LEGAL

Privacy Policy

Last updated: 15 July 2026

This Privacy Policy explains how personal data is collected and used when you visit rly.one ("the Site") or contact us through it. It also covers our use of cookies and, for business clients, the terms on which we process personal data on your behalf (Data Processing Agreement).

1. Who we are (Data Controller)

The data controller is:

Andrei Bushuev (sole trader / autónomo)

Mallorca 236, 08008 Barcelona, Spain

VAT / NIF: ESZ1110287J

Trading as: RLY

Contact: andrew@rly.one

For any privacy question or request, email andrew@rly.one.

2. What data we collect

We only collect the data you submit through the contact form on the Site:

Name

Email address

Brand URL

Monthly ad spend (range you select)

Message ("where the funnel leaks" free-text field)

We also process limited technical data through cookies and analytics — see Section 8.

We do not knowingly collect any special-category data. Please do not include sensitive personal information in the free-text field.

3. Why we use it and legal basis

We use this data only to respond to your inquiry and to take steps at your request prior to entering into a contract.

Legal basis: performance of a contract or steps prior to a contract (Art. 6(1)(b) GDPR), and our legitimate interest in answering and following up on business inquiries (Art. 6(1)(f) GDPR).

Analytics cookies are used only with your consent (Art. 6(1)(a) GDPR), given via the cookie banner.

We do not use your data for automated decision-making or profiling, and we do not sell it.

4. Where your data is stored and who processes it

Inquiry data is received and stored in our email systems and is not shared beyond the service providers ("processors") below:

Google (Google Workspace / Gmail) — email delivery and storage of your inquiry.

Cloudflare — website hosting, security and content delivery.

Google Analytics — website usage statistics (only if you consent).

Each processor acts on our instructions under a data-processing agreement.

5. International transfers

Google and Cloudflare are US-based providers and may process data outside the EU/EEA. Such transfers are covered by the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses, providing an adequate level of protection.

6. How long we keep it

We keep inquiry data only as long as needed to handle your request and any resulting business relationship, plus a reasonable follow-up period. If no relationship develops, we delete it within a reasonable time.

To request deletion at any time, email andrew@rly.one.

7. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict or object to the processing of your data, to data portability, and to withdraw consent at any time. To exercise any of these, email andrew@rly.one.

You may also lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD, www.aepd.es) or your local supervisory authority.

8. Cookie Policy

We use two categories of cookies:

Strictly necessary (always on): set by Cloudflare to run the Site securely and reliably. These do not require consent and cannot be switched off.

Analytics (optional): Google Analytics, used to understand how the Site is used. These are set only if you opt in via the cookie banner. You can withdraw consent at any time by clearing cookies or adjusting your choice in the banner.

Most browsers also let you block or delete cookies in their settings.

9. Data Processing Agreement (for clients)

This section applies where we (RLY / Andrei Bushuev) process personal data on behalf of a client in the course of providing our services (e.g. running managed campaigns). It forms a data-processing agreement under Art. 28 GDPR between the client ("Controller") and us ("Processor").

Subject matter and duration: processing lasts for the term of our service engagement.

Nature and purpose: processing personal data as needed to deliver the agreed services.

Types of data and data subjects: as determined by the Controller and limited to what the services require.

Our obligations: we process personal data only on the Controller's documented instructions; ensure persons authorised to process are bound by confidentiality; apply appropriate technical and organisational security measures; assist the Controller with data-subject requests and security/breach obligations; and, at the Controller's choice, delete or return the data at the end of the engagement.

Sub-processors: we use the providers listed in Section 4. The Controller consents to these and will be informed of intended changes so it can object.

International transfers: governed as described in Section 5.

To put a signed DPA in place, email andrew@rly.one.

10. Security

We apply reasonable technical and organisational measures (access controls, reputable providers, encryption in transit) to protect personal data. No system is completely secure, but we work to keep your data safe.

11. Changes

We may update this Policy from time to time. The current version is always available on the Site, with the date shown above.

12. Contact

Questions or requests: andrew@rly.one.

← Back to home