Skip to content
See services

Privacy policy

COMERCIO Y MARKETING ONLINE, S.L. · CIF B76750876

contacto@doymedia.com

We only process what is essential to deliver your order and reply to you: your email, the profile or link you want to boost and, if the service asks for them, the form details (links to posts, the option to vote for). Card details go encrypted to the payment gateway and we do not store them. Google cookies (analytics and advertising) are only activated if you accept them. We do not sell your data. To exercise any of your rights, write to contacto@doymedia.com.

1. Data controller

The controller of the personal data collected on this website is the company identified at the top of this page. For any data protection matter, write to contacto@doymedia.com.

2. What data we process

  • Order data: your email address, the social media profile or link to be boosted, the service and the pack, the origin and add-ons chosen, the amount and the language of the purchase.
  • Additional order data: if the service asks for them, the links to the posts, the number of posts or the poll option you enter in the form.
  • Payment data: card details (number, expiry date, security code and cardholder name) pass encrypted through our server and are sent in the same request to the payment gateway, which is the party that processes them. They are not stored, logged or retained in our systems. We only keep the result of the transaction and a gateway identifier.
  • Technical data: IP address, browser, country of connection and the browser data required by the 3D Secure protocol, to authenticate the payment and prevent fraud.
  • Contact and support data: your name, your email, the order reference if you provide it and the message you send us through the form or by email.
  • Tax data, only if you ask us for an invoice: name or company name, tax ID (NIF) and address.
  • Browsing data, only if you accept analytics or advertising cookies (see the cookie policy).
  • Performance of the contract (Art. 6(1)(b) GDPR): processing and delivering the order, refilling anything that drops within the guarantee, sending you the confirmation and issuing invoices.
  • Compliance with legal obligations (Art. 6(1)(c) GDPR): keeping the transaction records and the proof of your consent to an immediate start for the legally required periods.
  • Legitimate interest (Art. 6(1)(f) GDPR): preventing fraud and defending ourselves against unjustified payment disputes, using only the technical data and for 13 months.
  • Answering your queries (Art. 6(1)(b) or 6(1)(f) GDPR): replying to whatever you ask us through the form or by email.
  • Consent (Art. 6(1)(a) GDPR): measuring use of the website and the conversions from our ads with Google cookies, only if you accept them. You can withdraw your consent at any time from “Cookie settings”, in the footer of every page.

We do not send marketing emails or sign you up to anything.

4. How long we keep them

  • Order data, including the proof of consent to an immediate start: 6 years from the transaction (Article 30 of the Código de Comercio, the Spanish Commercial Code). After that, it is deleted automatically.
  • Technical data: 13 months from the transaction.
  • Support messages: 3 years from when the query is closed.
  • Tax data, if there is an invoice: 6 years.
  • Analytics and advertising cookies: the periods set out in the cookie policy.

We never keep card details.

5. Who we share them with

Only with the processors we need to provide the service, under a contract in accordance with Article 28 GDPR:

  • Cardinity (UAB, Lithuania): card payment gateway, 3D Secure authentication and fraud prevention.
  • Twilio SendGrid: sending confirmation and support emails.
  • Cloudflare: hosting of the website and of the order records.
  • Service fulfilment suppliers: they only receive the target profile or link, the quantity and, where necessary, the additional order data; never your email or your payment details.
  • Google Ireland Limited: analytics (Google Analytics 4) and conversion measurement (Google Ads), only if you accept those cookies.
  • Tax advisers: for our accounting obligations.

We do not sell, transfer or rent out personal data.

6. International transfers

If any processor handles data outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses (Decision 2021/914) or, where applicable, by an adequacy decision, such as the EU-US Data Privacy Framework for the companies that have signed up to it.

7. Your rights

You can exercise your rights of access, rectification, erasure, restriction of processing, objection and portability over your data, and withdraw your consent, by writing to contacto@doymedia.com. We reply within one month at most. If you are not satisfied, you can lodge a complaint with the Agencia Española de Protección de Datos (the Spanish Data Protection Agency, www.aepd.es) or with the data protection authority of your country of residence in the European Union.

To request erasure: write from the same email address you used for the order, with the subject “Data erasure” and, if you have it, the order reference. We immediately delete the email address, the target profile or link, the additional order data, the technical data and the support messages. What the law requires us to keep (amount, date and reference of the transaction) remains blocked until the retention period expires and is then deleted. We confirm by email what has been deleted and what remains blocked.

8. Security

The whole website runs over TLS encryption. The payment gateway is PCI-DSS certified and authenticates with 3D Secure. We apply technical and organisational measures to prevent unauthorised access to, loss of or alteration of the data.

9. Changes

We may update this policy because of legal or operational changes. If a change is substantial, we will notify it by email to anyone with an order in progress.

Updated on 24 September 2026