Legal information

Privacy Policy and Cookie Policy

How we collect, use and protect your personal data, and which cookies this website uses. Drafted to comply with European, Spanish and United States privacy law.

Last updated: 15 September 2026 RGPD · LOPDGDD · LSSI-CE · CCPA/CPRA
In short: we only process the data you give us so we can assist you (contact form, consultation booking and virtual assistant), we do not sell or disclose your data for commercial purposes, we only use strictly necessary technical cookies, and you can exercise your rights at any time by writing to contacto@dicra.io.

1. Data controller

In accordance with Article 13 of Regulation (EU) 2016/679 (GDPR) and Article 11 of Spanish Organic Law 3/2018 (LOPDGDD), the controller of your personal data is:

Identity
GLOBAL TORLA
Tax ID (NIF)
B10927689
Website
Camino IFÁ — caminoifa.com
Postal address
Paseo de la Castellana, 266 — Madrid (Spain)
Telephone
+34 690 840 690
Data protection contact
contacto@dicra.io
General site contact
contacto@caminoifa.com
Data Protection Officer
Not required under Article 37 GDPR or Article 34 LOPDGDD. Data protection matters are handled at contacto@dicra.io.

This policy covers the website caminoifa.com and all of its forms and services: the contact form, consultation booking and payment, the AI-powered virtual assistant and the technical visit log.

2. Applicable law and territorial scope

We process your data in accordance with whichever of the following applies to you:

European Union and European Economic Area

  • Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR).
  • Directive 2002/58/EC on privacy in electronic communications (ePrivacy), as regards cookies.

Spain

  • Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
  • Law 34/2002 on information society services and electronic commerce (LSSI-CE), in particular Article 22.2 on cookies and Article 10 on general information.
  • The cookie guidance and other criteria issued by the Spanish Data Protection Agency (AEPD).

United States

  • The CCPA (California Consumer Privacy Act) as amended by the CPRA, and its implementing regulations.
  • Equivalent state laws in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland and Tennessee, among others.
  • COPPA (Children's Online Privacy Protection Act), the CAN-SPAM Act and Nevada SB 220 on the sale of data.

If you live in the European Union, the GDPR protects you regardless of where our servers are located. If you live in the United States, section 13 applies to you in addition to everything set out in this policy.

3. Principles we apply

In line with Article 5 GDPR, we process your data lawfully, fairly and transparently; we collect it for specified, explicit and legitimate purposes; we limit ourselves to the data that is strictly necessary (minimisation); we aim to keep it accurate and up to date; we retain it only for as long as required; and we apply technical and organisational measures that safeguard its integrity and confidentiality.

We also keep the documentation that evidences this compliance (accountability, Article 5.2 GDPR), including the record of processing activities required by Article 30 GDPR, which we review periodically to confirm that it matches the data we actually collect and the disclosures we actually make.

4. What data we process, for what purpose and on what legal basis

We only process the data you provide and the strictly technical data generated by your browsing. We do not buy databases and we do not obtain your data from third parties.

4.1. Booking and delivery of IFÁ consultations (customers)

DataFull name, email address, WhatsApp number (optional, for video calls), the text of the question you write, language, chosen service, amount, payment reference and date.
PurposeManaging your booking, delivering the service you purchased, communicating with you about the consultation, and issuing and keeping invoices.
Legal basisPerformance of a contract or pre-contractual steps (Art. 6.1.b GDPR). For invoicing and its retention, compliance with legal obligations (Art. 6.1.c GDPR). For the content of the consultation, your explicit consent (Art. 9.2.a GDPR); see section 5.
SourceYou, through the booking form on the website.
NecessityFields marked as required are needed to deliver the service; without them we cannot process your booking.

About payment: payment is handled entirely by the Stripe gateway. Your card details are entered in Stripe's secure environment and never pass through or get stored on our servers. We only keep the payment session reference and its outcome (paid or not paid).

4.2. Contact form

DataName, email address, telephone (optional), service of interest and the message you write.
PurposeAnswering your enquiry, information request or quotation request.
Legal basisYour consent when submitting the form (Art. 6.1.a GDPR) and pre-contractual steps taken at your request (Art. 6.1.b GDPR).
Anti-abuseThe form includes an in-house verification code stored in the server session to prevent automated submissions. Legitimate interest in the security of the service (Art. 6.1.f GDPR).

