Privacy Policy
Last updated: March 2026
Data Controller
DSPATIAL S.L. is the data controller responsible for your personal data.
Data We Collect
- Account information (name, email, company)
- Billing information (address, VAT number)
- Order and transaction history
- Support ticket communications
- Technical data (IP address, browser type) for security and fraud prevention
- Download activity (IP address, browser, timestamp) to prevent unauthorized distribution
- Login attempts (IP address, browser, timestamp) for brute-force protection
- Cookie consent preferences
Legal Basis
We process personal data based on: contractual necessity (fulfilling orders), legitimate interest (security, fraud prevention), legal obligation (tax/invoicing), and consent (marketing communications, analytics cookies).
Third-Party Data Processors
We share data with the following third parties, solely for the stated purposes:
- Stripe — Payment processing. Stripe Privacy Policy
- PayPal — Payment processing. PayPal Privacy Policy
- Cloudflare Turnstile — CAPTCHA/bot protection on forms. Cloudflare processes your IP address and browser information for security verification. Cloudflare Privacy Policy
- Hetzner Online GmbH — Web hosting (Germany/EU). Hetzner Privacy Policy
IP Geolocation
During checkout, we use your IP address to automatically detect your country for VAT calculation purposes. This may involve sending your IP address to a geolocation service (ip-api.com). You can always manually select your country instead. This processing is based on our legitimate interest in correct tax calculation.
Security Logging
For security purposes, we log failed and successful login attempts (including IP address and browser type) and CAPTCHA verification data. This data is retained for up to 30 days and is used solely for brute-force protection and fraud prevention, based on our legitimate interest in securing our services.
Your Rights (GDPR)
Under GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data — via your account profile
- Erase your data ("right to be forgotten") — via your account profile
- Data portability — export all your data from your account profile
- Restrict processing
- Object to processing
- Withdraw consent at any time (including cookie preferences via "Manage Cookies" in the footer)
Data Retention
- Account data: retained while your account is active, or until you request deletion
- Order and invoice records: 7 years (Spanish tax law — Ley General Tributaria)
- Login attempts and security logs: 30 days
- Download activity logs: 30 days
- Cookie consent records: until withdrawn
Multi-Brand Disclosure
DUY Audio (duy.com) and Dspatial (dspatial.com) are both operated by DSPATIAL S.L. Customer accounts and data are shared between both brands under the same data controller. All data processing described in this policy applies to both brands.
Contact
For privacy-related requests, contact us at privacy@duy.com.
DSPATIAL S.L. — Plaza Lesseps 33, 08023 Barcelona, Spain
