Privacy Policy
StoryVero respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains how we collect, use, store, share, and protect personal data when you visit our website, contact us, use our client portal, communicate with us, or work with us as a client, supplier, partner, or business contact.
The data controller for the personal data described in this Privacy Policy is:
Company: STORYVERO SL
Legal address: Carrer d’Aribau, 168, 1-1, 08036 Barcelona, Spain
Tax/VAT number: ESB22598262
Contact: [email protected]
We do not sell personal data. We do not intentionally collect sensitive personal data through our website forms. We do not use personal data to make solely automated decisions that produce legal or similarly significant effects.
If you have questions about this Privacy Policy, you can contact us using the details above.
1. About StoryVero
StoryVero is an AI Visibility Engineering company for B2B brands. We process personal data only where we have a valid reason to do so, such as responding to enquiries, providing services, managing client relationships, operating our website, improving security, meeting legal obligations, and supporting our internal delivery work.
2. When this Privacy Policy applies
This Privacy Policy applies when you:
- visit storyvero.com or any page that links to this Privacy Policy;
- contact us through a website form, email, social media, or another communication channel;
- ask us about our services;
- become a client, supplier, partner, or business contact;
- use a client portal or project workspace we provide;
- share information with us as part of a project, audit, consultation, or service delivery process;
- request access, correction, deletion, restriction, portability, objection, or another privacy right.
This Privacy Policy does not replace any separate data processing agreement, service agreement, statement of work, or confidentiality agreement that applies to a specific client engagement. Where a separate agreement applies, it will govern the specific processing covered by that agreement.
3. What personal data we collect
The personal data we collect depends on how you interact with us.
3.1 Information you provide directly
You may provide personal data when you complete a form, send us an email, book a call, use a client portal, ask a question, or work with us.
This may include:
- name;
- business email address;
- company name;
- job title or role;
- phone number, if you choose to provide it;
- message content;
- enquiry details;
- project requirements;
- billing details;
- contract details;
- client portal account details;
- files, documents, comments, or other materials you choose to share with us.
Please do not submit sensitive personal data through our website forms or general enquiry channels. Sensitive personal data may include information about health, religion, political opinions, trade union membership, racial or ethnic origin, biometric data, genetic data, or sexual orientation.
If you submit sensitive personal data that we did not request, we may delete it, minimise it, or handle it only where required for a lawful and proportionate purpose.
3.2 Information collected automatically when you use the website
When you visit our website, certain technical information may be collected automatically.
This may include:
- IP address;
- browser type and version;
- device type;
- operating system;
- referring page or source;
- pages visited;
- date and time of visit;
- approximate location inferred from IP address;
- cookie identifiers or similar technical identifiers, where applicable.
This information is used to operate the website, maintain security, understand site performance, and improve the user experience.
We do not collect precise GPS location through the website unless we clearly ask for it and you allow it.
3.3 Cookies and similar technologies
We may use cookies and similar technologies to operate the website, remember preferences, understand website performance, and, where applicable, measure analytics.
Some cookies are necessary for the website to work. Other cookies, such as analytics cookies, are used only where required consent has been obtained.
You can find more information in our Cookie Policy.
3.4 Client-service and project data
When we provide services, we may process business and project information needed to deliver the work.
This may include:
- client contact details;
- project communications;
- website URLs;
- audit inputs;
- analytics or search-performance exports provided by the client;
- page inventories;
- technical observations;
- content drafts;
- audit findings;
- visibility measurement outputs;
- reports, recommendations, and delivery records.
Where client materials contain personal data, we process that data only for the relevant service, project, support, legal, or administrative purpose.
3.5 Information from public or third-party sources
In some cases, we may collect or review information from public or third-party sources as part of research, audits, visibility analysis, or service delivery.
This may include:
- publicly available website content;
- public business profiles;
- search results;
- public social or professional profiles;
- public directory entries;
- public citations, mentions, or references;
- client-provided access to analytics, search, or reporting systems;
- information provided by service providers used in our delivery workflow.
We do not use this information to make solely automated decisions about individuals.
