Privacy Policy
1. Data Controller
Identity: Jonathan Bassedas Carrillo
Tax ID (NIF): 40565236K
Address: Camí Age 9, 1.3 — 17520 Puigcerdà (Girona), Spain
Email: info@eluneconnections.com
Website: eluneconnections.com
Hereinafter, "Elune Connections" or the "Controller".
2. Purposes of processing and legal basis
2.1 Admin panel users (business clients)
- Contract management: execution of the service agreement, billing and operational communications. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
- Payments: processing charges through Stripe. Legal basis: Art. 6(1)(b) GDPR.
- Own commercial communications: sending updates about Elune Connections. Legal basis: Art. 6(1)(f) GDPR (legitimate interest) and Art. 21 LSSI-CE for existing clients. You may object at any time.
- Legal compliance: retention of invoices and tax obligations. Legal basis: Art. 6(1)(c) GDPR.
2.2 Digital card holders (end customers of businesses)
When a person fills in the digital card registration form, data is collected on behalf of the business client (Data Controller) and Elune Connections acts as a Data Processor (Art. 28 GDPR). The applicable legal basis is the freely given and informed consent provided through the form.
3. Categories of data processed
| Group | Data categories |
|---|---|
| Business clients | Name or company name, tax ID (NIF/CIF), contact details (email, phone), billing information, payment data (managed by Stripe). |
| Card holders | Name, email, phone, date of birth (optional), custom field data defined by the business client, date and version of GDPR consent. |
4. Recipients and international transfers
Data may be disclosed to the following data processors:
| Provider | Purpose | Safeguards |
|---|---|---|
| Stripe, Inc. | Payment processing | EU Standard Contractual Clauses (SCCs) + EU-U.S. Data Privacy Framework |
| Apple Inc. | Apple Wallet card issuance and push notifications | SCCs + EU-U.S. Data Privacy Framework |
| Google LLC | Google Wallet card issuance and push notifications | SCCs + EU-U.S. Data Privacy Framework |
| Railway Corp. | Hosting and database infrastructure | SCCs + EU-U.S. Data Privacy Framework |
| Google Firebase | Image storage | SCCs + EU-U.S. Data Privacy Framework |
Data is not shared with any third parties other than those listed above, unless required by law.
5. Data retention period
- Contractual and billing data: 5 years from the end of the business relationship (Art. 30 Spanish Commercial Code) and 4 years for tax obligations (Law 58/2003).
- GDPR consents (digital cards): as long as the holder keeps the card active. Once the card is deleted, data is retained in a blocked state for the applicable legal period.
- Log and security data: maximum 12 months.
6. Data subject rights
You may exercise at any time your rights of access, rectification, erasure, restriction, portability and objection by contacting:
Email: info@eluneconnections.com
Address: Camí Age 9, 1.3 — 17520 Puigcerdà (Girona)
You must identify yourself and specify the right you wish to exercise. We will respond within a maximum of one month (extendable by two further months in complex cases). You may also file a complaint with the Spanish Data Protection Agency (AEPD).
7. Security
Elune Connections implements appropriate technical and organisational measures commensurate with the level of risk: HTTPS/TLS encryption on all communications, restricted access to production environments, two-factor authentication on critical systems, and regular backups. Firebase stores data in ISO 27001 / SOC 2 certified infrastructure.
8. Cookies
This website only uses strictly necessary technical cookies for session operation and language/theme preferences. No third-party tracking or advertising cookies are used. Explicit consent is not required for these cookies under Art. 22.2 LSSI-CE.
9. Minors
Elune Connections services are aimed at professionals and businesses. We do not knowingly collect data from persons under 14 years of age. If we detect the processing of minors' data without parental consent, we will proceed to delete it immediately.
10. Updates to this policy
This policy may be updated to adapt to regulatory or business changes. The current version will always be available at eluneconnections.com/privacidad. When changes are substantial, we will notify registered users by email.
11. Instagram (Meta) integration
When a Client connects their Instagram Business account to Elune Connections via OAuth, we process the following Instagram data on their behalf.
Data we receive and store
- The connected Instagram Business account's user ID and username, stored to identify the account and display it in the Client's admin panel.
- A long-lived access token issued by Meta after OAuth, encrypted at rest. Valid for 60 days; deleted when the Client disconnects the account.
- Subscribed webhook events: comments on the Client's posts, mentions of the account, and replies to Stories. We retain only: the actor's Instagram user ID and/or username, the post or Story ID, the event type, and the timestamp. We do not retain comment text beyond in-memory processing for keyword matching configured by the Client, nor message content or Story reply content.
Data we do NOT process
- Followers or following lists.
- Account statistics or insights.
- Media content (photos, videos, Stories) beyond the post ID.
- Information about the commenter beyond their public username and user ID.
Purposes
- Send a private reply (direct message) to the author of a comment when the Client configures it, for example to deliver a link, a code, or the information the comment requested. It is sent through Instagram's official messaging API, once per comment and within the 7-day window allowed by Meta.
- Optionally publish a public reply to the comment when the Client configures it.
- Record the Instagram interaction (engagement) signal in the Client's CRM.
- If the actor is an enrolled member of the Client's loyalty program (identified by their Instagram handle registered on a wallet card), reflect the interaction on the customer's own wallet loyalty card. This is internal database processing and involves no additional Meta API calls.
Legal basis (GDPR)
- Legitimate interest of the Client (Art. 6.1.f GDPR) to automate Instagram customer support, with Elune Connections as data processor under Art. 28 GDPR.
- Consent of the Instagram Business account owner, expressed in the Meta OAuth flow when authorizing Elune.
Retention and deletion
- Access token and account identifiers are kept while the Client keeps the integration active. Disconnection deletes them immediately.
- Webhook event logs are retained for 24 months for auditing and support, then automatically deleted.
- Any data subject can request deletion at info@eluneconnections.com; we will respond within 30 days.
Compliance with Meta policies
- Elune Connections complies with Meta's Platform Terms and Developer Policies.
- We validate Meta's HMAC-SHA256 signature on every incoming webhook.
- When we send a private reply (direct message) to a comment, we use only Instagram's official messaging API, respecting Meta's rule of a single private reply per comment and the 7-day window. We do not initiate unsolicited conversations or send bulk promotional messages.
- We do not use Instagram data for targeted advertising or to build user profiles.