Legal
Privacy Policy
Last updated: July 6, 2026
This Privacy Policy explains how Joshias Tamayo Rodriguez, trading as Erea, processes personal data when you visit this website, request a preview, use the partner area, contact us, or purchase services.
1. Controller
The controller responsible for data processing is:
Joshias Tamayo RodriguezTrading as Erea
Strandpromenade 1
63110 Rodgau
Germany
Email: erea@erea.studio
Phone: +49 176 30363515
2. Legal bases
We process personal data only where there is a legal basis under the GDPR, especially:
- Art. 6(1)(b) GDPR: contract performance or pre-contractual measures.
- Art. 6(1)(c) GDPR: compliance with legal obligations.
- Art. 6(1)(f) GDPR: legitimate interests.
- Art. 6(1)(a) GDPR: consent, where consent is requested.
3. Website access, hosting, and security
When you visit the website, technical access data is processed automatically. This may include IP address, date and time of access, requested pages or files, referrer URL, browser and device information, operating system, HTTP status codes, and similar log data.
This processing is necessary to deliver the website, maintain security, detect abuse, debug errors, apply rate limits, and keep the service technically stable.
Our website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Vercel processes technical data needed to host, secure, deliver, and monitor the website.
Legal basis: Art. 6(1)(f) GDPR.
Legitimate interest: secure, reliable, and performant operation of the website.
4. Analytics and performance measurement
We use Vercel Analytics and Vercel Speed Insights to understand website usage, performance, page load behavior, and technical quality. These tools help us improve the website and detect performance problems.
Depending on Vercel's implementation and your request context, technical data such as page URL, referrer, device/browser information, approximate location derived from network data, timing/performance data, and other event data may be processed. We do not use these tools to build advertising profiles.
Legal basis: Art. 6(1)(f) GDPR.
Legitimate interest: measuring and improving website usability, reliability, and performance.
5. Contact and preview requests
If you contact us by email, request a free preview, or submit an inquiry, we process the information you provide. This may include your name, business name, website or online profile, email address, phone number, notes, project details, communication history, and publicly available business information relevant to preparing a preview.
We process this data to respond to your inquiry, prepare offers, create previews, negotiate contracts, prevent abuse, and perform requested services.
Preview request notifications may be sent through Resend, an external email delivery provider. This can include the submitted contact and request details needed to deliver the notification email.
Legal basis: Art. 6(1)(b) GDPR where the communication relates to a contract or pre-contractual inquiry; otherwise Art. 6(1)(f) GDPR.
6. Customer and contract data
If you become a customer, we process data required to create, perform, manage, and invoice our services. This may include name, business name, billing address, contact details, project requirements, contract documents, invoices, payment status, access information you voluntarily provide, and project communication.
Payments may be made by bank transfer or external payment providers if agreed for a specific order. Payment and invoice data is processed for contract performance, tax, accounting, fraud prevention, and payment security.
Legal basis: Art. 6(1)(b), Art. 6(1)(c), and Art. 6(1)(f) GDPR.
7. Partner accounts and partner dashboard
If you register as a partner or use the partner dashboard, we process account and program data such as email address, password authentication data, full name, phone number, country, outreach plan, referral code, seller code, payout email, account status, training progress, submitted leads, dashboard activity needed to provide the portal, and related communication.
Partner authentication, account sessions, password reset emails, email verification, and database storage are handled with Supabase. If you choose Google OAuth, Google may process data needed to authenticate you and provide your account email to Supabase and Erea.
Legal basis: Art. 6(1)(b) GDPR for partner account creation and use; Art. 6(1)(f) GDPR for fraud prevention, account security, abuse prevention, and program management.
8. Lead claims and referrals
Partners may submit or claim leads. We process lead data such as business name, website or online presence, normalized domain, contact person, contact method, notes, whether the business has already been contacted, referral attribution, status, and commission-related information.
Referral attribution may use a signed referral cookie when a visitor arrives with a referral parameter. We also compare submitted domains with active lead claims to avoid duplicate or conflicting attribution.
