Privacy Policy

Last updated: 18 June 2026

StoryVero respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we collect, use, store, share, and protect personal data when you visit our website, contact us, use our client portal, communicate with us, or work with us as a client, supplier, partner, or business contact.

The data controller for the personal data described in this Privacy Policy is:

Company: STORYVERO SL
Legal address: Carrer d’Aribau, 168, 1-1, 08036 Barcelona, Spain
Tax/VAT number: ESB22598262
Contact: [email protected]

We do not sell personal data. We do not intentionally collect sensitive personal data through our website forms. We do not use personal data to make solely automated decisions that produce legal or similarly significant effects.

If you have questions about this Privacy Policy, you can contact us using the details above.


1. About StoryVero

StoryVero is an AI Visibility Engineering company for B2B brands. We process personal data only where we have a valid reason to do so, such as responding to enquiries, providing services, managing client relationships, operating our website, improving security, meeting legal obligations, and supporting our internal delivery work.


2. When this Privacy Policy applies

This Privacy Policy applies when you:

  • visit storyvero.com or any page that links to this Privacy Policy;
  • contact us through a website form, email, social media, or another communication channel;
  • ask us about our services;
  • become a client, supplier, partner, or business contact;
  • use a client portal or project workspace we provide;
  • share information with us as part of a project, audit, consultation, or service delivery process;
  • request access, correction, deletion, restriction, portability, objection, or another privacy right.

This Privacy Policy does not replace any separate data processing agreement, service agreement, statement of work, or confidentiality agreement that applies to a specific client engagement. Where a separate agreement applies, it will govern the specific processing covered by that agreement.


3. What personal data we collect

The personal data we collect depends on how you interact with us.

3.1 Information you provide directly

You may provide personal data when you complete a form, send us an email, book a call, use a client portal, ask a question, or work with us.

This may include:

  • name;
  • business email address;
  • company name;
  • job title or role;
  • phone number, if you choose to provide it;
  • message content;
  • enquiry details;
  • project requirements;
  • billing details;
  • contract details;
  • client portal account details;
  • files, documents, comments, or other materials you choose to share with us.

Please do not submit sensitive personal data through our website forms or general enquiry channels. Sensitive personal data may include information about health, religion, political opinions, trade union membership, racial or ethnic origin, biometric data, genetic data, or sexual orientation.

If you submit sensitive personal data that we did not request, we may delete it, minimise it, or handle it only where required for a lawful and proportionate purpose.

3.2 Information collected automatically when you use the website

When you visit our website, certain technical information may be collected automatically.

This may include:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • referring page or source;
  • pages visited;
  • date and time of visit;
  • approximate location inferred from IP address;
  • cookie identifiers or similar technical identifiers, where applicable.

This information is used to operate the website, maintain security, understand site performance, and improve the user experience.

We do not collect precise GPS location through the website unless we clearly ask for it and you allow it.

3.3 Cookies and similar technologies

We may use cookies and similar technologies to operate the website, remember preferences, understand website performance, and, where applicable, measure analytics.

Some cookies are necessary for the website to work. Other cookies, such as analytics cookies, are used only where required consent has been obtained.

You can find more information in our Cookie Policy.

3.4 Client-service and project data

When we provide services, we may process business and project information needed to deliver the work.

This may include:

  • client contact details;
  • project communications;
  • website URLs;
  • audit inputs;
  • analytics or search-performance exports provided by the client;
  • page inventories;
  • technical observations;
  • content drafts;
  • audit findings;
  • visibility measurement outputs;
  • reports, recommendations, and delivery records.

Where client materials contain personal data, we process that data only for the relevant service, project, support, legal, or administrative purpose.

3.5 Information from public or third-party sources

In some cases, we may collect or review information from public or third-party sources as part of research, audits, visibility analysis, or service delivery.

This may include:

  • publicly available website content;
  • public business profiles;
  • search results;
  • public social or professional profiles;
  • public directory entries;
  • public citations, mentions, or references;
  • client-provided access to analytics, search, or reporting systems;
  • information provided by service providers used in our delivery workflow.

We do not use this information to make solely automated decisions about individuals.


