Privacy Policy
Last updated: 22 July 2026.
This policy explains how personal data is handled on this website, on the public demo, and in the Dispatch service. The data controller for this website and for prospective-customer data is Liam Cordrey (NIF Y7966498W, Andasol Business Center, Avenida Andasol, 29604 Marbella, Málaga, Spain, [email protected]). For personal data inside a customer's Dispatch instance, the customer is the controller and we act as processor under the Data Processing Agreement.
Visitors to this website
This site sets no cookies and uses no analytics or tracking. It is served through Cloudflare, whose edge infrastructure processes IP addresses transiently for security and delivery (see the subprocessor list).
Early-access requests (the contact form)
If you submit the form we process your name, email address, and optionally your company, to respond to your enquiry about Dispatch and to contact you about early access.
- Legal basis: taking steps at your request prior to entering into a contract (GDPR art. 6(1)(b)), and our legitimate interest in responding to business enquiries (art. 6(1)(f)).
- What happens to it: the submission is stored on our EU server and generates a private notification to the operator. It is not added to any marketing list and is never sold or shared for marketing.
- Retention: until your enquiry is resolved and, at most, 24 months from last contact, unless you become a customer.
The public demo
The demo at demo.dispatch.cordrey.co contains only fictional sample data. Its entry form processes the same categories as the contact form, on the same bases, and sets one functional cookie (see the Cookie Notice). Nothing you view in the demo is tracked beyond standard server logs.
Customers' portals (we act as processor)
Inside a customer's Dispatch instance we process, on the customer's documented instructions: authorised users' business contact data and login identifiers, editorial actions (attributed by email for audit), the customer's content and knowledge base, and any leads collected on the customer's own sites. Details — including subprocessors, security measures, breach notification and deletion — are in the Data Processing Agreement. Customers are responsible for their own privacy notices towards their staff and their audiences.
Where data lives and who receives it
Data is hosted on private servers in the European Union. Limited processing by the subprocessors listed at /legal/subprocessors (e.g. AI providers for drafting, Cloudflare for delivery, email delivery providers) may involve transfers outside the EEA, safeguarded by adequacy decisions (including the EU–US Data Privacy Framework) or Standard Contractual Clauses. AI providers used by Dispatch do not train their models on data submitted through their business APIs.
Your rights
You may request access, rectification, erasure, restriction, portability, or object to processing, by emailing [email protected]. We respond within one month. You may also complain to the Spanish supervisory authority (AEPD, aepd.es). Where we act as processor, we will refer your request to the relevant customer (the controller) and assist them in answering it.