1. Data controller
In accordance with Article 13 of Regulation (EU) 2016/679 (GDPR) and Article 11 of Spanish Organic Law 3/2018 (LOPDGDD), the controller of your personal data is:
- Identity
- GLOBAL TORLA
- Tax ID (NIF)
- B10927689
- Website
- Camino IFÁ — caminoifa.com
- Postal address
- Paseo de la Castellana, 266 — Madrid (Spain)
- Telephone
- +34 690 840 690
- Data protection contact
- contacto@dicra.io
- General site contact
- contacto@caminoifa.com
- Data Protection Officer
- Not required under Article 37 GDPR or Article 34 LOPDGDD. Data protection matters are handled at contacto@dicra.io.
This policy covers the website caminoifa.com and all of its forms and services: the contact form, consultation booking and payment, the AI-powered virtual assistant and the technical visit log.
2. Applicable law and territorial scope
We process your data in accordance with whichever of the following applies to you:
European Union and European Economic Area
- Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR).
- Directive 2002/58/EC on privacy in electronic communications (ePrivacy), as regards cookies.
Spain
- Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
- Law 34/2002 on information society services and electronic commerce (LSSI-CE), in particular Article 22.2 on cookies and Article 10 on general information.
- The cookie guidance and other criteria issued by the Spanish Data Protection Agency (AEPD).
United States
- The CCPA (California Consumer Privacy Act) as amended by the CPRA, and its implementing regulations.
- Equivalent state laws in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland and Tennessee, among others.
- COPPA (Children's Online Privacy Protection Act), the CAN-SPAM Act and Nevada SB 220 on the sale of data.
If you live in the European Union, the GDPR protects you regardless of where our servers are located. If you live in the United States, section 13 applies to you in addition to everything set out in this policy.
3. Principles we apply
In line with Article 5 GDPR, we process your data lawfully, fairly and transparently; we collect it for specified, explicit and legitimate purposes; we limit ourselves to the data that is strictly necessary (minimisation); we aim to keep it accurate and up to date; we retain it only for as long as required; and we apply technical and organisational measures that safeguard its integrity and confidentiality.
We also keep the documentation that evidences this compliance (accountability, Article 5.2 GDPR), including the record of processing activities required by Article 30 GDPR, which we review periodically to confirm that it matches the data we actually collect and the disclosures we actually make.
4. What data we process, for what purpose and on what legal basis
We only process the data you provide and the strictly technical data generated by your browsing. We do not buy databases and we do not obtain your data from third parties.
4.1. Booking and delivery of IFÁ consultations (customers)
| Data | Full name, email address, WhatsApp number (optional, for video calls), the text of the question you write, language, chosen service, amount, payment reference and date. |
|---|---|
| Purpose | Managing your booking, delivering the service you purchased, communicating with you about the consultation, and issuing and keeping invoices. |
| Legal basis | Performance of a contract or pre-contractual steps (Art. 6.1.b GDPR). For invoicing and its retention, compliance with legal obligations (Art. 6.1.c GDPR). For the content of the consultation, your explicit consent (Art. 9.2.a GDPR); see section 5. |
| Source | You, through the booking form on the website. |
| Necessity | Fields marked as required are needed to deliver the service; without them we cannot process your booking. |
About payment: payment is handled entirely by the Stripe gateway. Your card details are entered in Stripe's secure environment and never pass through or get stored on our servers. We only keep the payment session reference and its outcome (paid or not paid).