Legal basis: Art. 6(1)(b) GDPR for operating the partner program; Art. 6(1)(f) GDPR for attribution, fraud prevention, duplicate prevention, and business administration.
9. Internal request inbox and administration
Erea uses an internal request inbox to review, manage, respond to, update, and delete preview requests and partner leads. Admin users may process submitted contact details, messages, notes, request status, attribution data, and reply history.
This processing is necessary for customer support, sales follow-up, service delivery, lead management, and internal administration.
Legal basis: Art. 6(1)(b) and Art. 6(1)(f) GDPR.
10. Cookies and local storage
We use cookies and similar technologies for the following purposes:
- Supabase authentication cookies for login sessions, email verification, and password reset flows.
- The signed
erea.referralcookie to remember a referral code for up to 30 days. - A temporary partner OAuth context cookie used during partner Google sign-in or registration.
- Local storage in the partner dashboard to remember whether the sidebar is collapsed.
These technologies support authentication, security, referral attribution, user preferences, and requested website functionality.
Legal basis: Art. 6(1)(f) GDPR and, where applicable, Section 25(2) TDDDG. Where a non-essential technology legally requires consent, the legal basis is Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
11. Rate limiting and abuse prevention
To protect forms, login routes, partner routes, and admin routes from abuse, we process IP addresses, user/account identifiers where applicable, request timing, and rate-limit counters. If configured, rate-limit counters may be processed through Upstash Redis.
Legal basis: Art. 6(1)(f) GDPR.
Legitimate interest: preventing spam, credential attacks, denial-of-service attempts, and misuse of our forms and accounts.
12. Recipients and service providers
We may share personal data with service providers where necessary to operate our website and business. This may include:
- Vercel for hosting, analytics, and speed insights.
- Supabase for authentication, database, and account/session handling.
- Resend for email delivery.
- Upstash for rate limiting, if configured.
- Google for OAuth, if you choose Google sign-in.
- Payment providers, accounting or tax advisors, and legal advisors where needed.
- Domain, hosting, email, or project tools used for customer projects where agreed.
Where required, we conclude data processing agreements with processors pursuant to Art. 28 GDPR.
13. International data transfers
Some service providers may process data outside the EU/EEA, especially in the United States. Where this happens, we rely on appropriate safeguards such as EU Standard Contractual Clauses, adequacy decisions, the EU-U.S. Data Privacy Framework where applicable, or other legally recognised transfer mechanisms.
14. Retention
We retain personal data only as long as necessary for the purposes described in this Privacy Policy, unless legal retention obligations or legitimate preservation interests require longer storage.
Typical retention periods:
- Server logs and rate-limit data: short-term security and operational retention.
- Referral cookies: up to 30 days.
- Inquiries and preview requests: for handling, follow-up, and applicable limitation periods.
- Partner account and lead data: for the duration of the partner relationship and required follow-up.
- Contracts, business correspondence, invoices, and accounting records: according to statutory periods.
15. No automated decision-making
We do not use personal data for automated decision-making that produces legal effects concerning you or similarly significantly affects you.
16. Your rights
You have the following rights under the GDPR, subject to the legal requirements:
- Right of access.
- Right to rectification.
- Right to erasure.
- Right to restriction of processing.
- Right to data portability.
- Right to object to processing based on Art. 6(1)(f) GDPR.
- Right to withdraw consent at any time with future effect.
- Right to lodge a complaint with a data protection supervisory authority.
For Hessen, the competent supervisory authority is:
Hessian Commissioner for Data Protection and Freedom of InformationWilhelmstrasse 7
65185 Wiesbaden
Germany
Email: poststelle@datenschutz.hessen.de
17. Obligation to provide data
You are not legally required to provide personal data when simply visiting the public website. However, certain technical data is necessary to display and secure the site.
If you contact us, request a preview, create a partner account, submit leads, or enter into a contract, we need the data required to process the inquiry, provide the account, operate the program, or perform the contract. Without this data, we may not be able to respond, provide access, or deliver services.
18. Updates to this Privacy Policy
We may update this Privacy Policy if our website, services, legal obligations, service providers, or data processing practices change.