Privacy policy
Last updated
Who holds your data
Plain Spain is the trade name we work under, and Plain Spain is the controller of everything described on this page. The address for anything to do with your data is [email protected]. A person reads that inbox.
We work from Spain, and that is why the GDPR governs this page. The rule follows the controller, not the visitor and not the server: it makes no difference whether you are writing from Denver, Cape Town or Valencia, or which country the machine serving this page sits in.
What we collect, and when
The eligibility check collects nothing. Your six answers are packed into the page address so the result can be reloaded or sent to your partner, and that is the whole of it. No account, no email address, nothing written to a database of ours.
The contact form collects your name, your email address, which visa you are asking about, and what you wrote. If you arrived from the eligibility check, the result you were looking at comes with it. The message becomes an email in our inbox. Your IP address is held in the server's memory for ten minutes so that one script cannot post a hundred times; it is not written to disk and it is not attached to your message.
Paying collects less than you would think. Checkout happens on Stripe's own page, so a card number never reaches our server. What comes back to us is the package you bought, how many people it covers, the amount, the email address you paid with, and Stripe's reference for the payment.
A case in the portal is where the real file lives. We hold your account (name, email address, a scrambled form of your password, never the password itself), a sign-in record with the time, your browser's user-agent string and your IP address, the case itself (which visa, which route, the dates that decide things), every person in the household (name, date of birth, nationality, passport number and expiry, NIE once Spain issues one), every document uploaded by you or prepared by us, the messages between us, our own notes on the case, and a log of who did what and when.
Our notes are part of your file. If you ask for a copy of what we hold, they are in it.
The documents are the sensitive part
A Spanish residence application asks for a criminal-record certificate, a medical certificate, private health insurance, bank statements, and birth or marriage certificates for the household. Two of those get extra protection under the GDPR: the medical certificate and the insurance are health data under Article 9, and the criminal-record certificate falls under Article 10.
We handle both on your explicit consent, which you give by uploading them for your application. You can withdraw it by writing to us, and we will stop. Know what that costs before you do: no consulate will accept the file without those two certificates, so withdrawing consent stops the application altogether.
Uploads (PDF, JPG, PNG or HEIC, up to 20 MB each) go into an object-storage bucket rather than into the database. In production that bucket is Cloudflare R2. The only route out is the portal's own file handler, which checks on every single request whether the person asking is on that case; an identifier belonging to someone else gets exactly the same answer as one that never existed.
Why we are allowed to hold it
Answering your email: the steps you asked us to take before there is a contract, and our own interest in replying to people who write to us (Article 6(1)(b) and 6(1)(f)).
Running your case: the contract between us (Article 6(1)(b)).
The criminal-record and medical documents: your explicit consent (Article 9(2)(a)), and Article 10 for the criminal-record certificate. They are used to assemble the application you hired us to assemble, and for nothing else.
Invoices and payment records: a legal obligation we do not get to opt out of (Article 6(1)(c)).
Sign-in records and the rate limit on the contact form: keeping the service running and hard to abuse (Article 6(1)(f)).
There is no profiling here and no automated decision-making. The eligibility check is a decision tree you run in your own browser, and it leaves no record behind.
Who else sees it
The consulate or the Spanish immigration office sees your application when it is filed. That is the point of the exercise, and on most routes it is you who hands it over in person.
A sworn translator (traductor jurado) sees the documents that need translating, and only those. Spain requires the translation to be certified by a translator on the Foreign Ministry's list, so this step cannot be done in-house.
Four suppliers touch data on our behalf, each for one job: a payment processor for checkout (Stripe), an email service for the messages the portal sends (Resend), object storage for uploaded documents (Cloudflare R2), and the host our server runs on. Analytics is a fifth, but only where the deployment has it switched on: it is Plausible, which sets no cookie and stores no identifier, and where it is not configured no analytics script loads at all.
That is the complete list. No advertising networks, no data brokers, no lead resale. We do not sell your data, and there is no version of this business in which that would make sense.
Some of those suppliers process data outside the EU. We use a supplier only where its data-processing terms carry the European Commission's standard contractual clauses for such transfers.
How long we keep it
Email to us: until it stops being useful. Ask, and we delete yours.
Your case file: while the case runs, and after it closes. Renewals reuse most of the same documents, and people do come back for one, so the default is to keep the file. If you would rather we did not, say so and it goes.
Payment and invoice records: as long as Spanish commercial and tax law obliges us to keep them. That is longer than either of us would choose, and it is not a choice we have.
Sessions: a portal session dies after seven days of disuse, and after thirty days whatever you do. Signing out deletes it on the spot.
Case data is never deleted on a timer. Deletion is done by a person, which is why the portal's account page has a button that opens a request instead of one that pretends to erase a file on the spot.
Your rights, and how to use them
You can ask for a copy of what we hold, have it corrected, have it deleted, have its use restricted, take it elsewhere in a portable form, object to us holding it, and withdraw consent you gave. Withdrawing consent stops what happens next; it does not unmake what was lawful before.
Two of those already have buttons. Your account page in the portal has "Download all my documents", which builds a ZIP of everything you uploaded and everything we prepared, and "Request account deletion", which opens a request a person answers within five working days.
For anything else, write to [email protected]. We answer within a month. Article 12(3) lets a controller extend that by two further months for a genuinely complicated request; if we ever have to, we will tell you inside the first month and say why.
We may ask you to prove who you are before we hand over a file full of passports and bank statements. That check protects you, not us.
If you think we have got this wrong
Tell us first, at [email protected]. Most of what goes wrong with data is a mistake somebody can fix the same day.
If that gets you nowhere, you can complain to the Agencia Española de Protección de Datos, Spain's supervisory authority, at aepd.es. Article 77 also lets you complain to the authority where you live or work, which for most of our clients is closer to hand than Madrid.
Changes to this page
The date at the top is the date this text last changed. If we change something that affects a case in progress, we email the people it affects instead of leaving you to find it here.
Anything on this page you want explained in fewer words, write to us or email [email protected]. A person answers, and it is the same person who would handle your case.