4.3. AI-powered virtual assistant

DataThe messages you write, the recent conversation history (up to the last 8 turns, sent to provide context), the language, your IP address and a session counter, the last two used solely to apply usage limits.
PurposeProviding automated informational guidance on IFÁ and the Yoruba tradition, and preventing abuse of the service.
Legal basisYour consent when you voluntarily start the conversation (Art. 6.1.a GDPR) and legitimate interest in limiting abuse and controlling the cost of the service (Art. 6.1.f GDPR).
ProcessorMessages are transmitted to Anthropic PBC (United States), the provider of the language model that generates the reply. See sections 6 and 7.
Please do not type sensitive data into the chat. The assistant is an informational tool: it does not replace a personal consultation with a babalawo and does not constitute medical, psychological, legal or financial advice. We recommend not providing health data, other people's data, passwords or banking details.

4.4. Technical visit and interaction log

DataIP address, host name obtained by reverse DNS lookup, approximate location (city and country) derived from the IP, date and time, request method and path, data submitted through forms (excluding the verification code) and browser user agent.
PurposeWebsite security, detection and prevention of abuse and attacks, error diagnosis and internal usage statistics.
Legal basisOur legitimate interest in ensuring network and information security (Art. 6.1.f GDPR and recital 49).
NatureThis log is only active when the administrator enables it and is automatically deleted after 21 days. It is never used to build commercial or advertising profiles.

4.5. Cookies and browsing data

We use strictly necessary technical cookies only. Full details are in the Cookie policy (section 14).

4.6. Suppliers

Data subjectsPeople with whom we maintain a commercial relationship as suppliers of products or services.
DataIdentification and tax data: name or company name, tax ID, postal address, telephone and email.
PurposeManaging the supplier relationship, placing orders and handling invoicing.
Legal basisPerformance of the contract (Art. 6.1.b GDPR) and compliance with tax and accounting obligations (Art. 6.1.c GDPR).

4.7. Staff and collaborators

Data subjectsPeople who provide services for the controller.
DataIdentification and contact data, social security number and data needed to manage the relationship.
PurposeManaging the employment or service relationship and complying with labour, tax and social security obligations.
Legal basisPerformance of the contract (Art. 6.1.b GDPR) and compliance with legal obligations (Art. 6.1.c GDPR).
ErasureData is erased when the relationship ends, unless a legal obligation requires us to keep it.

4.8. Video surveillance on the premises

If you visit our premises in person and they are fitted with security cameras, you are informed by the notice displayed in a visible area. In that case the purpose is security and access control; the data subjects are the people who access or attempt to access the premises; the recipients are law enforcement authorities; and images are kept for a maximum of one month, except for those recording potentially unlawful acts, which are made available to the competent authority within 72 hours. Staff rest areas are not filmed, and public thoroughfares are avoided as far as possible. Monitors are located in restricted-access areas.

If no cameras are used on the premises, this section does not apply.

5. Sensitive data, beliefs and health

Our services relate to a spiritual tradition. Simply booking a consultation, or the content you write to us, may therefore reveal religious or philosophical beliefs and, occasionally, references to your health — data that Article 9 GDPR treats as special categories and that the CCPA/CPRA classes as sensitive personal information.

  • This data is processed solely on the basis of your explicit consent (Art. 9.2.a GDPR), which you give when you book a consultation and voluntarily provide that information, and which you may withdraw at any time.
  • It is processed only to deliver the service you requested — never for advertising, profiling or disclosure to third parties.
  • Access is limited to the babalawo handling your consultation and to the person responsible for administration, both bound by a duty of secrecy and confidentiality that remains in force even after the relationship ends.
  • Please do not give us more sensitive data than necessary, nor personal data about other people without their knowledge and consent.
  • We do not process genetic or biometric data, or data on sexual orientation, trade union membership, or racial or ethnic origin.
About the nature of the service. IFÁ consultations are spiritual and orientational in purpose. They do not constitute or replace medical or psychological diagnosis or treatment, nor legal or financial advice. If you are facing a health problem, please consult a healthcare professional.

