Important
This page summarises EU/Spain duties for social platforms. It is not legal advice. Consult counsel or AEPD/CNMC for your situation. Last updated: July 20, 2026.
1. What Soclya is
Soclya (soclya.com) is a social network operated by Pollocrudo Company under Spain (European Union) law.
- Accounts, posts, follows, groups, and private chats.
- Public content moderation (AI + staff).
- No staff browsing of private DMs unless a participant reports and selects specific messages (Meta-style).
- We do not sell personal data.
2. Key EU / Spain rules
| Law | Core duty | Spain authority |
|---|---|---|
| GDPR + LOPDGDD | Lawful basis, rights, security, processors, breach notice | AEPD |
| DSA (EU) 2022/2065 | Clear terms, contact points, illegal-content notice & action. 1:1 DMs are not “online platform” dissemination; public feed is. | CNMC (Digital Services Coordinator) |
| LSSI-CE | Legal notice, cookies/comms rules | Competent authorities |
| ePrivacy / cookies | Consent for non-essential cookies | AEPD |
3. What Soclya already implements
- Public legal suite + abuse/privacy contacts.
- In-app reporting for posts, users, groups, selected messages.
- Public-content AI moderation before publish.
- Hardened session cookies, CSRF, rate limits, CSP.
- Account deletion / privacy contact for GDPR rights.
- Staff DM access limited to reporter-selected evidence.
4. Private messages — Meta-style rule
Golden rule
Staff must not open private conversations for curiosity, ads, or AI training.
DM content may be reviewed only if:
- A chat participant files a report, and
- They explicitly select the messages to attach (max 30), and
- Only that snapshot is stored on the report — not the full thread.
Legal exceptions: valid court order / competent authority request under applicable law.
See also Privacy Policy and Community Guidelines.
5. Operator checklist (what you must keep current)
- Complete legal-notice identity (company, tax ID, address when formalised).
- Records of processing (GDPR Article 30 style inventory).
- Processor agreements (Cloudflare, Resend, AI vendors).
- Documented lawful bases + cookie consent where required.
- Notice & action channel: in-app reports + abuse@pollocrudocompany.com
- DSA contact: legal@pollocrudocompany.com
- Minors policy + zero CSAM tolerance.
- Breach response plan (notify AEPD ≤72h when required).
- Ads: transparency/consent; never use DM content for ads.
- Internal ban on browsing DMs outside selected evidence / legal orders.
6. Micro / small enterprise under the DSA
Extra platform duties (risk assessments, audits, transparency reports) mainly hit larger platforms. Micro/small enterprises are exempt from many of those, but still need clear terms, contacts, and illegal-content notice mechanisms. GDPR and LSSI still fully apply. Reassess if you scale toward VLOP thresholds.
7. Contacts
- Legal / DSA: legal@pollocrudocompany.com
- Privacy: privacy@pollocrudocompany.com
- Abuse: abuse@pollocrudocompany.com