Skip to content

Privacy Policy

Last updated: 8 July 2026

This policy explains what we do with the personal data you give us or that we collect automatically when you use Money Owl. We follow the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), Spain’s Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD), and the Spanish Law on Information Society Services (LSSI-CE, Ley 34/2002). Plain English where the law lets us; the verbatim legal terms where it doesn’t.

Who we are (data controller)

Money Owl is a personal-finance editorial site operated from Spain. For the purposes of GDPR Art. 4(7), the data controller is Jure Jaklič, the individual trading as Money Owl. The Legal Notice sets out the operator details; the tax ID and postal address are provided on request through the channels listed there. We have not appointed a Data Protection Officer; at our scale, GDPR Art. 37 does not require one.

How to contact us (data protection requests)

The primary contact channel for any data-protection matter is our contact form. If you prefer email, the direct address is published on the Legal Notice. Either channel works for exercising any of the rights listed further down this page. We reply at the email address you provide.

What we collect and why (purposes and lawful bases)

We list every processing activity that actually runs on this site. If something isn’t mentioned here, we don’t do it.

  • Contact form submissions. When you fill out the contact form we collect your name, email address, subject, message, and the time and IP address of the submission. Providing this data is voluntary; there is no legal or contractual obligation to give it, and the only consequence of not providing it is the practical one: without an email address we cannot reply. The form is protected by Cloudflare Turnstile (anti-bot). Lawful basis: your request to be contacted, GDPR Art. 6(1)(b) (pre-contractual steps) combined with our legitimate interests under Art. 6(1)(f) to reply to enquiries and keep the form free of spam.
  • Analytics (Google Analytics 4 and Microsoft Clarity). When you have given consent via the cookie banner, we measure how the site is used: pages viewed, time on page, broad device type, and rough location. Microsoft Clarity additionally records a session replay: mouse movement, scroll, clicks, and form-field interactions on the page. Clarity automatically masks keystrokes, passwords, payment-card fields, and anything inside an <input type="password"> element. We do not see what you type into sensitive fields. Lawful basis: your consent, GDPR Art. 6(1)(a) and LSSI-CE Art. 22.2. Where you do not consent, we run no analytics on your session.
  • Advertising (Google AdSense). When you have given consent via the cookie banner, and once AdSense is active on the site, we allow Google AdSense to serve advertising, including personalised advertising in the markets where it applies. Third-party vendors, including Google, use advertising cookies to serve ads based on your prior visits to this site or to other sites. Google’s advertising cookies enable Google and its partners to serve you personalised ads. You can opt out of personalised advertising at Google Ads Settings (opens in new tab) or, for other vendors, at www.aboutads.info (opens in new tab). Lawful basis: your consent, GDPR Art. 6(1)(a) and LSSI-CE Art. 22.2.
  • Privacy-first traffic measurement (Cloudflare Web Analytics). We also measure aggregate traffic with Cloudflare Web Analytics. It is cookieless: it stores nothing on your device, uses no fingerprinting, and reports only aggregate page views and load times, so it does not need consent under LSSI-CE Art. 22.2. Lawful basis: our legitimate interest (GDPR Art. 6(1)(f)) in knowing whether the site works.
  • Site operation (Cloudflare). Cloudflare sits in front of every request for CDN delivery, DDoS protection, and bot management. This is strictly necessary for the site to work and does not require consent under LSSI-CE Art. 22.2.

Who we share data with (processors and recipients)

Every third party we use is listed here. We don’t sell your data to anyone.

  • Cloudflare, Inc.: hosting, content delivery, bot mitigation via the __cf_bm cookie, the cookieless Web Analytics beacon, contact-form routing through a Cloudflare Worker, persistent storage of form submissions in Cloudflare Workers KV, and the email-notification relay to the operator via the Cloudflare Email Workers binding. Cloudflare is the backbone of the site.
  • Google LLC: Google Analytics 4 and Google AdSense, both gated by our consent management platform (Google Privacy & Messaging, TCF v2.3).
  • Google Ireland Limited: operator of the European Analytics and Tag Manager endpoints you’ll see in Network traffic (region1.google-analytics.com, googletagmanager.com).
  • Microsoft Corporation: Microsoft Clarity for session analytics and heatmaps, gated by our consent management platform.

All four processors are bound by their respective standard data-processing agreements. We do not transfer your personal data to any recipient not listed above.

International transfers

The plain version first: some of your data is processed in the United States by Google and Microsoft, and EU-approved legal safeguards cover those transfers. In legal terms: the transfers are covered by Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and the EU-US Data Privacy Framework adequacy decision of 10 July 2023. See GDPR Art. 44 and Art. 46(2)(c) for the framework. You can request a copy of the applicable safeguards through the contact form. Cloudflare’s EU-region offering keeps CDN and Worker processing within the EU where configured; some edge operations may still route through third-country points of presence and are covered by the same safeguards.

