Home / GDPR
European Privacy Rights

GDPR & European Privacy Rights.

This page explains how AXMDGTL approaches the EU General Data Protection Regulation (GDPR) when the regulation applies to our processing of personal data.

Effective: August 24, 2026 Last updated: August 24, 2026
Our approach

Privacy is built into the way we collect, use and protect personal data.

AXMDGTL uses data minimization, purpose limitation, access controls, retention review, vendor oversight and consent controls for non-essential analytics. This page supplements our Privacy Policy and Cookie Policy.

1. Who is responsible for your data

For personal data processed through the AXMDGTL website and direct business interactions, AXMDGTL acts as the controller unless another arrangement or client agreement states otherwise. AXMDGTL is operated by ALFONSO MUJICA DIGITAL LLC, a California limited liability company.

Privacy questions and rights requests can be submitted through our Contact page.

2. When the GDPR may apply

The GDPR can apply to organizations established in the European Economic Area and, in certain circumstances, to organizations outside the EEA that offer goods or services to people in the EEA or monitor their behavior there. Whether a specific AXMDGTL activity falls within that scope depends on the facts and applicable law.

3. Personal data we may process

Depending on your interaction with us, personal data may include:

  • Name, business name, email address, phone number and other contact details.
  • Business, project, service, timing and budget information you choose to provide.
  • Messages, files, recordings or other materials you voluntarily submit.
  • Technical information such as IP address, browser, device, timestamps, requested pages and security logs.
  • Analytics information when you consent to non-essential analytics.
  • Communication preferences and records associated with an inquiry or client relationship.

4. Purposes and lawful bases

PurposeTypical lawful basis when GDPR applies
Responding to inquiries and evaluating project requestsSteps requested before entering a contract; legitimate interests where appropriate
Providing contracted services and project administrationPerformance of a contract
Website security, fraud prevention and troubleshootingLegitimate interests; legal obligations where applicable
Business, tax, accounting and compliance recordsLegal obligations; legitimate interests where appropriate
Non-essential website analyticsConsent where required
Optional marketing communicationsConsent or another lawful basis permitted by applicable law

The lawful basis can vary with the context. Where processing is based on consent, you may withdraw that consent at any time without affecting processing that was lawful before withdrawal.

5. Google Analytics and consent

AXMDGTL uses Google Analytics 4 only after analytics consent is granted through our privacy controls. If analytics consent is rejected or has not yet been given, the AXMDGTL consent manager is configured not to load the Google Analytics tag.

You can change or withdraw your analytics choice at any time using Cookie Preferences.

6. Service providers and recipients

We may use service providers for website hosting, security, forms, communications, analytics, CRM, file storage, automation and technical support. Providers are given access only as reasonably necessary for their role and are expected to handle personal data under appropriate contractual, security and privacy obligations.

Third-party services, including Jotform and Google Analytics when enabled, maintain their own privacy documentation and may process information under their own infrastructure and contractual terms.

7. International data transfers

AXMDGTL is based in the United States. Personal data submitted from the EEA may therefore be processed in the United States or other countries where our service providers operate. Where GDPR requires a transfer mechanism, we seek to rely on an applicable lawful mechanism or safeguard made available under data-protection law, such as an adequacy mechanism or approved contractual safeguards.

8. Data retention

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including inquiry handling, service delivery, security, dispute resolution, business records and legal or accounting obligations. Retention periods differ by category and context. Data that is no longer needed may be deleted, anonymized or restricted where appropriate.

9. Your GDPR rights

When the GDPR applies, you may have rights including:

  • The right to receive information about how your personal data is processed.
  • The right to request access to personal data concerning you.
  • The right to request correction of inaccurate or incomplete data.
  • The right to request erasure in circumstances provided by law.
  • The right to request restriction of processing in certain circumstances.
  • The right to data portability where the legal requirements are met.
  • The right to object to certain processing, including direct marketing.
  • The right to withdraw consent at any time where consent is the basis for processing.
  • Rights relating to certain solely automated decisions and profiling.

10. Exercising your rights

Submit a privacy request through the Contact page and identify the request as a “GDPR Privacy Request.” Please provide enough information for us to understand the request. We may request reasonable information to verify identity and protect personal data from unauthorized access.

We will respond within the time required by applicable law. Some rights are subject to legal exceptions, and we may retain information where a lawful retention obligation or permitted exemption applies.

11. Supervisory-authority complaints

If the GDPR applies to your personal data, you may have the right to lodge a complaint with the data-protection supervisory authority in the EEA country where you live, work or believe an infringement occurred. You may contact us first so we have an opportunity to address the concern, but doing so does not remove any applicable right to contact a supervisory authority.

12. Automated decision-making

AXMDGTL does not currently use the website to make decisions based solely on automated processing that produce legal effects or similarly significant effects on website visitors. If that practice changes, we will provide the information and safeguards required by applicable law.

13. Security and privacy by design

We use administrative, technical and organizational measures intended to protect personal data, including encrypted connections, access controls, data minimization, security monitoring, vendor review, retention controls and least-privilege practices appropriate to the system and risk.

14. Changes to this notice

We may update this page as our services, vendors, technology or legal obligations change. The “Last updated” date above identifies the most recent revision.

15. Contact

For GDPR questions, privacy rights requests or concerns, use our Contact page.

Start a Project →