4. How we use personal data
We use personal data for the following purposes:
| Purpose | Examples of data used | Legal basis |
|---|---|---|
| Responding to enquiries | Name, email address, company, message content, enquiry details | Pre-contract steps or legitimate interests |
| Providing services | Client contact details, project files, communications, audit inputs, reports | Contract |
| Managing client portal access | Name, email address, role, login/account data, project records | Contract |
| Communicating with clients and business contacts | Name, email address, company, role, message history | Contract or legitimate interests |
| Operating and securing the website | IP address, device/browser data, server logs, security logs | Legitimate interests |
| Measuring website performance and analytics | Cookie identifiers, page events, device/browser data, approximate location | Consent where required |
| Managing invoices, payments, and accounting | Billing contact details, company details, VAT/tax data, invoice records, payment status | Contract and legal obligation |
| Managing contracts and legal records | Names, roles, signatures, company details, agreement records | Contract, legal obligation, or legitimate interests |
| Supporting service delivery with AI-assisted tools | Public website content, business information, project notes, drafts, audit observations, client-provided materials where appropriate | Contract or legitimate interests |
| Improving our services and internal workflows | Project records, feedback, audit observations, aggregated operational notes | Legitimate interests |
| Sending service-related communications | Contact details, project status, administrative updates | Contract or legitimate interests |
| Sending marketing communications, where applicable | Name, email address, company, consent or unsubscribe status | Consent or legitimate interests where lawful |
| Handling privacy rights requests | Contact details, request details, verification information, response records | Legal obligation |
| Protecting legal rights and preventing misuse | Relevant records, logs, communications, transaction history | Legitimate interests or legal obligation |
5. Legal bases we rely on
Where the General Data Protection Regulation applies, we rely on one or more of the following legal bases.
Contract
We process personal data when it is necessary to provide services, manage client relationships, operate client workspaces, communicate about projects, issue invoices, or take steps before entering into a contract.
Legitimate interests
We may process personal data where it is necessary for our legitimate business interests and those interests are not overridden by your rights and freedoms.
This may include:
- responding to business enquiries;
- operating and securing our website;
- improving our services;
- managing business communications;
- keeping appropriate business records;
- protecting our legal position;
- analysing business-facing website performance;
- using proportionate internal tools to support service delivery.
Consent
We rely on consent where required, including for non-essential cookies, certain analytics activities, and marketing communications where consent is the appropriate basis.
You may withdraw consent at any time. Withdrawing consent does not affect processing that took place before the withdrawal.
Legal obligation
We process personal data where required to comply with legal obligations, including accounting, tax, regulatory, and data protection obligations.
6. Use of AI-assisted tools
We may use AI-assisted tools to support research, drafting, summarisation, quality review, audit analysis, and internal service delivery.
Where possible, we use public, business, anonymised, or minimised information rather than unnecessary personal data. We do not intentionally submit sensitive personal data to AI-assisted tools unless it is necessary for a specific agreed purpose and appropriate safeguards are in place.
Depending on the service context, AI-assisted tools may process information such as public website content, business contact details, project notes, draft content, audit observations, prompt outputs, or client-provided materials.
We do not use AI-assisted tools to make solely automated decisions about individuals that produce legal or similarly significant effects. Human review remains part of our service delivery and decision-making process.
7. Website analytics.
We use Google Analytics (GA4) and Microsoft Clarity to understand website performance and visitor behaviour. Website usage data is captured using first and third-party cookies and other tracking technologies to determine the popularity of services and online activity. Additionally, we use this information for site optimisation and fraud/security purposes.
For more information about how Google collects and uses your data, visit the Google Privacy and Terms.
For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.
8. International data transfers
StoryVero S.L. is established in Spain and subject to the GDPR. Some of the providers are located outside the European Economic Area, principally in the United States, so personal data may be transferred internationally in the course of our work.
We have signed data processing agreements with providers that incorporate the Standard Contractual Clauses approved by the European Commission for transfers outside the EEA.
Google LLC is self-certified under the EU-U.S. Data Privacy Framework, recognised by the European Commission as providing an adequate level of protection for transfers to certified US organisations.
Microsoft Corporation is self-certified under the same framework.
We review the safeguards relied on by our service providers periodically and will update this section if that changes.
