This website uses cookies
Read our Privacy policy and Terms of use for more information.
Version 1 · Effective date: 07.09.2026 · Last updated:07.09.2026
Prime Perspectives
The data controller for everything described in this policy is:
Luca Büürma
Operating the publication Prime Perspectives
Ronda del General Mitre 57, 08017 Barcelona, Spain
Email: [email protected]
General contact: [email protected]
Prime Perspectives is an independent publication produced by one person. There is no company behind it and no data protection officer — I am not required to appoint one under Article 37 GDPR, and I handle every request personally. That is deliberate: it means requests are answered by the person who actually controls the data.
I am established in Spain, so the Spanish Data Protection Agency (AEPD) is my lead supervisory authority. Spanish and EU law apply.
You subscribed to the newsletter. I hold your email address, the record of your signup and your confirmation, where you came from, and what you open and click — plus a first as well as last name and anything about your role or company, if you chose to give it. That rests on your consent. I keep it until you unsubscribe, and then the consent record alone for three years.
You joined as a Founding member and gave a name. That name is shown publicly on the Founding Wall. It rests on a separate consent, asked separately from the subscription. It stays up until you ask me to take it down, or until I retire the page.
You visited the website. Aggregate, non-identifying analytics — no cookies, no profile, nothing stored on your device. Legitimate interest in knowing what people read. How long it is kept is set by the platform rather than by me: see §5.
You listened to an episode. A truncated IP address and device type, held by my podcast host in order to count downloads. Legitimate interest in audience measurement. Kept under my host's policy: see §5.
You emailed me. The email, and whatever is in it. Legitimate interest in being able to reply to you. Kept for 24 months from the last message in the thread.
You appeared as a guest. Your name, role, company, contact details, and the recording itself. That rests on the release you signed, together with freedom of expression and information. It stays while the episode is published.
Everything below is the detailed version. If you only want one thing from this page: unsubscribe from any email using the link at the bottom of it, or write to [email protected] and I will delete you.
The standard signup form asks for one thing: your email address. Nothing else is required.
When you subscribe, my email platform (beehiiv — see §7.1) records automatically:
Your email address
The date and time you submitted the form, and the date and time you confirmed it
The page or link you subscribed from, including any campaign tracking parameters in the URL (see §3.6)
The IP addresses used at those two moments, retained as evidence that the subscription was genuine
Double opt-in. Submitting the form does not subscribe you. It sends you one confirmation email, and nothing further is sent until you click the link inside it — no newsletter, no welcome email, nothing. If you never confirm, the pending record is deleted after 30 days. Your consent is evidenced by that confirmation click together with the timestamps and addresses above. If you were subscribed without your knowledge, tell me and I will delete the record and show you what it says.
Founding members and the Founding Wall. The Founding member signup page works the same way, with one addition. Once you have submitted your email address, you are asked — on a separate step, and optionally — for a name, so that it can be shown on the Founding Wall, a public page listing early members.
Giving a name is optional. Leave it blank and you are a Founding member on identical terms. Nothing is withheld from you.
A first name is enough. A surname is yours to add or not.
If you give one, you are consenting to it being displayed publicly on that page. That consent is asked separately from the newsletter subscription and can be withdrawn on its own.
Your name only goes up once your subscription is confirmed. If you give a name but never confirm, nothing is published and the pending record is deleted after 30 days.
Write to [email protected] and I will take your name off the Wall. You stay subscribed.
The Wall is something I maintain, not something you are owed. I may change how it looks or retire the page altogether. If that happens your name comes down with it, and nothing else about your subscription changes.
Nothing else about you appears there. No email address, no company, no job title.
Outside that page and the occasional survey described below, I do not ask for names.
After you subscribe, you may be asked — in the welcome email, in an occasional one-tap poll, or in a periodic survey — for:
Your first name
Your seniority, described as what you own rather than by job title
Your function or department
The size of your company
What kind of business you work in
What you are working on right now, in your own words
Answering is entirely optional and always will be. Nothing is withheld from you if you skip it, and most subscribers never answer. I use these answers to decide what to write and, later, to describe the audience honestly to potential sponsors — always in aggregate, never by naming you.