6. Recipients of the data and processors

We do not sell, rent or disclose your personal data to third parties for commercial or advertising purposes. It is accessed only by the providers strictly necessary to deliver the service, acting as processors under the contract required by Article 28 GDPR, and by the bodies to which we are legally required to disclose it.

6.1. Processors

ProviderService providedData accessedLocation
Stripe Payments Europe, Ltd. and Stripe, Inc.Payment gateway and fraud preventionName, email, amount and card details, entered directly in their environmentIreland / USA
Anthropic PBCLanguage model generating the virtual assistant's repliesThe messages you type in the chat and the recent conversation historyUSA
Google Ireland Ltd. / Google LLCWeb fonts (Google Fonts) served when the page loadsIP address and basic technical browser data. No cookies are set.Ireland / USA
ip-api.comApproximate IP geolocation, only when the visit log is enabledIP addressUSA / EU
Hosting and email providerWebsite and database hosting, and sending and receiving emailThe data stored on the serverEuropean Union

6.2. Disclosures required by law

Where legally required, we may disclose data to the Spanish Tax Agency, the Social Security General Treasury, banks and financial institutions for the management of payments and collections, our tax, accounting and employment advisers, and courts, tribunals and law enforcement authorities when they so require.

7. International data transfers

Some of our providers are located in the United States, which means international transfers outside the European Economic Area take place. These transfers rely on one of the safeguards set out in Chapter V of the GDPR:

  • The European Commission adequacy decision of 10 July 2023 on the EU-U.S. Data Privacy Framework, where the provider is certified under that framework.
  • The Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, supplemented where appropriate by additional measures: encryption in transit, minimisation of the data transferred and limited retention periods.

You may request a copy of the safeguards applied by writing to contacto@dicra.io. Beyond these cases, no international transfers are envisaged.

8. Retention periods

ProcessingRetention period
Customer bookings and consultationsFor the duration of the commercial relationship and thereafter for the statutory limitation periods: 4 years for tax matters, 5 years for personal actions and 6 years for commercial records under Spanish law.
Content of the spiritual consultationErased once the service has been delivered and the period for handling any complaint has elapsed, or earlier if you ask us to erase it.
Contact formAs long as needed to answer your request and, at most, 1 year from the last contact, unless a legal obligation applies.
Virtual assistant conversationsHeld in your browser session and lost when you close it. The daily per-IP counter is cleared when the day changes.
Technical visit log21 days, automatically deleted.
Supplier and staff dataThe periods laid down by tax, commercial and employment law.
Video surveillance images1 month maximum.
CookiesAs set out in the table in section 14: session or 12 months.

Once these periods expire, data is erased or anonymised using secure destruction measures.

9. Your rights and how to exercise them

The law grants you the following rights over your personal data. Exercising them is free of charge.

Access

Find out whether we process your data and obtain a copy, together with the purpose, the recipients, the envisaged retention periods and the origin of the data if you did not provide it yourself.

Rectification

Correct inaccurate data or complete incomplete data. Tell us which data you mean and what the correction should be.

Erasure

Ask us to delete your data when it is no longer necessary, when you withdraw consent, or when you object and no other legal basis applies.

Objection

Object to the processing of your data. If you object to direct marketing, we will stop processing your data for that purpose immediately.

Restriction

Ask us to suspend processing while the accuracy of the data or the balance of our legitimate interest is verified, or to keep the data if you need it for legal claims.

Portability

Receive the data you provided in a structured, commonly used, machine-readable format, or have us transmit it to another controller where technically feasible.

Withdraw consent

Withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.

Lodge a complaint

Lodge a complaint with the supervisory authority, particularly if you feel your request has not been properly addressed.

9.1. How to exercise your rights

By email: contacto@dicra.io

By post: GLOBAL TORLA — Paseo de la Castellana, 266 — Madrid (Spain)

State which right you are exercising and enclose a copy of your national ID or passport, or identify yourself by electronic means or by a signed document, so that we can verify your identity and prevent anyone else from accessing your data.

