Privacy policy.
Last updated: June 22, 2026.
At Not A Sea we take protecting your data seriously. This policy explains, clearly and completely, what information we collect when you interact with this website, what we use it for, how long we keep it, who we share it with, and what rights you have over it.
1. Data controller
The controller responsible for the personal data collected through this website is:
- Legal name: OTOCO MATIC LLC-TECH GENIUS-SERIES 122 (operating under the trade name Not A Sea).
- Address: 390 NE 191st St, Ste 8558, Miami, FL 33179, United States.
- General contact email: info@notasea.com
- Privacy / data protection email: privacy@notasea.com
- Phone: +1 (307) 306-5523
1.1. EU representative
If you are located in the European Union, please note we are in the process of designating an EU representative for data protection matters, as required under applicable EU data protection law for providers established outside the EEA who offer services to EU residents. Their contact details will be:
- Name: Abogados Cuesta Altable
- Business address: Calle Postas 8 5ºC, Aranda de Duero, 09400, Burgos, España
- Contact email: abogados@cuestaaltable.com
In the meantime, you can reach out directly to us at privacy@notasea.com for any question regarding the processing of your personal data, and we will respond as the data controller.
2. What data do we collect?
We only collect the data strictly necessary to provide you with a good service. Specifically:
2.1. Data you provide to us voluntarily
When you fill out one of the forms available on the website, you provide us with the following data:
| Form | Data requested |
|---|---|
| Proposal request (hero) | Service of interest, main goal, approximate budget, name and email. Optionally, free-text context, timeline or goals. |
| Free website audit (audit) | URL of the site you want audited and an email address to send the report to. |
| General contact (contact) | Name, email, service of interest and a free-text message. |
2.2. Data we collect automatically
While you browse the website, we automatically collect certain technical data:
- Technical data associated with form submission: IP address, date and time of submission, and basic browser data (user-agent). This is collected for security purposes and to prevent abuse of the forms.
- Analytics data: through Google Analytics 4, only if you accept it. Aggregated and anonymous information about your visit and interactions (pages viewed, time on site, device, country, traffic source, form completions and button clicks). We never send your name, email or message content to Google Analytics. See our cookie policy for more detail.
3. For what purpose and on what legal basis do we process your data?
| Purpose | Legal basis |
|---|---|
| Respond to your request for information, a quote, or an audit, and manage the pre-contractual commercial relationship. | Performance of steps prior to entering into a contract, at your request. |
| Provide the contracted services and bill for them. | Performance of a contract. |
| Comply with legal, accounting and tax obligations. | Compliance with a legal obligation. |
| Anonymously measure website usage through Google Analytics 4. | Your consent. You can withdraw it at any time. |
| Detect and prevent abuse of the forms (anti-spam). | Our legitimate interest. |
If you are located in the EU, UK, or another jurisdiction with similar data protection laws (such as the GDPR), these purposes correspond to the legal bases recognized under that law (e.g. consent, contract performance, legal obligation, and legitimate interest). We do not make automated decisions with legal effects, nor do we build profiles from your data.
4. How long do we keep your data?
We apply the principle of data minimization: we only keep data for as long as strictly necessary for each purpose.
- Leads who do not become clients: up to 1 year from the last contact. After that period, the data is deleted or anonymized.
- Clients with a contractual relationship: for the duration of the contract and, afterwards, for the legal periods necessary to address any potential liabilities.
- Billing and accounting obligations: in line with the accounting and tax record-keeping periods applicable to us (typically several years after the invoice date).
- Google Analytics data: up to 14 months, the period configured in the property. It is then automatically deleted.
- Anti-spam / form abuse log (IP address, email, submission time): up to 30 days, then automatically deleted by a scheduled process.
- Cookie banner consent: stored in your browser (localStorage) until you clear it or change it.
5. Who do we share your data with?
We do not sell or transfer your data to third parties for commercial purposes. Only the following service providers have access to it, as they help us run the website and respond to your requests:
| Provider | Service | Location |
|---|---|---|
| n8n (self-hosted by Not A Sea) | Receives and automatically processes form submissions. | European Union |
| Google LLC (Google Sheets) | Records the leads received through the forms. | United States (with appropriate safeguards). |
| IONOS | SMTP relay used to deliver the internal new-lead notification email to our team. | European Union. |
| Google LLC (Gmail) | Inbox where our team receives the internal new-lead notification. | United States (with appropriate safeguards). |
| Resend, Inc. | Sends the automatic confirmation email you receive after submitting a form. | United States (with appropriate safeguards). |
| Google LLC (Google Analytics 4) | Aggregated, anonymous measurement of website usage. Only if you accept the cookie banner. | United States (with appropriate safeguards). |
We may also disclose your data to public authorities or courts where there is a legal obligation to do so.
6. International data transfers
Some of our providers (Google LLC, Resend, Inc.) are located in the United States. Where applicable, these transfers rely on the following safeguards:
- Google LLC is certified under the EU-US Data Privacy Framework, recognized as providing an adequate level of protection by the European Commission. Additionally, our contracts with Google incorporate the Standard Contractual Clauses approved by the European Commission.
- Our agreement with Resend, Inc. incorporates the safeguards required by applicable data protection law for this type of international transfer, such as the Standard Contractual Clauses.
The server that hosts n8n and the SMTP relay (IONOS) used to deliver internal notifications are located in the European Union, so no international transfer takes place for that part of the process.
7. What rights do you have?
Depending on your country of residence, you may have rights such as the following — for example, if you are located in the EU, UK, EEA, or another jurisdiction with comparable data protection laws:
- Access: find out what data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request the deletion of your data when it is no longer necessary.
- Objection: object to processing on grounds relating to your particular situation.
- Restriction: ask us to pause processing in certain circumstances.
- Portability: receive your data in a structured format to transfer it to another controller.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
- Not be subject to automated decisions with significant legal effects.
If your local law grants you additional or different rights, those will also apply.
8. How to exercise your rights
You can exercise any of these rights by sending a request to privacy@notasea.com, indicating:
- The right you wish to exercise.
- Your name and a contact email.
- A copy of an identity document. We only use it to verify it's really you, and we delete it after verification.
We will respond to your request within a maximum of one month of receiving it, extendable by two further months in cases of particular complexity (we would notify you in that case).
9. Right to lodge a complaint with a supervisory authority
If you believe that the processing of your data does not comply with applicable law, you have the right to lodge a complaint with the competent data protection supervisory authority. If you are located in the EU or EEA, you can find your national authority through the European Data Protection Board's directory of national authorities. If you are in the UK, the competent authority is the Information Commissioner's Office (ICO). If you are located elsewhere, your local data protection or consumer-protection authority may apply.
We would, however, appreciate the chance to resolve any concern directly first — please write to privacy@notasea.com: in most cases we can sort it out quickly.
10. Security of your data
We apply reasonable technical and organizational measures to protect your data against unauthorized access, loss, or destruction: encrypted communications (HTTPS), strong-password access control and two-factor authentication where supported by our tools, regular backups, and ongoing review of our providers' security configuration. No system is 100% foolproof, but we do what's reasonable to keep that risk to a minimum.
11. Minors
This website is aimed at professionals and businesses. We do not knowingly collect data from minors under 16 (or the minimum age defined by applicable local law). If we become aware that a minor's data was provided without the consent of their legal guardian, we will delete it immediately.
12. Changes to this privacy policy
This policy may be updated to reflect legal, technical, or operational changes. We recommend reviewing it periodically. When changes are substantial, we will notify you prominently on the website. The date of the last update appears at the top of this document.