If you reply to an email, I read it. Where a reply tells me something about your role or your work, I may note it against your subscriber record so that I do not ask you the same question twice. Only professional detail is recorded this way — nothing personal, nothing sensitive. Ask me and I will delete it.
My email platform records whether an email was opened and which links were clicked. Open tracking works through a small invisible image loaded from a server when the email is displayed; this reveals that the email was opened, roughly when, and general device information.
I use this for three things: to know which subjects are worth writing about, to stop sending to people who clearly are not reading (see §5), and to report aggregate engagement to sponsors once sponsorship exists.
What you can do about it. One of these is in your hands, and one is in mine.
Open tracking you can stop yourself. Most email clients let you block remote images, which prevents it entirely; Apple Mail Privacy Protection already does this by default. It needs nothing from me and I never know you have done it.
Click tracking is harder, and I would rather be straight with you about why. My email platform applies it to the links themselves, and it offers me exactly two options for any subscriber: keep the record, engagement history included, or delete the record completely. There is no setting that turns tracking off for one person, and no way for me to erase the engagement history while keeping you subscribed. Promising you a switch that does not exist would be worse than telling you it does not.
So what I can offer is a choice between two real things. If you object under §9.6 and want to stay subscribed, I will stop using your engagement data to make any decision about you: you will not be segmented by it, you will not be sent anything because of it, and you will not be removed by the inactivity rule in §5. The platform keeps recording; I stop acting on it. If you would rather the data were gone, I will delete your record in full — which also ends the subscription, because complete deletion is the only erasure my platform offers. I will do it the day you ask.
Either way, write to [email protected] and say which you want.
The website at primeperspectives.io is a plain publication: episode pages, a newsletter signup page, and text pages. There are no accounts, no logins and no comment sections.
Analytics. I use the analytics built into the website platform itself (Framer — §7.3) and nothing else. There is no separate analytics company, no Google Analytics, and no third-party measurement tag anywhere on the site. It sets no cookies, stores nothing on your device and creates no persistent identifier: a visit is counted from a one-way hash of your IP address and browser combined with a secret value that is regenerated and destroyed every 24 hours, so today's visit cannot be linked to yesterday's. What it records is page URL, referrer, browser, operating system, device type and country or region — aggregated, never attached to an individual. No consent banner is required for it. It is disclosed here anyway, because you are entitled to know what runs on a page you visit.
The newsletter signup pages are hosted by beehiiv and measured by beehiiv, described in §7.1.
Server logs. My website host keeps standard technical logs (IP address, timestamp, requested resource) for security and abuse prevention. I do not use them analytically, and I do not control how long the host keeps them — see §5, which says so plainly rather than quoting a number I cannot guarantee.
Embedded players. Episode pages embed a YouTube video player and may embed a Spotify player. These are described in §6.
Downloads. Episode playbooks and Blueprint graphics are offered as direct downloads. Downloading one does not require an email address and does not create a record about you.
If a resource is ever placed behind an email address, the page will say so before you enter it, and it will make clear which of two things is happening: either the file is sent to you and joining the newsletter is a separate box you are free to leave unticked, or the file is what you receive for subscribing and the page says exactly that. Either way, an address given this route is handled under §3.1, double opt-in included.
When you play or download an episode, the audio file is served by my podcast host (§7.2). The host records the request in order to deliver the file and to count downloads: a truncated IP address (the final portion is removed, so it cannot identify you), user agent, timestamp and approximate country.
I never see an untruncated IP address for a listener, and I cannot identify any individual listener. What I see is a download count by episode, day and country.
If you listen on Spotify, Apple Podcasts or YouTube, those companies collect their own data about you under their own privacy policies, as independent controllers. See §6.
Links I publish on LinkedIn, YouTube, in show notes and in guest kits carry campaign parameters (utm_source, utm_medium, utm_campaign). If you subscribe after clicking one, those parameters are stored on your subscriber record.
This tells me which channels bring readers. It also serves a second purpose: together with the signup and confirmation timestamps, it is the evidence that your subscription was genuine if that is ever questioned.
Messages to hello@, guests@, partners@ or [email protected] all forward into a single mailbox (§7.5). hello@ is also the reply-to address on the newsletter, so replying to an issue arrives in the same place. I keep this correspondence so I can reply, maintain continuity in a conversation, and keep a record of agreements. Legal basis: legitimate interest in running a correspondence, or steps taken at your request before entering a contract.