4.2. Contact form
| Data | Name, email address, telephone (optional), service of interest and the message you write. |
|---|---|
| Purpose | Answering your enquiry, information request or quotation request. |
| Legal basis | Your consent when submitting the form (Art. 6.1.a GDPR) and pre-contractual steps taken at your request (Art. 6.1.b GDPR). |
| Anti-abuse | The form includes an in-house verification code stored in the server session to prevent automated submissions. Legitimate interest in the security of the service (Art. 6.1.f GDPR). |
4.3. AI-powered virtual assistant
| Data | The messages you write, the recent conversation history (up to the last 8 turns, sent to provide context), the language, your IP address and a session counter, the last two used solely to apply usage limits. |
|---|---|
| Purpose | Providing automated informational guidance on IFÁ and the Yoruba tradition, and preventing abuse of the service. |
| Legal basis | Your consent when you voluntarily start the conversation (Art. 6.1.a GDPR) and legitimate interest in limiting abuse and controlling the cost of the service (Art. 6.1.f GDPR). |
| Processor | Messages are transmitted to Anthropic PBC (United States), the provider of the language model that generates the reply. See sections 6 and 7. |
4.4. Technical visit and interaction log
| Data | IP address, host name obtained by reverse DNS lookup, approximate location (city and country) derived from the IP, date and time, request method and path, data submitted through forms (excluding the verification code) and browser user agent. |
|---|---|
| Purpose | Website security, detection and prevention of abuse and attacks, error diagnosis and internal usage statistics. |
| Legal basis | Our legitimate interest in ensuring network and information security (Art. 6.1.f GDPR and recital 49). |
| Nature | This log is only active when the administrator enables it and is automatically deleted after 21 days. It is never used to build commercial or advertising profiles. |
4.5. Cookies and browsing data
We use strictly necessary technical cookies only. Full details are in the Cookie policy (section 14).
4.6. Suppliers
| Data subjects | People with whom we maintain a commercial relationship as suppliers of products or services. |
|---|---|
| Data | Identification and tax data: name or company name, tax ID, postal address, telephone and email. |
| Purpose | Managing the supplier relationship, placing orders and handling invoicing. |
| Legal basis | Performance of the contract (Art. 6.1.b GDPR) and compliance with tax and accounting obligations (Art. 6.1.c GDPR). |
4.7. Staff and collaborators
| Data subjects | People who provide services for the controller. |
|---|---|
| Data | Identification and contact data, social security number and data needed to manage the relationship. |
| Purpose | Managing the employment or service relationship and complying with labour, tax and social security obligations. |
| Legal basis | Performance of the contract (Art. 6.1.b GDPR) and compliance with legal obligations (Art. 6.1.c GDPR). |
| Erasure | Data is erased when the relationship ends, unless a legal obligation requires us to keep it. |
4.8. Video surveillance on the premises
If you visit our premises in person and they are fitted with security cameras, you are informed by the notice displayed in a visible area. In that case the purpose is security and access control; the data subjects are the people who access or attempt to access the premises; the recipients are law enforcement authorities; and images are kept for a maximum of one month, except for those recording potentially unlawful acts, which are made available to the competent authority within 72 hours. Staff rest areas are not filmed, and public thoroughfares are avoided as far as possible. Monitors are located in restricted-access areas.
If no cameras are used on the premises, this section does not apply.
5. Sensitive data, beliefs and health
Our services relate to a spiritual tradition. Simply booking a consultation, or the content you write to us, may therefore reveal religious or philosophical beliefs and, occasionally, references to your health — data that Article 9 GDPR treats as special categories and that the CCPA/CPRA classes as sensitive personal information.
- This data is processed solely on the basis of your explicit consent (Art. 9.2.a GDPR), which you give when you book a consultation and voluntarily provide that information, and which you may withdraw at any time.
- It is processed only to deliver the service you requested — never for advertising, profiling or disclosure to third parties.
- Access is limited to the babalawo handling your consultation and to the person responsible for administration, both bound by a duty of secrecy and confidentiality that remains in force even after the relationship ends.
- Please do not give us more sensitive data than necessary, nor personal data about other people without their knowledge and consent.
- We do not process genetic or biometric data, or data on sexual orientation, trade union membership, or racial or ethnic origin.
