Website hosting and email routing
- Provider
- Cloudflare, Inc.
- Processes
- Site request logs; inbound mail routing to our mailbox
- Location
- USA (EU edge locations)
Case file · Practice · US · 2026
AI Visibility Partners ("AIVP", "we") is a service of Astratto Design LLC, a US company whose team works remotely from Valencia, Spain, serving clients in the United States. This notice explains what personal data we handle, why, and what your rights are. It is written to be read, not skimmed past — if anything in it is unclear, email us at hello@aivispartners.com.
AI Visibility Partners · Last updated: 19 September 2026
1
This is a static website. It sets no cookies, runs no tracking scripts, and has no forms. We do not use advertising pixels, session recording, or third-party analytics tags.
The site is hosted by Cloudflare (Cloudflare, Inc., USA). To deliver pages and protect the site, Cloudflare processes the technical data any web server sees — your IP address, browser type, the pages requested, and timestamps — and keeps short-lived request logs for security and performance purposes. We do not receive or use this data to identify individual visitors.
2
Every "contact us" action on this site is a plain email link to hello@aivispartners.com. When you write to us, we receive whatever you choose to send — typically your name, email address, firm name, website, and your message. We use it to reply to you and, if you become a client, to run the engagement. Our email is handled by Google LLC (Gmail) and reaches us through Cloudflare Email Routing.
Legal basis (GDPR): our legitimate interest in responding to enquiries; performance of a contract once an engagement begins.
Retention: enquiry emails are kept for up to 12 months after our last exchange, unless you become a client (see section 3) or ask us to delete them sooner.
We do not add you to a mailing list. We do not send newsletters or automated sequences. If we follow up on an enquiry, a person is writing to you.
3
Our work is about how AI engines describe and cite businesses, so most of what we handle is business information, not personal data. Where personal data is involved, this is what happens:
The business facts you give us to publish (name, phone, address, credentials, service areas — the "published-facts pass" in our intake questionnaire); the names and work contact details of your points of contact; and, only where you grant it, access to your website platform, Google Analytics, and Search Console.
We ask for the least access that lets us do the agreed work (viewer access where viewer access is enough). Credentials are exchanged only through a password-manager share or the access method agreed at intake, never in ordinary email or in our working documents. Access is revoked at the end of the engagement and the revocation date is confirmed to you in writing.
To measure your AI visibility we run buyer-style prompts on AI engines and keep the raw answers, screenshots, timestamps, and source lists as evidence. Those answers are generated by the engines and may name businesses and people (your competitors, reviewers, your own team). We keep this evidence because our reports must be reproducible; we redact private contact details, billing data, and anything unrelated to your engagement before sharing evidence outside your engagement workspace.
We publish nothing about your engagement without your written consent, re-confirmed at publication. You can choose to be named, anonymized, or not published at all, as set out in your agreement.
Legal basis (GDPR): performance of the contract with you; our legitimate interest in keeping accurate, reproducible records of our work; legal obligation for invoicing and tax records.
Retention: engagement evidence, reports, and working files are kept for 12 months after the engagement ends, then deleted, unless you ask for earlier deletion or an approved case study requires the underlying evidence to be archived for as long as it is published. Invoices and tax records are kept for as long as applicable US and Spanish law requires.
4
We are a small practice and we use third-party services to do the work. Each receives only what it needs:
International transfers. We are based in Spain and most of these providers are in the United States. Where personal data leaves the EEA, we rely on the EU–US Data Privacy Framework where the provider is certified under it, and otherwise on the standard contractual clauses included in the provider's terms. For our US clients, the practical picture is simpler: your data is handled by a Spain-based team and by the same US services you likely already use.
5
We do not sell personal data. We do not share it with anyone for advertising. We do not buy contact lists. We do not scrape or store personal data about individuals as part of our research — our prospect research is about businesses and their public web presence. We do not train AI models on your data, and we do not enter your credentials or confidential information into any AI tool.
6
If you are in the EU/EEA or UK, you have the right to access, correct, delete, or restrict the personal data we hold about you, to receive a copy of it in a portable format, and to object to processing based on our legitimate interests. You can also lodge a complaint with a supervisory authority; ours is the Agencia Española de Protección de Datos (AEPD), www.aepd.es. If you are in the United States, several state laws give similar rights; we extend the same rights to everyone regardless of where you live.
To exercise any of these, email hello@aivispartners.com. We will respond within 30 days and will not ask you to jump through hoops.
7
This site and our services are for businesses and are not directed at anyone under 18. We do not knowingly collect personal data from children.
8
If we change how we handle data — a new tool, a new retention period — we update this page and change the date at the top. Material changes to how we handle client data are communicated to current clients directly.