Writing to me does not subscribe you to the newsletter. I will never add you to a list because you emailed me.
For every guest I hold: name, job title, employer, professional contact details, photograph, the audio and video recording of the conversation, the signed release agreement, the electronic signature metadata that proves it was signed (IP address, timestamp, transaction identifier), and the correspondence around it.
The legal position, stated precisely because it matters:
Making and using the recording rests on the contract between us — the signed guest release (Article 6(1)(b) GDPR).
Publishing the episode and keeping it published rests on my legitimate interest in publishing editorial content (Article 6(1)(f) GDPR), exercised as part of the right to freely communicate and receive truthful information protected by Article 20 of the Spanish Constitution. Where erasure of published editorial content is requested, Article 17(3)(a) GDPR applies directly: the right to erasure does not extend to processing necessary for exercising the right of freedom of expression and information.
Consent is deliberately not the basis for publication. Consent can be withdrawn at any moment, and a published episode that could vanish from the archive years later would be no archive at all. Guests are told this in plain language before they sign, and the release says the permission is perpetual and irrevocable. Guests retain every other GDPR right, including access, correction and objection, and I take a well-founded objection seriously — but the right to erasure does not automatically override published editorial content.
Third parties named or discussed in an episode (a colleague, a competitor, a former employer) are covered by the same editorial basis.
Before I approach someone, I record professional information from public sources — LinkedIn profile, company website, interviews, conference listings — in a research file. This is business contact information about someone in a professional role, held on the basis of legitimate interest in editorial research and business development.
If you are in that file and would rather not be, email [email protected] and I will delete it. No explanation needed.
Special category data: health, political opinions, religion, trade union membership, sexual orientation, biometric or genetic data.
Data about anyone I know to be under 16.
Payment card details (see §7.6 when payments become active — those go directly to the payment processor and never reach me).
Data bought, scraped or harvested from anywhere. I do not import contacts. Being a LinkedIn connection, a conference attendee, a guest's colleague or someone who once emailed me does not put you on any list.
Sending you the newsletter. Consent, 6(1)(a). Confirmed by double opt-in. Withdraw with one click in any email.
Storing your email and consent record. Consent, then legal claims, 6(1)(a) → 6(1)(f). The consent record outlives the subscription (§5).
Open and click tracking in emails. Consent, 6(1)(a) — given when you subscribe, having been told here. My platform cannot switch this off for one person. §3.3 sets out exactly what I can and cannot do if you object.
Optional profile fields you volunteer. Consent, 6(1)(a). Answering is optional.
Showing your name on the Founding Wall. Consent, 6(1)(a). Asked separately from the subscription and withdrawable on its own (§3.1).
Noting professional detail from your replies. Legitimate interest, 6(1)(f). Continuity of correspondence; deleted on request (§3.2).
Website analytics. Legitimate interest, 6(1)(f). Aggregate and non-identifying; balancing test favours processing because the intrusion is close to nil.
Server and security logs. Legitimate interest, 6(1)(f). Security and abuse prevention.
Podcast download measurement. Legitimate interest, 6(1)(f). Truncated IP; no individual is identifiable.
Replying to your email. Legitimate interest / pre-contractual steps, 6(1)(f) / 6(1)(b).
Recording a guest. Contract, 6(1)(b). The signed release.
Publishing and archiving an episode. Legitimate interest, 6(1)(f), exercised as freedom of expression and information. Erasure limited by Art. 17(3)(a) GDPR. See §3.8.
Editorial and sponsor research. Legitimate interest, 6(1)(f). Professional data only.
Accounting and tax records. Legal obligation, 6(1)(c). Not active. Begins with the first paid transaction.
Fulfilling a paid order. Contract, 6(1)(b). Not active. Begins with the first paid product
Where a row above relies on legitimate interest, I have carried out and written down the balancing test that Article 6(1)(f) requires. You may ask me for the assessment behind any of those rows and I will send it to you.
Unconfirmed signup, where the double opt-in was never completed - 30 days, then deleted.
An unconfirmed address is not a subscriber, and there is no reason to keep it.
