Privacy Policy
Last updated: August 9, 2026
1. Data controller
- Controller: Philipp Greulich, trading as Clutch
- NIF: ES-Z0204222X
- Address: Carrer d'Aragó 331 P1, 08009 Barcelona, Spain
- Email for data protection requests: phil@weareclutch.io
2. What data we process
When you book an initial call or contact us through this website, we process the data you provide, typically: name, business email address, company name, and the content of your inquiry.
3. Purposes of processing
- Handling your inquiry and scheduling a call
- Preparing and delivering the GTM sprint once a contract is in place
- Ongoing communication as part of the service
4. Legal basis
Processing is based on your consent (Art. 6(1)(a) GDPR) when you contact us, and on the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR).
5. Retention period
We retain your data for as long as necessary for the purposes described, or as required by law. As a general rule: inquiry and contact data is retained for up to 12 months if no contract results. Data related to an active service agreement is retained for the duration of the agreement and for 6 years afterward, in line with Spanish commercial record-keeping obligations (Código de Comercio, Art. 30) and applicable tax law.
6. Recipients and international transfers
We use the following third-party tools for scheduling, email communication, service delivery, and payment processing: Calendly, Google Workspace, Slack, Clay, and Stripe. Where data is processed outside the EU/EEA, this is done on the basis of Standard Contractual Clauses or an EU adequacy decision.
7. Your rights
You have the right to access, rectify, erase, restrict processing, data portability, and object (Art. 15-22 GDPR). To exercise these rights, contact us at phil@weareclutch.io.
You also have the right to lodge a complaint with the Spanish data protection authority: Agencia Española de Protección de Datos (AEPD), www.aepd.es.
8. Security
We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss, or misuse.