SoclyaSoclya← Back to Soclya

Legal documentation

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Legal Notice
  • Community Guidelines
  • EU Compliance
  • DMCA / Copyright
TermsPrivacyCookiesLegal NoticeCommunityEU / DSADMCA

Pollocrudo Company

EU Compliance (DSA / GDPR)

What Soclya does and which EU/Spain duties the operator must maintain.

Last updated: July 20, 2026Version 2.0

On this page

  1. What Soclya is
  2. Applicable laws
  3. What we already do
  4. Private messages
  5. What you must maintain
  6. SME / micro-enterprise
  7. Official contacts

Important

This page summarises EU/Spain duties for social platforms. It is not legal advice. Consult counsel or AEPD/CNMC for your situation. Last updated: July 20, 2026.

1. What Soclya is

Soclya (soclya.com) is a social network operated by Pollocrudo Company under Spain (European Union) law.

  • Accounts, posts, follows, groups, and private chats.
  • Public content moderation (AI + staff).
  • No staff browsing of private DMs unless a participant reports and selects specific messages (Meta-style).
  • We do not sell personal data.

2. Key EU / Spain rules

LawCore dutySpain authority
GDPR + LOPDGDDLawful basis, rights, security, processors, breach noticeAEPD
DSA (EU) 2022/2065Clear terms, contact points, illegal-content notice & action. 1:1 DMs are not “online platform” dissemination; public feed is.CNMC (Digital Services Coordinator)
LSSI-CELegal notice, cookies/comms rulesCompetent authorities
ePrivacy / cookiesConsent for non-essential cookiesAEPD

3. What Soclya already implements

  • Public legal suite + abuse/privacy contacts.
  • In-app reporting for posts, users, groups, selected messages.
  • Public-content AI moderation before publish.
  • Hardened session cookies, CSRF, rate limits, CSP.
  • Account deletion / privacy contact for GDPR rights.
  • Staff DM access limited to reporter-selected evidence.

4. Private messages — Meta-style rule

Golden rule

Staff must not open private conversations for curiosity, ads, or AI training.

DM content may be reviewed only if:

  1. A chat participant files a report, and
  2. They explicitly select the messages to attach (max 30), and
  3. Only that snapshot is stored on the report — not the full thread.

Legal exceptions: valid court order / competent authority request under applicable law.

See also Privacy Policy and Community Guidelines.

5. Operator checklist (what you must keep current)

  1. Complete legal-notice identity (company, tax ID, address when formalised).
  2. Records of processing (GDPR Article 30 style inventory).
  3. Processor agreements (Cloudflare, Resend, AI vendors).
  4. Documented lawful bases + cookie consent where required.
  5. Notice & action channel: in-app reports + abuse@pollocrudocompany.com
  6. DSA contact: legal@pollocrudocompany.com
  7. Minors policy + zero CSAM tolerance.
  8. Breach response plan (notify AEPD ≤72h when required).
  9. Ads: transparency/consent; never use DM content for ads.
  10. Internal ban on browsing DMs outside selected evidence / legal orders.

6. Micro / small enterprise under the DSA

Extra platform duties (risk assessments, audits, transparency reports) mainly hit larger platforms. Micro/small enterprises are exempt from many of those, but still need clear terms, contacts, and illegal-content notice mechanisms. GDPR and LSSI still fully apply. Reassess if you scale toward VLOP thresholds.

7. Contacts

  • Legal / DSA: legal@pollocrudocompany.com
  • Privacy: privacy@pollocrudocompany.com
  • Abuse: abuse@pollocrudocompany.com
Terms of ServicePrivacy PolicyCookie PolicyLegal NoticeCommunity GuidelinesEU ComplianceDMCA / Copyright

© 2026 Pollocrudo Company · Soclya — Pollocrudo Company