Alexander Shuranov
RUENES
Request a consult
Skip to main content

Last updated: 28 July 2026

This Privacy Policy explains how personal data is processed for people who visit shuranov.online, write through the contact form, or get in touch by email or WhatsApp.

It has been prepared in accordance with Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), and Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE).

1. Data controller

Owner Alexander Shuranov (individual, self-employed — autónomo)
NIE X4409176F
Address Pl. Bandes de Música de la Comunitat Val 20, 46013 Valencia, España
Email info@shuranov.online
Phone +385 91 519 6333
Activity Business management consultancy (CNAE 7020, IAE 8499)
Website https://shuranov.online

For any question about this policy or about your personal data, write to info@shuranov.online with “Data protection” in the subject line.

Data Protection Officer

No Data Protection Officer (DPO) has been appointed. The processing described here does not fall within any of the cases listed in Article 37 GDPR, nor within the list of entities required to appoint one under Article 34 LOPDGDD: the owner is not a public authority or body, does not carry out regular and systematic monitoring of data subjects on a large scale, and does not process special categories of data or criminal conviction data on a large scale.

Data protection enquiries are handled directly by the owner at the contact details above.

2. What data is processed and where it comes from

All data comes directly from you. No databases are purchased and no personal information is obtained from third-party sources.

2.1 Contact form

The form on the site collects: name, company, email address, service of interest, and the text of your message. Any additional information you choose to include in the message is processed as well.

Fields marked as mandatory are needed in order to reply to you; without them the request cannot be handled. Please do not include sensitive data (health, beliefs, trade union membership), third-party data, passwords, or banking details in your message.

2.2 Email and WhatsApp

If you write to info@shuranov.online or use the WhatsApp button, the following are processed: your email address or phone number, the name shown on your account, the content of the conversation, and any files you attach.

The WhatsApp button opens that service’s app or website; you initiate the connection. From that point on, the transmission of your message is also governed by Meta’s terms and privacy policy.

2.3 Browsing data and cookies

When you visit the site, technical data is recorded in the server logs: IP address, browser and device type, pages requested, date and time.

The site sets a single first-party cookie: pll_language, from the Polylang multilingual component, with a lifetime of 365 days. It stores only the language you choose to view the site in. It is a user-preference cookie and is exempt from the consent requirement under Article 22.2 LSSI-CE and the criteria of the AEPD Guide on the use of cookies.

No analytics, measurement, visit-source attribution or advertising cookies are used, whether first-party or third-party. For that reason the site displays no consent banner: no cookie requiring consent is set.

When the online shop goes live, WooCommerce will add strictly necessary technical cookies for the cart and the shopping session (woocommerce_cart_hash and woocommerce_items_in_cart, session cookies, and wp_woocommerce_session_*, 2 days), which are likewise exempt from consent; the Cookie Policy will be updated at that point.

Each cookie, its purpose and its lifetime are listed in the Cookie Policy. You can inspect, block or delete cookies at any time through your browser settings.

2.4 Billing data (future use)

An e-commerce platform is installed on the site, but no service is currently offered for sale through it. When online ordering is enabled, the data needed to issue an invoice will also be processed: name or company name, NIF/NIE, postal address, and order details.

Payment data will be processed directly by the payment provider engaged for that purpose; the owner does not receive full card details. This policy will be updated before that functionality goes live.

2.5 Automated decision-making

No automated decisions are made and no profiling is carried out that would produce legal effects concerning you or similarly significantly affect you.

