This Privacy Policy explains how Glass Pyramid Group (“we”, “us”, or “our”), operating under the legal entity Global Connect & Partners S.L. (NIF: ES-B 269 939 72), based in San Pedro Alcántara, Marbella, Spain, collects, uses, and protects personal data when you interact with our website, contact us, or use our products and services.
Data Controller: Global Connect & Partners S.L. · CL. Pizarro 41, 1 · 29670 San Pedro Alcántara, Marbella, España ·
info@glasspyramidgroup.com 1. Scope of This Policy
This policy applies to:
- Visitors to glasspyramidgroup.com and any related subdomains.
- Prospective and current clients who contact us or receive our services.
- Users of operational portals and software systems we deploy on behalf of clients (where we act as data processor — see Section 9).
2. What Data We Collect
2.1 Data you provide directly
- Identity data — name, company name, job title.
- Contact data — email address, phone number, WhatsApp number.
- Business data — information about your company, project requirements, or technical needs that you share during consultations or onboarding.
- Communication data — the content of emails, messages, or form submissions you send us.
- Financial data — billing information for invoice purposes (no payment card numbers are stored by us).
2.2 Data collected automatically
- Usage data — pages visited, time spent, clicks, browser type, device, operating system.
- Technical data — IP address, referral URL, session identifiers.
- Cookie data — see our Cookie Policy for full details.
3. Legal Basis for Processing (GDPR)
We process personal data only where we have a valid legal basis:
- Consent (Art. 6(1)(a)) — when you opt in to analytics cookies or marketing communications.
- Contractual necessity (Art. 6(1)(b)) — to deliver services you have engaged us for, issue invoices, and communicate during a project.
- Legitimate interests (Art. 6(1)(f)) — to respond to enquiries, improve our products, prevent fraud, and maintain business records.
- Legal obligation (Art. 6(1)(c)) — where required by Spanish, EU, or other applicable law (e.g., tax and accounting obligations).
4. How We Use Your Data
- To respond to enquiries and provide the services you request.
- To onboard you as a client and set up your operational system.
- To issue invoices and manage our commercial relationship.
- To send you relevant project updates, proposals, or follow-ups.
- To improve our website, products, and internal processes.
- To comply with legal and tax obligations under Spanish law.
We do not sell, rent, or trade your personal data to any third party for marketing purposes.
5. Sharing Your Data
We may share your data only in the following circumstances:
- Service providers — companies that process data on our behalf to provide the service (listed in Section 6). Each is bound by a data processing agreement.
- Legal obligation — if required by law, court order, or regulatory authority.
- Business transfer — in the event of a merger, acquisition, or sale of our business, your data may be transferred to the successor entity subject to equivalent protections.
6. Third-Party Processors
We use the following sub-processors to operate our services. All are contractually bound to process data only for the purposes we specify:
- Vercel Inc. (USA) — hosting and deployment infrastructure. EU region used where applicable. Covered by EU-US Data Privacy Framework.
- Supabase Inc. (USA) — database and authentication infrastructure. Data stored in EU region (Frankfurt, AWS eu-central-1).
- Resend Inc. — transactional email delivery for invoices, onboarding documents, and notifications.
- Google LLC — Google Analytics (anonymised usage data, only after cookie consent). Google Drive used for document storage where client-configured.
- Anthropic PBC — AI-assisted document processing and assistant features (zero data retention policy applied; no training on client data).
- Stripe Inc. (USA) — payment processing for service subscriptions and setup fees. Covered by EU-US Data Privacy Framework. Stripe processes cardholder name, billing address, and payment details; we do not store card data.
- Twilio Inc. (USA) — SMS and WhatsApp Business messaging for direct client communication where initiated by the client. Covered by EU-US Data Privacy Framework.
- Meta Platforms — WhatsApp Business for direct client communication where initiated by the client.
7. Data Retention
- Client records — retained for the duration of the engagement plus 7 years (Spanish commercial law requirement for accounting records).
- Prospect and enquiry data — retained for up to 2 years after last contact, unless you request earlier deletion.
- Analytics data — aggregated, anonymised usage data retained for up to 26 months (Google Analytics default).
- Email communications — retained for 3 years unless part of a live engagement, in which case client record retention applies.
8. International Transfers
Our primary service providers are US-based companies. Where data is transferred outside the European Economic Area (EEA), we rely on:
- EU Standard Contractual Clauses (SCCs) incorporated in our data processing agreements.
- EU-US Data Privacy Framework adequacy decisions where applicable (Vercel, Google).
- Storage in EU-region infrastructure where available (Supabase Frankfurt).
9. When We Act as Data Processor
When we deploy an operational system (OS) for a client, the client is the data controller for the personal data of their own customers and team members. We act as the data processor. In this capacity:
- We process data only on the documented instructions of the client.
- We do not access client data except for technical support or as required by law.
- We maintain appropriate security measures for the data we process.
- We sign a Data Processing Agreement (DPA) with each client before system deployment.
- We delete or return all client data upon termination of the engagement, as agreed in the DPA.
If you are an end-user of a Glass Pyramid OS system deployed by one of our clients, please contact that client directly regarding their privacy practices, as they are your data controller.
10. Your Rights (GDPR)
If you are in the EU or EEA, you have the following rights regarding your personal data:
- Right of access (Art. 15) — request a copy of the data we hold about you.
- Right to rectification (Art. 16) — request correction of inaccurate data.
- Right to erasure (Art. 17) — request deletion of your data where no legal basis for retention exists.
- Right to restriction (Art. 18) — request that we limit how we process your data.
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format.
- Right to object (Art. 21) — object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any right, contact us at info@glasspyramidgroup.com. We will respond within 30 days. You also have the right to lodge a complaint with the Spanish data protection authority (AEPD) at aepd.es.
11. Data Security
We implement appropriate technical and organisational security measures including:
- HTTPS encryption for all data in transit.
- Row-level security (RLS) policies in our database ensuring each client's data is isolated.
- JWT authentication with short-lived tokens for access control.
- File validation and size limits on all upload endpoints.
- No plaintext storage of passwords or API secrets.
- Regular security reviews of deployed systems.
No internet-based system is completely secure. If you believe a security incident has occurred, contact us immediately at info@glasspyramidgroup.com.
12. Cookies
We use cookies on our website. For full details of what cookies we use, why, and how to control them, see our Cookie Policy.
13. Children's Privacy
Our services are not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately.
14. Changes to This Policy
We may update this Privacy Policy as our services evolve or as legal requirements change. Material changes will be noted by updating the “Last updated” date and, where appropriate, notifying active clients by email. Continued use of our services after an update constitutes acceptance of the revised policy.
15. Contact
- Company: Global Connect & Partners S.L.
- Trading as: Glass Pyramid Group
- Address: CL. Pizarro 41, 1 · 29670 San Pedro Alcántara, Marbella, España
- NIF: ES-B 269 939 72
- Email: info@glasspyramidgroup.com
This policy was last updated in August 2026. Previous versions are available on request.