Privacy policy
Effective 2 October 2026
This policy explains how LMC Flow handles information when you visit lmcflow.com, contact us by email or authorise access to data used by LMC Flow Analytics.
Who is responsible
LMC Flow is operated by NJ LIFESTYLE & MANAGEMENT SL. The company determines how and why personal data from this website and our correspondence is used, and is the data controller. You can contact us about privacy at info@lmcflow.com.
For data from client websites, we act on the client's instructions. The client decides the purposes of processing and is the data controller. The owners of client websites are responsible for explaining the collection of data on their websites.
Visiting this website
We do not use cookies, analytics scripts or contact forms on this website.
The site is hosted on GitHub Pages. GitHub logs visitors' IP addresses for security, including visits by people who are not signed in to GitHub. Its privacy statement describes its handling of technical data.
The site loads fonts from Google Fonts. Your browser connects to Google's servers to retrieve them, which sends Google your IP address and the technical details of the request. We rely on our legitimate interest in displaying the site's typography consistently. See Google's privacy policy.
When you email us
We receive your email address, your message and any name, contact details or attachments you choose to include. We use these to answer you and continue the conversation. Providing them is voluntary, but we need enough information to respond to your request.
For enquiries about working together, processing is necessary to take steps you request before entering into a contract, or to perform an existing contract. For other correspondence, we rely on our legitimate interest in responding to people who contact the agency. Records that we are legally required to retain are kept to meet those obligations.
Our email is provided through Microsoft 365 Exchange Online. Our mailbox data is stored in Spain, within the EU.
Data used by LMC Flow Analytics
The agency team uses the application to understand website performance, investigate search visibility and prepare reports for the relevant brand or client. Access is limited to properties for which the agency has permission.
- Google Analytics 4: aggregate reports and property settings. Reports cover measures such as visits, traffic sources and page performance. We do not export individual-user records. We may change property settings at the property owner's direction.
- Google Search Console: search queries, pages, country-level results and URL indexing information. We also submit sitemaps for connected properties.
- PageSpeed Insights: performance checks on publicly accessible pages.
Google Ads access is planned but is not currently active. The planned use is read-only research into historical keyword demand.
This data supports the analytics work agreed with the property owner. A client report contains that client's data; it does not include another client's results.
Who processes analytics data
The agency team can access the working data and reports. We work in a team with artificial intelligence. We share working context, including aggregate Google results, search queries and page addresses, with Anthropic and OpenAI to analyse results and prepare or review reports. These providers process that context under their own service terms.
We do not sell Google user data or transfer it to data brokers or advertising platforms. We do not use it for ad targeting, credit scoring or lending decisions.
Where data is processed
Our working analytics files are stored on an agency work computer. Raw responses from the data collector are kept in restricted storage, separately from code repositories. One-off analyses are stored with the relevant work, and reports with the relevant brand's records. The use of Anthropic and OpenAI services also involves processing within those providers' systems.
GitHub and Google may process data outside the European Economic Area, including in the United States. Their published transfer safeguards include the EU–US Data Privacy Framework where applicable and European Commission standard contractual clauses. Details are available in GitHub's privacy statement and Google's data transfer information.
How long information is kept
We keep correspondence while the conversation is active and for any further period required by law. Once those purposes have ended, we delete it.
Raw responses from the analytics data collector have a configured retention period of 400 days. Deletion is carried out manually. There is no automatic deletion schedule.
We retain reports while they are needed for the agreed work or to check its results. We delete them when those purposes have ended, unless a legal obligation requires us to keep them longer.
At each quarterly review, we delete working files from one-off analyses whose related work has been closed for more than 90 days. We keep them longer if an unresolved dispute or request requires them, or if retention is required by law. Summary figures remain in our long-term work records after the underlying files are deleted.
GitHub and Google retain the technical data they receive under their respective privacy policies. Revoking access to a connected property stops future access through that permission; it does not itself delete reports or other copies already held by the agency.
Your rights and choices
You can ask to access or correct your personal data, request its deletion, restrict its use or object to processing. You may also have a right to receive a portable copy. These rights apply under the conditions set by data protection law. Where processing relies on consent, you may withdraw it without affecting the lawfulness of earlier processing.
Write to info@lmcflow.com with your request. You can also complain to the Spanish Data Protection Agency (AEPD) or the supervisory authority where you live or work.
Property owners can remove the agency's access in their Google service settings. Contact us if you also want us to review or delete data already retained for the work.
Changes to this policy
We will update this page when our practices change. If we intend to use connected Google data for a new purpose, we will explain that change and obtain any required authorisation before doing so.