Privacy Policy
Last updated: July 13, 2026
1. Data controller
IANOVA — Karin Andrea Jorquera Montecinos, based in Valencia (Spain). Tax ID (NIF): Z2643977V. Contact: hola@ianova.tech.
2. Scope of this policy
This policy covers the personal data of creators who engage 3LIT3 and of visitors to 3lit3.io, for whom IANOVA acts as Data Controller.
The data of each creator's own students is governed by that creator's own privacy policy, with IANOVA acting as Data Processor on that creator's behalf.
3. Data processed and purposes
- Managing the creator's account — legal basis: performance of a contract.
- Billing and tax compliance — legal basis: legal obligation and contract.
- Support and customer service — legal basis: performance of a contract and legitimate interest.
- Our own marketing communications — legal basis: consent or legitimate interest, with a right to object.
4. Retention periods
Data is retained for the duration of the contractual relationship and, once it ends, for the applicable legal periods (commercial, tax, and statute-of-limitations).
5. Data processors
To provide the service we rely on technology providers, each with its own confidentiality and security commitments:
- Supabase (database and authentication infrastructure — EU, Ireland).
- Lovable / Google Cloud (hosting and edge).
- Cloudflare (CDN and security).
- Apple and Google (push notification delivery).
- Stripe and KunfuPay (payment processing).
- Zoho (email and management suite).
6. International transfers
When a provider involves a transfer outside the European Economic Area, that transfer is covered by the EU-US Data Privacy Framework or by Standard Contractual Clauses approved by the European Commission, applying additional safeguards where appropriate.
7. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction, portability and withdrawal of consent by writing to hola@ianova.tech.
You also have the right to file a complaint with the Spanish Data Protection Agency (www.aepd.es).
8. Security
We apply appropriate technical and organizational measures, including encryption in transit, per-user access control, and isolation between accounts.
9. Changes to this policy
We'll publish the current version on this same page, noting its update date.