How long we keep data (retention)

  • Contact-form submissions are stored in Workers KV, Cloudflare’s secure storage system, with a 90-day time-to-live, after which they are automatically deleted. The notification email sent to the operator at submission time is retained in the operator’s mailbox in line with ordinary email retention; if you want that copy gone too, ask, and we delete it under the right to erasure below.
  • Analytics data is kept per each provider’s settings: our Google Analytics 4 property keeps user-level data for 14 months (the maximum a standard GA4 property allows), and Microsoft Clarity follows Microsoft’s published cookie table. Cookie-level durations are listed in full on the Cookie Policy.
  • Advertising cookies follow the duration set by Google AdSense, listed on the Cookie Policy.
  • Strictly-necessary cookies have variable durations: Cloudflare bot-management and Turnstile challenge cookies last about 30 minutes per session; the CMP consent-state cookies last 13 months (FCCDCF) and 12 months (FCNEC) so your choice is remembered across visits. Full per-cookie durations are on the Cookie Policy.

We apply the data-minimisation principle of GDPR Art. 5(1)(c): we don’t keep data longer than we need.

Your rights (data subject rights)

You can exercise any of the following rights over the data we hold about you:

  • Right of access (GDPR Art. 15): ask for a copy of the personal data we hold about you.
  • Right to rectification (GDPR Art. 16): correct anything that’s wrong or incomplete.
  • Right to erasure (GDPR Art. 17): also known as the right to be forgotten.
  • Right to restriction of processing (GDPR Art. 18): ask us to pause processing while we sort something out.
  • Right to data portability (GDPR Art. 20): receive your data in a common, machine-readable format.
  • Right to object (GDPR Art. 21): object to processing based on legitimate interests, including direct marketing.
  • Right not to be subject to automated decision-making, including profiling (GDPR Art. 22): we don’t currently run anything that would trigger this right, but it’s yours anyway.
  • Right to withdraw consent (GDPR Art. 7(3)): where we rely on consent, you can withdraw it as easily as you gave it. Use the “Cookie settings” link in the site footer to reopen the consent banner and revoke analytics or advertising consent.

To exercise any of these rights, use the contact form. Under GDPR Art. 12(3) we reply within one month of receiving your request, extendable by a further two months for complex cases (we’ll tell you if we’re extending).

Complaints to the supervisory authority (AEPD)

If you believe we’ve mishandled your data and you aren’t satisfied with our response, you have the right to lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD), under GDPR Art. 77. You can do that through the AEPD’s online complaint service, reachable from its site at www.aepd.es (opens in new tab). If the AEPD contacts us with observations or requests on behalf of your complaint, we will engage with them directly. No further action is required from you.

GDPR Art. 77 also lets you complain to the supervisory authority of the EU Member State where you live or work, or where the issue happened; that authority coordinates with the AEPD for you. Readers in the United Kingdom can raise a concern with the Information Commissioner’s Office (ICO) at ico.org.uk/make-a-complaint (opens in new tab); we apply the same standard to every reader wherever they are. Readers in the EEA/EFTA states (Norway, Iceland, Liechtenstein) hold the same GDPR rights as EU readers. And if you read Money Owl from anywhere else in the world, this policy still applies as written: we run one privacy standard for everyone.

Security of processing

Per GDPR Art. 32 we apply appropriate technical and organisational measures for the scale of this site. In practice that means: HTTPS across every page and every form submission; Cloudflare’s managed WAF and bot-mitigation layer in front of the site; Cloudflare Turnstile on the contact form; a 90-day auto-delete on stored contact-form submissions so they don’t accumulate indefinitely; and access controls (two-factor authentication, scoped API tokens) on the operator-side Cloudflare dashboard, GitHub repository, and editor-local development environment. We don’t process special-category personal data, we don’t store passwords, and we don’t run background jobs over user data.

Cookies

Cookies and similar technologies on this site are governed by our Cookie Policy, which lists every cookie we set, what it’s for, how long it lasts, and how you consent to or withdraw from each category through the Google Privacy & Messaging banner. The legal basis is LSSI-CE Art. 22.2.

Changes to this policy (effective date and versioning)

We update this policy when something actually changes, usually a new processor, a shorter retention window, or a new regulatory duty. When that happens, the “Last updated” effective date at the top of this page moves with it (current effective date: 8 July 2026). Anything bigger, a new legal basis or a real change in the data we hold, gets a dated note on this page too. If you want to know exactly what moved, it’s written down.