Privacy policy

 

Close Eyes Studio logo Close Eyes Studio

Last updated: 7 July 2026


1. Data controller

  • Controller: David Berrocoso Salmeron
  • Tax ID (NIF): 77129400G
  • VAT number (ROI/VAT): ES77129400G
  • Registered address: Carrer dels Pirineus 15, Santa Coloma de Gramenet, 08923, Barcelona
  • Contact email: legal@closeeyesstudio.com
  • Website domain: www.closeeyesstudio.com

This Privacy Policy governs the processing of the personal data that the Controller collects through the website www.closeeyesstudio.com (hereinafter, "the Website"), dedicated to the online sale of digital files in STL format and other 3D printing formats, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016 (GDPR) and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).


2. Principles applicable to data processing

The processing of the user’s personal data shall be subject to the following principles:

  • Principle of lawfulness, fairness and transparency: the user’s consent, or another legally provided legal basis, will be required at all times for the processing of their personal data, and such consent may be withdrawn at any time.
  • Principle of data minimisation: only the data strictly necessary in relation to the purposes for which they are required will be requested.
  • Principle of storage limitation: data will be kept for no longer than is necessary for the purposes of the processing; depending on the purpose, the corresponding retention period will be communicated. In the case of data relating to the contractual relationship, they will be kept for as long as neither party requests their deletion and, in any event, for the periods legally established in commercial, tax and accounting matters.
  • Principle of integrity and confidentiality: data will be processed in such a way as to guarantee their security, confidentiality and integrity.
  • Principle of proactive accountability: the Controller is responsible for complying with the above principles and for having available the documentation necessary to demonstrate such compliance to the competent supervisory authorities.

3. What data do we process, for what purpose and on what legal basis?

The purposes of the personal data processing that may take place on the Website, the data processed for each purpose and the legal basis legitimising such processing are detailed below:

3.1. Management of the purchase process and delivery of the digital files acquired

  • Data processed: first name and surname(s), email, billing address, NIF/CIF (if an invoice is requested), order details, download history.
  • Purpose: to manage the purchase process, issue the invoice or proof of purchase, enable the download of the STL files acquired and provide after-sales customer service (queries, incidents, warranties).
  • Legal basis: performance of a contract to which the data subject is a party (Article 6.1.b GDPR), as well as compliance with legal obligations in tax and commercial matters (Article 6.1.c GDPR).
  • Retention: for the duration of the contractual relationship and, thereafter, for the limitation periods of the applicable tax and commercial obligations (as a general rule, 5 years from the last transaction, without prejudice to longer periods that may arise from judicial or administrative proceedings).

3.2. Management of the user account (if the Website offers registration)

  • Data processed: username, email, password (encrypted), purchase history.
  • Purpose: to allow access to a private area, keep the order history and facilitate subsequent downloads of the files acquired.
  • Legal basis: performance of a contract/pre-contractual relationship at the request of the data subject (Article 6.1.b GDPR).
  • Retention: for as long as the account remains active and its deletion is not requested; in the event of prolonged inactivity, the account may be cancelled following prior notice to the user.

3.3. Handling of queries and communications through contact forms

  • Data processed: name, email and any other data the user voluntarily includes in the message.
  • Purpose: to respond to requests for information or queries raised by the user.
  • Legal basis: the data subject’s consent, given by submitting the form (Article 6.1.a GDPR), and/or the legitimate interest of the Controller in dealing with the requests received (Article 6.1.f GDPR).
  • Retention: for the time necessary to deal with the query and, thereafter, until any liability arising from it becomes time-barred.

3.4. Sending of commercial communications and newsletter (optional)

  • Data processed: email and, where applicable, name.
  • Purpose: to send commercial communications about new products, offers or news from the Website.
  • Legal basis: the user’s express consent, given by means of a non-pre-ticked acceptance box at the time of subscription (Article 6.1.a GDPR and Article 21 LSSI-CE). If the user is already a customer, the Controller may rely on the legitimate interest provided for in Article 21.2 LSSI-CE to send communications about its own products similar to those purchased, without prejudice to the user’s right to object at any time.
  • Retention: until the user withdraws their consent or objects to the processing.

3.5. Management of cookies and tracking technologies

  • Purpose and legal basis: as detailed in the Website’s Cookie Policy.

3.6. Product ratings and reviews (if enabled on the Website)

  • Data processed: name or alias, rating and comment, email (not published).
  • Purpose: to publish reviews of the STL files purchased for the benefit of other users.
  • Legal basis: the user’s consent when submitting the review (Article 6.1.a GDPR).
  • Retention: for as long as the product remains published on the Website or until the user requests its removal.

