Privacy Policy
Last updated: July 2026
Version of this policy: v2 · July 2026 (identifier: privacidad-v2-2026-07)
1. Data Controller
Identity: Make Now
Email: [email protected]
Website: makenow.io
2. Personal Data We Collect
At Make Now, we only collect personal data when you voluntarily provide it through:
- Contact forms: name, email, message.
- Session bookings (Calendly): name, email, selected date and time.
- Email communication: data included in your correspondence with us.
- Free web audit requests: the address (URL) of the website you want us to analyse and your contact email address so we can send you the report.
We do not collect sensitive data or special categories of personal data.
3. Purpose of Processing
We process your personal data for the following purposes:
- Responding to your enquiries and information requests.
- Managing the booking and holding of strategy sessions.
- Carrying out an automated analysis of the website you provide us with and sending you the resulting report by email.
- Sending you communications related to our services, only if you have given your consent.
- Complying with applicable legal obligations.
Aggregated data. The technical results of our audits (for example, performance, SEO or accessibility scores) are kept in aggregated, anonymised form for statistical purposes and to improve our own analysis. The domain analysed is never published in an identifiable way, either on its own or combined with other data that would allow it to be inferred: we do not publish or share rankings, listings or examples that identify audited websites without your express written authorisation.
4. Legal Basis for Processing
The processing of your data is based on:
- Consent: by filling in a form or booking a session, you consent to the processing of your data for the stated purpose. In the case of the free web audit, the legal basis is your express consent (Art. 6(1)(a) GDPR), which you give by ticking the corresponding box before submitting your request. Together with your request we record the date, the time and the version identifier of this policy that you accepted, so that we can evidence which text was shown to you. You can withdraw your consent at any time by writing to [email protected], without affecting the lawfulness of processing carried out beforehand.
- Legitimate interest: for managing the business relationship and improving our services.
- Legal obligation: when necessary to comply with applicable legislation.
5. Data Recipients
Your personal data will not be shared with third parties except where required by law. We use the following service providers who may access your data as data processors:
- Calendly: session booking management. Calendly Privacy Policy.
- Supabase: the database where audit and contact requests are stored. Supabase Privacy Policy.
- Purelymail: the email service we use to send you the report and reply to your messages. Purelymail Privacy Policy.
- Hosting provider: website hosting.
International transfers. Not all of these providers are established in the European Union, and we want you to know exactly where you stand:
- Calendly (Calendly LLC) is a US company. Its transfers rely on the European Commission's Standard Contractual Clauses.
- Supabase (Supabase Inc.) is a US company whose infrastructure runs on data centres that allow a region to be chosen. Our project is configured in the European region (Frankfurt, Germany), so requests are stored in the EU; provider access from the United States relies on the Standard Contractual Clauses set out in its data processing addendum.
- Purelymail (Add Rabbit LLC, Pennsylvania, United States) does not publish the specific location of its servers, so you should assume that sending and temporarily storing email may involve an international transfer of data to the United States.
If you would rather we did not handle your email address through a provider outside the EU, write to us and we will find an alternative before sending you anything.
6. Data Retention
We will retain your personal data for as long as necessary to fulfil the purpose for which it was collected and to comply with applicable legal obligations. In general:
- Contact data: for the duration of the business relationship and during the applicable legal limitation periods.
- Booking data: for 12 months from the last interaction.
- Web audit requests (URL and email) and the report generated: for 12 months from the date the report is sent. We keep that period so that we can resend the report if you lose it, compare a second audit against the previous one and answer any later questions. After that period they are deleted.
- Consent record (date, time and version of this policy accepted): for 3 years from its withdrawal or from the deletion of the request, this being the maximum limitation period for data protection infringements. It is the only item we keep longer than the request itself, and it exists precisely so that we can demonstrate that we informed you.
- Aggregated, anonymised technical results: with no time limit, since once anonymised they are no longer personal data and cannot be used to re-identify the website analysed.
7. Your Rights
Under the General Data Protection Regulation (GDPR), you have the right to:
- Access: know what personal data of yours we process.
- Rectification: request the correction of inaccurate or incomplete data.
- Erasure: request the deletion of your data when no longer necessary.
- Restriction: request the restriction of processing in certain circumstances.
- Portability: receive your data in a structured, commonly used format.
- Objection: object to the processing of your data in certain circumstances.
To exercise these rights, send us an email at [email protected] specifying your request and attaching a copy of your identification document.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD).
8. Cookies
This website uses cookies. For more information, please see our Cookie Policy.
9. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction.
10. Changes and Versions
We reserve the right to modify this privacy policy to adapt it to legislative or case-law developments. We recommend reviewing it periodically.
Each version of this policy has its own identifier, shown at the top of this page. The current version is
privacidad-v2-2026-07. When you submit a form we store that identifier together with your
consent, so that we can always know — and show you — exactly which text you were presented with at the time.
A change to this policy does not retroactively alter what you accepted.
11. Contact
If you have any questions about this privacy policy or about the processing of your data, you can contact us at [email protected].