Active subscriber record - Until you unsubscribe or I remove you.
Consent record after unsubscribe (email hash, timestamps, source) - 3 years.
Matches the limitation period for data protection infringements under Article 78 of Organic Law 3/2018, so I can prove your subscription was lawful if challenged.
Subscribers with no opens or clicks in 180 days - Re-engagement email, then removal. Anyone who has objected under §3.3 is exempt from this.
List hygiene and deliverability.
Optional profile fields - With the subscriber record.
A name shown on the Founding Wall - Until you ask for it to be taken down, or until I retire the page.
Either of us can end it: you by asking, me by discontinuing the Wall (§3.1).
Email correspondence - 24 months from the last message in the thread.
Longer where it forms part of an agreement.
Guest recordings, raw and edited - While the episode is published, plus the production archive.
Signed guest releases and their signature metadata - For as long as the episode is published, and in any event for the limitation periods applicable to any claim arising from the agreement.
The release is the evidence of the rights granted and the consent given. Article 1964 of the Spanish Civil Code sets 5 years for contractual actions.
Guest administrative data not needed for the above - 5 years from the recording date.
Unless a longer statutory retention applies.
Editorial research files - Until the research is stale or you ask for deletion.
Website server logs - Per my website host's policy (§7.3).
These are the host's technical logs. I do not set the period and will not quote one I cannot guarantee.
Website and landing-page analytics - Per the policy of the platform that produces it (§7.3, §7.1). The figures I work from are aggregate, and I keep those while they are useful for comparison.
Aggregate statistics are not personal data.
Podcast download logs - Per my host's policy (§7.2); aggregate statistics kept indefinitely.
Aggregate statistics are not personal data.
Payment and invoice records - 4 years minimum, 6 years for accounting books. Not active yet.
Article 66 General Tax Law; Article 30 Commercial Code.
When a period ends, data is deleted or irreversibly aggregated.
Prime Perspectives is distributed on Spotify, Apple Podcasts, YouTube and other podcast directories that pick up the public RSS feed.
These platforms are independent data controllers, not my processors. When you use them, they collect data about you under their own terms and for their own purposes — account data, listening history, device identifiers, advertising profiles. I have no contract governing that processing, no access to their raw data, no ability to delete it, and no responsibility for it.
Spotify - Spotify AB, Sweden
https://www.spotify.com/legal/privacy-policy/
Apple Podcasts - Apple Inc. / Apple Distribution International Ltd., Ireland
https://www.apple.com/legal/privacy/
YouTube - Google Ireland Ltd. / Google LLC
https://policies.google.com/privacy
Episodes shared privately with subscribers. Some episodes are never published on the public feed — the Founding member exclusive is one of them. Where that happens, the episode is shared with subscribers as an unlisted YouTube link. Opening that link takes you to YouTube, where Google processes your data as an independent controller under its own privacy policy, exactly as it would for any other video there. The link itself is tracked as a click in my email platform (§3.3) but nothing about what you then watch comes back to me beyond the aggregate figures below.
Unlisted means the video is not indexed, searchable or listed on the channel. It does not mean it is private: anyone holding the link can open it. Treat it as yours rather than as something to forward.
What I receive from them is aggregate, anonymised creator analytics: play counts, average completion, subscriber counts, country breakdowns, age and gender bands. I cannot identify an individual listener from any of it, and I make no attempt to.
Embedded players on my website. YouTube embeds on episode pages use YouTube's privacy-enhanced mode (youtube-nocookie.com), which prevents YouTube from setting tracking cookies until you actually press play. Any Spotify embed is loaded behind a click-to-load placeholder, so nothing is requested from Spotify's servers until you choose to activate it. Pressing play on an embedded player connects you to that platform and its data collection begins at that point. The Cookie & Tracking Notice sets this out in full.
Each of these acts on my instructions under a data processing agreement meeting Article 28 GDPR.
beehiiv Inc., 228 Park Avenue S. #29976, New York, NY 10003, United States. Stores the subscriber list, sends every email, records engagement, and hosts newsletter.primeperspectives.io, the public archive, the Founding member signup page and the Founding Wall. The measurement on those pages is beehiiv's own.
