Who is responsible
Data controller: Josue Perez Andujar, working under the trading name PereX. PereX is a trading name, not a company — the controller is an individual. Barcelona, Spain · josue@perex.design. A postal address for formal notices is available on request.
What this website collects
No cookies of any kind. No tracking cookies, no advertising, no fingerprinting, no cross-site tracking, no profiles, no ad networks. Nothing is sold, and nothing is shared for advertising. The only thing this site stores in your browser is your light/dark theme choice, which stays on your device and is never transmitted.
One small measurement layer exists, and I would rather name it than claim a purity the site doesn't have:
- A first-party page and interaction counter. On each page view your browser sends the page path — and nothing else — to a function on this domain, which keeps only running totals per page and per day. A few portfolio actions add only a fixed aggregate label so I can tell whether those routes work. It never sends message text, form values, a referrer, a cookie, an identifier, or a record of individual visits. It sends nothing at all if your browser signals Do Not Track or Global Privacy Control.
Like every website, this one also leaves ordinary server access logs with its host, which include IP addresses.
What arrives when you contact or hire me
Two forms on this site submit through Netlify Forms, which stores the submission and emails it to me:
- The contact form — your name, email address and message.
- The reference form at /vouch — your name, your role, how you know me, your words, and your explicit tick-box permissions for where that quote may appear. Nothing is published without the tick.
If you email, book a call, or purchase, I also receive what you provide: your name, email, company, and engagement details. Legal basis: taking steps toward and performing a contract (GDPR art. 6(1)(b)), and legitimate interest in replying to messages; for a published reference quote, your consent (art. 6(1)(a)), which you may withdraw at any time. I keep engagement records for as long as tax law requires invoices to be kept; correspondence that leads nowhere is deleted within a year.
Processors involved
Netlify hosts this site and provides its forms and serverless functions; form submissions are stored on Netlify's US infrastructure and are screened for spam. Scheduling runs on Calendly and email on Google, both acting on my instructions. Stripe handles payments and acts in two capacities: on my instructions for the payment itself, and on its own account for fraud prevention and the anti-money-laundering checks the law requires of it. Each of these is a US-headquartered provider, and each processes your data under its own GDPR safeguards (standard contractual clauses and/or EU–US Data Privacy Framework, per its then-current certification).
Contra is different, and worth stating plainly: the two fixed-price audits are booked and paid through Contra, so if you buy that way it is Contra — not I — that decides how your data is handled, as an independent controller under its own privacy policy, which permits it to transfer and store information outside the EU. If you would rather your data did not go to Contra, email me and we will arrange the engagement directly.
Your rights
Access, rectification, erasure, restriction, portability, objection — email me and it happens. You may also complain to the AEPD (Spain's data-protection authority). I don't sell data; there is nothing to opt out of. For US state privacy laws (e.g. CCPA): this practice is far below every applicability threshold, and the no-sale, no-tracking statements above apply regardless.