6. Recipients of the data and processors
We do not sell, rent or disclose your personal data to third parties for commercial or advertising purposes. It is accessed only by the providers strictly necessary to deliver the service, acting as processors under the contract required by Article 28 GDPR, and by the bodies to which we are legally required to disclose it.
6.1. Processors
| Provider | Service provided | Data accessed | Location |
|---|---|---|---|
| Stripe Payments Europe, Ltd. and Stripe, Inc. | Payment gateway and fraud prevention | Name, email, amount and card details, entered directly in their environment | Ireland / USA |
| Anthropic PBC | Language model generating the virtual assistant's replies | The messages you type in the chat and the recent conversation history | USA |
| Google Ireland Ltd. / Google LLC | Web fonts (Google Fonts) served when the page loads | IP address and basic technical browser data. No cookies are set. | Ireland / USA |
| ip-api.com | Approximate IP geolocation, only when the visit log is enabled | IP address | USA / EU |
| Hosting and email provider | Website and database hosting, and sending and receiving email | The data stored on the server | European Union |
6.2. Disclosures required by law
Where legally required, we may disclose data to the Spanish Tax Agency, the Social Security General Treasury, banks and financial institutions for the management of payments and collections, our tax, accounting and employment advisers, and courts, tribunals and law enforcement authorities when they so require.
7. International data transfers
Some of our providers are located in the United States, which means international transfers outside the European Economic Area take place. These transfers rely on one of the safeguards set out in Chapter V of the GDPR:
- The European Commission adequacy decision of 10 July 2023 on the EU-U.S. Data Privacy Framework, where the provider is certified under that framework.
- The Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, supplemented where appropriate by additional measures: encryption in transit, minimisation of the data transferred and limited retention periods.
You may request a copy of the safeguards applied by writing to contacto@dicra.io. Beyond these cases, no international transfers are envisaged.
8. Retention periods
| Processing | Retention period |
|---|---|
| Customer bookings and consultations | For the duration of the commercial relationship and thereafter for the statutory limitation periods: 4 years for tax matters, 5 years for personal actions and 6 years for commercial records under Spanish law. |
| Content of the spiritual consultation | Erased once the service has been delivered and the period for handling any complaint has elapsed, or earlier if you ask us to erase it. |
| Contact form | As long as needed to answer your request and, at most, 1 year from the last contact, unless a legal obligation applies. |
| Virtual assistant conversations | Held in your browser session and lost when you close it. The daily per-IP counter is cleared when the day changes. |
| Technical visit log | 21 days, automatically deleted. |
| Supplier and staff data | The periods laid down by tax, commercial and employment law. |
| Video surveillance images | 1 month maximum. |
| Cookies | As set out in the table in section 14: session or 12 months. |
Once these periods expire, data is erased or anonymised using secure destruction measures.
9. Your rights and how to exercise them
The law grants you the following rights over your personal data. Exercising them is free of charge.
Access
Find out whether we process your data and obtain a copy, together with the purpose, the recipients, the envisaged retention periods and the origin of the data if you did not provide it yourself.
Rectification
Correct inaccurate data or complete incomplete data. Tell us which data you mean and what the correction should be.
Erasure
Ask us to delete your data when it is no longer necessary, when you withdraw consent, or when you object and no other legal basis applies.
Objection
Object to the processing of your data. If you object to direct marketing, we will stop processing your data for that purpose immediately.
Restriction
Ask us to suspend processing while the accuracy of the data or the balance of our legitimate interest is verified, or to keep the data if you need it for legal claims.
Portability
Receive the data you provided in a structured, commonly used, machine-readable format, or have us transmit it to another controller where technically feasible.
Withdraw consent
Withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.
Lodge a complaint
Lodge a complaint with the supervisory authority, particularly if you feel your request has not been properly addressed.