9.2. Response times

  • We will reply without undue delay and within one month at the latest from receipt of your request.
  • That period may be extended by a further two months where the request is particularly complex or where we receive a large number of requests. In that case we will tell you about the extension and the reasons for it within the first month.
  • If you submit your request electronically, we will reply by the same means unless you ask otherwise.
  • If we do not act on your request, we will explain why, also within one month, and inform you of your right to complain to the Spanish Data Protection Agency and to seek a judicial remedy.
  • We keep evidence that we have complied with our duty to answer the requests received.

9.3. Supervisory authority

Authority
Spanish Data Protection Agency (AEPD)
Address
Calle Jorge Juan, 6 — 28001 Madrid, Spain
Website
www.aepd.es
Electronic office
sedeagpd.gob.es

On the right of access to video surveillance images: to verify your identity we will ask for a recent photograph and a copy of your identity document, as well as the date and time range concerned. Direct access will not be given to images showing third parties; in that case you will receive a document confirming or denying the existence of images of you.

10. Artificial intelligence and automated decisions

The site's virtual assistant generates its replies automatically using a language model. However:

  • We do not take automated decisions producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR.
  • We do not build profiles — commercial, advertising or behavioural — from your conversations or your browsing.
  • The assistant's answers are indicative and may contain inaccuracies. The actual consultation is always carried out by a person, the babalawo.
  • The chat interface clearly tells you that you are interacting with an artificial intelligence system and not with a person.

11. Security measures and data breaches

We apply the appropriate technical and organisational measures required by Articles 5.1.f and 32 GDPR to guarantee the integrity and confidentiality of the data, including:

Organisational measures

  • A duty of confidentiality and secrecy for all staff with access to personal data, which continues even after the employment or collaboration relationship ends.
  • A prohibition on disclosing data to third parties, and particular care during telephone and email enquiries.
  • Locking the screen when leaving the workstation, and keeping paper documents and electronic media in a secure, restricted-access place.
  • Secure destruction of documents and media (CDs, USB drives, hard disks) before disposal.
  • Informing and training staff on their data protection obligations.
  • Periodic review of the security measures.

Technical measures

  • Unambiguous identification of each user with their own username and password, and separation between administrator profiles and everyday user profiles.
  • Strong passwords of at least 8 characters combining letters and numbers, never shared or written down in accessible places.
  • Encryption in transit via HTTPS/TLS across the whole site, and assessment of encryption for data taken off the premises.
  • Computers and devices kept up to date, with updated antivirus software and a properly configured firewall.
  • Regular backups on a device other than the one used for day-to-day work, stored securely in a separate location.
  • Access keys for external services are stored outside the server's public folder and are never exposed in the browser.
  • The database and data folders are blocked from direct access over the internet.

Data breaches

Should a personal data breach occur, we will notify the Spanish Data Protection Agency within 72 hours of becoming aware of it, through sedeagpd.gob.es, unless the breach is unlikely to result in a risk to your rights and freedoms. Where the breach is likely to result in a high risk, we will also inform you without undue delay (Articles 33 and 34 GDPR). If you live in the United States, the applicable state breach notification laws will also apply.

12. Children

  • Our services are aimed exclusively at people aged 18 or over. We do not provide consultations or ceremonies to minors.
  • Under Article 7 LOPDGDD, consent-based processing of the data of children under 14 is lawful only with the consent of the holder of parental responsibility or guardianship.
  • In line with the US COPPA, we do not knowingly collect personal information from children under 13. We also do not sell or share the personal information of consumers under 16 within the meaning of the CCPA/CPRA.
  • If we find that we have collected a child's data without the necessary authorisation, we will delete it immediately. If you are a parent or guardian and believe this has happened, please write to contacto@dicra.io.

13. Privacy notice for United States residents

This section supplements the information above and is addressed to consumers residing in California (CCPA/CPRA) and in other states with applicable privacy legislation. In it, the terms personal information, sale and sharing have the meaning given to them by the relevant law.