4. How we use personal data

We use personal data for the following purposes:

PurposeExamples of data usedLegal basis
Responding to enquiriesName, email address, company, message content, enquiry detailsPre-contract steps or legitimate interests
Providing servicesClient contact details, project files, communications, audit inputs, reportsContract
Managing client portal accessName, email address, role, login/account data, project recordsContract
Communicating with clients and business contactsName, email address, company, role, message historyContract or legitimate interests
Operating and securing the websiteIP address, device/browser data, server logs, security logsLegitimate interests
Measuring website performance and analyticsCookie identifiers, page events, device/browser data, approximate locationConsent where required
Managing invoices, payments, and accountingBilling contact details, company details, VAT/tax data, invoice records, payment statusContract and legal obligation
Managing contracts and legal recordsNames, roles, signatures, company details, agreement recordsContract, legal obligation, or legitimate interests
Supporting service delivery with AI-assisted toolsPublic website content, business information, project notes, drafts, audit observations, client-provided materials where appropriateContract or legitimate interests
Improving our services and internal workflowsProject records, feedback, audit observations, aggregated operational notesLegitimate interests
Sending service-related communicationsContact details, project status, administrative updatesContract or legitimate interests
Sending marketing communications, where applicableName, email address, company, consent or unsubscribe statusConsent or legitimate interests where lawful
Handling privacy rights requestsContact details, request details, verification information, response recordsLegal obligation
Protecting legal rights and preventing misuseRelevant records, logs, communications, transaction historyLegitimate interests or legal obligation

5. Legal bases we rely on

Where the General Data Protection Regulation applies, we rely on one or more of the following legal bases.

Contract

We process personal data when it is necessary to provide services, manage client relationships, operate client workspaces, communicate about projects, issue invoices, or take steps before entering into a contract.

Legitimate interests

We may process personal data where it is necessary for our legitimate business interests and those interests are not overridden by your rights and freedoms.

This may include:

  • responding to business enquiries;
  • operating and securing our website;
  • improving our services;
  • managing business communications;
  • keeping appropriate business records;
  • protecting our legal position;
  • analysing business-facing website performance;
  • using proportionate internal tools to support service delivery.

Consent

We rely on consent where required, including for non-essential cookies, certain analytics activities, and marketing communications where consent is the appropriate basis.

You may withdraw consent at any time. Withdrawing consent does not affect processing that took place before the withdrawal.

Legal obligation

We process personal data where required to comply with legal obligations, including accounting, tax, regulatory, and data protection obligations.


6. Use of AI-assisted tools

We may use AI-assisted tools to support research, drafting, summarisation, quality review, audit analysis, and internal service delivery.

Where possible, we use public, business, anonymised, or minimised information rather than unnecessary personal data. We do not intentionally submit sensitive personal data to AI-assisted tools unless it is necessary for a specific agreed purpose and appropriate safeguards are in place.

Depending on the service context, AI-assisted tools may process information such as public website content, business contact details, project notes, draft content, audit observations, prompt outputs, or client-provided materials.

We do not use AI-assisted tools to make solely automated decisions about individuals that produce legal or similarly significant effects. Human review remains part of our service delivery and decision-making process.


7. Website analytics. 

We use Google Analytics (GA4) and Microsoft Clarity to understand website performance and visitor behaviour. Website usage data is captured using first and third-party cookies and other tracking technologies to determine the popularity of services and online activity. Additionally, we use this information for site optimisation and fraud/security purposes. 

For more information about how Google collects and uses your data, visit the Google Privacy and Terms.

For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.


8. International data transfers

StoryVero S.L. is established in Spain and subject to the GDPR. Some of the providers are located outside the European Economic Area, principally in the United States, so personal data may be transferred internationally in the course of our work.

We have signed data processing agreements with providers that incorporate the Standard Contractual Clauses approved by the European Commission for transfers outside the EEA.

Google LLC is self-certified under the EU-U.S. Data Privacy Framework, recognised by the European Commission as providing an adequate level of protection for transfers to certified US organisations.

Microsoft Corporation is self-certified under the same framework.

We review the safeguards relied on by our service providers periodically and will update this section if that changes.


9. How long we keep personal data

We keep personal data only for as long as necessary for the purposes set out in this Privacy Policy, or as required by law.