4. Data of minors

Access to and/or use of the Website, as well as making purchases, is reserved exclusively for persons of legal age (18 years) or, where applicable, minors who have the authorisation of their parents, guardians or legal representatives, who shall be considered responsible for the acts carried out through the Website by the minors in their care, including the completion of forms with the personal data of such minors and the reading of the conditions of use and of this Privacy Policy.


5. To which recipients will the data be disclosed?

For the correct provision of the service, the user’s personal data may be disclosed to the following recipients, in their capacity as data processors or, where appropriate, as independent controllers where applicable:

  • Web hosting provider(s): CLOUDFLARE (www.cloudflare.com), responsible for the technical hosting of the Website.
  • E-commerce / order management platform: SHOPIFY (https://www.shopify.com/)
  • Payment gateway(s): Shopify Payments, the payment processing system of Shopify Inc., which manages the payment methods available on the Website (currently including, among others, PayPal, Apple Pay, Google Pay, Klarna, Stripe and cards of the main card networks). The Controller does not have access to and does not store users’ full payment card details. Shopify Payments operates under the PCI-DSS security standard.
  • Commercial communications/newsletter provider: Shopify Email and Google Workspace, as data processors for the sending of communications.

The Controller requires all its suppliers, in their capacity as data processors, to comply with data protection regulations, formalising the corresponding data processing agreements required by Article 28 GDPR.


6. International data transfers

Some of the providers indicated in the previous section may be located outside the European Economic Area (EEA), in particular in the United States. In such cases, the Controller guarantees that the transfer is carried out subject to one of the safeguards provided for in Chapter V of the GDPR, such as:

  • Adequacy decisions of the European Commission (for example, in respect of entities adhering to the EU-U.S. Data Privacy Framework).
  • Standard contractual clauses approved by the European Commission.
  • Other appropriate safeguards provided for by law.

The user may request further information about the safeguards applied to these transfers by contacting the address indicated in section 1.


7. What are the user’s rights when providing us with their data?

The user may exercise, where applicable, the following data protection rights:

  • Right of access: to know which of their personal data are being processed.
  • Right to rectification: to request the correction of inaccurate data.
  • Right to erasure ("right to be forgotten"): to request the deletion of their data when, among other reasons, they are no longer necessary for the purposes for which they were collected.
  • Right to object: to object to the processing of their data, in particular with regard to the sending of commercial communications.
  • Right to restriction of processing: to request the restriction of the processing of their data in the cases provided for by law.
  • Right to data portability: to receive the personal data they have provided in a structured, commonly used and machine-readable format, and to transmit them to another controller.
  • Right not to be subject to automated individual decision-making: including profiling, which produces legal effects concerning them or similarly significantly affects them.
  • Right to withdraw consent: at any time, without affecting the lawfulness of the processing based on consent prior to its withdrawal.

The user may exercise these rights by sending a request to the email address legal@closeeyesstudio.com, indicating the right they wish to exercise and the data that reasonably allow their identity to be verified (for example, the email address with which they are registered on the Website or other data held by us). As a general rule, it will not be necessary to provide a copy of a national identity document or any other identity document. Only where there are reasonable doubts about the identity of the applicant that cannot be resolved by other less intrusive means may additional information be requested to confirm it, limited to what is strictly necessary.

The Controller will deal with the request within the legally established period (as a general rule, one month from receipt of the request, which may be extended by two months in duly justified cases of particular complexity).

Likewise, the user has the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), in particular where they have not obtained satisfaction in the exercise of their rights, through its electronic office: www.aepd.es


8. Security measures

The Controller has adopted appropriate technical and organisational security measures to guarantee a level of security appropriate to the risk of the processing of the personal data processed, in compliance with the provisions of Article 32 GDPR, preventing, as far as possible, their alteration, loss, unauthorised processing or unauthorised access.


9. Accuracy and truthfulness of the data provided

The user is solely responsible for the truthfulness and accuracy of the data they submit to the Website, releasing the Controller from any liability in this regard. Users guarantee and are responsible, in any event, for the accuracy, validity and authenticity of the personal data provided, and undertake to keep them duly updated.


10. Changes to this Privacy Policy

The Controller reserves the right to modify this Privacy Policy in order to adapt it to legislative or case-law developments, as well as to industry practices. These policies shall remain in force until they are replaced by others duly published, and users are advised to consult them periodically.