Transfers: to the United States, under the EU Standard Contractual Clauses (Module 2) incorporated in beehiiv's Data Processing Addendum, supplemented where applicable by the EU–US Data Privacy Framework.
Their sub-processors: https://subprocessors.beehiiv.com
Their privacy policy: https://www.beehiiv.com/privacy
Podigee GmbH, Revaler Straße 28, 10245 Berlin, Germany. Infrastructure provided by Hetzner Online GmbH, Germany. Stores and serves the audio files, generates the RSS feed, counts downloads. Truncates IP addresses before storage.
Transfers: none outside the EU.
Their privacy policy: https://www.podigee.com/en/about/privacy/
Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, Netherlands. Hosting on Amazon Web Services. Builds and serves primeperspectives.io, keeps the technical server logs described in §3.4, and provides the built-in analytics described there. That analytics sets no cookies and creates no persistent identifier: it hashes IP address and browser against a secret value that is regenerated and deleted every 24 hours.
Transfers: governed by the Standard Contractual Clauses in Framer's DPA, with the EU–US Data Privacy Framework applying to certified recipients.
Their sub-processors: https://trust.framer.com
There is no dedicated analytics company involved in this publication. Website measurement comes from Framer's built-in, cookieless analytics (§7.3); newsletter and signup-page measurement comes from beehiiv (§7.1). There is no Google Analytics, no Meta or LinkedIn pixel, no heatmap or session-recording tool, and no third-party measurement tag of any kind on the website. If that ever changes, the provider is named in this section and the Cookie & Tracking Notice is updated before anything goes live.
IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany, hosts the@primeperspectives.io mailboxes. The hello@,guests@,partners@ and privacy@ addresses all forward into one IONOS mailbox, which is where every message described in §3.7 arrives.
Transfers: none outside the EU.
Google Ireland Ltd. (Gmail and Google Calendar) for a separate general-purpose account and for scheduling. Correspondence sent to the domain addresses above does not pass through it.
Transfers: under Google's Standard Contractual Clauses and the EU–US Data Privacy Framework.
Not active. This begins with the first paid product or subscription.Stripe Payments Europe Ltd., Ireland, via beehiiv or a storefront. Card details are entered directly with Stripe and never reach me. I receive the transaction record, name, email and country only.
Riverside.fm for remote recording, transcription and editing, and occasionally Zoom, Google Meet or Microsoft Teams where a guest's setup requires it. (Riverside.fm Ltd. is established in Israel, a country covered by a European Commission adequacy decision, so no additional transfer safeguard is required. The others operate under Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.)
Dropbox International Unlimited Company, Ireland, for delivering episode material to my freelance editor and receiving it back, under Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
An electronic signature platform (Adobe Sign, DocuSign or equivalent) for executing guest release agreements. This records the signature metadata described in §3.8.
A freelance editor, engaged under a written confidentiality and data processing agreement, receives episode material for post-production and returns or deletes it on delivery. The editing itself is done in DaVinci Resolve on his own equipment; the footage is not uploaded to the software maker and no further company sees it. These process guest recordings only. No listener or subscriber data passes through any of them.
There are no other processors. I do not use advertising networks, data brokers, retargeting pixels, session recording, heatmapping, or social media tracking pixels of any kind. I have never sold personal data and will not.
I will disclose data where I am legally obliged to — a court order, a binding request from a Spanish authority, or the establishment or defence of a legal claim. Nothing else.
Four of my processors are based in the United States or transfer data there: beehiiv, Google, Dropbox, and Framer's hosting. Those transfers rely on the Standard Contractual Clauses, supported where applicable by the EU–US Data Privacy Framework adequacy decision. My mailboxes and my podcast host sit entirely within the European Union.
Where this stands. The Data Privacy Framework is valid law today. It survived its first challenge in the EU General Court in September 2025, and that ruling is under appeal to the Court of Justice. Two of the framework's predecessors were struck down by that same court. I therefore rely on the Standard Contractual Clauses as the primary mechanism rather than on adequacy alone, and I keep the option of moving to EU-hosted alternatives open. If the framework falls, this policy will be updated and you will be told.
For the data I hold on a subscriber, the practical exposure is small: an email address, a subscription date, and a record of which newsletters were opened.
