Privacy Policy

1. Data Controller

This Privacy Policy governs the processing of personal data provided through mistresselektra.org, its forms, and the contact channels linked to the website.

Trade name: Mistress Elektra
Website: mistresselektra.org
Email: [email protected]

For any questions relating to privacy or the exercise of your rights, you may contact me using the email address indicated above.

2. Information We Process

Depending on how you use the website or contact me, technical browsing data and any information you voluntarily provide through forms, email, WhatsApp, or other available channels may be processed.

This information may include contact details, information relating to a request or service, and the content necessary to manage the communications exchanged.

Due to the nature of certain services, users may voluntarily provide particularly personal or intimate information. Where such information constitutes a special category of personal data, it will be processed with the appropriate safeguards required under data protection legislation.

The GDPR includes data concerning a person’s sex life among special categories of personal data and establishes additional requirements for its processing.

3. Purposes of Processing

Personal data may be used to:

  • Manage enquiries, requests, and bookings.
  • Maintain the necessary communications with the data subject.
  • Assess, organise, and prepare the requested services.
  • Manage forms and preliminary processes relating to those services.
  • Retain necessary information where there is an ongoing relationship or future requests.
  • Manage communications requested by the user.
  • Improve the operation and security of the website and the systems used.
  • Compile internal statistics and analyse the performance of contact channels.
  • Prevent abuse, fraud, or misuse of the services.
  • Comply with legal obligations and address potential liabilities.

Personal data will not be used for purposes incompatible with those for which it was collected.

4. Forms

Certain individuals may be given access to forms intended to collect the information necessary to assess, organise, or prepare a service.

Information provided through these forms may be retained where necessary to manage the relationship with the data subject or subsequent requests.

Where forms involve the processing of special categories of personal data, the relevant information will be provided and, where necessary, the data subject’s explicit consent will be requested.

Users may subsequently request the deletion of their data where applicable under relevant legislation.

5. Contact via WhatsApp and Automated Processes

WhatsApp may be used as a contact channel and for managing requests.

Certain stages of the process may be automated in order to organise communications, validate certain responses, and direct each request to the appropriate next step.

For this reason, users accessing this channel through the website are informed that automated assistance is in use.

The system may incorporate artificial intelligence tools used internally to interpret or classify certain responses. These tools may assist in determining which step or predefined response is appropriate within the process.

Their use does not necessarily mean that the user is engaging in a conversation directly generated by artificial intelligence.

Transparency obligations relating to AI systems depend on the way in which the system interacts with individuals, rather than simply on the fact that AI is used somewhere within the process.

6. Use of Artificial Intelligence

Artificial intelligence tools may be used as technical support in certain internal processes, including classification, organisation, validation, or information management.

AI tools may also be used to assist with the preparation, editing, translation, or review of website content.

Published content is reviewed and subject to editorial control before publication.

7. Legal Basis

The legal basis for processing will depend on the purpose concerned and may include:

  • Taking pre-contractual steps requested by the data subject.
  • Performance of a contractual relationship.
  • The data subject’s consent.
  • Explicit consent where required for the processing of special categories of personal data.
  • Legitimate interests in ensuring security, preventing abuse, and properly managing the activity.
  • Compliance with legal obligations.

Applicable legislation requires the data subject to be informed, among other matters, of the purposes of processing, the legal basis, recipients, retention periods, and their rights.

8. Technology Providers

Personal data is not sold or disclosed to third parties for commercial purposes.

Technology providers may be involved in the operation of the website and contact channels and may process certain information to the extent necessary to provide their services.

These may include hosting, infrastructure, communications, email, forms, storage, backup services, WhatsApp/Meta, and artificial intelligence service providers.

Where required, the safeguards provided for under applicable data protection legislation will be implemented.

9. International Data Transfers

Some technology providers may process information outside the European Economic Area.

Where an international transfer of personal data takes place, the mechanisms and safeguards required by applicable legislation will be applied.

10. Data Retention

Personal data will be retained for as long as necessary to fulfil the purposes for which it was collected.

The retention period may vary depending on the type of information, the relationship with the data subject, and applicable legal obligations.

Certain information may be retained where necessary to manage future requests or an ongoing relationship.

Technical logs and backups may be retained for additional periods where necessary for operational or security reasons, or to address potential liabilities.

When data is no longer required, it will be deleted, restricted, or minimised in accordance with the applicable criteria.

The principle of storage limitation requires that personal data not be kept for longer than necessary for the purpose for which it is processed.

11. Security

Technical and organisational measures are adopted to protect personal data against loss, alteration, unauthorised access, disclosure, or misuse.

Website communications use secure connections where appropriate, and access to systems containing information is restricted according to the needs of the activity.

No system connected to the Internet can guarantee absolute security.

12. Rights of Data Subjects

Where applicable, you may exercise the following rights:

  • Access.
  • Rectification.
  • Erasure.
  • Restriction of processing.
  • Objection.
  • Data portability.
  • Withdrawal of consent.

Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.

To exercise your rights, you may write to:

[email protected]

You may also lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD) if you believe your rights have been infringed.

Information on how to exercise these rights forms part of the information obligations established under the GDPR.

13. Deletion of Information

You may request the deletion of your personal data using the email address indicated above.

The request will be handled where legally applicable, without prejudice to any data that must be retained temporarily in order to comply with legal obligations or address potential liabilities.

Where certain data temporarily remains in technical backups, it will not be used again for ordinary purposes once its deletion is required.

14. Email Communications

Where you voluntarily provide your email address to receive communications, it will be used for the purpose indicated at the time it is collected.

Where such communications are based on consent, you may withdraw that consent at any time.

15. Cookies

The use of cookies and similar technologies is governed by the Cookie Policy available at mistresselektra.org.

16. Legal Requests

Personal data may be disclosed to authorities, courts, or public bodies where there is a legal obligation or a valid request made in accordance with applicable law.

Data will not be disclosed to third parties that do not have a sufficient legal basis for requesting it.

17. Minors

The services linked to this website are intended exclusively for persons over the age of 18.

Requests from minors relating to these services are not accepted.

If it is discovered that a minor has provided information relating to such services, that information may be deleted.

18. Changes to This Policy

This Privacy Policy may be updated to reflect changes in services, forms, automated systems, technology providers, internal procedures, or applicable legislation.

The version published on mistresselektra.org will be the version in force at any given time.

WhatsApp

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

Analytics

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.