Legal
Privacy policy
What data we process, why and for how long. And how you can see it, correct it or have it erased.
Last updated: 6 October 2026
Base text · have your adviser review it before publishing
On this page
Who processes your data
The controller is [LEGAL_COMPANY_NAME], tax ID [LEGAL_TAX_ID], registered at [LEGAL_ADDRESS].
For any question about your data, write to us at [LEGAL_EMAIL].
What data we process and why
We only ask for the data we need for each purpose. The table sums up each case and the legal basis that allows it under the General Data Protection Regulation (GDPR).
| When | What data | Why | Legal basis |
|---|---|---|---|
| Contact form | Name and email. If you give them, also your company, phone, company size, what you’re interested in and your message. | To reply and, if you ask, to prepare a proposal. | Your request (GDPR art. 6(1)(b)). |
| Assessment booking | Name, email and the day and time you prefer. | To confirm the call and prepare the assessment. | Your request (GDPR art. 6(1)(b)). |
| App account | Name, email, company and password, stored so that nobody can read it. | To create your account and let you sign in. | The contract (GDPR art. 6(1)(b)). |
| Billing | Your plan, your payments and the billing details you give us for the invoice. | To charge the subscription and issue invoices. | The contract and tax obligations (GDPR art. 6(1)(b) and 6(1)(c)). |
| Your company’s data on the platform | What your team writes and saves: requests, conversations, tasks and the company profile. | So the virtual employees can prepare the work you ask for. | We process it on your company’s behalf, as a processor (GDPR art. 28). |
| Security | IP address, browser and time of each sign-in. Who approves or changes what in the app. When you send a form or sign in, a fingerprint of your IP address and your email. | To protect accounts, stop abusive submissions and keep a record of who did what. | Legitimate interest in protecting the service (GDPR art. 6(1)(f)). |
We don’t sell your data or use it for advertising.
We make no automated decisions that affect you legally. A person always reviews what the AI prepares.
How long we keep data
We keep data only as long as we need it. After that, it is erased automatically.
| Data | Period |
|---|---|
| Contact and assessment requests | 24 months. |
| Your account and your company’s data | While the account is active. |
| Technical record of each request to the virtual employees | 90 days after it finishes. |
| Each company’s usage record | 13 months. |
| Signed-in sessions | Up to 30 days, or until you sign out. |
| Fingerprints of IP addresses and emails used to stop abuse | Erased after 48 hours. |
| Invoices | 6 years, as the Spanish Commercial Code requires (art. 30). |
If you delete your account after using the free trial that month, we keep a one-way fingerprint of your email and the usage spent until the end of the month. It only stops the trial from starting over with a new account. It is erased when the next month begins.
The platform’s total daily usage, with no personal data, is kept to control spending.
Providers that process data for us
We work with few providers. Each one processes only the data it needs for its task, on our behalf and following our instructions.
| What for | Provider |
|---|---|
| Hosting for the website, the app and the database | [LEGAL_HOSTING_PROVIDER] |
| Artificial intelligence: preparing the virtual employees’ work | Google Cloud EMEA Limited (Ireland): Gemini AI models. It processes data in the USA and other countries where Google has facilities, with no option to keep it in the EU only. |
| Email: account notices and replies to your requests | Resend, Inc. (USA) |
| Payments and invoicing | None for now. |
| Visit measurement | None. We don’t measure visits. |
Before adding a new provider, we will tell the admins of each customer company.
Transfers outside Europe
Some providers are in the United States or process data there.
Those transfers rely on the EU-US Data Privacy Framework or on the European Commission’s standard contractual clauses.
Your rights
You can ask us at any time to:
- Show you the data we hold about you.
- Correct it or erase it.
- Hand it over so you can take it to another service.
- Restrict its use, or stop using it.
Write to us at [LEGAL_EMAIL]. We reply within one month at most.
If you have an account, you can download your data and delete your account yourself from the app’s settings.
If you think we have mishandled your data, you can complain to the Spanish Data Protection Agency (www.aepd.es).
Your company’s data on the platform
What your team writes in OFICIA belongs to your company. Your company decides what data it uses and why: it is the controller.
We process that data only to provide the service and following its instructions. We are its processor (GDPR art. 28).
We don’t use it for anything else, and we don’t use it to train AI models.
The data processing agreement is part of the terms of use. If your adviser asks for a signed copy, write to us.
How we protect data
- Each company’s data is kept apart from every other company’s.
- Each person sees and does only what their role allows.
- Passwords are stored so that nobody can read them, not even us.
- The connection to the website and the app is encrypted.
- The app records who approves each thing and when.
- From your account you can see your open sessions and sign them out.
Changes to this policy
If we change this policy, we will update this page and its date.
If the change is important, we will also tell each account’s admins by email.