13.1. Information we collect (Notice at Collection)

CCPA categoryCollected?Examples on this site
A. IdentifiersYesName, email, telephone or WhatsApp, IP address
B. Customer records information (Cal. Civ. Code §1798.80)YesName, telephone and payment transaction data
C. Protected classification characteristicsNoWe do not ask for age, sex, origin or marital status
D. Commercial informationYesServices purchased and booking history
E. Biometric informationNo
F. Internet or network activityYesPages visited, user agent, date and time, technical cookies
G. Geolocation dataYes (approximate)City and country derived from the IP, only when the log is enabled. We do not use precise geolocation
H. Sensory information (audio, video)Only if applicableVideo surveillance images at physical premises
I. Professional or employment informationStaff onlyData of staff and collaborators
J. Education information (FERPA)No
K. Inferences used to create a profileNoWe do not create profiles
L. Sensitive personal informationYesReligious or philosophical beliefs and, where applicable, references to health voluntarily included in the text of your consultation

13.2. Sources, purposes and recipients

  • Sources: directly from you, through the forms and the chat, and automatically from your device as you browse.
  • Business purpose: delivering and invoicing the service you requested, communicating with you, keeping the site secure, preventing fraud and complying with legal obligations.
  • Recipients: only the service providers listed in section 6, bound by contract and not permitted to use the information for their own purposes.

13.3. We do not sell or share your personal information

We do not sell personal information and we do not share it for cross-context behavioural advertising, nor have we done so in the preceding 12 months. We also do not sell or share the personal information of consumers under 16. This site therefore does not need a Do Not Sell or Share My Personal Information link: there is no such sale or sharing to opt out of.

We also do not use or disclose sensitive personal information for purposes other than those permitted by CCPA §1798.121 — that is, solely to provide the service you requested. Even so, you may ask us to limit its use if you prefer.

13.4. Your rights

  • Right to know / access: learn the categories and specific pieces of personal information we have collected about you, their sources, the purpose and the recipients over the preceding 12 months.
  • Right to delete: request deletion of the personal information we have collected, subject to the statutory exceptions.
  • Right to correct: request correction of inaccurate information.
  • Right to opt out of sale or sharing: not applicable, as we neither sell nor share personal information.
  • Right to limit the use of sensitive information: you may request it, although we already restrict ourselves to permitted uses.
  • Right to data portability: receive the information in a commonly used, machine-readable format.
  • Right to non-discrimination: we will not deny you service, charge you different prices or provide a different level of quality because you exercised your rights. We do not offer financial incentives in exchange for personal information.
  • Right to appeal: if we decline your request and you live in Virginia, Colorado, Connecticut, Texas, Oregon, Montana or another state that provides for it, you may ask us to review our decision by replying to our communication.

13.5. How to exercise these rights

Write to contacto@dicra.io with the subject line US Privacy Request, or by post to the address in section 1. To protect your information we will verify your identity by matching the details you give us against those already in our records; for requests for specific pieces of information we may require enhanced verification. We will respond within 45 days, extendable by a further 45 days with notice. There is no charge, except for manifestly unfounded or excessive requests.

Authorised agent: you may designate a person or entity to act on your behalf. We will ask them to provide written proof of your authorisation, and we may ask you to confirm both your identity and the authorisation directly.

13.6. Browser opt-out signals

We honour Global Privacy Control (GPC) and Do Not Track signals sent by your browser. Since we do not sell or share personal information and use no advertising or analytics cookies, there is no further processing to switch off when we receive them.

13.7. Other state notices

  • California — Shine the Light (Cal. Civ. Code §1798.83): we do not disclose personal information to third parties for their own direct marketing purposes.
  • Nevada (SB 220): we do not sell personal information covered by that law; you may nevertheless send us an opt-out request at the email address above.
  • Commercial communications (CAN-SPAM): we only send emails relating to the service you requested. Should we ever send commercial communications, they will always include a free and effective unsubscribe mechanism.
  • Retention: we keep personal information for the periods set out in section 8 and do not use it for purposes incompatible with those for which it was collected.

14. Cookie policy

This section complies with Article 22.2 LSSI-CE, Directive 2002/58/EC and the AEPD cookie guidance.

14.1. What cookies are

A cookie is a small text file that a website stores in your browser to save and retrieve information about your visit: remembering your preferences, keeping your session open or protecting a form, for example. Alongside cookies there are similar technologies, such as browser local storage, which this site does not use.