3. Purposes, legal bases and retention periods

Purpose Legal basis (Art. 6 GDPR) Retention period
Answering enquiries and requests received through the form, by email or via WhatsApp, and preparing service proposals or quotes. Art. 6(1)(b) — pre-contractual steps taken at the data subject’s request. Up to 1 year from the last contact if no service is ultimately engaged.
Providing the business management consultancy services engaged and managing the client relationship. Art. 6(1)(b) — performance of a contract. For the term of the contract and, afterwards, blocked for the applicable limitation periods.
Issuing invoices, keeping accounts, and complying with tax and commercial obligations. Art. 6(1)(c) — compliance with legal obligations (Art. 30 of the Spanish Commercial Code; General Tax Law 58/2003). 6 years for accounting books and commercial records; 4 years for tax purposes from the end of the filing deadline for each return.
Remembering the language you choose to view the site in (cookie pll_language). Art. 6(1)(f) — legitimate interest in displaying the site in the language selected by the user. Preference cookie exempt from consent under Art. 22.2 LSSI-CE. 365 days from when it is set or last refreshed.
Keeping the website available and secure: server logs, backups, and prevention of abuse. Art. 6(1)(f) — legitimate interest in the security and availability of the site. Server logs, no more than 12 months; backups are overwritten in their rotation cycles.
Handling requests to exercise data protection rights and demonstrating compliance. Art. 6(1)(c) — compliance with legal obligations. Up to 3 years, the maximum limitation period for infringements under the LOPDGDD.

Commercial communications. No newsletters or commercial communications are currently sent and no subscription list exists. If that service is offered in the future, messages will be sent only to those who have given prior express consent (Art. 6(1)(a) GDPR and Art. 21 LSSI-CE), and every message will include a simple, free way to unsubscribe.

On legitimate interest. Before relying on Article 6(1)(f), that interest was balanced against your rights and freedoms, and processing is limited to what is strictly needed to keep the site secure and functional. You may request information about that balancing test at the contact address.

Blocking. Once the periods above expire, data is blocked in accordance with Article 32 LOPDGDD: it remains available solely to courts, the public prosecutor and the competent authorities until any liability becomes time-barred, and is then deleted.

4. Recipients and processors

Your data is not sold, rented, or disclosed to third parties for advertising purposes. Beyond what is described below, it is disclosed only where there is a legal obligation to do so.

4.1 Processors

In accordance with Article 13(1)(e) GDPR, the categories of recipients are identified:

  • Web hosting provider. Hosts the website, the database and the backups, and generates the technical server logs.
  • Transactional email provider. Delivers the messages generated by the contact form and the related correspondence.

A data processing agreement under Article 28 GDPR is (or will be) signed with each processor, including confidentiality obligations, appropriate security measures, and a prohibition on using the data for the processor’s own purposes.

If you wish to know the specific identity of these providers and the location of the servers on which your data is held, you may request it at any time at info@shuranov.online; the information will be provided free of charge.

4.2 Third parties your browser connects to

These are not processors acting on the owner’s behalf: the connection is made directly by your browser when the page loads. They are described in detail in section 5.2.

  • Google (Google Fonts). The site’s fonts are loaded from fonts.googleapis.com and fonts.gstatic.com; that connection transmits your IP address and technical device data to Google. You can prevent it using blocking extensions or your browser settings.
  • StyleMix Themes. Some theme images are served from consulting.stylemixthemes.com, with the same technical transmission of your IP address.
  • Meta (WhatsApp and Instagram). If you tap the WhatsApp button, you initiate the connection to that service. On pages where the Instagram feed is displayed, your browser connects to servers of Meta Platforms Ireland Limited. In both cases Meta’s own policies also apply.

4.3 Other recipients

  • Where applicable, the tax and accounting adviser working with the owner, and the bank, for invoicing and collection.
  • The Spanish Tax Agency (AEAT), the social security authorities, and other public bodies or courts, where a legal obligation applies.

5. International transfers

5.1 Processors the owner has a contract with

The owner selects web hosting and transactional email providers that process data within the European Economic Area or that, where the processing involves an international transfer, provide one of the safeguards set out in Chapter V GDPR:

  • a European Commission adequacy decision covering the country or certification framework concerned; and/or
  • the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914, together with any supplementary measures required.

Because this processing is governed by an Article 28 GDPR contract, you may request the identity of the provider, the location of the servers, and a copy of the safeguards applied by writing to info@shuranov.online.

