Privacy policy.
What data we process when you visit milaflow.dev, create an account, buy or use a MilaFlow licence, and what rights you have. In short: we process the minimum needed to provide and charge for the service, and the content of your sites never passes through us.
This is a translation provided for convenience; in case of discrepancy, the Spanish version prevails.
Last updated · October 2, 2026Data controller
- ControllerAxia Strategies SL (Milato Studio)
- Tax ID (NIF)B75963686
- AddressC. de la Sort, 11 · 25700 La Seu d'Urgell (Lleida), Spain
- Contacthola@milatostudio.com (subject "Privacy")
What data we process, why and on what basis
| Activity | Data | Purpose and legal basis | Retention |
|---|---|---|---|
| Browsing | IP address, browser, requested page and date (technical server logs). | Serving the website and protecting it against abuse. Legitimate interest (art. 6.1.f GDPR). | The strictly necessary technical time. |
| Customer account | Email, name, password (only its hashed form, never in plain text), Google identifier if you sign in with Google, active sessions. | Creating and managing your account and giving you access to your licences. Performance of a contract (art. 6.1.b). | For as long as you keep the account. Sessions expire after 30 days. |
| Purchases and billing | Name or company name, billing address, country, VAT number if provided, products, amounts and dates. | Charging, invoicing and complying with tax and commercial obligations. Contract and legal obligation (art. 6.1.b and c). | 6 years from the transaction (Spanish Commercial Code and tax legislation). |
| Licences | Licence key, domains where you activate it, plugin version, validation dates and migrations used. | Applying the limits of your plan, delivering updates and preventing misuse. Contract and legitimate interest. | While the licence is in force and for 12 months afterwards. |
| Service emails | Email and name. | Confirming your email, resetting your password, sending your licence and renewal or payment notices. Contract. | Same as the account. |
| Support and reports | Your message and, if sent from the plugin, the technical context attached (domain, WordPress, PHP and plugin versions, active theme and builder) and the reply-to email. | Handling your query or solving the issue. Consent when you send it and legitimate interest in improving the product. | 2 years from when the query is closed. |
| Contact form | Name, email, message, the page you write from and IP address. | Replying to you. Consent when you send it. The IP is only used to limit repeated submissions and prevent abuse (legitimate interest). | 2 years. The per-IP submission counter, 2 hours. |
| Analytics (only if you accept it) | Pages you visit (including pricing), checkout starts and purchases, cookie identifiers, device and browser type, and approximate location. | Understanding how the site is used and improving it, with Google Analytics 4. Consent (art. 6.1.a GDPR and art. 22.2 LSSI-CE). | Up to 14 months in Google Analytics. |
| Advertising (only if you accept it) | Visits and conversions (checkout starts and purchases), cookie identifiers and browser data. | Measuring and attributing the conversions of our Facebook and Instagram campaigns, with the Meta pixel. Consent. | Meta cookies last up to 90 days. |
| Consent record | Your cookie choice, its date and a consent identifier. | Being able to prove what you accepted or rejected. Legal obligation (art. 7.1 GDPR). | 12 months; after that we ask you again. |
We do not send you commercial communications without your prior consent, which you may withdraw at any time.
Analytics and advertising are accepted separately and you can change your mind at any time from the cookie policy. If you reject them, the site, purchases, licence delivery and service emails work just the same.
What we do not process
MilaFlow runs on your WordPress server and is operated by your AI agent (Claude Code, Codex, Cursor or another) with your subscription. We therefore do not receive the content of your sites, the data of your users or customers, or your conversations with the agent. That information is processed between your hosting and the AI provider you choose, under their own terms. We only receive what is described above (such as the domain when validating the licence) and whatever you send us in a report.
If you use MilaFlow on your clients' sites, you (or your client) remain the controller of the data on those sites; we do not access it and do not act as its processor.
Who we share data with
We do not sell data. Only the providers needed to deliver the service are involved:
- Cloudflare (website hosting, database and storage, inbound mail for hola@milaflow.dev and abuse protection): processor.
- Stripe (payments): processes payment and billing data. Your card is handled by Stripe; we never see it.
- Customer.io (sending service emails: account access, licence and purchase, and contact-message notices), in its EU data centre: processor.
- Google: if you choose "Sign in with Google", it confirms your email and name to us. If you accept analytics, Google Analytics 4 and Google Tag Manager (which loads the measurement tags) act as processors.
- Meta Platforms Ireland (only if you accept advertising): measures the conversions of our ads with its pixel.
- CookieYes (managing and recording cookie consent): processor.
- Tax and accounting advisers, for legal obligations, and public authorities where required by law.
Some of these providers may process data outside the European Economic Area, mainly in the United States. In such cases the transfer is covered by the EU-U.S. Data Privacy Framework (for participating companies) and by the standard contractual clauses approved by the European Commission.
Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw any consent you have given, by writing to hola@milatostudio.com with the subject "Privacy". We will reply within one month. We may ask you to verify your identity.
If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es).
Security
Communications are encrypted (HTTPS). Passwords are stored using a key derivation function (PBKDF2), and sessions and access links are stored only as cryptographic hashes. Access to data is restricted to the staff who need it.
Other matters
- MilaFlow is aimed at professionals and businesses. It is not intended for anyone under 18.
- We do not make decisions based solely on automated processing that produce legal effects concerning you.
- The data you provide must be accurate and up to date; you can correct it from your account or by writing to us.
- If we change this policy in a material way, we will notify you by email or in your account before the change takes effect.