Privacy policy
Personal data protection and confidentiality
This document describes how Flecsa collects, uses, stores, and protects personal data of users and visitors, in accordance with Regulation (EU) 2016/679 (GDPR), applicable national law, and other relevant data protection and digital services rules.
1. Data controller
Identification of the controller
The controller of personal data collected through the Flecsa platform is the entity operating the service (hereinafter “Flecsa” or “we”), with a registered address in the European Union and a dedicated contact at privacy@flecsa.com.
When you access Flecsa as a registered user, we process your data as controller to provide the subscribed service. In certain cases —for example, when you upload third-party documents— you may act as controller and Flecsa as processor to the extent we process that content following your instructions within the application.
2. Scope of application
Who this policy applies to
This policy applies to all processing of personal data in the context of the website, web application, APIs, integrations, and any official Flecsa channel, including private beta environments.
It does not cover third-party sites, services, or links you may access from Flecsa. We recommend reviewing those third parties’ privacy policies independently.
3. Data we collect
Categories of information
We collect only data strictly necessary to provide, maintain, improve, and secure the service. The main categories are:
- Account and identity data: name, email address, user identifier, optional profile photo, language preferences, and account settings.
- Authentication data: session tokens, OAuth provider identifiers (e.g. Google), access logs, and security metadata associated with sign-in.
- Content and documents: files you upload (PDF, images, etc.), extracted metadata (amounts, dates, entities, categories), folders, tags, comments, and search results.
- Usage and essential telemetry: pages visited within the app, actions performed (uploads, searches, agent interactions), session duration, device type, browser, shortened or pseudonymized IP address where appropriate.
- Communications data: support messages, notifications sent, email alert preferences, and delivery logs.
- Billing data (when applicable after beta): information required to process payments, preferably handled by certified payment providers.
4. Purposes and legal bases
Why we process your data
We process your personal data for the purposes below, relying on the legal bases set out in Article 6 GDPR:
- Contract performance (Art. 6(1)(b)): create and manage your account, store documents, classify them, enable search, run requested AI features, and maintain your workspace.
- Legitimate interest (Art. 6(1)(f)): ensure security, prevent fraud or abuse, improve service reliability, perform aggregated or anonymized analytics, and communicate relevant product changes.
- Consent (Art. 6(1)(a)): non-essential cookies, optional marketing communications, or experimental features requiring explicit authorization. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): retain information required by tax, commercial, consumer, or cooperation laws with competent authorities.
5. Document processing and artificial intelligence
Uploaded content and automated outputs
Documents you upload are yours. Flecsa processes them to index, extract metadata, enable search, and —if enabled— answer queries using artificial intelligence models. This may involve semantic analysis, OCR, automatic classification, and responses generated from your files.
AI outputs are provided for informational purposes only. They do not constitute legal, tax, accounting, medical, or any other professional advice. You must verify any critical information (amounts, deadlines, IBAN, tax IDs, due dates) before making decisions.
We do not use your document content to train general-purpose models shared with third parties without a legal basis and, where required, explicit consent. During private beta, processing is limited to providing the subscribed service and aggregated or pseudonymized technical improvements.
6. Retention periods
How long we keep data
We retain personal data for as long as strictly necessary to fulfill the described purposes and applicable legal obligations.
Documents remain in your account until you delete them or request account deletion. After deletion, we apply logical deletion procedures and subsequently physical deletion or irreversible anonymization according to our retention cycles and backups.
Security and access logs are typically kept for 6 to 24 months, unless a longer legal retention period applies. Data needed for claims or litigation is kept for the duration of the procedure and applicable limitation periods.
7. Recipients and processors
Who we share data with
We do not sell or transfer your personal data to third parties for commercial purposes. We may disclose data to:
- Infrastructure providers (hosting, databases, object storage, CDN) acting as processors under contract and data protection clauses.
- Authentication providers (e.g. Google OAuth) when you choose to sign in with them.
- AI and document processing providers strictly necessary for features you use, with contractual safeguards and, where applicable, international transfer mechanisms.
- Professional advisers (legal, tax, audit) bound by confidentiality duties.
- Public authorities when required by law or valid request.
8. International transfers
Data outside the European Economic Area
Our goal is to process data preferably within the European Economic Area (EEA). If any provider processes data outside the EEA, we implement appropriate safeguards under GDPR Chapter V, such as Standard Contractual Clauses, adequacy decisions, or supplementary measures where necessary.
You may request additional information about applicable safeguards by emailing privacy@flecsa.com.
9. Information security
Technical and organizational measures
We apply technical and organizational security measures appropriate to the risk, including encryption in transit (TLS), role-based access controls, environment segregation, monitoring, encrypted backups, and periodic reviews.
No system is completely infallible. We recommend strong passwords, enabling available account security measures, and not sharing credentials. We will notify personal data breaches as required by applicable law.
10. Data subject rights
How to exercise your rights
You may exercise your GDPR rights at any time:
- Access: confirm whether we process your data and obtain a copy.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion where applicable (“right to be forgotten”).
- Restriction: limit processing in certain circumstances.
- Portability: receive your data in a structured format and transmit it to another controller where technically feasible.
- Objection: object to processing based on legitimate interest or to marketing communications.
- Automated decisions: not be subject to decisions based solely on automated processing with significant legal effects, except where legally permitted.
To exercise your rights, contact privacy@flecsa.com stating your request and verifying your identity when necessary. We will respond within one month, extendable by two additional months in complex cases.
You have the right to lodge a complaint with your supervisory authority (e.g. the Spanish AEPD or the authority in your country of residence or alleged infringement).
11. Minors
Use by children
Flecsa is not directed at children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect data from minors without valid parental or guardian consent. If we become aware of such processing, we will delete the relevant information.
12. Changes to this policy
Updates and notification
We may update this policy to reflect legal, technical, or operational changes. We will publish the revised version with the “Last updated” date at the top. If changes are material, we will notify you by email or prominent in-app notice with reasonable advance notice.
Continued use of the service after the new version takes effect will, where legally permitted, constitute acceptance of the updated policy.