5.2 Technical connections made by your browser

The third parties listed below are not processors acting on the owner’s behalf. The connection is initiated directly by your browser when the page loads or when you tap a button, and it transmits your IP address and technical device data. The owner has no contract with these entities, does not take part in that transmission and does not control it, and therefore cannot provide you with a copy of the safeguards each of them applies: for that processing, each entity acts as its own controller under its own privacy policy.

  • Google LLC (Google Fonts). Fonts are loaded from fonts.googleapis.com and fonts.gstatic.com; the processing may take place in the United States.
  • StyleMix Themes (consulting.stylemixthemes.com). Some theme images are served from that external domain; your browser transmits your IP address and the processing may take place on servers outside the European Economic Area. The owner intends to move these files to his own server so that this connection disappears.
  • Meta. The WhatsApp button (a connection you initiate) and the Instagram content connect to servers of Meta Platforms Ireland Limited, which may transfer data to Meta Platforms, Inc. in the United States under its own safeguards.

Google LLC and Meta Platforms, Inc. appear on the public list of entities certified under the EU-US Data Privacy Framework, the framework recognised by the European Commission adequacy decision of 10 July 2023; maintaining and evidencing that certification is the responsibility of those entities, and the owner cannot guarantee it.

You can prevent these connections with blocking extensions or your browser settings; the site will remain usable, although its appearance may change.

6. Your rights

You may exercise the following rights at any time:

  • Access (Art. 15 GDPR): find out what data about you is processed and obtain a copy.
  • Rectification (Art. 16): correct inaccurate or incomplete data.
  • Erasure (Art. 17): request deletion when the data is no longer necessary.
  • Restriction of processing (Art. 18).
  • Objection (Art. 21), in particular to processing based on legitimate interest.
  • Portability (Art. 20): receive your data in a structured, commonly used format.
  • Not to be subject to automated decision-making (Art. 22).
  • Withdrawal of consent, where processing is based on it, at any time and without affecting the lawfulness of processing carried out beforehand.

How to exercise them

Send a request to info@shuranov.online or to the postal address in section 1, stating which right you are exercising. It is enough that the request allows you to be identified; sending it from the same email address or phone number you used to get in touch is normally sufficient. Requests are free of charge.

You do not need to attach a copy of your identity document upfront. Only where there are reasonable doubts about the identity of the person making the request will you be asked for the additional information necessary to confirm it, in accordance with Article 12(6) GDPR, and that information will be used solely for that purpose.

A reply will be provided within one month of receipt. If the request is particularly complex or several requests are received, that period may be extended by two further months, and you will be informed of the reason within the first month (Art. 12(3) GDPR).

Complaints

If you believe your data is not being handled properly, please contact the owner first — most issues are resolved directly.

In any case, you may lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es.

7. Data security and personal data breaches

Technical and organisational measures appropriate to the risk are applied (Art. 32 GDPR): encrypted HTTPS/TLS connections, access control with individual credentials, keeping the content management system and its components updated, regular backups, and vetting of the providers engaged.

The principle of data minimisation applies: only the data needed for each purpose is requested, and it is kept for the periods set out in section 3.

No system is infallible. If a personal data breach occurs, it is recorded in the internal breach register and, where it poses a risk to your rights, it is notified to the AEPD within 72 hours of becoming aware of it (Art. 33 GDPR). Where the risk is high, you will also be informed without undue delay, with a description of what happened and the measures taken (Art. 34 GDPR).

8. Minors

The site is aimed at companies, professionals and adults. It is not directed at children under 14 years of age, and their data is not knowingly collected (Art. 7 LOPDGDD).

Services may only be engaged by adults with legal capacity to contract, as set out in the Terms of Service and Right of Withdrawal. If data belonging to a child under 14 is found to have been received without the consent of the holder of parental authority or guardianship, it will be deleted immediately.

9. Changes to this policy

This policy may be updated when the services provided, the providers used, or the applicable legislation change. The version in force is always the one published on this page, with its update date.

If the changes substantially affect processing based on your consent, fresh consent will be requested before they are applied.

Date of last update: 28 July 2026.

Related documents: Legal Notice · Cookie Policy · Terms of Service and Right of Withdrawal.