9. How long we keep personal data
We keep personal data only for as long as necessary for the purposes set out in this Privacy Policy, or as required by law.
| Data category | Retention period | Why |
|---|---|---|
| Enquiry and lead data (contacts who do not become clients) | 12 months from last contact | To allow reasonable follow-up, after which we delete the record unless the person re-engages |
| Client and project records (drafts, audit findings, deliverables, project communications, client portal account data) | 6 years from the end of the engagement | Aligned with our accounting record-keeping period for consistency across all client-related records |
| Invoices, billing, and accounting records | 6 years from the date of issue | Required under the Spanish Commercial Code, regardless of preference |
| Website analytics data (Google Analytics) | 14 months | Matches our configured Google Analytics retention setting; data is automatically deleted by Google after this period |
When we have no ongoing need to keep personal data, we delete or anonymise it. Where deletion is not immediately possible, for example because data exists in backup archives, we securely isolate it from further use until deletion can be completed.
10. How we keep personal data secure
We use a combination of technical and organisational measures to protect personal data against unauthorised access, loss, or misuse.
All core systems used to store and process personal data are protected with two-factor authentication.
Where personal data is processed by our service providers, those providers maintain their own independently verified security measures: encryption in transit and at rest, IP-restricted access, and regular security testing, SOC 2 Type II, ISO 27001, and ISO 27701 certifications.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. However, we take reasonable steps appropriate to the nature of the data we handle, and we review our practices as our use of tools and services evolves.
11. Children’s data
Our services are intended for businesses and professional contacts, not for children. We do not knowingly collect personal data from anyone under 18 years of age. If we become aware that we have inadvertently collected personal data from a minor, we will take reasonable steps to delete it.
If you believe a minor has provided us with personal data, please contact us using the details in section 1.
12. Your data protection rights
Where the GDPR or UK GDPR applies to the processing of your personal data, you have the following rights:
Right of access, to obtain confirmation of whether we process your personal data and a copy of it. Right to rectification, to have inaccurate or incomplete personal data corrected. Right to erasure, to request deletion of your personal data in certain circumstances. Right to restrict processing, to limit how we use your personal data while a concern is resolved. Right to data portability, to receive personal data you provided to us in a structured, commonly used format, where processing is based on consent or contract and carried out by automated means. Right to object, to object to processing based on legitimate interests, including for direct marketing. Right to withdraw consent, at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
You also have the right to lodge a complaint with a supervisory authority. As StoryVero S.L. is established in Spain, the relevant authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), though you may also contact the supervisory authority in your own country of residence.
How to exercise these rights. Contact us at [email protected]. To protect your data, we may need to verify your identity before acting on a request. We aim to respond within one month, extendable by a further two months for complex requests, in which case we will explain the delay.
These rights may not apply, or may be limited, in certain circumstances permitted by law, for example where we have an overriding legal obligation to retain data.
13. US privacy notice
Most of our US-based contacts interact with us in a business-to-business capacity, for example as an employee, contractor, or representative of a client, supplier, or business partner, rather than as an individual consumer.
Many comprehensive US state privacy laws, including those in Virginia, Colorado, Connecticut, and Utah, generally apply to personal information processed in a personal or household context, and exclude personal information processed in an employment or business-to-business context. Where that exclusion applies, those laws do not create rights beyond what is already described in this Policy.
California’s privacy law (the CCPA, as amended by the CPRA) does extend some rights to personal information collected in a business-to-business context. However, CCPA obligations apply only to businesses meeting specific size or data-volume thresholds, for example, gross annual revenue above $25 million, or processing personal information for a large volume of consumers or households. We do not currently meet these thresholds.
Regardless of strict legal applicability, we extend the following to any US-based contact, consistent with the rest of this Policy: we do not sell or share personal information for cross-context behavioural advertising; you may request access to, correction of, or deletion of your personal data by contacting [email protected]; and we will not discriminate against you for exercising these rights.
If you believe a specific state law gives you rights not addressed here, please contact us and we will respond accordingly.
14. Do Not Track signals
Some web browsers offer a “Do Not Track” (DNT) setting. There is currently no industry-standard way to interpret DNT signals, so we do not respond to them. If a uniform standard is adopted in the future, we will update this Policy accordingly.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. The “Last updated” date at the top of this Policy shows when it was last revised. Where changes are material, we will take reasonable steps to bring them to your attention, for example by posting a notice on our website. We encourage you to review this Policy periodically.