← BACK TO INVINIC 247
Legal

Privacy policy

Effective · 2026-04-23 · Version 0.1 DRAFT · GDPR / LOPDGDD
Draft — pending counsel review. Prepared for review by our Spanish abogado specialising in data protection. We comply with the EU General Data Protection Regulation (GDPR) and the Spanish LOPDGDD. Sections marked [REVIEW] require specific professional input.

1. Who is responsible for your data

The data controller under GDPR Article 4(7) is [REVIEW: legal entity name and CIF], registered at [REVIEW: registered address], Spain. You can reach our Data Protection contact at [email protected].

[REVIEW: whether a DPO is required based on scale and specific processing]

2. What we collect and why

Account data

Order and delivery data

Payment data

Device and usage data

Communications

3. Who we share it with

We only share your data with the processors necessary to operate the Service. All are bound by data-processing agreements (DPAs):

We do not sell your data. We do not share it for marketing by third parties. We may disclose it to law-enforcement when legally compelled.

4. International transfers

Some of our processors store data in the United States. Transfers are governed by the EU–US Data Privacy Framework or by Standard Contractual Clauses where the framework does not apply.

5. How long we keep it

6. Your rights

Under GDPR you have the right to:

Exercise any of these by emailing [email protected]. We respond within 30 days.

You also have the right to lodge a complaint with the Spanish Data Protection Authority, Agencia Española de Protección de Datos (AEPD), aepd.es.

7. Cookies

We use a minimal set of cookies:

See our Cookie Policy for details [REVIEW: create if we deploy GA].

8. Security

We protect your data with HTTPS-only transport, hashed passwords (bcrypt), short-lived API tokens, encrypted backups, role-based access control, and regular security reviews. No system is 100% secure; if we detect a breach affecting your data we will notify you within 72 hours in line with GDPR Art. 33.

9. Children

The Service is not intended for anyone under 18. We do not knowingly collect data from minors. If you believe a minor has provided us data, contact [email protected] and we will delete it.

10. Changes

When we change this policy we update the "Effective" date above and — for material changes — notify you by email 14 days before the change takes effect.

11. Contact

Data Protection contact: [email protected].
General support: [email protected].

Invinic247 · MMXXVI · BENAHAVÍS VERSION 0.1 · DRAFT