9.1. How to exercise your rights
By email: contacto@dicra.io
By post: GLOBAL TORLA — Paseo de la Castellana, 266 — Madrid (Spain)
State which right you are exercising and enclose a copy of your national ID or passport, or identify yourself by electronic means or by a signed document, so that we can verify your identity and prevent anyone else from accessing your data.
9.2. Response times
- We will reply without undue delay and within one month at the latest from receipt of your request.
- That period may be extended by a further two months where the request is particularly complex or where we receive a large number of requests. In that case we will tell you about the extension and the reasons for it within the first month.
- If you submit your request electronically, we will reply by the same means unless you ask otherwise.
- If we do not act on your request, we will explain why, also within one month, and inform you of your right to complain to the Spanish Data Protection Agency and to seek a judicial remedy.
- We keep evidence that we have complied with our duty to answer the requests received.
9.3. Supervisory authority
- Authority
- Spanish Data Protection Agency (AEPD)
- Address
- Calle Jorge Juan, 6 — 28001 Madrid, Spain
- Website
- www.aepd.es
- Electronic office
- sedeagpd.gob.es
On the right of access to video surveillance images: to verify your identity we will ask for a recent photograph and a copy of your identity document, as well as the date and time range concerned. Direct access will not be given to images showing third parties; in that case you will receive a document confirming or denying the existence of images of you.
10. Artificial intelligence and automated decisions
The site's virtual assistant generates its replies automatically using a language model. However:
- We do not take automated decisions producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR.
- We do not build profiles — commercial, advertising or behavioural — from your conversations or your browsing.
- The assistant's answers are indicative and may contain inaccuracies. The actual consultation is always carried out by a person, the babalawo.
- The chat interface clearly tells you that you are interacting with an artificial intelligence system and not with a person.
11. Security measures and data breaches
We apply the appropriate technical and organisational measures required by Articles 5.1.f and 32 GDPR to guarantee the integrity and confidentiality of the data, including:
Organisational measures
- A duty of confidentiality and secrecy for all staff with access to personal data, which continues even after the employment or collaboration relationship ends.
- A prohibition on disclosing data to third parties, and particular care during telephone and email enquiries.
- Locking the screen when leaving the workstation, and keeping paper documents and electronic media in a secure, restricted-access place.
- Secure destruction of documents and media (CDs, USB drives, hard disks) before disposal.
- Informing and training staff on their data protection obligations.
- Periodic review of the security measures.
Technical measures
- Unambiguous identification of each user with their own username and password, and separation between administrator profiles and everyday user profiles.
- Strong passwords of at least 8 characters combining letters and numbers, never shared or written down in accessible places.
- Encryption in transit via HTTPS/TLS across the whole site, and assessment of encryption for data taken off the premises.
- Computers and devices kept up to date, with updated antivirus software and a properly configured firewall.
- Regular backups on a device other than the one used for day-to-day work, stored securely in a separate location.
- Access keys for external services are stored outside the server's public folder and are never exposed in the browser.
- The database and data folders are blocked from direct access over the internet.
Data breaches
Should a personal data breach occur, we will notify the Spanish Data Protection Agency within 72 hours of becoming aware of it, through sedeagpd.gob.es, unless the breach is unlikely to result in a risk to your rights and freedoms. Where the breach is likely to result in a high risk, we will also inform you without undue delay (Articles 33 and 34 GDPR). If you live in the United States, the applicable state breach notification laws will also apply.
12. Children
- Our services are aimed exclusively at people aged 18 or over. We do not provide consultations or ceremonies to minors.
- Under Article 7 LOPDGDD, consent-based processing of the data of children under 14 is lawful only with the consent of the holder of parental responsibility or guardianship.
- In line with the US COPPA, we do not knowingly collect personal information from children under 13. We also do not sell or share the personal information of consumers under 16 within the meaning of the CCPA/CPRA.
- If we find that we have collected a child's data without the necessary authorisation, we will delete it immediately. If you are a parent or guardian and believe this has happened, please write to contacto@dicra.io.
