1. Controller and scope
Opportunity Relay is the trading name used on this website by Ricardo Crespillo Romero, based in Madrid, Spain. Ricardo is the controller for information collected through this website. Questions can be sent to ricardo2.crespilloromero@gmail.com.
This policy covers the public website and its project-inquiry flow. Third-party websites linked from this site have their own policies.
2. Information collected
The free review asks for a public website or business profile, the main priority, and the best email to reach you; optional context may be added. A longer project inquiry may also include your name, company, project type, desired timeline, project brief, page path, a random submission identifier, the policy version shown, and limited security metadata needed to prevent abuse.
If you allow optional measurement, the inquiry may also include a bounded first-touch source, medium, campaign, referral category, and landing path. Do not submit credentials, payment information, regulated data, client-confidential documents, or unnecessary sensitive personal information.
3. Why information is used
Information is used to assess project fit, respond to your request, prepare a requested scope or proposal, protect the service, prevent spam, troubleshoot delivery, meet legal obligations, and establish or defend legal claims.
Depending on the request, processing may be necessary to take steps before a contract, support the legitimate interest in answering genuine business inquiries and operating a secure service, meet a legal obligation, or—only for optional measurement—rely on your consent. The form acknowledgement is not marketing consent, and inquiry submitters are not automatically added to a marketing list.
4. Inquiry delivery and storage
The form sends your information to a same-origin Opportunity Relay API. The interface confirms receipt only after the API accepts the record. A random identifier helps prevent an accidental duplicate record.
Inquiry contents are not intentionally sent to Google Analytics, an AI model, application analytics, or application logs. If transactional email is configured, the API may notify the website operator and send a confirmation to the email address supplied. Email delivery is secondary to storage.
If the API cannot confirm receipt, the form keeps your entries in the browser and offers a direct email option. Choosing that option involves your email provider and the recipient's email provider.
Bilingual Voice Intake: public tour and Operations
The optional Bilingual Voice Intake requests microphone permission only after you activate its recording control. A recording is limited in the page to 15 seconds and 3 MB, sent through a same-origin endpoint to the configured transcription provider, and shown as an editable transcript before the corrected text can reach the Source-Backed Answer Desk. Guided and typed paths do not require microphone or transcription-provider access.
In the public tour, application code holds recording chunks in page-scoped state and intentionally writes neither raw audio nor transcript text to application storage or the database. Application request logs omit audio and transcript content; the Answer Desk trace uses a one-way question fingerprint. Optional spoken output requires a separate action and a one-use, 120-second in-memory permission bound to the exact visible approved answer.
In that tour, reset, replacement, and page close clear the application's audio references and temporary voice state as far as the browser allows. This does not establish deletion from browser or operating-system internals, network infrastructure, hosting systems, or transcription and speech providers; their retention has not been verified end to end. Do not use the tour for confidential, credential, child, health, legal, financial, or other regulated information.
When an authenticated Operations workspace is activated under a customer agreement, raw-audio retention remains fixed at zero and only the corrected transcript needed for the governed answer workflow is retained, encrypted and scoped to that workspace. Role-based access, authenticated audit records, configured retention and deletion, encrypted backup and restore, and owner-approved provider policies apply. The applicable agreement and data-processing terms define the controller/processor roles and customer-specific retention.
5. Optional measurement
Optional measurement is off until you choose to allow it. The site stores that choice locally. For the current tab, it may retain a bounded first landing path, referral category, and campaign values; it does not store a full referring URL, search term, name, email, form brief, or other inquiry content for analytics.
Google Analytics is not currently active. No Google Analytics script or analytics cookie is loaded by this website.
6. Providers and international processing
Service providers may support hosting, email, scheduling, analytics, security, or delivery and receive only the information reasonably needed for their role. Some providers may process information in the United States or other countries. Appropriate legal and contractual safeguards are used where required. Information may also be disclosed when required by law or necessary to protect rights and safety.
Opportunity Relay does not sell personal information and does not use inquiry information for advertising.
7. Retention and security
Unconverted inquiries are ordinarily kept in the active inquiry system for no longer than 90 days. If an inquiry becomes a client relationship, relevant records follow the applicable contract, accounting, and legal retention requirements. Backup copies expire through the applicable backup cycle.
Authenticated Operations records follow the retention configured for the applicable workspace and customer agreement. Their protected stores use encryption at rest, role-bound access, integrity verification, authenticated deletion records, encrypted off-site backups, and restore checks; expiry removes the associated encrypted payloads through the governed purge process.
Proportionate administrative and technical safeguards, restricted access, and separate service credentials are used. No transmission or storage system can be guaranteed completely secure.
8. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection, or portability, and may withdraw optional measurement consent without affecting earlier lawful processing. Legal exceptions may apply, and proportionate information may be needed to verify identity.
Use the privacy-rights request link. You may also complain to the competent supervisory authority. In Spain, this is the Spanish Data Protection Agency (AEPD).
9. Changes and contact
This policy may change as the website, inquiry system, or services evolve. The revision date above identifies the current version. Contact ricardo2.crespilloromero@gmail.com for general questions.