable basis is performance of the client engagement, steps connected with it and MC²Digital’s legitimate interest in delivering and securing the service. Access is limited to authorised participants and administrators.
Client-service records are retained for the period agreed with the relevant client, or otherwise only as long as reasonably necessary to deliver the engagement and meet legal or contractual obligations. A client-specific notice or agreement may provide additional information and takes precedence where it gives more specific terms.
Sharing and retention
Information is shared only with service providers needed to host the website, deliver email and operate the business, or where disclosure is legally required. Providers may process information outside the European Economic Area subject to the safeguards made available by the relevant provider.
Enquiries that do not lead to an engagement are normally deleted after 24 months. Information connected with a client relationship may be kept longer where needed for the relationship, accounting, legal obligations or the establishment or defence of legal claims.
Your rights
Depending on the circumstances, you may ask to access, correct or erase your personal information; restrict or object to its use; or receive portable data. You may also complain to the data-protection authority in the country where you live or work. For Spain, this is the Agencia Española de Protección de Datos.
Security and changes
We use proportionate organisational and technical safeguards, including encrypted website delivery and restricted access to business systems. This notice is reviewed when the website or its data use changes.
Last updated: 3 September 2026
Back to the website