13. Privacy notice for United States residents
This section supplements the information above and is addressed to consumers residing in California (CCPA/CPRA) and in other states with applicable privacy legislation. In it, the terms personal information, sale and sharing have the meaning given to them by the relevant law.
13.1. Information we collect (Notice at Collection)
| CCPA category | Collected? | Examples on this site |
|---|---|---|
| A. Identifiers | Yes | Name, email, telephone or WhatsApp, IP address |
| B. Customer records information (Cal. Civ. Code §1798.80) | Yes | Name, telephone and payment transaction data |
| C. Protected classification characteristics | No | We do not ask for age, sex, origin or marital status |
| D. Commercial information | Yes | Services purchased and booking history |
| E. Biometric information | No | — |
| F. Internet or network activity | Yes | Pages visited, user agent, date and time, technical cookies |
| G. Geolocation data | Yes (approximate) | City and country derived from the IP, only when the log is enabled. We do not use precise geolocation |
| H. Sensory information (audio, video) | Only if applicable | Video surveillance images at physical premises |
| I. Professional or employment information | Staff only | Data of staff and collaborators |
| J. Education information (FERPA) | No | — |
| K. Inferences used to create a profile | No | We do not create profiles |
| L. Sensitive personal information | Yes | Religious or philosophical beliefs and, where applicable, references to health voluntarily included in the text of your consultation |
13.2. Sources, purposes and recipients
- Sources: directly from you, through the forms and the chat, and automatically from your device as you browse.
- Business purpose: delivering and invoicing the service you requested, communicating with you, keeping the site secure, preventing fraud and complying with legal obligations.
- Recipients: only the service providers listed in section 6, bound by contract and not permitted to use the information for their own purposes.
13.3. We do not sell or share your personal information
We do not sell personal information and we do not share it for cross-context behavioural advertising, nor have we done so in the preceding 12 months. We also do not sell or share the personal information of consumers under 16. This site therefore does not need a Do Not Sell or Share My Personal Information link: there is no such sale or sharing to opt out of.
We also do not use or disclose sensitive personal information for purposes other than those permitted by CCPA §1798.121 — that is, solely to provide the service you requested. Even so, you may ask us to limit its use if you prefer.
13.4. Your rights
- Right to know / access: learn the categories and specific pieces of personal information we have collected about you, their sources, the purpose and the recipients over the preceding 12 months.
- Right to delete: request deletion of the personal information we have collected, subject to the statutory exceptions.
- Right to correct: request correction of inaccurate information.
- Right to opt out of sale or sharing: not applicable, as we neither sell nor share personal information.
- Right to limit the use of sensitive information: you may request it, although we already restrict ourselves to permitted uses.
- Right to data portability: receive the information in a commonly used, machine-readable format.
- Right to non-discrimination: we will not deny you service, charge you different prices or provide a different level of quality because you exercised your rights. We do not offer financial incentives in exchange for personal information.
- Right to appeal: if we decline your request and you live in Virginia, Colorado, Connecticut, Texas, Oregon, Montana or another state that provides for it, you may ask us to review our decision by replying to our communication.
13.5. How to exercise these rights
Write to contacto@dicra.io with the subject line US Privacy Request, or by post to the address in section 1. To protect your information we will verify your identity by matching the details you give us against those already in our records; for requests for specific pieces of information we may require enhanced verification. We will respond within 45 days, extendable by a further 45 days with notice. There is no charge, except for manifestly unfounded or excessive requests.
Authorised agent: you may designate a person or entity to act on your behalf. We will ask them to provide written proof of your authorisation, and we may ask you to confirm both your identity and the authorisation directly.
13.6. Browser opt-out signals
We honour Global Privacy Control (GPC) and Do Not Track signals sent by your browser. Since we do not sell or share personal information and use no advertising or analytics cookies, there is no further processing to switch off when we receive them.