Under Articles 15–22 GDPR you have the right to:
9.1 Access — a copy of the data I hold about you and an explanation of what I do with it.
9.2 Rectification — correction of anything inaccurate or incomplete.
9.3 Erasure — deletion of your data. For subscribers this is immediate and unconditional, and it removes the whole record including the engagement history. For published editorial content, this right is balanced against freedom of expression and information (§3.8), and I will explain my reasoning in writing if I decline.
9.4 Restriction — a pause on processing while a dispute about accuracy or legitimate interest is resolved.
9.5 Portability — your data in a structured, machine-readable format, for anything based on consent or contract.
9.6 Objection — to any processing based on legitimate interest, including editorial research and email tracking. Where you object to direct marketing, I must stop, with no balancing exercise. For email tracking specifically, §3.3 sets out what my platform makes possible and what it does not.
9.7 Withdraw consent — at any time, without affecting the lawfulness of what came before. One click in any email footer, and separately for the Founding Wall (§3.1).
9.8 Freedom from automated decision-making — I make no automated decisions with legal or similarly significant effects. Segmenting a list to decide which article to send is not that.
How to exercise them: email [email protected]. No form, no template and no account is required. Say what you want in your own words.
I will respond within one month, extendable by two further months for genuinely complex requests, in which case I will tell you within the first month and explain why. It is free. If a request is manifestly unfounded or repetitive I may charge a reasonable fee or refuse, and I will explain which and why.
I may ask you to confirm the request from the email address concerned. That is identity verification, not obstruction.
If you think I have handled your data badly, write to [email protected]. Most things turn out to be a misunderstanding and are settled in a single reply, and I would rather resolve it with you directly than have you left with a bad experience of this publication.
You are also entitled to go to a supervisory authority at any time, without contacting me first. That right is yours regardless of anything written on this page:
Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan 6, 28001 Madrid, Spain · +34 901 100 099 · https://www.aepd.es
You may also complain to the supervisory authority of the EU or EEA country where you live or work, or where the issue occurred.
All sites and emails are served over TLS.
Every platform account uses a unique password from a password manager, with two-factor authentication enabled everywhere it is offered.
Guest recordings are stored in encrypted cloud storage, and shared with the freelance editor working on that episode through a private link under a written confidentiality obligation. Access is limited to the two of us.
No subscriber data is stored on a personal device.
I collect as little as possible. Data that was never collected cannot be exposed.
If a breach occurs that is likely to result in a risk to your rights, I will notify the AEPD within 72 hours of becoming aware of it, and I will notify you directly and without undue delay where the risk is high. I will tell you what happened, what data was affected, and what I am doing about it.
Prime Perspectives is made for working professionals and is not directed at children. I do not knowingly collect data about anyone under 16.
(Spanish law sets the age at which a child can validly consent to data processing at 14 — Article 7 of Organic Law 3/2018. This publication applies a higher bar because it is aimed at people running businesses.)
If you believe a child's data has reached me, write to [email protected] and I will delete it.
These are disclosed now so that nothing arrives as a surprise later. None of them is active, and no data is being processed for any of them. Each will be activated by an update to this policy, a new version number, and — where the change is material — advance notice by email before it takes effect.
If a paid subscription, digital product, course, community platform or ticketed event is ever offered, the data involved is what those things require and nothing more: payment handled by Stripe (§7.6), an order or enrolment record, access rights, and for an event any dietary or accessibility requirement you choose to give me. The legal bases are contract, plus legal obligation for the tax and accounting records that follow a transaction. A community platform would additionally involve a profile and whatever you choose to post, which other members can see — that being the point of a community, and it would be explained at the point of joining.
A sponsor receives aggregate audience statistics only — list size, engagement rates, and the distribution of role, company size and function across subscribers who volunteered them. A sponsor never receives your email address or any data identifying you, and I will not run a sponsorship arrangement that requires it. Click data on a sponsor link is reported to the sponsor as a number, not as a list of people. Sponsored content is always labelled — see the Advertising & Sponsorship Disclosure.
Where I earn a commission, the destination site may record that the visit came from me. That site's privacy policy governs from the moment you click. Affiliate links are always labelled as such.
Material changes are announced by email before they take effect. Minor corrections take effect on publication. The version number and date at the top of this page always tell you which version you are reading.