← Back to CTO Manager

Privacy and data protection

CTO Manager is a personal project. This page follows data minimisation: it only collects what is necessary to handle a request and does not use telemetry, analytics or advertising.

Controller

Óscar de la Cuesta, acting as a private individual and author of CTO Manager. Privacy questions can be sent through the form on this page.

Data processed

To download CTO Manager: email address and, only if you choose to provide them, a name or alias and notes for the author. Notes are completely optional. To prevent form abuse, a hash of the IP address is used temporarily for about 15 minutes. The hosting provider may keep its own technical security logs according to its configuration.

Purpose

Only to manage your request, enable the immediate CTO Manager download and receive any optional notes you choose to send to the author. The number of copies is counted with an anonymous counter containing no name, email, notes or IP.

Legal basis

Your consent when submitting the form. You may withdraw it at any time without affecting processing already carried out.

Recipients

Data is not sold or shared for commercial purposes. Hosting and email providers may process it only to provide those services. Analytics, advertising and third-party captchas are not enabled by default.

Retention

The notification email received by the author may contain your email address, optional name/alias and optional notes. It is kept only as long as necessary and, as a general rule, no longer than 90 days after the download or last contact. It is then deleted. The anonymous copy counter may be retained indefinitely because it does not identify people.

Your rights

You may request access, rectification, erasure, restriction, objection or withdrawal of consent. You may also complain to the Spanish Data Protection Agency. Use the privacy form at the end of this page.

Cookies and tracking

This page uses no analytics or advertising cookies and no persistent local storage to remember your behaviour. Language is detected on each visit. The form uses a signed token without creating a user session.

Security

The destination email, form configuration and signing keys remain in private server files and are not included in HTML or JavaScript. Requests are not stored in a nominative log. The installer is delivered through a short-lived signed link and direct HTTP access to the file is blocked.

Exercise a privacy right

Last updated: 30 August 2026 · AEPD