13.7. Other state notices
- California — Shine the Light (Cal. Civ. Code §1798.83): we do not disclose personal information to third parties for their own direct marketing purposes.
- Nevada (SB 220): we do not sell personal information covered by that law; you may nevertheless send us an opt-out request at the email address above.
- Commercial communications (CAN-SPAM): we only send emails relating to the service you requested. Should we ever send commercial communications, they will always include a free and effective unsubscribe mechanism.
- Retention: we keep personal information for the periods set out in section 8 and do not use it for purposes incompatible with those for which it was collected.
15. Links to third-party sites
This site may contain links to third-party pages, such as the Stripe payment gateway or AEPD resources. When you visit them you are subject to their own privacy and cookie policies, over which we have no control. We recommend reading them before providing your data. GLOBAL TORLA is not responsible for how those third parties process your information.
16. Changes to this policy
We may amend this policy to reflect legislative or case-law changes or new services on the site. The version in force is always the one published on this page, showing the date it was last updated. If the changes substantially affect how we process your data, we will tell you through a visible notice or by email where we have your address. We recommend checking this page from time to time.
17. Legal notice (Article 10 LSSI-CE)
- Site owner
- GLOBAL TORLA
- Tax ID (NIF)
- B10927689
- Registered address
- Paseo de la Castellana, 266 — Madrid (Spain)
- Contact
- contacto@caminoifa.com · +34 690 840 690
- Activity
- Provision of consultation and spiritual guidance services in the Yoruba IFÁ tradition, ceremonies, training and online sale of consultations.
Intellectual property. The contents of the site (texts, images, logos and design) belong to GLOBAL TORLA or are used with due authorisation, and are protected by intellectual and industrial property law. Reproduction, distribution or transformation without express authorisation is not permitted.
Terms of use. Access to the site is free, save for the cost of your connection. Users undertake to use it in accordance with the law and in good faith, and not to introduce unlawful or harmful content or content that could damage the systems.
Prices and payments. Consultation services are purchased online through Stripe. Prices are shown in the currency indicated for each product and include applicable taxes where relevant. You will receive a confirmation email once payment is complete.
Governing law and jurisdiction. This policy is governed by Spanish law. For any dispute, the parties submit to the courts of the consumer's domicile where consumer protection law so requires. The European Commission also provides an online dispute resolution platform.
The Spanish version of this policy is the official version. In the event of any discrepancy with this English translation, the Spanish text prevails.
18. Annex: information clause for forms
The following text must appear, in line with the AEPD documentation, on every form used to collect personal data, whether on paper or on the web:
Controller: GLOBAL TORLA — NIF: B10927689. Postal address: Paseo de la Castellana, 266, Madrid. Telephone: +34 690 840 690. Email: contacto@dicra.io
"At GLOBAL TORLA we process the information you provide us for the purpose of providing the service requested and processing billing. The data provided are retained for the duration of the commercial relationship or for the period necessary to comply with legal obligations and to attend to the possible responsibilities that may arise from compliance with the purpose for which the data were collected. Data shall not be assigned to third parties unless there is a legal obligation to do so. You have the right to obtain information as to whether at GLOBAL TORLA we are processing your personal data, and therefore you may exercise your rights of access, rectification, erasure and portability of data and limitation of or objection to processing, by contacting GLOBAL TORLA, Paseo de la Castellana, 266, Madrid, or by email to contacto@dicra.io, properly identifying yourself by electronic means or by means of a signed document. Furthermore, and especially where you consider that the exercise of your rights has not been fully satisfied, you may lodge a complaint with the national supervisory authority, contacting the Spanish Data Protection Agency, Calle Jorge Juan, 6 — 28001 Madrid."
We also request your authorisation to offer you products and services related to those you have requested and to build customer loyalty: ☐ YES ☐ NO
Questions about your data?
Write to contacto@dicra.io and we will get back to you. Exercising your rights is always free.