Data categoryRetention periodWhy
Enquiry and lead data (contacts who do not become clients)12 months from last contactTo allow reasonable follow-up, after which we delete the record unless the person re-engages
Client and project records (drafts, audit findings, deliverables, project communications, client portal account data)6 years from the end of the engagementAligned with our accounting record-keeping period for consistency across all client-related records
Invoices, billing, and accounting records6 years from the date of issueRequired under the Spanish Commercial Code, regardless of preference
Website analytics data (Google Analytics)14 monthsMatches our configured Google Analytics retention setting; data is automatically deleted by Google after this period

When we have no ongoing need to keep personal data, we delete or anonymise it. Where deletion is not immediately possible, for example because data exists in backup archives, we securely isolate it from further use until deletion can be completed.


10. How we keep personal data secure

We use a combination of technical and organisational measures to protect personal data against unauthorised access, loss, or misuse.

All core systems used to store and process personal data are protected with two-factor authentication.

Where personal data is processed by our service providers, those providers maintain their own independently verified security measures: encryption in transit and at rest, IP-restricted access, and regular security testing, SOC 2 Type II, ISO 27001, and ISO 27701 certifications.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. However, we take reasonable steps appropriate to the nature of the data we handle, and we review our practices as our use of tools and services evolves.


11. Children’s data

Our services are intended for businesses and professional contacts, not for children. We do not knowingly collect personal data from anyone under 18 years of age. If we become aware that we have inadvertently collected personal data from a minor, we will take reasonable steps to delete it.

If you believe a minor has provided us with personal data, please contact us using the details in section 1.


12. Your data protection rights

Where the GDPR or UK GDPR applies to the processing of your personal data, you have the following rights:

Right of access, to obtain confirmation of whether we process your personal data and a copy of it. Right to rectification, to have inaccurate or incomplete personal data corrected. Right to erasure, to request deletion of your personal data in certain circumstances. Right to restrict processing, to limit how we use your personal data while a concern is resolved. Right to data portability, to receive personal data you provided to us in a structured, commonly used format, where processing is based on consent or contract and carried out by automated means. Right to object, to object to processing based on legitimate interests, including for direct marketing. Right to withdraw consent, at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.

You also have the right to lodge a complaint with a supervisory authority. As StoryVero S.L. is established in Spain, the relevant authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), though you may also contact the supervisory authority in your own country of residence.

How to exercise these rights. Contact us at [email protected]. To protect your data, we may need to verify your identity before acting on a request. We aim to respond within one month, extendable by a further two months for complex requests, in which case we will explain the delay.

These rights may not apply, or may be limited, in certain circumstances permitted by law, for example where we have an overriding legal obligation to retain data.


13. US privacy notice

Most of our US-based contacts interact with us in a business-to-business capacity, for example as an employee, contractor, or representative of a client, supplier, or business partner, rather than as an individual consumer.

Many comprehensive US state privacy laws, including those in Virginia, Colorado, Connecticut, and Utah, generally apply to personal information processed in a personal or household context, and exclude personal information processed in an employment or business-to-business context. Where that exclusion applies, those laws do not create rights beyond what is already described in this Policy.

California’s privacy law (the CCPA, as amended by the CPRA) does extend some rights to personal information collected in a business-to-business context. However, CCPA obligations apply only to businesses meeting specific size or data-volume thresholds, for example, gross annual revenue above $25 million, or processing personal information for a large volume of consumers or households. We do not currently meet these thresholds.

Regardless of strict legal applicability, we extend the following to any US-based contact, consistent with the rest of this Policy: we do not sell or share personal information for cross-context behavioural advertising; you may request access to, correction of, or deletion of your personal data by contacting [email protected]; and we will not discriminate against you for exercising these rights.

If you believe a specific state law gives you rights not addressed here, please contact us and we will respond accordingly.


14. Do Not Track signals

Some web browsers offer a “Do Not Track” (DNT) setting. There is currently no industry-standard way to interpret DNT signals, so we do not respond to them. If a uniform standard is adopted in the future, we will update this Policy accordingly.


15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. The “Last updated” date at the top of this Policy shows when it was last revised. Where changes are material, we will take reasonable steps to bring them to your attention, for example by posting a notice on our website. We encourage you to review this Policy periodically.