14.2. Cookies used by this site

Camino IFÁ uses strictly necessary technical cookies only, so that the site works and remembers the language you chose. We use no analytics, advertising, profiling or social media cookies, which is why, under Article 22.2 LSSI-CE, your prior consent is not required to set them and no cookie banner is displayed.

CookieOwnerTypePurposeDuration
PHPSESSID caminoifa.com First party Strictly necessary Identifies your session on the server so we can validate the contact form verification code and apply the virtual assistant's usage limits. It holds no personal data — only a random identifier. Session (deleted when you close the browser)
lang caminoifa.com First party Technical / personalisation Remembers the language you chose (Spanish or English) so you do not have to select it on every visit. 12 months
__stripe_mid, __stripe_sid and other Stripe cookies stripe.com Third party Technical / security and fraud prevention Set only if you start a payment and are redirected to the Stripe gateway, and set on Stripe's own domain. They serve to detect fraudulent transactions. See Stripe's privacy policy. __stripe_mid: 1 year · __stripe_sid: 30 minutes

14.3. Third-party services without cookies

The site's typefaces are loaded from Google Fonts. This service sets no cookies, but when downloading the files your browser communicates your IP address and basic technical data to Google. See Google's privacy policy.

14.4. How to manage or delete cookies

You can allow, block or delete the cookies stored on your device through your browser settings:

You can also browse in private or incognito mode, where cookies are deleted when you close the window.

What happens if you block technical cookies. If you disable PHPSESSID, the contact form will not be able to validate the verification code and cannot be submitted, and the virtual assistant may stop working properly. If you disable lang, the site will no longer remember your language and will revert to the default on every visit.

14.5. Updates to this cookie policy

We review this list of cookies periodically and whenever we add a new service. Should we ever use analytics, advertising or any other non-exempt cookies, we would first implement a consent mechanism in line with the AEPD guidance, with equivalent options to accept, reject and configure, and with the ability to withdraw consent at any time.

15. Links to third-party sites

This site may contain links to third-party pages, such as the Stripe payment gateway or AEPD resources. When you visit them you are subject to their own privacy and cookie policies, over which we have no control. We recommend reading them before providing your data. GLOBAL TORLA is not responsible for how those third parties process your information.

16. Changes to this policy

We may amend this policy to reflect legislative or case-law changes or new services on the site. The version in force is always the one published on this page, showing the date it was last updated. If the changes substantially affect how we process your data, we will tell you through a visible notice or by email where we have your address. We recommend checking this page from time to time.

18. Annex: information clause for forms

The following text must appear, in line with the AEPD documentation, on every form used to collect personal data, whether on paper or on the web:

Controller: GLOBAL TORLA — NIF: B10927689. Postal address: Paseo de la Castellana, 266, Madrid. Telephone: +34 690 840 690. Email: contacto@dicra.io

"At GLOBAL TORLA we process the information you provide us for the purpose of providing the service requested and processing billing. The data provided are retained for the duration of the commercial relationship or for the period necessary to comply with legal obligations and to attend to the possible responsibilities that may arise from compliance with the purpose for which the data were collected. Data shall not be assigned to third parties unless there is a legal obligation to do so. You have the right to obtain information as to whether at GLOBAL TORLA we are processing your personal data, and therefore you may exercise your rights of access, rectification, erasure and portability of data and limitation of or objection to processing, by contacting GLOBAL TORLA, Paseo de la Castellana, 266, Madrid, or by email to contacto@dicra.io, properly identifying yourself by electronic means or by means of a signed document. Furthermore, and especially where you consider that the exercise of your rights has not been fully satisfied, you may lodge a complaint with the national supervisory authority, contacting the Spanish Data Protection Agency, Calle Jorge Juan, 6 — 28001 Madrid."

We also request your authorisation to offer you products and services related to those you have requested and to build customer loyalty: ☐ YES    ☐ NO

Warning. If the person ticks NO, marketing material may under no circumstances be sent to them.

Questions about your data?

Write to contacto@dicra.io and we will get back to you. Exercising your rights is always free.