Privacy Policy
This page explains what personal data ConnectBarcelona (connect-barcelona.com) collects, why we collect it, and what rights you have. It covers this website only.
1. Who is responsible for your data
The website connect-barcelona.com is operated by:
ConnectBarcelona
Email: dimitris.kazarnovskis@web.de
Our full operator details, including our postal address, are being finalised and will be published on this page and in our Legal Notice. Until then, please write to us at the email address above; we will answer any request, including a request for those details.
Under EU data protection law (the GDPR), this makes ConnectBarcelona the “controller” responsible for the personal data described below.
2. What we collect, and why
2.1 The enquiry form on provider pages
Provider pages on this site have a form you can use to send a service provider a question or ask for an introduction. It asks for your name, your email address, an optional phone number, and a free-text message, and it has a consent checkbox you must tick before you can send it. The form also quietly records which provider page you filled it in on and that page’s web address, so your enquiry reaches the right provider.
What happens to it: your submission is saved in this website’s own database, and a copy is emailed to ConnectBarcelona’s own inbox. We read it, and then pass it on to the service provider your enquiry is about. That provider then sees your enquiry in their own account on this site; section 3.5 lists exactly what they see.
The form also records the IP address you sent it from and the identifier your browser sends about itself. We keep those two for six months. They exist so that a flood of automated submissions can be told apart from real enquiries, and they are never used to build any profile of you. Legal basis: our legitimate interest in keeping the form usable (Article 6(1)(f) GDPR).
Legal basis: we process this data because it is necessary to take the steps you asked for — putting you in touch with that provider — before any contract with the provider exists (Article 6(1)(b) GDPR).
Do you have to provide it? No, filling in the form is voluntary. But if you leave out your name or email, neither we nor the provider have any way to respond to you, so in practice your enquiry cannot be handled without them.
2.2 The form on our homepage
The form on our homepage works the same way, and asks for the same things plus the kind of service you are looking for. The difference is that no provider is named yet: you are asking us to find one. We read it, choose a provider we have checked, and pass your details to them, as section 4 describes. Nothing you send through this form appears in any provider’s dashboard.
2.3 The page-view counter
Each provider page keeps a simple visit counter in this website’s own database — a running total, plus a count for each of the last 30 days. This counter is a plain number. It does not record your IP address, your name, or any other identifier, and it does not use a cookie. Because no personal data is involved, this isn’t something GDPR governs — we mention it here for transparency only, not because it is “analytics” in the usual sense. This site does not use Google Analytics, or any other visitor-tracking analytics tool.
Separately, this site is registered with Google Search Console, connected through the Site Kit plugin. That gives us statistics about how the site appears in Google’s own search results — it is based on Google’s own search data, not on tracking your visit to this site.
2.4 Google Fonts
Pages on this site load some of their fonts directly from Google’s servers (fonts.googleapis.com and fonts.gstatic.com). When your browser does this, it automatically sends your IP address to Google — for every visitor, before you have made any cookie choice, because the page needs the font file to display correctly.
The data involved is the technical information your browser sends with any request: your IP address, the type of browser and device you are using, and the address of the page you are on. This happens on every page of this site, and it is a transfer of data to a company in the United States — see section 5.
3. Provider accounts and the provider dashboard
Service providers listed on this site can have an account here. Clients cannot: there is nothing on this site for a client to sign up for. If you are here as a client, the part of this section that concerns you is section 3.5, which says what the provider gets to see about you.
3.1 How an account comes to exist
There is no sign-up form anywhere on this site and no way to register yourself. An account exists only because we created it by hand, after we had checked the provider ourselves. So a provider with an account already knows about it: it came out of a conversation with us, not out of a registration page.
Legal basis: we need the account to do what we agreed with that provider (Article 6(1)(b) GDPR).
3.2 What an account holds
A provider account holds a username, the provider’s name, their email address, a password, and an internal identifier that ties the account to that provider’s own page on this site.
The password is not kept as it was typed. It is stored only as a hash, a scrambled version that cannot be turned back into the password. Nobody here can look up a provider’s password; we can only replace it.
3.3 Signing in, and the cookies that come with it
Providers sign in at connect-barcelona.com/account/. Signing in sets WordPress session cookies in the browser. They do one job: keep the provider signed in from one page to the next. They are not used for analytics, not used for advertising, and not shared with anyone. They last two days, or fourteen days if the provider ticks “Keep me signed in”, and they end when the provider signs out.
Providers cannot reach the WordPress administration area at all. The dashboard at /account/ is all an account can do on this site.
3.4 Password changes and failed sign-ins
A provider can change their own password on that page. When they do, we record the time of the change and the IP address it was made from. We also count failed sign-in attempts on an account. We keep both for six months.
Why we keep them: so that somebody trying to get into an account that is not theirs does not go unnoticed.
Legal basis: our legitimate interest in keeping provider accounts, and the client enquiries behind them, secure (Article 6(1)(f) GDPR).
3.5 What a provider sees about you
If you have sent an enquiry through a provider’s page, that provider sees it in their dashboard: your name, your email address, your phone number if you gave one, your message, and the date you sent it. Nothing else about you reaches them from us.
A provider sees only the enquiries sent through their own page. They cannot see enquiries sent to another provider, and an enquiry sent through the form on our homepage never appears in any dashboard. If you write to us through the homepage form, we choose a provider for you and pass your details to them ourselves, as section 4 describes.
Inside the dashboard the provider marks how far your enquiry has got (new, contacted, in progress, closed, lost), and once a job is done, they report the amount to us, so that our commission can be worked out. That figure is about the job, not about you.
Who is responsible for what: we pass your enquiry to the provider you asked for, and the consent checkbox you tick before sending the form is what covers passing it on. From the moment it arrives with them, the provider handles it under their own responsibility. They are not acting on our instructions, and they decide for themselves how they store your enquiry and how long they keep it. Section 4 says the same in the list of who receives your data.
4. Who receives your data
- The provider named in your enquiry. We pass your enquiry on to them, and they also read it in their own account on this site (section 3.5): your name, email address, phone number if you gave one, message, and date. Once it reaches them, that provider decides for themselves how to use, store, and respond to it. From that point on, your relationship is with the provider, not with ConnectBarcelona — the provider is a separate controller of your data, not someone acting on our instructions. A provider only ever receives the enquiries sent through their own page. An enquiry sent through the form on our homepage does not appear in any provider’s account; when we find you a provider, we pass your details to them ourselves and tell you who they are.
- Our hosting provider. This site is hosted by IONOS SE, Elgendorfer Strasse 57, 56410 Montabaur, Germany, a German company. IONOS stores this website’s database and files and therefore holds any personal data contained in them, acting on our instructions.
- Google. As explained in section 2.4 above, loading Google Fonts sends your IP address to Google.
5. Data sent outside the EU
Google is a US company. When your browser loads a Google Font, your IP address reaches Google in the United States — a country outside the EU/EEA. Google states that it complies with the EU-U.S. Data Privacy Framework, and that it additionally relies on Standard Contractual Clauses for transfers not covered by an adequacy decision. We checked this on Google’s own published policy on 1 August 2026.
The service providers introduced through this site are Barcelona-based businesses within the EU, so forwarding your enquiry to one of them does not, by itself, send your data outside the EU.
6. How long we keep your data
- Enquiry form submissions: we keep your enquiry for as long as it takes to make the introduction and to check afterwards that it went well, and then as a record of that introduction. The longest we keep one is 24 months, counted from the last time anything about it changed. For as long as we keep it, and for as long as that provider still has an account here, they can also see it in their account, including after they have marked it closed or lost. You can ask us to delete your enquiry at any time, and we will do so unless we are legally required to keep it; deleting it also removes it from that provider’s account on this site. What we cannot delete is any copy the provider has saved elsewhere, and section 7 explains what to do about that.
- Provider accounts: an account stays for as long as the provider works with us, and we delete it, with the provider’s name and email address, within 30 days of that arrangement ending.
- Security records: The security records described in section 3.4, meaning the time and IP address of a password change and the count of failed sign-ins: six months.
- Page-view counter: this is a running number with no personal data attached, so no personal-data retention period applies to it.
- Hosting-level technical logs: like most websites, ours sits behind a webserver operated by our hosting provider, which may automatically record basic connection details such as IP address, browser type and the time of the request, for security and stability. These logs are created and kept by the hosting provider under its own retention rules; we do not use them for any other purpose, and we do not combine them with anything else.
7. Your rights
Under the GDPR, you can ask us at any time to:
- tell you what personal data we hold about you, and give you a copy (right of access);
- correct data that is wrong or incomplete (right of rectification);
- delete your data (right of erasure);
- limit what we do with your data while a request is being looked into (right of restriction);
- object to our processing of your data;
- receive the data you gave us in a portable format (right of data portability).
One limit worth stating plainly: these rights cover what we hold. Once your enquiry has reached the provider, they hold their own copy and answer for it themselves (section 3.5). We can delete our copy, and that also removes it from their account on this site, but we cannot delete anything they have saved elsewhere. If you no longer remember which provider received your enquiry, ask us: we will tell you, and we will forward your request to them if you prefer.
If you are a provider with an account here, the same rights cover your account data: seeing what it holds, correcting it, and deleting it. Write to the same address.
To use any of these rights, contact us at the email address in section 1.
Complaints: you can also complain to a data protection authority. For us, that is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), the state data protection authority for North Rhine-Westphalia, Germany. You are also free to complain to the data protection authority in whichever country you live in — you do not have to contact the German authority specifically.
8. Automated decisions
We do not use automated decision-making or profiling. Every enquiry you send through this site is read and handled by a person.
9. Cookies, and what loads before you choose
This site loads no optional cookies at all, so you will not see a consent banner asking you about them. If that ever changes, we will ask for your permission before anything that is not strictly necessary is allowed to run. At the time of writing, no optional service is switched on behind that banner — there is no advertising on this site, and no analytics tool such as Google Analytics is in use.
Two things load for everyone regardless of your cookie choice, because the page cannot display without them: the Google Fonts described in section 2.4 above, and this website’s own strictly necessary technical data needed to keep the site working, such as remembering your cookie-consent choice itself.
There is one more set of cookies, and only providers ever get it: signing in at connect-barcelona.com/account/ sets the WordPress session cookies described in section 3.3. The banner does not ask about them, because without them the sign-in would not survive the next click. They are not used for analytics or advertising, they last two days (fourteen with “Keep me signed in”), and signing out ends them. If you have never signed in as a provider, this site sets no login cookie for you at all.
If we switch on any additional service in future that reads or writes cookies — for example analytics or advertising — we will ask for your consent through the banner first, and you will be able to withdraw that consent at any time.
Last updated
This policy was last updated on 14 August 2026. The new section 3 covers provider accounts, the provider dashboard, and what a provider sees about you.